Preloader spinner
Project team reviewing project risks and planning information

Project risk management is the process of identifying uncertain events or conditions that could affect project objectives, assessing their significance and deciding how to respond. Good risk management does not remove uncertainty. It helps the project team recognise important uncertainty early enough to make informed decisions.

What is a project risk?

A risk is something uncertain that may happen and, if it does, could affect time, cost, scope, quality, benefits or other project objectives.

For example: There is a risk that the specialist supplier may not deliver equipment by the required date, which could delay testing and the planned launch.

Risk vs issue

A risk might happen. An issue has already happened or already exists.

  • Risk: the supplier may miss the delivery date.
  • Issue: the supplier has confirmed delivery will be two weeks late.

Once a risk occurs, the project normally manages the resulting issue rather than continuing to treat it as a possibility.

Why manage risks early?

Risks are usually easier and cheaper to influence before they become problems. Early identification can give the team time to change the approach, secure alternatives, clarify requirements or adjust sequencing.

How to identify project risks

Useful sources include project-team workshops, stakeholder interviews, lessons from previous projects, supplier discussions, assumptions, dependencies, technical reviews and schedule or resource reviews.

Thinking in categories also helps. Common areas include:

  • scope and requirements
  • schedule and dependencies
  • cost and funding
  • people and resources
  • suppliers
  • technical performance
  • commercial and contractual matters
  • regulation and compliance
  • stakeholders and organisational change

Write risks clearly

A vague entry such as “supplier risk” is difficult to manage. A clearer structure describes the cause, uncertain event and possible effect.

For example: Because the project relies on a single specialist supplier, there is a risk that equipment delivery may be delayed, which could postpone testing and move the planned go-live date.

Assess probability and impact

Risks are commonly assessed according to how likely they are to occur and how serious the effect would be. Organisations may use simple scales such as Low, Medium and High or numerical scales such as 1 to 5.

The purpose is to support prioritisation, not to create artificial mathematical precision.

What is a risk matrix?

A risk matrix plots probability against impact so higher-priority risks are easier to identify. It is a useful communication tool, but the colour or score should not replace judgement. Two risks with the same score can require very different responses.

What is a risk owner?

A risk owner is responsible for ensuring that a particular risk is understood, monitored and managed. They do not necessarily carry out every action personally, but someone has clear accountability for keeping the risk under review.

How can a project respond to threats?

  • Avoid: change the approach so the threat no longer exists.
  • Reduce or mitigate: lower the probability or impact through preventive action.
  • Transfer or share: move or share some exposure through contracts, insurance or specialist suppliers where appropriate.
  • Accept: monitor the risk when further preventive action is not justified.

Projects can also identify positive uncertainty and take action to increase worthwhile opportunities.

What is a contingency plan?

A contingency plan describes what will happen if a risk occurs. For example, if a supplier misses a defined date, the team may activate an alternative supplier or resequence other work.

Mitigation acts before the event. Contingency explains what to do if it happens.

What is residual risk?

Residual risk is the exposure remaining after planned responses have been applied. A response may reduce a risk without eliminating it, so the remaining exposure still needs monitoring.

What should a risk register contain?

A practical risk register may record the risk description, category, probability, impact, priority, owner, response, action owner, target date, current status and residual exposure.

The register should support decisions. If it becomes a large document nobody reviews, it is not doing its job.

How often should risks be reviewed?

Review frequency should reflect the pace and complexity of the project. Reviews should ask whether probability or impact has changed, whether actions are complete, whether new risks have appeared, whether a risk has become an issue and whether anything can be closed.

Risks, assumptions and dependencies

An assumption is something the project is treating as true for planning purposes. If it might prove false, that uncertainty can create a risk.

A dependency is something the project relies on. Uncertainty around that dependency can also create risk.

Risk management and the project plan

Risk responses often add tasks, require resources, alter sequencing or create contingency. Risk management therefore needs to connect with planning rather than operate separately.

See What Is a Project Plan? for how scope, schedules, resources, costs and risks fit together.

Common project risk mistakes

  • Identifying risks once and never revisiting them.
  • Using vague descriptions.
  • Recording every imaginable problem until important risks are lost in noise.
  • Failing to assign an owner.
  • Confusing risks with issues.
  • Recording risks without response actions.
  • Hiding risks to make the project look healthier.

A simple project risk process

  1. Identify meaningful uncertainty.
  2. Describe each risk clearly.
  3. Assess probability and impact.
  4. Prioritise what matters most.
  5. Assign an owner.
  6. Choose an appropriate response.
  7. Complete response actions.
  8. Monitor residual exposure.
  9. Review throughout the project.

Frequently asked questions

Who is responsible for project risk?

The project manager coordinates the process, but individual risks should be owned by people best placed to understand and manage them.

What is the difference between mitigation and contingency?

Mitigation reduces probability or impact before the event. Contingency describes the planned response if the event occurs.

Can a project have too many risks?

It can have too many poorly defined entries. A useful register prioritises meaningful uncertainty rather than documenting every conceivable problem.

Develop your project-management skills with ExperTrain

The Project Management Fundamentals course covers risk identification and management alongside business cases, stakeholders, scope, requirements, work breakdown structures, schedules, budgets and change.

The APM Project Management Qualification (PMQ) also covers risk and issue management within a broader professional syllabus.

You can also explore PRINCE2 Project Management Foundation and the wider Project Management training portfolio.

Keep ExperTrain in your Google results

Found this article useful? Add ExperTrain as a Preferred Source on Google to help surface more of our training guides, articles and learning resources.

Join our mailing list

Receive details on our new courses and special offers

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.