8.4 Risk 5-Step Technique & Application
Key Takeaways
- The v7 risk technique is a five-step cycle: identify, assess, plan, implement, and communicate — communication is woven through the cycle, not a final stage.
- Threat responses are avoid, reduce, transfer, accept, share, and prepare; opportunity responses are exploit, enhance, share, accept, and reject — the response sets differ and must not be conflated.
- The Risk Owner is accountable for managing a specific risk; the Risk Actionee executes the agreed response — the roles may be combined but are conceptually distinct.
- For small or low-risk projects, risk management is tailored down: a lighter Risk Management Approach, simpler assessment scales, and fewer formal responses, while keeping the five-step discipline.
The Five-Step Risk Technique
PRINCE2 v7 structures risk management as a five-step technique. The steps are not strictly linear — communication in particular runs through the whole cycle — but they provide a disciplined sequence for thinking about each risk.
Step 1 — Identify
Identify the risks worth managing, along with their causes, events, and effects. Techniques include risk workshops, checklists, prompt lists, brainstorming, lessons from previous projects, and review of the project's assumptions. The output is a populated Risk Register (or v7 Project Log) with each risk expressed as a cause-event-effect statement. Identification also surfaces the risk categories defined in the Risk Management Approach, ensuring the team does not fixate on one category (e.g. technical) and miss another (e.g. commercial).
Step 2 — Assess
Assess each identified risk in two stages. Estimate the probability, impact, and proximity — these are the raw numerical or qualitative judgements. Then evaluate the net effect on objectives, taking account of any correlations between risks (one risk may amplify or dampen another). The output is a prioritised view of risks, typically expressed through a probability-impact grid and a net effect summary, that informs which risks warrant planned responses and which can be monitored.
Step 3 — Plan
For each risk that exceeds the project's risk tolerance, select an appropriate risk response and assign a Risk Owner (and, where appropriate, a Risk Actionee). Planning also includes estimating the cost of responses, updating the risk budget, and revising the project plan where responses change the schedule or scope. A risk with no planned response is accepted by default — but that acceptance should be explicit, not accidental.
Step 4 — Implement
Execute the agreed responses and monitor their effectiveness. Implementation is not a one-off action: risks evolve, proximity changes, new risks emerge, and responses sometimes fail. The Risk Owner tracks status and triggers escalation when a risk moves outside tolerance. Implementation feeds back into Steps 1 and 2 — re-identify and re-assess as the project changes.
Step 5 — Communicate
Communicate risk status to stakeholders throughout the cycle — not as a final report but as an ongoing stream. Communication includes risk reports to the Project Board at end-stage boundaries, highlight reports during stages, and ad-hoc escalation when a risk breaches tolerance. Communication is the step most often underdone in practice and one of the most frequently tested in scenarios.
Risk Responses: Threats vs Opportunities
The response sets for threats and opportunities are different. Conflating them is a high-frequency exam error. The table below sets out the full v7 response sets.
| Threat response | What it does | Opportunity response | What it does |
|---|---|---|---|
| Avoid | Change the plan to remove the cause or event | Exploit | Change the plan to make the opportunity happen |
| Reduce | Reduce probability and/or impact | Enhance | Increase probability and/or impact |
| Transfer | Shift the impact to a third party (e.g. insurance, fixed-price contract) | Share | Share the opportunity with a partner who can help realise it |
| Accept | Take no action; tolerate the risk within tolerance | Accept | Take no action; tolerate the opportunity not being realised |
| Share | Share the threat with a partner who can absorb part of it | Reject | Decide not to pursue the opportunity (e.g. out of scope) |
| Prepare | Plan a contingency response to be triggered if the risk occurs | — | (opportunities do not have a direct 'prepare' equivalent) |
A reliable mnemonic: threats are avoided, reduced, transferred, accepted, shared, or prepared for; opportunities are exploited, enhanced, shared, accepted, or rejected. Note that share appears in both sets but with different intent — sharing a threat spreads a potential loss; sharing an opportunity spreads a potential gain.
A common scenario shape describes a situation and asks you to choose the best response. The key is to identify whether the scenario describes a threat or an opportunity first, then match the response verb to the action being taken. 'Taking out insurance' is transfer; 'choosing a different supplier to remove the risk' is avoid; 'adding a contingency fund in case the risk occurs' is prepare (a threat) — not accept, because a planned contingency is a form of preparation.
Risk Owner vs Risk Actionee
The Risk Owner is the person accountable for managing a specific risk — they decide on the response, monitor the risk, and report its status. The Risk Actionee is the person who executes the agreed response action on the owner's behalf. The two roles may be held by the same individual, but they are conceptually separate: ownership is about accountability, actionee-ship is about execution. A scenario that describes someone 'responsible for carrying out the agreed mitigation' is describing the Risk Actionee; a scenario that describes someone 'accountable for the risk and its overall management' is describing the Risk Owner.
Tailoring for Small Projects
Risk management must be proportionate. For a small or low-risk project, PRINCE2 expects the technique to be tailored down, not abandoned:
- A lighter Risk Management Approach — perhaps a single page defining categories, tolerance, and reporting frequency.
- Simpler assessment scales — e.g. high/medium/low rather than a five-point scale.
- Fewer formal responses — many low-priority risks can simply be monitored.
- Combined roles — the PM may act as Risk Owner for most risks.
- The five-step discipline is retained — identify, assess, plan, implement, communicate — even if each step is lightweight.
A scenario that asks how to apply risk management to a small project is testing whether you understand that tailoring simplifies the mechanics while preserving the discipline. Dropping a step entirely is not tailoring — it is neglect.
Exam Scenario Patterns
- Choosing the right response. Identify threat vs opportunity first, then match the response verb to the action. Watch for 'prepare' (a threat-only response involving a contingency plan) and 'reject' (an opportunity-only response involving a deliberate decision not to pursue).
- Sequencing the five steps. A scenario describes an activity; map it to identify / assess / plan / implement / communicate. Remember that communicate runs throughout.
- Risk Owner vs Risk Actionee. Look for the words 'accountable' (owner) versus 'carries out' or 'executes' (actionee).
- Tailoring. A small-project scenario that asks for appropriate risk management expects a simplified but complete application of the five-step technique, not its removal.
A project identifies a chance that a new technology could deliver a key feature earlier than planned, saving four weeks of schedule. The Project Manager decides to deliberately change the plan to make this benefit happen. Which opportunity response is being applied?
A risk has been identified and a response selected. One person is accountable for the risk overall, including monitoring and reporting its status; another person will carry out the agreed mitigation actions. Which term describes the second person?
A small, low-risk internal project is being set up. Which approach to risk management best reflects PRINCE2 v7 tailoring?