KEVOS® Project Delivery Handbook
Project Risk Management
Why Risk Management Is the Skill That Separates Good PMs from Great Ones A practical KEVOS handbook for project delivery teams.
In this handbook article
- Why Risk Management Is the Skill That Separates Good PMs from Great Ones
- What Is Project Risk — And When Does It Peak?
- The Risk–Investment Paradox
- The Risk Management Process: A Six-Step Framework
- Step 1 — Establish the Context
- Step 2 — Identify the Risks
- Risk Categories — The Breakdown Structure
- Step 3 — Analyse the Risks (Qualitative)
- The Risk Rating Matrix
- Step 4 — Analyse the Risks (Quantitative)
- Step 5 — Treat the Risks (Plan Risk Responses)
- Step 6 — Monitor, Review, and Control
- How to Build It: The Risk Management Plan
- The Pitfalls: Where Risk Management Goes Wrong
- Key Takeaways
Why Risk Management Is the Skill That Separates Good PMs from Great Ones
Every project carries uncertainty. The steel shipment might arrive late. The regulator might change the approval criteria mid-build. The lead engineer might resign on day forty-five. These aren't hypothetical nightmares — they are the everyday realities of projects in heavy engineering, defence, and manufacturing.
The difference between a project that absorbs a shock and one that collapses under it comes down to a single discipline: Project Risk Management.
Neglecting risk management doesn't just increase the chance of cost overruns or schedule slippage — it can lead to total project failure. In today's commercial environment, project managers are held accountable and liable for their conduct, and judicial systems tend to sympathise with the end user, not the service provider. Professional judgement must therefore align with public expectations.
Core Definition: Project Risk Management is the art and science of identifying, assessing, and responding to project risk throughout the life of a project and in the best interests of its objectives. It is a formal, systematic, and continuing integrative function that spans the entire project life cycle.
What Is Project Risk — And When Does It Peak?
Risk is not static. It moves, shifts, and transforms as a project progresses through its life cycle. Understanding when risk is highest — and when the stakes are highest — is the first conceptual leap every PM must make.
The Risk–Investment Paradox
During the planning phase, opportunity and risk are both relatively high, but because investment is still low, the amount at stake remains modest. This is the cheapest time to influence outcomes.
During the implementation phase, risks progressively fall as unknowns become knowns — but the amount at stake rises steadily as resources are committed. A risk that was manageable in planning can become devastating in execution.
Key Insight: Risk is always relative to the circumstances at the time of assessment. A risk rated "low" today could escalate to "high" tomorrow if conditions change. This is why risk management must be a continuous process, not a one-off exercise.
Relationship details
| From | Relationship | To |
|---|---|---|
| High Risk / Low Stakes | leads to | Declining Risk / Rising Stakes |
| Declining Risk / Rising Stakes | leads to | Low Risk / Highest Stakes |
Relationship details
| From | Relationship | To |
|---|---|---|
| R1 | leads to | R2 |
| R2 | leads to | R3 |
| R3 | leads to | R4 |
| I1 | leads to | I2 |
| I2 | leads to | I3 |
| I3 | leads to | I4 |
| Project Life Cycle → — Concept → Definition → Execution → Closeout | leads to | R1 |
| Level of Risk & Opportunity | leads to | R1 |
| Amount at Stake / — Cumulative Investment | leads to | I4 |
The Risk Management Process: A Six-Step Framework
The risk management process follows a structured, repeatable cycle. Each step feeds the next, and the entire cycle operates on a Plan–Do–Check–Act loop.
Relationship details
| From | Relationship | To |
|---|---|---|
| 1. Establish — Context | leads to | 2. Identify — Risks |
| 2. Identify — Risks | leads to | 3. Analyse — Risks |
| 3. Analyse — Risks | leads to | 4. Assess — Risk |
| 4. Assess — Risk | leads to | 5. Treat — Risks |
| 5. Treat — Risks | leads to | 6. Monitor — & Review |
| 6. Monitor — & Review | Continuous — Feedback | 1. Establish — Context |
Step 1 — Establish the Context
Before identifying anything, define the scope and boundaries of the risk management effort. What are the project's strategic objectives? What is the organisation's risk appetite? What external factors (regulatory, market, environmental) frame the operating environment?
