CertFlow PRO
PMBOK8-Business · Part 5 of 8

Risk Management PMBOK 8: Identify to Monitor

··Updated ·17 min read
Share:
Risk Management PMBOK 8

If you don't treat risk as both a threat and an opportunity, your project will always be caught off guard. Learn the PMBOK 8 approach end-to-end.

1. Risk = Threats + Opportunities

The biggest mistake PMs make is thinking risk is only a "bad thing." PMBOK 8 defines it clearly:

PMBOK® 8, Section 2.7.1: "A risk is an uncertain event or condition that, if it occurs, has a positive or negative effect on one or more project objectives. Potentially harmful risks, often called threats, may negatively impact objectives. Positive risks, better known as opportunities, may positively affect objectives."

PMs must manage BOTH: minimize threats AND maximize opportunities.

4 Risk Types by Knowledge Matrix

Known

Unknown 

Known

Known-Known — Facts, certainties. E.g., you need 5 developers.

Known-Unknown — Identified risks. E.g., the vendor MAY be delayed. → Contingency reserve

Unknown

Unknown-Known — Unconscious knowledge, biases. E.g., the team knows about an issue but hasn't spoken up.

Unknown-Unknown — Black swans. E.g., pandemic, earthquake. → Management reserve


2. Core Concepts — Risk Appetite, Threshold, Exposure

Concept

PMBOK 8 Definition

Example

Risk Appetite

"The degree of uncertainty an organization is willing to accept in anticipation of a reward"

Startup: high appetite (innovate fast). Bank: low appetite (protect assets).

Risk Threshold

"The measure of acceptable variation around an objective reflecting risk appetite"

±5% cost variance = low threshold. ±15% = high threshold.

Risk Exposure

"An aggregate measure of the potential impact of all risks at any given point in time"

Total EMV of all identified risks = $500K exposure.

Risk Tolerance

Organization's or stakeholder's ability to ENDURE risk — closely related to appetite

Organization has $2M reserve → can tolerate $500K exposure.


3. Six Risk Management Processes per PMBOK 8

Step

Process

Purpose

When

1

Plan Risk Management

Define how to conduct risk activities

Project conception → early planning

2

Identify Risks

Recognize threats and opportunities

Iteratively throughout project

3

Perform Risk Analysis

Evaluate probability, impact, priority

After identification, iteratively

4

Plan Risk Responses

Develop strategies for each risk

Throughout project

5

Implement Risk Responses

Execute agreed-upon response plans

When triggers occur or proactively

6

Monitor Risks

Track, review, evaluate effectiveness

Continuously


4. Identify Risks — Continuous Discovery

PMBOK 8: "An important part of the Identify Risks process is separating real risks from concerns, knowing initial identification is incomplete. Iterative identification adapts to new information as the project progresses."

Risk Identification Tools

  • - Brainstorming — Team generates risks freely, without judgment

  • - Checklists — From historical data, similar projects, industry knowledge

  • - SWOT Analysis — Strengths, Weaknesses (internal) + Opportunities, Threats (external)

  • - Interviews — SMEs, experienced PMs, stakeholders

  • - Assumption and Constraint Analysis — PMBOK 8: "Explores the validity of assumptions and constraints to determine which pose a risk"

  • - Root Cause Analysis — Identify underlying causes that could generate multiple risks

  • - AI-powered risk identification — New in PMBOK 8: "GenAI and data analytics for comprehensive risk identification"

Risk Breakdown Structure (RBS)

PMBOK 8: RBS categorizes risks into: Technical, External, Organizational, and Project Management. Each category has subcategories — ensuring comprehensive identification with no areas overlooked.


5. Analyze Risks — Qualitative and Quantitative

Qualitative Risk Analysis

Each risk is assessed by Probability × Impact. PMBOK 8: "Qualitative analysis evaluates risks based on their probability and impact throughout the project."

