Applying the PRINCE2 risk practice

Organizational context
A project may need to align its approach to risk management with organizational, programme, or portfolio policies, standards, or approaches.
This might include:
- Aligning with any centrally defined risk management policies, standards, and approaches
- Using any centrally defined risk management techniques
- Adopting any centrally deployed tools
- Aligning with any centrally defined risk management roles or competency frameworks
- Aligning with any industry or sector-specific policies, standards or approaches, for example, health and safety.
Organizations often require that a consistent, mandated process be used across different projects, typically to ensure that they can assess the business’s overall risk exposure across projects.
If a project is part of a programme, the risk management approach should identify the types of risk that will be managed at the project level.
The risk tolerance should show when risks must be escalated to the programme for further action.
Commercial context
In a commercial context, there may be a need for more than one risk register. Some project risks may be unique to only one party, which may have good reasons for not making the risk register visible to the other party.
When a joint risk register is used, care should be taken to establish whose risk it is, and the risk owner should be appointed accordingly.
For example, on a fixed-price contract, any cost overruns will impact the supplier’s business case, but timescale overruns will typically impact the customer’s business case.
It is important to assess the context in which a project exists, including the environment and working relationships, to adapt and tailor PRINCE2 as best as possible.
To help achieve this, an assessment tool such as the Agilometer in PRINCE2 Agile can answer the question, ‘How agile can we be on this project?’
Delivery method
The approach to managing risk must work with and support the project’s chosen delivery method.
For example, a risk management approach that includes monthly risk review meetings will need help to support an iterative-incremental delivery method with two-week sprints.
The PRINCE2 method does not require a particular format for risk management products nor specific timings for risk management activities.
They must be appropriate for the format and pace of the project.
For example, in an agile delivery method, risks in a risk register may be written on a whiteboard and reviewed as part of a daily stand-up meeting. In this context, this manual approach is as valid as using a specialized IT system to capture and review risks.
It is also essential to recognize that the project’s delivery method might work to mitigate or reinforce specific risks.
For example, an agile approach ensures that users do not overspecify requirements at the beginning of a project, which can be a risk in a more linear approach.
Although agile is characterized by a high level of engagement with the users directly involved in the project, if not managed correctly, this can lead to uncontrolled changes to the agreed baseline.
Linear approaches reinforce the impression of ‘controlled change’ but can appear unresponsive and alienate users. It is of importance that the risk management approach recognizes these inherent differences.
Sustainability
A project’s business case will incorporate specific sustainability targets and tolerances, which should be assessed for risks.
Risk management considerations related to sustainability can include:
- Defining the approach to managing risks relating to the sustainability of the project work (for example, the project not meeting its sustainability performance targets)
- Defining the approach to managing risks relating to the sustainability of the project product (for example, one or more products not meeting their sustainability performance requirements)
- Incorporating the cost of responding to sustainability risks into the risk budget (for example, extreme weather events that may affect the project or the resilience of the supply chain)
- Documenting specific risks and actions relating to sustainability into the risk register and including them in regular risk communications.
Scale
It is essential to ensure that the risk management approach is appropriate for the project’s size, scale, complexity, and likely risk impact.
Project scale and impact need to be considered separately.
For example, a small-scale project to replace an element of a business’s IT network infrastructure could disrupt the whole business if it goes wrong. Projects can create impacts beyond their apparent size, scale, and complexity.
It is essential that the risk management approach supports effective decision-making in the project and does not create an undue burden or bureaucracy.
In general, smaller, more straightforward projects will need correspondingly simpler risk management arrangements, and larger, more complex projects will need more thorough controls.
For example, the project manager would typically directly undertake most risk management activities in a simple project. However, these activities might be delegated to a dedicated risk manager or risk management team in more complex projects.
Similarly, risks might be held in a simple list on a whiteboard, spreadsheet, or dedicated system. It is essential to ensure that the approach to risk management is appropriate and understood by everyone involved in the project.
The risk budget is based on the aggregate cost of all the project’s planned risk responses. Combining the cost of all risk responses will usually be enough for more straightforward projects. However, care must be taken for more complex projects so that a few significant risks balance the aggregation of the factored costs.
