PMI PMP: Risk & Issue Management — Study Guide
Part of the PMP — Study Guide. Practice with verified answers in the PMI exam hub, or take timed practice tests on ExamRoll.io.
Risk Identification and Register Maintenance
Risk identification is a continuous, iterative discipline rather than a one-time planning event. From project initiation through closeout, the project manager and the team scan for uncertainties that could affect scope, schedule, cost, quality, resources, or stakeholder satisfaction. Techniques include brainstorming, Delphi sessions with subject matter experts, SWOT analysis, assumption and constraint analysis, document reviews, checklists derived from lessons learned, and prompt lists such as PESTLE for external categories.
The risk register is the authoritative artifact where every identified risk is captured. A well-maintained register goes far beyond a list of concerns. Each entry should include a unique identifier, a clearly worded risk statement using cause-event-effect structure, the risk category, the assessed probability and impact (both qualitative and, where warranted, quantitative), the resulting risk score or exposure, an assigned risk owner, one or more trigger conditions, the planned response strategy, secondary and residual risks, and a status field. When numerical modeling is applied — Monte Carlo simulation, decision trees, or expected monetary value — outputs feed the risk report, which summarizes overall project risk exposure for sponsors and steering committees.
A common failure mode is letting the register accumulate low-priority entries indefinitely until it becomes noise. Every risk should either be actively managed, accepted with rationale, or closed. Housekeeping the register — pruning obsolete items, elevating those whose probability or impact has grown, demoting those whose triggers have passed — is a governance responsibility of the project manager, typically reviewed at each status cadence.
Response Planning: Mitigation, Contingency, Fallback, and Workarounds
Response strategies for threats fall into five categories: escalate, avoid, transfer, mitigate, and accept. For opportunities the mirror strategies are escalate, exploit, share, enhance, and accept. The distinctions among mitigation, contingency, and workaround are frequently blurred in practice and must be sharp on paper.
- Mitigation
- Timing: Proactive; executed before the risk occurs
- Triggered By: Planned action to reduce probability or impact
- Approval Path: Approved during planning; funded from project budget
- Contingency (Plan B)
- Timing: Reactive; executed if a specific trigger fires
- Triggered By: Pre-defined trigger conditions
- Approval Path: Pre-approved response and reserve during planning
- Fallback
- Timing: Executed if contingency fails or is insufficient
- Triggered By: Failure of primary contingency
- Approval Path: Pre-approved as secondary response
- Workaround
- Timing: Reactive; unplanned
- Triggered By: An unidentified risk or issue materializing
- Approval Path: Requires change control if it affects baselines
Mitigation reduces exposure in advance — for example, prototyping a novel integration to reduce technical uncertainty. Contingency is a deliberate, pre-authorized response tied to a trigger, such as engaging a second supplier if the primary vendor misses a defined milestone. Fallback is the response if the contingency underperforms. A workaround, by contrast, is an unplanned reaction to an unidentified risk that has become an issue. Because workarounds bypass planning, applying them without routing scope, schedule, or cost impacts through integrated change control undermines baseline integrity, distorts earned value data, and hides accountability. Even under time pressure, the workaround must be documented, the issue logged, and any baseline impact submitted to the change control board.
Reserves must be aligned to these strategies. Contingency reserves cover known risks and reside inside the cost and schedule baselines; the project manager may authorize their use when a trigger fires. Management reserves address unknown-unknowns, sit outside the baselines, and require sponsor or CCB approval to release. Both should be transparently reflected in forecasts (EAC, ETC) rather than buried inside padded estimates.
Monitoring, Escalation, and Issue Management
Once a risk materializes, it ceases to be a risk and becomes an issue. It is moved — not merely copied — from the risk register to the issue log, which tracks description, owner, priority, target resolution date, status, and actions taken. Following the issue-management procedure defined in the risk management plan matters because it enforces consistent triage, accountability, and communication.
Escalation criteria should be established up front. A risk or issue is escalated when it exceeds the project manager’s authority thresholds, when it affects objectives outside the project’s scope, when it requires resources the project cannot commit, or when it involves policy, safety, legal, or reputational dimensions. Escalation is not abdication: the project manager retains the responsibility to frame the decision, present options, and integrate the outcome back into project artifacts.
Ownership is the axis on which monitoring turns. Every risk and every issue must have a single named owner, not a team or a role. Without an owner, responses drift, triggers pass unnoticed, and the same risk recurs. During status reviews, the project manager verifies that each open response is progressing, that residual risk is acceptable, and that new secondary risks introduced by the response itself are logged.
