8.3 Threat and Opportunity Response Strategies
Key Takeaways
- PRINCE2 7 table 9.1 lists six risk response options that apply to threats and opportunities alike: avoid a threat / exploit an opportunity, reduce a threat / enhance an opportunity, transfer, share, accept, and prepare contingent plans.
- On the threat side: avoid makes the situation certain by removing the risk; reduce (mitigate) changes probability and/or impact now; transfer imparts part of the risk to a third party such as an insurer; share splits pain and gain across the supply chain; accept takes the chance.
- On the opportunity side the same table applies: exploit makes the upside certain, enhance raises its probability or impact, and transfer, share, accept, and prepare contingent plans all work symmetrically — 'reject' was a 6th Edition opportunity response and is not a PRINCE2 7 response option.
- Every risk response must be evaluated for secondary risks (new risks generated directly by implementing the cure) and residual risks (remaining exposure after treatment) to verify net exposure reduction.
- The Risk Owner maintains overarching accountability for managing and monitoring the risk, whereas the Risk Action Owner is tasked with executing specific, assigned response actions under the Risk Owner's oversight.
Threat and Opportunity Response Strategies in PRINCE2 7
Practitioner Core Mandate: Formulating effective risk responses is the operational test of project management leadership. A brilliant risk register filled with sophisticated probability-impact calculations is useless if the project team selects inappropriate, disproportionate, or legally defective response strategies. In PRINCE2 7, responses must treat uncertainty symmetrically—systematically neutralizing negative threats while aggressively pursuing positive opportunities—while vigilantly guarding against secondary risks and upholding strict role segregation.
1. The Symmetrical Response Architecture of PRINCE2 7
PRINCE2 7 sets out six response options in a single table that covers threats and opportunities together. This is a deliberate change from the 6th Edition, which listed separate threat and opportunity lists and included a 'reject' option for opportunities. In Version 7, the same six options are read in two directions — downside and upside — and 'fallback' has been renamed prepare contingent plans:
THE SIX PRINCE2 7 RISK RESPONSE OPTIONS
DOWNSIDE READING (THREAT) UPSIDE READING (OPPORTUNITY)
┌────────────────────────────────┐ ┌────────────────────────────────┐
│ AVOID A THREAT │ ◄──────► │ EXPLOIT AN OPPORTUNITY │
│ Make the situation certain by │ │ Make the situation certain by │
│ removing the risk │ │ implementing the causal factor │
├────────────────────────────────┤ ├────────────────────────────────┤
│ REDUCE A THREAT (mitigate) │ ◄──────► │ ENHANCE AN OPPORTUNITY │
│ Act now to change probability │ │ Act now to make it more likely │
│ and/or impact │ │ or increase its impact │
├────────────────────────────────┴──────────┴────────────────────────────────┤
│ TRANSFER THE RISK — impart part of the risk to a third party. Insurance is │
│ the commonest form. Applies to opportunities too (a third party gains a │
│ cost benefit while the primary risk taker gains another benefit). │
├────────────────────────────────────────────────────────────────────────────┤
│ SHARE THE RISK — multiple parties, typically in a supply chain, share on a │
│ pain/gain share basis. Different in nature from transfer. │
├────────────────────────────────────────────────────────────────────────────┤
│ ACCEPT THE RISK — the business 'takes the chance'. No change to residual │
│ risk and no cost incurred now. Inappropriate above risk tolerance. │
├────────────────────────────────────────────────────────────────────────────┤
│ PREPARE CONTINGENT PLANS — plan but wait to act. Usually paired with │
│ accept, but applies to every other option as a fallback if it fails. │
└────────────────────────────────────────────────────────────────────────────┘
Master Comparison Matrix: The 6 PRINCE2 7 Response Options
| Response option (table 9.1) | Threat reading | Opportunity reading | Operational action | Practical project example |
|---|---|---|---|---|
| Avoid / Exploit | Avoid a threat | Exploit an opportunity | Remove the cause of the threat, or implement the factor that leads to the opportunity, so the situation becomes certain. May cost nothing if achieved by replanning; any cost must be justified. | Cancelling a drone flight over residential areas in favour of ground cameras; adopting a pre-assembled modular bridge to guarantee early toll collection. |
