CertFlow PRO
PMBOK8-Business · Bài 5/8

Quản Lý Rủi Ro Dự Án: Từ Nhận Diện đến Giám Sát PMBOK 8

··Cập nhật ·17 phút đọc
Chia sẻ:
Risk Management PMBOK 8

PMBOK 8 nhìn rủi ro theo hai chiều: threats cần mitigate và opportunities cần exploit. Bài này đi qua risk management toàn diện theo góc nhìn PMBOK 8 thực chiến.

1. Rủi ro = Threats + Opportunities

Sai lầm lớn nhất của PM là chỉ nghĩ rủi ro là "thứ xấu." PMBOK 8 định nghĩa rõ:

PMBOK® 8, Section 2.7.1: "A risk is an uncertain event or condition that, if it occurs, has a positive or negative effect on one or more project objectives. Potentially harmful risks, often called threats, may negatively impact objectives. Positive risks, better known as opportunities, may positively affect objectives."

PM phải quản lý CẢ HAI: minimize threats VÀ maximize opportunities.

4 loại rủi ro theo Knowledge Matrix

Known

Unknown 

Known

Known-Known — Facts, certainties. VD: cần 5 developers.

Known-Unknown — Identified risks. VD: vendor CÓ THỂ trễ. → Contingency reserve

Unknown

Unknown-Known — Unconscious knowledge, biases. VD: team biết vấn đề nhưng chưa nói.

Unknown-Unknown — Black swans. VD: pandemic, earthquake. → Management reserve


2. Khái niệm nền tảng — Risk Appetite, Threshold, Exposure

Concept

Định nghĩa PMBOK 8

Ví dụ

Risk Appetite

"The degree of uncertainty an organization is willing to accept in anticipation of a reward"

Startup: high appetite (innovate fast). Bank: low appetite (protect assets).

Risk Threshold

"The measure of acceptable variation around an objective reflecting risk appetite"

±5% cost variance = low threshold. ±15% = high threshold.

Risk Exposure

"An aggregate measure of the potential impact of all risks at any given point in time"

Total EMV of all identified risks = $500K exposure.

Risk Tolerance

Organization's or stakeholder's ability to ENDURE risk — closely related to appetite

Organization has $2M reserve → can tolerate $500K exposure.


3. Sáu quy trình quản lý rủi ro theo PMBOK 8

Bước

Process

Mục đích

Khi nào

1

Plan Risk Management

Define how to conduct risk activities

Project conception → early planning

2

Identify Risks

Recognize threats and opportunities

Iteratively throughout project

3

Perform Risk Analysis

Evaluate probability, impact, priority

After identification, iteratively

4

Plan Risk Responses

Develop strategies for each risk

Throughout project

5

Implement Risk Responses

Execute agreed-upon response plans

When triggers occur or proactively

6

Monitor Risks

Track, review, evaluate effectiveness

Continuously


4. Identify Risks — Tìm kiếm liên tục

PMBOK 8: "An important part of the Identify Risks process is separating real risks from concerns, knowing initial identification is incomplete. Iterative identification adapts to new information as the project progresses."

Risk Identification Tools

  • - Brainstorming — Team generates risks freely, không judge

  • - Checklists — From historical data, similar projects, industry knowledge

  • - SWOT Analysis — Strengths, Weaknesses (internal) + Opportunities, Threats (external)

  • - Interviews — SMEs, experienced PMs, stakeholders

  • - Assumption and Constraint Analysis — PMBOK 8: "Explores the validity of assumptions and constraints to determine which pose a risk"

  • - Root Cause Analysis — Identify underlying causes that could generate multiple risks

  • - AI-powered risk identification — PMBOK 8 mới: "GenAI and data analytics for comprehensive risk identification"

Risk Breakdown Structure (RBS)

PMBOK 8: RBS phân loại risks theo categories: Technical, External, Organizational, Project Management. Mỗi category có subcategories — giúp đảm bảo identification comprehensive, không bỏ sót areas.


5. Analyze Risks — Qualitative và Quantitative

Qualitative Risk Analysis

Đánh giá mỗi risk theo Probability × Impact. PMBOK 8: "Qualitative analysis evaluates risks based on their probability and impact throughout the project."

