After a change management risk assessment, test the assumptions each risk rating rests on, about readiness, adoption and capacity, before anyone approves the rollout plan. The ratings arrive looking finished. In early 2016 the Government of Canada received a readiness assessment that flagged a critical risk, set it aside, and went live anyway.

A change management risk assessment rates how likely a planned change is to stall in adoption, given its scope and the organisation's readiness and capacity to absorb it.

The textbook sequence after a change management risk assessment

The standard assessment scores two things. Prosci's version rates the characteristics of the change, such as its scope and the number of people it affects, against the attributes of the organisation: its values, its openness to change and its history with past initiatives. Each risk is then ranked by impact and by how much the team can influence it.

The output sets the size of everything that follows. A high-risk profile earns a heavier effort in organisational change management: more sponsors, more communication, more training, a longer transition. Teams pick the top three to five risks, assign mitigations and fold them into the change management plan.

What to do after a change management risk assessment: test the readiness and capacity assumptions behind each rating before approving the rollout
Risk ratings from a change assessment sit on top of readiness and capacity assumptions that rarely get checked before rollout.Click to expand

From there the sequence is familiar. Sponsors approve the plan. Readiness checkpoints are scheduled before go-live, usually as surveys or sign-offs from each affected unit. Training runs. The go-live date is fixed, and the register becomes a monitoring document reviewed at steering committee meetings, in the same way any output of a risk assessment is carried forward.

At every stage, the ratings from the original assessment are treated as inputs to the plan, not as claims to be checked.

The value in that sequence

The sequence does real work. It forces a sponsor to say, on the record, that a change is large, that it touches thousands of people, and that the organisation has struggled with similar programmes before. Without it, change effort is easily sized by whatever budget remains once the technical work is funded.

It also answers a failure that is well documented across the change management field. John Kotter's analysis of failed transformations found that executives sometimes underestimate how hard it can be to drive people out of their comfort zones. A structured assessment makes that difficulty visible before the money is spent.

And it gives the rollout a shared reference point. When finance, operations and HR all see the same adoption rating, arguments about resourcing start from a common record rather than from whoever speaks loudest. Later, when ratings are weighed against criteria in risk evaluation, there is something concrete to compare.

The assessment is good at naming where a change could go wrong. It is much weaker at saying whether the conditions behind each rating are true.

The structural blind spot

Every rating in a change management risk assessment is a compressed assumption. "Adoption risk: medium" means someone believes the affected teams will reach working proficiency inside the training window. "Capacity risk: low" means someone believes those teams have room in their week to absorb a new process. The rating keeps the conclusion and drops the belief that produced it.

Readiness is the clearest case. In the research literature, Weiner (2009) defines organisational readiness for change as members' shared resolve to implement a change and their shared belief in their collective capability to do so. It is a psychological state. A survey that asks whether the team is ready measures confidence, which matters, but confidence is not throughput under live load.

What the assessment producedWhat it assumedGap to test
Adoption risk: mediumStaff will reach working proficiency within the scheduled training windowTime a pilot group on real transactions, not training exercises
Capacity risk: lowAffected teams can absorb the new process alongside their current workloadCompare output per person today with the output the new process requires
Readiness: green in every unitUnit sign-offs reflect operational readiness, not loyalty to the sponsorCheck day-one conditions independently of the people who signed off
Sponsor support: strongExecutive commitment will hold when the schedule slipsAgree in advance which evidence would delay go-live

The assessment is also often run by the team that owns the go-live date. That team chooses the questions, the respondents and the scoring. Nobody in that arrangement is asked what the ratings would look like if the beliefs underneath them were wrong.

None of these assumptions is unreasonable on its face. The trouble is that they reach the approval meeting disguised as ratings. A rating invites a mitigation plan. An assumption invites a test.

Pick the risk your rollout plan rates lowest and write down what has to be true about the affected teams for that rating to hold. Start the Walk →

How the Government of Canada learned this

In 2009 the Government of Canada began replacing the 40-year-old system that paid 290,000 public servants across 101 departments and agencies. The initiative had a budget of C$310 million and was expected to save about C$70 million a year. It paired a new PeopleSoft-based pay system, Phoenix, with a centralised pay centre in Miramichi, New Brunswick. Phoenix went live in two waves, on 24 February and 21 April 2016.

The central capacity assumption was written down. According to the Auditor General's 2018 audit, pay advisors had handled an average of 184 employee files each. The plan expected 200 after centralisation and at least 400 once Phoenix was running. By July 2015 the department knew advisors in Miramichi were handling about 150. Executives still expected productivity to more than double on the new system.

A readiness assessment existed. The Treasury Board Secretariat hired Gartner in December 2015 to review departmental readiness, and its report, delivered on 11 February 2016, flagged one critical risk: Phoenix might not pay employees accurately and on time. Gartner recommended a gradual rollout and running the old and new systems in parallel. The Auditor General found that Phoenix executives did not consider the report before go-live. A separate readiness review interviewed only project staff.

The pilot had already gone. It was cancelled in June 2015 because of major defects, and rather than delay, executives chose to run none. An IBM representative later told a Senate committee that executives "really needed to go live in full by April 2016 because the compensation advisors had already been given their notices," as recorded in the House of Commons Public Accounts Committee report.

The Auditor General judged the decision to implement "unreasonable according to the information available at the time." A Senate committee estimated approximately C$2.2 billion in unplanned expenditures in place of the promised savings. The risk was on paper. The capacity assumption, that advisors would double their output, was never tested before the rollout was approved.

Testing assumptions before committing resources

The missing step sits between the assessment and the approval. Take each rating that bears on the rollout decision and write out the belief it depends on in plain terms: advisors will handle 400 files, every unit will be trained by March, the old system can be switched off. Then ask which of those beliefs, if wrong, would change the decision.

That is the work the Universal Decision-Making Method is built around. Its five steps run Frame, Tentative Elements, Assumptions, Sufficient Certainty, and Implement+Monitor. The Assumptions step surfaces what the rollout rests on. Sufficient Certainty asks how much evidence is enough to proceed, which for a rollout might mean one unit running live for two cycles rather than a green readiness dashboard.

Evidence behind a rollout approval
Ratings and sign-offsAssumptions tested in live conditions
Approval on ratings alone: every risk has an owner and a mitigation, so the file feels complete.
Approval after testing: a pilot, a throughput check or a period of parallel running shows whether the capacity and adoption beliefs hold.

Where a test is impossible before go-live, the assumption becomes a monitoring trigger with a named threshold for pausing. Rollouts where operations cannot pause need that trigger most, and it should shape which change approach fits in the first place. After a change management risk assessment, the rating is the start of the question, not the answer.

You could approve the rollout on its risk ratings and still leave the readiness and adoption assumptions behind them untested.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.