Free PMI-RMP Exam Flashcards
Memorize 50 essential terms and definitions for the PMI Risk Management Professional (PMI-RMP). See the term, recall the definition, then flip to check yourself.
Risk (PMI definition)
An uncertain event or condition that, if it occurs, has a positive or negative effect on one or more project objectives. Risk includes both threats (downside) and opportunities (upside).
Filter by Topic
Jump to Card
About These PMI-RMP Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the PMI Risk Management Professional (PMI-RMP). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
Risk (PMI definition)
An uncertain event or condition that, if it occurs, has a positive or negative effect on one or more project objectives. Risk includes both threats (downside) and opportunities (upside).
Threat vs Opportunity
A threat is a risk with a negative effect on objectives; an opportunity is a risk with a positive effect. PMI manages both — each has its own set of five response strategies.
Individual risk vs Overall project risk
An individual risk is a single uncertain event affecting one or more objectives. Overall project risk is the cumulative effect of all uncertainty on the project as a whole, including its exposure to variation.
Risk appetite
The degree of uncertainty an organization is willing to accept in anticipation of a reward. It is a high-level, strategic attitude — broader than tolerance or threshold.
Risk tolerance vs Risk threshold
Tolerance is the range of acceptable variation around an objective. A threshold is a specific measurable trigger point that, once crossed, forces action. Tolerance is a band; threshold is a line.
Risk Management Plan
Defines HOW risk will be managed: methodology, roles, budgeting, timing, risk categories, probability/impact definitions, and reporting formats. It does NOT list the actual risks.
Risk Register vs Risk Report
The Risk Register records individual risks (description, owner, response, status). The Risk Report summarizes sources of overall project risk and the big-picture exposure. Register = detail; Report = summary.
Risk Breakdown Structure (RBS)
A hierarchical, categorized list of potential risk sources used to organize identification (e.g., technical, management, commercial, external). It groups risks by source, not by work package like the WBS.
Risk owner vs Risk action owner
The risk owner is accountable for monitoring a risk and ensuring its response works. A risk action owner carries out a specific assigned response action. Owner oversees; action owner executes.
Why engage stakeholders in risk management?
Stakeholders supply risk information, hold differing risk attitudes, and own or are affected by responses. Engaging them aligns risk thresholds, surfaces hidden risks, and secures buy-in for response actions.
Stakeholder risk attitude factors
Risk attitude is shaped by risk appetite, tolerance, threshold, and individual perception. Differing attitudes among stakeholders must be reconciled so the project applies consistent risk criteria.
Risk communication purpose
Targeted, timely risk communication keeps stakeholders informed of exposure and response status, manages expectations, and prevents surprises. The Risk Report is the primary vehicle for overall-risk communication.
Delphi technique
An anonymous, iterative expert-survey method used to build consensus and identify risks while avoiding groupthink and dominant-personality bias. Responses are aggregated and fed back across rounds.
SWOT analysis in risk identification
Examines Strengths, Weaknesses, Opportunities, and Threats. Strengths/opportunities surface upside risks; weaknesses/threats surface downside risks. It deliberately captures both threats and opportunities.
Ishikawa (fishbone / cause-and-effect) diagram
A root-cause technique that traces an effect back to contributing causes grouped by category. Used to find the underlying drivers of risks rather than just symptoms.
Assumption and constraint analysis
Tests the validity of project assumptions and explores constraints to surface risks. Invalid or unstable assumptions and tight constraints are common sources of threats.
Prompt lists
Predetermined category lists (e.g., PESTLE, TECOP, RBS, VUCA) used to stimulate risk identification so that whole categories of risk are not overlooked.
Risk trigger (warning sign)
An indicator or symptom showing that a risk is about to occur or has occurred, prompting the response. Triggers are identified early and monitored throughout the project.
Qualitative risk analysis
Prioritizes individual risks by subjectively assessing probability and impact (often via a probability-impact matrix). It is fast and ranks risks; it does NOT produce numeric cost/schedule outcomes.
