Why This Matters: Every Project Is a Bet Against Uncertainty
Here is an uncomfortable truth that seasoned project managers understand instinctively: every project is risky. There may be similarities with previous work, and there may be a proven methodology to follow, but each project contains aspects that are fundamentally unique. Even if the deliverable is identical to something built before, the world keeps changing — key resources leave, legislation shifts, environmental factors vary, technologies evolve, and stakeholder expectations drift.
Risk is not the enemy of project success — it is the reason projects exist. If outcomes were certain, there would be no need for project management at all. The discipline of risk management exists to help project managers make informed decisions under conditions of uncertainty, turning potential threats into manageable challenges and hidden opportunities into realised value.
What Is 'Risk'? Establishing a Common Language
The Everyday Definition
This captures the everyday sense of the word — something bad might happen. But professional project management demands a more precise, nuanced, and ultimately more useful definition.
The PMBOK Definition
Earlier process-based project-management guidance described risk as an uncertain condition that can affect objectives positively or negatively.
Notice something critical here: the PMBOK definition explicitly includes positive effects. Risk is not exclusively about things going wrong — it also encompasses unexpected upside. This dual nature is central to modern risk management thinking.
The ISO 31000 Definition
ISO 31000:2018 uses the broader, objective-centred concept of the effect of uncertainty on objectives. The current vocabulary reference is ISO 31073:2022.
This definition is deliberately expansive. The accompanying notes elaborate:
- Note 1: An effect is a deviation from the expected — positive and/or negative.
- Note 2: Objectives can have different aspects (financial, health and safety, environmental) and can apply at different levels (strategic, organisational, project, product, process).
- Note 3: Risk is often characterised by reference to potential events and consequences, or a combination of these.
- Note 4: Risk is often expressed as a combination of the consequences of an event and the associated likelihood of occurrence.
- Note 5: Uncertainty is the state, even partial, of deficiency of information related to understanding or knowledge of an event, its consequence, or likelihood.
- Note 6: A risk may have one or more causes and, if it occurs, it may have one or more impacts.
Comparing the Definitions
| Dimension | PMBOK® Guide | ISO 31000:2018 |
|---|---|---|
| Core concept | Uncertain event or condition | Effect of uncertainty on objectives |
| Scope | Project objectives | Any level of objectives |
| Direction | Positive or negative | Positive and/or negative |
| Focus | Event-driven | Uncertainty-driven (broader) |
| Application | Project-specific | Enterprise-wide, adaptable to projects |
The key insight from comparing these two standards is that ISO 31000 takes a wider lens — it does not require a discrete "event" to constitute risk. Uncertainty itself, in any form that affects objectives, qualifies. Uncertainty-management sources (authors of Project Risk Management: Processes, Techniques and Insights) argue strongly that the focus should be on "uncertainty about anything that matters" rather than just identifiable events, because many sources of project uncertainty are ambiguous, diffuse, or systemic rather than event-shaped.
The Three Elements of Risk
Regardless of which formal definition you adopt, risk has three fundamental elements:
- The perception that something could happen — a recognised source of uncertainty exists.
- The likelihood of something happening — a probability, however imprecise, can be estimated.
- The consequences if it happens — an impact on one or more project objectives can be described.
This trio — perception, likelihood, and consequence — forms the foundation of every risk assessment technique you will encounter in this guide.
Risk Is Not Uncertainty
A common point of confusion: risk and uncertainty are not the same thing.
- Uncertainty is the broad condition of incomplete information — we do not know what will happen.
- Risk is uncertainty that matters — specifically, uncertainty that could affect the achievement of objectives.
Not all uncertainty is risk. Whether it rains on a Tuesday is uncertain, but it is only a project risk if your Tuesday involves outdoor concrete pours. The project manager's job is to identify which uncertainties are relevant to the project's objectives and manage those — not to catalogue every conceivable unknown.
Risk Is Both Threat and Opportunity
One of the most important paradigm shifts in modern risk management is the recognition that risk includes upside as well as downside.
