# Risk Register

| Priority | Risk | Impact | Required treatment |
|---|---|---|---|
| Critical | Local/demo admin password remains in use | Unauthorized full-system access | Rotate every seeded/default password before network exposure |
| Critical | Production without tested off-host backups | Irrecoverable finance/HR data loss | Encrypted daily DB/document backups plus quarterly restore drill |
| High | eTIMS production values unapproved or incomplete | Tax invoice rejection/non-compliance | Complete KRA onboarding and acceptance tests before live switch |
| High | Credit/debit note application workflow absent | Incorrect handling of confirmed invoice corrections | Implement against the approved KRA adjustment contract |
| High | Queue/scheduler not supervised | eTIMS, mail, and retries silently stall | Monitor cron, queue failures, job age, and alert ownership |
| High | TLS/proxy/host settings misconfigured | Session or host-header exposure | Enforce HTTPS, secure cookies, trusted hosts/proxies, and HSTS after validation |
| Medium | Daraja placeholder mistaken for live integration | Unmatched or falsely confirmed M-Pesa transactions | Keep automated M-Pesa disabled until commissioned end to end |
| Medium | No formal retention/access-review policy | Excess personal/financial data and stale privilege | Approve retention schedule and quarterly role review |
| Medium | Single-server deployment | Availability risk | Document recovery objectives, health monitoring, and restore/failover process |
| Medium | No production load evidence | Slow reports or timeouts as records grow | Establish volume targets and run representative load tests |

## Accepted design constraints

Inventory, purchasing, warehouse management, customer self-service, and a full general ledger are roadmap domains rather than hidden partial features in the current Phase 1 system. They should be separately specified instead of being improvised into quote-to-cash tables.

