PMBOK 8 nhìn rủi ro theo hai chiều: threats cần mitigate và opportunities cần exploit. Bài này đi qua risk management toàn diện theo góc nhìn PMBOK 8 thực chiến.
1. Rủi ro = Threats + Opportunities
Sai lầm lớn nhất của PM là chỉ nghĩ rủi ro là "thứ xấu." PMBOK 8 định nghĩa rõ:
PMBOK® 8, Section 2.7.1: "A risk is an uncertain event or condition that, if it occurs, has a positive or negative effect on one or more project objectives. Potentially harmful risks, often called threats, may negatively impact objectives. Positive risks, better known as opportunities, may positively affect objectives."
PM phải quản lý CẢ HAI: minimize threats VÀ maximize opportunities.
4 loại rủi ro theo Knowledge Matrix
Known | Unknown | |
|---|---|---|
Known | Known-Known — Facts, certainties. VD: cần 5 developers. | Known-Unknown — Identified risks. VD: vendor CÓ THỂ trễ. → Contingency reserve |
Unknown | Unknown-Known — Unconscious knowledge, biases. VD: team biết vấn đề nhưng chưa nói. | Unknown-Unknown — Black swans. VD: pandemic, earthquake. → Management reserve |
2. Khái niệm nền tảng — Risk Appetite, Threshold, Exposure
Concept | Định nghĩa PMBOK 8 | Ví dụ |
|---|---|---|
Risk Appetite | "The degree of uncertainty an organization is willing to accept in anticipation of a reward" | Startup: high appetite (innovate fast). Bank: low appetite (protect assets). |
Risk Threshold | "The measure of acceptable variation around an objective reflecting risk appetite" | ±5% cost variance = low threshold. ±15% = high threshold. |
Risk Exposure | "An aggregate measure of the potential impact of all risks at any given point in time" | Total EMV of all identified risks = $500K exposure. |
Risk Tolerance | Organization's or stakeholder's ability to ENDURE risk — closely related to appetite | Organization has $2M reserve → can tolerate $500K exposure. |
3. Sáu quy trình quản lý rủi ro theo PMBOK 8
Bước | Process | Mục đích | Khi nào |
|---|---|---|---|
1 | Plan Risk Management | Define how to conduct risk activities | Project conception → early planning |
2 | Identify Risks | Recognize threats and opportunities | Iteratively throughout project |
3 | Perform Risk Analysis | Evaluate probability, impact, priority | After identification, iteratively |
4 | Plan Risk Responses | Develop strategies for each risk | Throughout project |
5 | Implement Risk Responses | Execute agreed-upon response plans | When triggers occur or proactively |
6 | Monitor Risks | Track, review, evaluate effectiveness | Continuously |
4. Identify Risks — Tìm kiếm liên tục
PMBOK 8: "An important part of the Identify Risks process is separating real risks from concerns, knowing initial identification is incomplete. Iterative identification adapts to new information as the project progresses."
Risk Identification Tools
- Brainstorming — Team generates risks freely, không judge
- Checklists — From historical data, similar projects, industry knowledge
- SWOT Analysis — Strengths, Weaknesses (internal) + Opportunities, Threats (external)
- Interviews — SMEs, experienced PMs, stakeholders
- Assumption and Constraint Analysis — PMBOK 8: "Explores the validity of assumptions and constraints to determine which pose a risk"
- Root Cause Analysis — Identify underlying causes that could generate multiple risks
- AI-powered risk identification — PMBOK 8 mới: "GenAI and data analytics for comprehensive risk identification"
Risk Breakdown Structure (RBS)
PMBOK 8: RBS phân loại risks theo categories: Technical, External, Organizational, Project Management. Mỗi category có subcategories — giúp đảm bảo identification comprehensive, không bỏ sót areas.
5. Analyze Risks — Qualitative và Quantitative
Qualitative Risk Analysis
Đánh giá mỗi risk theo Probability × Impact. PMBOK 8: "Qualitative analysis evaluates risks based on their probability and impact throughout the project."
