Department of Defense Risk, Issue, and Opportunity (RIO) Management Guide for Defense Acquisition Programs
Summary
This guide provides comprehensive Department of Defense guidance for planning and executing Risk, Issue, and Opportunity (RIO) management across defense acquisition programs. It emphasizes tailoring RIO practices across all six Adaptive Acquisition Framework (AAF) pathways and integrating risk management with systems engineering, program management tools, cybersecurity, digital engineering, and agile software development.
Cover Page
Department of Defense Risk, Issue, and Opportunity (RIO) Management Guide for Defense Acquisition Programs
September 2023
Office of the Executive Director for Systems Engineering and Architecture Office of the Under Secretary of Defense for Research and Engineering Washington, D.C.
Distribution Statement A. Approved for public release. Distribution is unlimited.
Publication Information
Department of Defense Risk, Issue, and Opportunity Management Guide for Defense Acquisition Programs
Office of the Executive Director for Systems Engineering and Architecture Office of the Under Secretary of Defense for Research and Engineering 3030 Defense Pentagon Washington, DC 20301-3030 [email protected] https://www.cto.mil/sea/
Distribution Statement A. Approved for public release. Distribution is unlimited. DOPSR Case # 23-S-3231
Approval and Change Record
Approval and Change Record
Approved by Principal Deputy Executive Director for Systems Engineering and Architecture Office of the Under Secretary of Defense for Research and Engineering September 2023
Risk, Issue, and Opportunity (RIO) Management Guide Change Record
- January 2017 (Version 1): Approved for public release.
- September 2023 (Version 2): Included a new section on Adaptive Acquisition Framework (AAF) pathways (Section 5). Added Appendix A information on: Other risk management methods; Software engineering considerations in RIO management; Digital engineering considerations in RIO management; Independent Technical Risk Assessment (ITRA) considerations in RIO management. Updated references.
- October 2023 (Version 2.1): Administrative change: Revised change record table and Section 2 footer.
Contents
CONTENTS Preface …1 1 Introduction…3 1.1 Purpose … 3 1.2 Scope … 4 1.3 Risk Management Overview … 5 2 Risk and Issue Management…7 2.1 Risk Management Process Planning… 8 2.2 Risk Identification … 9 2.2.1 Risk Identification Methodologies… 9 2.2.2 Risk Categories… 12 2.2.3 Risk Statement … 13 2.3 Risk Analysis… 14 2.3.1 Consequence … 15 2.3.2 Likelihood … 17 2.3.3 Risk Reporting and Prioritization… 18 2.3.4 Risk Register… 21 2.4 Risk Mitigation… 24 2.4.1 Risk Acceptance… 25 2.4.2 Risk Avoidance … 26 2.4.3 Risk Transfer… 26 2.4.4 Risk Control … 27 2.4.5 Risk Burn-Down … 28 2.5 Risk Monitoring… 30 2.6 Issue Management… 34 3 Opportunity Management… 37 4 Management of Cross-Program Risks… 43 5 Managing Risk by Adaptive Acquisition Framework Pathway… 48 5.1 Overview of Adaptive Acquisition Framework … 48 5.2 Managing Risk for Urgent Capability Acquisition (UCA) Pathway… 49 5.2.1 UCA Pre-Development Phase… 49 5.2.2 UCA Development Phase … 50 5.2.3 UCA Production and Deployment Phase … 51 5.2.4 UCA Operations and Support Phase … 52 5.3 Managing Risk for Middle Tier of Acquisition (MTA) Pathway… 54 5.3.1 MTA Rapid Prototyping Path … 54 5.3.2 MTA Rapid Fielding Path… 56 5.4 Managing Risk for Major Capability Acquisition (MCA) Pathway… 57 5.4.1 MCA Planning Considerations … 57 5.4.2 MCA Pre-Materiel Development Decision Phase … 60 5.4.3 MCA Materiel Solution Analysis Phase … 60 5.4.4 MCA Technology Maturation and Risk Reduction Phase … 63 5.4.5 MCA Engineering and Manufacturing Development Phase… 66 5.4.6 MCA Production and Deployment Phase … 67 5.4.7 MCA Operations and Support Phase … 68 5.5 Managing Risk for Operation of Software Acquisition Pathway… 68 5.5.1 Software Planning Phase… 69 5.5.2 Software Execution Phase… 74 5.5.3 Software Risk Reduction… 78 5.6 Managing Risk for Defense Business Systems (DBS) Acquisition Pathway… 80 5.6.1 DBS Capability Need Identification Phase … 81 5.6.2 DBS Solution Analysis Phase … 82 5.6.3 DBS Functional Requirements and Acquisition Planning Phase… 82 5.6.4 DBS Acquisition, Testing, and Deployment Phase… 83 5.6.5 DBS Capability Support Phase … 84 5.7 Managing Risk for Acquisition of Services Pathway… 85 5.7.1 Acquisition of Services Planning Phase… 85 5.7.2 Acquisition of Services Development Phase … 86 5.7.3 Acquisition of Services Execution Phase… 88 Appendix A. Additional Methods and Considerations for Managing Risk in Defense Programs… 90 Appendix B. Program Risk Management Process and Roles… 106 Appendix C. Risk Management in Relation to Other Program Management and Systems Engineering Tools … 117 Appendix D. Risk Management Process Implementation Example… 125 Glossary… 130 Acronyms… 136 References … 141