| Reduce / Enhance | Reduce (mitigate) a threat | Enhance an opportunity | Take definite action now to change probability and/or impact. Costs are committed immediately, so they must be justified against the change in residual risk. | Adding redundant power supplies; assigning senior developers to raise the chance of beating a competitor to market. |
| Transfer | Impart part of the threat to a third party; the insured retains impacts on other objectives such as time | Less common, but valid: a third party gains a cost benefit while the project gains another benefit | Insurance, warranties, performance bonds, fixed-price contracts. Some elements of risk can never be transferred. | Builder's risk insurance; a fixed-price vendor contract with penalty clauses. |
| Share | Share downside across the supply chain | Share upside across the supply chain | Pain-share / gain-share arrangements between multiple parties. Distinct in nature from transfer — risks are rarely shared entirely. | A target-cost construction contract splitting overruns or savings 50/50. |
| Accept | Take the chance and manage the full impact if it occurs | Take the chance that the upside occurs | No change to residual risk and no cost incurred now. Not appropriate where exposure exceeds the risk tolerance threshold. | Not hedging currency exposure on a modest foreign-supplier payment. |
| Prepare contingent plans | Plan the fallback if the threat occurs | Plan the standby action if the favourable event occurs | Prepare plans but wait to act. Usually associated with accept, but applies to every option as the fallback when the original response does not work. | Reserving standby diesel generators funded from the risk budget in case grid power fails. |
[!EXAM WATCHPOINT: 'REJECT' IS NOT A PRINCE2 7 RESPONSE] The 6th Edition offered 'reject' as an opportunity response and 'fallback' as a threat response. PRINCE2 7 table 9.1 has neither term: a decision not to pursue an upside is recorded as accept, and fallback planning is prepare contingent plans. Practice material that still lists nine or ten separate responses is testing you on the previous edition.
2. In-Depth Threat Response Strategies
2.1 Avoid
- Mechanism: Changing the project baseline (scope, schedule, technology, procurement method, or approach) so that the threat can never occur. Probability is reduced to zero.
- Application: Best suited for catastrophic or intolerable threats that exceed organizational risk appetite.
- Practitioner Pitfall: Avoidance often requires descoping deliverables or making substantial architectural compromises. Avoidance is not free—it alters the project baseline.
2.2 Reduce (Mitigation)
- Mechanism: Proactive intervention before the risk event occurs to make it less likely, less damaging, or both:
- Reducing Probability (Prevention): Implementing rigorous QA inspections, hiring expert consultants, or running pre-production pilot tests.
- Reducing Impact (Protection): Installing automated fire suppression systems, implementing data encryption, or building flood barrier walls.
2.3 Transfer
- Mechanism: Passing the financial, contractual, or operational consequence of a threat to an external third party.
- Common Vehicles: Insurance policies, third-party warranties, performance bonds, indemnification agreements, and turnkey fixed-price supply contracts.
[!CRITICAL PRACTITIONER RULE: REPUTATIONAL RISK CANNOT BE TRANSFERRED] On the Practitioner exam, remember that while you can transfer financial liability to an insurer or contractor, you can never transfer operational accountability or reputational risk. If an outsourced cloud provider leaks client healthcare records, the insurer pays the fine, but the client organization suffers irreparable brand damage and executive loss of trust.
2.4 Accept
- Mechanism: The business 'takes the chance' that the risk will occur and manages its full impact if it does. There is no change to residual risk, but no cost is incurred now either. Legitimate when the threat sits comfortably within risk tolerance, or when the cost of response exceeds the risk's expected monetary value. PRINCE2 7 states explicitly that accept is not appropriate where exposure exceeds the risk tolerance threshold for the activity in question.
