Books on Project Risk Management

Finding risks before they arrive, sizing them honestly, and building a plan that survives the ones you missed.

Risk management fails in a predictable way, which is a register filled in once, reviewed monthly and never allowed to change a decision. The books here treat risk as something that alters the plan, covering identification from historical data, the arithmetic of turning uncertainty into a buffer or a range, and the specific risks that arrive with people and with security. They are ordered from the practical workshop material through to the judgement research underneath all of it.

  1. Identifying and Managing Project Risk

    Kendrick's PERIL database of failed projects becomes a set of identification checklists for scope, schedule and resource risk. The most directly usable book here, because it tells you what to ask rather than only how to score the answer.

  2. Waltzing with Bears

    The case that a project with no risk worth managing carries no value worth having. DeMarco and Lister give you risk diagrams, the five core risks of software projects and a way to show uncertainty to a sponsor without losing the room.

  3. How Big Things Get Done

    Large projects fail in the tail rather than at the average, which is why the mean overrun tells you so little. Flyvbjerg's remedy is to plan slowly, build fast and use modular repeatable pieces so that a failure stays small.

  4. Critical Chain

    Goldratt's answer to schedule risk is to stop protecting individual tasks and pool the protection into a buffer you can monitor. Buffer consumption then works as an early warning, which a monthly register review never gives you.

  5. Threat Modeling: Designing for Security

    Shostack turns security risk into a structured design activity through the four question framework and STRIDE, so it happens before a penetration test rather than after one. Read it if your product handles payments, personal data or anything regulated.

  6. The Mythical Man-Month

    The oldest risks in software delivery, including the second system effect and the cost of adding people to recover a slip. Worth revisiting whenever a recovery plan opens with a request for more staff.

  7. Thinking, Fast and Slow

    4.1236 ratings

    Optimism bias, the planning fallacy and the narrow framing that makes a real risk look unlikely. Kahneman explains the mental habits that keep a register short and comfortable.

Other reading lists