Probability and Impact Matrix:
Very Low Impact | Low | Medium | High | Very High | |
|---|---|---|---|---|---|
Very High Prob | Medium | High | High | Critical | Critical |
High Prob | Low | Medium | High | High | Critical |
Medium Prob | Low | Medium | Medium | High | High |
Low Prob | Very Low | Low | Medium | Medium | High |
Very Low Prob | Very Low | Very Low | Low | Low | Medium |
Quantitative Risk Analysis
PMBOK 8: "Quantitative analysis numerically analyzes the combined effect of identified risks and other sources of uncertainty on overall project objectives."
Tool | Mô tả | Output |
|---|---|---|
EMV (Expected Monetary Value) | Probability × Impact ($). VD: 30% × -$100K = -$30K | Dollar value per risk, sum = total exposure |
Sensitivity Analysis (Tornado) | Which risk has MOST impact on objectives? | Tornado diagram ranking risks by impact |
Monte Carlo Simulation | Run thousands of scenarios to determine probability distributions | "80% chance project finishes by March 15" |
Decision Tree Analysis | Compare options with different risk profiles | Best path based on EMV of each branch |
6. Plan và Implement Risk Responses
7 Strategies cho Threats (Negative Risks)
Strategy | Mô tả | Ví dụ |
|---|---|---|
Avoid | Eliminate threat entirely — change plan to remove risk | Change technology to avoid vendor dependency |
Mitigate | Reduce probability and/or impact | Add testing phases, prototype, cross-training |
Transfer | Shift impact to third party | Insurance, fixed-price contract, warranty |
Accept (Active) | Acknowledge and prepare contingency | Allocate contingency reserve |
Accept (Passive) | Acknowledge without specific action | "We'll deal with it if it happens" |
Escalate | Beyond project scope — escalate to program/portfolio | Market risk affecting multiple projects |
5 Strategies cho Opportunities (Positive Risks)
Strategy | Mô tả | Ví dụ |
|---|---|---|
Exploit | Ensure opportunity IS realized | Assign best resources to capitalize |
Enhance | Increase probability and/or impact | Add resources to accelerate time-to-market |
Share | Allocate ownership to third party best positioned | Joint venture, partnership |
Accept | Willing to take advantage if it occurs, no active pursuit | "Nice if it happens" |
Escalate | Beyond project scope — escalate upward | Strategic opportunity for portfolio |
Secondary và Residual Risks
Secondary risks = new risks CREATED by implementing a risk response. VD: transferring risk via insurance → secondary risk = insurance doesn't cover everything. Residual risks = risks REMAINING after response implemented. VD: mitigated vendor risk nhưng still 10% chance of delay. Cả hai phải được identified, analyzed, và planned.
7. Risk Register — Trái tim của risk management
PMBOK 8: Risk register bao gồm: list of identified risks (unique ID + structured description), potential risk owners, list of potential risk responses, probability and impact assessment, risk priority/ranking, response strategies, trigger conditions, và status tracking.
Maintain the Risk Register
Risk register là living document — updated liên tục: new risks added khi identified, existing risks re-assessed periodically, closed risks archived, responses updated based on effectiveness, và status tracked (active, triggered, closed, accepted).
ECO Example: "Maintain a risk register (e.g., poor IT security)" — IT security là ví dụ risk cần tracked: probability of breach, impact assessment, mitigation measures (encryption, access controls, penetration testing), residual risk level, và ongoing monitoring.
8. Monitor Risks và Communicate Status
Monitor Risks — PMBOK 8
PMBOK 8: "Monitor Risks is the process of monitoring the implementation of risk response plans, tracking identified risks, identifying and analyzing new risks, planning responses for new risks, and evaluating the effectiveness of risk responses throughout the project."
Monitoring activities: risk reviews (regular meetings to review top risks), risk audits (assess effectiveness of risk management process), reserve analysis (are contingency reserves adequate?), and technical performance analysis (compare actual vs planned technical metrics as risk indicators).
