
Risk Breakdown Structure (RBS): Grouping Project Risks by Categories
PMBOK v8 Definition
Risk categories provide a means for grouping individual project risks. A common way to structure risk categories is with a risk breakdown structure (RBS), which is a hierarchical representation of potential sources of risk. An RBS helps the project team consider the full range of sources from which individual project risks may arise, and can be useful when identifying risks or when categorizing identified risks.
Why It Matters for the Exam
The RBS appears frequently in PMI exam questions about Identify Risks and Plan Risk Responses. Questions test your understanding of how risk categories help develop more effective risk responses by focusing attention on areas of highest risk exposure, and whether you can distinguish the RBS from the Work Breakdown Structure (WBS) and other categorization frameworks.
Key Points to Remember (for the exam)
- Primary Purpose: Group individual project risks by source (not by project deliverables)
- Common Structure: Hierarchical representation of potential sources of risk (e.g., Technical, External, Organizational, Project Management)
- Main Input to: Identify Risks process (Risk Management Knowledge Area)
- Key Output: Risk categories are defined in the Risk Management Plan
- Flexibility: Organization may have a generic RBS, multiple RBS frameworks for different project types, or a tailored RBS for the specific project
- Alternative Frameworks: If RBS is not used, may use custom categorization based on: WBS (area affected), project phase, project budget, roles and responsibilities, or common root causes
- Key Benefit: Grouping risks into categories leads to developing generic risk responses to address groups of related risks
Typical PMI Exam Example
A project manager is identifying risks for a construction project. She notices several risks related to permits, environmental regulations, and legislation. Which risk category should these be grouped under in the RBS?
Answer: External Risk (category 4 in the sample RBS), specifically subcategories 4.1 Legislation, 4.4 Environmental/weather, and 4.6 Regulatory.
PMI Exam Traps
-
Trap: Confusing RBS with WBS
- Reality: RBS groups risks by source (hierarchical sources of risk); WBS groups work by deliverables (hierarchical decomposition of project scope)
-
Trap: Thinking the RBS is a mandatory output of Identify Risks
- Reality: The RBS is a tool (risk categorization framework), not an output. The organization may already have a generic RBS, or the project may develop a tailored one
-
Trap: Assuming all projects use the same RBS
- Reality: The organization may have a generic RBS, multiple RBS frameworks for different project types, or the project may develop a tailored RBS
-
Trap: Believing risk categories are only based on source (RBS)
- Reality: Risks can also be categorized by area affected (WBS), project phase, budget, roles, or common root causes
Important PMI Connections
| Related Concept | Relationship Type | Exam Attention Point |
|---|---|---|
| Risk Management Plan | Contains risk categories | The RBS or custom categorization framework is defined in this plan |
| Identify Risks | Process using RBS | RBS helps identify and categorize risks; outputs include risk register |
| Work Breakdown Structure (WBS) | Alternative categorization method | Risks can be categorized by WBS area (not just RBS source) |
| Risk Responses | Outcome of categorization | Grouping risks leads to generic risk responses for related risks |
Quick Review Questions
-
What is the primary difference between an RBS and a WBS in project risk management?
-
During which process are risk categories (including the RBS) defined and documented?
-
A project team identifies several risks related to subcontractors, client stability, and partnerships. Under which major RBS category would these be grouped?
-
True or False: The RBS is a mandatory output of the Identify Risks process.
-
What are three alternative ways to categorize project risks if an RBS is not used?
PMBOK v8 Reference
Section 4 – Inputs and Outputs (Figure 4-5: Excerpt From a Sample Risk Breakdown Structure)
Section 2.4 – Finance Performance Domain
Section 5 – Tools and Techniques (Risk categorization, Risk probability and impact assessment)