Probability and Impact Matrix:

Very Low Impact

Low

Medium

High

Very High

Very High Prob

Medium

High

High

Critical

Critical

High Prob

Low

Medium

High

High

Critical

Medium Prob

Low

Medium

Medium

High

High

Low Prob

Very Low

Low

Medium

Medium

High

Very Low Prob

Very Low

Very Low

Low

Low

Medium

Quantitative Risk Analysis

PMBOK 8: "Quantitative analysis numerically analyzes the combined effect of identified risks and other sources of uncertainty on overall project objectives."

Tool

Mô tả

Output

EMV (Expected Monetary Value)

Probability × Impact ($). VD: 30% × -$100K = -$30K

Dollar value per risk, sum = total exposure

Sensitivity Analysis (Tornado)

Which risk has MOST impact on objectives?

Tornado diagram ranking risks by impact

Monte Carlo Simulation

Run thousands of scenarios to determine probability distributions

"80% chance project finishes by March 15"

Decision Tree Analysis

Compare options with different risk profiles

Best path based on EMV of each branch


6. Plan và Implement Risk Responses

7 Strategies cho Threats (Negative Risks)

Strategy

Mô tả

Ví dụ

Avoid

Eliminate threat entirely — change plan to remove risk

Change technology to avoid vendor dependency

Mitigate

Reduce probability and/or impact

Add testing phases, prototype, cross-training

Transfer

Shift impact to third party

Insurance, fixed-price contract, warranty

Accept (Active)

Acknowledge and prepare contingency

Allocate contingency reserve

Accept (Passive)

Acknowledge without specific action

"We'll deal with it if it happens"

Escalate

Beyond project scope — escalate to program/portfolio

Market risk affecting multiple projects

5 Strategies cho Opportunities (Positive Risks)

Strategy

Mô tả

Ví dụ

Exploit

Ensure opportunity IS realized

Assign best resources to capitalize

Enhance

Increase probability and/or impact

Add resources to accelerate time-to-market

Share

Allocate ownership to third party best positioned

Joint venture, partnership

Accept

Willing to take advantage if it occurs, no active pursuit

"Nice if it happens"

Escalate

Beyond project scope — escalate upward

Strategic opportunity for portfolio

Secondary và Residual Risks

Secondary risks = new risks CREATED by implementing a risk response. VD: transferring risk via insurance → secondary risk = insurance doesn't cover everything. Residual risks = risks REMAINING after response implemented. VD: mitigated vendor risk nhưng still 10% chance of delay. Cả hai phải được identified, analyzed, và planned.


7. Risk Register — Trái tim của risk management

PMBOK 8: Risk register bao gồm: list of identified risks (unique ID + structured description), potential risk owners, list of potential risk responses, probability and impact assessment, risk priority/ranking, response strategies, trigger conditions, và status tracking.

Maintain the Risk Register

Risk register là living document — updated liên tục: new risks added khi identified, existing risks re-assessed periodically, closed risks archived, responses updated based on effectiveness, và status tracked (active, triggered, closed, accepted).

ECO Example: "Maintain a risk register (e.g., poor IT security)" — IT security là ví dụ risk cần tracked: probability of breach, impact assessment, mitigation measures (encryption, access controls, penetration testing), residual risk level, và ongoing monitoring.


8. Monitor Risks và Communicate Status

Monitor Risks — PMBOK 8

PMBOK 8: "Monitor Risks is the process of monitoring the implementation of risk response plans, tracking identified risks, identifying and analyzing new risks, planning responses for new risks, and evaluating the effectiveness of risk responses throughout the project."

Monitoring activities: risk reviews (regular meetings to review top risks), risk audits (assess effectiveness of risk management process), reserve analysis (are contingency reserves adequate?), and technical performance analysis (compare actual vs planned technical metrics as risk indicators).