Communicate Risk Status
Audience | Cần biết gì | Format |
|---|---|---|
Sponsor | Top 5 risks, overall exposure, decisions needed | Risk dashboard, RAG status |
Steering Committee | Strategic risks, risk appetite alignment, escalated risks | Risk report, trend analysis |
Team | Risks affecting their work, trigger conditions, response plans | Risk register excerpt, standup blockers |
External stakeholders | Risks affecting them, mitigation status | Per communication plan |
Predictive vs. Adaptive Risk Management
Aspect | Predictive | Adaptive |
|---|---|---|
Identification | Upfront + periodic reviews | Continuous — each sprint planning + retrospective |
Analysis | Formal P×I matrix, EMV, simulations | Story-level risk assessment, risk-adjusted backlog |
Responses | Formal response plans, reserves | Spikes, timeboxed experiments, iterative mitigation |
Monitoring | Risk reviews, audits, reserve analysis | Sprint retrospectives, daily standups, demos |
Register | Formal risk register document | Risk board, risk-adjusted backlog items |
PMBOK® 8 Adaptive Tailoring: "In agile, the team conducts risk assessments at the beginning of each sprint. Regular risk review meetings with stakeholders at the end of each iteration to incorporate feedback. Frequent, iterative risk management and risk-adjusted backlogs maintain alignment."
9. Mẹo thi PMP
📍Mẹo 1 — Avoid ≠ Ignore: "Avoid" = eliminate the threat (change plan). "Accept (passive)" = acknowledge without action. Khi đề hỏi "PM decides not to do anything about the risk" → passive acceptance, KHÔNG phải avoidance.
📍Mẹo 2 — Transfer ≠ Eliminate: Insurance, fixed-price contracts = transfer. Risk still EXISTS — ownership shifts. Khi đề hỏi "risk is transferred via contract" — the BUYER transferred cost risk to SELLER, nhưng risk vẫn tồn tại.
📍Mẹo 3 — EMV = Probability × Impact: Threat: 40% × -$200K = -$80K. Opportunity: 30% × +$100K = +$30K. Total EMV negative = need contingency. Đề thi hay tính EMV và hỏi "what is the project's risk exposure?"
📍Mẹo 4 — Contingency vs Management Reserve: Contingency = known-unknowns (identified risks), PM uses. Management reserve = unknown-unknowns (unidentified risks), senior management approval. Đề thi: "identified risk occurs" → contingency. "Unforeseen event" → management reserve.
10. Mười câu hỏi trắc nghiệm tình huống
Question 1
Your risk register identifies: Risk A (40% probability, $200K impact), Risk B (60% probability, $100K impact), Risk C (20% probability, $500K impact).
Which risk has the highest EMV and should be prioritized?
A. Risk A — EMV = $80K
B. Risk B — EMV = $60K
C. Risk C — EMV = $100K
D. Risk B — highest probability means highest priority
Question 2
Your construction project faces a risk of soil instability at the site. The geotechnical survey shows 30% chance of unstable soil that could add $1M to costs.
The PM decides to change the building location to a site with stable soil. What risk response strategy is this?
A. Mitigate — reducing the probability by changing locations
B. Avoid — eliminating the threat by changing the plan to remove the risk entirely
C. Transfer — moving the risk to the new site owner
D. Accept — acknowledging and budgeting for the possibility
Question 3
A key vendor supplies critical components. You're concerned about their financial stability (30% risk of default). You negotiate a fixed-price contract with penalty clauses and arrange a backup vendor agreement.
What risk response strategies are you using?
A. Avoidance and transfer
B. Transfer (fixed-price contract shifts cost risk) and Mitigation (backup vendor reduces impact if default occurs)
C. Mitigation only
D. Acceptance with contingency
Question 4
During execution, a risk you identified early (vendor delay) actually occurs. The risk register has a planned response: "Use internal team as backup for 2 weeks."
What should you do?
A. Reassess the risk before taking action.
B. Execute the planned response immediately, move the risk to the issue log, assess any secondary risks from using the internal team, and communicate status to stakeholders.
C. Submit a change request before implementing the response.
D. Escalate to the sponsor for approval.
Question 5
Your team identifies a potential opportunity: a new open-source library could reduce development time by 3 weeks. However, using it requires team training and has some stability concerns.
What opportunity response strategy is MOST appropriate?
A. Exploit — mandate the team to use the library immediately.
B. Enhance — invest in team training to increase the probability of successfully adopting the library, while conducting a stability evaluation to manage the associated threat.
C. Accept — use it if it works out naturally.
D. Share — partner with the open-source community.
Question 6
Your project has 50 identified risks. The team spends 4 hours every week reviewing all 50. Most risks haven't changed status in months. Team complains the meetings are unproductive.
How should you improve the risk monitoring process?
