The Risk Practice – Part 1
Taking a simplistic definition of risk; “an event that has yet to happen, it may or may not happen at some point in the future, but if it does it will have an impact on my project”, you may be fooled into thinking that risk management is hard. But you would be wrong!
The purpose of the Risk Practice is to identify, assess and control uncertainty and, as a result, improve the ability of the project to succeed.
PRINCE2 defines risk as “An uncertain event or set of events that, should it occur, will have an effect on the achievement of objectives”
Many projects fail due to poor risk management which is totally unnecessary as there is a very logical and straightforward approach to the management of risks within a PRINCE2 7 project.
By taking the mind-set of “what could possibly go wrong with my project” and making a list of such situations, then working out how to either prevent or minimize the risk (at a minimum just to control it), would greatly reduce the number of failed projects.
Performing risk management will protect your project by preventing or controlling situations that would have, as a minimum, caused problems, and at a maximum, potentially ruin the project.
PRINCE2 7 includes a well-documented risk theme that covers all potential project and organisational risks.
In keeping with this fact, PRINCE2 7 defines risk as “an uncertain event or set of events that, should it occur, would have an effect on the achievement of objectives”.
The first step in risk management is to develop the Risk Management Strategy, and is the chosen approach so that you clearly understand how risks will be handled during the project. This is the project risk “how-to” document!
As part of tailoring PRINCE2 7 according to the individual project risk environment, the Risk Management Approach will define your risk approach for a particular project and this forms part of the Project Initiation Documentation created within the Initiation stage.
As part of managing risk, responses for each risk will be determined, and such responses will require actions and resources to carry them out. Therefore risk management does not come free but instead needs to be budgeted for accordingly. This is called the Risk Budget.
The Risk Budget has several advantages as it makes clear what portion of the project funding will be put aside for each risk, and since this budget forms part of the whole project budget, the Project Manager already has the authority to use it.
The key management tool used here is the Risk Register which provides a record of all identified risks within the project and includes their status and history.
Risk Practice support of the continued business justification Principle
The Risk Practice recognizes that risk management is an ongoing activity throughout the project life, and without this there cannot be sufficient confidence that the project will meet its objectives, and hence whether it is worthwhile to continue. Hence effective risk management supports the continued business justification Principle.
The PRINCE2 7 Five-Step Risk Management technique
PRINCE2 7 has a procedural based risk management model consisting of four elements, with a fifth element called ‘communicate’ which works in parallel with the previous four elements:

The Risk Management procedure is split into FIVE main steps:
- Identify. Identify the specific objectives that are at risk – and to formulate the Risk Management Strategy, capture the risks and place on the Risk Register
- Assess. Estimate the probability, impact, proximity and severity of each risk
- Plan. Prepare responses to the risks – Avoid, Reduce, Fallback, Transfer, Share, and Accept
For opportunities the response choices are, Exploit, Enhance, Share, and Reject.
- Implement. Carry out the risk/opportunity actions, monitor and report
- Communicate. Ensure internal and external communication on the aggregated risks.
Threat or opportunity impact should be considered under the following headings:
- Time
- Cost
- Quality
- Scope
- Benefit
- Sustainability
- People/resources
Risk Response Types for Threats and Opportunities
You would want to use the following responses in terms of reducing or removing Threats, but maximizing and enhancing for Opportunities:

