0% found this document useful (0 votes)
3 views60 pages

Project Risks Management

The document outlines Project Cycle and Delivery Methodologies, focusing on Project Risk Management, which includes identifying, analyzing, and responding to risks that may affect project objectives. It differentiates between various types of risks, such as fiduciary, event-based, and non-event-based risks, and emphasizes the importance of a risk register for tracking and managing these risks. Additionally, it discusses techniques for risk assessment and management, including qualitative analysis and the use of tools like SWOT analysis.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views60 pages

Project Risks Management

The document outlines Project Cycle and Delivery Methodologies, focusing on Project Risk Management, which includes identifying, analyzing, and responding to risks that may affect project objectives. It differentiates between various types of risks, such as fiduciary, event-based, and non-event-based risks, and emphasizes the importance of a risk register for tracking and managing these risks. Additionally, it discusses techniques for risk assessment and management, including qualitative analysis and the use of tools like SWOT analysis.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

MBA 610

PROJECT CYCLE AND DELIVERY


METHODOLOGIES
BY
ASSOC. PROF. ABRAHAM A. KIAZOLU, II

© 2026
Outline
• Project Cycle Management
• Project Monitoring & Evaluation
• Project Procurement Management
• Project Financial Management
• Project Risks Management

© 2026
PROJECT RISKS MANAGEMENT
OUTLINE
➢Meaning of Risks
➢Difference between Risks and Assumption
➢Types of Risks
➢Risks Management Steps and Techniques

© 2026
What is a Risk?

© 2026
Risk is defined an uncertain event or condition, that if it
occurs, have a negative or positive effect on one or
more of a project objectives.
Threat
Opportunity
Project Risk Management includes the processes for
conducting risk management planning, identification,
analysis, response planning, response implementation
and monitoring risks on a project.
Decrease the probability
Optimize the
and/impact of negative risks
chances of project
Increase the probability success.
and/impact of positive risks
© 2026
So, they are unforeseen events of bigger or smaller entity
which can affect the project at various levels. They are
events that could or could not happen in the future.
When they happen, they cease to be a risk of course,
then they have materialized into an event…
In project management, we try to foresee what can
happen as far as possible and devise strategies on how
to deal with these events in the best way. That’s what we
call project risk management. And I would add, that this
applies just as much to development projects!
Decrease the probability
and/impact of negative risks
Optimize the
Increase the probability chances of project
and/impact of positive risks success.
© 2026
Inputs, Tools, Techniques and Outputs
Inputs, tools, and techniques used
to produce the outputs of each
process in the project management
life cycle. Inputs, tools and
Techniques help ensure that project
activities and tasks are clearly
defined and that the necessary
resources and approaches are
available to completely produce
outputs. Outputs are tangible and
intangible products resulting from
project activities. They can be
reports, plans, products, services, or
any other results produced by the
project.

© 2026
Difference between assumptions and risks

© 2026
Difference between assumptions and risks

© 2026
Three Elements that Compose a Risk
• A risk is composed of 3 elements: there is a source,
which can (or cannot) result in an event, which in
turn causes an effect.
• E.g. The counterpart staff changes -> there is a
new positive colleague -> the project benefits from
new expertise and improves the quality.
• E.g. The counterpart staff changes -> there is a
new unhelpful colleague -> the project loses
quality in the implementation of the relevant
activities.

© 2026
© 2026
Classification of Risks
There are many ways in which you can categorize risks,
Maybe your organization has done so, in which case you
can use those categories. If not, the simplest way of
categorizing is by distinguishing external and internal risks.
❑External risks: regulatory, environmental, government,
market shifts.
❑Internal risks: time, cost, or scope changes; inexperience;
poor planning; people; staffing; materials; equipment.
❑Technical Changes in technology.