A. Reduce reviews to monthly.
B. Focus weekly reviews on TOP risks (highest exposure, nearest triggers, status changes). Review ALL risks monthly or at milestones. Close risks that are no longer relevant. Make reviews shorter and action-oriented.
C. Assign each risk to an owner and let them manage independently.
D. Use an automated dashboard that flags changes, eliminating the need for meetings.
Question 7
The project sponsor says: "Our organization has low risk appetite. I want zero risks on this project." The project involves new technology with inherent uncertainties.
How should you respond?
A. Implement maximum risk responses to eliminate all risks.
B. Explain that zero risk is impossible — all projects carry uncertainty. Low risk appetite means: aggressive identification, thorough analysis, proactive responses (avoid and mitigate where possible), and tight monitoring. Present the risk management plan showing how risks are managed within the organization's appetite threshold.
C. Switch to a proven technology to eliminate risk.
D. Add more contingency reserve to cover all risks.
Question 8
You implement a risk response (outsource a risky component). After implementation, you discover the outsourcing created a NEW risk: the vendor's work quality is inconsistent, requiring additional QA effort.
What type of risk is this?
A. Residual risk — remaining after response
B. Secondary risk — a new risk created BY the risk response
C. Unknown-unknown — couldn't have been anticipated
D. Trigger event — the original risk materializing
Question 9
Your agile team identifies a risk in Sprint 3 that the third-party API may not support required functionality. In predictive, this would go to the risk register with a formal response plan.
How should this be managed in agile?
A. Create a formal risk register entry and response plan.
B. Add a "spike" (timeboxed investigation) to the sprint backlog to evaluate the API's capabilities. If the risk is confirmed, create backlog items for mitigation (alternative API, custom development). Track on the risk board or as risk-adjusted backlog items.
C. Accept the risk and deal with it when it materializes.
D. Escalate to the Product Owner for a decision.
Question 10
At month 3 of a 12-month project, risk exposure has increased 40% from the original baseline. The risk register has grown from 20 to 35 risks. The PM hasn't updated the risk management plan or contingency reserves.
What is the BIGGEST concern?
A. Too many risks — the team is over-identifying.
B. Risk exposure growth of 40% with no corresponding update to contingency reserves or the risk management plan means the project is UNDER-PROTECTED. The PM should update the risk plan, reassess reserve adequacy, and communicate the changed risk profile to the sponsor.
C. The risk register is too large — reduce to top 20.
D. This is normal — risks emerge as the project progresses.
Đáp án
Question 1: Answer: C
— EMV: A = 0.4 × $200K = $80K. B = 0.6 × $100K = $60K. C = 0.2 × $500K = $100K. Risk C has highest EMV despite lowest probability — the massive impact outweighs the lower probability. Priority should be based on EMV, not probability alone.
Question 2: Answer: B
— Avoidance = change the plan to eliminate the threat entirely. By moving to stable soil, the soil instability risk no longer exists. Mitigation would be soil reinforcement (reduce probability/impact, not eliminate). Transfer would be insurance against soil issues.
Question 3: Answer: B
— Fixed-price contract = transfer (seller bears cost overrun risk). Backup vendor = mitigation (reduces impact of default, doesn't eliminate risk). Two complementary strategies addressing different aspects of the same risk.
Question 4: Answer: B
— The response was pre-approved when the risk plan was approved. PMBOK 8: "Implement Risk Responses ensures agreed-upon responses are executed as planned." No need for re-approval — act quickly. But DO assess secondary risks (internal team overloaded?) and communicate.
Question 5: Answer: B
— Enhance = increase probability and/or impact of an opportunity. Training increases adoption success. Stability evaluation manages the associated threat. Exploit (A) is too aggressive given stability concerns. Accept (C) is too passive for a significant opportunity.
Question 6: Answer: B
— Tailor the monitoring process. PMBOK 8: risk monitoring should be "appropriate to project size and complexity." Reviewing 50 unchanging risks weekly is overhead. Focus weekly reviews on active, high-priority risks. Keep full reviews periodic. Ownership (C) is good but needs coordination. Dashboard (D) helps but doesn't replace discussion.