Probability and Impact Matrix:

Very Low Impact

Low

Medium

High

Very High

Very High Prob

Medium

High

High

Critical

Critical

High Prob

Low

Medium

High

High

Critical

Medium Prob

Low

Medium

Medium

High

High

Low Prob

Very Low

Low

Medium

Medium

High

Very Low Prob

Very Low

Very Low

Low

Low

Medium

Quantitative Risk Analysis

PMBOK 8: "Quantitative analysis numerically analyzes the combined effect of identified risks and other sources of uncertainty on overall project objectives."

Tool

Description

Output

EMV (Expected Monetary Value)

Probability × Impact ($). E.g., 30% × -$100K = -$30K

Dollar value per risk, sum = total exposure

Sensitivity Analysis (Tornado)

Which risk has MOST impact on objectives?

Tornado diagram ranking risks by impact

Monte Carlo Simulation

Run thousands of scenarios to determine probability distributions

"80% chance project finishes by March 15"

Decision Tree Analysis

Compare options with different risk profiles

Best path based on EMV of each branch


6. Plan and Implement Risk Responses

7 Strategies for Threats (Negative Risks)

Strategy

Description

Example

Avoid

Eliminate threat entirely — change plan to remove risk

Change technology to avoid vendor dependency

Mitigate

Reduce probability and/or impact

Add testing phases, prototype, cross-training

Transfer

Shift impact to third party

Insurance, fixed-price contract, warranty

Accept (Active)

Acknowledge and prepare contingency

Allocate contingency reserve

Accept (Passive)

Acknowledge without specific action

"We'll deal with it if it happens"

Escalate

Beyond project scope — escalate to program/portfolio

Market risk affecting multiple projects

5 Strategies for Opportunities (Positive Risks)

Strategy

Description

Example

Exploit

Ensure opportunity IS realized

Assign best resources to capitalize

Enhance

Increase probability and/or impact

Add resources to accelerate time-to-market

Share

Allocate ownership to third party best positioned

Joint venture, partnership

Accept

Willing to take advantage if it occurs, no active pursuit

"Nice if it happens"

Escalate

Beyond project scope — escalate upward

Strategic opportunity for portfolio

Secondary and Residual Risks

Secondary risks = new risks CREATED by implementing a risk response. E.g., transferring risk via insurance → secondary risk = insurance doesn't cover everything. Residual risks = risks REMAINING after the response is implemented. E.g., mitigated vendor risk but still a 10% chance of delay. Both must be identified, analyzed, and planned.


7. Risk Register — The Heart of Risk Management

PMBOK 8: The risk register includes: a list of identified risks (unique ID + structured description), potential risk owners, a list of potential risk responses, probability and impact assessment, risk priority/ranking, response strategies, trigger conditions, and status tracking.

Maintain the Risk Register

The risk register is a living document — continuously updated: new risks added when identified, existing risks re-assessed periodically, closed risks archived, responses updated based on effectiveness, and status tracked (active, triggered, closed, accepted).

ECO Example: "Maintain a risk register (e.g., poor IT security)" — IT security is an example of a risk that must be tracked: probability of breach, impact assessment, mitigation measures (encryption, access controls, penetration testing), residual risk level, and ongoing monitoring.


8. Monitor Risks and Communicate Status

Monitor Risks — PMBOK 8

PMBOK 8: "Monitor Risks is the process of monitoring the implementation of risk response plans, tracking identified risks, identifying and analyzing new risks, planning responses for new risks, and evaluating the effectiveness of risk responses throughout the project."

Monitoring activities: risk reviews (regular meetings to review top risks), risk audits (assess effectiveness of risk management process), reserve analysis (are contingency reserves adequate?), and technical performance analysis (compare actual vs planned technical metrics as risk indicators).