Preface
Preface
This guide is one of several Department of Defense (DoD) policy and guidance documents that address the Department’s focus on risk management. This guide builds from and supersedes the DoD Risk, Issue, and Opportunity (RIO) Management Guide of 2017 but includes revisions to emphasize RIO management for the DoD Adaptive Acquisition Framework (AAF) pathways (see DoD Instruction (DoDI) 5000.02).
DoD policy, regulation, and statute identify risk management for its recognized positive relationship to program outcomes; however, the value of risk management is not tied to a formal adherence to policy. Rather the value lies in the Program Manager’s (PM) ability to apply critical thinking and adopt a culture of risk management that influences program decisions and execution of technical solutions. This approach aims to manage uncertainty and increase predictable outcomes in delivering capability to the warfighter.
Risk management is an integral part of program planning and execution regardless of the acquisition pathway the program uses to acquire a system, product, or service. The PM and Lead Systems Engineer (LSE) are the program members primarily responsible for leading risk management. A PM must align risk tolerance with organizational capacity to manage risks and must allocate resources to the best effect. Risk management principles addressed in this document echo the time-proven 1986 Packard Commission recommendations.
This guide describes strategies and processes for RIO management that a program should begin early in development and reevaluate, revise, and reapply throughout the acquisition life cycle. Each program should tailor the practices and avoid adding a process that does not add value. Identifying the program’s key uncertainties and challenges early can help inform decisions on the basic program structure and the activities needed to enable the program to deliver the intended product or services successfully and efficiently.
Although this guide focuses primarily on the Government program office, industry plays a central role in the management necessary to deliver acquisition products and services. Government and industry may differ in the prioritization of risks, in part because of differing perspectives or incentives. For example, the type of contract, cost or fixed price and associated incentives, can affect the nature of the actions taken by Government and industry in their respective roles. Nevertheless, close collaboration and a shared commitment to performance objectives, even when inconvenient, are essential to effective risk management.
The guide is organized as follows:
- Section 1: Introduces the scope and overview of the guide.
- Section 2: Describes how a program manages risks and issues by developing plans to reduce the consequences and/or the likelihood of the risks or issues.
- Section 3: Describes opportunity management, including the similarities and differences between opportunity and risk management.
- Section 4: Highlights considerations to manage risks related to internal and external interfaces with interdependent programs. Discusses the different priorities of interdependent programs and techniques to manage and mitigate cross-program risks.
- Section 5: Describes how risk informs the decisions shaping a program Acquisition Strategy and structure, and the most important activities to manage risk by AAF acquisition pathway.
- Appendices provide information on additional methods and considerations for managing risk, roles and responsibilities, integrating risk management with other roles and tools, and illustrative vignettes.
Text boxes highlight expectations that programs should have in mind as they seek to improve the planning and execution of risk management processes and techniques.
