PRINCE2 7th Edition Risk Practice
The risk practice purpose
The risk practice aims to identify, assess, and control uncertainties that would affect the project’s objectives and, as a result, improve the project’s ability to succeed.
Risk is defined as an uncertain event or set of events that, should they occur, will affect the achievement of objectives. Risk is measured by the probability of a perceived threat or opportunity occurring and the magnitude of its impact on objectives.
All projects encounter uncertainty when trying to achieve their objectives.
Risks can have a negative or positive impact on objectives if they occur. PRINCE2 uses the terms’ threat’ for uncertain events that would negatively impact objectives and ‘opportunity’ for uncertain events that would positively impact objectives.
Threats and opportunities can impact the project’s objective of delivering an agreed scope and benefits to an agreed time, cost, and quality and within agreed sustainability targets.
As all projects involve some degree of risk-taking, they need to manage risk in a way that supports effective decision-making. The risk practice provides a disciplined environment for proactive decision-making.
This uncertainty may arise from events inside or outside the business. For example, there may be uncertainty from within the business about the ability to agree to the project’s scope within specific timescales or the availability of key people and critical resources.
There may also be uncertainty from outside the business, such as geopolitical events, economic conditions, changes to legislation, or suppliers’ responses to procurement requests coming within expected costs.
The approach used by PRINCE2 to manage risk is aligned with the ISO standard, ISO 31000. This is the international standard for risk management.
By providing comprehensive principles and guidelines, this standard helps organizations with their risk analysis and risk assessments.
PRINCE2 risk approach is also aligned with regional variants of the ISO standard and can be tailored to meet these local requirements.
Guidance for effective risk management
Effective risk management provides confidence that the project can meet its objectives and that the business justification remains valid. It supports decision-making by ensuring that the project team understands individual risks and the overall risk exposure at a particular time.
For risk management to be effective:
- Risks that might prevent the project from achieving its objectives must be identified, captured, and described. Each risk needs to be assessed and prioritized.
- The overall risk exposure needs to be kept under review, together with the impact of the risk on the overall business justification for the project.
- Responses to each risk need to be planned and assigned to people who can take ownership of the risk and perform the necessary action.
- Risk responses need to be implemented, monitored, and controlled.
- Information about risks is communicated to relevant stakeholders.
- Each risk needs to be assigned and owned by a risk owner.
PRINCE2 7th Edition Risk Definitions
Risk owner: the person who is assigned to take responsibility for responding to a risk.
Risk action owner: the person who is the nominated owner of agreed actions to respond to a risk. This role is also known as the risk actionee.
Risk probability: the estimated chance that a risk will occur. Probability is often estimated by considering a risk’s likelihood or frequency of occurrence.
Risk impact: the estimated effect on objectives should a risk occur.
Risk proximity: how near in time a risk might occur.
Risk velocity: how quickly a risk would impact objectives should it occur.
Risk exposure: the degree to which a particular objective is at risk. Risk exposure is a neutral concept, as exposure can be positive or negative.
Risk appetite: the amount and type of risk the business is willing to take to pursue its objectives.
Risk budget: money to fund specific management responses to the project’s threats and opportunities (for example, to cover the costs of any contingent plans should a risk materialize).
Risk tolerance: a measurable threshold to represent the tolerable range of outcomes for each objective at risk’ using the same units to measure performance for that objective.
PRINCE2 7th Edition Risk planning
The use of risk categories helps projects identify and prioritize risks. Techniques such as PESTLE (political, economic, social, technological, legal, and environmental) analysis and SWOT (strengths, weaknesses, opportunities, threats) analysis (both described later in this chapter) can be used to analyze the internal and external context for risks.
These techniques also help identify different risk types that may affect the project (for example, sustainability, cybersecurity, or systems
integration). Understanding the types of risks can also help identify the most appropriate owners.
A critical item that needs to be recorded in the risk management approach is the project board’s attitude towards risk-taking, documented as risk tolerance. The project board will set the risk tolerance based on the business’s overall risk appetite.
An essential aspect of identifying risks is providing an unambiguous expression of each risk. A helpful way of expressing risk is to consider the following aspects:
Risk cause should describe the source of the risk, such as the event or situation that causes it. These are often referred to as risk drivers. They are not risks in themselves but are potential trigger points for risk. These may be either internal or external to the project.
Risk event: this should describe the area of uncertainty in terms of the threat or the opportunity.
Risk effect: this should describe the risk’s impact on the project objectives, should the risk materialize.
The cause, event, and effect relationship could also be expressed as follows:
Threat: insufficient staffing capacity (risk cause) could lead to the business being unable to provide enough staff to complete user training in the planned timescales (risk event), resulting in the project taking longer than planned (risk effect).
Opportunity: if allowable under data regulations, the company could include a discount code in the email (risk event) when it renews customer details every year (risk cause), generating income to offset the cost of the regulatory requirement (risk effect).
PRINCE2 7th edition Risk analysis
Risk analysis can include qualitative and quantitative approaches. Qualitative risk analysis comprises, at minimum, assessing its probability (the chance that the risk will occur) and its impact (the effect size on one or more objectives if the risk occurs).
Other qualitative assessments include analyzing a risk’s proximity (how near in time it might occur) and velocity (how quickly it would impact objectives should it occur).
A helpful way of summarizing the set of risks and their estimations is to plot them onto a risk matrix, an example of which is shown below.

This represents a situation at a specific time (such as a snapshot of the risk environment). The numbered markers in the matrix represent unique risk identifiers used in the risk register on which this is based.
The risks above and to the right of the dashed risk tolerance line represent those the business will not tolerate except under exceptional circumstances.
In the depicted case, the project manager would refer risks 1, 3, and 4 to the project board.
The risk matrix can also be used to show trends. For example, risk six may have previously been recorded as ‘low probability, high impact’, indicating that its probability of occurring is increasing. It is also possible to take a quantitative approach to prioritize risks.
Quantitative risk assessment (for example, Monte Carlo analysis) involves using modelling techniques to calculate overall risk exposure levels and analyze the risk effects.
Risk models use statistical methods to analyze the effect of uncertainty on objectives.
Quantitative risk assessment can be used to analyze the impact on cost (known as quantitative risk cost analysis) or time objectives (known as quantitative risk schedule analysis).
