AstraZenecaPart 1 of 5
A risk register for US Oncology Compliance
I wrote the requirements and built the interface prototypes for the US Oncology Business Unit's commercial risk register. ECS built the released application in Power Apps, and its first phase launched in March 2026.
- Contribution
- Product design, business analysis, and prototype implementation
Facts
- Engagement
- August 2025 to August 2026
- Contract title
- Senior UI/UX Business Analyst
- Responsibilities
- Requirements, interaction design, frontend prototypes, and shared design patterns
- Collaboration
- Business owners, medical specialists, product partners, designers, and model and backend engineers
The project I joined
A clearer way to manage commercial risk
Every quarter, Compliance needed the same three answers. Which commercial risks need attention. Who owns each action plan. What changed since last time. Getting them meant a spreadsheet, a run of email updates, and a report assembled for leadership.
I joined the US Oncology Business Unit project to work with Compliance and with ECS, the offshore delivery team. I wrote the requirements and built the interface prototypes. When the business gave feedback, I turned it into changes ECS could build and test. ECS built the released application in Power Apps.
The experience I proposed
The process around the spreadsheet
The working records and reporting reference
How the project unfolded
September 2025
I learned the existing process from recorded walkthroughs, from colleagues, and from the business owner. Then I wrote requirements and early wireframes.
October 2025
The team put data entry ahead of the proposed chatbot. The first release needed to make the core register work.
December 2025
I compiled the reference designs for ECS. We clarified how quarterly progress should open, and the business owner approved the revised wireframes.
February 2026
I worked through business testing with Compliance and ECS. Their feedback became clarified requirements and assigned fixes.
March 2026
The first phase launched. My work continued with reporting improvements and requirements for the next phase.
Follow one mitigation through the work
Keep the risk in view
I wanted people to update a mitigation without losing their place in the register. So I tried a detail panel, collapsible navigation, and tighter tables. I also asked the team to match the names and fields in the prototype references.
I used AI-assisted prototyping to make the Figma flow interactive so the team could try the proposed design.
Open a risk and check its action plans
Record the work, quarter by quarter
Keep evidence beside the update
Keep earlier updates available
Give Compliance a stable update to review
In the later requirements, submitting an update locked it while Compliance reviewed it. A request for changes reopened it for editing. Owners couldn't review their own submissions. We called a completed review Reviewed to distinguish it from approving a policy exception.
The required review behavior
Ready to send
The owner or an assigned contributor updates the mitigation and submits it for review.
Under review
The update is read-only for owners and contributors while Compliance reviews it.
Reviewed or changes requested
Compliance records the review or requests changes, reopening the update for editing.
Contributor permissions and the earlier sketch
Let contributors update their assigned work
Business owners needed colleagues to help with data entry while they remained accountable for the work. I specified a Contributors field for assigning that help. Contributors could update mitigation progress, attach supporting documentation, and submit updates for review. Risk fields stayed read-only for both business owners and contributors. Version History would name the person who made each edit.
Contributor permissions
A missing update was not necessarily overdue work
Describe what the record actually tells us
During the April review, the business owner pointed out that a mitigation could be finished even though nobody had entered the update. Calling the work overdue would tell the wrong story.
I specified Missing for a blank quarterly update and informational highlighting without red warnings. Reminders would go out at the start of each quarter, with no automatic nudges during it.
Find assigned tasks in My Work
Which updates belong in My Tasks?
This quarter
A blank update appears in the task list from the start of the quarter.
An earlier quarter
A missing update stays visible until someone records it, even when the next quarter begins.
A future quarter
The update stays out of the task list until that quarter starts.
Take the email straight to the task
The business owner wanted reminder emails to open My Tasks directly. Sending someone to the landing page meant making them find the work again. I included the direct link in the later requirements.
Keep completed work when a risk is canceled
Canceling a risk stopped its unfinished mitigation work and kept what had already been completed. The rule logged each resulting change. Canceled items would leave the active counts and missing-update calculations. This was specified behavior for the next phase.
Allow completion dates in the past
A date rule blocked people from recording work they had already completed. The revised requirement allowed past completion dates, including dates before the record was created. The related fixes were still in the backlog in March.
Put the decision in front of the team
Bring the reference designs together
In December, I brought the Excel templates, Power BI demonstration, my Figma exploration, and ECS wireframes into one reference pack. I sent it with the requirements and brand guidance so we could discuss the same fields and interactions.
