Risk Management
Summary
The discipline of naming what could go wrong, who owns the response, what the trigger is and what the contingency looks like — before the campaign needs it.
Body
Risk management in a campaign means writing down the things that could go wrong (legal, political, reputational, security, funding, coalition, opposition), ranking them by likelihood and impact, naming an owner for each, defining the trigger that turns risk into active crisis, and pre-writing the response. It is the missing layer between campaign-planning (the optimistic path) and governance (the decision-rules when the path breaks).
The People Power Manual’s Campaign Strategy Guide treats scenario-planning as part of the situational-analysis work, alongside forcefield analysis and the problem tree, and pairs it with the tactical-timeline exercise so each planned tactic has a named condition under which it changes [source: people-power-manual]. The Community Tool Box’s action-planning chapters treat risk as one of the inputs the team must consider before tactics are chosen, on the principle that an action plan without a risk register is a plan that has not been stress-tested [source: community-tool-box]. The Commons Library’s organising modules repeat the same discipline: the campaign plan should state, for each tactic, what would make it unsafe to run and who would call that judgment [source: commons-library].
A useful campaign risk register has four columns:
- Risk — what could go wrong (named concretely, not “things might not work”).
- Likelihood / impact — a rough two-axis score, kept simple enough to revise weekly.
- Trigger — the observable event that flips the risk from background to active.
- Owner and response — who decides, and what the pre-agreed action is.
The Commons Library treats this discipline as inseparable from governance: the risk register is what makes decisions pre-authorised, so the team does not have to convene a meeting in the moment of crisis [source: commons-library].
Use it for
Pre-launch stress-test of a campaign plan; preparing a coalition for the most likely disruption; aligning a board on what counts as a “stop the campaign” trigger; designing an action’s safety protocol.
Worked examples
- montgomery-bus-boycott — the campaign’s risk register: legal (city’s anti-boycott ordinances), security (white-supremacist retaliation — the 1956 bombings), reputational (negative framing), political (federal response), operational (car-pool capacity); each risk had a named owner and a trigger.
- nigeria-endsars-2020 — the campaign’s post-incident risk review: the Lekki tollgate response revealed that the campaign’s risk register had not anticipated state-surveillance retaliation, and the post-incident review produced the protection-planning discipline now standard.
Related
- campaign-planning
- governance
- kpis-and-dashboards
- swot-analysis
- commons-library
- community-tool-box
- people-power-manual
Open Questions
- 2026-06-23 — The four-column risk register above is the standard practitioner pattern but is not stated verbatim in the locally fetched RAW for any cited source. Re-fetch a deeper Community Tool Box or Commons Library chapter on risk and scenario planning, or pull a Seeds for Change / MobLab risk-management guide, before this page can be promoted to
emergingorestablished. - 2026-06-23 — No source currently in the corpus explicitly covers scenario trees, decision rules, or trigger-event methodologies for civil-society campaigns. Likely homes: WRI handbook, Smk campaign-training, or MobLab Campaign Accelerator deep-dive. Listed as a sourcing target.
Learn more
- On Wikipedia: Risk management — CC BY-SA 4.0
FAQ
What is risk management?
Risk management is the discipline of naming what could go wrong, who owns the response, what the trigger is, and what the contingency looks like — before the campaign needs it. The discipline is the missing layer between campaign-planning (the optimistic path) and governance (the decision-rules when the path breaks). It means writing down the things that could go wrong — legal, political, reputational, security, funding — ranking them, and naming an owner for each.
What does a useful campaign risk register look like?
A useful campaign risk register has four columns. Risk — what could go wrong, named concretely, not things might not work. Likelihood / impact — a rough two-axis score, kept simple enough to revise weekly. Trigger — the observable event that flips the risk from background to active. Owner and response — who decides, and what the pre-agreed action is. The Commons Library treats this discipline as inseparable from governance: the risk register is what makes decisions pre-authorised [source: commons-library].
How does the People Power Manual frame risk?
The People Power Manual’s Campaign Strategy Guide treats scenario-planning as part of the situational-analysis work, alongside forcefield analysis and the problem tree, and pairs it with the tactical-timeline exercise so each planned tactic has a named condition under which it changes [source: people-power-manual]. The Community Tool Box treats risk as one of the inputs the team must consider before tactics are chosen [source: community-tool-box]. The Commons Library repeats the same discipline [source: commons-library].
What is the relationship between risk management and governance?
Risk management and governance are inseparable. The Commons Library treats the risk register as the operational discipline that makes governance real: the register is what makes decisions pre-authorised, so the team does not have to convene a meeting in the moment of crisis [source: commons-library]. Without the register, governance is a meeting ritual; with the register, governance is a pre-agreed response to a pre-named trigger.
Sources & verification
- sources/people-power-manual — grounding: secondary — RAW (7977 chars)
- sources/commons-library — grounding: secondary — RAW (5257 chars)
- sources/community-tool-box — grounding: secondary — RAW (833 chars)
