Skip to content

← Back to blog

AI & Risk · 7 min read · 2026-05-28

The problem with scoring risks in a spreadsheet (it's not what you think)

AI doesn't replace your judgment on risk — it removes the part nobody enjoys: staring at a blank description and guessing whether it's a 3 or a 4. Here's exactly how it works in KinetiRisk.

Ask any project manager what they dislike most about risk management and the answer is usually the same: the scoring. Not the thinking — they are good at the thinking. It is the bit where you stare at a risk description and try to decide whether the probability is a 3 or a 4, knowing that the number you choose will determine whether it escalates, who sees it, and how much urgency the programme manager attaches to it. It is a consequential decision and there is very little guidance to help you make it consistently.

Spreadsheets make this worse. They give you a blank cell and expect you to fill it with a number. No context, no rationale, no consistency check. One person's 3 is another person's 4, and by the time you have five project managers scoring risks across three programmes, your P×I matrix is a fiction dressed up as data.

This is the problem AI risk scoring is actually designed to solve. Not to replace your judgment — but to make that judgment faster, better-informed, and consistent across the entire portfolio.


What Happens When You Submit a Risk in KinetiRisk

When you log a risk in KinetiRisk, you give it a title, a description, and an owner. That is enough for the AI to work with. It reads your description in the context of the project — its name, its description, and the industry your organisation operates in — and returns four things:

  • Probability score. A number from 1 to 5, with 1 being rare and 5 being near-certain. The AI explains why it has chosen that number based on the specific language in your description.
  • Impact score. A number from 1 to 5, reflecting the severity of consequences if the risk materialises. Again, with a plain-English rationale tied to the description you wrote.
  • Reasoning. A short paragraph in plain English explaining the scoring logic — what it read, what patterns it recognised, and what factors drove the numbers. You can read it and disagree with it. That is the point.
  • Mitigation action plan. A structured set of actions designed to reduce the probability or impact of the risk, each with a suggested owner role so your team has a clear starting point for assigning accountability.

The whole analysis takes a few seconds. What would have taken a project manager 10–15 minutes of careful thought — and still left them uncertain — is done in the time it takes to save a form.


The Scoring Model: P×I, 1 to 5

KinetiRisk uses a standard probability-times-impact matrix, where both probability and impact run from 1 to 5. That gives you a maximum score of 25 and a minimum of 1. The escalation threshold is set at 15: any risk with a P×I score of 15 or above is automatically escalated for human review.

That threshold is not arbitrary. A score of 15 means the risk is either high-probability and moderate-impact (P5×I3), moderate-probability and high-impact (P3×I5), or any combination in between. These are risks that genuinely warrant a senior decision-maker's attention — not every risk on the register, but the ones where the cost of inaction outweighs the cost of acting.

The AI applies this model consistently. A risk described in identical terms by a project manager in one programme will get the same score as an identical risk logged in another programme. That consistency is something a spreadsheet with five different people filling it in simply cannot produce.


AI Proposes. You Decide.

This is the part that matters most, and it is worth being explicit about it: KinetiRisk is human-in-the-loop by design. The AI never makes a final decision. It proposes. Every AI-generated score goes into a human review queue — a project manager or portfolio owner reviews it before anything is confirmed.

The reviewer sees the risk description, the AI's proposed probability score, the proposed impact score, and the reasoning behind both. They have three options:

  • Accept the AI's analysis. The scores are confirmed, the risk moves to the appropriate status, and the suggested mitigation actions are ready for the team to assign and act on.
  • Override the scores. The reviewer can change either the probability or the impact — or both — and provide their own reasoning. That override is recorded in the audit trail alongside the original AI proposal, so there is a full record of what changed and why.
  • Re-run the analysis. If the reviewer thinks the description is insufficient or has been updated, they can trigger a fresh AI analysis and review the new output.

This is not AI replacing governance. It is AI doing the grunt work so the human doing the governance can focus on judgment rather than arithmetic.


Visibility Across the Whole Hierarchy

A single risk lives in a project. But project risks roll up to programme level, and programme risks roll up to portfolio level. This is the Portfolio → Programme → Project hierarchy that KinetiRisk is built around, and it is where AI scoring pays its biggest dividend.