Compare the design references
Read quarterly progress without editing the record
The business owner marked Q1 on the wireframe to show where she expected to open its progress summary. She wanted to read the update without entering edit mode. ECS confirmed the changes, and she approved the wireframes on 18 December with one correction to the quarter order.
Her feedback on the quarter control
Turn business testing into assigned fixes
During testing, owners couldn't edit some of their assigned mitigations, and My Work showed items that were no longer pending. I checked the requirements and sent ECS specific fixes. With Compliance and ECS, I set out which roles and tasks to test and when testing could start. We also agreed what had to pass before we accepted the application.
Business testing and ECS follow-up
Keep the first release focused
We deferred the overdue rule and lower-priority changes to Phase 2 so the team could finish access, permissions, and record updates. I documented those decisions and the process for deferring work.
Make smaller pieces ready for review
Between long specification threads and gaps in updates, it was hard to tell which decisions were settled. I made a deck with short explanations and pictures. The business owner wanted smaller pieces she could review as the work progressed.
I asked for a weekly update showing requests, work in progress, and completed changes. We were still discussing how to establish that routine.
Why I made the deck and what it covered
Make the open questions explicit
Plan for launch and the questions after it
The delivery plan ran from specification review and wireframes through access dependencies, testing, migration, and training, ending at a go/no-go decision. The support model separated business questions from IT issues. Its routes ran through Compliance, Enabling Systems, ECS, the Power Platform team, and Microsoft support.
The launch preparation plan
Zoom in, then scroll the diagram. With the diagram focused, use the arrow keys.
Who handles a support question?
Zoom in, then scroll the diagram. With the diagram focused, use the arrow keys.
One system, four sets of responsibilities
What use revealed, and what came next
Add mitigation progress to committee reports
After the March launch, the business owner needed mitigation progress in her compliance committee reports. The application could not include it. I mocked up field selection and specified year and quarter filters so the reports would include the relevant progress summaries.
Choose the reporting period and export format
Reuse the patterns and respect different rules
Global Oncology needed risks that could exist without mitigation plans. That changed which validation, review, and cancellation rules applied. A person could share a login while still having separate access to each register.
I specified different risk categories and leadership labels, with a shared landing page directing people to the registers they could access. Each register would keep its own records, permissions, and notifications.
Shared patterns, separate records
Separate the next release from the wider ideas
The team had already put data entry ahead of the chatbot in October. In April, the scope proposal deferred the role-specific KPI dashboard, AI helper, and bulk editing to Phase 3. It dropped cross-register exports, a Global Contributor role, and the separate Forms submission path.
What waited, and what came out
What this work contributed
The first phase launched in March 2026. My contribution covered requirements, interface prototypes, business testing, and the follow-up work on reporting and quarterly updates.
Where testing time actually went
The wider assistant direction
Inspect the intended change
Alongside the core register, I explored an assistant for asking about risks, comparing trends, and taking follow-up actions. In one early proposal, people could inspect an update before choosing Confirm Changes or Reject Updates.
The team deferred the chatbot to focus the first release on entering and updating records. These prototypes show the ideas we explored beyond that release.
Review what the assistant proposed
Ask about a risk, then follow up
Give the question a scope and the answer a next action
In a separate assistant prototype, I explored how leaders could ask about rising risks, audit readiness, and board reporting. The controls set a reporting period, an organizational scope, a status, and a sensitivity level. For escalation, I added recipient selection and an editable message. The answer could come out as a board slide, an executive summary, or an evidence pack.
I also explored a risk-entry form with fields for assessment, ownership, controls, and supporting files. These component studies weren't connected into a working service.
Connect the people, records, and decisions
I mapped how business owners, Compliance, leadership, and Audit could work with the same risk records. The original map connects mitigations, reviews, evidence, reports, and proposed AI assistance. Its reminder and escalation ideas are an earlier proposal, distinct from the later quarterly requirements.
Explore the original system map
Zoom in, then scroll the diagram. With the diagram focused, use the arrow keys.
Three places to enter the proposal
Asking the register a question in plain language
Results
- The risk register's first phase launched in March 2026. ECS built it in Power Apps. I contributed requirements, interface prototypes, acceptance testing, and issue triage.
- After launch, I specified the report filters the business owner needed and helped scope the second phase, which was approved in April 2026.
Evidence limit
No adoption, time-saved, or KPI result was measured. The KPI dashboard moved to a later phase.


























