Risk Management
❦
A risk is an uncertain event or condition that, if it occurs, affects project objectives, positively or negatively. A threat is a negative risk and an opportunity a positive one. An issue is a risk that has already occurred, so it must be managed now (PMI, 2021).
The Risk Management Process
1. Plan how risk will be managed: roles, methods, thresholds.
2. Identify risks through brainstorming, checklists, interviews, lessons learned, and review of assumptions.
3. Analyze qualitatively: assess probability and impact.
4. Analyze quantitatively where justified: put numbers on exposure.
5. Plan responses.
6. Implement and monitor.
ISO 31000:2018 describes a similar cycle of establishing context, assessing, treating, monitoring, and communicating (ISO, 2018). The eighth edition of the PMBOK Guide lists Risk as one of its seven performance domains, with about six associated processes in one published index (PMI, 2025; Projectmanagement.com.br, 2025).
Writing a Good Risk Statement
State the cause, the event, and the effect: "Because the only interview recorder is shared with another lab (cause), it may not be available in the data collection window (event), delaying fieldwork by two weeks (effect)."
Qualitative Analysis: Probability-Impact Matrix
Rate probability and impact on a scale, such as 1 to 5, and multiply them to get a score.
| Score (P × I) | Rating | Typical action |
| 1 to 4 | Low | Accept and monitor |
| 5 to 12 | Medium | Plan a response |
| 15 to 25 | High | Prioritize; act now |
Quantitative Analysis
The expected monetary value (EMV) of a risk is probability multiplied by impact. For example, a 30% chance of a 20,000 loss has an EMV of 6,000. More advanced techniques include sensitivity analysis, decision trees, and Monte Carlo simulation, which runs thousands of trials with random values drawn from the estimate ranges to produce a distribution of possible outcomes (Hillson, 2009).
Responses to Threats and Opportunities
| Response to threats | Response to opportunities | Meaning |
| Avoid | Exploit | Eliminate the threat or make the opportunity certain |
| Mitigate | Enhance | Reduce probability or impact, or increase them for opportunities |
| Transfer | Share | Shift the risk, for example by insurance or contract, or share the gain |
| Accept | Accept | Do nothing, or hold a contingency |
The Risk Register
A risk register is a living table. Here is an example for a master's thesis:
| ID | Risk | P | I | Score | Response | Owner |
| R1 | Ethics approval takes longer than planned | 4 | 4 | 16 | Submit early; ask the committee for the review calendar; prepare a desk-based fallback | Student |
| R2 | Low participant response rate | 3 | 4 | 12 | Pilot recruitment; offer several routes; set a minimum sample | Student |
| R3 | Data loss | 2 | 5 | 10 | Three backups; cloud storage; version control | Student |
| R4 | Supervisor unavailable at a key time | 3 | 3 | 9 | Agree dates early; identify a second contact | Student |
| R5 | Illness or burnout | 3 | 5 | 15 | Buffer in the plan; use support services; communicate early | Student |
| R6 | Key software or equipment fails | 2 | 3 | 6 | Test early; arrange alternatives | Student |
Review the register at every progress meeting, retire risks that have passed, add new ones, and record what happened.
Risk Attitude
Different people and organizations differ in risk appetite. A doctoral student exploring an unproven method accepts more technical risk than an undergraduate with a fixed deadline. The important thing is to take risks knowingly.
CHAPTER 11