Some of the most important programme risks do not begin as risks.

They begin as assumptions.

That distinction matters because a risk that has been identified can be owned, monitored and mitigated. An assumption that everyone believes to be true can sit quietly underneath the plan until something forces it into the open.

I encountered exactly that on a complex international acquisition and operational-establishment programme.

The plan depended on something we thought had already been proven

The programme involved acquiring and preparing a site that would support critical infrastructure and a new operational hub. Due diligence had been carried out, plans had been approved and delivery was progressing across multiple workstreams.

Then a structural issue emerged in part of the acquired property.

The main building met the required standard. An annex did not.

The issue was not a minor defect that could be added to a snagging list. The annex required demolition and reconstruction.

More importantly, the non-compliance had not been visible in the information we had been working from.

At that point, the programme problem was larger than the building problem. Several delivery assumptions had suddenly become invalid at once: available space, sequencing, infrastructure dependencies, cost exposure and the credibility of parts of the original due-diligence evidence.

None of those appeared in the RAID log the week before.

The first job was to establish facts

When something like this happens, speed matters, but reacting quickly is not the same as making a quick decision.

We brought in independent technical expertise to establish the actual condition of the structure and separate fact from interpretation. That gave us a basis for the commercial discussion with the seller and, just as importantly, a basis for replanning the programme.

The seller ultimately carried the cost of demolition and reconstruction.

But recovering the programme still required more than resolving who would pay.

Critical infrastructure that had originally depended on the annex was moved into the compliant main building. The annex scope was reduced. Dependencies were re-baselined around the new sequence, and acceptance controls were strengthened so that the programme was not relying on the same kind of unverified assumption twice.

The objective was not to pretend the original plan could still be preserved. It was to preserve the outcome that mattered.

Risk management is also assumption management

Traditional RAID processes are useful, but they can create a false sense that the important uncertainties are the ones already written down.

On complex programmes, I increasingly look for a different category of question:

Those questions often reveal more than another review of the risk register.

The lesson is not that every assumption should become a risk. That would make governance unusable. The lesson is that critical assumptions deserve the same discipline as critical dependencies.

Protect the outcome, not the original plan

When a hidden condition emerges, there is a strong temptation to defend the baseline because so much effort has already gone into creating it.

That is usually the wrong thing to protect.

A baseline is a model of how you expect to achieve an outcome. When reality changes, the model should change with it.

In this case, changing the infrastructure sequence and reducing the annex scope allowed the wider programme to continue while the structural issue was resolved separately. The plan changed substantially. The strategic objective did not.

That is an important distinction in programme leadership.

Good control is not the ability to make reality conform to the original plan. It is the ability to understand what has changed, make the consequences visible, and reorganise delivery quickly enough that the intended outcome remains achievable.

Sometimes the most dangerous risk is not the one marked red.

It is the thing the plan assumes is already green.