- Practitioner note on framing: where an uncertain event could swing positive or negative (currency movement, for example), PRINCE2 7 treats it as two risks — one leading to loss and one leading to gain — so that a different response can be chosen for each.
- Active Acceptance: Establishing early-warning trigger indicators and monitoring the risk continuously in the Risk Register. If the trigger trips, fallback contingency is deployed.
- Passive Acceptance: Consciously deciding to absorb the impact if it happens, requiring no monitoring or standby resources (appropriate only for negligible, low-impact risks).
2.5 Prepare Contingent Plans
- Mechanism: Preparing plans but waiting to take action. The plan remains dormant until an agreed risk trigger occurs. PRINCE2 7 notes that this option is most usually associated with accept — the risk is accepted for now, but a plan exists for what to do if the situation changes.
- It applies to every other response: a contingent plan is the fallback used when the original response does not work, so it can sit behind avoid, reduce, transfer, and share as well as behind exploit and enhance.
- Funding: Standby contingent plans are typically funded from the Risk Budget.
- Timing Distinction: Unlike reduce (which acts before the event), a contingent plan is executed after the event materializes, to limit damage and restore operations.
3. In-Depth Opportunity Response Strategies
Opportunities represent untapped business value, schedule acceleration, or cost reduction. PRINCE2 7 requires active, aggressive exploitation of upside uncertainty.
OPPORTUNITY RESPONSE DECISION FLOWCHART
Identified Positive Opportunity
│
▼
Can we alter the plan to make the upside CERTAIN?
├──► YES ──► EXPLOIT (Implement the factor that leads to the opportunity)
│
└──► NO ──► Can we proactively INCREASE probability or impact?
├──► YES ──► ENHANCE (Invest resources to maximize upside)
│
└──► NO ──► Can a third party help us capture it?
├──► pain/gain share ──► SHARE
├──► third party gains the cost benefit ──► TRANSFER
│
└──► NO ──► Does the justified cost of pursuit
exceed the value?
├──► YES ──► ACCEPT (take the chance;
│ commit nothing now)
│
└──► NO ──► PREPARE CONTINGENT PLANS
(plan now, act on trigger)
3.1 Exploit
- Mechanism: Taking decisive action to alter the project plan or delivery approach to ensure that the opportunity is guaranteed to happen (probability reaches 1.0 / 100%).
- Example: A municipal railway project discovers that closing a roadway completely for two weeks instead of running rolling lane closures guarantees completion 2 months ahead of schedule. The Project Manager secures road closure permits, altering the baseline to guarantee early completion.
3.2 Enhance
- Mechanism: Taking proactive measures to increase the probability, increase the positive impact, or both, without being able to guarantee 100% realization.
- Example: An e-commerce platform project offers early delivery bonuses to third-party software developers, increasing the likelihood that mobile checkout will be ready before Black Friday.
3.3 Share
- Mechanism: Entering into an agreement with a partner, vendor, or consortium to co-realize and divide an opportunity that neither party could capture independently.
- Example: Partnering with an academic research institute to co-develop proprietary patent algorithms, splitting commercial licensing revenues 50/50.
3.4 Accept (the upside equivalent of the retired 'reject')
- Mechanism: A conscious, documented decision to take the chance on the opportunity without committing money or effort to make it more likely. This is appropriate when the capital expenditure, resource distraction, secondary risks, or strategic misalignment of chasing the opportunity outweigh its prospective benefits.
- Terminology warning: the 6th Edition called this 'reject'. PRINCE2 7 table 9.1 does not contain a 'reject' option, so on the Version 7 paper the correct label for declining to invest in an upside is accept.
4. Secondary Risks, Residual Risks & Net Risk Evaluation
A critical exam competency is evaluating the ripple effects of risk responses.