© 2026
Classification of Risks
You could also classify risks by their root causes:
❑Political and institutional risks: governance
❑Financial and budgetary risks
❑Economic risks: the market
❑Social risks, such as labour conflicts, SGBV
❑Environmental risk
❑Risks in procuring
❑Risks of force majeure

© 2026
Types of Risks
❑Fiduciary Risks refers to unforeseen incidents or
developments that could impact a project such as the risk
that funds are not used for the intended purposes; do not
achieve value for money; and/or are not properly
accounted for. Included in this category are poor financial
management, poor procurement management, and poor
contracts management practices. Examples:
Corrupt practices: the offering, giving, receiving or soliciting,
directly or indirectly, of anything of value to influence
improperly the actions of another party.
Fraudulent practices: any act or omission, including a
misrepresentation, that knowingly or recklessly misleads, or
attempts to mislead, a party to obtain a financial or other
benefit or to avoid an obligation.
© 2026
Types of Risks
Collusive practices: an arrangement between two or more
parties designed to achieve an improper purpose, including
to influence improperly the actions of another party.
Coercive practices: impairing or harming, or threatening to
impair or harm, directly or indirectly, any party or the property
of the party to influence improperly the actions of a party.
Obstructive practices: deliberately destroying, falsifying,
altering or concealing of evidence material to the
investigation or making false statements to investigators in
order to materially impede an investigation into allegations of
a corrupt, fraudulent, coercive or collusive practice; and/or
threatening, harassing or intimidating any party to prevent it
from disclosing its knowledge of matters relevant to the
investigation or from pursuing the investigation, etc.
© 2026
Types of Risks
Conflict of interest a situation in which a person is
involved in multiple interests, financial or otherwise,
and serving one interest could involve working
against another; Typically, this relates to situations
in which the personal interest of an individual or
organization might adversely affect a duty owed
to make decisions for the benefit of a third party.

© 2026
Types of Risks
You can also classify risks by the level at which it exist under a project.
Risks exist at two levels within every project. Each project contains
individual project risks that can affect the achievement of project
objectives. It is important to consider the overall riskiness of the project
which arises from the combination of individual project risks and other
sources of uncertainty.
❑Individual Project Risk - an uncertain event or condition that, if occurs,
has a negative or positive impact on one or more project objectives.
❑Overall Project Risk - the effect of uncertainty on the project as a
whole, arising from all sources of uncertainty including individual risks,
representing an exposure of stakeholders to the implications of
variations in project outcomes, both positive or negative.

© 2026
Types of Risks
We also have:
❑Event-Based Risk refers to unforeseen incidents or
developments that could impact a project. These are
unpredictable occurrences that may require careful
consideration and mitigation strategies. An example could
be a sudden regulatory change affecting project
requirements or a key supplier may go out of a certain
product during the project’s execution.
❑Non-Event-Based Risk on the other hand, are inherent
aspects of a project’s environment. These risks are ongoing
and do not rely on specific incidents. Financial uncertainties
(Inflation), and compliance or regulatory issues are
examples of non-event-based risks. Identifying and
managing these risks is crucial for sustained project success.
© 2026
CASE SENARIO - Currency Fluctuation (SDR VS. USD)
IRISE Project
• Special drawing rights (SDRs) refer to an international type of monetary reserve currency
created by the International Monetary Fund (IMF) in 1969. It operates as a supplement to
the existing money reserves of member countries. Created in response to concerns
about the limitations of gold and dollars as the sole means of settling international
accounts, SDRs augment international liquidity by supplementing the standard reserve
currencies.
• The IRISE Project budget was fixed in SDR and was equivalent to US $47 million. Thus, the
project planning and budgeting were carried out considering the US dollars equivalent
of SDR. During the Project’s implementation, the USD equivalent of the SDR value kept
depreciating as implementation progresses. As a result, the Project suffered a USD 2M
budget shortfall.


What went wrong
What lessons to learn

© 2026
Risks Management Steps and Techniques

© 2026
Step 1: Risks Identification
• How do you identify risks?
• You need to scan and analyze the context and
use all your existing planning documents that you
already have. Your organization may well have an
organizational risk register which is also an
important input to this analysis.
• See a list of sources and techniques which you can
use at your discretion, you being the judge on
which is / are the most useful:

