← ArticlesQualitative Project Risk AnalysisProject Delivery · RiskLesson 1/8← PrevNext →
GuidePublished 13 Aug 202611 min readBy Kevin Joginqualitative risk analysisprobability impactrisk priorityrisk urgency

Project Delivery · Project Risk Management

Qualitative Project Risk Analysis

A defensible approach to screening and prioritising risks using calibrated likelihood, consequence, urgency, proximity and data-quality judgements.

11 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

A defensible approach to screening and prioritising risks using calibrated likelihood, consequence, urgency, proximity and data-quality judgements. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Confirm criteria
  • Assess likelihood and consequence
  • Consider urgency and proximity
  • Challenge data quality and bias
  • Prioritise action and deeper analysis
  1. Confirm criteria
  2. Assess likelihood and consequence
  3. Consider urgency and proximity
  4. Challenge data quality and bias
  5. Prioritise action and deeper analysis

Why You Cannot Treat Every Risk Equally

A complex defence programme might identify 200 or more individual risks during the Identify Risks process. A project manager who attempts to develop detailed response strategies for every single one will exhaust the team's time, budget, and attention — accomplishing nothing well while attempting everything. The corresponding activity in the earlier process model — Perform Qualitative Risk Analysis — exists to solve this problem. It separates the critical few from the trivial many, enabling focused allocation of management attention and contingency resources to the risks that matter most.

Qualitative risk analysis assesses each risk in terms of its probability of occurrence and impact on project objectives, using the definitions and scales established in the Risk Management Plan. The result is a prioritised risk list that tells the project manager where to focus — which risks demand immediate, aggressive response planning, which should be monitored on a watch list, and which warrant further quantitative analysis.

What Is the corresponding activity in the earlier process model — Perform Qualitative Risk Analysis?

Inputs Tools & Techniques Outputs
Risk Management Plan Risk Probability & Impact Assessment Project Documents Updates (Risk Register Updates)
Scope Baseline Probability & Impact Matrix
Risk Register Risk Data Quality Assessment
Enterprise Environmental Factors Risk Categorisation
Organisational Process Assets Risk Urgency Assessment
Expert Judgment

The process takes the raw risk register from the corresponding activity in the earlier process model, applies six assessment tools, and produces an updated register with priority rankings, category groupings, urgency classifications, and trend data.

How It Works: Six Tools and Techniques

1. Risk Probability and Impact Assessment

Each risk in the register is assessed on two dimensions:

Risk Probability — the likelihood that the risk event will occur. This is expressed using the probability scale defined in the Risk Management Plan (e.g., Very Low / Low / Medium / High / Very High, or numerical values like 0.10, 0.25, 0.50, 0.75, 0.90). Risk Impact — the potential effect on project objectives (scope, schedule, cost, quality) if the risk event does occur. This is expressed using the impact scale defined in the Risk Management Plan.

Both the probability and impact are assigned scores according to the pre-defined scales in the Risk Management Plan. These scores are then combined — typically by multiplication — to produce a risk score that enables ranking and prioritisation.

Risk Score=Probability×Impact\text{Risk Score} = \text{Probability} \times \text{Impact}

For example, a risk with a probability of 0.50 (Medium) and an impact of 0.80 (Very High) would receive a risk score of:

Risk Score=0.50×0.80=0.40\text{Risk Score} = 0.50 \times 0.80 = 0.40

2. Probability and Impact Matrix (PIM)

The PIM is the core tool of qualitative analysis. It maps every combination of probability and impact to a risk rating — typically using a colour-coded grid that visually separates extreme, high, moderate, and low-priority risks.

The PMBOK® Guide provides a standard matrix format that addresses both threats and opportunities: Threats (Negative Risks):

Probability Impact 0.05 Impact 0.20 Impact 0.60 Impact 0.80
0.90 0.05 0.18 0.54 0.72
0.75 0.04 0.15 0.45 0.60
0.50 0.03 0.10 0.30 0.40
0.25 0.01 0.05 0.15 0.20
0.10 0.01 0.02 0.06 0.08

The specific thresholds that separate the risk rating zones are set by the organisation during the corresponding activity in the earlier process model (Plan Risk Management), not during the analysis itself. This ensures consistency across assessors and prevents individual biases from distorting the prioritisation.

Applying the Matrix: A Defence Manufacturing Example

Consider three risks identified on an armoured vehicle upgrade programme:

Risk Probability Impact Risk Score Rating
R-003: Ceramic armour tiles may exhibit micro-cracking under thermal cycling 0.50 (Medium) 0.80 (Very High — quality/safety critical) 0.40 High
R-005: Allied nation competing for same supplier's capacity 0.75 (High) 0.60 (High — 3-month schedule delay) 0.45 High
R-004: Upgrade facility bay assumption may be invalid 0.25 (Low) 0.20 (Low — minor schedule adjustment) 0.05 Minimal

R-003 and R-005 move into the priority zone for detailed response planning. R-004 goes onto the watch list.

3. Risk Data Quality Assessment

Before trusting the probability and impact assessments, the team must evaluate the quality of the data underlying those assessments. This involves examining:

Quality Dimension Question
Understanding How well is this risk understood? Is the cause-risk-effect chain clearly articulated?
Accuracy Are the probability and impact estimates based on reliable data, or on guesswork?
Reliability Would different assessors arrive at similar ratings for this risk?
Integrity Is the data free from bias — or has it been influenced by political pressures, optimism bias, or groupthink?

