Most program risk is people, not technical
Risk registers are full of technical risks. Thermal margins, supplier lead times, software defects. They are easy to list because they are easy to see. The risks that actually sink programs are harder to put on a slide.
In my experience the biggest slips were not engineering surprises. They were human ones. A decision that never got made. Two teams that each assumed the other one owned an interface. A concern someone raised in a hallway and never in a meeting.
We under-weight org and coordination failure modes because they are uncomfortable to name. You cannot assign a clean probability and a mitigation to "the chief engineer and the program manager don't trust each other" the way you can to a vibration test.
So I treat communication as a system, not a soft skill. Who needs to know what, by when, and how do I know it landed. Decisions go in writing within a day or they did not happen. I pre-align in one-on-ones before a group meeting, so the meeting confirms a direction instead of discovering a disagreement.
None of that shows up cleanly on a risk register. It is still where most of the risk lives.