KEVOS
ArticlesServicesCase studiesAboutContact
ArticlesServicesCase studiesAboutContact
← ArticlesRisk Management BasicsProject Delivery · RiskLesson 12/31← PrevNext →
GuidePublished 12 Aug 2026Updated 13 Aug 20267 min readBy Kevin Jogin
On this page

Ask about this page

KEVOS AIRisk Management Basics

KEVOS knowledge first · trusted web sources when needed

POSTER 11 · UNCERTAINTY & RISK

Risk Management Basics

Risk is the effect of uncertainty on objectives. Manage it as a continuous loop — identify, analyse, plan a response, and monitor — never a one-off event.

Project Management

The Risk Process (6 steps)

1
Plan Risk ManagementDecide how risk will be run: scales, roles, appetite, thresholds.
2
Identify RisksFind threats & opportunities. Write as cause → risk → effect.
3
Qualitative AnalysisRank by probability × impact. Prioritise the vital few.
4
Quantitative AnalysisModel overall effect on cost/schedule (e.g. Monte Carlo).
5
Plan ResponsesChoose a strategy + owner for each prioritised risk.
6
Monitor & ControlTrack, re-assess, watch triggers, manage the reserve.

Types of Risk

  • Threat — uncertainty with a negative effect.
  • Opportunity — uncertainty with a positive effect.
  • Known risk — identified; managed with a contingency reserve.
  • Unknown risk — unforeseeable; covered by a management reserve.
  • Individual risk — affects one or more objectives if it occurs.
  • Overall risk — the combined effect of uncertainty on the whole project.
  • Residual — what remains after responses; secondary — created by a response.

Probability × Impact

P \ IVLLMHVH
VHMHEEE
HLMHHE
MLMMHH
LLLMMH
VLLLLMM
Low Medium High Extreme

Response Strategies

AvoidEliminate the threat — change scope or plan.
ExploitMake sure the opportunity happens.
TransferShift the threat to a third party (insure, contract).
ShareAllocate the opportunity to a capable partner.
MitigateReduce probability and/or impact of the threat.
EnhanceIncrease probability and/or impact of the opportunity.
AcceptTake no action; set a contingency reserve (active) or none (passive).
EscalateOutside authority? Raise to programme / portfolio level.

Key Terms

  • Risk appetite — uncertainty an org is willing to take on.
  • Risk threshold — the level of impact that triggers action.
  • Risk owner — person responsible for managing a risk.
  • Trigger — a warning sign that a risk is about to occur.
  • Contingency reserve — time/cost set aside for known risks.
  • EMV — Expected Monetary Value = probability × impact.

Memory Hooks

  • “Cause → Risk → Effect” — the shape of every good risk statement.
  • Threats: A-T-M-A — Avoid, Transfer, Mitigate, Accept.
  • Opportunities: E-S-E-A — Exploit, Share, Enhance, Accept.
  • Contingency = known, Management = unknown reserve.

Common Questions

  • Risk vs issue? A risk is future & uncertain; an issue has already happened.
  • Who owns the reserve? PM controls contingency; sponsor controls management reserve.
  • Qualitative or quantitative first? Qualitative — it filters what is worth modelling.

Review Checklist

  • I can list the 6 process steps in order.
  • I can give the 4 threat & 4 opportunity responses.
  • I know contingency vs management reserve.
  • I can write a cause–risk–effect statement.
  • I can place a risk on the P×I matrix.

Executive Summary

Effective risk management is proactive, not reactive. Build a prioritised risk register early, assign a named owner to every significant risk, fund a contingency reserve sized to your analysis, and review the register at every status point. The goal is not zero risk — it is taking the right risks knowingly, within a defined appetite, so opportunities are captured and threats never become surprises.

Industry applications: construction · IT delivery · finance · healthcare · engineering programmes

Handbook application: from concept to controlled practice

Purpose. This expanded section turns the original page into a practical handbook. It preserves the supplied material and adds a repeatable way to apply, check and review Risk Management Basics. It does not replace a contract, legislation, a controlled standard, competent engineering judgement or specialist advice.

The operating aim is to convert the subject into a governed decision, owned work, usable evidence and a reviewable outcome. Read the original explanation first, then use the workflow and checks below to convert knowledge into evidence.

Use Risk Management Basics as a decision instrument rather than an administrative form. The subject terms—risk, types, process, probability, impact—need an explicit connection to the project objective, business value and stakeholder commitments. Before completing the artefact, write one sentence stating who will use it, what decision it supports and when that decision is required.

Apply a disciplined information model. Separate facts supported by evidence, forecasts derived from a method, assumptions awaiting validation, constraints that limit choice, risks that may occur, issues that already exist and actions assigned to people. Each material entry should have an owner, date, status and next review point. Where probability or impact scores are used, define the scale so different reviewers interpret it consistently.

