Risks and Mitigations
Key adoption, governance, and delivery risks.
Adoption Risks
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Training stays generic | Medium | High | Use client workflows and require reusable outputs |
| Leaders send mixed signals | Medium | High | Start with executive alignment and explicit guardrails |
| Staff fear job replacement | Medium | Medium | Frame AI as capability amplification and focus on human review |
| Champions are not given time | High | Medium | Agree champion expectations with managers up front |
Governance Risks
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Sensitive data is entered into the wrong tool | Medium | High | Tool tiers, data rules, and examples of prohibited use |
| AI outputs are trusted without checking | High | High | Teach review checklists and evidence standards |
| Policy blocks useful experimentation | Medium | Medium | Define approved low-risk use cases |
| Shadow AI usage continues | High | Medium | Provide sanctioned tools and a path to ask questions |
Delivery Risks
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Participants have uneven skill levels | High | Medium | Use role-based tracks and optional advanced exercises |
| Tool access is not ready | Medium | High | Confirm licences and accounts before workshops |
| Too many use cases are selected | High | Medium | Limit pilots to two or three workflows |
| Value is not measured | Medium | High | Define success metrics during assessment |
Open Questions
- Which audience should be prioritised first: executives, staff, champions, or technical teams?
- Should the first engagement focus on productivity, governance, automation, or a specific business function?
- Which tools are already approved for client use?
- Should training material be public-facing, client-specific, or private by default?