Communicate Risk Status

Audience

Cần biết gì

Format

Sponsor

Top 5 risks, overall exposure, decisions needed

Risk dashboard, RAG status

Steering Committee

Strategic risks, risk appetite alignment, escalated risks

Risk report, trend analysis

Team

Risks affecting their work, trigger conditions, response plans

Risk register excerpt, standup blockers

External stakeholders

Risks affecting them, mitigation status

Per communication plan

Predictive vs. Adaptive Risk Management

Aspect

Predictive

Adaptive

Identification

Upfront + periodic reviews

Continuous — each sprint planning + retrospective

Analysis

Formal P×I matrix, EMV, simulations

Story-level risk assessment, risk-adjusted backlog

Responses

Formal response plans, reserves

Spikes, timeboxed experiments, iterative mitigation

Monitoring

Risk reviews, audits, reserve analysis

Sprint retrospectives, daily standups, demos

Register

Formal risk register document

Risk board, risk-adjusted backlog items

PMBOK® 8 Adaptive Tailoring: "In agile, the team conducts risk assessments at the beginning of each sprint. Regular risk review meetings with stakeholders at the end of each iteration to incorporate feedback. Frequent, iterative risk management and risk-adjusted backlogs maintain alignment."


9. Mẹo thi PMP

📍Mẹo 1 — Avoid ≠ Ignore: "Avoid" = eliminate the threat (change plan). "Accept (passive)" = acknowledge without action. Khi đề hỏi "PM decides not to do anything about the risk" → passive acceptance, KHÔNG phải avoidance.

📍Mẹo 2 — Transfer ≠ Eliminate: Insurance, fixed-price contracts = transfer. Risk still EXISTS — ownership shifts. Khi đề hỏi "risk is transferred via contract" — the BUYER transferred cost risk to SELLER, nhưng risk vẫn tồn tại.

📍Mẹo 3 — EMV = Probability × Impact: Threat: 40% × -$200K = -$80K. Opportunity: 30% × +$100K = +$30K. Total EMV negative = need contingency. Đề thi hay tính EMV và hỏi "what is the project's risk exposure?"

📍Mẹo 4 — Contingency vs Management Reserve: Contingency = known-unknowns (identified risks), PM uses. Management reserve = unknown-unknowns (unidentified risks), senior management approval. Đề thi: "identified risk occurs" → contingency. "Unforeseen event" → management reserve.


10. Mười câu hỏi trắc nghiệm tình huống

Question 1

Your risk register identifies: Risk A (40% probability, $200K impact), Risk B (60% probability, $100K impact), Risk C (20% probability, $500K impact).

Which risk has the highest EMV and should be prioritized?

A. Risk A — EMV = $80K

B. Risk B — EMV = $60K

C. Risk C — EMV = $100K

D. Risk B — highest probability means highest priority

Question 2

Your construction project faces a risk of soil instability at the site. The geotechnical survey shows 30% chance of unstable soil that could add $1M to costs.

The PM decides to change the building location to a site with stable soil. What risk response strategy is this?

A. Mitigate — reducing the probability by changing locations

B. Avoid — eliminating the threat by changing the plan to remove the risk entirely

C. Transfer — moving the risk to the new site owner

D. Accept — acknowledging and budgeting for the possibility

Question 3

A key vendor supplies critical components. You're concerned about their financial stability (30% risk of default). You negotiate a fixed-price contract with penalty clauses and arrange a backup vendor agreement.

What risk response strategies are you using?

A. Avoidance and transfer

B. Transfer (fixed-price contract shifts cost risk) and Mitigation (backup vendor reduces impact if default occurs)

C. Mitigation only

D. Acceptance with contingency

Question 4

During execution, a risk you identified early (vendor delay) actually occurs. The risk register has a planned response: "Use internal team as backup for 2 weeks."

What should you do?

A. Reassess the risk before taking action.

B. Execute the planned response immediately, move the risk to the issue log, assess any secondary risks from using the internal team, and communicate status to stakeholders.

C. Submit a change request before implementing the response.

D. Escalate to the sponsor for approval.

Question 5

Your team identifies a potential opportunity: a new open-source library could reduce development time by 3 weeks. However, using it requires team training and has some stability concerns.

What opportunity response strategy is MOST appropriate?

A. Exploit — mandate the team to use the library immediately.

B. Enhance — invest in team training to increase the probability of successfully adopting the library, while conducting a stability evaluation to manage the associated threat.

C. Accept — use it if it works out naturally.

D. Share — partner with the open-source community.

Question 6

Your project has 50 identified risks. The team spends 4 hours every week reviewing all 50. Most risks haven't changed status in months. Team complains the meetings are unproductive.

How should you improve the risk monitoring process?

