8.4 Risk 5-Step Technique & Application

Key Takeaways

  • The v7 risk technique is a five-step cycle: identify, assess, plan, implement, and communicate — communication is woven through the cycle, not a final stage.
  • Threat responses are avoid, reduce, transfer, accept, share, and prepare; opportunity responses are exploit, enhance, share, accept, and reject — the response sets differ and must not be conflated.
  • The Risk Owner is accountable for managing a specific risk; the Risk Actionee executes the agreed response — the roles may be combined but are conceptually distinct.
  • For small or low-risk projects, risk management is tailored down: a lighter Risk Management Approach, simpler assessment scales, and fewer formal responses, while keeping the five-step discipline.
Last updated: August 2026

The Five-Step Risk Technique

PRINCE2 v7 structures risk management as a five-step technique. The steps are not strictly linear — communication in particular runs through the whole cycle — but they provide a disciplined sequence for thinking about each risk.

Step 1 — Identify

Identify the risks worth managing, along with their causes, events, and effects. Techniques include risk workshops, checklists, prompt lists, brainstorming, lessons from previous projects, and review of the project's assumptions. The output is a populated Risk Register (or v7 Project Log) with each risk expressed as a cause-event-effect statement. Identification also surfaces the risk categories defined in the Risk Management Approach, ensuring the team does not fixate on one category (e.g. technical) and miss another (e.g. commercial).

Step 2 — Assess

Assess each identified risk in two stages. Estimate the probability, impact, and proximity — these are the raw numerical or qualitative judgements. Then evaluate the net effect on objectives, taking account of any correlations between risks (one risk may amplify or dampen another). The output is a prioritised view of risks, typically expressed through a probability-impact grid and a net effect summary, that informs which risks warrant planned responses and which can be monitored.

Step 3 — Plan

For each risk that exceeds the project's risk tolerance, select an appropriate risk response and assign a Risk Owner (and, where appropriate, a Risk Actionee). Planning also includes estimating the cost of responses, updating the risk budget, and revising the project plan where responses change the schedule or scope. A risk with no planned response is accepted by default — but that acceptance should be explicit, not accidental.

Step 4 — Implement

Execute the agreed responses and monitor their effectiveness. Implementation is not a one-off action: risks evolve, proximity changes, new risks emerge, and responses sometimes fail. The Risk Owner tracks status and triggers escalation when a risk moves outside tolerance. Implementation feeds back into Steps 1 and 2 — re-identify and re-assess as the project changes.

Step 5 — Communicate

Communicate risk status to stakeholders throughout the cycle — not as a final report but as an ongoing stream. Communication includes risk reports to the Project Board at end-stage boundaries, highlight reports during stages, and ad-hoc escalation when a risk breaches tolerance. Communication is the step most often underdone in practice and one of the most frequently tested in scenarios.

Risk Responses: Threats vs Opportunities

The response sets for threats and opportunities are different. Conflating them is a high-frequency exam error. The table below sets out the full v7 response sets.

Threat responseWhat it doesOpportunity responseWhat it does
AvoidChange the plan to remove the cause or eventExploitChange the plan to make the opportunity happen
ReduceReduce probability and/or impactEnhanceIncrease probability and/or impact
TransferShift the impact to a third party (e.g. insurance, fixed-price contract)ShareShare the opportunity with a partner who can help realise it
AcceptTake no action; tolerate the risk within toleranceAcceptTake no action; tolerate the opportunity not being realised
ShareShare the threat with a partner who can absorb part of itRejectDecide not to pursue the opportunity (e.g. out of scope)
PreparePlan a contingency response to be triggered if the risk occurs(opportunities do not have a direct 'prepare' equivalent)

A reliable mnemonic: threats are avoided, reduced, transferred, accepted, shared, or prepared for; opportunities are exploited, enhanced, shared, accepted, or rejected. Note that share appears in both sets but with different intent — sharing a threat spreads a potential loss; sharing an opportunity spreads a potential gain.

A common scenario shape describes a situation and asks you to choose the best response. The key is to identify whether the scenario describes a threat or an opportunity first, then match the response verb to the action being taken. 'Taking out insurance' is transfer; 'choosing a different supplier to remove the risk' is avoid; 'adding a contingency fund in case the risk occurs' is prepare (a threat) — not accept, because a planned contingency is a form of preparation.

Risk Owner vs Risk Actionee

The Risk Owner is the person accountable for managing a specific risk — they decide on the response, monitor the risk, and report its status. The Risk Actionee is the person who executes the agreed response action on the owner's behalf. The two roles may be held by the same individual, but they are conceptually separate: ownership is about accountability, actionee-ship is about execution. A scenario that describes someone 'responsible for carrying out the agreed mitigation' is describing the Risk Actionee; a scenario that describes someone 'accountable for the risk and its overall management' is describing the Risk Owner.

Tailoring for Small Projects

Risk management must be proportionate. For a small or low-risk project, PRINCE2 expects the technique to be tailored down, not abandoned:

  • A lighter Risk Management Approach — perhaps a single page defining categories, tolerance, and reporting frequency.
  • Simpler assessment scales — e.g. high/medium/low rather than a five-point scale.
  • Fewer formal responses — many low-priority risks can simply be monitored.
  • Combined roles — the PM may act as Risk Owner for most risks.
  • The five-step discipline is retained — identify, assess, plan, implement, communicate — even if each step is lightweight.

A scenario that asks how to apply risk management to a small project is testing whether you understand that tailoring simplifies the mechanics while preserving the discipline. Dropping a step entirely is not tailoring — it is neglect.

Exam Scenario Patterns

  • Choosing the right response. Identify threat vs opportunity first, then match the response verb to the action. Watch for 'prepare' (a threat-only response involving a contingency plan) and 'reject' (an opportunity-only response involving a deliberate decision not to pursue).
  • Sequencing the five steps. A scenario describes an activity; map it to identify / assess / plan / implement / communicate. Remember that communicate runs throughout.
  • Risk Owner vs Risk Actionee. Look for the words 'accountable' (owner) versus 'carries out' or 'executes' (actionee).
  • Tailoring. A small-project scenario that asks for appropriate risk management expects a simplified but complete application of the five-step technique, not its removal.
Test Your Knowledge

A project identifies a chance that a new technology could deliver a key feature earlier than planned, saving four weeks of schedule. The Project Manager decides to deliberately change the plan to make this benefit happen. Which opportunity response is being applied?

A
B
C
D
Test Your Knowledge

A risk has been identified and a response selected. One person is accountable for the risk overall, including monitoring and reporting its status; another person will carry out the agreed mitigation actions. Which term describes the second person?

A
B
C
D
Test Your Knowledge

A small, low-risk internal project is being set up. Which approach to risk management best reflects PRINCE2 v7 tailoring?

A
B
C
D