Question 7: Answer: B
— PMBOK 8: "Risk appetite is the degree of uncertainty an organization is willing to accept." Zero risk is unrealistic — the PM should educate the sponsor and demonstrate a robust risk management approach aligned with low appetite. Switching technology (C) may avoid SOME risks but creates new ones.
Question 8: Answer: B
— Secondary risk = new risk arising directly from implementing a risk response. The response (outsource) created a new risk (vendor quality). PMBOK 8 requires identifying secondary risks when planning responses. Residual risk (A) would be if the original risk was partially addressed but some exposure remained.
Question 10: Answer: B
— PMBOK 8 Adaptive: "risk assessments at beginning of each sprint, risk-adjusted backlogs." A spike is the agile tool for investigating uncertainty — timeboxed, focused, actionable. Results inform the backlog. This is iterative risk management in action.
Question 8: Answer: B
— Risk identification growing is EXPECTED and healthy. But 40% exposure increase without updating reserves or plans = growing gap between risk exposure and protection. PMBOK 8: risk management is iterative — plans and reserves must be updated as risk profile changes. The sponsor needs to know the risk position has materially changed.
11. Tổng kết
Risk management là "hệ miễn dịch" của dự án — khi hoạt động tốt, dự án chống chịu được threats và tận dụng opportunities. Ba takeaways:
1. Risks = Threats + Opportunities — manage both — PM chỉ focus threats = bỏ lỡ 50% value. Opportunities cần Exploit, Enhance, Share — không chỉ "hope." PMBOK 8 cân bằng 6 threat strategies + 5 opportunity strategies. PM giỏi tìm cách maximize opportunities, không chỉ minimize threats.
2. Iterative, not once — risk management là continuous — Identify liên tục, analyze khi có thông tin mới, update responses khi bối cảnh thay đổi, monitor triggers, re-assess reserves. Risk register cũ 3 tháng = blind spots. PMBOK 8: "Iterative identification adapts to new information as the project progresses."
3. Quantify to prioritize — không phải mọi risk đều equal — EMV, P×I Matrix, Sensitivity Analysis cho phép PM tập trung vào risks thật sự quan trọng, không lãng phí effort vào low-exposure risks. Và contingency reserves phải match risk exposure — nếu exposure tăng 40% mà reserves không đổi, dự án đang under-protected.
PMBOK® 8, Section 2.7: "The Risk performance domain represents a comprehensive approach to creating project resilience by managing risk through risk management practices. This domain advocates for a proactive stance in planning for identified project risks, coupled with adaptive and flexible response mechanisms."
Câu Hỏi Thường Gặp (FAQ)
4 chiến lược ứng phó rủi ro (threats) trong PMBOK là gì?
Cho threats (rủi ro tiêu cực): Avoid — thay đổi plan để loại bỏ risk hoàn toàn; Transfer — chuyển giao risk cho bên thứ ba (insurance, contracts); Mitigate — giảm probability hoặc impact của risk; Accept — chấp nhận nếu cost of response > cost of risk. Cho opportunities (rủi ro tích cực): Exploit, Enhance, Share, Accept.
Risk Register và Risk Report khác nhau như thế nào?
Risk Register: document chi tiết từng risk — ID, description, probability, impact, risk score, owner, response strategy, contingency plan. Cập nhật thường xuyên, là working tool của PM. Risk Report: summary-level document dành cho management và steering committee — high-level status của top risks, overall risk exposure, và trend over time. Report xuất phát từ Register.
Agile project quản lý risks theo PMBOK 8 như thế nào?
Trong agile, risks được handle thông qua: Risk-based spike (sprint đặc biệt để investigate risk), Risk burndown chart (track risk exposure theo time), Risk-adjusted backlog (prioritize backlog items theo risk), và regular risk reviews trong Sprint Retrospectives. Agile không loại bỏ risk management — mà làm nó nimbler và more continuous.
Bạn đã nắm vững quản lý rủi ro dự án — giờ là lúc luyện tập với câu hỏi thi thật.
Bài tiếp theo: Cải Tiến Liên Tục: Lessons Learned, OPAs & PDCA theo PMBOK 8
Nguồn tham khảo chính thức:
Bạn đã sẵn sàng luyện tập chưa?
Thử CertFlow miễn phí — 10 câu hỏi, không cần đăng ký.
Bắt Đầu Miễn Phí


