PRINCE2 risk planning, analysis and control
PRINCE2 Risk planning
The use of risk categories helps projects identify and prioritize risks. Techniques such as PESTLE (political, economic, social, technological, legal, and environmental) analysis and SWOT (strengths, weaknesses, opportunities, threats) analysis (both described later) can be used to analyze the internal and external context for risks.
These techniques also help identify different risk types that may affect the project (for example, sustainability, cybersecurity, or systems integration). Understanding the types of risks can also help identify the most appropriate owners.
A critical item that needs to be recorded in the risk management approach is the project board’s attitude towards risk-taking, documented as risk tolerance. The project board will set the risk tolerance based on the business’s overall risk appetite.
An essential aspect of identifying risks is providing an unambiguous expression of each risk. A helpful way of expressing risk is to consider the following elements:
Risk cause should describe the source of the risk, such as the event or situation that causes it. These are often referred to as risk drivers. They are not risks in themselves but are potential trigger points for risk. These may be either internal or external to the project.
Risk event: this should describe the area of uncertainty in terms of the threat or the opportunity.
Risk effect: this should describe the impact that the risk would have on the project objectives should the risk materialize
The cause, event, and effect relationship could also be expressed as follows:
Threat: insufficient staffing capacity (risk cause) could lead to the business being unable to provide enough staff to complete user training in the planned timescales (risk event), resulting in the project taking longer than planned (risk effect).
Opportunity: if allowable under data regulations, the company could include a discount code in the email (risk event) when it renews customer details every year (risk cause), generating income to offset the cost of the regulatory requirement (risk effect).
PRINCE2 Risk analysis
Risk analysis can include qualitative and quantitative approaches. Qualitative analysis of a risk includes, as a minimum, assessing its probability (the chance that the risk will occur) and its impact (the effect size on one or more objectives if the risk occurs).
Other qualitative assessments include analyzing a risk’s proximity (how near in time it might occur) and velocity (how quickly it would impact objectives should it occur).
The Risk Matrix
A helpful way of summarizing the set of risks and their estimations is to plot them onto a risk matrix, an example of which is shown below.

This represents a situation at a specific time (such as a snapshot of the risk environment).
The numbered markers in the matrix represent unique risk identifiers used in the risk register on which this is based.
The risks above and to the right of the dashed risk tolerance line represent those the business will not tolerate except under exceptional circumstances. The project manager would refer risks 1, 3, and 4 to the project board.
The risk matrix can also be used to show trends. For example, risk six may have previously been recorded as ‘low probability, high impact’, indicating that its probability of occurring is increasing.
It is also possible to take a quantitative approach to prioritize risks. Quantitative risk assessment (for example, Monte Carlo analysis) involves using modelling techniques to calculate levels of overall risk exposure and analyze the effects of risk.
Risk models use statistical methods to analyze the effect of uncertainty on objectives.
Quantitative risk assessment can be used to analyze the impact on cost (known as quantitative risk cost analysis) or time objectives (known as quantitative risk schedule analysis).
PRINCE2 Risk Control
Risk responses
The best actions to respond to risks will depend on the particular situation and type of risk.
Different responses may be appropriate for threats and opportunities.
Avoid a threat. Exploit an opportunity
This option is about making an uncertain situation sure by removing the risk. This can often be achieved by eliminating the cause of a threat or by implementing a factor that leads to an opportunity.
This option may be adopted for no extra cost by changing how the work is planned.
However, often, costs will be incurred to remove all residual risk for threats and opportunities. Where costs are incurred, they must be justified.
For example, it is acceptable to discover the cost of a response to make the situation certain.
Reduce a threat. Enhance an opportunity.
This option chooses to take definite action now to change the probability or impact of the risk.
The term ‘mitigate’ is relevant when discussing the reduction of a threat, which involves making the threat less likely to occur or reducing the impact if it did.
Enhancing an opportunity is the reverse process, which involves making the opportunity more likely to occur or increasing the impact if it does.
Again, because this option now commits the business to the costs for reduction or enhancement, response costs must be justified in terms of the change to residual risk.
Transfer the risk
This option aims to impart part of the risk to a third party. Insurance is the most common form of transfer, where the insurer accepts the risk cost, but the insured retains the impact on other objectives (for example, a time delay).
The transfer can apply to opportunities where a third party gains a cost-benefit, and the primary risk taker gains another benefit. This is not a commonly used option, whereas transfer of threats is frequently used.
Again, the transfer cost must be justified regarding the change to residual risk (for example, is the premium you pay worth it?).
It is important to note that some risk elements cannot be transferred, although the business may delegate the risk management to a third party.
Share the risk
This option differs from the transfer response, as it seeks for multiple parties, typically within a supply chain, to share the risk on a pain or gain share basis. Risks can rarely be entirely shared in this way.
For example, the primary risk taker must always protect their brand and reputation. However, this can successfully encourage collaboration on risk management activities, particularly in programmes and projects.
Accept the risk
This option means that the business ‘takes the chance’ that the risk will occur, managing its full impact if it does. There is no change to residual risk with the accept option, but no costs are incurred now to manage the risk or to prepare to manage the risk in future.
An example would be the risk to profitability because of currency fluctuations.
The business may not engage in hedging or other provisions to protect margins from wide rate variations. This option would not be appropriate if the risk exposure exceeded the risk tolerance threshold for the activity in question.
Note that in a case such as currency fluctuations, where the impact could be positive or negative, this counts as two risks because a risk is the relationship between the uncertain event and the impact of that event.
There is a risk leading to loss and another leading to gain, so framing the uncertainty as two risks allows for different responses to each.
Prepare contingent plans
This option involves preparing plans but waiting to act. It is most usually associated with the ‘accept’ option. The preparation of contingent plans suggests that the risks are accepted for now, but a plan will be made for what should be done if the situation changes.
This option applies equally to other responses and is often referred to as a fallback plan, which is the plan if the original response does not work. Fallback plans apply to all other strategies, including avoiding a threat and exploiting an opportunity, because the plan to avoid or exploit may not be successful despite good intentions.
If a threat is reduced rather than removed, the most considerable realistic probability or size of the impact of the remaining risk is called the ‘residual’ risk. If the residual risk is significant, selecting more than one risk response may be appropriate.
Implementing a risk response may reduce or remove other related risks. The responses to risks may also change some aspects of the project after execution.
Consequently, this may lead to secondary risks (risks that occur because of invoking a risk response). These must be identified, assessed, and controlled in the same way as the initially identified risk.
Risk responses must balance the cost of implementing the response against the probability and impact of allowing the risk to occur. One way to assess this is to compare the cost of the risk response with the difference in the expected monetary value of the risk.
This is the product of a risk’s estimated most likely financial impact and its estimated probability, both before and after the risk response. If the cost of the risk response is lower than the reduction in the expected monetary value, then it is worth undertaking the risk response.
However, remembering the overall effect of all risk response activities on the project team is always worth remembering, as it may move their focus away from delivering the project to risk response actions.
