21.4 Governance in Risk and Issue Management

Key Takeaways

  • Governance sets the risk appetite and tolerances that determine which exposures may be accepted and which must be escalated.
  • Responses cost money and time, so someone with authority must fund them — a register without funded responses is a list of concerns.
  • Escalation only works if it reaches a body that can actually decide, which is a governance design question rather than a reporting one.
  • Independent challenge and assurance stop registers drifting towards optimism, where probabilities are quietly reduced rather than managed.
  • Transferring risk to a supplier under contract does not remove the need for governance — the organisation retains the consequence of failure even where the cost sits elsewhere.
Last updated: August 2026

Outcome 23d is a single line — understand why governance is important in risk and issue management — and it is the outcome that ties this objective back to Chapter 3. Risk management without governance produces a well-maintained register that changes nothing.

Why Governance Matters in Risk and Issue Management

Governance is the framework of authority and accountability. Without it, risk and issue management becomes a private list on the project manager’s laptop. With it, exposure is controlled in line with organisational risk appetite, delegated authority, and strategic objectives.

Risk governance building blocks

ElementRole in control
Risk appetiteHow much risk the organisation is willing to take in pursuit of objectives; sets what is acceptable residual exposure
Risk ownersIndividuals accountable for managing specific risks and responses (not always the project manager for every risk)
Project managerIntegrates risk process, maintains visibility, ensures responses are planned and monitored within tolerances
Sponsor / boardSet appetite context, decide escalated risks, approve contingency beyond PM limits, judge business-case impact
Escalation thresholdsClear rules for when residual risk or issues must go upward
ReportingRegular risk/issue status to the level that can act — exception-based for boards
AssuranceIndependent check that the process is real, not theatre
Link to change controlResponses and issues that alter baselines follow controlled change

Escalation and reporting to the board

Escalate when:

  • Residual threat exceeds appetite or project tolerances (time, cost, benefits, safety, compliance).
  • A response requires authority above the project manager (funding, major descope, contractual transfer).
  • An issue blocks progress and cannot be resolved at team level.
  • Opportunity pursuit would reallocate scarce enterprise resources or change strategic priorities.
  • Contingency draw-down rules require sponsor/board approval.

Good escalation is timely, evidence-based, and option-led: description, impact on objectives and business case, residual exposure, options with pros/cons, recommendation, and decision needed by when. Poor escalation is late, problem-only, or used to dump routine decisions that sit inside the PM’s authority.

Board reporting should highlight top risks and issues, trend (improving/worsening), residual vs appetite, contingency status, and decisions required — not every low-priority register line.

Issue governance

Issues need equal discipline:

  1. Single log with severity and age (aged issues are a governance smell).
  2. Analysis of impact on objectives, compliance, and stakeholders.
  3. Action owners with deadlines and completion criteria.
  4. Escalation when blockers need senior organisational power (resource priority, supplier default, regulatory interface).
  5. Decision record when the resolution accepts residual damage or triggers change control.
  6. Closure only when actions complete or residual risk is formally accepted and owned.

Scenario — governance in action

A rail signalling project faces a high residual safety-related threat after reduce and transfer responses. Contingency can fund extra testing, but the residual still sits near organisational appetite for passenger-service risk. The project manager must not quietly accept that exposure. Correct path: update analysis, present residual risk and options (delay go-live, further reduce, additional independent assurance), escalate to sponsor and board, obtain a decision aligned to appetite and legal duties, then implement and monitor. That is governance creating safe value — not slowing the project for sport.

Scenario — issue governance

A key interface supplier stops work over a payment dispute. This is an issue. Log and analyse impact on critical path and benefits. Assign commercial and technical actions. If resolution exceeds financial authority or threatens the business case, escalate to the sponsor/board with options (settle, replace supplier, re-sequence). Parallel risks (further insolvency, quality rush after restart) stay under risk owners. Without issue governance, email threads replace decisions and the critical path erodes silently.

Common Exam Traps

  • Treating transfer as zero residual risk for the organisation.
  • Confusing accept with ignoring the risk.
  • Forgetting opportunities and their four strategies.
  • Ignoring secondary risk created by crashing, outsourcing, or insurance structures.
  • Assuming iterative teams need no escalation or appetite control.
  • Reporting every risk equally instead of exception-based board focus.
  • Closing issues when people are tired of them, not when actions are done.

Answer Pattern for Long-Response Questions

  1. Classify threat/opportunity or issue.
  2. Select a response strategy and justify it against objectives and appetite.
  3. State residual and any secondary risk.
  4. Name owner, monitoring/trigger, and contingency if relevant.
  5. State what escalates to sponsor/board and why governance requires it.

That structure covers LO23(c)–(d): proactive/reactive responses for threats and opportunities, and why governance — appetite, ownership, escalation, and reporting — makes risk and issue management real.

Test Your Knowledge

After transferring a package of work to a supplier under a fixed-price contract, why is risk governance still required?

A
B
C
D