The Escalate Risk Response Strategy for Out-of-Scope Risks

The Escalate Risk Response Strategy for Out-of-Scope Risks

PMBOK v8 Definition

The escalate risk response strategy is appropriate when the project team or project sponsor agrees that a threat or opportunity is outside the scope of the project or that the proposed response would exceed the project manager's authority. Escalated risks are managed at the portfolio level, program level, or other relevant part of the organization, but not at the project level.

This strategy applies to both threats and opportunities. For threats, escalation transfers ownership to a higher organizational level that matches the objectives that would be affected. For opportunities, escalation moves the opportunity to portfolio, program, or other relevant organizational levels for management.

Why It Matters for the Exam

The escalate strategy appears frequently in PMI exam questions because it tests the candidate's understanding of project manager authority boundaries and organizational governance. Questions often present scenarios where a risk exceeds the project manager's control, requiring the candidate to identify escalation as the correct response rather than attempting inappropriate mitigation, avoidance, or enhancement.

Key Points to Remember (for the exam)

  • Trigger Condition: Escalation is used ONLY when the risk is outside project scope OR the response exceeds the project manager's authority
  • Ownership Transfer: After escalation, ownership must be accepted by the relevant party in the organization
  • No Further Monitoring: Escalated threats are NOT monitored further by the project team after escalation
  • Recording Requirement: Escalated threats may be recorded in the risk register for information purposes only
  • Dual Application: The escalate strategy applies to BOTH threats and opportunities (five strategies exist for each)
  • Management Level: Escalated risks are managed at portfolio level, program level, or other relevant part of the organization
  • Project Manager Role: The project manager determines who should be notified and communicates details to that person or part of the organization

Typical PMI Exam Example

A project manager identifies a regulatory change that could delay the project by six months. The proposed response requires renegotiating the company's compliance agreement with a government agency, which exceeds the project manager's signing authority. The project manager should escalate this threat to the program level, where the appropriate authority exists to negotiate with the agency.

PMI Exam Traps

  • Trap: Confusing escalation with transfer (for threats)

  • Reality: Escalation moves risk to higher organizational authority; transfer shifts financial impact to a third party (e.g., insurance)

  • Trap: Thinking the project team continues monitoring escalated risks

  • Reality: After escalation, the project team does NOT monitor escalated threats further

  • Trap: Applying escalation when the risk is within scope but severe

  • Reality: Escalation is only appropriate when the risk is outside scope OR the response exceeds the project manager's authority

  • Trap: Confusing escalation for opportunities with sharing or exploiting

  • Reality: Escalation moves ownership to higher organizational level; sharing involves partnering with another party; exploiting aims to ensure the opportunity happens

Important PMI Connections

Related ConceptRelationship TypeExam Attention Point
Risk RegisterOutput of risk identification; records escalated risksEscalated threats may be recorded "for information" only
Risk Response PlanningPart of Plan Risk Responses processEscalate is one of five strategies for threats AND opportunities
Project ResilienceComplementary conceptEscalation supports resilience by ensuring risks are managed at appropriate authority levels
Overall Project RiskRelated to acceptance strategyWhen escalation is not possible and risk exceeds thresholds, acceptance may be used

Quick Review Questions

  1. A project team identifies a threat that would require approval from the company's board of directors to implement the response. What risk response strategy should the project manager use?

  2. After escalating a threat to the program level, what is the project team's responsibility regarding monitoring that threat?

  3. A project sponsor agrees that an opportunity to expand into a new market is outside the project's scope. What risk response strategy is most appropriate?

  4. What is the key difference between escalating a threat and transferring a threat?

  5. At what organizational levels are escalated risks managed after the project team escalates them?

PMBOK v8 Reference

Section 5.2 - Plan Risk Responses (Strategies for Opportunities) and Section 5.2 - Plan Risk Responses (Strategies for Threats)