© 2026
Step 1: Risks Identification
1. Documentation reviews: you use existing relevant documents such as project
reports, strategic documents etc. which are relevant to your project and screen for
risks.
2. Information gathering techniques include:
• Brainstorming with your team or with stakeholders,
• Delphi technique: This technique is used to build consensus of experts who
participate anonymously. A request for information is sent to the experts, their
responses are compiled, and the results are sent back to them for further review
until consensus is reached. This technique can also be used for estimating time and
cost.
• Interviewing
3. SWOT analysis
4. Checklist of risks: you can use risk categories to help to identify specific risks within
each category.
5. Assumptions analysis: analyzing each assumption that have been made on the
project and if they are valid may lead to the identification of more risks. © 2026
Detailed Risk Identification Process
• Identify Risks - the process of identifying individual project risks as well
sources of overall project risks. The Key output of this process is the risk
register. A Risks Register captures the details of identified individual project
risks. The results of perform qualitative risks analysis, plan risk responses,
implement responses and monitor risks are recorded in the risk register as
these processes are conducted throughout the project. The Risk register
may contain limited of extensive information depending on the project
variables such as size and complexity.
Inputs
Project Management Plan
Enterprise Environmental Factors
Organization process assets
Agreements
Procurement Documentation
Tools and Techniques
Identify Risks Expert Judgements
Data Analysis
❖ SWOT Analysis
Interpersonal and Team Skills
Meetings
Outputs
❖ Risk Register © 2026
Detailed Risk Identification Process –
SWOT Analysis
❑SWOT Analysis is a technique that
examines the project or business from STRENGH WEAKNESS OPPORTUNITIES THREATS
each the strengths, weaknesses,
opportunities and threats perspectives. Qualified The Project PM is familiar Bureaucrati
For risks identification, it is used to Project implemente with Key c
increase the breadth of identified risks Manager d in a matrix decision bottleneck
including internally generated risks. The organization makers
technique starts with the identification
of strength and weaknesses of the Experience Not familiar Cash flow Lacks skilled
organization, focusing on either the contractor with the efficiency workers in
project, organization, or business area local context project
in general. SWOT analysis then location
identifies any opportunities for the
project that may arise from the
strength, and any threats that may
arise from weaknesses. The analysis
also examines the degree to which
organization strength may offset
threats and determine if weaknesses
might hinder opportunities.
© 2026
Detailed on Risks Register
Content of the risk register are:
• A unique identifier - enables tracking of each individual risk
• Description of risk - a clear describe of the risk in as much detail as possible
to ensure unambiguous understanding of the risk.
• Probability - the likelihood of occurrence of the risk. May be classified as
High, Medium or Low in percentage with high percentage denoted high
probability of occurrence and low percentage denoting low probability of
occurrence.
• Impact - the effect of the risk on the project’s objective. May be classified
as High, Medium or Low in percentage with high percentage denoted high
impact with the risk occurs and low percentage denoting low impact.
• Risk response - describes the plan response to each risk in the risk register.
• Risk Owner - the person or persons responsible for monitoring the risk and
ensuring the implementation of the risk response
• Status - shows whether the risk is open or closed.
© 2026
Example of Risks Register

© 2026
Step 2: Conduct Risks Assessment
• Risk management is about determining what you are
going to do about risks. Would you want to do something
about all the risks identified? Of course not. That would be
too expensive and you would not have enough time.
Therefore, qualitative risk analysis involves creating a short
list of the previously identified risks. The shortlisted risks will
then be further analyzed.
• Assessment is often accompanied by a quantitative
assessment of the risk impact, in case it occurs, on the
project objectives, quality, cost and schedule.
• The qualitative risk analysis is a subjective analysis of the
risks identified.

© 2026
Risks Assessment
• What makes a risk important?
• Its likelihood of occurrence and impact. High impact but
unlikely is not an important risk.

© 2026
Risks Assessment
The result can be depicted in this color code matrix.

