Stating Risks and Assumptions Openly
Memo · 10 min read ·
A risks and assumptions section earns trust by naming what could go wrong. How to find the key assumptions, test them, rank risks and write them plainly.
The section that readers trust most in an early venture memo is often the one founders like least: the risks. It feels like admitting weakness. In practice it does the opposite. A founder who can say precisely what might go wrong, and what they are doing about it, shows judgement. A founder who says there are none shows either inexperience or a wish to hide something.
This guide explains how to find your key assumptions, rank the risks, test them and write the section plainly. It is general information, not investment or legal advice.
Assumptions and risks
An assumption is a belief you hold without proof for now. Every venture is built on a stack of them: that this customer has this problem, that they will pay, that the technology works at scale, that you can reach them at a sensible cost.
A risk is the possibility that something goes wrong. The two are linked: each risk is the chance that an assumption is false. Risk management, as a discipline, involves identifying, assessing and prioritising risks and then taking steps to reduce or monitor them. For an early venture, the practical version is a short list of what must be true and a plan for finding out.
Find your assumptions
Most founders know their riskiest assumptions but rarely write them down. Spend an hour.
Step 1: Write the story of success. "A customer finds us, tries the product, gets value, pays and tells a friend." Write the steps.
Step 2: For each step, ask what must be true. For example:
- Customers exist who have this problem and recognise it.
- They are looking for a solution, or can be reached.
- They will try ours rather than stay with what they have.
- Our product solves the problem well enough.
- They will pay a price that covers our costs.
- We can reach enough of them affordably.
- We can build and run it with the team we have.
Step 3: Write each as a plain statement. "Independent therapists will pay a monthly fee for booking software."
Step 4: Mark what you know and what you do not. Known (tested), partly known (some evidence) and unknown.
The unknown and partly known ones are your risks.
Rank them
Not all risks are equal. Rank by two measures.
- Impact: if this assumption is wrong, how badly does it hurt? If customers will not pay, the venture fails; if a feature is slow, it is annoying.
- Uncertainty: how little do you know?
The riskiest assumptions are those with high impact and high uncertainty. These come first in your testing and in your memo.
A simple table helps: assumption, impact (high, medium, low), evidence so far, what would change your mind.
Test the riskiest first
Design the cheapest test that would tell you whether the assumption is true.
- Customers have the problem. Interviews with people who fit the description; count how many describe it unprompted.
- They will try a solution. A simple landing page or a prototype shown to real prospects.
- They will pay. A pre-order, deposit or paid pilot; any real commitment of money.
- It works. A minimum viable product, which, in the common definition, is a version with just enough features to be used by early customers who can provide feedback.
- You can reach them. A small, real experiment in the channel you plan to use, with results counted.
- The team can deliver. A fixed-time build of a small piece.
Customer development, the practice of testing assumptions through conversations with customers, recommends getting out and talking to people before building more than you need. A handful of well-chosen tests can settle the biggest questions in weeks.
Record the result of each test with the date, even when it disappoints. A failed assumption, caught early, is cheap.
Write the section
For each of the top three to five risks, write three short lines.
- The assumption. One sentence.
- What we know so far. Evidence and its status.
- What we are doing about it. The test, the timeframe and what would change our plan.
Example:
"Assumption: independent therapists will pay a monthly fee for booking software. So far: four trial practices use the product weekly; none has yet been asked to pay. Next: by the end of next month we will ask all four to start a paid plan and record who agrees, who declines and why. If fewer than two accept, we will revisit pricing and the target group."
That is plain, specific and testable. A reader can see exactly where the venture stands and what will happen next.
Types of risk to consider
Cover the main categories, though only the most important will make it to the page.
- Customer risk: do they exist, do they care?
- Product risk: can you build it, and does it work?
- Market risk: is the market big enough, and is timing right?
- Competitive risk: can others copy or respond?
- Channel risk: can you reach customers affordably?
- Team risk: key-person dependence, skills gaps, time commitment.
- Financial risk: how long do resources last?
- Legal and regulatory risk: data protection, sector rules and contracts.