Step 2 — Identify the Risks
This is the creative, exhaustive phase. Use brainstorming, checklists, stakeholder interviews, SWOT analysis, lessons learned, and documentation reviews to surface everything that could go wrong — or right.
Warning: Project managers often concentrate on technical risks and fail to identify management, political, and economic issues. A complete risk register covers all categories.
Risk Categories — The Breakdown Structure
Risks can be categorised in multiple ways. A common framework for construction and engineering projects uses five pillars:
| Category | Example Risk Events |
|---|---|
| Economic | Inflation, energy shortage, financial uncertainty, currency fluctuation |
| Contractual | Failure of payment, delay disputes, coordination failure, change orders, labour disputes |
| Political | Environmental regulation, public disorder, government acts, tax changes, permits |
| Construction | Labour uncertainty, equipment uncertainty, material uncertainty, delayed site access, quantity variation, defective work |
| Management | Productivity, quality control, safety, mistakes, management competence |
Alternatively, risks can be mapped against PMBOK Knowledge Areas — Scope, Time, Cost, Quality, Human Resources, Communications, and Procurement — to ensure nothing falls through the cracks.
Step 3 — Analyse the Risks (Qualitative)
Qualitative analysis prioritises risks by assessing their probability and impact using defined rating scales.
Probability Matrix:
| Level | Descriptor | Description |
|---|---|---|
| A | Almost Certain | Expected to occur in most circumstances |
| B | Likely | Will probably occur in most circumstances |
| C | Possible | Might occur at some time |
| D | Unlikely | Could occur at some time |
| E | Rare | May occur only in exceptional circumstances |
Impact Matrix:
| Level | Descriptor | Description |
|---|---|---|
| 1 | Insignificant | No injuries, no environmental/heritage impact, low financial loss |
| 2 | Minor | First aid treatment, environmental impact remedied on-site, medium financial loss |
| 3 | Moderate | Medical treatment required, environmental impact managed with assistance, high financial loss |
| 4 | Major | Extensive injuries, loss of production capability, long-term detrimental effects, major financial loss |
| 5 | Catastrophic | Death, significant environmental/heritage impact, huge financial loss |
The Risk Rating Matrix
Cross-referencing probability and impact produces a risk rating that drives response urgency:
Low Impact" --> "High Impact · Low Likelihood" --> "High Likelihood
HIGH
- Classify relevant stakeholders here
EXTREME
- Classify relevant stakeholders here
MODERATE
- Classify relevant stakeholders here
LOW
- Classify relevant stakeholders here
| Insignificant (1) | Minor (2) | Moderate (3) | Major (4) | Catastrophic (5) | |
|---|---|---|---|---|---|
| Almost Certain (A) | High | High | Extreme | Extreme | Extreme |
| Likely (B) | Moderate | High | High | Extreme | Extreme |
| Possible (C) | Low | Moderate | High | Extreme | Extreme |
| Unlikely (D) | Low | Low | Moderate | High | Extreme |
| Rare (E) | Low | Low | Moderate | High | High |
Risk Response Actions by Rating:
| Rating | Required Action |
|---|---|
| Extreme | Immediate action required |
| High | Senior management attention required |
| Moderate | Management responsibility must be specified |
| Low | Manage by routine procedures |
Step 4 — Analyse the Risks (Quantitative)
Once qualitatively prioritised, high-ranking risks can be examined numerically using techniques such as:
- Influence diagrams — mapping cause-and-effect relationships
- Probability trees — charting branching outcomes with assigned probabilities
- Monte Carlo simulation — modelling thousands of scenarios to determine statistical distributions of time and cost outcomes
- Sensitivity analysis — identifying which variables have the greatest effect on project objectives
- Expected Monetary Value (EMV):
Where = probability of the risk event and = monetary impact if the event occurs.
