A list of identified risks is available (from Risk Storming, PI Planning, Risk Matrix or comparable activity).
ROAM Board
Prerequisite
What needs to be finished first
Preparation
What needs to be ready before start
Board with 4 columns (Resolved, Owned, Accepted, Mitigated); risk list as cards or notes; definitions per column visible; tool for async maintenance (Notion, Jira, Miro); review date in calendar.
One risk owner (RTE, program lead, Tech Lead) for maintenance; all risk owners; reviewers per cadence (team representatives, stakeholders); optionally one coach for ROAM introduction.
Risk list from previous step; written definition per category; review cadence proposal (for example weekly or per sprint); escalation rules for unmoved risks.
20-40 min initial, then 10-15 min per review
Board with four columns. Definitions per column as banner: Resolved=done; Owned=watched with owner; Accepted=consciously accepted without action; Mitigated=active countermeasure running. Review date as recurring series.
Core question
The one question this method answers
Which risks are in which follow-up state, who is responsible, and which need movement between columns now?
Flow
Marker: Phase
| Step | Duration | Action | Hint |
|---|---|---|---|
1Phase 1: Calibrate definitions | 10 min | Review definition per column together. Clarify that every risk is in exactly one column. Discuss edge cases (for example watched AND mitigated -> Mitigated wins). | If definitions remain unclear, risks land in wrong column. Mitigated must mean active, not "we are thinking about it". |
2Phase 2: Initially assign risks | 15-20 min | Choose column per risk, name owner. For Owned and Mitigated, next action and deadline. For Accepted, rationale in comment. | Risk without owner is risk without consequence. Anyone not naming owner has not defined responsibility. Workshop does not end with risks without owner. |
3Phase 3: Set review cadence | 5 min | Choose cadence frequency (weekly for active programs, every 2 weeks for stable). Create recurring calendar series. Define maintenance responsibility. | Cadence decays quickly if not in calendar. First review within 1 week after initial creation. Without cadence, board dies in 4 weeks. |
4Phase 4: Run reviews | 10-15 min per review | Per risk: status changed? Owner active? Action done? Document status move between columns. Escalate on repeatedly unmoved risks. | Mitigated -> Resolved is target path. Owned unchanged after 4 weeks: check real owner or Accepted candidate? |
Artifact
What comes out at the end
ROAM board with risks in four columns, owner column, status date, action note. Snapshot per review archived in wiki. Escalation list for unmoved risks.
Board is living. Snapshot per review (date) as archive. Status changes with date and rationale. Move Resolved risks to archive after 3 months, do not delete.
- Miro or FigJam with ROAM template
- Jira with custom status R/O/A/M
- Notion database with status property
- Trello with four lists
- Confluence page with table
roam-board-working-template.md
Compact working template for ROAM Board with context, input, output artifacts, and next step.
ROAM Board Canvas
Context
What is this method used for?
Core question
Which question should be answered at the end?
Input
Which data, observations, or materials are available?
Working area
- Area 1:
- Area 2:
- Area 3:
- Relationships / patterns:
Output artifacts
- ROAM Board:
- Owner List:
Open questions
- ...
Next step
Owner, date, success signal.
Example output
Concrete filled scenario, fictional example
roam-board-beispiel.md
Concrete filled scenario, fictional example
ROAM Board - PI Planning Q3/2026, review status 2026-05-18
Resolved (3)
- R1: Multi-tenant tenant-management data model open -> Q1 clarified with Bounded Context Workshop.
- R2: SSO integration blocked by IT approval -> approval received in week 14.
- R3: QA capacity unclear -> 2 additional QA engineers from April.
Owned (5)
- O1: PSP breaking change Q3. Owner: @marcus. Next action: request sandbox access by 2026-05-31.
- O2: Order Service bus factor 1. Owner: @lisa. Knowledge-sharing plan by 2026-06-15.
- O3: Outdated Order API docs. Owner: @lisa. Quarterly review Q3.
- O4: Compliance audit date open. Owner: @ben. Clarification by 2026-05-25.
- O5: Frontend performance at more than 1000 tenants. Owner: @anna. Monitoring setup by 2026-05-22.
Accepted (2)
- A1: Browser support for IE11 remains absent. Rationale: <0.5% user share, effort not justified.
- A2: Seasonal throughput dip in August. Rationale: empirical value, planned.
Mitigated (4)
- M1: DB replication without failover. Mitigation: multi-leader spike running, ETA 2026-05-30. Owner: @ben.
- M2: Payment webhook without retry. Mitigation: Sprint 23 implementation. Owner: @anna.
- M3: Inventory without idempotency. Mitigation: Sprint 24. Owner: @ben.
- M4: AI receipt recognition vendor risk. Mitigation: vendor comparison running. Owner: @anna.
Escalation: O3 unmoved for 6 weeks, discussion in next review: re-classify as Accepted?
Pitfalls
Recognize symptoms and steer against them
Double classification
Risks sit in multiple columns or oscillate between Mitigated and Owned without rule.
Rule: one risk, one column. On transition from Mitigated back to Owned (for example mitigation paused), document rationale. Clear definitions help.
Cadence decays
First review happens, after 4 weeks meeting postponed, after 8 weeks board forgotten.
Cadence as calendar series. Maintenance owner with reminder duty. On cadence skip, at least short status note.
Accepted as forgetting
Risks land in Accepted because nobody wants to care, without conscious decision.
Accepted needs rationale. Without rationale, risk belongs in Owned. Quarterly review Accepted list whether acceptance still justified.
Owned without action
Owner set, next action missing, risk remains Owned for months without movement.
Owned needs action with deadline. Silent Owned > 4 weeks discussed in escalation: is action still planned? If no, re-classify.
Board without visibility
Board lives in PM tool, team and stakeholders do not know it, risks discussed elsewhere in parallel.
Make board visible in team meetings (sprint review, stakeholder briefing). Link in central communication channels. Whoever reports risk goes to board.
Stop criteria
Done signals checkable in under a minute
Finished the runsheet?
Go to the profile for purpose, similar methods, and sources or continue to the next method in the catalog.