The traditional view treated risk management as essentially defensive — identifying what could go wrong and preventing it. The contemporary view, reflected in both PMBOK and ISO 31000, treats risk management as a balanced discipline that seeks to:
- Minimise threats — reduce the probability and/or impact of adverse events.
- Maximise opportunities — increase the probability and/or impact of beneficial events.
Business risks are more general and relate to the organisation's overall health, whereas project risks relate specifically to the achievement of project objectives. A single event — say, a major technology shift — could simultaneously be a business opportunity and a project threat, or vice versa.
What Is Risk Management?
Having defined risk, we can now define the discipline that manages it.
ISO 31000:2018 frames risk management as coordinated activities for directing and controlling an organisation with regard to risk.
The earlier Australian Standard (AS/NZS 4360:1995) offered a more descriptive definition, characterising risk management as the set of tasks that identify, analyse, evaluate, treat, and monitor risk — activities that should be an integral part of good management practice and, to be effective, should be embedded in the organisation's culture.
Historical project-management guidance similarly presented project risk management as a structured process for understanding and responding to uncertainty.
Five Foundational Principles
Drawing from the supplied guidance (Project Risk Management by the supplied source material), five principles underlie effective risk management:
- Risk is any uncertainty you can control or track. The trick is identifying the critical risks — the ones that could make or break your project — and keeping them visible.
- Risk is integral to business and project planning. It is not a separate activity bolted on at the end; it is why projects exist and why planning matters.
- Focus on high-risk, resource-consuming tasks. You cannot monitor everything at once. Assessing risk is a question of rank-ordering and keeping your eye on what matters most.
- Monitor risk at key milestones. Identify decision points in the schedule where risk status needs to be reassessed — equipment tests, resource availability gates, technology validation points.
- Plan responses using scenarios. Create expected, pessimistic, and optimistic scenarios to understand the range of possible outcomes and prepare proportionate responses.
The Scope of Risk in Projects
Risk may include, but is certainly not limited to:
| Category | Examples |
|---|---|
| Strategic | Failure to recognise and take advantage of opportunities |
| Objective | Failure of the project to reach its objectives |
| Stakeholder | Client dissatisfaction; unfavourable publicity |
| Safety | Threat to physical safety; breach of security |
| Operational | Failure of equipment or computer systems; mismanagement |
| Legal / Contractual | Breach of legal or contractual responsibility; fraud |
| External | Failure to implement legislative changes; technological change |
| Financial | Deficiencies in financial controls and reporting |
This breadth is precisely why risk management cannot be an afterthought. It touches every knowledge area and every phase of the project lifecycle.
Common Pitfalls
Treating risk as exclusively negative. Teams that only look for threats miss opportunities to deliver above expectations, reduce costs, or accelerate schedules. Confusing risk with uncertainty. Attempting to catalogue every unknown is paralysing. Focus on uncertainty that matters — that which could affect objectives. Separating risk management from project planning. Risk management is not a standalone process to be completed once; it is a continuous, iterative activity woven into every planning and execution decision. Ignoring the human dimension. project-risk guidance and risk-attitude guidance note that despite well-defined processes and widespread practice, risk management often fails because the essential ingredient of risk attitude — how individuals and organisations perceive and respond to risk — is overlooked. Over-reliance on quantitative methods. While probability analysis and Monte Carlo simulation have their place, they require reliable input data. In many projects, professional judgement and qualitative assessment are more practical and equally valid.
Key Takeaways
- Risk is uncertainty that matters — specifically, uncertainty that could affect the achievement of project objectives, for better or worse.
- Two authoritative definitions shape our understanding: PMBOK focuses on uncertain events/conditions with positive or negative effects; ISO 31000 defines risk as the effect of uncertainty on objectives.
- Risk has three elements: perception, likelihood, and consequence.
- Risk includes both threats and opportunities — modern risk management balances minimising the downside with maximising the upside.
- Risk management is not a separate activity — it must be integral to project planning, embedded in organisational culture, and practiced continuously throughout the project lifecycle.
- Five principles guide effective practice: control what you can track, integrate with planning, focus on what matters most, monitor at milestones, and plan responses using scenarios.