Probability and Impact (P-I) matrix
A grid that multiplies probability rating by impact rating to score and rank each risk into priority zones (e.g., red/yellow/green). It is the core qualitative prioritization tool.
Risk score (qualitative)
Probability × Impact, using the rating scales defined in the risk management plan. Higher scores get prioritized for detailed analysis or response; it is relative, not a dollar figure.
Other qualitative parameters beyond P-I
Risks can also be assessed by urgency, proximity, manageability, detectability, connectivity, dormancy, and strategic impact. These help refine prioritization beyond probability and impact alone.
Risk categorization (qualitative)
Grouping risks by source (RBS), affected area (WBS), root cause, or project phase to reveal concentrations of exposure and target responses more efficiently.
Quantitative risk analysis
Numerically analyzes the combined effect of risks on overall project objectives (cost/schedule), producing ranges and probabilities. It is optional, resource-intensive, and follows qualitative analysis.
Monte Carlo simulation
Runs thousands of iterations with random sampling from input distributions to model overall cost/schedule outcomes. Produces an S-curve showing the probability of meeting any given target.
Sensitivity analysis / Tornado diagram
Identifies which individual risks or variables have the greatest impact on the project outcome. The tornado diagram ranks them with the most influential bar at the top.
Three-point estimate (PERT)
Uses optimistic (O), most likely (M), and pessimistic (P) values to model uncertainty. Triangular mean = (O+M+P)/3; Beta/PERT mean = (O+4M+P)/6, weighting the most likely value.
Expected Monetary Value (EMV)
EMV = Probability × Impact (in currency). Threats are negative, opportunities positive. Summed across a branch, EMV gives the weighted-average value used to compare decision options.
EMV worked example
A risk with 20% probability and a $50,000 loss has an EMV of −$10,000 (0.20 × −50,000). A 30% chance of a $40,000 gain has an EMV of +$12,000. Net EMV here = +$2,000.
Decision tree analysis
A diagram that evaluates choices under uncertainty by computing EMV down each branch (cost of decision plus probability-weighted outcomes). You select the path with the most favorable EMV.
Contingency reserve vs Management reserve
Contingency reserve covers KNOWN risks (identified, with responses) and is controlled by the project manager within the cost baseline. Management reserve covers UNKNOWN risks, sits outside the baseline, and needs management approval to use.
How is contingency reserve sized?
Typically from the EMV of known risks or from quantitative analysis (e.g., Monte Carlo at a chosen confidence level). It funds planned contingency/fallback responses, not unforeseen events.
Cost/schedule baseline vs reserves
Cost baseline = work estimates + contingency reserve. Total budget = cost baseline + management reserve. Management reserve is in the budget but NOT the baseline, so consuming it changes the baseline.
Five threat (negative) response strategies
Escalate, Avoid, Transfer, Mitigate, Accept. Avoid eliminates the cause; Transfer shifts impact to a third party; Mitigate reduces probability/impact; Accept takes no proactive action.
Five opportunity (positive) response strategies
Escalate, Exploit, Share, Enhance, Accept. Exploit makes the opportunity certain; Share allocates it to a partner best able to capture it; Enhance increases probability/impact; Accept takes it if it arises.
Escalate (response strategy)
Used for threats OR opportunities outside the project's authority/scope. Ownership is handed to program/portfolio level; the risk is then removed from the project's active register and monitored elsewhere.
Transfer vs Share
Transfer moves a THREAT's impact (and ownership of response) to a third party, usually for a premium (insurance, warranties, contracts). Share allocates an OPPORTUNITY to a partner better able to capture it (partnerships, joint ventures).
Mitigate vs Enhance
Mitigate reduces the probability and/or impact of a THREAT. Enhance increases the probability and/or impact of an OPPORTUNITY. They are mirror-image proactive strategies.
Active vs Passive acceptance
Active acceptance establishes a contingency reserve (time, money, resources) to handle the risk if it occurs. Passive acceptance takes no action beyond documenting and periodically reviewing the risk.