Communicate Risk Status

Audience

What They Need to Know

Format

Sponsor

Top 5 risks, overall exposure, decisions needed

Risk dashboard, RAG status

Steering Committee

Strategic risks, risk appetite alignment, escalated risks

Risk report, trend analysis

Team

Risks affecting their work, trigger conditions, response plans

Risk register excerpt, standup blockers

External stakeholders

Risks affecting them, mitigation status

Per communication plan

Predictive vs. Adaptive Risk Management

Aspect

Predictive

Adaptive

Identification

Upfront + periodic reviews

Continuous — each sprint planning + retrospective

Analysis

Formal P×I matrix, EMV, simulations

Story-level risk assessment, risk-adjusted backlog

Responses

Formal response plans, reserves

Spikes, timeboxed experiments, iterative mitigation

Monitoring

Risk reviews, audits, reserve analysis

Sprint retrospectives, daily standups, demos

Register

Formal risk register document

Risk board, risk-adjusted backlog items

PMBOK® 8 Adaptive Tailoring: "In agile, the team conducts risk assessments at the beginning of each sprint. Regular risk review meetings with stakeholders at the end of each iteration to incorporate feedback. Frequent, iterative risk management and risk-adjusted backlogs maintain alignment."


9. PMP Exam Tips

📍Tip 1 — Avoid ≠ Ignore: "Avoid" = eliminate the threat (change the plan). "Accept (passive)" = acknowledge without action. When a question states "PM decides not to do anything about the risk" → passive acceptance, NOT avoidance.

📍Tip 2 — Transfer ≠ Eliminate: Insurance, fixed-price contracts = transfer. The risk still EXISTS — only ownership shifts. When a question states "risk is transferred via contract" — the BUYER transferred cost risk to the SELLER, but the risk still exists.

📍Tip 3 — EMV = Probability × Impact: Threat: 40% × -$200K = -$80K. Opportunity: 30% × +$100K = +$30K. Total EMV negative = need contingency. Exam questions often calculate EMV and ask "what is the project's risk exposure?"

📍Tip 4 — Contingency vs Management Reserve: Contingency = known-unknowns (identified risks), used by the PM. Management reserve = unknown-unknowns (unidentified risks), requires senior management approval. Exam question: "identified risk occurs" → contingency. "Unforeseen event" → management reserve.


10. Ten Scenario-Based Practice Questions

Question 1

Your risk register identifies: Risk A (40% probability, $200K impact), Risk B (60% probability, $100K impact), Risk C (20% probability, $500K impact).

Which risk has the highest EMV and should be prioritized?

A. Risk A — EMV = $80K

B. Risk B — EMV = $60K

C. Risk C — EMV = $100K

D. Risk B — highest probability means highest priority

Question 2

Your construction project faces a risk of soil instability at the site. The geotechnical survey shows 30% chance of unstable soil that could add $1M to costs.

The PM decides to change the building location to a site with stable soil. What risk response strategy is this?

A. Mitigate — reducing the probability by changing locations

B. Avoid — eliminating the threat by changing the plan to remove the risk entirely

C. Transfer — moving the risk to the new site owner

D. Accept — acknowledging and budgeting for the possibility

Question 3

A key vendor supplies critical components. You're concerned about their financial stability (30% risk of default). You negotiate a fixed-price contract with penalty clauses and arrange a backup vendor agreement.

What risk response strategies are you using?

A. Avoidance and transfer

B. Transfer (fixed-price contract shifts cost risk) and Mitigation (backup vendor reduces impact if default occurs)

C. Mitigation only

D. Acceptance with contingency

Question 4

During execution, a risk you identified early (vendor delay) actually occurs. The risk register has a planned response: "Use internal team as backup for 2 weeks."

What should you do?

A. Reassess the risk before taking action.

B. Execute the planned response immediately, move the risk to the issue log, assess any secondary risks from using the internal team, and communicate status to stakeholders.

C. Submit a change request before implementing the response.

D. Escalate to the sponsor for approval.

Question 5

Your team identifies a potential opportunity: a new open-source library could reduce development time by 3 weeks. However, using it requires team training and has some stability concerns.

What opportunity response strategy is MOST appropriate?

A. Exploit — mandate the team to use the library immediately.

B. Enhance — invest in team training to increase the probability of successfully adopting the library, while conducting a stability evaluation to manage the associated threat.

C. Accept — use it if it works out naturally.

D. Share — partner with the open-source community.

Question 6

Your project has 50 identified risks. The team spends 4 hours every week reviewing all 50. Most risks haven't changed status in months. Team complains the meetings are unproductive.

