Prepare the Risk Management Approach
A critical item that needs to be recorded in the risk management approach is the project board’s
attitude towards risk-taking, documented as risk tolerance. The project board will set the risk tolerance based on the business’s overall risk appetite.
As the risk budget is part of the project budget, there may be a tendency to treat it as just another sum the project manager can spend. This culture should be discouraged, and the risk management approach should define the mechanisms for the
control of and access to this budget.
The following will influence the project’s risk management approach:
● user’s quality expectations
● the number of organizations involved and the relationships between them
● the needs of the stakeholders involved with the project
● the importance, complexity, and scale of the project
● the delivery method being used (linear-sequential, iterative-incremental, hybrid)
● what assumptions have been made
● the business environment (legislative or governance requirements)
● business policies, standards, processes, and procedures
● whether the project is part of a programme.
This information will be derived from the project mandate, the project brief, and the project product
description.
It is a standard error to try to identify specific risks before completing this process. With a shared
understanding of the objectives at risk, there is a possibility that the uncertainties identified are
related to the objectives. There is no risk if the uncertainty does not impact one or more of the
defined objectives.
Risk Management Approach – how to create and apply.
The biggest mistake project managers can make is to start planning before thinking through the best strategy to deliver the end product. Four fundamental PRINCE2 approaches must be considered and developed, beginning with the Risk Management Approach.
The Risk Management Approach includes the procedure to manage risks, the roles and responsibilities, the tolerances and timing of risk management activities, the tools and techniques that will be used to manage risks within a PRINCE2 project, and the reporting requirements.
PRINCE2 Risk Management Approach – the contents
The risk management approach document contains these sections:
- introduction
- risk management procedure
- tools and techniques
- records
- reporting
- timing of risk management activities
- roles and responsibilities
- scales
- proximity
- risk categories
- risk response categories
- early warning indicators
- risk tolerance
- risk budget
Before creating the document, PRINCE2 recommends that the following information be used to help define and create the risk management approach:
The Project Brief should be checked to determine if any corporate or programme management strategies, standards or practices related to risk management should be applied or adhered to in this project.
Either using the Lessons Log and/or seeking lessons from brainstorm sessions for similar previous projects, determine if any approaches could be valuable in treating risks within this project.
The Daily Log will have been used up to this point to capture any risks, and these should also be used by transferring those risks to the Risk Register and applied to this project.
The Risk Register should be set up, and any Daily Log risks already identified should be transferred to this register.
The approach to managing risk must work with and support the project’s chosen delivery method.
For example, a risk management approach that includes monthly risk review meetings will need help to keep an iterative-incremental delivery method with two-week sprints.
The PRINCE2 method does not require a particular format for risk management products nor specific timings for risk management activities. They must be appropriate for the format and pace of the project.
For example, in an agile delivery method, risks in a risk register may be written on a whiteboard and reviewed as part of a daily stand-up meeting. In this context, this manual approach is as valid as using a specialized IT system to capture and review risks.
It is also essential to recognize that the project’s delivery method might work to mitigate or reinforce specific risks. For example, an agile way of working ensures that users understand requirements at the beginning of a project, which can be a risk in a more linear approach.
Although agile is characterized by a high level of engagement with the users directly involved in the project, it can lead to uncontrolled changes to the agreed baseline if not managed correctly. Linear approaches reinforce the impression of ‘controlled change’ but can appear unresponsive and alienate users. It is of importance that the risk management approach recognizes these
inherent differences.
The Risk Management Approach needs to be created, and considerations in compiling this document should include:
The risk management procedure currently being used within your organization should be applied or modified to suit this particular project.
Any special tools, techniques, or records that will be kept should be captured in this document.
When the risk management activities should occur, how should the performance of the risk management procedure be reported, and what are the roles and responsibilities for the risk management activities?
A set of scales to estimate the probability and impact of negative threats and positive opportunities should be determined and included.
Guidance should be set out on how proximity for risks will be accessed, including the definition of risk categories to be used.
The project manager will want to discuss their risk tolerance or ‘risk appetite’ risks with the project board, which should be stated within the Risk Management Approach.
The analysis of risks and their responses will take time and resources, and the project manager will want to discuss and agree with the project board on whether or not a risk budget to fund these activities will be established and, if so, how such a budget will be controlled.
The Risk Management Approach should be reviewed by project assurance to ensure that it meets the needs of the project board and all corporate or programme management if this project is part of a programme.
The project board may wish to approve the Risk Management Approach at this point, or they may prefer to review it and approve it later as part of the Project Initiation Documentation.
PRINCE2® 7 Foundation and Practitioner


Learn PRINCE2® 7 Foundation and Practitioner Online
** Enhance your PRINCE2 career now **
PRINCE2® Masterclass gives you the skills necessary to manage projects effectively and achieve your objectives.
Get 7 days a week 12 months one to one coaching with ex PRINCE2 examiner Dave Litten.
PRINCE2® is a globally recognized project management framework. By completing both the Foundation and Practitioner courses through our self-paced e-learning, you will develop an understanding of the methodology and learn how to effectively adapt it to any project.
The PRINCE2® 7 Foundation and Practitioner Masterclass is PeopleCert Accredited and guarantees to take you from PRINCE2 Novice to PRINCE2 Practitioner with our famous video learning, study guides and practice exams.
What Does the Masterclass Cover?
The PRINCE2 Foundation examination assesses your knowledge and comprehension of the PRINCE2 project management methodology as detailed in the syllabus. The PRINCE2 Practitioner examination, on the other hand, gauges your ability to apply and tailor the PRINCE2 method. Candidates who pass the Practitioner exam should be able to start implementing the method on an actual project with some guidance. However, their effectiveness may differ based on their experience in project management, the complexity of the project, and the level of support they receive in their work environment.