The probability
The impact
of each risk
(amount at
occurring can stake, or
be indicated, consequences,
using a positive or
standard scale negative) of
each risk
such as Low,
occurring can
Medium, High also be
(or 1 to 10). indicated,
again using a
standard scale
such as Low,
Medium, High
(or 1 to 10).
© 2026
Perform Qualitative Risk Analysis
• Qualitative Risk Analysis - the process prioritizing individual
project risks for further analysis or action by assessing their
probability of occurrence and impact as well as other
characteristics. The key benefit of this project is to rank the
risk in the risk register in order to focus on the high priority
risks. It assesses the probability of the risk occurrence and
the corresponding impact should the risks occur.
Inputs
Project Management Plan
Enterprise Enviromental Factors
Organization process assets

Qualitative Risk Tools and Techniques


Analysis Expert Judgements
Data Analysis
Meetings
Risk Categorization
Output
Project Document Updated
© 2026
Data Analysis Techniques use to Perform
Qualitative Risk Analysis
• Risk Data Quality Assessment - evaluates the degree to
which the data about the individual project risks is
accurate and reliable as a basis for qualitative risk
analysis. The use of wrong data or low-quality data may
lead to a qualitative risk analysis that is of little or no use to
the project.
• Risk Probability and Impact Assessment - considers the
likelihood that a specific risk will occur. Risk impact
considers the potential effect on one or more project
objectives such as schedule, cost, quality or performance.
Impact will be negative for threats and positive for
opportunities. Risk with low probability and impact may be
included within the risk register as part of a watch list for
future monitoring. © 2026
Data Analysis Techniques use to Perform
Qualitative Risk Analysis
• Assessment of other risk parameters - Project team may consider
other characteristics of risk (in addition to probability and impact)
when prioritizing risks for further analysis or action. These include:
Urgency - the period of time Proximity - the period of time in which Dormancy- the period of time that
in which the risk response the risk might have an impact on one may elapse after a risk has occurred
needs to be implemented in order to or more objectives. before its impact is discovered.
be effective. A short period indicates A short period indicates A short period indicates
high urgency. high proximity. low dormancy.

Manageability - the ease with which Detectability - the ease with which the results of the
the risk owner risk occurring or being about to occur can be
(or owning organization) can manage Detected and recognized. Where the risk
a risk. Where management is easy, occurrence can be detected easily, Detectability
manageability is high. is high.

Controllability - the degree to which Strategic Impact - the potential for


Connectivity - the extent to which
the risk owner the risk to have a negative or positive
the risk is connected to other
(or owning organization) is able to effect or the organization’s strategic
individual project risks.
control the risk outcome. goal. Where the risk has a major
Where the risks is connected to more
Where outcome can be easily effect on strategic goal, strategic
risks, Connectivity is high.
controlled, controllability is high. impact is high. © 2026
Data Analysis Techniques using
Quantitative Risk Analysis
• Quantitative Risk Analysis - the process of numerically analyzing project risks on a
project. The benefit of this process is that it quantifies overall project risk exposure,
and can also provide additional information to support risk response planning.
• This process will not produce a ranking of risks like the qualitative risk analysis
process but will produce numerical analysis such as deplorable road condition to
some project sites may result in four weeks of delay to the project or the
probability of increase in price of a certain product required by the project is 10%
costing the project additional $40,000.00.
Inputs
Project Management Plan
Enterprise Environmental Factors
Organization process assets
Agreements
Procurement Documentation
Quantitative Tools and Techniques
Expert Judgements
Risk Analysis Data Analysis
Interpersonal and Team Skills
Representative of uncertainties
Meetings
Outputs
Project Documents updated © 2026
Expected Monetary Value (EMV)
• Monetary value analysis assigns a certain dollar amount to
risks. It can be done using the decision tree analysis or make or
buy analysis. Decision tree analysis uses the cost and
probability to determine the overall impact of risk on a project.
• Example: House meets
requirements
Buy a newly
constructed house
Cost $ 100,000.00 Prob.
25% House don’t meet
requirements
Buy a New house Impact: $40,000.00
or buy an older
house and remodel

Buy an older House meets


house and remodel requirements
Cost: $ 80,000.00
Prob.
10% House don’t meet
requirements
Impact: $50,000.00
© 2026
Expected Monetary Value (EMV)
Initial Cost Risk Cost Prob EMV Total Cost
Buy a 100,000.00 $40,000.00 25% $10,000.00 $110,000.00
New
House
Remod $80,000.00 $50,000 10% $5,000.00 $85,000.00
el Older
House
To calculate the EMV, multiply the probability by the risk cost. To
get the total cost, add the EMV to the initial cost.