Step 5 — Treat the Risks (Plan Risk Responses)
With risks analysed and prioritised, the PM must decide how to respond. The PMBOK identifies distinct strategies for threats and opportunities:
Strategies for Negative Risks (Threats):
| Strategy | Description | Example |
|---|---|---|
| Avoid | Eliminate the threat entirely | Extend the schedule to avoid working through cyclone season |
| Transfer | Shift consequence to a third party | Take out insurance or subcontract the high-risk work package |
| Mitigate | Reduce probability or impact | Hire a more experienced contractor, add quality inspections |
| Accept | Acknowledge the risk and prepare a contingency | Set aside a contingency reserve for potential cost increases |
Strategies for Positive Risks (Opportunities):
| Strategy | Description | Example |
|---|---|---|
| Exploit | Ensure the opportunity is realised | Assign top talent to capture an early-completion bonus |
| Share | Partner with a third party better positioned to capture value | Form a joint venture to access new technology |
| Enhance | Increase probability or positive impact | Accelerate procurement to lock in favourable material prices |
Contingent Response Strategies are pre-planned actions triggered by specific events, such as a missed milestone or a change in regulatory status.
Step 6 — Monitor, Review, and Control
Risk management does not end once the register is built. Throughout implementation:
- Reassess existing risks at each milestone or review point
- Identify newly emerging risks as unknowns become knowns
- Track the effectiveness of risk treatments
- Update the Risk Register and Risk Management Plan continuously
How to Build It: The Risk Management Plan
The Risk Management Plan is a standalone document, typically annexed to the Project Management Plan. It should include:
- An overview of the project and key risk categories
- Assigned responsibilities for control and containment of identified risks
- Defined milestones and review points for reassessment
- Chosen risk assessment methodologies
- A Risk Register combining all risk data, including responsibilities, review actions, and performance measurement guidance
Relationship details
| From | Relationship | To |
|---|---|---|
| Risk Management Plan | leads to | Project Overview — & Key Categories |
| Risk Management Plan | leads to | Assigned — Responsibilities |
| Risk Management Plan | leads to | Milestones & — Review Points |
| Risk Management Plan | leads to | Assessment — Methodologies |
| Risk Management Plan | leads to | Risk Register |
| Risk Register | leads to | Source & Nature |
| Risk Register | leads to | Consequences — & Likelihood |
| Risk Register | leads to | Existing Controls |
| Risk Register | leads to | Risk Rating |
| Risk Register | leads to | Treatment Schedule — & Action Plan |
The Pitfalls: Where Risk Management Goes Wrong
- Treating it as a one-off exercise. Risk management must be continuous. A risk register created in planning and never updated is worthless by execution.
- Focusing only on technical risks. Economic, political, contractual, and management risks are just as capable of derailing a project.
- Ignoring the "Amount at Stake" curve. The cheapest time to manage risk is early — but most PMs don't invest sufficient effort until the implementation phase, when changes are expensive.
- Failing to assign ownership. Every risk must have a named owner with authority and accountability to act.
- Confusing risk identification with risk analysis. Listing risks is not the same as prioritising them. Without probability–impact assessment, the team cannot focus on what matters most.
Key Takeaways
- Risk management is a continuous, integrative function — not a deliverable you complete once and file away.
- Risk and investment move in opposite directions through the project life cycle. Act early when influence is highest and cost of change is lowest.
- Categorise risks broadly — economic, contractual, political, construction, and management — to avoid blind spots.
- Use the Probability × Impact matrix to prioritise risks and determine the appropriate level of management response.
- Choose the right response strategy — Avoid, Transfer, Mitigate, or Accept for threats; Exploit, Share, or Enhance for opportunities.
- The Risk Register and Risk Management Plan are living documents that must be reviewed and updated at every milestone.