SECONDARY VS. RESIDUAL RISK DYNAMICS
┌─────────────────────────────────────────────────────────────────────────┐
│ INITIAL THREAT: High Impact Server Overheating ($100k exposure) │
└────────────────────────────────────┬────────────────────────────────────┘
│ Implement Response: Liquid Cooling
▼
┌────────────────────────────────────┴────────────────────────────────────┐
│ │
│ ┌─────────────────────────┐ ┌─────────────────────────┐ │
│ │ RESIDUAL RISK │ │ SECONDARY RISK │ │
│ ├─────────────────────────┤ ├─────────────────────────┤ │
│ │ Remaining thermal risk │ │ NEW risk generated by │ │
│ │ after cooling system │ │ the cure: Coolant leak │ │
│ │ installed: $10k exposure│ │ short-circuits chips │ │
│ └─────────────────────────┘ └─────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────────┘
- Residual Risk: The risk remaining after the response has been implemented. No mitigation reduces risk to zero. The Project Manager must verify that residual risk falls safely within the project's Risk Tolerance.
- Secondary Risk: A brand new risk brought about as a direct result of implementing a risk response. Every proposed response must be examined for secondary risks. If a response creates a secondary risk that is more dangerous than the original threat, the response must be rejected.
- Net Risk Evaluation: Before executing any response, the Project Manager must conduct a net risk equation:
If net exposure increases, the proposed response is economically irrational.
5. Segregation of Execution Duties: Risk Owner vs. Risk Action Owner
PRINCE2 7 establishes strict role boundaries between oversight and execution to maintain accountability:
RISK OVERSIGHT VS. RISK EXECUTION
┌─────────────────────────────────┐ ┌─────────────────────────────────┐
│ RISK OWNER │ │ RISK ACTIONEE │
│ (Strategic Oversight) │ │ (Tactical Execution) │
├─────────────────────────────────┤ ├─────────────────────────────────┤
│ • Named individual accountable │ │ • Named individual tasked with │
│ for managing the risk │ │ executing assigned actions │
│ • Monitors probability, impact, │ │ • Implements tactical steps │
│ and proximity continuously │ │ (e.g., tests, purchases) │
│ • Tracks early warning triggers │ │ • Reports completion & blockers │
│ • Verifies response efficacy │ │ directly to the Risk Owner │
│ • Reports updates to the PM │ │ • Does NOT oversee risk strategy│
└─────────────────────────────────┘ └─────────────────────────────────┘
Practical Comparison Table
| Operational Feature | Risk Owner | Risk Action Owner |
|---|---|---|
| Core Duty | Monitoring risk triggers, assessing status, and ensuring strategy validity | Executing specific, designated response tasks in the plan |
| Accountability | Accountable to the Project Manager for the overall management of the risk | Accountable to the Risk Owner for completing assigned tactical tasks |
| Who Can Fill the Role? | Project Board member, Project Manager, Team Manager, or senior functional lead | Specialist technician, external supplier, team member, or contractor |
| Authority | Directs response adjustments; recommends escalation to the PM | Carries out tasks within assigned operational parameters |
| Can They Be the Same Person? | Yes, on simple risks, a Risk Owner can also execute the action | But for complex or technical risks, duties are segregated |
6. Managing Risks in Agile & Fast-Changing Contexts
In modern delivery environments utilizing Scrum, Kanban, or hybrid delivery, risk management must adapt to high velocity and empirical feedback.
6.1 Agile Risk Mechanisms in PRINCE2 7
- Short Feedback Loops: Rather than relying solely on monthly Highlight Reports, agile teams surface emerging threats and opportunities daily during Daily Standups and sprint reviews.
- Risk-Adjusted Backlog: The product backlog is not prioritized solely by user value; it is prioritized by Value vs. Risk. High-risk, high-uncertainty user stories are pulled into early iterations to fail fast or retire architectural uncertainty early.
- Spikes & Proof-of-Concepts (PoCs): A timeboxed research or prototyping activity designed specifically as a Reduce threat response. A team spends a two-day spike testing a third-party API to determine whether it can support required transaction volumes before committing to development.
- Empirical Retrospectives: At the end of every sprint or timebox, teams conduct retrospectives to identify internal process risks and update team working agreements.
