Taking a simplistic definition of risk; “an event that has yet to happen, it may or may not happen at some point in the future, but if it does it will have an impact on my project”, you may be fooled into thinking that risk management is hard. But you would be wrong!
Many projects fail due to poor risk management which is totally unnecessary as there is a very logical and straightforward approach to the management of risks within a PRINCE2 project.
By taking the mindset “what could possibly go wrong with my project” making a list of such situations, and then working out how to either prevent or minimize the risk (at a minimum just to control it), would greatly reduce the number of failed projects.
Performing risk management will protect your project and prevents or controls situations that would have as a minimum, caused problems, and at a maximum, potentially ruin the project.
PRINCE2 includes a well documented risk tpractice that covers all potential project and organisational risks.
A definition of risk is “the adverse consequences of future events” but this only assumes that a risk is some form of negative threat to the project objectives, whereas in fact, a risk may also give rise to a positive outcome and this is called an opportunity.
In keeping with this fact, PRINCE2 now defines risk as “an uncertain event or set of events that, should it occur, would have an effect on the achievement of objectives”.
The first step in the risk management is to develop the risk management approach so that you clearly understand how risks will be handled during the project. This is the project risk “how-to” document!
The risk management approach is part of the project initiation documentation, and its purpose is to describe how risk will be managed on the project. This includes the specific procedures, techniques, standards, and responsibilities to be applied.
As part of tailoring PRINCE2 7 according to the individual project risk environment, the risk management approach will define your risk approach for a particular project and this forms part of the project initiation documentation created within the initiation stage.
As part of managing risk, responses for each risk will be determined, and such responses will require actions and resources to carry them out. Therefore risk management does not come free but instead needs to be budgeted for accordingly. This is called the risk budget.
The risk budget has several advantages as it makes clear what portion of the project funding will be put aside for each risk, and since this budget forms part of the whole project budget, then the project manager already has the authority to use it.
The key management tool used here is the risk register which provides a record of all identified risks within the project and includes their status and history.
PRINCE2 7 Risk Management model.
PRINCE2 has a procedural based risk management model consisting of four elements, with a fifth element called ‘communicate’ which works in parallel with the previous four:

Since PRINCE2 projects are the mechanisms for change, and therefore will always include risk aspects when changing from the old to the new ways of working, they must use risk management in order to be successful. More precisely, risk is really uncertainty and it is this that must be managed.
In the context of PRINCE2 project it is the project objectives that are at risk, and it is important to establish and maintain a cost effective risk management procedure.
To perform effective risk management we need to understand risk causes, the probability, there impact and timing, and select a suitable response or set of responses for each risk. Care should be taken not to spend more avoiding the risk than the impact of the risk itself.
Risk management starts at the very beginning of PRINCE2 and is a continual activity carried out throughout the life of the project, without this, it would not be possible to have the confidence that the project is able to meet its objectives and should therefore be continued.
In other words, risk management threatens the Business Case and hence the continued business justification principle.
A simple way of describing a risk is, an event which may or may not occur at some point in the future, but if it does occur it will have an impact on the project objectives.
There are two types of risk; those with a negative impact and those with a positive impact: risks which have a negative impact are called threats and those with a positive impact are called opportunities – both have the common characteristic of uncertainty.
A risk management system is one which first identifies risks and then assesses them, followed by the planning and implementation of risk responses.
Having been first identified (usually done in a risk or planning workshop), in terms of their impact, and timing, the overall of risk associated with the project often called the aggregated risk, needs to be understood and agreed by the project board for effective risk management within PRINCE2.
Each risk will now need an appropriate response followed by the assignment of a risk owner, and then monitoring and controlling (and hence risk management) of those responses.
In the Starting up the Project process, the project manager will use the Daily Log to capture and manage any known risks; these will be used as part of the evidence put before the project board to decide whether or not to proceed.
In the initiation stage The Risk Management Approach will be created to describe how risk management will be embedded within the project. At the same time, The Risk Register will be created and any risks currently within the Daily Log will now be transferred to this register.
Using The Project Brief and the Project Product Description, The Risk Management Strategy will include the following information: the risk management procedure to be applied including tools and techniques to be used, records, reporting and timing of risk management activities, risk responsibilities, risk tolerances and a risk budget if it is to be used.
One aspect to consider here is the project board’s attitude towards risk taking as this will influence the amount of risk that is acceptable and the most effective responses required.
The Risk Register is a project management tool used to contain information on all of the identified threats and opportunities within a project.
It will contain information such as the category and description of the risk, its probability, impact and expected value, its proximity and risk responses, its current status and the risk owner. Project support will normally maintain this for the project manager.
It is vital that risks are clearly and unambiguously described, and it is useful to consider each risk in terms of the risk cause (the source of the risk), the risk event describing the area of uncertainty, and the risk effect describing the impact of the risk should it occur.
The Risk Management Approach structure
Scope: description of the scope of the risk management approach
Risk management procedures: description of project’s risk management activities (for example, identify,
assess, plan, implement, communicate) (Any variation from business standards should be highlighted,
together with justification for any variation.)
Risk tolerance guidance: provides additional guidance to the risk tolerance levels defined for the project in the business case
Timing of risk management activities: states when formal risk management activities are to be undertaken (such as at the end of a stage)
Responsibilities: defines responsibilities for risk management activities (This should include responsibilities for risk owners and risk action owners.)
Resources: for the risk management activities, for example, any testing equipment required
Supporting tools and techniques: for the risk management activities, including any systems will be used
and how, and any specific techniques such as pre-mortems
Standards: any standards that apply to risk management such as the grading system used for rating
probability, impact, proximity, and velocity (The standards should also specify the composition and format
of the risk register and other risk records.)
References: for any associated documents or products, for example, the business’ or supplier’s risk
management systems.
Click here: for more information on Passing Your PRINCE2 Exam!
PRINCE2® 7 Foundation and Practitioner


Learn PRINCE2® 7 Foundation and Practitioner Online
** Enhance your PRINCE2 career now **
PRINCE2® Masterclass gives you the skills necessary to manage projects effectively and achieve your objectives.
Get 7 days a week 12 months one to one coaching with ex PRINCE2 examiner Dave Litten.
PRINCE2® is a globally recognized project management framework. By completing both the Foundation and Practitioner courses through our self-paced e-learning, you will develop an understanding of the methodology and learn how to effectively adapt it to any project.
The PRINCE2® 7 Foundation and Practitioner Masterclass is PeopleCert Accredited and guarantees to take you from PRINCE2 Novice to PRINCE2 Practitioner with our famous video learning, study guides and practice exams.
What Does the Masterclass Cover?
The PRINCE2 Foundation examination assesses your knowledge and comprehension of the PRINCE2 project management methodology as detailed in the syllabus. The PRINCE2 Practitioner examination, on the other hand, gauges your ability to apply and tailor the PRINCE2 method. Candidates who pass the Practitioner exam should be able to start implementing the method on an actual project with some guidance. However, their effectiveness may differ based on their experience in project management, the complexity of the project, and the level of support they receive in their work environment.

