Two documents, done properly, in one pass
SWOT and risk analysis usually happen separately and inconsistently — a rushed SWOT with threats that are actually internal problems, and a risk register full of one-line entries nobody can act on. Doing both from the same input, with the same rigour, is faster and catches things a single-lens review misses.
What it does
- A properly bounded SWOT. Strengths and weaknesses stay internal; opportunities and threats stay external. Each item ties back to evidence in the input.
- Risks written as cause → event → effect. Not a category label — an actual chain you can act on.
- Scored and categorised. Likelihood, impact, and score per risk, across delivery, technical, resource, commercial, regulatory, and more.
- Top five by score, with this month's action. Plus every risk with no named owner, called out explicitly.
- Risks kept separate from issues. A risk may happen. An issue already is. Mixing the two is one of the most common register mistakes.
Example
Made up for illustration, not a real client project.
Project brief: migrating the billing system before year-end. Sponsor is strong. Only one SME knows the legacy system and she's part-time. New provider still finalising SLAs.
WEAKNESS: Only one person holds legacy system knowledge, and she's part-time — single point of failure. RISK R-01: SME is part-time and sole knowledge-holder, so requirements sign-off may slip past the year-end deadline. Likelihood 4, Impact 5, Score 20. Action: negotiate two dedicated SME days/week this month. Owner: [OWNER TO CONFIRM]
How it works with Claude
A 10-minute one-time install into Claude.
Paste your project brief, business case, or notes.
Get the SWOT and the scored risk register back, together.
FAQs
What's the most common mistake in a SWOT analysis?
Misfiling an internal weakness as an external threat. Strengths and weaknesses are within the organisation's control; opportunities and threats are external only — keeping that boundary clean is what makes a SWOT actually useful.
How should a risk actually be written?
As cause, then event, then effect. "Resource risk" tells you nothing actionable; "the key SME is part-time, so requirements sign-off may slip past the March gate" tells you exactly what to watch and what to do about it.