A risk is an uncertain event or condition that, if it occurs, has an effect on at least one project objective. The event is uncertain, which separates a risk from an issue that has already happened, and the effect is an effect rather than a harm, so opportunities belong inside risk management rather than beside it.
Treating risk as a synonym for threat throws away half the discipline, since a project that only plans to avoid bad outcomes never plans to capture good ones.
Identify, analyse, respond, monitor
Planning risk management settles how risk will be handled on this project, including the categories, the definitions of probability and impact, and who does what.
Identifying risks is continuous rather than an exercise at the start, because new risks appear as the project proceeds and old ones expire. The output is a register naming each risk, its cause and its potential effect, written specifically enough to act on.
Qualitative analysis rates each risk by probability and impact and orders the register accordingly. It is quick and subjective, it is applied to everything, and its purpose is to decide what deserves further attention rather than to produce a number.
Quantitative analysis models the combined effect of risks on the objectives numerically, usually by simulating the schedule or cost model many times, and it produces statements such as a probability of finishing by a date. It is expensive, it is applied only to what qualitative analysis promoted, and many projects never do it.
Planning responses assigns an owner and a strategy to each risk that warrants one. Implementing them is the step most often skipped, since a register full of unexecuted plans is a document rather than a control. Monitoring tracks identified risks, watches for new ones, and evaluates whether the responses are working.
The probability and impact matrix
Qualitative analysis needs a scale that everybody in the room reads the same way, and the matrix is where that scale is written down before any risk is scored against it.
Impact is scaled unevenly on purpose, so a severe impact counts for far more than four times a trivial one, and a low probability with a severe impact still lands in the top band. On this project anything from 0.18 upward needs a planned response, the band from 0.05 to 0.14 goes on a watch list, and anything below 0.05 is accepted and reviewed at the next cycle.
Where the band boundaries fall is a decision the project makes in advance and writes into the risk management plan. Setting them after the risks are scored lets the boundary move to suit whichever answer somebody already wanted.
Responding to threats
Avoid removes the threat entirely by changing the plan, whether by dropping the component that carries the uncertainty or by extending the schedule so the risky compression is unnecessary. It is the strongest response and it usually costs something.
Transfer moves the impact and the ownership of the response to a third party, through insurance, a warranty or a fixed price contract. The risk does not disappear, and a premium is paid to somebody willing to carry it.
Mitigate reduces the probability or the impact to an acceptable level, which is the most common response and the one people mean when they say a risk is being managed.
Escalate hands the risk upward because it falls outside the project manager's authority. Ownership genuinely leaves the project, and the risk is recorded but no longer actively managed by the team.
Accept acknowledges the risk without acting on it now. Active acceptance sets aside a contingency reserve of time or money, and passive acceptance does nothing beyond documenting the decision and reviewing it.
Responding to opportunities
The five strategies map onto their threat counterparts. Exploit is the mirror of avoid, making certain the opportunity is realised rather than merely likely, such as assigning the strongest engineers to guarantee an early finish that unlocks a bonus.
Share allocates ownership to a partner better placed to capture the benefit, mirroring transfer. Enhance increases the probability or the positive impact, mirroring mitigate. Escalate and accept work exactly as they do for threats.
Ten strategies, five of them mirrored
The strategies pair up. Every threat response has an opportunity response that does the same thing to a positive outcome, and reading them side by side is the fastest way to keep them straight.
| Threat strategy | What it does | Opportunity mirror | What it does |
|---|---|---|---|
| Avoid | Removes the threat by changing the plan, such as dropping the component that carries the uncertainty | Exploit | Makes the gain certain rather than likely, such as putting the strongest engineers on the finish that unlocks a bonus |
| Transfer | Moves impact and response ownership to a third party, such as insuring the shipment against loss | Share | Gives a partner better placed to capture the gain a stake in it, such as a joint bid with a specialist firm |
| Mitigate | Reduces probability or impact, such as prototyping the risky interface in the first month | Enhance | Raises probability or the size of the gain, such as briefing the regulator early to make the early approval likelier |
| Escalate | Hands a threat outside the project manager's authority to the level that owns it, such as a policy conflict | Escalate | Hands an opportunity beyond the project's remit upward, such as a reusable asset the whole programme could adopt |
| Accept | Takes the threat knowingly, with a contingency reserve or with nothing beyond a documented decision | Accept | Takes the gain if it arrives, without spending anything to pursue it |
Expected monetary value
Expected monetary value puts a single figure on an uncertain outcome by multiplying the probability that it happens by what it would be worth. Threats carry a negative value and opportunities a positive one, so the two can be added together into one number.
| Risk | Probability | Impact if it happens | Expected monetary value |
|---|---|---|---|
| The supplier misses the integration window | 0.30 | £80,000 of extra cost | 0.30 × 80,000 gives £24,000 of exposure |
| The regulator approves early, releasing a bonus | 0.20 | £50,000 of gain | 0.20 × 50,000 gives £10,000 of expected gain |
| The two together | £24,000 less £10,000, so £14,000 of net exposure |
The £14,000 is what would be set aside as contingency reserve for these two risks, and it is also the number that decides what a response is worth. A mitigation that costs £30,000 to halve the supplier risk saves £12,000 of expected exposure and is a poor trade, whereas one costing £5,000 for the same reduction is an obvious one.
The figure has a well known limitation. The supplier either misses the window and costs £80,000, or does not and costs nothing, and £24,000 is a value the project will never actually see. Expected monetary value earns its keep across a portfolio of risks, where the individual outcomes average out, and it misleads whenever a single large risk is treated as though its expected value were the outcome.
Appetite, threshold and reserve
Risk appetite is the degree of uncertainty an organisation will take on in pursuit of a reward, and it is a stance rather than a number. A risk threshold is the measurable level at which that stance becomes a rule, such as a limit on schedule exposure that cannot be accepted without executive approval.
Reserves are how appetite becomes money. Contingency reserve covers identified risks, sits inside the cost baseline, and is spent by the project manager when a planned response triggers. Management reserve covers unknown risks, sits outside the cost baseline but inside the project budget, and needs management approval before it can be used.
Drawing on contingency is an ordinary act of project management, whereas drawing on management reserve is a change to the baseline, and telling which a situation calls for is usually the whole of the decision.
Secondary and residual risk
Every response creates consequences of its own. A secondary risk arises directly from implementing a response, such as the new supplier brought in to reduce a delivery risk bringing its own reliability problem. Secondary risks are identified, analysed and responded to like any other, and neglecting them is how a mitigation makes the position worse.
Residual risk is what remains after a response has been applied. Mitigation reduces exposure rather than eliminating it, and the leftover portion is accepted deliberately and recorded, which is different from having failed to notice it.