Reassessment Under External Events and Regulatory Change
External shocks — geopolitical events, commodity price swings, currency fluctuations, pandemics, regulatory rulings, permit denials, new tariffs — invalidate prior probability and impact assumptions across the register. When such an event occurs, the correct sequence is to trigger a formal risk reassessment before choosing a corrective action. Reassessment re-evaluates each affected risk, identifies newly emerged risks, and updates the overall risk exposure. Only then can informed decisions be made about schedule compression, alternate sourcing, or scope adjustments.
Consider a construction project affected by a global petroleum supply disruption that delays deliveries of asphalt and plastics. Rushing to expedite one shipment addresses a symptom. The disciplined first step is to reassess supply-chain risks broadly, quantify the new exposure, and then bring options — alternate suppliers, resequencing, scope deferral — through change control. Similarly, when subject matter experts advise additional time for permit approvals and the CCB agrees, the schedule baseline is the first document updated, because the approved change is a schedule extension; the risk register, cost forecasts, and communications plan follow.
Opportunity Identification and Exploitation
Opportunities deserve the same rigor as threats but are frequently treated passively. Positive risks — an early vendor delivery, a favorable exchange rate, an available expert freed from another project — should be logged, scored, owned, and pursued with an explicit strategy. Exploit ensures the opportunity is realized (e.g., locking in a discounted contract immediately). Enhance increases probability or impact. Share transfers ownership to a partner better positioned to capture value. When a project manager has, mid-execution, a more efficient response idea than the one originally documented, the disciplined path is to evaluate it, update the response plan, secure approval through change control if baselines are affected, and then execute — not to substitute silently.
Common Traps and Why They Fail
Ad-hoc workarounds bypass change control, corrupt baselines, and erase traceability; even when speed is essential, documentation and post-hoc change requests preserve governance. Neglecting to update the register when likelihood or impact shifts leaves the team steering by an obsolete map, misallocating reserves and attention. Failing to assign owners guarantees recurrence, because monitoring without accountability collapses into wishful thinking. And allowing the register to bloat with trivial items dilutes focus, so critical risks lose visibility precisely when discipline matters most.
Practical Problem: Use-Case Scenario
Scenario: Priya Chandran is managing the Meridian Payments Gateway integration, a 14-month, $4.8M initiative for a mid-sized bank that will connect four legacy core-banking systems to a new real-time payments network. The project is in month five, and the risk register has swelled to 87 entries since kickoff — most carrying probability and impact scores below 6, several duplicated across workstreams, and 12 with no assigned owner. During the last steering committee, the sponsor complained that the monthly risk report was unreadable and that two material risks — a vendor certification delay and an unresolved cryptographic key management gap — were buried on page four.
Challenge: Priya must restore the risk register’s usefulness as a decision-support tool without losing traceability on lower-priority items, and she must do it before the next steering committee in three weeks.
Recommended Approach:
- Convene a two-hour risk review workshop with the six workstream leads and the enterprise risk representative to walk the full register entry by entry, using the existing probability-impact matrix as the sorting lens.
- Reclassify entries into three tiers: active (score ≥ 12), watchlist (score 4–11), and archived (score < 4 or trigger conditions no longer plausible), and move watchlist and archived items to separate tabs so the active view stays focused.
- Rewrite the top 15 active risks using strict cause-event-effect syntax, assign a named individual owner (not a team) to each, and define at least one measurable trigger condition per risk.
- Escalate the vendor certification delay and the key management gap immediately to the sponsor with proposed response strategies and EMV calculations rather than waiting for the scheduled report.
- Establish a standing 30-minute weekly risk huddle and a rule that any new risk must have an owner and trigger before it is admitted to the active tier.
- Update the risk management plan to document these tiering thresholds and hygiene rules, and circulate it to the steering committee.
Why This Works: Tiering preserves the audit trail PMI expects while eliminating the noise that erodes stakeholder trust in the register. Naming individual owners and explicit triggers converts passive monitoring into accountable response readiness, and surfacing material risks directly to the sponsor honors the PM’s escalation duty rather than letting governance channels obscure genuine threats.
← Scope · All domains · Quality Management →
Practice these questions → · Timed practice on ExamRoll.io →
Pass the whole exam — not just this question
You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.
Pass your exam →