Treat every PMI-RMP scenario as a two-step decision: first classify whether the stem describes an individual project risk (one uncertain event) or overall project risk (combined uncertainty), then choose the response strategy, document it in the matching artifact, and fund it from the matching reserve. Work the two construction scenarios and the layered-labeling exercise until the classification is automatic.
Individual risk versus overall project risk: the layering problem
Treat risk on the PMI-RMP as two distinct layers: individual project risk — a single uncertain event or condition — and overall project risk — the combined effect of all uncertainty on objectives. Every scenario decision starts by labeling which layer the stem describes.
An individual risk is a discrete, identifiable uncertain event: a pile-driving refusal, a concealed utility strike, a supplier's price change. Overall project risk is the aggregate exposure created by all uncertainty together, including common-cause variation in durations and ambiguity about an evolving scope. The two layers differ in object, method, and output, so a correct answer for one layer can be exactly wrong for the other.
Apply the distinction with stem cues. Named events with an owner and a probability-impact score point to individual risk; cumulative overruns across a program, stakeholder uncertainty over changing scope, or aggregate schedule variability point to overall risk. When a stem describes an aggregate exposure, options that add one more row to the risk register are traps — look instead for whole-project quantitative analysis, management reserves, or escalation to someone with the authority to act on the aggregate.
Matching response strategies to threats and opportunities without misusing transfer
Match the response to the risk's sign. Threats use escalate, avoid, transfer, mitigate, or accept; opportunities use escalate, exploit, share, enhance, or accept. The strategies mirror each other, and each changes the project in a specific, testable way.
For threats: avoid eliminates the exposure by changing the plan so the event cannot occur; transfer shifts ownership or the financial consequence to another party, typically through insurance, warranties, or a fixed-price subcontract, at the cost of a risk premium; mitigate reduces probability, impact, or both while keeping the risk; accept leaves the risk unmanaged except for contingency plans or reserves; escalate routes the risk to a level above the project when it exceeds your authority or objectives.
For opportunities the mirrors apply: exploit makes a positive outcome certain, such as assigning your strongest team to capture a completion bonus; share partners with another party so both capture more value, as in a joint venture; enhance raises the probability or impact of the upside; accept takes no deliberate action. One precision point matters in scenarios: transfer moves the financial consequence, not the reputational one — an insurer can pay for a damage claim while the stakeholder criticism still lands on your organization.
| Strategy | Threat use | Opportunity mirror | What changes on the project |
|---|---|---|---|
| Eliminate the uncertainty | Avoid: change the plan so the threat cannot occur | Exploit: make the upside certain | Scope, schedule, or approach is altered |
| Move it to another party | Transfer: insurance, warranty, fixed-price subcontract (premium paid) | Share: joint venture or partnership | Ownership and value split with a third party |
| Reduce its size | Mitigate: lower probability and/or impact | Enhance: raise probability and/or impact | Risk stays, at reduced (or increased) exposure |
| Keep it | Accept: contingency plan or reserve | Accept: no deliberate action | Nothing changes; exposure is acknowledged |
| Send it up | Escalate: outside project authority or objectives | Escalate: upside needs higher-level commitment | Ownership moves to program or governance level |
Qualitative scoring versus quantitative analysis: when EMV changes the answer
Qualitative analysis scores and ranks risks by probability and impact to prioritize responses; quantitative analysis converts priority risks into numbers — expected monetary value, decision trees, simulation — to support a specific decision. Use qualitative first, then quantify where a real decision justifies the effort.
Qualitative tools — the probability-impact matrix, risk categorization, and data quality assessment — produce a prioritized list that decides which risks get owners and responses and which are simply accepted. Quantitative tools go further: EMV multiplies probability by monetary impact, decision trees compare options across outcome branches, and simulation models combined uncertainty on cost or schedule. The practical skill is knowing which question each tool can answer.
Worked scenario 1 — choosing an excavation package. Bid A is $500,000 with a 20% chance of a $300,000 dewatering overrun; Bid B is $580,000 with a 5% chance of a $200,000 overrun. EMV(A) = $500,000 + (0.20 × $300,000) = $560,000; EMV(B) = $580,000 + (0.05 × $200,000) = $590,000. The plausible mistake is selecting on headline price alone or reflexively paying for mitigation: a $40,000 pre-contract geotechnical survey cutting A's overrun probability to 10% gives EMV(A) = $500,000 + (0.10 × $300,000) = $530,000 before the survey cost, or $570,000 including it. The mitigation saves only $30,000 in expected overrun against a $40,000 price, so the better decision is Bid A unmitigated at $560,000. This matters because the comparison is about expected exposure net of response cost, not the sticker number.
