Considerations Risk Size in Tailoring for Project Management

Considerations Risk Size in Tailoring for Project Management

PMBOK v8 Definition

Project size and complexity are critical tailoring considerations within the Risk performance domain. PMBOK v8 states that because each project is unique, activities and processes in the Risk performance domain should be tailored, specifically requiring the project team to "Determine if the project's size or complexity necessitates a more detailed risk management approach or if a simplified process suffices." This determination is driven by the guiding project management principles, where organizations with low risk appetite implement structured processes and oversight mechanisms, while those with higher risk tolerance prioritize agility and decision-making autonomy.

Why It Matters for the Exam

The concept of tailoring risk management based on project size and complexity appears frequently in PMI exam questions about adaptation, process customization, and situational leadership. Exam questions typically present a scenario with a specific project context (small vs. large, simple vs. complex) and ask which risk approach is most appropriate. Understanding that risk management is not "one size fits all" but must be calibrated to project characteristics is essential for scoring well on situational judgment questions.

Key Points to Remember (for the exam)

  • Core Principle: Project size and complexity determine whether a detailed or simplified risk management approach is appropriate—never apply a fixed number of procedures without tailoring.

  • Organizational Risk Appetite Driver: Low risk appetite organizations implement structured processes and oversight; high risk tolerance organizations prioritize agility and decision-making autonomy.

  • Tailoring Factors: The tailoring process considers project context, goals, operating environment, scale, and complexity to determine which elements are most useful.

  • Suitability Filter Tool: A suitability filter is a decision-making tool (not a rigid method) that helps project teams evaluate circumstances and determine the best fit among predictive, adaptive, or hybrid approaches.

  • Risk Report Content: After Identify Risks, the risk report includes sources of overall project risk (most important drivers) and summary information on identified individual project risks (threats and opportunities distribution across categories).

  • Common Confusion: Tailoring is NOT about eliminating risk management—it is about adjusting rigor based on project needs. Simplified does not mean absent; detailed does not mean bureaucratic.

  • Ongoing Process: Tailoring is not a one-time decision—it involves selecting initial development approach, tailoring for organization, tailoring for project, and implementing ongoing improvement (Figure 3-1).

Typical PMI Exam Example

A project manager is assigned to a small, low-complexity software enhancement project for an organization with high risk tolerance. The team has only three members and a six-week timeline. The PMO standard requires a full risk register with probability-impact matrix. What should the project manager do?

Correct approach: Tailor the risk management process by using a simplified risk identification and response approach, as the project size and complexity do not necessitate a detailed risk management process.

PMI Exam Traps

  • Trap: Assuming all projects require the same level of risk documentation regardless of size. Reality: Project size and complexity dictate whether a detailed or simplified risk approach suffices—small projects can use simplified processes.

  • Trap: Confusing "simplified process" with "no risk management." Reality: Simplified still includes risk identification and response, just with less rigor and formality appropriate to project scale.

  • Trap: Thinking tailoring is only about choosing predictive vs. adaptive approaches. Reality: Tailoring includes adjusting risk management activities, processes, documentation, and oversight based on project size, complexity, and organizational risk appetite.

  • Trap: Applying the same risk management approach for all projects in an organization with low risk appetite. Reality: Even in low-risk-appetite organizations, project size and complexity determine the level of detail—not all projects need the same structured processes.

Important PMI Connections

Related ConceptRelationship TypeExam Attention Point
Organizational Risk AppetiteDriver of tailoringLow appetite → structured processes; high tolerance → agility with autonomy
Suitability FilterDecision-making toolHelps determine predictive, adaptive, or hybrid approach based on project characteristics
Risk Report (Output of Identify Risks)Contains tailored risk informationSources of overall project risk + summary of individual risks (threats/opportunities)
Perform Risk AnalysisProcess influenced by tailoringLevel of detail in analysis depends on project size and complexity

Quick Review Questions

  1. A project with low complexity and a small team is being initiated. The organization has a moderate risk appetite. What should the project manager consider when tailoring the risk management approach?

  2. What is the primary difference between how organizations with low risk appetite versus high risk tolerance approach risk management tailoring?

  3. During which step of the tailoring process does the project team evaluate whether a detailed or simplified risk management approach is needed?

  4. A project manager is using a suitability filter. What is the purpose of this tool in the context of risk management tailoring?

  5. After completing the Identify Risks process, what two types of information should be included in the risk report according to PMBOK v8?

PMBOK v8 Reference

Section 2.7.3 - Tailoring Considerations (Risk Performance Domain) Section 3.1 - Overview (Tailoring Process)