1 Introduction
1 INTRODUCTION
1.1 Purpose This guide seeks to advance the ability of DoD programs to plan for and manage risks, issues, and opportunities. Managing these areas requires strategic thinking and begins with early decisions about program structure that take into account the program’s unique uncertainties and risks. The analysis and informed judgment needed to identify and control risk are fundamental to effective program planning and management.
For the purpose of this guide, the terms risk, issue, and opportunity are defined as follows:
- A risk is a potential future event or condition that may have a negative effect on achieving program objectives for cost, schedule, and performance. A risk is defined by (1) the likelihood that an undesired event or condition will occur and (2) the consequences, impact, or severity of the undesired event, were it to occur.
- An issue is an event or condition with negative effect that has occurred (such as a realized risk) or is certain to occur (likelihood of 5) that should be addressed.
- An opportunity offers potential future benefits to the program’s cost, schedule, or performance baseline.
Figure 1-1 shows a simple portrayal of technical, programmatic, and business events that may lead to risks, issues, or opportunities, each with cost, schedule, or performance consequences.
- What can go wrong? -> Risk Management
- What has or is certain to go wrong? -> Issue Management
- What can be improved? -> Opportunity Management
1.2 Scope DoD distinguishes statute and mandatory policy from recommended guidance. This document serves solely as guidance and not as a mandatory checklist. It reflects experience from numerous DoD programs and suggests risk considerations and mitigation that programs should keep in mind when developing an Acquisition Strategy and program structure.
This guidance is intended primarily for PMs and their staff. This guide includes a strategic consideration of how risk shapes program structure and content, as well as a suggested process to manage risks by phase. The process is designed to produce risk mitigation plans, which provide the substantive steps a program will take to mitigate its individual risks. This guide uses the term “risk mitigation plan” to refer to the plans a program initially summarizes in the Acquisition Strategy and updates as the program continues to identify and manage risks.
This guide uses the term “Program Risk Management Process (PRMP)” to refer to how the program will describe and execute its RIO processes. The term PRMP is not mandatory but is a suggestion to distinguish process documentation from descriptions of risk mitigation plans.
This guide does not attempt to address, in detail, specific requirements to prevent and manage risks related to any functional areas such as system safety or system hazards, including environment, safety, and occupational health (ESOH) hazards and ESOH domain hazards, or risks identified in their respective plans. The reader should refer to guidance including the following for specific areas: DoDI 5000.88, “Engineering of Defense Systems”; MIL-STD-882, “Standard Practice for System Safety”; DoDI 5000.95, “Human Systems Integration in Defense Acquisition”; and the Human Systems Integration (HSI) Guidebook (2022).
Programs should refer to DoDI 8500.01, “Cybersecurity” and DoDI 8510.01, “Risk Management Framework (RMF) for DoD Systems,” for policy and procedures regarding the enterprise-wide structure for cybersecurity risk management. Appendix A presents an overview of the RMF for DoD Systems and Cyber Table Top (CTT) risk assessment as examples of specialized cybersecurity risk management methods.
For specialized risk induced by electromagnetic spectrum (EMS) supportability and compatibility (EMC), programs should refer to DoDI 4650.01 and DoDI 3222.03 for spectrum supportability risk assessment (SSRA) and E3 assessments.
1.3 Risk Management Overview The PM is ultimately responsible for implementing risk management within program constraints. Successful risk management requires planning and resourcing, and should be implemented early in the life cycle based on collaboration among operational, acquisition, and technology communities. Risk management needs to be both top-down and bottom-up to be successful.
2 Risk and Issue Management
2 RISK AND ISSUE MANAGEMENT
Risk and issue management are closely related and use similar processes. All defense programs encounter risks and issues and must anticipate and address them on a continuing basis.
Risks are commonly characterized by likelihood and consequence. Through risk management, programs apply resources to lessen the likelihood of a future event occurring or the consequence should it occur.
An issue differs from a risk in that its occurrence is certain, not probabilistic. An issue is characterized by its consequence, and issue management applies resources to address and reduce the potential negative consequences associated with a past, present, or future certain event.