When every risk in every project has been scored consistently — not by five different people interpreting a blank cell differently, but by the same AI logic applied to each description — the portfolio view becomes meaningful. A P×I of 16 in one project genuinely compares to a P×I of 16 in another. A portfolio owner can look at the escalated risks across all their programmes and know that the ranking reflects real relative severity, not scoring drift.

Without consistent scoring, a portfolio heatmap is just a visualisation of how different people answered the same question differently. With consistent AI scoring plus human override, it is a picture of your actual risk exposure.


What About the Mitigation Plan?

The AI does not just score the risk — it also suggests what to do about it. The mitigation action plan that comes back with each analysis is a structured list of actions, each with a suggested owner role. When a reviewer accepts the analysis, those actions become the starting point for the mitigation work, with the named owners accountable for delivery.

This matters because one of the most common failure modes in risk management is the risk that gets scored, logged, and then sits there with no action attached. The AI builds the action plan into the analysis, so the path from "risk identified" to "someone is doing something about it" is much shorter.

Owners can also update the risk status, add notes, and log changes — all of which feed into the version history that creates your audit trail.

KinetiRisk analyses every risk automatically and suggests a mitigation plan. No spreadsheet required. Start free →

Start free See how it works

Why Your Spreadsheet Can't Do This

Spreadsheets can hold a P×I matrix. They can even colour-code cells above a threshold. What they cannot do is apply consistent scoring logic across a distributed team, surface the reasoning behind a score, route escalated risks to a reviewer queue automatically, or produce an audit trail that shows who changed what score, when, and why.

  • Consistency. Five PMs filling in scores independently means five interpretations of what a 3 means. AI scoring means one interpretation applied everywhere.
  • Reasoning. A spreadsheet number has no explanation attached. An AI-proposed score comes with a plain-English rationale that the reviewer can read, agree with, or challenge.
  • Escalation. A spreadsheet can highlight a cell. KinetiRisk's escalation workflow automatically flags the risk when P×I reaches 15. Email notifications to the project owner are available on the Starter plan (£5/month) and above. The reviewer action queue — where escalated risks require formal sign-off — is available on the Team plan (£25/month).
  • Audit trail. Every change to every risk — score, status, owner, notes — is logged with a timestamp and the identity of the person who made it. Export to CSV at any point for reporting or audit evidence. Full compliance audit logging is a Team plan feature (£25/month).
  • Portfolio view. A spreadsheet shows you one project at a time. KinetiRisk rolls up from project to programme to portfolio automatically.

Frequently Asked Questions

How does AI risk analysis actually work?

When you log a risk in KinetiRisk, the AI reads your risk description alongside the project description and industry context. It proposes a probability score from 1 to 5, an impact score from 1 to 5, and a plain-English rationale explaining its reasoning. It also suggests a mitigation action plan. The whole analysis takes a few seconds. You then review, adjust if your context warrants it, and approve — your name is on the decision.

Does AI risk analysis replace the project manager's judgment?

No — and it is not designed to. AI does the initial scoring so you are starting from a reasoned proposal rather than a blank cell. You review that proposal, check whether the reasoning matches your context, and approve or override it. If you change a score, your reasoning is recorded alongside the AI's original proposal. The judgment stays with the human; the AI handles the arithmetic.

What happens when the AI scores a risk incorrectly?

You override it. The reviewer sees the AI's proposed probability and impact scores alongside the reasoning behind them. If the AI has missed important context — a key relationship, a recent event, a sector-specific pattern — you adjust the scores and add a note. That override is stored in the audit trail: the AI's proposal, your adjustment, and your reasoning are all recorded.

Is AI risk scoring consistent across different project managers?

Yes — that is its main value. The same risk described in the same way by two different project managers will receive the same AI-proposed score, regardless of their experience, mood, or intuition. That consistency is what makes portfolio-level risk views meaningful: a P×I of 16 in one project genuinely compares to a P×I of 16 in another.

Risk analysis does not have to be the part of project management that nobody enjoys. When the AI does the initial scoring and explains its reasoning, the human's job becomes reviewing judgment, not guessing at numbers. That is a better use of everyone's time — and it produces a risk register that is actually useful when something goes wrong and you need to explain what you knew and when.

Start free →