← ArticlesWhy Project Risk Management MattersProject Delivery · RiskLesson 2/8← PrevNext →
GuidePublished 13 Aug 202613 min readBy Kevin Joginrisk valueproject successcritical success factorsproactive management

Project Delivery · Project Risk Management

Why Project Risk Management Matters

A decision-focused business case for proactive risk management, including value protection, opportunity capture, success factors and common causes of ineffective practice.

14 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

A decision-focused business case for proactive risk management, including value protection, opportunity capture, success factors and common causes of ineffective practice. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Connect risk to value
  • Expose assumptions early
  • Prioritise scarce attention
  • Make responses executable
  • Measure whether practice changes decisions
  1. Connect risk to value
  2. Expose assumptions early
  3. Prioritise scarce attention
  4. Make responses executable
  5. Measure whether practice changes decisions

Why Good Risk Management Is Harder Than It Sounds

In theory, risk management is straightforward: identify what could go wrong (or right), assess the probability and impact, develop response plans, and monitor throughout the project lifecycle. The logic is clear, the tools exist, and the frameworks are well-documented.

In practice, most project risk management fails.

One study found that a third of all software projects were terminated before completion, while more than 50% cost approximately double the estimate. When practitioners were surveyed, the highest-ranked factor for project failure was inadequate risk management—above lack of top management involvement and weak business cases .

The gap between theory and practice isn't a knowledge gap—it's an implementation gap. Risk management fails not because teams don't know the process, but because organisational culture, individual psychology, and structural barriers systematically prevent the process from working as designed.

What Does Effective Risk Management Look Like?

The Six Foundations

Effective risk management consistently exhibits these characteristics:

  1. Consistency — Standardised risk registers, risk policies, and frameworks applied across all projects. When everyone uses the same language, categories, and scales, risks can be compared, aggregated, and escalated meaningfully.

  2. Expertise and Experience — Risk management requires both technical knowledge (of the tools and processes) and domain knowledge (of the specific project environment). The best risk managers combine formal training with deep operational experience.

  3. Accountability and Responsibility — Every risk must have an owner—someone with the authority, resources, and motivation to implement the response plan. Unowned risks are unmanaged risks.

  4. Words into Practice — The organisation doesn't just have a risk policy on paper; it demonstrates that policy in its day-to-day decisions and behaviours.

  5. Effective Information Storage and Accessibility — Risk data must be captured, stored, and retrievable so that current decisions are informed by historical experience. Software systems enable this, but they require discipline to maintain.

  6. Culture of Unconscious Competence — At the highest level of maturity, risk awareness is embedded in how people think and work at every level of the organisation. Risk management isn't a separate activity—it's how work gets done.

The Value of a Formal Documented Risk Process

Why formalise something that could be managed informally? Because a documented process delivers:

Proactive vs Reactive Risk Management

This is perhaps the single most important distinction in practical risk management.

Proactive Risk Management

Definition: The process of continuously assessing what can go wrong, determining which risks are important, evaluating their impact, and implementing strategies to deal with them—before they materialise.

Proactive risk management treats risk as a continuous, forward-looking process embedded in project planning and execution. It anticipates problems, prepares responses, and creates options for the project team.

Reactive Risk Management

Definition: Also known as crisis management or "putting out fires." This approach only engages with risk after something has already gone wrong.

Reactive risk management almost always negatively affects the organisation's schedule, cost, and quality. Worse, it crowds out process improvement opportunities—when you're fighting fires, you don't have time to install smoke detectors.

Dimension Proactive Approach Reactive Approach
Timing Before events occur After events occur
Focus Prevention and preparation Damage control and recovery
Cost Lower (early intervention is cheaper) Higher (fixing is more expensive than preventing)
Quality impact Preserves or enhances quality Typically degrades quality
Team morale Builds confidence and trust Creates stress and blame culture
Learning Generates reusable knowledge Generates firefighting skills but little transferable learning
Stakeholder perception Professional and competent Chaotic and unreliable

A recognised risk-attitude framework's Six Simple Questions

Practitioner guidance offers a powerful framework for structuring your risk process by asking six simple questions:

  1. What are we trying to achieve? (Define objectives)
  2. What could affect us? (Identify risks — threats and opportunities)
  3. Which are the most important? (Prioritise through analysis)
  4. What should we do about them? (Plan responses)
  5. Did it work? (Monitor and review effectiveness)
  6. What did we learn? (Capture lessons for future projects)

Barriers to Effective Risk Management

Understanding what prevents effective risk management is as important as knowing what enables it. These barriers are well-documented and depressingly common:

Attitudinal Barriers

Structural Barriers

Temporal Barriers

Cognitive Barriers

Enablers of Effective Risk Management

The mirror image of every barrier is an enabler. Effective risk management requires:

What Makes a Good Risk Manager?

Whether you're hiring a risk manager or taking on the responsibility yourself, effective risk managers typically demonstrate:

Managing Risk Throughout the Project Lifecycle

Managing risk is an integral part of the management process at every phase. While the executive may be responsible for defining and documenting policy, all managers must play a part in interpreting and implementing that policy at the operational level.

Risk management needs to be integrated at every level and in everyone's thinking:

Pitfalls: Common Failures in Practice

Pitfall 1: The "risk meeting" that doesn't discuss risk. Some managers put risk on the agenda to satisfy governance requirements, then skip past it or allow no time for meaningful discussion. This is worse than no meeting at all—it creates a false sense of security. Pitfall 2: Treating risk management as a planning-phase-only activity. Risk identification and analysis during planning is necessary but not sufficient. Risks evolve throughout the project lifecycle, and new risks emerge. Continuous monitoring is essential. Pitfall 3: Failing to communicate risks effectively. It doesn't matter what risks you've identified if you haven't communicated them to the people who have a stake in the project and who can help address them. The challenge is to present risks so that people understand and engage, not to create fear. Pitfall 4: Ignoring the "risk as opportunity" dimension. Teams that only catalogue threats will miss chances to capture value. Risk management should be an equal-parts exercise in threat reduction and opportunity exploitation. Pitfall 5: The conspiracy of optimism. There is a natural human tendency toward optimism in project planning. Without the counterweight of rigorous risk analysis, this optimism leads to systematically underestimated costs, compressed schedules, and unachievable scope commitments.

Key Takeaways

How CSFs Connect to Project Success: the multilateral development institution Evidence

Efficiency and Effectiveness Framework

While investigating critical success factors for a multilateral development institution projects, project-success researchers established that project success involves both efficiency (doing things right) and effectiveness (doing the right things). They identified two distinct analytical dimensions: Project Success Criteria — the established standards used to define and measure project success — encompassing five sub-dimensions:

  1. Significance — the degree to which the project meets the urgencies of a particular stakeholder
  2. Efficacy — the degree to which the project can be delivered using the least expensive resources
  3. Competence — the ability of the project to meet its stated objectives
  4. Effect — the positive or negative changes realised by the project
  5. Sustainability — whether the project outcomes are likely to continue after completion and handover Critical Success Factors — the conditions and inputs that contribute to achieving those criteria.

The critical finding from this research is that CSFs and success criteria are distinct but interdependent constructs. CSFs are not success criteria — they are the factors that enable the achievement of success criteria. This distinction has profound implications for risk management: when identifying risks, the risk manager must be clear about which success criteria a risk threatens and which CSFs might be leveraged to mitigate it.

The Business Case for Risk Management

There is growing awareness across all sectors — private, government, non-government, and not-for-profit — that formal risk management serves several critical functions. It exists to alert decision makers to material risks early; to confirm that a thorough evaluation process has been applied; to ensure a program of work is in place to address major risks; to help organisations survive and prosper in competitive environments; and to reduce the impact and consequences of risks before they materialise — the principle that a stitch in time saves nine.

Project-risk guidance and risk-attitude guidance make the point eloquently: despite wide convergence on the elements of a good risk management process, supported by capable tools, an accepted body of knowledge, and extensive practical experience, risk management often fails to meet expectations. Foreseeable threats materialise into crises, and achievable opportunities are missed. The mere existence of accepted principles and well-defined processes is not sufficient to guarantee success — some other essential ingredient is missing.

That missing ingredient, they argue, is risk attitude: the way individuals and organisations perceive and respond to uncertainty. Process without culture is procedure without power.

The Elephant Trap: What Falls Down the Crack

An early project-risk researcher uses the metaphor of an elephant trap — disguised as a mere crack — to describe the gap between common practice risk management and common practice project management.

Interval estimates, including all relevant interpretations of single values and bias issues, are addressed by neither common practice risk management (because they fall outside the "risk event" concept) nor common practice project management (because they are assumed to be part of the risk process). The result is that crucial issues fall into a gap between the two disciplines, unaddressed by either.

Other critical issues that fall down this elephant trap include:

Optimism bias — systematically underestimating costs and durations and overestimating benefits, as documented extensively by megaproject research in their study of megaprojects. Common practice risk management does not address bias in base estimates because it focuses on risk events layered on top of those estimates. Value management integration — the relationship between risk and value is fundamental but poorly addressed. Value engineering decisions change the risk profile; risk analysis should inform value trade-offs. In common practice, these are typically separate disciplines conducted by separate teams at separate meetings. Lifecycle perspective — common practice risk management typically focuses on the execution and delivery phase. But many of the most consequential uncertainties exist at the concept, design, and business case stages — precisely where the knowledge lens is most needed and the performance lens is least adequate.

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Connect risk to value is defined, owned, evidenced and linked to the relevant project decision.
Check 02Expose assumptions early is defined, owned, evidenced and linked to the relevant project decision.
Check 03Prioritise scarce attention is defined, owned, evidenced and linked to the relevant project decision.
Check 04Make responses executable is defined, owned, evidenced and linked to the relevant project decision.
Check 05Measure whether practice changes decisions is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

Project Risk Management FundamentalsGuide · RiskNEXT LESSON →The Evolution of Project Risk ManagementGuide · RiskProject Risk and Enterprise RiskGuide · RiskISO 31000 for Project Risk ManagementGuide · Risk