Why Definitions Matter More Than You Think
In everyday language, "risk" is a simple word. In project management, it's anything but.
Ask five project managers to define risk, and you'll likely get five different answers. Some will talk about threats. Others will mention opportunities. A few might bring up uncertainty. And at least one will confuse risk with issues entirely.
This isn't a semantic game. How you define risk determines what your risk process captures—and what it misses. A team that defines risk purely as "things that can go wrong" will systematically fail to identify upside opportunities. A project manager who conflates risk with uncertainty will attempt to apply structured responses to situations that may require adaptive, learning-based approaches instead.
Getting the definitions right is the foundational act of project risk management.
What Is Risk? Defining the Concept with Precision
Notice that this definition explicitly includes positive effects. This is a deliberate departure from the colloquial understanding of risk as something purely dangerous. In project management, we deal with two distinct species of risk: Threats are risk events whose occurrence would have a negative impact on project objectives — cost blowouts, schedule delays, quality defects, or scope erosion. Opportunities are risk events whose occurrence would have a positive impact — cost savings, schedule acceleration, quality improvements, or scope enhancements that deliver additional value to stakeholders.
Risk studies frame this elegantly: a risk event in itself is neither good nor bad. A risk with low probability of occurring and very low impact may be insignificant enough to be ignored. Conversely, a risk with high probability and high impact may be worth not taking at all — or at least worth hedging against. The key variables are always the same: probability of occurrence and impact on project objectives.
The Risk Equation
The core mathematical relationship underpinning all risk analysis is deceptively simple:
Where:
| Variable | Definition |
|---|---|
| R | Risk exposure (the composite measure of overall risk) |
| P | Probability of the unfavourable (or favourable) outcome occurring |
| C | Consequence or impact of that outcome on project objectives |
This formula tells us that risk increases when either the probability of occurrence or the severity of consequence increases. However, as risk studies caution, this is not a linear relationship. The impact of risk on a project depends heavily on where you are in the project lifecycle. A risk event that materialises early — before significant resources have been committed — carries a fundamentally different consequence profile than the same event occurring deep into the execution phase when sunk costs are substantial.
Risk Sources: Internal vs External
Every risk event has a source — the underlying cause or condition that creates the uncertainty. These sources fall into two broad categories: External sources are factors beyond the project team's direct control. These include regulatory changes, weather events, supply chain disruptions, currency fluctuations, geopolitical shifts, and acts of force majeure. In defence contracting, external sources also encompass changes in government policy, export control regulations (such as ITAR and EAR), and sovereign capability requirements. Internal sources are factors within the project team's sphere of influence — though not always within their direct control. These include technical complexity, workforce capability gaps, design maturity, tooling availability, quality management system effectiveness, and stakeholder engagement.
The practical distinction is critical: you cannot prevent a cyclone from striking your fabrication yard (external), but you can develop contingency plans, maintain insurance, and design your construction schedule with weather windows built in (internal response to external risk).
What Exactly Is "Risk"?
The PMBOK Definition
Three things to notice immediately:
First, risk includes both threats and opportunities. This dual-sided view was somewhat controversial when first proposed but has since become mainstream, embedded in ISO 31000 and virtually every modern standard.
Second, risk is about effects on objectives. A risk isn't just "something bad happening"—it's something that moves a project objective (schedule, budget, scope, quality) away from its planned target, in either direction.
Third, risk has two defining dimensions: the probability (likelihood) that the event will occur, and the impact (consequence) if it does occur. These two components combine to determine the risk's significance.
The ISO 31000 Perspective
ISO 31000:2018 takes an even broader view, defining risk as the "effect of uncertainty on objectives." This definition encompasses threats, opportunities, and the full spectrum of uncertain outcomes that organisations face.
The uncertainty-management sources Perspective
Risk management scholars uncertainty-management sources argue for a still wider lens. They propose defining risk as:
Under this view, opportunities and threats are sources of uncertainty that cause risk, rather than risk in themselves. This is a subtle but powerful distinction: it shifts the focus from cataloguing individual risk events to understanding the deeper currents of uncertainty that shape project outcomes.