Once a plan is signed off, then monitoring and reporting can take place. This will normally consist of checking that the actions are having the desired effect, watching for warning signs and trends, and ensuring that the overall management of risk is effective.
Risk management is an on-going and iterative activity throughout a project and its stages.
The total risk situation should be checked at key points – particularly at those times when the Project Board needs to authorize a Next Stage Plan or Exception Plan.
The risk situation should be included in the regular Highlight Report sent from the Project Manager to the project board.
Also the risk situation should be checked when:
- Planning, authorizing and accepting Work Packages
- Examining project issues, as part of management by exception
- When closing the project – operational risks that need to be managed by others after closure
Since PRINCE2 7 projects are the mechanisms for change, they will always include risk aspects when changing from the old to the new ways of working and must use risk management in order to be successful.
More precisely, risk is really uncertainty and it is this that must be managed.
In the context of a PRINCE2 project it is the project objectives that are at risk, and it is important to establish and maintain a cost effective risk management procedure.
To perform effective risk management we need to understand risk causes, the probability, their impact and timing, and select a suitable response or set of responses for each risk.
Care should be taken not to spend more avoiding the risk than the impact of the risk itself.
Risk management starts at the very beginning of PRINCE2 and is a continual activity carried out throughout the life of the project, without this, it would not be possible to have the confidence that the project is able to meet its objectives and should continue.
In other words, risk management threatens the Business Case and hence the continued business justification principle.
A simple way of describing a risk is, an event which may or may not occur at some point in the future, but if it does occur it will have an impact on the project objectives.
There are two types of risk; those with a negative impact and those with a positive impact: risks which have a negative impact are called threats and those with a positive impact are called opportunities – both have the common characteristic of uncertainty.
A risk management system is one which first identifies risks and then assesses them, followed by the planning and implementation of risk responses.
Having been first identified (usually done in a risk or planning workshop) in terms of their impact, and timing, the overall of risk associated with the project is called the aggregated risk, and this needs to be understood and agreed by the Project Board for effective risk management within PRINCE2.
Each risk will now need an appropriate response followed by the assignment of a Risk Owner, and then the monitoring and controlling of those responses. The Risk Owner can optionally delegate the management of a particular risk to a role called the Risk Assignee.
In the Starting up the Project process, the Project Manager will use the Daily Log to capture and manage any known risks; these will be used as part of the evidence put before the Project Board to decide whether or not to proceed into the Initiation Stage.
The Risk Management Approach will be created in the Initiation stage and describes how risk management will be embedded within the project.
The purpose of the Risk Management Approach describes the specific risk management techniques and standards to be applied to the project, and the responsibilities for achieving an effective risk management procedure.
At the same time, The Risk Register will be created and any risks currently within the Daily Log will now be transferred to this register.
Using The Project Brief and the Project Product Description as inputs, The Risk Management Approach will include the following information:
- The risk management procedure to be applied
- Tools and techniques to be used
- Records and reporting
- Timing of risk management activities
- Risk responsibilities
- Risk tolerances
- The Risk Budget if it is to be used
One aspect to consider here is the project board’s attitude towards risk-taking as this will influence the amount of risk that is acceptable and the most effective responses required.
This is called the project board’s ‘risk tolerance’ or ‘risk appetite’, and is not the same as the term tolerance when applied as part of management by exception.
The Risk Budget
This is a sum of money included within the project budget that is used to fund the risk responses to the project’s Threats and Opportunities.
The Risk Register
This is a project management tool used to contain information on all of the identified threats and opportunities within a project.
The purpose of the Risk Register is to provide a record of all identified project risks, their status and history. It is used to capture and maintain information on the entire project identified threats and opportunities.
It will contain information such as
- The category and description of the risk
- Risk probability
- Risk impact and expected value
- Risk proximity and risk responses
- Risk current status
- The Risk Owner
Project Support will normally maintain the Risk Register for the project manager.
It is vital that risks are clearly and unambiguously described, and it is useful to consider each risk in terms of
- The risk cause (the source of the risk)
- The risk event describing the area of uncertainty
- The risk effect describing the impact of the risk should it occur
An example here could be: “As a result of heavy rainfall in the last 24 hours (Risk cause), many local roads are flooded (Risk event), and as a result of this, local drivers may experience severe delays or be unable to reach their destinations (Risk effect/impact)
The Probability of a risk is the likelihood of it occurring if no response actions were taken.
The Impact of a risk is the impact if it were to occur on one or more of the project’s objectives. The impact could be on the impact to benefits, time, cost or quality for example.
The Risk Proximity would be how close to the present time the risk event is expected to happen. Proximity could be expressed as a time frame, or within a stage, within the project or beyond the project.
Risk Appetite or tolerance. This is the organization’s risk appetite or unique attitude toward risk taking, and ultimately will help setting tolerance levels. Traditional institutions such as banks have a very low risk appetite, whereas, say, a venture capital project would have a much higher appetite.
PRINCE2® 7 Foundation and Practitioner


Learn PRINCE2® 7 Foundation and Practitioner Online
** Enhance your PRINCE2 career now **
PRINCE2® Masterclass gives you the skills necessary to manage projects effectively and achieve your objectives.
Get 7 days a week 12 months one to one coaching with ex PRINCE2 examiner Dave Litten.
PRINCE2® is a globally recognized project management framework. By completing both the Foundation and Practitioner courses through our self-paced e-learning, you will develop an understanding of the methodology and learn how to effectively adapt it to any project.
The PRINCE2® 7 Foundation and Practitioner Masterclass is PeopleCert Accredited and guarantees to take you from PRINCE2 Novice to PRINCE2 Practitioner with our famous video learning, study guides and practice exams.
What Does the Masterclass Cover?
The PRINCE2 Foundation examination assesses your knowledge and comprehension of the PRINCE2 project management methodology as detailed in the syllabus. The PRINCE2 Practitioner examination, on the other hand, gauges your ability to apply and tailor the PRINCE2 method. Candidates who pass the Practitioner exam should be able to start implementing the method on an actual project with some guidance. However, their effectiveness may differ based on their experience in project management, the complexity of the project, and the level of support they receive in their work environment.

