Written by
Nick Rivett
Published on
April 10, 2025
Last updated
September 15, 2026

RAID stands for Risks, Assumptions, Issues, and Dependencies. In project management, it's the shorthand for the four things a project team tracks: what could go wrong, what the plan is relying on, what has already gone wrong, and what the work is waiting on from elsewhere. You'll usually see them collected in a single document called a RAID log.

That's the quick answer. The slightly longer answer is that not everyone agrees on what two of the letters stand for, and it's worth knowing why.

What each letter means

Risks are things that might happen and would harm the project if they did. They haven't happened yet, which is what separates them from issues. You log them so you can spot them early and do something before they land.

Assumptions are the things the plan takes for granted. Every project rests on a few, and the danger is that they stay unspoken until one turns out to be wrong. Writing them down forces the team to see what it's leaning on.

Issues are problems that have already happened and are affecting the project now. Where a risk is about the future, an issue is about the present, and it usually needs action rather than watching.

Dependencies are the things the project needs from someone else, or that others need from it. They're a common place for projects to stall, because they sit outside the team's direct control.

For how to build and run a log around these four, see our full guide to what a RAID log is. This post is about the acronym itself, which is where the confusion usually starts.

The variations: A and D aren't fixed

Two of the four letters have common alternatives, and both are legitimate. Which you use depends on what your projects need to track.

A: Assumptions or Actions. Some teams use the A for Actions instead of Assumptions, tracking a running list of things people have committed to do. Assumptions and Actions answer different questions. Assumptions ask what you're taking on trust that could be wrong; Actions ask who agreed to do what. Teams that worry more about being blindsided tend to keep Assumptions; teams that want an accountability record lean toward Actions.

D: Dependencies or Decisions. The D is either Dependencies (what the project is waiting on) or Decisions (a log of choices made and who made them). A Decisions log is useful on projects where governance matters and people later ask who signed off on something. Dependencies matter more when the project's progress hinges on other teams.

You'll also occasionally meet a six-letter version, RAAIDD, which keeps both pairs: Risks, Actions, Assumptions, Issues, Decisions, Dependencies. It's more common on large, complex programmes than on a single project, where four columns are usually enough.

The practical advice: pick the expansion that matches how your projects run, write it down so the team is consistent, and don't assume everyone in the room means the same thing by RAID until you've checked.

Who uses RAID?

The RAID log is a working tool for project managers, but its audience is wider. Business analysts contribute to it, sponsors read it to understand where a project stands, and PMOs use it as a governance instrument, often consolidating RAID across several projects to see where risks and dependencies cluster. That last use, RAID across a whole portfolio rather than one project, is where it stops being a document and becomes a management discipline. Our RAID log guide covers that in full.

Frequently asked questions

What does RAID stand for in project management?
Risks, Assumptions, Issues, and Dependencies. Some teams use Actions in place of Assumptions and Decisions in place of Dependencies, so you'll see variations depending on the template and the organisation.

Is it Assumptions or Actions?
Both are used. Assumptions track what the plan is taking on trust; Actions track what people have committed to do. Choose based on which your projects need, and keep it consistent across the team.

What is a RAAIDD log?
A six-letter version that keeps both pairs: Risks, Actions, Assumptions, Issues, Decisions, Dependencies. It's used mainly on large or complex programmes where all six are worth tracking separately.

Where do you record RAID?
In a RAID log, usually a document or spreadsheet with a section for each of the four (or six) categories. See our guide to building one.

Ready to unlock project success?

Schedule a demo to find out more about how Altus can help your organisation unlock project management success and reach your strategic goals.