Identifying PRINCE2 7 Risk – Part 2
PRINCE2 7 Risk planning
The use of risk categories helps projects to identify and prioritize risks.
Techniques such as PESTLE (political, economic, social, technological, legal, and environmental) analysis and SWOT (strengths, weaknesses, opportunities, threats) analysis can be used to analyse the internal and external context for risks.
These techniques also help to identify different types of risk that may affect the project (for example, sustainability, cybersecurity, or systems integration). An understanding of the types of risks can also help to identify the most appropriate owners.
A key item that needs to be recorded in the risk management approach is the project board’s
attitude towards risk-taking, documented as the risk tolerance. The risk tolerance will be set by the
project board based on the business’ overall risk appetite.
An important aspect of identifying risks is the ability to provide a clear and unambiguous expression
of each risk. A useful way of expressing risk is to consider the following aspects:
risk cause: this should describe the source of the risk, such as the event or situation that causes it. These are often referred to as risk drivers. They are not risks in themselves but are potential trigger points for risk. These may be either internal or external to the project.
risk event: this should describe the area of uncertainty in terms of the threat or the opportunity.
risk effect: this should describe the impact that the risk would have on the project objectives,
should the risk materialize.
The cause, event, and effect relationship could also be expressed as follows:
threat: insufficient staffing capacity (risk cause) could lead to the business being unable to
provide enough staff to complete user training in the planned timescales (risk event), resulting
in the project taking longer than planned (risk effect).
opportunity: if allowable under data regulations, the company could include a discount code
in the email (risk event) when it renews customer details every year (risk cause), generating
income to offset the cost of the regulatory requirement (risk effect).
Differentiating between PRINCE2 risks and impacts

When I’m running risk workshops, one of the first points I clarify for those present, is to identify PRINCE2 Risks, and then to avoid confusion between risks and impacts.
When first asking folks to identify risks, they will often say “there is a risk that the development time will take longer than planned”.
What they are describing here is not the risk itself, but rather, its impact. As such, stating the impact alone is of little use in developing risk analysis and actions. The risks are what may cause the development time to take longer than expected, and this conversation needs to happen first before considering any potential risk responses or actions to take.
Understanding this opens the way to using a very helpful risk analysis technique, which can be helpful in the systematic review of risk.
The Ishikawa or fishbone diagram
As you can see from the diagram below looks a little like the bones of a fish where the bones are the risk categories:

The Ishikawa diagram can also be known as a “cause and effect diagram”. The impact is the effect, and you can systematically look at the causes, that is, the risks that may give that impact.
You can use the chosen risk categories as shown above, or develop your own depending on the nature and environment of the project.
As you can see, this is a hierarchical diagram and is helpful because it takes you systematically through every area of risk and so give structure to this part of your risk analysis. The technique encourages you to think about every area and so helps for and risks that you may not otherwise relies on there.
You can use other techniques for identifying risk in tandem with the above risk checklists and issue diagrams. There are many to consider here, but here are three:
Interviewing
Talk to the executive and other PRINCE2 project board members, team specialists, team managers, external suppliers, and project managers who have manage similar projects in the past.
The Product Flow Diagram (PFD)
It is important to exam and the Product Flow Diagram and for each product box, are asked whether anything made on wrong with its development. One red flag are any external products upon which to project depends. An external product should immediately be considered as a risk.

The risk of an external product may be its delay, the ability of the external team to create a quality product, or if it is an existing product, then its availability. These possibilities are risks.
Prerequisites and constraints
Each of these are also potential risks. A prerequisite is something that must be in place before work can commence – such as a signed and authorized document. A constraint is an external situation that you have no control over and can often impact the scope of the project.
PRINCE2 Risk Workshop
As I’ve mentioned above, running a risk workshop is a smart and efficient way of identifying risks by inviting individuals whose knowledge skills and experience and highlight areas of risks that you may not have thought of.
Even just capturing risk areas of flipchart and potential actions to take to manage them can be very effective. A risk workshop also has a powerful advantage in that key players on the project are already aware of risk because they went to the workshop and joined in the destruction.
This helps greatly with risk ownership and is far more powerful than just reading the risks in the Risk Register later.
My last piece of advice is this, if you really want to pass your PRINCE2 Foundation and Practitioner exams at your first try – and that includes becoming a master of risk management – then you really should join the PRINCE MASTERCLASS
PRINCE2® 7 Foundation and Practitioner


Learn PRINCE2® 7 Foundation and Practitioner Online
** Enhance your PRINCE2 career now **
PRINCE2® Masterclass gives you the skills necessary to manage projects effectively and achieve your objectives.
Get 7 days a week 12 months one to one coaching with ex PRINCE2 examiner Dave Litten.
PRINCE2® is a globally recognized project management framework. By completing both the Foundation and Practitioner courses through our self-paced e-learning, you will develop an understanding of the methodology and learn how to effectively adapt it to any project.
The PRINCE2® 7 Foundation and Practitioner Masterclass is PeopleCert Accredited and guarantees to take you from PRINCE2 Novice to PRINCE2 Practitioner with our famous video learning, study guides and practice exams.
What Does the Masterclass Cover?
The PRINCE2 Foundation examination assesses your knowledge and comprehension of the PRINCE2 project management methodology as detailed in the syllabus. The PRINCE2 Practitioner examination, on the other hand, gauges your ability to apply and tailor the PRINCE2 method. Candidates who pass the Practitioner exam should be able to start implementing the method on an actual project with some guidance. However, their effectiveness may differ based on their experience in project management, the complexity of the project, and the level of support they receive in their work environment.

