dod-rio

Provides reference knowledge for DoD risk, issue, and opportunity management in defense acquisition programs.

5|1|Updated Jun 19, 2026
One-click install
npx skills add https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs --skill dod-rio-jgsystemsconsulting
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dod-rio
Source: https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs/tree/main/packs/dod-rio
Command: npx skills add https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs --skill dod-rio-jgsystemsconsulting

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Program managers and systems engineers on U.S. defense acquisition programs need the DoD RIO Management Guide's specific scoring rules, mitigation options, and governance structures on demand, without re-reading a 141-page document mid-task. ## Core Features & Use Cases - RIO Framework Reference: Covers the three managed objects (risk, issue, opportunity), the five-step risk process, 1-5 likelihood/consequence scoring, the 5x5 risk matrix, and the four mitigation options (accept/avoid/transfer/control). - Pathway and Method Tailoring: Details RIO tailoring across all six AAF pathways (UCA/MTA/MCA/Software/DBS/Services) plus specialized methods like RMF, Cyber Table Top, FMECA, and ITRA/DTRAM. - Use Case: Ask how to build a burn-down plan for a high-consequence risk on an MCA program, and get the six-step method, IMS integration guidance, and the relevant chapter references. ## Quick Start Ask the agent to explain how to score and mitigate a schedule risk on a Major Capability Acquisition program using the DoD RIO guide.

Frequently Asked Questions about dod-rio

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I score risk likelihood and consequence in DoD acquisition?

Score likelihood 1-5 against probability bands and consequence 1-5 as the maximum of cost, schedule, and performance impacts, assessed unmitigated with fully burdened costs. A KPP or APB threshold breach forces a Level 5 performance rating, and fractional scores are not allowed.

What are the four risk mitigation options in the DoD RIO guide?

The four options are Accept (track as a Watch Item), Avoid (alternate path or deferral), Transfer (reassign via MOA/MOU, which never fully removes Government exposure), and Control (actively reduce likelihood or consequence). High and moderate risks require a six-step burn-down plan loaded into the IMS.

What is the difference between a risk and an issue in DoD program management?

A risk is a possible future event characterized by likelihood and consequence, while an issue has already occurred or is certain (probability = 1) and is scored on consequence only. Issues use a parallel process with Ignore or Control options and a corrective action plan with an EAC.

Does this skill cover cybersecurity RMF and system safety in depth?

No. It summarizes RMF, Cyber Table Top, FMECA, and similar methods as risk sensors feeding the enterprise register, but defers depth to their own authorities such as DoDI 8510.01 and MIL-STD-882. Use dedicated packs like nist-800-37 or mil-std-882 for those regimes.

How does RIO management change across AAF acquisition pathways?

Each pathway pre-sets the risk posture: UCA accepts deficiencies for speed, MTA fails early and descopes, MCA front-loads decisions and burns down risk in TMRR, Software builds automation up front, DBS uses fit-gap analysis, and Services treat the requirement as the risk.