5.1 Risk Practice & Risk Management Approach
Key Takeaways
- PRINCE2 7 defines risk as an uncertain event or set of events that, should it occur, will have an effect on the achievement of project objectives.
- The Risk practice addresses both negative threats (to be avoided, mitigated, transferred, shared, or accepted) and positive opportunities (to be exploited, enhanced, shared, or rejected).
- The 5-step PRINCE2 Risk Procedure follows a continuous cycle: Identify, Assess, Plan, Implement, and Communicate.
- Risk Cause, Event, and Effect must be clearly distinguished in the Risk Register using the standard syntax: 'Because of [cause], [event] may occur, leading to [effect]'.
- The Risk Budget is a dedicated financial allocation set aside by the Executive specifically to fund agreed risk responses.
5.1 Risk Practice & Risk Management Approach
Every project is an endeavor that introduces organizational change, operates under constraints, and deals with uncertainty. In PRINCE2 7, the Risk Practice provides the structured framework required to identify, assess, and control uncertainty, thereby increasing the project's probability of success while safeguarding business investment.
PRINCE2 7 Definition: A risk is an uncertain event or set of events that, should it occur, will have an effect on the achievement of objectives. Risks are measured by a combination of the probability of a perceived threat or opportunity occurring and the magnitude of its impact on objectives.
Notice that PRINCE2 explicitly defines risk to encompass both negative outcomes (threats) and positive possibilities (opportunities). Effective risk management is not merely defensive; it actively identifies upside opportunities that can enhance value, reduce delivery time, or lower costs.
The Concept of Risk: Threat vs. Opportunity
In project environments, uncertainty manifests in two distinct directions:
- Threats: Uncertain events that would have an adverse impact on project objectives (e.g., key supplier insolvency, regulatory delays, technical failures).
- Opportunities: Uncertain events that would have a favorable impact on project objectives (e.g., favorable currency fluctuations, early vendor component availability, emerging digital automation tools).
| Attribute | Threat Management | Opportunity Management |
|---|---|---|
| Focus | Minimize downside loss and delay | Maximize upside value and efficiency |
| Goal | Protect baseline targets (cost, time, quality, scope) | Exceed baseline targets or lower baseline investment |
| Primary Responses | Avoid, Mitigate, Transfer, Share, Accept, Contingency | Exploit, Enhance, Share, Reject, Contingency |
| Financial Impact | Potential cost overrun or delay | Potential cost savings or accelerated delivery |
Risk Cause, Event, and Effect Syntax
A critical requirement in PRINCE2 risk management is maintaining a clear distinction between the cause, the risk event, and the effect. Conflating these three elements leads to vague risk statements and ineffective response strategies.
To ensure precision, PRINCE2 recommends the standard three-part risk statement structure:
- Risk Cause: Existing facts, conditions, or environmental factors that create uncertainty (e.g., "Because the development team is using a newly released third-party API...").
- Risk Event: The specific uncertain occurrence that may happen (e.g., "...the API integration may experience unexpected latency and authentication errors...").
- Risk Effect: The direct impact on project performance targets if the risk event occurs (e.g., "...leading to a 3-week delay in stage testing and an additional $25,000 in refactoring costs.").
The Risk Management Approach
The Risk Management Approach is a foundational management product created during the Initiating a Project process. It defines how risk management will be conducted specifically for the project, establishing the procedures, techniques, roles, responsibilities, scales, and reporting frequencies.
Key Components of the Risk Management Approach
- Procedure: The specific steps to be followed (conforming to the PRINCE2 5-step risk procedure).
- Tools and Techniques: Risk identification techniques (e.g., PESTLE, SWOT, risk breakdown structures, industry checklists) and assessment methods.
- Scales & Matrix: Standardized scales for measuring Probability (e.g., Very Low to Very High) and Impact (monetary, time, quality), along with a Risk Severity Matrix.
- Proximity Definitions: Categories for when the risk might occur (e.g., Immediate, Near-term, Far-term).
- Risk Tolerance Limits: Explicit thresholds established by the Project Board beyond which risks must be escalated.