A. Reduce reviews to monthly.

B. Focus weekly reviews on TOP risks (highest exposure, nearest triggers, status changes). Review ALL risks monthly or at milestones. Close risks that are no longer relevant. Make reviews shorter and action-oriented.

C. Assign each risk to an owner and let them manage independently.

D. Use an automated dashboard that flags changes, eliminating the need for meetings.

Question 7

The project sponsor says: "Our organization has low risk appetite. I want zero risks on this project." The project involves new technology with inherent uncertainties.

How should you respond?

A. Implement maximum risk responses to eliminate all risks.

B. Explain that zero risk is impossible — all projects carry uncertainty. Low risk appetite means: aggressive identification, thorough analysis, proactive responses (avoid and mitigate where possible), and tight monitoring. Present the risk management plan showing how risks are managed within the organization's appetite threshold.

C. Switch to a proven technology to eliminate risk.

D. Add more contingency reserve to cover all risks.

Question 8

You implement a risk response (outsource a risky component). After implementation, you discover the outsourcing created a NEW risk: the vendor's work quality is inconsistent, requiring additional QA effort.

What type of risk is this?

A. Residual risk — remaining after response

B. Secondary risk — a new risk created BY the risk response

C. Unknown-unknown — couldn't have been anticipated

D. Trigger event — the original risk materializing

Question 9

Your agile team identifies a risk in Sprint 3 that the third-party API may not support required functionality. In predictive, this would go to the risk register with a formal response plan.

How should this be managed in agile?

A. Create a formal risk register entry and response plan.

B. Add a "spike" (timeboxed investigation) to the sprint backlog to evaluate the API's capabilities. If the risk is confirmed, create backlog items for mitigation (alternative API, custom development). Track on the risk board or as risk-adjusted backlog items.

C. Accept the risk and deal with it when it materializes.

D. Escalate to the Product Owner for a decision.

Question 10

At month 3 of a 12-month project, risk exposure has increased 40% from the original baseline. The risk register has grown from 20 to 35 risks. The PM hasn't updated the risk management plan or contingency reserves.

What is the BIGGEST concern?

A. Too many risks — the team is over-identifying.

B. Risk exposure growth of 40% with no corresponding update to contingency reserves or the risk management plan means the project is UNDER-PROTECTED. The PM should update the risk plan, reassess reserve adequacy, and communicate the changed risk profile to the sponsor.

C. The risk register is too large — reduce to top 20.

D. This is normal — risks emerge as the project progresses.

Đáp án

Question 1: Answer: C

— EMV: A = 0.4 × $200K = $80K. B = 0.6 × $100K = $60K. C = 0.2 × $500K = $100K. Risk C has highest EMV despite lowest probability — the massive impact outweighs the lower probability. Priority should be based on EMV, not probability alone.

Question 2: Answer: B

— Avoidance = change the plan to eliminate the threat entirely. By moving to stable soil, the soil instability risk no longer exists. Mitigation would be soil reinforcement (reduce probability/impact, not eliminate). Transfer would be insurance against soil issues.

Question 3: Answer: B

— Fixed-price contract = transfer (seller bears cost overrun risk). Backup vendor = mitigation (reduces impact of default, doesn't eliminate risk). Two complementary strategies addressing different aspects of the same risk.

Question 4: Answer: B

— The response was pre-approved when the risk plan was approved. PMBOK 8: "Implement Risk Responses ensures agreed-upon responses are executed as planned." No need for re-approval — act quickly. But DO assess secondary risks (internal team overloaded?) and communicate.

Question 5: Answer: B

— Enhance = increase probability and/or impact of an opportunity. Training increases adoption success. Stability evaluation manages the associated threat. Exploit (A) is too aggressive given stability concerns. Accept (C) is too passive for a significant opportunity.

Question 6: Answer: B

— Tailor the monitoring process. PMBOK 8: risk monitoring should be "appropriate to project size and complexity." Reviewing 50 unchanging risks weekly is overhead. Focus weekly reviews on active, high-priority risks. Keep full reviews periodic. Ownership (C) is good but needs coordination. Dashboard (D) helps but doesn't replace discussion.

Question 7: Answer: B

— PMBOK 8: "Risk appetite is the degree of uncertainty an organization is willing to accept." Zero risk is unrealistic — the PM should educate the sponsor and demonstrate a robust risk management approach aligned with low appetite. Switching technology (C) may avoid SOME risks but creates new ones.

