# Risk, Continuity, and Governance Worksheet

Use categories as prompts, not limits. Verify every compliance deadline with qualified internal or external sources.

## How to use this worksheet

1. Make a working copy.
2. Use fictional, aggregated, de-identified, or expressly authorized information.
3. State assumptions instead of silently filling gaps.
4. Mark questions that need finance, legal, HR, insurance, privacy, technology,
   governance, or district input.


## Risk register

| Risk statement | Category | Likelihood | Impact | Velocity | Controls | Owner | Action | Trigger |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
|  |  |  |  |  |  |  |  |  |

**Notes and decisions**

- 
- 


## Continuity plan

| Essential function | Minimum level | Dependencies | Maximum disruption | Alternate method | Recovery owner |
| --- | --- | --- | --- | --- | --- |
|  |  |  |  |  |  |

**Notes and decisions**

- 
- 


## Compliance calendar

| Requirement | Authority or source | Due date | Owner | Backup | Evidence | Escalation |
| --- | --- | --- | --- | --- | --- | --- |
|  |  |  |  |  |  |  |

**Notes and decisions**

- 
- 


## Succession map

| Responsibility or access | Primary | Emergency backup | Readiness gap | Development action |
| --- | --- | --- | --- | --- |
|  |  |  |  |  |

**Notes and decisions**

- 
- 


## Completion check

- [ ] I used evidence or labeled assumptions.
- [ ] Every action, decision, or follow-up has an owner.
- [ ] I identified at least one cross-district implication.
- [ ] I identified at least one financial, legal, compliance, privacy, people, or continuity risk.
- [ ] I removed or protected sensitive information appropriately.

## Information safety

Do not upload personally identifiable student information, protected student records, confidential personnel information, unredacted contracts, credentials, or sensitive financial information to an AI system without explicit authorization. Follow FERPA, IDEA, district policy, employment-confidentiality duties, contractual restrictions, records rules, and approved data-security procedures.