Figure 2-1 illustrates a suggested five-step management process:
- Risk Management Process Planning (What are the program’s risk and issue management processes?)
- Identification (What has, can, or will go wrong?)
- Analysis (What is the likelihood of the risk and the consequence of the risk or issue?)
- Mitigation/Correction (What, if anything, will be done about the risk or issue, and when?)
- Monitoring (How has the risk or issue changed?) With continuous Communication and Feedback throughout.
2.1 Risk Management Process Planning Risk management process planning consists of the program’s activities to develop, implement, and document steps the program will take to manage individual risks. The Systems Engineering Plan (SEP) should summarize the process, which can reference a detailed PRMP document.
2.2 Risk Identification A program identifies risks by answering: What can go wrong? What is particularly difficult in this program development? What information is lacking? The PM should appoint a trained risk manager to oversee the risk management process and maintain the risk register.
2.2.1 Risk Identification Methodologies Techniques include reviewing source documents (JCIDS, AoA, TRAs, test results), conducting interviews with SMEs and team leads, examining RFPs/proposals, conducting Systems Engineering Technical Reviews (SETRs), analyzing metric trends, examining external influences and supply chain/production factors.
2.2.2 Risk Categories
- Technical (Technology, Engineering, Integration)
- Programmatic (estimating, planning, execution, staffing, contract structure)
- Business (External) (dependencies, funding, priorities, regulations, market factors, weather)
2.2.3 Risk Statement A good risk statement contains the potential event and the associated consequences, along with an existing contributing circumstance (cause) if known, typically in an “if-then” format.
2.3 Risk Analysis Risk analysis involves estimating likelihood (1-5) and consequence (1-5 for cost, schedule, performance) to determine the risk level (low/green, moderate/yellow, high/red) using a 5x5 matrix.
- Table 2-1 defines consequence criteria across levels 1 (Minimal) to 5 (Critical).
- Table 2-2 defines likelihood criteria from Level 1 (Not Likely, >1% to <=20%) to Level 5 (Near Certainty, >80% to <=99%).
- Expected Monetary Value (EMV) = Likelihood x Cost Consequence. Life Cycle ROI = (Risk-Weighted Consequence - Cost to Mitigate) / Cost to Mitigate.
2.4 Risk Mitigation Four options:
- Accept (Watch Item)
- Avoid (eliminate root cause/change path)
- Transfer (reassign responsibility)
- Control (actively reduce likelihood/consequence)
2.4.5 Risk Burn-Down Programs develop burn-down plans for high/moderate risks consisting of time-phased activities with measurable success criteria linked to the IMS.
2.5 Risk Monitoring Continuously track and evaluate mitigation progress against metrics, reporting status via trend matrices and risk burn-down charts.
2.6 Issue Management Applies to realized risks or certain events (likelihood=5). Issues are rated solely on consequence and addressed through Corrective Action Plans (POA&Ms) via Ignore, Control, Avoid, or Transfer options.
3 Opportunity Management
3 OPPORTUNITY MANAGEMENT
Opportunities are potential future benefits to the program’s cost, schedule, or performance baseline, usually achieved through proactive steps that include allocation of resources. Opportunity management helps deliver “Should-Cost” objectives below “Will-Cost” baselines.
The Opportunity Management Process mirrors the risk management process:
- Opportunity Process Planning
- Opportunity Identification
- Opportunity Analysis
- Opportunity Management (Pursue now, Defer, Reevaluate, or Reject)
- Opportunity Monitoring
Opportunities should be tracked in an Opportunity Register and integrated into the program IMS.
4 Management of Cross-Program Risks
4 MANAGEMENT OF CROSS-PROGRAM RISKS
Interdependent programs must manage internal and external interfaces (hardware, software, SWAP-C, schedules, funding priorities). Activities include:
- Designating technical authorities and establishing Interface Control Working Groups (ICWGs).
- Establishing Memorandums of Agreement (MOAs) with cost, schedule, and performance tripwires.
- Maintaining synchronized schedules showing cross-program milestones, touchpoints, and integration test activities.
