21.3 Proactive and Reactive Risk Responses

Key Takeaways

  • Threat responses are avoid, reduce, transfer, and accept; opportunity responses mirror them as exploit, enhance, share, and reject.
  • Avoid removes the exposure entirely, usually by changing the approach; reduce lowers probability or impact without eliminating it.
  • Transfer moves the financial consequence to another party through insurance or contract, but it does not remove the project’s accountability for the outcome.
  • Residual risk is what remains after a response has been applied; secondary risk is new risk introduced by the response itself.
  • Accepting a risk is a legitimate, deliberate decision when the cost of response exceeds the exposure — provided it is recorded and contingency is held where appropriate.
Last updated: August 2026

Outcome 23c names eight responses in two sets: for threats, avoid, reduce, transfer or accept; for opportunities, exploit, enhance, share or reject. Learn them as matched pairs — the opportunity set mirrors the threat set — and be ready to justify a choice against a scenario rather than simply listing all eight.

Proactive and Reactive Responses

Once risks are identified and analysed, the project must respond. The syllabus distinguishes proactive and reactive approaches:

  • Proactive responses act now to change the probability and/or impact of a risk before it occurs (or to make an opportunity more likely / more valuable).
  • Reactive (contingent) responses are pre-planned actions that run if a trigger occurs — fallback plans, contingency draw-down, and issue-style recovery.

Both are legitimate. Mature plans often combine them: reduce probability proactively, and hold a contingent response plus contingency reserve for residual exposure. Doing nothing until crisis is not a professional "accept" decision unless acceptance was conscious, documented, and within risk appetite.

Threat Response Strategies

For threats (negative uncertain events), standard strategies are avoid, reduce, transfer, accept.

StrategyIntentTypical actionsExample
AvoidRemove the threat by changing the plan so the risk cannot occur (or cannot affect objectives)Descope, change method, choose different supplier/route, remove dependencyCancel night-time roof work in storm season; redesign to eliminate a hazardous process
ReduceLower probability and/or impact to an acceptable levelExtra testing, training, dual path, early trials, quality gates, buffersCross-train a second engineer before commissioning; prototype a high-risk interface early
TransferShift ownership of impact (often commercial/insurance) to a party better able to manage itContract clauses, insurance, performance bonds, outsourcing a specialist packageFixed-price package for well-defined works; professional indemnity for design risk
AcceptConsciously retain the threat because treatment is not cost-effective or possibleDocument residual risk; set monitoring triggers; fund contingency; escalate if neededAccept low-probability force-majeure residual after insurance and contractual treatment

Important nuances

  • Transfer does not delete risk for the project. Reputation, benefits delay, and stakeholder impact often remain with the organisation even if cost risk sits with a supplier.
  • Accept is active governance, not silence. Passive hope is unmanaged risk.
  • Avoid may cost scope or time; the sponsor must agree if business value changes.
  • Reduce (sometimes called mitigation in other guides) is the most common day-to-day strategy and should be proportionate to exposure.

Scenario — threat responses compared

A data centre cutover faces a threat that power failover testing fails on the night of go-live.

  • Avoid: delay go-live until a full parallel run in a non-live window is completed (plan change).
  • Reduce: run partial failover tests weekly; add monitoring; rehearse rollback.
  • Transfer: contract a specialist facilities firm with liquidated damages for test failure (cost impact partly commercial — service downtime risk may remain).
  • Accept: if residual probability is low after reduce, hold a contingent rollback plan and time contingency; monitor trigger metrics.

Opportunity Response Strategies

Risk management also pursues opportunities (positive uncertain events). Strategies: exploit, enhance, share, reject.

StrategyIntentTypical actionsExample
ExploitMake the opportunity certain (or as certain as practical)Assign best resources, re-plan to capture it, secure commitmentsSecure exclusive early access to a shared tool and plan its use so early finish becomes the baseline path
EnhanceIncrease probability and/or positive impactInvest in enablers, early engagement, partial pilotsFund a short spike that improves chance of regulatory fast-track approval
ShareAllocate opportunity to a party best able to capture it, often with gain-sharePartnering, joint ventures, incentivised contractsTarget-cost contract with share of savings if early completion increases benefit
RejectConsciously not pursue the opportunityDocument decision; free capacity for higher prioritiesDecline optional feature that distracts from critical path benefits

Exam trap: Managing only threats. APM treats opportunities as part of risk management; long-response answers that ignore upside miss marks when the scenario offers a clear positive uncertainty.

Scenario — opportunity

Another programme will free a test environment two weeks early. Exploit by resequencing testing and booking the environment immediately. Enhance by adding a small integration team to maximise use of the window. Share by co-funding environment support with the other programme under a memorandum that both gain schedule. Reject if using it would pull critical staff off a regulatory deadline with higher strategic value.

Residual Risk and Secondary Risk

Every serious response leaves a trail that examiners love to test.

ConceptMeaningManagement implication
Residual riskExposure remaining after planned responsesMust be re-analysed, accepted within appetite, covered by contingency/monitoring, or escalated
Secondary riskA new risk created by implementing a responseMust be identified, analysed, and treated like any other risk

Example: Transferring ground-risk to a contractor via fixed price may leave residual programme risk if disputes delay the site, and create a secondary risk of adversarial claims behaviour if the specification is ambiguous. Reducing schedule risk by crashing work may create secondary quality and safety risks.

Always close the loop: response → residual assessment → secondary scan → update register → report if residual exceeds tolerance.

Contingency in Response Planning

Contingency is the practical companion of accept and of residual risk after reduce/transfer.

  • Size contingency from analysis (not gut feel alone).
  • Link draw-down to triggers and owners.
  • Report use so boards see whether residual risk is crystallising.
  • Distinguish contingency for identified risks from management reserve or pure estimating allowance where the organisation uses those terms.
  • When contingency is exhausted, that is a governance signal: re-analyse exposure, re-plan, or escalate — do not hide overruns in unrelated budgets.
Test Your Knowledge

A project faces a threat that a single scarce specialist may be unavailable at commissioning. Which action best illustrates a reduce response?

A
B
C
D
Test Your Knowledge

A risk workshop finds a chance to finish a work package early if another team shares a new tool. Which opportunity response best fits making the positive outcome as certain as practical?

A
B
C
D