Project Risk: Team-Defined Thresholds and Continuous Management

Project Risk: Team-Defined Thresholds and Continuous Management

PMBOK v8 Definition

Project Risk is a performance domain encompassing the processes required to conduct risk management planning, identification, analysis, response planning, response implementation, and risk reviews on a project. The team defines the risk thresholds of the project and participates in subsequent risk management activities. The objectives are to increase the probability and impact of positive risks while decreasing the probability and impact of negative risks, accelerating project resilience, reducing uncertainty, and increasing the chances of project success.

Why It Matters for the Exam

Risk management appears in approximately 15-20% of PMI exam questions, making it one of the most heavily tested performance domains. Questions frequently test the sequence of risk processes, the distinction between individual project risks and overall project risk, and the specific outputs produced at each stage. Expect scenario-based questions asking you to identify the correct next step in the risk management process.

Key Points to Remember (for the exam)

  • Risk Threshold Definition: The team defines the risk thresholds early in the project. This is not imposed by the project manager alone—it is a team responsibility.

  • Core Processes (in order):

    • Plan Risk Management
    • Identify Risks
    • Perform Risk Analysis (qualitative and quantitative)
    • Plan Risk Responses
    • Implement Risk Responses
    • Monitor Risks
  • Risk Management Plan Components (frequently tested):

    • Risk strategy (general approach)
    • Methodology (specific approaches, tools, data sources)
    • Roles and responsibilities (lead, support, team members)
    • Funding (funds needed for risk activities)
  • Risk Report: Progressive output developed throughout risk processes. Contains sources of overall project risk, summary information on identified individual risks, and results from Perform Risk Analysis, Plan Risk Responses, Implement Risk Responses, and Monitor Risks.

  • Positive vs. Negative Risk: The domain explicitly addresses both—increasing probability/impact of positive risks (opportunities) while decreasing probability/impact of negative risks (threats).

  • Key Inputs for Perform Risk Analysis: Risk management plan, scope baseline, schedule baseline, cost baseline, assumption log, cost estimates, duration estimates, resource requirements, risk register, stakeholder register.

  • Continuous Process: Risk management starts at project conception and continues throughout the project lifecycle. Risk reviews are performed on an ongoing basis.

Typical PMI Exam Example

A project team is beginning risk management activities on a new software development project. The project manager asks the team to define the levels of risk the organization is willing to accept. According to PMBOK v8, what should the team establish first?

Answer: The team should define the risk thresholds of the project during Plan Risk Management. These thresholds will guide all subsequent risk identification, analysis, and response activities.

PMI Exam Traps

  • Trap: Thinking the project manager alone defines risk thresholds

    • Reality: The team defines the risk thresholds and participates in all subsequent risk activities
  • Trap: Confusing the Risk Management Plan with the Risk Register

    • Reality: The Risk Management Plan outlines how to conduct risk activities (methodology, roles, funding). The Risk Register contains identified risks and their details.
  • Trap: Believing risk management is a one-time planning activity

    • Reality: Risk management is performed throughout the project, starting at conception, with continuous reviews and updates
  • Trap: Treating opportunities and threats with the same response strategies

    • Reality: The domain explicitly separates strategies for managing threats, strategies for managing opportunities, and strategies for managing overall project risk

Important PMI Connections

Related ConceptRelationship TypeExam Attention Point
Stakeholder EngagementInput to risk identificationStakeholder register is a key input for risk analysis; stakeholders influence risk thresholds
Resource ManagementComplementary domainTeams restrict/enable access to resources; resource requirements feed risk analysis
Scope/Schedule/Cost BaselinesInputs to Perform Risk AnalysisThese baselines are essential inputs—changes to baselines trigger risk reassessment
Quality ManagementLinked through risk responsesRisk responses may affect quality requirements; quality risks are a subset of project risks

Quick Review Questions

  1. What are the six processes included in the Risk performance domain, and in what order should they be performed?

  2. Which document is developed progressively throughout the risk processes and includes results from multiple risk activities?

  3. What are the four components of the Risk Management Plan that are specifically listed in PMBOK v8?

  4. A project team is about to begin risk identification. What key documents should they have ready as inputs?

  5. What is the difference between managing individual project risks and managing overall project risk?

PMBOK v8 Reference

Section 2 – Project Management Performance Domains (Risk Performance Domain) Section 3 – Project Management Principles (Team defines risk thresholds)