How should you improve the risk monitoring process?

A. Reduce reviews to monthly.

B. Focus weekly reviews on TOP risks (highest exposure, nearest triggers, status changes). Review ALL risks monthly or at milestones. Close risks that are no longer relevant. Make reviews shorter and action-oriented.

C. Assign each risk to an owner and let them manage independently.

D. Use an automated dashboard that flags changes, eliminating the need for meetings.

Question 7

The project sponsor says: "Our organization has low risk appetite. I want zero risks on this project." The project involves new technology with inherent uncertainties.

How should you respond?

A. Implement maximum risk responses to eliminate all risks.

B. Explain that zero risk is impossible — all projects carry uncertainty. Low risk appetite means: aggressive identification, thorough analysis, proactive responses (avoid and mitigate where possible), and tight monitoring. Present the risk management plan showing how risks are managed within the organization's appetite threshold.

C. Switch to a proven technology to eliminate risk.

D. Add more contingency reserve to cover all risks.

Question 8

You implement a risk response (outsource a risky component). After implementation, you discover the outsourcing created a NEW risk: the vendor's work quality is inconsistent, requiring additional QA effort.

What type of risk is this?

A. Residual risk — remaining after response

B. Secondary risk — a new risk created BY the risk response

C. Unknown-unknown — couldn't have been anticipated

D. Trigger event — the original risk materializing

Question 9

Your agile team identifies a risk in Sprint 3 that the third-party API may not support required functionality. In predictive, this would go to the risk register with a formal response plan.

How should this be managed in agile?

A. Create a formal risk register entry and response plan.

B. Add a "spike" (timeboxed investigation) to the sprint backlog to evaluate the API's capabilities. If the risk is confirmed, create backlog items for mitigation (alternative API, custom development). Track on the risk board or as risk-adjusted backlog items.

C. Accept the risk and deal with it when it materializes.

D. Escalate to the Product Owner for a decision.

Question 10

At month 3 of a 12-month project, risk exposure has increased 40% from the original baseline. The risk register has grown from 20 to 35 risks. The PM hasn't updated the risk management plan or contingency reserves.

What is the BIGGEST concern?

A. Too many risks — the team is over-identifying.

B. Risk exposure growth of 40% with no corresponding update to contingency reserves or the risk management plan means the project is UNDER-PROTECTED. The PM should update the risk plan, reassess reserve adequacy, and communicate the changed risk profile to the sponsor.

C. The risk register is too large — reduce to top 20.

D. This is normal — risks emerge as the project progresses.

Answer Key

Question 1: Answer: C

— EMV: A = 0.4 × $200K = $80K. B = 0.6 × $100K = $60K. C = 0.2 × $500K = $100K. Risk C has highest EMV despite lowest probability — the massive impact outweighs the lower probability. Priority should be based on EMV, not probability alone.

Question 2: Answer: B

— Avoidance = change the plan to eliminate the threat entirely. By moving to stable soil, the soil instability risk no longer exists. Mitigation would be soil reinforcement (reduce probability/impact, not eliminate). Transfer would be insurance against soil issues.

Question 3: Answer: B

— Fixed-price contract = transfer (seller bears cost overrun risk). Backup vendor = mitigation (reduces impact of default, doesn't eliminate risk). Two complementary strategies addressing different aspects of the same risk.

Question 4: Answer: B

— The response was pre-approved when the risk plan was approved. PMBOK 8: "Implement Risk Responses ensures agreed-upon responses are executed as planned." No need for re-approval — act quickly. But DO assess secondary risks (internal team overloaded?) and communicate.

Question 5: Answer: B

— Enhance = increase probability and/or impact of an opportunity. Training increases adoption success. Stability evaluation manages the associated threat. Exploit (A) is too aggressive given stability concerns. Accept (C) is too passive for a significant opportunity.

Question 6: Answer: B

— Tailor the monitoring process. PMBOK 8: risk monitoring should be "appropriate to project size and complexity." Reviewing 50 unchanging risks weekly is overhead. Focus weekly reviews on active, high-priority risks. Keep full reviews periodic. Ownership (C) is good but needs coordination. Dashboard (D) helps but doesn't replace discussion.