- Tracking dependencies and risk health via interdependency charts.
5 Managing Risk by Adaptive Acquisition Framework Pathway
5 MANAGING RISK BY ADAPTIVE ACQUISITION FRAMEWORK PATHWAY
5.1 Overview of Adaptive Acquisition Framework The AAF comprises six pathways under DoDI 5000.02:
- Urgent Capability Acquisition (UCA) (DoDI 5000.81)
- Middle Tier of Acquisition (MTA) (DoDI 5000.80)
- Major Capability Acquisition (MCA) (DoDI 5000.85)
- Software Acquisition (DoDI 5000.87)
- Defense Business Systems (DBS) Acquisition (DoDI 5000.75)
- Acquisition of Services (DoDI 5000.74)
5.2 Urgent Capability Acquisition (UCA) Designed to fulfill urgent operational needs in <2 years. Focuses on streamlined processes across Pre-Development (days), Development (months), Production & Deployment (months), and Operations & Support (months-years).
5.3 Middle Tier of Acquisition (MTA) Delivers capability in 2-5 years via Rapid Prototyping (fielding operational prototype within 5 years) or Rapid Fielding (producing systems within 5 years with minimal development).
5.4 Major Capability Acquisition (MCA) Follows traditional milestone phases (Materiel Solution Analysis, TMRR, EMD, Production & Deployment, Operations & Support). Emphasizes early risk reduction prototyping, rigorous SETRs, framing assumptions validation, and cost-type vs. fixed-price contract risk allocation.
5.5 Software Acquisition Pathway Facilitates rapid and iterative delivery of software capability using Agile, DevSecOps, Lean practices, and “test and evaluation as a continuum”. Encompasses Planning Phase (CNS/SW ICD, User Agreements) and Execution Phase (continuous iterations, MVP, MVCR, automated pipelines, sBOM, and automated security scans).
5.6 Defense Business Systems (DBS) Pathway Follows the Business Capability Acquisition Life Cycle (BCALC) through Capability Need Identification, Solution Analysis, Functional Requirements & Acquisition Planning, Acquisition/Testing/Deployment, and Capability Support.
5.7 Acquisition of Services Pathway Incorporates the Seven Steps to the Services Acquisition Process structured across Plan, Develop, and Execute phases.
Appendices and Supplementary Material
Appendix A: Additional Methods and Considerations for Managing Risk in Defense Programs
- Details the Risk Management Framework (RMF) for DoD Systems (7 steps: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) across three governance levels.
- Mission-Based Cyber Risk Assessments (MBCRA) & Cyber Table Top (CTT) exercises.
- Software Engineering & DevSecOps integration with RIO, including agile metrics (Size, Time, Effort, Defects).
- Digital Engineering (DE), FMECA integration, DEBoK, and modeling risks.
- Independent Technical Risk Assessments (ITRA) under USD(R&E) and the Defense Technical Risk Assessment Methodology (DTRAM).
- Technology Transfer and Research Security (protecting Essential Technology Elements against foreign exploitation).
Appendix B: Program Risk Management Process and Roles
- Detailed PRMP document outline, RMB and RWG operations, Joint RMBs, selection of tools (Project Recon, Active Risk Manager, Risk Exchange), and tiered roles and responsibilities across Executive, Management, and Working levels.
Appendix C: Risk Management in Relation to Other Program Management and Systems Engineering Tools
- Integration with Work Breakdown Structure (WBS), Integrated Master Plan/Schedule (IMP/IMS), DCMA 14-Point Schedule Health Assessment, Earned Value Management (EVM), SMART Technical Performance Measures (TPMs), Schedule Risk Analysis (SRA), Cost Risk Analysis (CRA), and Performance Risk Analysis (PRA).
Appendix D: Risk Management Process Implementation Example
- Detailed walkthrough vignette of a UAV Jammer turbine generator power risk managed across TMRR into EMD, demonstrating identification, analysis, burn-down planning, bench/flight testing, and closure.
Glossary, Acronyms, and References
- Comprehensive definitions of key defense acquisition and risk terms, full acronym list, and relevant DoD instructions, directives, standards, and external guides.