Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Risk And Mitigant Register

ASecurity

Builds a live risk register pairing every material risk with a named mitigant, an owner and a residual assessment, when you need to show which risks are priced into the bid and which are simply accepted.

8 stars
0 votes
0 copies
1 views
Added 9/19/2026
ai-agentsgoexpress

Works with

cli

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add andreworia/claude-finance-skills --skill risk-and-mitigant-register --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Risk And Mitigant Register?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Risk And Mitigant Register
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/andreworia-risk-and-mitigant-register/badge)](https://www.skillsdirectory.com/skills/andreworia-risk-and-mitigant-register)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: Risk and Mitigant Register
description: Builds a live risk register pairing every material risk with a named mitigant, an owner and a residual assessment, when you need to show which risks are priced into the bid and which are simply accepted.
---

# Risk and Mitigant Register

## When to use

Use this skill from the point diligence findings start landing through to the first board meeting after close. The IC memo carries a risk matrix; this is the instrument behind it, kept live and handed over at completion. Reach for it when the risk section reads as a list of things that might go wrong rather than decisions taken.

## What it does

Produces a register in which each risk is sized in the currency of the deal, matched to one mitigant with one named owner and a date, assessed for what remains after it, and classified as priced, transferred, mitigated or accepted -- ending with the accepted risks on one page.

## Method

1. **Harvest, never invent.** Every entry traces to a finding in a workstream, cited by source. Generic risks -- competition, cyclicality, key person -- are cut unless a finding gives them a number.
2. **Size before you rank.** Express each risk as EBITDA at risk, enterprise value at risk, or months of delay. "Customer concentration" is not a risk; "the top customer, 18% of revenue, renews eleven months after close" is.
3. **Name one mitigant and one owner.** The mitigant is an action with a date, not a posture; the owner is a person, not a committee. Mitigants come in four families: priced into the bid, transferred by instrument, secured contractually, or executed in the 100-day plan.
4. **Assess the residual, not the gross.** Restate probability and severity after the mitigant applies. Residual is the only column the committee should act on, and one that does not move it is not a mitigant but a comfort.
5. **Separate priced from accepted.** Say which each risk is: priced -- reflected in the offer, with the amount; transferred -- to the seller or an insurer, with instrument and cap; mitigated -- reduced by action, with the owner; or accepted -- taken on knowingly at this price. A register in which nothing is accepted has not been read honestly.
6. **Test for correlation.** Risks sharing a driver -- one customer, one site, one regulator, one refinancing window -- are not independent. Group them and size the group, because the group is the loss that arrives.
7. **Set a tripwire for the top five.** For each, the observable that says it is materialising, the date of the first look and who looks. A risk without one is discovered late by definition.
8. **Carry it across completion.** At close the register becomes the ownership risk log: owners transfer to the chair and management, and the accepted page is read at the first board meeting so nobody rediscovers it later.

## Inputs

- Diligence findings by workstream, with the issues log
- QoE report, with rejected add-backs and normalisations
- Draft SPA terms: warranties, indemnities, escrow, W&I cover and caps
- The returns model, to price a risk in multiple terms
- The 100-day plan, for operationally mitigated items

## Output format

- Entries in prose: risk, source, size, mitigant, owner, date, residual, treatment
- A correlation section grouping risks that share a driver, sized together
- A priced summary reconciling risk adjustments to the bid
- One accepted-risk page, without mitigants, recording what was knowingly taken
- Tripwires for the top five, each with an observable, a date and a watcher
- Present the register and all schedules in prose, never as markdown tables

## Example

Kellerman Fluid Systems (fictional, illustrative): revenue 150, QoE EBITDA 30, bid at 9.0x for enterprise value of 270. The technical review found 6 of deferred maintenance capex in years one and two; treatment is priced -- the bid drops by the full 6 to 264, or 8.8x, and the spend sits in the model, not the risk narrative. The top customer is 27 of revenue at 18%, carrying 10.8 of contribution at a 40% contribution margin against EBITDA of 30; treatment is contractual, a three-year renewal signed before completion, residual medium because the renewal secures the contract but not the volume inside it, owner the deal partner until close, the chair after. The single site is accepted: no mitigant exists at this price, and the continuity review is a control not a cure. Saying so on the accepted page serves the committee better than calling a control a mitigant.

Attribution

andreworiaandreworia
View sourceMore from andreworia →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693621 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →