
Plan Risk Responses: Strategies for Threats and Opportunities
PMBOK v8 Definition
Plan Risk Responses is the process of developing options, selecting strategies, and agreeing on actions to address overall project risk exposure, as well as to treat individual project risks. The key benefit of this process is that it identifies suitable ways to address overall project risk and individual project risks. This process belongs to the Risk Performance Domain (not a traditional Process Group/Knowledge Area in PMBOK v8).
Why It Matters for the Exam
This concept appears frequently in PMI exam questions testing your ability to select the correct risk response strategy for a given scenario. Expect situational questions where you must differentiate between the five threat response strategies (avoid, mitigate, transfer, accept, escalate) and the five opportunity response strategies (exploit, enhance, share, accept, escalate). Common confusion points involve distinguishing transference from mitigation, and knowing when to use escalation versus acceptance.
Key Points to Remember (for the exam)
- Threat Response Strategies (5): Avoid, Mitigate, Transfer, Accept, Escalate
- Opportunity Response Strategies (5): Exploit, Enhance, Share, Accept, Escalate
- Escalation applies to both threats and opportunities: Used when the response is beyond the project manager's authority or requires action at program/portfolio level
- Acceptance applies to both threats and opportunities: Acknowledging the risk exists but taking no proactive action (passive = no action; active = contingency reserve)
- Key Outputs: Risk register updates, risk report updates, project management plan updates, and change requests
- Common Confusion: Transfer (threat) vs. Share (opportunity) – both involve a third party, but transfer shifts liability for a threat, while share involves partnering to capture an opportunity
- Critical Distinction: Avoidance eliminates the threat entirely (e.g., changing scope); Mitigation reduces probability or impact
Typical PMI Exam Example
Your project faces a high probability of supplier delays for a critical component. The supplier has a poor track record. As project manager, you decide to contract with an alternative supplier who guarantees on-time delivery, even at higher cost. This is an example of which threat response strategy?
Answer: Avoidance – because you are eliminating the threat by removing the unreliable supplier from the equation entirely.
PMI Exam Traps
-
Trap: Confusing "Transfer" with "Mitigate" Reality: Transfer shifts financial liability to a third party (insurance, warranty, performance bond). Mitigate reduces probability or impact but does not shift liability.
-
Trap: Thinking "Accept" means ignoring the risk Reality: Acceptance is a deliberate strategy. Passive acceptance = no action; active acceptance = establishing contingency reserves or fallback plans.
-
Trap: Using "Exploit" when "Enhance" is correct Reality: Exploit ensures the opportunity definitely happens (e.g., assigning best talent). Enhance increases probability or impact without guaranteeing occurrence.
-
Trap: Escalation is only for threats Reality: Escalation applies to both threats and opportunities when the response is outside the project's authority.
Important PMI Connections
| Related Concept | Relationship Type | Exam Attention Point |
|---|---|---|
| Implement Risk Responses | Output to | Plan Risk Responses produces plans; Implement Risk Responses executes those plans |
| Monitor Risks | Follows sequentially | After implementing responses, Monitor Risks tracks effectiveness and identifies new risks |
| Risk Register | Input to | Contains identified risks that need response strategies assigned |
| Risk Report | Input to | Provides overall project risk exposure analysis to inform response selection |
Quick Review Questions
-
A key supplier goes bankrupt. Your project team decides to self-insure by creating a contingency fund. Which risk response strategy is being used?
-
Your project identifies an opportunity to complete the project two months early if a new technology is adopted. You decide to assign your most experienced developer to ensure this happens. Which opportunity response strategy is this?
-
A threat has a probability of 0.8 and impact of $50,000. You purchase insurance for $5,000. Is this mitigation or transference? Why?
-
During Plan Risk Responses, you identify a threat that requires action at the organizational level. What strategy should you use?
-
Your team decides to do nothing about a low-probability, low-impact threat. They document it in the risk register but take no action. Is this active or passive acceptance?
PMBOK v8 Reference
Section 2.7.2.4 – Plan Risk Responses (Risk Performance Domain)