- Risk Budget Governance: Rules for allocating and accessing the project Risk Budget.
The 5-Step PRINCE2 Risk Procedure
PRINCE2 defines a continuous, iterative 5-step risk management procedure executed throughout the project lifecycle:
[Step 1: Identify] ──> [Step 2: Assess] ──> [Step 3: Plan] ──> [Step 4: Implement] ──> [Step 5: Communicate]
▲ │
└───────────────────────────────── Continuous Cycle ───────────────────────────────────┘
Step 1: Identify (Context & Risks)
- Identify Context: Understand the project environment, business objectives, stakeholder risk appetites, and risk management policies.
- Identify Risks: Capture potential threats and opportunities using brainstorming, prompt lists (PESTLE), lessons logs, and risk breakdown structures. Express every risk using the Cause-Event-Effect format and record it in the Risk Register.
Step 2: Assess (Estimate & Evaluate)
- Estimate: Determine the probability, impact, and proximity of each individual risk. Evaluate the net impact before and after proposed risk responses.
- Evaluate: Assess the combined risk exposure for the stage and project. Compare aggregate risk exposure against the risk tolerance thresholds set by the Project Board.
Step 3: Plan (Select Strategies)
Select the appropriate response strategy for each identified threat or opportunity. Formulate secondary measures, calculate response costs, and ensure responses are proportional to the risk severity.
Step 4: Implement (Assign Ownership & Action)
Ensure selected responses are planned and assigned to specific individuals:
- Risk Owner: An individual designated to monitor the risk and take overall responsibility for its management.
- Risk Actionee: An individual nominated to execute the specific risk response action under the direction of the Risk Owner.
Step 5: Communicate (Ongoing Reporting)
Risk information must flow continuously across all project governance levels. Risk status, emerging threats, and changes in probability/impact are communicated through Highlight Reports, Checkpoint Reports, and End Stage Reports.
Threat & Opportunity Response Strategies
PRINCE2 7 specifies distinct response categories for threats and opportunities:
Threat Responses
- Avoid: Remove the risk cause or redesign the project so the threat can no longer occur (e.g., choosing a proven vendor instead of an unverified startup).
- Mitigate (Reduce): Take proactive action to reduce the probability of occurrence, the severity of impact, or both (e.g., conducting additional automated testing to lower defect rates).
- Transfer: Pass the financial impact of the threat to a third party (e.g., purchasing insurance, incorporating penalty clauses in supplier contracts).
- Share: Partner with an external entity to share the risk exposure proportionally (e.g., establishing a joint venture).
- Accept: Decide not to take action in advance, absorbing the impact if the threat occurs because mitigation cost exceeds the potential loss.
- Contingency: Formulate a pre-planned response to be executed only if the threat occurs (often backed by a contingency budget).
Opportunity Responses
- Exploit: Take action to ensure the opportunity definitely happens (100% probability) to secure its benefits.
- Enhance: Take action to increase the probability of occurrence or increase the scale of positive impact.
- Share: Work with a third party to capture an opportunity that neither organization could realize alone.
- Reject (Ignore): Decide not to pursue the opportunity because the cost or effort of capture outweighs the benefit.
- Contingency: Plan actions to capitalize on the opportunity if specific trigger events occur.
The Risk Budget
PRINCE2 7 Definition: A Risk Budget is a sum of money allocated by the Executive and included in the project budget to fund specific responses to identified risks (threats or opportunities).
Key Risk Budget Rules:
- Dedicated Purpose: It must not be used to absorb general cost overruns, scope creep, or unbudgeted design changes.
- Executive Governance: Access to the Risk Budget is controlled strictly in accordance with rules set out in the Risk Management Approach.
- Ring-Fenced Funding: If no risks materialize, the unused Risk Budget is returned to corporate/programme management upon project closure.
Which of the following represents the correct PRINCE2 7 standard statement structure for logging a risk?
A project team purchases insurance to cover potential equipment damage during ocean transport. Which threat response strategy is being implemented?
What is the primary purpose of a Risk Budget in a PRINCE2 project?