If the data quality for a particular risk is unacceptable — for example, if the probability estimate is based on no historical precedent and no expert input — the team may need to gather additional information before the assessment can be considered reliable. In practice, low-quality assessments are flagged and targeted for deeper investigation, often through expert interviews or analogy-based estimation from similar programmes.

4. Risk Categorisation

Grouping risks by their RBS category — technical, programmatic, supply chain, regulatory, etc. — reveals patterns that may not be visible when risks are examined individually. If the qualitative analysis reveals that 60% of the high-priority risks fall within the "Supply Chain" category, this signals a systemic vulnerability that warrants a holistic response strategy (e.g., a comprehensive supplier development programme) rather than individual risk-by-risk responses.

5. Risk Urgency Assessment

Not all risks demand immediate attention. A risk with a high probability and high impact that could materialise next week is qualitatively different from an equally severe risk whose trigger window is eighteen months away. Risk urgency assessment considers the time available to affect a risk response and the proximity of the risk event.

Urgency indicators include:

In some qualitative approaches, urgency is combined with the probability-impact score to produce a final risk severity rating — a three-dimensional assessment that captures how bad, how likely, and how soon.

6. Expert Judgment

Expert judgment in qualitative analysis relates specifically to assessing the probability and impact of individual risks. Experts with experience of similar projects can provide calibrated estimates where historical data is unavailable — which is frequently the case for novel defence systems.

How It Works: Outputs — Project Documents Updates

The primary output is an updated Risk Register enriched with the following information: Relative ranking or priority list of project risks — risks classified by individual significance using the probability and impact matrix. Risks may be listed by priority separately for schedule, cost, and performance, since organisations may value one objective over another. Risks grouped by categories — pointing to common underlying causes that may suggest holistic response strategies. Discovering concentrations of risk can improve the effectiveness of risk responses by addressing root causes rather than individual symptoms. List of risks requiring near-term response — those risks whose urgency assessment indicates that action must be taken immediately, separated from those that can be addressed at a later date. List of risks for additional analysis — some risks may warrant further quantitative analysis (the corresponding activity in the earlier process model) before response strategies can be developed. These are flagged for escalation to Monte Carlo simulation, EMV analysis, or decision tree analysis. Watch lists of low-priority risks — those not assessed as significant are placed on a monitoring list. They are not forgotten — they are tracked at a lower frequency and reviewed for any changes in probability, impact, or urgency. Trends in analysis results — because qualitative analysis is iterative, trends for particular types of risk may become apparent over time. An increasing concentration of high-priority risks in a specific category signals a developing systemic issue.

Qualitative vs Quantitative: Understanding the Boundary

Qualitative analysis uses descriptive scales (High/Medium/Low) and subjective expert judgment to assess probability and impact. It is relatively fast, inexpensive, and applicable to all projects regardless of size or data availability.

Quantitative analysis (the corresponding activity in the earlier process model) uses numerical data, statistical techniques, and mathematical models (Monte Carlo simulation, decision trees, sensitivity analysis) to calculate precise probability distributions and expected monetary values.

Dimension Qualitative (11.3) Quantitative (11.4)
Data requirement Expert opinion and descriptive scales Historical data and probability distributions
Output Prioritised risk list (ordinal ranking) Numerical probability distributions, EMV, confidence levels
Speed Fast (hours to days) Slow (days to weeks)
Cost Low (workshop-based) High (specialist tools and analysts)
When sufficient Small to medium projects; initial prioritisation on all projects Large, complex projects where cost and schedule confidence levels are critical

In defence and heavy engineering, the rule of thumb is: always perform qualitative analysis to prioritise the risk register, then selectively apply quantitative analysis to the highest-priority risks and to the overall project schedule and cost confidence assessment.

Common Pitfalls

Treating qualitative analysis as precise measurement. A risk score of 0.40 is not meaningfully different from 0.42. Qualitative analysis produces ordinal rankings (first, second, third priority), not precise cardinal measurements. Over-engineering the scoring system creates false precision that undermines trust in the process. Allowing bias to dominate. Optimism bias, anchoring to previous assessments, and groupthink can systematically distort probability and impact ratings. Using structured techniques like the Delphi method, independent pre-meeting assessments, and explicit bias awareness training helps mitigate these distortions. Failing to reassess. Qualitative analysis must be repeated regularly because risk profiles change as the project progresses. A risk rated "Low" during design may become "High" during integration as the trigger window narrows. Ignoring opportunities. The probability and impact matrix applies to both threats and opportunities. Teams that only assess downside risks miss the chance to proactively pursue upside scenarios. Inconsistent use of scales. If different assessors interpret "High probability" differently — one meaning 60% and another meaning 90% — the resulting prioritisation is meaningless. This is why the corresponding activity in the earlier process model must define these scales explicitly.

Key Takeaways

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Confirm criteria is defined, owned, evidenced and linked to the relevant project decision.
Check 02Assess likelihood and consequence is defined, owned, evidenced and linked to the relevant project decision.
Check 03Consider urgency and proximity is defined, owned, evidenced and linked to the relevant project decision.
Check 04Challenge data quality and bias is defined, owned, evidenced and linked to the relevant project decision.
Check 05Prioritise action and deeper analysis is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

NEXT LESSON →Risk Matrix Design and CalibrationGuide · RiskInherent, Current and Residual RiskGuide · RiskPareto Prioritisation for Project RiskGuide · RiskSelecting Quantitative Risk Analysis MethodsGuide · Risk