7. Integrating Sustainability, Climate & ESG Risks in PRINCE2 7
A signature enhancement of PRINCE2 7 is embedding Sustainability as the seventh aspect of project performance. Risk management must actively govern environmental, social, and governance (ESG) uncertainties.
SUSTAINABILITY RISK DIMENSIONS IN PRINCE2 7
1. CLIMATE RISK ── Extreme weather disruptions, flood resilience of
assets, and temperature extremes during execution
2. REGULATORY ESG RISK ── Carbon border adjustment taxes, mandatory ESG
disclosure rules, and emission cap penalties
3. SUPPLY CHAIN ETHICS ── Scope 3 supplier carbon emissions, labor standards,
and circular material sourcing integrity
4. ECOLOGICAL FOOTPRINT ── Embodied carbon of materials, water usage, toxic
waste generation, and biodiversity protection
Managing Sustainability Risks in Practice
- Sustainability in the Risk Register: Risks must capture carbon overruns, climate vulnerabilities, and ecological disruption. Example: "Because solar panel manufacturing uses rare earth minerals sourced from high-conflict regions [Cause], there is a risk of supply chain embargoes and ethical audit failures [Event], resulting in severe brand damage and a 4-month project stoppage [Effect]."
- Sustainability Tolerances: The Project Board sets explicit sustainability tolerances (e.g., maximum embodied carbon caps). If a proposed risk response (such as air-freighting replacement parts to avoid schedule delays) causes carbon emissions to breach stage sustainability tolerance, the Project Manager cannot execute the response autonomously. An Exception Report must be submitted to the Project Board.
8. Practical Practitioner Scenario Evaluations
Scenario A: Selecting an Inappropriate Response (Transferring Reputational Risk)
On a smart healthcare records digitization project, a severe threat is identified: "A potential cyber-breach of patient medical histories could expose confidential data and result in $5,000,000 in regulatory fines." The Project Manager purchases a $10,000,000 comprehensive cyber-insurance policy and records the response strategy as Transfer. The Project Manager then reduces cloud security testing hours to save budget, arguing that because financial liability is 100% transferred to the insurance provider, the project is completely protected.
Practitioner Evaluation:
- Governance Flaw: The Project Manager committed a fatal error by assuming that purchasing insurance completely transfers operational and reputational risk.
- Impact: While insurance transfers financial loss, it cannot transfer legal accountability, regulatory sanctions, or devastating brand damage. Weakening security testing to rely on insurance represents reckless management that destroys Continued Business Justification.
- Correct PRINCE2 Action: Insurance must only serve as a secondary financial fallback. The primary response must be Reduce (investing in rigorous penetration testing, zero-trust architecture, and data encryption) to prevent the breach from occurring in the first place.
Scenario B: Failing to Identify a Critical Secondary Risk
To eliminate the threat of supply delays for specialized prefabricated steel trusses on a sports arena project, the Project Manager changes the procurement plan from domestic maritime shipping to chartered cargo air freight (Response: Reduce). However, the Project Manager fails to analyze the downstream effects of this decision. When the steel is flown in, the local municipal airport lacks cargo cranes capable of offloading the 30-ton crates, leaving the aircraft grounded, incurring $50,000 per day in demurrage fines, and causing Stage 2 carbon emissions to exceed the approved sustainability tolerance by 40%.
Practitioner Evaluation:
- Governance Flaw: The Project Manager failed to evaluate Secondary Risks and neglected sustainability performance targets.
- Impact: The response successfully addressed the primary shipping delay threat, but generated catastrophic secondary risks (airport lifting incapacity and severe carbon tolerance breach) that cost far more than the original shipping delay.
- Correct PRINCE2 Action: Before authorizing the cargo air freight response, the Project Manager was obligated to evaluate secondary operational constraints and calculate the carbon footprint impact. If the secondary risk threatens stage tolerances, an Exception Report or alternative response strategy is required.
