The risk management process
A risk is an uncertain event that, if it happens, affects a project objective such as time, cost, scope or quality. It can be a threat (negative) or an opportunity (positive). Risk management is a repeating process, not a one-off exercise.
| Step | What you do | Output |
|---|---|---|
| 1. Plan | Decide how risk will be managed, who is responsible and how risks are scored | Risk management plan |
| 2. Identify | Find risks using brainstorming, checklists, interviews, lessons from earlier projects, and the WBS | Risk register entries |
| 3. Analyze (qualitative) | Rate probability and impact and rank risks | Prioritized register |
| 4. Analyze (quantitative) | Estimate the numerical effect of the top risks | Expected monetary values, contingency |
| 5. Plan responses | Decide actions for each important risk | Response plan with owners |
| 6. Implement and monitor | Carry out responses, watch triggers, find new risks, review regularly | Updated register and reports |
Identifying risks well
Many students list generic risks such as delays and budget overruns. Better risks are specific and written as cause, event and effect: because the vendor is relying on a single supplier (cause), delivery of the servers may slip (event), which would delay testing by two weeks (effect).
To make sure you cover the ground, use a risk breakdown structure (RBS), which groups risks by source.
| Category | Example risks |
|---|---|
| Technical | New technology does not work as expected; integration problems |
| External | Supplier delay; regulation change; weather |
| Organizational | Key staff leave; competing priorities; unclear sponsorship |
| Project management | Poor estimates; scope creep; weak communication |
| Commercial | Price rises; customer changes requirements; budget cuts |
Walk through your WBS and ask what could go wrong with each work package, which finds risks that a general brainstorm misses.
Scoring probability and impact
A qualitative assessment scores each risk on probability and impact, usually from 1 (very low) to 5 (very high). Multiply the two to give a score from 1 to 25, then rank.
| Score | Probability | Impact on schedule (example scale) | Impact on cost (example scale) |
|---|---|---|---|
| 1 | Very unlikely, below 10 percent | Less than one day | Less than $2,000 |
| 2 | Unlikely, 10 to 30 percent | 1 to 3 days | $2,000 to $10,000 |
| 3 | Possible, 30 to 50 percent | 3 to 7 days | $10,000 to $25,000 |
| 4 | Likely, 50 to 70 percent | 1 to 2 weeks | $25,000 to $50,000 |
| 5 | Very likely, above 70 percent | More than 2 weeks | More than $50,000 |
| Score range | Rating | Typical action |
|---|---|---|
| 1 to 6 | Low | Accept and monitor |
| 8 to 12 | Medium | Plan a response and assign an owner |
| 15 to 25 | High | Immediate action and senior attention |
Agree the scale at the start and write it in the risk management plan, because without defined scales, scores are just opinions. In a project risk matrix, these scores are plotted on a grid of probability against impact, with red, amber and green zones.
A worked risk register
Here is a short register for the customer portal project from our guide on charters and work breakdown structures. The risks and figures are hypothetical.
| ID | Risk (cause, event, effect) | P | I | Score | Response | Owner |
|---|---|---|---|---|---|---|
| R1 | Scope creep: stakeholders request extra features, adding work and delaying launch | 4 | 4 | 16 | Mitigate: change control process and sponsor sign-off on any scope change | Project manager |
| R2 | Key developer leaves, so the integration stalls | 3 | 4 | 12 | Mitigate: pair programming, documentation; identify a backup | Development lead |
| R3 | User adoption is low, so call volume does not fall | 3 | 4 | 12 | Mitigate: early user testing, in-app prompts, staff scripts pointing to the portal | Business analyst |
| R4 | Vendor delivers hosting late, delaying testing | 4 | 3 | 12 | Transfer: penalty clause in contract; start a fallback environment | Procurement |
| R5 | Data migration errors corrupt order records | 2 | 5 | 10 | Avoid: run migrations on a copy and verify before cutover | Data lead |
| R6 | Budget overrun from underestimated integration work | 3 | 3 | 9 | Mitigate: include contingency; monthly cost review | Project manager |
Each row includes a cause, an event and an effect, a score, a response strategy and a named owner. A good register also records a trigger (the early warning sign), the status and the date of the last review.
Choosing a response
| Strategy | For threats | For opportunities | Example |
|---|---|---|---|
| Avoid / Exploit | Change the plan to remove the risk | Make sure the opportunity happens | Drop a risky feature; assign the best staff to a promising task |
| Mitigate / Enhance | Reduce probability or impact | Increase probability or impact | Extra testing; training that raises adoption |
| Transfer / Share | Move impact to a third party | Share the benefit with a partner | Insurance, fixed-price contract; joint venture |
| Accept | Do nothing now, with or without a contingency | Take the benefit if it occurs | Accept a small risk and hold a reserve |
Responses should be proportionate. Spending $20,000 to reduce a risk worth $5,000 makes no sense. Also consider residual risk (what remains after the response) and secondary risk (new risk created by the response, such as a fixed-price contract that a vendor later disputes).
Working on this assignment now? Get a price for help with your paper.
Get an instant quoteQuantitative analysis: expected monetary value
For the most important risks, estimate the money at stake. Expected monetary value (EMV) is probability multiplied by impact. Summing EMVs gives a rough guide to the contingency reserve you need.
| Risk | Probability | Cost impact | EMV |
|---|---|---|---|
| R1 Scope creep | 50 percent | $30,000 | $15,000 |
| R2 Developer leaves | 30 percent | $40,000 | $12,000 |
| R3 Low adoption | 30 percent | $25,000 | $7,500 |
| R4 Vendor delay | 40 percent | $15,000 | $6,000 |
| R5 Data migration errors | 20 percent | $60,000 | $12,000 |
| R6 Budget overrun | 30 percent | $20,000 | $6,000 |
| Total expected value of risks | $58,500 |
The total of $58,500 is a starting point for setting the contingency reserve, which covers identified risks and is controlled by the project manager. A separate management reserve, held by the sponsor, covers unidentified risks. Remember that summing EMVs assumes risks are independent and that actual costs will be either zero or the full impact, not the average. Mention these limits, and explain that techniques such as decision trees and Monte Carlo simulation give a fuller picture.
Keeping the register alive
| Activity | Frequency | Output |
|---|---|---|
| Review top risks in the team meeting | Weekly | Status, new triggers, actions due |
| Update scores and responses | Every two weeks | Revised register |
| Report to the sponsor | Monthly | Top five risks, trend, decisions needed |
| Close or retire risks | As the phase ends | Closed list with lessons |
Track risk burndown: the total of risk scores each month. If the sum of the top ten scores falls from 112 to 84 to 61, mitigation is working; a flat line means actions are not being done.
Risk appetite and thresholds
Organizations differ in how much risk they accept. A plan should state thresholds, such as: any risk scoring 15 or above goes to the sponsor within two days; any risk with a cost impact above $50,000 needs sponsor approval for its response. Without thresholds, escalation is a matter of mood.
Writing the risk management plan
The plan describes the approach, not the individual risks. Typical contents are listed below.
- Methodology Process, tools and data sources.
- Roles and responsibilities Who identifies, assesses, owns and reports risks.
- Scoring definitions The probability and impact scales and the thresholds for low, medium and high.
- Risk categories The RBS used to group risks.
- Reporting and review How often risks are reviewed and who sees the reports.
- Budget and schedule for risk work Time and reserve set aside.
- Escalation When and how to raise a risk to the sponsor.
In agile projects, risks are reviewed at planning and retrospective meetings, and the backlog is reprioritized as risks change. Whichever approach your assignment assumes, say how the register stays alive. If you want help building a register or plan, you can order project management assignment help.