Secondary risk vs Residual risk
A secondary risk is a NEW risk created by implementing a response. A residual risk is the LEFTOVER risk that remains after the response is applied. New from the fix vs. what's still left.
Contingency plan vs Fallback plan
A contingency plan (Plan A) executes when a risk's trigger fires. A fallback plan (Plan B) is held in reserve for when the contingency plan fails or the risk exceeds tolerance.
Workaround
An unplanned response to an UNIDENTIFIED risk (or a residual risk) that has already occurred. Unlike a contingency plan, it is not prepared in advance — it is improvised during execution.
Risk audit vs Risk review
A risk audit evaluates the EFFECTIVENESS of the risk management process and responses. A risk review reassesses existing risks, closes outdated ones, and identifies new risks. Audit = process; review = the risks themselves.
Reserve analysis (monitoring)
Compares the amount of contingency/management reserve remaining against the amount of risk remaining, to confirm reserves are still adequate as the project progresses.
Risk reassessment
A recurring activity that identifies new risks, reassesses current ones, and closes risks that are obsolete. It keeps the risk register current as project conditions change.
Risk closure
A risk is closed when it can no longer occur or its response is fully complete (it occurred and was handled, or the window passed). Closed risks are archived with notes for lessons learned.
Variance and trend analysis in risk monitoring
Reviews cost/schedule performance trends (e.g., earned value variances) to forecast emerging risk exposure. Worsening trends can signal that overall project risk is increasing.
Key Risk Indicators (KRIs) vs triggers
A KRI is a metric tracked over time to signal changing risk exposure (leading indicator). A trigger is the specific point that signals a particular risk is occurring. KRIs trend; triggers fire.
Lessons learned (risk)
Captured throughout and at closure, lessons document what risks occurred, how effective responses were, and what to repeat or avoid. They feed organizational process assets for future projects.
Specialized risk analyses across approaches (predictive vs agile/hybrid)
Predictive projects emphasize up-front quantitative analysis and reserves. Agile/hybrid handles risk iteratively — backlog reprioritization, short feedback loops, and frequent reassessment reduce exposure as work proceeds.
Frequently Asked Questions
How many questions are on the PMI-RMP exam?
The PMI-RMP exam has 115 questions: 100 scored and 15 unscored pretest items, delivered in a mix of multiple-choice and multiple-response formats. You have 150 minutes (2.5 hours) to complete it, with two optional 10-minute breaks. The exam is administered through Pearson VUE at test centers and via online proctoring.
What is the passing score for the PMI-RMP exam?
PMI uses a pass/fail result based on a psychometrically scaled score, not a fixed percentage. PMI does not publish an official passing percentage or pass rate for the PMI-RMP; widely cited prep estimates place the effective threshold around 65-70%, but treat that only as a study target. Your score report shows performance bands (Above Target, Target, Below Target, Needs Improvement) per domain rather than a raw percentage.
What are the PMI-RMP exam domains and their weights?
The current PMI-RMP Exam Content Outline organizes the test into five domains: Risk Strategy and Planning, Stakeholder Engagement, Risk Process Facilitation, Risk Monitoring and Reporting, and Performing Specialized Risk Analyses. Questions are spread across these domains, with analysis and response planning representing the heaviest application-focused content. Master both qualitative and quantitative techniques.
What are the prerequisites for the PMI-RMP exam?
There are two eligibility paths. Path 1: a secondary degree (high school diploma or equivalent) plus 36 months of project risk management experience within the last five years and 40 hours of project risk management education. Path 2: a four-year degree plus 24 months of experience within the last five years and 30 hours of education. You must also follow the PMI Code of Ethics.
How long should I study for the PMI-RMP exam?
Most candidates need 100-150 hours of study over 8-12 weeks. Prioritize quantitative analysis (EMV, decision trees, Monte Carlo simulation) and the ten risk response strategies, since these application-heavy topics challenge most test-takers. PMI lets you attempt the exam up to three times within your one-year eligibility period; after three failures you must wait one year to reapply.
Explore More PMI Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.