Risk Management Process: Planning, Identification, Analysis, Response & Monitoring

Risk Management Process: Planning, Identification, Analysis, Response & Monitoring

PMBOK v8 Definition

Risk management in a project requires conducting risk management planning, identification, analysis, response planning, response implementation, and risk reviews throughout the project. The processes include: Plan Risk Management (defines how to conduct risk management activities), Identify Risks, Perform Risk Analysis, Plan Risk Responses, Implement Risk Responses (executing risk plans to address risks, minimize threats, maximize opportunities), and Monitor Risks (tracking and analyzing risks, implementing response plans, evaluating effectiveness). These processes are performed across the Project Performance Domains.

Why It Matters for the Exam

This integrated risk management sequence appears in approximately 15-20% of PMI exam questions, often testing the correct order of processes, which outputs feed into which subsequent processes, and what each process produces. Questions frequently present scenarios asking which risk process should be performed next, or what document contains specific risk information.

Key Points to Remember (for the exam)

  • Process Order: Plan Risk Management → Identify Risks → Perform Risk Analysis → Plan Risk Responses → Implement Risk Responses → Monitor Risks
  • Main Input to Identify Risks: Risk management plan, cost baseline, schedule baseline, resource requirements, stakeholder register, agreements, enterprise environmental factors, organizational process assets
  • Key Output from Identify Risks: Risk report containing sources of overall project risk, most important drivers of overall project risk exposure, summary information on identified individual project risks (number of threats and opportunities, distribution across risk categories, metrics and trends)
  • Critical Distinction: Plan Risk Responses (selecting strategies) vs. Implement Risk Responses (executing the planned responses) — these are separate processes
  • Common Confusion: Risk register vs. risk report — the risk report is the output from Identify Risks and contains summary information; the risk register is a separate document
  • When to Begin: Plan Risk Management should begin when a project is conceived and should be completed early in the project
  • Continuous Nature: Risk management activities are performed throughout the entire project, not just at the beginning

Typical PMI Exam Example

During project execution, a project manager identifies a new threat that could delay the critical path by 15 days. The project has already completed Plan Risk Responses. According to PMBOK v8, what should the project manager do next? Answer: Update the risk register, then perform Plan Risk Responses to develop a response strategy, followed by Implement Risk Responses.

PMI Exam Traps

  • Trap: Confusing Plan Risk Management with Identify Risks

  • Reality: Plan Risk Management defines how to conduct risk activities; Identify Risks identifies what the risks are

  • Trap: Thinking Risk Responses are implemented immediately after planning

  • Reality: Plan Risk Responses (selecting strategies) and Implement Risk Responses (executing) are two separate sequential processes

  • Trap: Assuming risk management is a one-time activity at project start

  • Reality: Risk management is performed throughout the project, with risk reviews conducted continuously

  • Trap: Confusing the risk report with the risk register

  • Reality: The risk report (output of Identify Risks) contains summary information and sources of overall project risk; the risk register contains detailed individual risk entries

Important PMI Connections

Related ConceptRelationship TypeExam Attention Point
Schedule BaselineInput to Identify RisksRisks can impact schedule; schedule baseline provides activity durations and dependencies for risk analysis
Cost BaselineInput to Identify RisksCost reserves are often allocated during risk response planning
Stakeholder RegisterInput to Identify RisksStakeholders provide risk information; their risk appetite and thresholds guide responses
Lessons Learned RegisterInput to Plan Risk ResponsesHistorical risk responses inform current strategy selection

Quick Review Questions

  1. What is the FIRST process in the risk management sequence that must be completed before any risk identification can occur?

  2. The risk report output from Identify Risks contains what two main categories of information?

  3. A project manager has completed Plan Risk Responses. What is the NEXT process to perform?

  4. When should Plan Risk Management begin according to PMBOK v8?

  5. What is the difference between the risk register and the risk report?

PMBOK v8 Reference

Section 2.7.2.1 - Plan Risk Management Section 2.7.2 - Risk Performance Domain (including Identify Risks, Perform Risk Analysis, Plan Risk Responses, Implement Risk Responses, Monitor Risks)