Question 7: Answer: B

— PMBOK 8: "Risk appetite is the degree of uncertainty an organization is willing to accept." Zero risk is unrealistic — the PM should educate the sponsor and demonstrate a robust risk management approach aligned with low appetite. Switching technology (C) may avoid SOME risks but creates new ones.

Question 8: Answer: B

— Secondary risk = new risk arising directly from implementing a risk response. The response (outsource) created a new risk (vendor quality). PMBOK 8 requires identifying secondary risks when planning responses. Residual risk (A) would be if the original risk was partially addressed but some exposure remained.

Question 10: Answer: B

— PMBOK 8 Adaptive: "risk assessments at beginning of each sprint, risk-adjusted backlogs." A spike is the agile tool for investigating uncertainty — timeboxed, focused, actionable. Results inform the backlog. This is iterative risk management in action.

Question 8: Answer: B

— Risk identification growing is EXPECTED and healthy. But 40% exposure increase without updating reserves or plans = growing gap between risk exposure and protection. PMBOK 8: risk management is iterative — plans and reserves must be updated as risk profile changes. The sponsor needs to know the risk position has materially changed.


11. Conclusion

Risk management is the project's "immune system" — when it works well, the project withstands threats and capitalizes on opportunities. Three key takeaways:

  1. 1. Risks = Threats + Opportunities — manage both — A PM who only focuses on threats misses 50% of the value. Opportunities need to be Exploited, Enhanced, or Shared — not just "hoped for." PMBOK 8 balances 6 threat strategies + 5 opportunity strategies. A great PM seeks to maximize opportunities, not just minimize threats.

  2. 2. Iterative, not once — risk management is continuous — Identify continuously, analyze as new information emerges, update responses as context changes, monitor triggers, and re-assess reserves. A risk register that is 3 months old creates blind spots. PMBOK 8: "Iterative identification adapts to new information as the project progresses."

  3. 3. Quantify to prioritize — not all risks are equal — EMV, P×I Matrix, and Sensitivity Analysis allow PMs to focus on the risks that truly matter, without wasting effort on low-exposure risks. Contingency reserves must match risk exposure — if exposure increases 40% while reserves remain unchanged, the project is under-protected.

PMBOK® 8, Section 2.7: "The Risk performance domain represents a comprehensive approach to creating project resilience by managing risk through risk management practices. This domain advocates for a proactive stance in planning for identified project risks, coupled with adaptive and flexible response mechanisms."

Frequently Asked Questions (FAQ)

What are the 4 risk response strategies for threats in PMBOK?

For threats (negative risks): Avoid — change the plan to eliminate the risk entirely; Transfer — shift the risk to a third party (insurance, contracts); Mitigate — reduce the probability or impact of the risk; Accept — accept it when the cost of response exceeds the cost of the risk. For opportunities (positive risks): Exploit, Enhance, Share, Accept.

What is the difference between a Risk Register and a Risk Report?

Risk Register: a detailed document for each individual risk — ID, description, probability, impact, risk score, owner, response strategy, and contingency plan. Updated frequently; it is the PM's working tool. Risk Report: a summary-level document for management and the steering committee — high-level status of top risks, overall risk exposure, and trends over time. The report is derived from the register.

How does an agile project manage risks per PMBOK 8?

In agile, risks are handled through: a Risk-based spike (a dedicated sprint to investigate a risk), a Risk burndown chart (tracking risk exposure over time), a Risk-adjusted backlog (prioritizing backlog items by risk), and regular risk reviews in Sprint Retrospectives. Agile does not eliminate risk management — it makes it nimbler and more continuous.


You've mastered project risk management — now it's time to practice with real exam questions.

Try Free PMP Practice Questions →

Official References:

Ready to practice?

Try CertFlow free — 10 questions, no signup needed.

Get Started Free
PMPPMBOK 8Plan and Manage RiskBusiness Environment DomainRisk ManagementRisk RegisterRisk ResponseProbability Impact Matrix