© 2026
Step 4: Plan Project Risks Responses
• The management of risks necessarily includes the
planning of responses and then controlling the risks
and acting on them with the plan, if that becomes
necessary.
• The objectives of project risk management are to
increase the likelihood and impact of positive
events, and decrease the likelihood and impact of
negative events in the project. (Source: PMBOK,
2013)
• In any case, remember that you can act on the
Source, on the Event, and on the Impact!
© 2026
Step 4: Plan Project Risks Responses

• You can for instance minimize the likelihood of


staff-turnover. You can also respond to the event
by immediately hiring somebody new, maybe
even before the staff has left. And finally, you can
react once the impact - some delay may – has
occurred by reviewing the activity schedule. So,
now you see that a correct risk description is
actually important.

© 2026
Step 4: Plan Project Risks Responses
Plan Risk Responses – is the process of developing options, selecting strategies, and
agreeing on actions to address overall project risk exposure, as well as to treat
individual project risks. The Key benefit of this process is that it identifies appropriate
ways to address overall project risk and individual project risks.
Inputs
Project Management Plan
Enterprise Enviromental Factors
Organization process assets
Project Documents
Tools and Techniques
Plan Risk Responses Expert Judgements
Data Analysis
Meetings
Interpersonal and Team Skills
Risk Categorization
Strategies for Theats
Strategies for Opportunities
Contingency Response Strategy
Strategy for Overall Project Risk

Outputs
Change Request
Project Management Plan Updated
© 2026
Step 4: Plan Project Risks Responses
• Response Strategies:

© 2026
Step 4: Plan Project Risks Responses
• Response Strategies to threats:
1. Avoid – eliminate the threat by eliminating the cause. E.g. remove
the activity or the person. Risks avoidance is when the project team
acts to eliminate the threat or protect the project from its impact.
Risk avoidance may be appropriate for high priority threats with high
probability of occurrence or large negative impact.
2. Mitigate – reduce the probability or impact of the threat so that the
risk can be smaller as a result. You should look at options for
reducing the probability separately from options for reducing the
impact. Both can be deployed. Early mitigation is action is more
effective than damage repair after the threat has occurred.
3. Transfer – this means you make another party responsible. You can
do this through insurance or guarantee, or may be sub-contracting
some activity. It involves shifting ownership of the threat to a third
party to manage the risk and bears the impact if the threat occurs.
Beware that subcontracting and procurement of course bring their
own risk as well. © 2026
Step 4: Plan Project Risks Responses
• Response Strategies to Both Threat and Opportunity:
1. Accept – in all cases, you can also simply accept the risk.
Risk acceptance acknowledges the existence of a threat,
but no proactive action is taken. This strategy is
appropriate for low priority threat and it may also be
adopted where it is not possible or cost effective to
address a threat in any other way.
Passive Acceptance - involves no proactive
Active Acceptance - a contingency is set aside action apart from periodically reviewing the
to respond to the threat only when it happens. Risk to ensure it does not change.

2. Escalate – if the risk goes beyond the possibility of the


project manager to react, then s/he should push it up to a
higher level – on program or policy level.

© 2026
Step 4: Plan Project Risks Responses
• Response Strategies to Opportunity
1. Exploit – this is the reverse of avoid. You make use of the opportunity
when it comes. The exploit strategy may be selected for high priority
opportunity where the organization wants to ensure that the
opportunity is realized. The strategy seeks to capture the benefit
associated with a particular opportunity by ensuring that it definitely
happens, by increasing the probability of occurrence to 100%.
Example of exploit may include assigning the organization most
talented resources to a critical project in order to reduce the
completion timeline, using technology upgrade to reduce cost and
duration.
2. Enhance – This is the reverse of mitigate. It means you actually act to
increase the likelihood and positive impact of the opportunity. The
project will be changed as the result. The probability of occurrence
of an opportunity can be increased by focusing attention on its
causes. Example of enhancing opportunity include adding mor
resources to an activity to finish early. © 2026
Step 4: Plan Project Risks Responses
• Response Strategies to Opportunity
3. Share – this is like transfer of threats. You completely give away the
opportunity to another organization or you share it in order to take full
advantage. Risk sharing involves transferring the ownership of the
opportunity to a third party so that it shares some of the benefits if the
opportunity is realized. It is important to select the owner of the
opportunity carefully so that they are best able to capture the
opportunity for the benefit of the project.
Example of risk sharing include partnership and joint ventures.