- Dependency risk: reliance on a supplier, platform or single customer.
Legal and regulatory risk deserves particular care. If your venture handles personal data, sells to regulated sectors or makes claims in advertising, take advice early. Do not mention legal matters in a memo unless you understand them; a wrong statement is worse than silence.
Tone
- Calm and factual. Do not dramatise.
- Specific. "Churn may be high" is vague; "two of four trial users stopped using it in week three" is specific.
- Balanced. Do not bury the reader in minor risks, and do not hide major ones.
- Forward-looking. Say what you will do, not just what could go wrong.
- Honest about unknowns. "We do not yet know" is a good sentence.
Avoid defensive phrasing such as "the only real risk is that we grow too fast". Readers see through it.
Keep it alive
Risks change. Review the section whenever you learn something important and at least monthly. When a risk is resolved, move it to a "tested" list with the result and date. When a new one appears, add it. A risk section with a visible history of tested assumptions is some of the strongest evidence a young venture can show.
Mistakes to avoid
- Listing only trivial risks to appear thorough.
- Listing only risks you have already solved.
- No plan for any of them.
- A list so long that none stands out.
- Presenting a risk as an opportunity in disguise.
- Hiding risks you know about. Material omissions undermine credibility, and in some contexts can have legal consequences if the document is meant to encourage investment.
A worked example
A venture building a tool to help allotment societies manage plots writes its risk section.
"1. Assumption: societies will pay for software. So far: seven have trialled it free; none has been asked to pay. Next: ask all seven to start a small annual plan next quarter; if fewer than two agree, we will explore grant-funded or free-with-donations models.
-
Assumption: committee volunteers will actually use it. So far: four of seven have logged in weekly; three stopped after the first month, citing time. Next: simplify the monthly routine and re-test with the three.
-
Assumption: we can reach enough societies. So far: a national association has offered to mention us in a newsletter; we have not tested it. Next: run one newsletter mention and count sign-ups.
-
Team: the second founder works two days a week. Next: agree a review point in September.
Tested and closed: we assumed that plot holders would want a mobile app; interviews showed a web page is enough."
The section is short, specific and shows that the founders are learning. It is the part of the memo a thoughtful reader would trust most.
Questions founders ask
Will naming a risk scare readers away? Rarely. Readers already suspect most of the risks. What encourages them is seeing that you have noticed them too and have a plan.
What if I do not know my riskiest assumption? Ask someone outside the venture to read your story of success and point out the step that sounds least certain. Outsiders often see the weak link immediately.
How do I balance risk with confidence? State the risk plainly and your reasons for optimism separately. Confidence and honesty are not opposites.
Should the risk section be public? On a public profile, a short version is usually enough. Keep sensitive details, such as negotiations, for private conversations.
What if a risk comes true? Say so, early, and explain what you are doing. Handling a realised risk well often builds more trust than never having had one.
A weekly ten-minute review
Once a week, open the list and ask three questions. What did we learn this week that changes an assumption? Which test is due next and who owns it? Is there a new risk we should add? Update the dates and statuses, and note anything that moved from unknown to known. Over months, the list becomes a map of what you have learned, and the habit of reviewing it turns a document into a working tool.
Summary
Naming risks is a sign of strength. Write the story of success, list what must be true, rank assumptions by impact and uncertainty and test the riskiest first with the cheapest experiment. Write each of the top few risks as an assumption, what you know and what you are doing about it. Keep the tone calm and specific, review it as you learn and keep a record of what you have tested and closed. Readers who see honest risk thinking will believe the rest of your story more readily.
Questions and answers
- Why list risks in a venture memo?
- It shows that you understand what must be true for the venture to work and that you are testing it, which is more reassuring to a reader than a claim that there are no risks.
- What is an assumption?
- A belief about customers, markets or technology that you are treating as true while you work, but have not yet proved.
- How many risks should I list?
- Three to five of the most important. A long list dilutes the message.
- Should I include a mitigation for each risk?
- Yes, where there is one. If there is none yet, say what you will do to learn more.