{{ summaryTitle }}
{{ summaryValue }}

{{ summaryLine }}

Inherent{{ resultsReady ? `${computation.values.inherent_points} points` : '—' }} Readiness{{ resultsReady ? signedPoints(computation.values.readiness_adjustment) : '—' }} Blockers{{ resultsReady ? computation.values.blocker_count : '—' }}
Change risk report inputs
Use the exact identifier reviewers will recognize.
Write a concise, plain-language title.
This anchors approval routing and impact wording.
A team name is appropriate when ownership is shared.
Use the approved window or the proposed window under review.
Choose the path used by the change-management record.
One concise paragraph is enough when the risk factors and gates are precise.
Rate the consequence if implementation or post-change behavior goes wrong.
/ 5
Estimate implementation, validation, or post-change uncertainty.
/ 5
Rate execution and troubleshooting complexity.
/ 5
Include loss, integrity, privacy, privilege, certificate, and secret-handling exposure.
/ 5
Use 0 when no visible disruption is expected.
minutes
Visibility influences communications and approval routing.
Choose the strongest recovery evidence available before approval.
Validation drives go/no-go confidence and closeout acceptance.
Coverage should span the before, during, and post-change period.
Communication gaps raise governance and customer-impact risk.
Optional and score-neutral; when present, it is appended to the decision brief.
{{ decisionBrief }}
FactorLevelPointsEvidenceRecommendationCopy
{{ row.factor }}{{ row.level }}{{ row.points }}{{ row.evidence }}{{ row.recommendation }}
GateStatusEvidenceActionOwnerCopy
{{ row.gate }}{{ row.status }}{{ row.evidence }}{{ row.action }}{{ row.owner }}

The chart renderer is unavailable. The same driver values remain available in Risk evidence.

An IT change can be technically correct and still be unsafe to release. Its risk depends on how widely failure would spread, how uncertain the work is, how difficult recovery would be, and whether the people watching the service can recognize trouble quickly enough to act.

A useful assessment separates inherent risk from residual risk. Inherent risk describes the exposure created by the change itself: its path, impact radius, failure likelihood, complexity, data or security consequences, expected disruption, and visibility. Residual risk is what remains after rollback, validation, monitoring, and communication readiness are taken into account.

Standard change
A repeatable, pre-authorized procedure with a proven model and defined boundaries.
Normal change
A planned change that needs risk review and approval appropriate to its impact.
Emergency change
Urgent work routed through emergency authority, with stronger evidence and post-implementation review expected.

Ratings are only as sound as the evidence behind them. A narrow description can hide a large dependency chain, a zero-minute disruption estimate can ignore degraded service, and a documented rollback may not work inside the available window. The assessment should therefore be completed with the implementation plan, dependency map, acceptance thresholds, rollback timing, and named owners close at hand.

A score supports a decision; it does not make one. Local freezes, incident load, staffing, vendor constraints, compliance duties, and business tolerance can justify a stricter route than the numeric tier suggests. Missing readiness evidence should be closed or explicitly accepted by the accountable authority before implementation.

How to Use This Tool:

Start with the approved or proposed change record, then rate the change and its readiness using evidence available before the implementation window.

  1. Enter the change identifier, title, affected service, accountable owner, implementation window, and a concise summary of what will change.
  2. Choose Standard, Normal, or Emergency to match the change-management path actually being used.
  3. Rate impact, likelihood, complexity, and data or security exposure, then enter expected visible disruption and the audience likely to notice it.
  4. Select the strongest current evidence for rollback, validation, monitoring, and stakeholder communications. Planned work is not equivalent to completed evidence.
  5. Read the residual tier and approval route, then use Approval actions to close every Blocked or Review gate before go/no-go.

Interpreting Results:

The residual score shows the combined effect of inherent drivers and readiness adjustments. Use the risk evidence to find the largest positive contributions, but do not treat a low total as permission to ignore a blocked rollback, validation, monitoring, or communication gate.

Low and Moderate describe the model's point bands, not universal approval policy. High and Critical call for wider authority, while every emergency change follows the emergency route regardless of its score. Attach the resulting brief to the change record and preserve actual outcomes for closeout.

Technical Details:

The scoring model is a documented, repo-authored rubric. It is not an ITIL, NIST, or regulatory formula. Seven inherent-risk contributions are added first, four readiness adjustments are then applied, and the final total is prevented from falling below zero.

Formula Core

The residual score uses whole-number points throughout. The final rounding step is retained explicitly, although every current contribution is already an integer.

R = max ( 0 , round ( I + A ) )

Here R is residual risk, I is the sum of inherent-risk points, and A is the combined rollback, validation, monitoring, and communication adjustment.

I = C + 6i + 7l + 5x + 6d + D + V

C is the change-path weight; i, l, and x are the 1-to-5 impact, likelihood, and complexity ratings; d is the 0-to-5 data or security exposure rating; D is the disruption weight; and V is the visibility weight.

Rule Core

Inherent change risk weights
FactorRule
Change pathStandard 3; Normal 9; Emergency 18 points
Impact radiusRating × 6 points
Failure likelihoodRating × 7 points
Technical complexityRating × 5 points
Data or security exposureRating × 6 points
User visibilityNone 0; Internal 8; Customer or partner 16; Regulated, executive, or contractual 22 points

Expected disruption uses inclusive boundaries. Zero minutes adds no points; the first non-zero minute moves the change into the short-disruption band.

Expected disruption point bands
Expected disruptionPoints
0 minutes0
1 to 15 minutes5
16 to 60 minutes11
61 to 240 minutes18
More than 240 minutes26
Readiness adjustments and gate states
Readiness areaEvidence stateAdjustmentGate
RollbackTested / Documented / Planned / Missing−8 / +4 / +12 / +22Ready / Review / Blocked / Blocked
ValidationComplete / Scheduled or partial / Missing−6 / +7 / +17Ready / Review / Blocked
MonitoringComplete / Partial or manual / Missing−5 / +5 / +13Ready / Review / Blocked
CommunicationsSent or not required / Drafted or scheduled / Missing−4 / +4 / +10Ready / Review / Blocked

The final tiers are Low below 50 points, Moderate from 50 to 89, High from 90 to 129, and Critical at 130 or more. Emergency changes always route to emergency change authority plus post-implementation review. Other routes rise from a pre-approved standard path or peer review through change advisory board and senior operations approval as the tier increases.

Limitations and Privacy Notes:

The model cannot discover hidden dependencies, current incident load, staff availability, local freezes, vendor conditions, or approval rules. Ratings remain judgment calls and can understate risk when scope or readiness is described too optimistically.

Assessment data is processed in the browser and no production system is contacted. Meaningful inputs can be carried in a shareable page address, so remove confidential change details before sharing a link or captured report.

Worked Examples:

Planned customer-facing migration

A normal change rated 3 for impact, likelihood, and complexity, 1 for data exposure, 15 minutes of disruption, and customer visibility produces 90 inherent points. Documented rollback, scheduled validation, complete monitoring, and drafted communications add a net 10 points, so residual risk is 100 points and High. The practical next step is to finish the review gates and follow the change advisory or delegated change-manager route rather than treating the score alone as approval.

References: