Why Analysis Without Action Is Wasted Effort
A beautifully constructed risk register, a meticulously populated probability-impact matrix, and a professionally executed Monte Carlo simulation are all worthless if they do not lead to concrete, actionable response strategies that change the project's risk profile. The corresponding activity in the earlier process model — Plan Risk Responses — is where risk management transitions from analysis to action. It is the process of developing options and actions to enhance opportunities and reduce threats to project objectives.
Every response strategy must satisfy five criteria to be effective: it must be appropriate to the significance of the risk, cost-effective in meeting the challenge, realistic within the project context, agreed upon by all parties involved, and owned by a responsible person. A response that is theoretically elegant but practically unaffordable, or one that no individual is accountable for implementing, will fail when the risk materialises.
What Is the corresponding activity in the earlier process model — Plan Risk Responses?
| Inputs | Tools & Techniques | Outputs |
|---|---|---|
| Risk Management Plan | Strategies for Negative Risks or Threats | Project Management Plan Updates |
| Risk Register | Strategies for Positive Risks or Opportunities | Project Document Updates |
| Contingent Response Strategies | ||
| Expert Judgment |
The process takes the prioritised, analysed risk register and assigns a specific response strategy — along with an owner, budget, timeline, and trigger conditions — to each risk that warrants action.
How It Works: Four Strategies for Threats
When a risk represents a threat — an uncertain event that would negatively impact project objectives if it occurred — the project team selects from four possible strategies:
1. Avoid — Eliminate the Risk Entirely
Avoidance involves taking action to reduce the probability of the risk and/or its impact to zero. This typically means changing the project plan to circumvent the risk entirely — altering scope, schedule, strategy, or approach to remove the source of uncertainty.
Avoidance is the most decisive strategy, but it is not always possible. Some risks are inherent to the project scope and cannot be eliminated without fundamentally changing what the project delivers.
2. Transfer — Shift the Liability
Transfer involves shifting the management burden and financial impact of a risk to a third party. It does not eliminate the risk — it simply ensures that if the risk materialises, someone else bears the consequences.
Common transfer mechanisms include:
| Mechanism | How It Works | Defence Context |
|---|---|---|
| Insurance | The insurance company assumes financial liability in exchange for a premium | Construction all-risk insurance covering physical damage during facility build |
| Fixed-Price Contracts | The contractor assumes cost overrun risk in exchange for a price premium | Fixed-price subcontract for hull fabrication — the subcontractor bears the cost risk of material price increases |
| Performance Bonds | A surety guarantees the contractor's performance; if the contractor fails, the surety pays | Performance bond on a critical subsystem supplier ensuring delivery of a qualified product |
| Warranties and Guarantees | The supplier assumes post-delivery risk of defects or failures | Extended warranty on a propulsion system covering defects discovered during the first 5,000 operating hours |
3. Mitigate — Reduce Probability and/or Impact
Mitigation involves taking early action to reduce the probability of the risk occurring, its impact if it does occur, or both. Mitigation does not eliminate the risk — it reduces it to an acceptable level.
| Mitigation Approach | What It Targets | Defence Manufacturing Example |
|---|---|---|
| Reduce probability | Makes the risk event less likely to occur | Conducting additional prototype testing before committing to a production design — reducing the probability of production-stage design rework |
| Reduce impact | Limits the damage if the risk event occurs | Pre-qualifying an alternative titanium supplier so that if the primary supplier fails, the schedule impact is weeks rather than months |
| Reduce both | Addresses probability and impact simultaneously | Implementing a comprehensive welding quality programme with enhanced NDE inspection — reducing both the probability of defects and the impact of any defects that occur (caught earlier, fixed cheaper) |
Mitigation is the most commonly applied strategy and the one that demands the most creativity and engineering judgment. The project manager must balance the cost of mitigation against the expected cost of the risk — a mitigation action that costs more than the expected value of the risk it addresses is not cost-effective.
4. Accept — Acknowledge and Prepare
Acceptance is the strategy chosen when the team decides to take no proactive action to address a risk, either because the risk is assessed as low-priority or because the cost of any other strategy would be disproportionate to the risk itself.
Acceptance comes in two forms:
Passive acceptance — the team simply acknowledges the risk and decides to deal with it if and when it occurs, without pre-planning a specific response. Active acceptance — the team establishes a contingency reserve (time, money, or resources) that will be deployed if the risk materialises. This is the more disciplined form of acceptance and is appropriate for risks that are well-understood but deemed too expensive or impractical to avoid, transfer, or mitigate.
How It Works: Four Strategies for Opportunities
When a risk represents an opportunity — an uncertain event that would positively impact project objectives if it occurred — the project team selects from four parallel strategies:
1. Exploit — Make It Happen
Exploitation aims to ensure that the opportunity is realised with certainty. This involves taking decisive action to capture the upside potential.
2. Share — Partner for Mutual Benefit
Sharing involves allocating some or all of the ownership of the opportunity to a third party who is best able to capture it for the benefit of the project. Sharing mechanisms include:
- Risk-sharing partnerships
- Joint ventures (JVs)
- Special-purpose companies
- Teaming agreements
3. Enhance — Increase the Odds
Enhancement increases the probability that the opportunity will occur, its positive impact if it does, or both.
4. Accept — Be Ready If It Comes
Acceptance of an opportunity means being willing to take advantage of it if it materialises, but not actively pursuing it. This is appropriate for opportunities with low probability or where the cost of exploitation, sharing, or enhancement exceeds the expected benefit.
Contingent Response Strategies
Contingent response strategies are a special category of response that bridges the gap between proactive planning and reactive execution. A contingent response is a pre-planned action that is only triggered when specific predefined conditions are met.
The key characteristics of contingent responses are:
Pre-planned: The response is designed and resourced in advance, not improvised in the heat of a crisis. Conditional: The response is only activated when a specific trigger event occurs — a leading indicator that the risk is about to materialise. Time-sensitive: There must be sufficient warning between the trigger event and the risk impact to allow the response to be implemented effectively.
The Mirror Symmetry: Threats and Opportunities Side by Side
The four threat strategies and four opportunity strategies are mirror images of each other, reflecting the dual nature of risk as both downside and upside uncertainty:
| Threat Strategy | Action | ↔︎ | Opportunity Strategy | Action |
|---|---|---|---|---|
| Avoid | Eliminate the risk entirely | ↔︎ | Exploit | Ensure the opportunity is realised |
| Transfer | Shift liability to third party | ↔︎ | Share | Allocate to partner best able to capture |
| Mitigate | Reduce probability/impact | ↔︎ | Enhance | Increase probability/impact |
| Accept | Acknowledge with contingency | ↔︎ | Accept | Be ready to take advantage |
This symmetry is not just conceptual elegance — it reminds the project manager that every risk assessment should consider both the threat and opportunity dimensions. A regulatory change, for example, might threaten the current design approach while simultaneously creating an opportunity to leapfrog competitors by adopting a more advanced solution ahead of the compliance deadline.
How It Works: Outputs
Project Management Plan Updates
The risk management plan itself may need modification as response strategies are developed. Response strategies that involve scope changes, additional procurement, or schedule modifications will ripple into the schedule management plan, cost management plan, and procurement management plan.
Project Document Updates
The risk register is updated to include, for each prioritised risk:
- The selected response strategy
- Specific actions to implement the strategy
- The risk owner responsible for execution
- Trigger conditions for contingent responses
- Budget and timeline for response implementation
- Secondary risks introduced by the response strategy itself
- Residual risks remaining after the response is implemented
- Fallback plans if the primary response fails
Common Pitfalls
Selecting a strategy without costing it. Every response strategy has a cost — even acceptance (through contingency reserves). If the cost of mitigation exceeds the EMV of the risk, the strategy is not economically rational unless non-financial factors (safety, reputation, regulatory compliance) override the financial calculus. Failing to assign a risk owner. A response strategy without an accountable individual is a response strategy that will not be executed. The risk owner must have the authority, resources, and accountability to implement the response when required. Ignoring secondary risks. Every response strategy can introduce new risks. Transferring risk through a fixed-price contract may introduce a secondary risk that the contractor cuts quality. Mitigating a schedule risk by adding overtime may introduce a secondary risk of workforce fatigue and error rates. These secondary risks must be identified, assessed, and added to the register. Defaulting to acceptance for everything. Acceptance is the easiest strategy to "implement" because it requires no immediate action. Lazy risk management manifests as a register full of "accepted" risks with poorly sized contingency reserves. True acceptance is a deliberate, informed decision — not the absence of a decision. Treating response planning as a one-time event. As the project progresses and the risk landscape evolves, response strategies must be reviewed and updated. A mitigation strategy that was appropriate during the design phase may be irrelevant during the integration phase.
Key Takeaways
Plan Risk Responses (11.5) develops concrete actions to reduce threats and enhance opportunities — bridging the gap between risk analysis and risk management.
Four strategies address threats: Avoid (eliminate), Transfer (shift liability), Mitigate (reduce probability/impact), and Accept (acknowledge with contingency).
Four strategies address opportunities: Exploit (ensure realisation), Share (partner to capture), Enhance (increase probability/impact), and Accept (be ready if it comes).
Contingent response strategies are pre-planned actions triggered by predefined conditions — they combine the discipline of proactive planning with the efficiency of conditional execution.
Every response must be appropriate, cost-effective, realistic, agreed upon, and owned by a responsible person with the authority and resources to act.
Secondary risks introduced by response strategies must themselves be identified and assessed — risk management is recursive by nature.
From Strategy to Documentation: Controls and Treatment Plans
The Controls Register — Documenting What's Already in Place
Before planning new responses, the project team must understand what controls are already in place and whether they are working. The Controls Register is the document that captures this information.
The Controls Register structure is straightforward:
| Column | Purpose |
|---|---|
| Ref | Cross-reference to risk register entry |
| The Risk | Risk event title |
| Details of Existing Controls | Complete description of each control measure currently in place |
The value of the Controls Register lies in forcing an honest assessment of current risk exposure. Many project teams discover, when they actually document existing controls, that:
- Controls exist on paper but are not consistently implemented
- Controls address only part of the risk (e.g., prevention but not detection)
- Controls were designed for a previous project phase and are no longer relevant
- Multiple overlapping controls exist for some risks while other risks have no controls at all
Worked Example — Site Security Controls
Consider the "Trespassers" risk from a construction site. The Controls Register documents four existing controls:
| Ref | Risk | Control Description |
|---|---|---|
| P1 | Trespassers | All visitors to the Site are required to report to the office |
| P1 | Trespassers | No trespassing signs located around site perimeter |
| P1 | Trespassers | Staff requested to ensure all buildings are locked when not occupied |
| P1 | Trespassers | Site fitted with intruder alarms and exterior security lighting |
These controls fall into two categories:
Preventive controls (reduce the likelihood of the risk occurring):
- Visitor reporting requirement
- Building locking procedures
Detective controls (reduce the time to detect and respond when the risk occurs):
- No trespassing signage (deterrence + legal basis for prosecution)
- Intruder alarms and security lighting
The risk register's assessment that implementation is "Inadequate" might reflect that staff are not consistently locking buildings, that the visitor reporting requirement is not enforced at all entry points, or that the intruder alarm system has not been tested recently. This assessment drives the need for a Treatment Plan.
The Treatment Plan — Documenting What Will Be Done
The Risk Treatment Plan documents the response actions for risks that require further intervention beyond existing controls. It is the action plan that closes the gap between current residual risk and the target risk level.
The Treatment Plan structure captures the full decision-making chain:
| Column | Purpose |
|---|---|
| Ref | Cross-reference to risk register |
| The Risk | Risk event title |
| Possible Treatment Options | All options considered — not just the preferred one |
| Preferred Options | The selected treatment approach |
| Cost/Benefit Assessment & Resource Requirement | Economic justification |
| Risk Rating After Treatment | Expected residual risk level post-implementation |
| Responsible Officer | Named individual accountable for implementation |
| Timeline | Implementation schedule |
| Outcome from Action | Documented result after implementation |
Worked Example — Trespasser Treatment Plan
For the P1 Trespassers risk, the Treatment Plan documents four treatment options:
Treatment 1 — Security Guards at Events
- Preferred option: Yes
- Cost/benefit: Direct charge per event
- Risk rating after treatment: Medium
- Responsible: Site Manager
- Timeline: Immediate implementation
Treatment 2 — Comprehensive Visitor Management Policy
- Possible option: New visitor policy — all visitors report to reception, fill in visitors' register, receive identification tags, are escorted to venue, and escorted back to sign out and return tags. Anyone without identification to be challenged. All staff to wear identification tags.
- Preferred option: Visitors report to reception, receive and return identification tags. Anyone without tags to be challenged. All staff to wear tags.
- Cost/benefit: Plastic tags produced at minimum cost and recyclable
- Risk rating after treatment: Medium
- Responsible: Site Office
- Timeline: Immediate implementation
Treatment 3 — Equipment Security
- Possible option: Secure all equipment — strap computers to desks, store valuables in locked areas
- Preferred option: All valuables stored in secure storerooms
- Cost/benefit: Minimal cost and resource demands
- Risk rating after treatment: Medium
- Responsible: Project Manager
- Timeline: Completed by specified date
Treatment 4 — Physical Security Upgrades
- Possible option: Security areas to have metal grilles fixed to windows and deadlocks fitted to doors
- Preferred option: Upgrade existing secure storerooms
- Cost/benefit: Minimal cost for maximised benefit
- Risk rating after treatment: Medium
- Responsible: Site Manager
- Timeline: Completed by start of next project phase
