21.3 Proactive and Reactive Risk Responses
Key Takeaways
- Threat responses are avoid, reduce, transfer, and accept; opportunity responses mirror them as exploit, enhance, share, and reject.
- Avoid removes the exposure entirely, usually by changing the approach; reduce lowers probability or impact without eliminating it.
- Transfer moves the financial consequence to another party through insurance or contract, but it does not remove the project’s accountability for the outcome.
- Residual risk is what remains after a response has been applied; secondary risk is new risk introduced by the response itself.
- Accepting a risk is a legitimate, deliberate decision when the cost of response exceeds the exposure — provided it is recorded and contingency is held where appropriate.
Outcome 23c names eight responses in two sets: for threats, avoid, reduce, transfer or accept; for opportunities, exploit, enhance, share or reject. Learn them as matched pairs — the opportunity set mirrors the threat set — and be ready to justify a choice against a scenario rather than simply listing all eight.
Proactive and Reactive Responses
Once risks are identified and analysed, the project must respond. The syllabus distinguishes proactive and reactive approaches:
- Proactive responses act now to change the probability and/or impact of a risk before it occurs (or to make an opportunity more likely / more valuable).
- Reactive (contingent) responses are pre-planned actions that run if a trigger occurs — fallback plans, contingency draw-down, and issue-style recovery.
Both are legitimate. Mature plans often combine them: reduce probability proactively, and hold a contingent response plus contingency reserve for residual exposure. Doing nothing until crisis is not a professional "accept" decision unless acceptance was conscious, documented, and within risk appetite.
Threat Response Strategies
For threats (negative uncertain events), standard strategies are avoid, reduce, transfer, accept.
| Strategy | Intent | Typical actions | Example |
|---|---|---|---|
| Avoid | Remove the threat by changing the plan so the risk cannot occur (or cannot affect objectives) | Descope, change method, choose different supplier/route, remove dependency | Cancel night-time roof work in storm season; redesign to eliminate a hazardous process |
| Reduce | Lower probability and/or impact to an acceptable level | Extra testing, training, dual path, early trials, quality gates, buffers | Cross-train a second engineer before commissioning; prototype a high-risk interface early |
| Transfer | Shift ownership of impact (often commercial/insurance) to a party better able to manage it | Contract clauses, insurance, performance bonds, outsourcing a specialist package | Fixed-price package for well-defined works; professional indemnity for design risk |
| Accept | Consciously retain the threat because treatment is not cost-effective or possible | Document residual risk; set monitoring triggers; fund contingency; escalate if needed | Accept low-probability force-majeure residual after insurance and contractual treatment |
Important nuances
- Transfer does not delete risk for the project. Reputation, benefits delay, and stakeholder impact often remain with the organisation even if cost risk sits with a supplier.
- Accept is active governance, not silence. Passive hope is unmanaged risk.
- Avoid may cost scope or time; the sponsor must agree if business value changes.
- Reduce (sometimes called mitigation in other guides) is the most common day-to-day strategy and should be proportionate to exposure.
Scenario — threat responses compared
A data centre cutover faces a threat that power failover testing fails on the night of go-live.
- Avoid: delay go-live until a full parallel run in a non-live window is completed (plan change).
- Reduce: run partial failover tests weekly; add monitoring; rehearse rollback.
- Transfer: contract a specialist facilities firm with liquidated damages for test failure (cost impact partly commercial — service downtime risk may remain).
- Accept: if residual probability is low after reduce, hold a contingent rollback plan and time contingency; monitor trigger metrics.
Opportunity Response Strategies
Risk management also pursues opportunities (positive uncertain events). Strategies: exploit, enhance, share, reject.
| Strategy | Intent | Typical actions | Example |
|---|---|---|---|
| Exploit | Make the opportunity certain (or as certain as practical) | Assign best resources, re-plan to capture it, secure commitments | Secure exclusive early access to a shared tool and plan its use so early finish becomes the baseline path |
| Enhance | Increase probability and/or positive impact | Invest in enablers, early engagement, partial pilots | Fund a short spike that improves chance of regulatory fast-track approval |
| Share | Allocate opportunity to a party best able to capture it, often with gain-share | Partnering, joint ventures, incentivised contracts | Target-cost contract with share of savings if early completion increases benefit |
| Reject | Consciously not pursue the opportunity | Document decision; free capacity for higher priorities | Decline optional feature that distracts from critical path benefits |
Exam trap: Managing only threats. APM treats opportunities as part of risk management; long-response answers that ignore upside miss marks when the scenario offers a clear positive uncertainty.
Scenario — opportunity
Another programme will free a test environment two weeks early. Exploit by resequencing testing and booking the environment immediately. Enhance by adding a small integration team to maximise use of the window. Share by co-funding environment support with the other programme under a memorandum that both gain schedule. Reject if using it would pull critical staff off a regulatory deadline with higher strategic value.
Residual Risk and Secondary Risk
Every serious response leaves a trail that examiners love to test.
| Concept | Meaning | Management implication |
|---|---|---|
| Residual risk | Exposure remaining after planned responses | Must be re-analysed, accepted within appetite, covered by contingency/monitoring, or escalated |
| Secondary risk | A new risk created by implementing a response | Must be identified, analysed, and treated like any other risk |
Example: Transferring ground-risk to a contractor via fixed price may leave residual programme risk if disputes delay the site, and create a secondary risk of adversarial claims behaviour if the specification is ambiguous. Reducing schedule risk by crashing work may create secondary quality and safety risks.
Always close the loop: response → residual assessment → secondary scan → update register → report if residual exceeds tolerance.
Contingency in Response Planning
Contingency is the practical companion of accept and of residual risk after reduce/transfer.
- Size contingency from analysis (not gut feel alone).
- Link draw-down to triggers and owners.
- Report use so boards see whether residual risk is crystallising.
- Distinguish contingency for identified risks from management reserve or pure estimating allowance where the organisation uses those terms.
- When contingency is exhausted, that is a governance signal: re-analyse exposure, re-plan, or escalate — do not hide overruns in unrelated budgets.
A project faces a threat that a single scarce specialist may be unavailable at commissioning. Which action best illustrates a reduce response?
A risk workshop finds a chance to finish a work package early if another team shares a new tool. Which opportunity response best fits making the positive outcome as certain as practical?