
Risk (Negative Risk)
PMBOK v8 Definition
A risk is "a risk that would have a negative effect on one or more portfolio, program, or project objectives." In PMBOK v8, risks are classified as negative risks (threats) that decrease the probability and impact of achieving objectives, while opportunities represent positive risks. The Risk performance domain includes processes for risk management planning, identification, analysis, response planning, response implementation, and risk reviews throughout the project life cycle.
Why It Matters for the Exam
Risk questions appear in 15-20% of PMI exam questions, making it one of the most heavily tested domains. You will encounter scenario-based questions requiring you to distinguish between risk types (known-known, known-unknown, unknown-unknown), select appropriate response strategies, and understand how risk management integrates with other performance domains like scope, schedule, and budget.
Key Points to Remember (for the exam)
-
Risk Classification (from Figure 2-46):
- Known-Known: Managed as part of scope. NOT a risk (facts and requirements)
- Known-Unknown: Classic risk. Knowledge exists to identify probability and impact
- Unknown-Unknown: Emergent risk. Knowledge does not exist within sphere of influence
-
Risk Appetite vs. Risk Threshold:
- Risk appetite: Degree of uncertainty an organization is willing to accept in anticipation of reward
- Risk threshold: Predetermined value of a measurable project variable that represents a limit requiring action if reached
-
Objectives of Risk Performance Domain: Increase probability and impact of positive risks (opportunities) while decreasing probability and impact of negative risks (threats)
-
Risk Response Strategies for Overall Project Risk (same strategies apply to both individual and overall project risk):
- Avoid: Used when overall project risk is significantly negative and outside agreed-upon risk thresholds
-
Risk Impact on Other Domains: Risks can impact project scope (increase or decrease), which affects schedule and budget. Finance domain is directly influenced—internal projects see cost changes, external projects face revenue generation or loss
-
Risk Management Process: Begins at project conception with Plan Risk Management, then continues through identification, analysis, response planning, response implementation, and periodic reviews
-
Risk vs. Issue: A risk is a potential event that has not yet occurred; an issue is a risk that has materialized. The PMBOK v8 glossary explicitly links risk with "issue, opportunity, and risk"
Typical PMI Exam Example
A project manager is assessing a newly identified uncertainty about a critical vendor's ability to deliver raw materials on time. The team has historical data on similar vendor delays but cannot predict exactly when or if this specific delay will occur. Question: How should this risk be classified? Answer: Known-Unknown (classic risk) because knowledge exists to identify probability and impact, but the exact timing and occurrence remain uncertain.
PMI Exam Traps
-
Trap: Confusing "Known-Known" with a risk
- Reality: Known-Known items are facts and requirements managed as scope—they are NOT risks
-
Trap: Thinking risk appetite and risk threshold are the same
- Reality: Risk appetite is the willingness to accept uncertainty; risk threshold is the specific measurable limit that triggers action
-
Trap: Applying risk response strategies only to individual risks
- Reality: The same strategies (avoid, transfer, mitigate, accept for threats) apply to both individual project risks AND overall project risk
-
Trap: Ignoring that risks can increase scope, schedule, or budget
- Reality: Risks can have positive effects (opportunities) that increase scope or reduce costs, not just negative impacts
Important PMI Connections
| Related Concept | Relationship Type | Exam Attention Point |
|---|---|---|
| Issue | Opposite of risk | A risk that has occurred becomes an issue; PMBOK v8 explicitly links them in the glossary |
| Opportunity | Positive counterpart | Risks are negative; opportunities are positive risks—both use same management processes |
| Scope Management | Directly influenced | Risks can increase or decrease scope, which cascades to schedule and budget impacts |
| Finance Performance Domain | Directly influenced | Internal projects see cost changes; external projects face revenue generation or loss from risk events |
Quick Review Questions
-
A project team identifies a potential supplier bankruptcy that could delay delivery by 3 months. Historical data shows 15% of suppliers in this region face bankruptcy annually. How should this risk be classified?
-
An organization sets a policy that any project with a cost variance exceeding 10% requires immediate escalation. What PMBOK v8 term describes this 10% value?
-
During risk planning, a team identifies a known regulatory requirement that must be met. Should this be managed as a risk or as part of scope?
-
A project has overall risk exposure that exceeds the organization's risk appetite but is within the risk threshold. What action does the risk threshold require?
-
What are the two main objectives of the Risk performance domain according to PMBOK v8?
PMBOK v8 Reference
Section 2 – Project Management Performance Domains (pages 93-101), specifically:
- Figure 2-46: Risk Classification (page 93)
- Risk performance domain description (pages 93-94, 101)
- Glossary: Risk, Risk appetite, Risk threshold (page 275)