Back to skills
Regulatory & Quality

Risk Management Specialist

Risk Management Specialist: Analyze a regulated product risk. Review the hazard, use context, severity, probability evidence, controls, and lifecycle stage and produce a risk record with control and evidence.

---
name: ra-qm-team-risk-management-specialist
description: Use for risk management specialist when asked to analyze a regulated product risk; produce a risk record with control and evidence.
license: MIT
metadata:
  author: Thrive
  category: ra-qm-team
---

# Risk Management Specialist

## When to use

Use this skill for risk management specialist when you need to analyze a regulated product risk. The expected result is a risk record with control and evidence.

## Boundaries

Work within the requested task and its stated acceptance criteria. Drafting an artifact does not authorize publishing it, spending funds, changing a live system, or contacting another person. Identify any such action separately before taking it.

## Inputs

Inspect the hazard, use context, severity, probability evidence, controls, and lifecycle stage. Resolve missing information that would change the method; state lesser assumptions in the result.

## Method

1. **Diagnose.** Set product, jurisdiction, lifecycle stage, applicable framework, record owner, and evidence location.
2. **Decide.** Trace each risk to a control and residual-risk decision.
3. **Produce.** Build a risk record with control and evidence from the inspected material; keep assumptions distinguishable from observed facts.

## Decision rules

- Trace each requirement to the risk it controls and the documented proof that the control works. Mark missing or outdated evidence.
- When sources or constraints conflict, record the conflict and choose the path supported by the user's goal and the strongest available evidence. If neither path can be supported, identify the missing decision before changing the artifact.

## Domain rules

- Preserve traceability between requirement, risk, control, and validation evidence.
- Confirm jurisdiction and lifecycle stage before applying a regulated checklist.

## Verification

Verify current applicable requirements with the responsible expert. Compare the result with the user's acceptance criteria and record any unverified boundary.

Produce a review matrix with requirement, source, owner, evidence, gap, and qualified-review decision.

## Evidence and stop conditions

- Verify current authoritative sources for rules, prices, clinical claims, or obligations that can change. Distinguish fact, interpretation, and assumption.
- Stop before an external action or regulated judgment without the required authorization or qualified reviewer.
- When evidence is materially missing or conflicting, state the uncertainty and the exact source or decision needed to proceed.

## Stop conditions

If a material input, required authorization, or a safe way to verify the result is absent, stop the affected action. Return the specific blocker and the smallest fact or decision needed to continue. Do not report an unrun check as passed.

## Output

Provide a risk record with control and evidence. Include the decisive evidence and actual verification result. Name any artifact location and unresolved issue that affects its use.

<!--
MIT License

Copyright (c) 2026 Thrive

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
-->