A baseline is useful only when changes are visible. Give the artefact an identifier, version, approval state and effective date. Define which changes require reapproval, how superseded versions are retained and where supporting evidence is stored. During reviews, focus on exceptions, decisions and trends rather than reading every field aloud. Record the decision and rationale, not merely that a meeting occurred.

Close the loop beyond delivery. Confirm acceptance criteria, unresolved items, transferred responsibilities and operational ownership. Where benefits are expected, identify the outcome measure, baseline, target, observation period and owner who remains accountable after the project team disbands. Lessons should describe the condition, consequence and reusable action; a generic statement such as “communicate better” cannot improve the next project.

Step-by-step operating method

  1. Clarify the decision. Name the outcome, sponsor, affected stakeholders and decision that this work must enable.
  2. Set boundaries. Record scope, assumptions, constraints, dependencies, tolerances and escalation conditions.
  3. Plan the evidence. Define deliverables, measures, owners, due dates and acceptance criteria before execution.
  4. Control delivery. Compare actual performance with the baseline, assess changes and manage risks and issues explicitly.
  5. Close the loop. Confirm acceptance, transfer ownership, capture lessons and track benefits beyond handover.

Completion and governance protocol

Start with a short drafting workshop involving the accountable owner and the people who hold the evidence. Complete high-consequence fields first: objective, scope, owner, baseline, acceptance, dependencies and escalation. Mark unknowns as assumptions or actions rather than hiding them behind vague prose. Circulate a review draft, resolve conflicting interpretations, baseline the approved version and place the next review date in an owned schedule.

Information typeMinimum useful contentReview test
OutcomeObservable change and intended recipientNot merely a deliverable or activity
MeasureDefinition, baseline, target, frequency and sourceTwo reviewers would calculate it the same way
OwnershipOne accountable role plus contributors and approverAuthority matches responsibility
UncertaintyAssumption, risk or issue with response and triggerStatus reflects current reality
ControlVersion, approval, review date and change ruleCurrent baseline is identifiable

Common failure modes and recovery actions

1. Watch for

Producing a document with no named decision or accountable owner.

Recovery: Return to the governing definition or requirement and restate the decision in one sentence.

2. Watch for

Mixing risks, current issues, assumptions and actions in one unstructured list.

Recovery: Separate evidence from assumption, assign an owner and set a date for validation.

3. Watch for

Measuring activity or output while leaving the intended outcome undefined.

Recovery: Run a small counterexample, boundary test, pilot or independent check before proceeding.

4. Watch for

Accepting changes without evaluating effects on value, scope, schedule, cost and risk.

Recovery: Record the consequence, decision and rationale, then update the controlled baseline.

5. Watch for

Closing the project at delivery even though benefit ownership has not transferred.

Recovery: Escalate when the issue affects safety, compliance, acceptance, material value or an agreed tolerance.

Review checklist

  • Which decision or commitment does this artefact support?
  • Who owns each action, risk, acceptance and post-project benefit?
  • What is the baseline and what variance triggers escalation?
  • Where is the evidence that the result was accepted and transferred?
  • Are mandatory requirements distinguished from recommendations and illustrative values?
  • Are sources, assumptions, units, dates and versions recorded closely enough to reproduce the decision?
  • Have safety, legal, ethical, stakeholder and operational consequences been considered at the appropriate level?
  • Is there a named owner and a trigger for review, escalation, change or retirement?

Questions for deeper application

What is the most important distinction a practitioner must preserve when applying Risk Management Basics?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

Which assumption about risk would change the result most if it proved false?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

What evidence would allow an independent reviewer to reproduce or challenge the conclusion?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

Which boundary, exception or failure case has not yet been tested?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

What must be handed over, monitored or reviewed after the immediate work is complete?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

Authoritative references and use notes

The sources below were selected as institutional or primary guidance for the broader practice. They support the handbook method; they do not imply that every statement or clause in a source applies to every project. Confirm the current edition, jurisdiction, contract and application before treating any requirement as mandatory.

  • Risk Management in Portfolios, Programs, and Projects: A Practice Guide — Project Management Institute. Used for risk practices across portfolios, programs and projects. Accessed 2026-08-13.
  • ISO 31000 family — Risk management — International Organization for Standardization. Used for principles and guidance for enterprise risk management. Accessed 2026-08-13.

Continue learning

Policy Gradient OptimizationGuide · RiskNEXT LESSON →Risk — Fundamentals & PrinciplesGuide · RiskPolicy Gradient EstimationGuide · RiskActor–Critic MethodsGuide · Risk
KEVOS · Engineering, manufacturing and project improvement
ArticlesServicesCase studiesAboutContact
© 2026 KEVOS®