© 2026
Step 4: Plan Project Risks Responses
• Secondary Risks: are risks that arise as a direct result of
implementing a risk response to a specific risk. In short, the
secondary risk is a new risk that comes from responding to the
initial risk.
• Example 1: Let’s say you’re a preparing for a professional
examination that you need to pass in order to stand out among
your colleagues. Achieving this certification could potentially
come with job promotion and increased salary. You reduce the
risk of not passing by staying up all night to study even the day
before the examination. But this increases the risk of oversleeping
and missing the exam entirely.
• Example 2: You buy an old townhouse and decide to replace the
carpet with hardwood floors. This decreases the risk of mold and
allergies; however, once the wood floors are installed, there is now
the secondary risk of someone slipping and hurting themselves on
the new floors. © 2026
Step 4: Plan Project Risks Responses
• Residual Risks: are those risks that are expected to remain
after the planned responses of risks have been taken, as well
as those that have been deliberately accepted.
• Residual risks are related to the initial risk. This means you
might only need to add an extra step to your initial response.
You can accept the residual risk or find ways to mitigate
them.
• Example: You’re planning an outdoor event and the weather
forecast says that it will rain for the first two hours of the event.
You set up umbrellas and canopies, but what happens if it
continues to rain after two hours? The residual risk that the rain
won’t stop may not need any response since you’re already
prepared for rain.
© 2026
Step 5: Risk Management Planning
• Once the responses are planned, the risk management plan must
be completed. This process consists of transforming the risk
response strategies into an action plan, taking into consideration
the project constraints and the organizational context.

Project constraints Organizational context

© 2026
Step 5: Risk Management Planning
• Risk Management Planning - the process of defining how to
conduct risk management activities for the project. The major
output of this Process is the Risk Management Plan. The Risk
Management plan is a component of the overall Project
Management Plan that describes how risk management activities
will be structured and performed.

© 2026
Elements of the Risk Management Plan
❑Risk Strategy - Describes the general approach for managing risk on a
project.
❑Methodology - Defines specific approaches, tools and data sources
that will be used to perform risk management on the project.
❑Roles and Responsibilities - Defines the lead, support, and risk
management team members for each type of activities described in
the risk management plan and clarifies their responsibilities.
❑Funding - Identifies the funds needed to perform activities related to
the Project Risk Management. Establishes protocols for the application
of contingency and management reverses.
❑Timing - Defines when and how often risk management processes will
be performed throughout the project life cycle.
❑ Risk Categories - Provides the means for grouping of individual project
risks. A common way to structure risk categories is with the Risk
Breakdown Structure (RBS) which is a hierarchical representation of
potential sources of risks.
❑Stakeholder risk appetite - Risk appetite is the amount of risk an
organization is willing to take to achieve its objectives. The risk appetite
of key stakeholder on the project needs to be recorded in the risk
management plan.
© 2026
Risk Management Plan
❑ Definition of Risk Probability and RBS LEVEL 0 RBS LEVEL 1 RBS LEVEL 2
Impacts - The Definition of
Scope Defination
probability and impact are specific
Requirements Defination
to the project context and reflects
1) Technical Risk Estimates, assumption and
the risk appetite and threshold of constrains
the organization and key
Technology
stakeholders.
Project management
Type of Organization
❑ Reporting Format - Defines how the
2) Management Program & Portfolio
outcome of Project Risk Risk Management
Management processes will be ALL SOURCES Communication
documented, analyzed, and OF PROJECT
Contract terms and conditions
communicated. RISKS
Procurement
3) Commercial Suppliers and vendors
❑ Tracking - Documents how risk Risk capacity
activities will be recorded and how
risk management processes will be Exchage Rate
audited. Legislation
External Risk Regulatory Bodies
Example of definitions for Probability and
Impacts
+/- IMPACT ON PROJECT OBJECTIVES
SCALE PROBABILITY
TIME COST QUALITY
Very High > 70% > 6 months > 1M Very significant impact on overall
functionality