Scenario C: Exploiting an Opportunity that Destabilizes Project Tolerances
During Stage 3 of a commercial banking portal build, the software supplier identifies an opportunity: incorporating a newly released biometric authentication plugin will increase user security satisfaction by 50%. The supplier estimates the integration will cost $40,000 and take 3 weeks. The approved stage tolerances are ±$15,000 and ±1 week. Enthusiastic about the benefit, the Project Manager immediately instructs the supplier to implement the plugin, recording the strategy as Exploit.
Practitioner Evaluation:
- Governance Flaw: The Project Manager breached the Manage by Exception principle while pursuing an opportunity.
- Impact: Opportunities cannot be exploited at the expense of unauthorized tolerance breaches. Spending $40,000 and adding 3 weeks exceeds the Project Manager's delegated stage tolerances (±$15,000 / ±1 week).
- Correct PRINCE2 Action: While the opportunity offers substantial business value, capturing it requires an Exception Report to the Project Board. Only the Project Board holds the authority to approve an Exception Plan or increase stage tolerances to exploit an opportunity that exceeds delegated limits.
9. Practitioner Exam Pitfalls & Governance Traps
- Trap 1: Believing Insurance Eliminates Risk: Transferring financial liability via insurance or warranties does not transfer reputational, operational, or legal accountability. Exam options that suggest insurance absolves the team of prevention are traps.
- Trap 2: Forgetting Secondary Risks: Every response must be screened for secondary risks. The exam frequently tests whether candidates recognize that a proposed mitigation creates an even deadlier secondary problem.
- Trap 3: Unilateral Tolerance Breaches to Exploit Opportunities: You cannot breach stage time or cost tolerances to exploit an opportunity without Project Board approval. If capturing an opportunity breaches tolerance, an Exception Report is mandatory.
- Trap 4: Confusing Enhance with Exploit: Exploit makes the situation certain by implementing the factor that leads to the opportunity. Enhance merely increases the probability or impact through proactive measures without making the outcome certain.
- Trap 4b: Answering with 6th Edition response names: distractors built on 'reject' or 'fallback' are testing whether you know PRINCE2 7 table 9.1. The six current options are avoid/exploit, reduce/enhance, transfer, share, accept, and prepare contingent plans.
- Trap 5: Conflating Risk Owner with Risk Action Owner: The Risk Owner oversees, monitors, and evaluates the risk's control strategy. The Risk Action Owner performs the operational task. The Risk Action Owner cannot be held accountable for risk monitoring.
A municipal highway project involves constructing an overpass above an electrified railway line. A major threat is identified: 'Crane operations during live rail traffic may strike overhead catenary lines, causing electrocution, rail network shutdown, and tens of millions in contractual penalties.' The contractor offers to purchase an insurance policy covering up to $50 million in rail disruption damages. However, the Project Manager decides instead to reschedule all heavy crane lifting exclusively during pre-planned night-time rail possession windows when train service is suspended and the overhead electric power is turned off and grounded. What response strategy has the Project Manager implemented, and why is this superior to insurance in this context?
During the development of a next-generation medical diagnostic imaging device, the engineering team discovers that a newly released optical sensor from an existing supplier would increase image resolution by 40% with no additional hardware cost. However, utilizing the sensor requires redesigning the internal optical mount, which would cost $35,000 and extend the current development stage by two weeks. The approved stage tolerances are ±$50,000 and ±3 weeks. After verifying that the enhanced resolution will double projected market sales, the Project Manager modifies the design specification and authorizes the redesign. Which opportunity response has been implemented?
On a cloud infrastructure migration project, the Project Manager identifies a threat that the primary data center could experience prolonged power outages. The Project Manager selects a Reduce response: install an automatic failover standby diesel generator system. The Project Manager assigns the Lead Facilities Engineer as the Risk Owner and an external electrical subcontractor as the Risk Action Owner. Before purchasing the generator, the Lead Facilities Engineer points out that storing 10,000 liters of diesel fuel on-site creates a new threat: potential chemical soil contamination and local environmental regulatory fines if storage tanks leak. Under PRINCE2 7, how should the team treat this new fuel leakage threat, and what is the Risk Owner's responsibility?