Question 8: Answer: B

— Secondary risk = new risk arising directly from implementing a risk response. The response (outsource) created a new risk (vendor quality). PMBOK 8 requires identifying secondary risks when planning responses. Residual risk (A) would be if the original risk was partially addressed but some exposure remained.

Question 10: Answer: B

— PMBOK 8 Adaptive: "risk assessments at beginning of each sprint, risk-adjusted backlogs." A spike is the agile tool for investigating uncertainty — timeboxed, focused, actionable. Results inform the backlog. This is iterative risk management in action.

Question 8: Answer: B

— Risk identification growing is EXPECTED and healthy. But 40% exposure increase without updating reserves or plans = growing gap between risk exposure and protection. PMBOK 8: risk management is iterative — plans and reserves must be updated as risk profile changes. The sponsor needs to know the risk position has materially changed.


11. Tổng kết

Risk management là "hệ miễn dịch" của dự án — khi hoạt động tốt, dự án chống chịu được threats và tận dụng opportunities. Ba takeaways:

  1. 1. Risks = Threats + Opportunities — manage both — PM chỉ focus threats = bỏ lỡ 50% value. Opportunities cần Exploit, Enhance, Share — không chỉ "hope." PMBOK 8 cân bằng 6 threat strategies + 5 opportunity strategies. PM giỏi tìm cách maximize opportunities, không chỉ minimize threats.

  2. 2. Iterative, not once — risk management là continuous — Identify liên tục, analyze khi có thông tin mới, update responses khi bối cảnh thay đổi, monitor triggers, re-assess reserves. Risk register cũ 3 tháng = blind spots. PMBOK 8: "Iterative identification adapts to new information as the project progresses."

  3. 3. Quantify to prioritize — không phải mọi risk đều equal — EMV, P×I Matrix, Sensitivity Analysis cho phép PM tập trung vào risks thật sự quan trọng, không lãng phí effort vào low-exposure risks. Và contingency reserves phải match risk exposure — nếu exposure tăng 40% mà reserves không đổi, dự án đang under-protected.

PMBOK® 8, Section 2.7: "The Risk performance domain represents a comprehensive approach to creating project resilience by managing risk through risk management practices. This domain advocates for a proactive stance in planning for identified project risks, coupled with adaptive and flexible response mechanisms."

Câu Hỏi Thường Gặp (FAQ)

4 chiến lược ứng phó rủi ro (threats) trong PMBOK là gì?

Cho threats (rủi ro tiêu cực): Avoid — thay đổi plan để loại bỏ risk hoàn toàn; Transfer — chuyển giao risk cho bên thứ ba (insurance, contracts); Mitigate — giảm probability hoặc impact của risk; Accept — chấp nhận nếu cost of response > cost of risk. Cho opportunities (rủi ro tích cực): Exploit, Enhance, Share, Accept.

Risk Register và Risk Report khác nhau như thế nào?

Risk Register: document chi tiết từng risk — ID, description, probability, impact, risk score, owner, response strategy, contingency plan. Cập nhật thường xuyên, là working tool của PM. Risk Report: summary-level document dành cho management và steering committee — high-level status của top risks, overall risk exposure, và trend over time. Report xuất phát từ Register.

Agile project quản lý risks theo PMBOK 8 như thế nào?

Trong agile, risks được handle thông qua: Risk-based spike (sprint đặc biệt để investigate risk), Risk burndown chart (track risk exposure theo time), Risk-adjusted backlog (prioritize backlog items theo risk), và regular risk reviews trong Sprint Retrospectives. Agile không loại bỏ risk management — mà làm nó nimbler và more continuous.


Bạn đã nắm vững quản lý rủi ro dự án — giờ là lúc luyện tập với câu hỏi thi thật.

Làm thử đề PMP miễn phí →

Nguồn tham khảo chính thức:

Bạn đã sẵn sàng luyện tập chưa?

Thử CertFlow miễn phí — 10 câu hỏi, không cần đăng ký.

Bắt Đầu Miễn Phí
PMPPMBOK 8Plan and Manage RiskBusiness Environment DomainRisk ManagementRisk RegisterRisk ResponseProbability Impact Matrix