High 51 - 70% 3-6 months 500K - 1M Significant impact on overall functionality

Medium 31 - 50% 1-3 months 100-499K Some impact in key areas


Low 11 -30% 1-4 weeks 50-99K Minor impact on overall functionality

Very Low 1-10% 1 week < 50K Minor impact to secondary function
Nill < 1% No change No change No change to functionality

© 2026
Contingency Response Strategy
Some responses are designed for used only if certain events
occurs. For some risks, it is important for the project team to
make a response plan that will only be executed under
certain predefined conditions. It is believed that there will
be sufficient warning to implement the plan. Events that
triggers the contingency response, such as missing a
milestone should be defined and tracked.
Risk responses identified using this technique are often
called contingency plans or fallback plans and include
identified triggering events that sets the plan in effect.

© 2026
Contingency Response Strategy
A construction company sets a milestone for completion of
casting the upper-level floor slab of a building at March
24th. On March 21st, the project manager reviews the
project activities and found out that all prerequisite
activities for casting of the concrete slab are not
completed and thus the use of onsite concrete mixer to
casting the floor slab could not be helpful at achieving the
milestone. The PM makes a contingency plan of hiring a
ready mixed concrete company that will deliver the
prepared concrete in the required volume and pour into
the slab’s formwork in order to meet the milestone.

© 2026
Risks Management Planning
And finally, a contingency budget is set aside at the start of
a project to be used in case of need. The amount of this
budget depends on the level of risk the project faces and
also on the overall project budget itself.
❑Unforeseen increases in costs.
❑Inflation
❑Exchange rate variation
The contingency budget should be held separately to your
main budget and be used transparently.

© 2026
Implement Risk Responses
The process of implementing agreed upon risk response plans.
The Key benefit of this process is that it ensures that agreed-
upon risk responses are executed as planned in order to address
overall project risk exposure, minimize individual project threats,
and maximize project opportunities.
Inputs
Project Management Plan
Work Perfomance Data
Work Performance Report

Tools and Techniques


Monitor Risks Data Analysis
Audit
Meetings

Output
Work Performance Information
Change Request
Project Documents update
© 2026
Step 5: Risks Monitoring and Control
Monitoring and controlling
risks is the process to
continually monitor risks
and identify any changes
that occur, and that may
mean that they
materialize and turn into
an issue. Therefore, it is
necessary to track
identified risks, monitor
residual risks and identify
new risks.

© 2026
Step 5: Risks Monitoring and Control
It is good to use regular meetings to for risk review and to
up-date the risk assessment. Indeed, risks are dynamic, so
the risk register that has been established must be
maintained throughout the project.

It is also important to assess if the risk response measures


work effectively or not. The risk register is then up-dated
accordingly.

© 2026
Step 5: Risks Monitoring and Control
• The idea of having risk indicators in the risk management plan
is to have a trigger that can alert you to when you have to
become more vigilant. It is useful to be notified that a risk is
going to occur before it actually does. In this way impact of
risk may be better mitigated or the risk response strategy may
be implemented in a timely fashion to prevent it to occur.

• You can for instance set a trigger at “the inflation rate should
not get above x%”. Or you could set something like “the
number of participants in the courses should not drop below
80% of foreseen number”.
© 2026
Monitor Risks Processes Use Work
Performance Information to Determine if:
Implemented risk responses are effective That assumption are still valid

Level of overall project risk has changed That Management procedures are still valid

Status of Identified individual project risks has Contingency reserve for cost and time require
changed modification

New individual project risks has arisen Project strategy is still valid

The risk management approach is still appropriate


© 2026
Conclusion
• Simply think of future events which could once
materialized make the project outputs and outcomes
underachieved or unsustainable. Address these events as
risk and identify preventive, detective and corrective
controls. When this is done, you can then strategically
monitor the project environment and report about risks.
- Alessandro, M&E Specialist
• The M&E specialist and Project Manager need to ensure
that the monitoring system integrates risk monitoring,
reporting and control. Most of the time, risk management
is done using the risk register and the project progress
reports are used to communicate about risks.

© 2026
THANK YOU!

You might also like