Risk register versus risk report: putting each artifact in its place
The risk register holds individual risks with their attributes: description, category, scores, owner, agreed responses, and resulting residual or secondary risks. The risk report summarizes overall project risk, exposure trends, and sources. Individual detail goes in the register; aggregate findings go in the report.
A complete register entry lets a reader reconstruct the risk: a cause-risk-effect statement, its probability and impact scores before and after response, the response strategy chosen, the risk owner accountable for monitoring, and any residual risk that remains. Scenario answers that say 'update the risk register' are right when the stem adds a new individual risk, changes a score, assigns a new owner, or executes a response.
The risk report answers questions the register cannot: how much total exposure does the project carry, is it trending better or worse, and where does the uncertainty come from? In scenario options, phrases about trends, sources of overall risk, or summary exposure for stakeholders signal the report. Keeping the two artifacts distinct also keeps the answer options distinct — a response executed on one individual risk updates the register; a governance briefing on combined cost exposure draws on the report.
Residual and secondary risks plus contingency versus management reserves
After a response executes, residual risk remains at reduced probability or impact, and the response itself can create secondary risks. Contingency reserves fund identified residual risks and sit with the project manager; management reserves cover unknown-unknowns and are released above the project manager's authority.
Take a mitigation example: a pre-contract geotechnical survey mitigates a dewatering threat, but a residual risk remains — the survey's borehole spacing can still miss a localized aquifer at reduced probability. The survey itself creates a secondary risk: borehole work near an existing utility trench could damage it. In the register, both entries reference the original risk and its response, which is exactly the linkage a scenario answer is testing when it asks what changed after mitigation.
The reserve distinction turns on who releases the money. Contingency reserve is allocated for identified risks — the residual risks your register already lists — and the project manager can authorize its use within the agreed basis. Management reserve is set aside for unforeseen work inside scope but outside the identified risk set, and using it typically triggers a change request upward. In a scenario, a condition already identified and tracked points to contingency reserve; a condition nobody identified in advance points to management reserve. Reading the stem for that identification status resolves the choice.
Construction scenario 2: aggregate exposure that individual mitigations cannot fix
Construction stems add layers — multiple contracts, weather windows, shared site logistics — so read for the decision-maker's authority first. Worked scenario 2 shows why an aggregate exposure calls for escalation and quantitative analysis, not a thirteenth register entry.
Worked scenario 2 — the weather-window aggregate. A contractor is building three towers on one site; the register holds eleven individual weather-window risks, each with an owner and mitigation, yet the combined schedule exposure keeps growing because one facade fabricator feeds all three towers and every slip compounds. The plausible mistake is writing a twelfth individual risk with another mitigation, which treats a systemic exposure as a local one. The better decision: escalate to the governance level that owns the fabricator relationship, request program-level quantitative analysis of the combined schedule, and record the aggregate finding in the risk report. This matters because no single project-level response can change a dependency shared across the whole program.
Train the read by matching cue words to layers. Cues such as 'across all three buildings,' 'collective impact on the completion date,' or 'management is tracking a worsening trend' describe overall project risk and point toward the report, escalation, or management reserve. Cues that name one event, one owner, and one scored probability describe individual risk and point toward the register and a specific strategy. Practicing this two-column sort on mixed stems builds the classification reflex the rest of the reasoning depends on.
A preparation sequence and a layered-labeling exercise with a self-check rubric
Sequence your practice in stages: paired concept differentiation first, response selection second, artifact placement third, EMV math fourth, mixed scenarios last. Use the layered-labeling exercise below as a recurring drill, and measure progress by rubric milestones, not hours logged.
Exercise — the layered sort. Take ten risks from a practice scenario set. For each, write four things in thirty seconds: the layer (individual or overall), the response strategy you would choose, the artifact it belongs in (register or report), and the reserve that would fund any cost (contingency or management). Then revisit each and justify the response against the stem's constraint — schedule, budget, or authority. Repeat the full drill after three days with a fresh set of ten.
An adaptable sequence: stage one, learn the paired concepts in this guide as comparison pairs (individual/overall, threat/opportunity, register/report, contingency/management) and rebuild the table from memory; stage two, drill response selection on construction-style stems with a stated constraint; stage three, sort artifact and reserve questions only; stage four, compute EMV until probability-times-impact is automatic; stage five, run mixed timed scenarios and finish each one by writing a one-line label before reading the options. Readiness checks: you can define every strategy in one sentence, sort ten risks into the correct layer without notes, compute a two-branch EMV in under two minutes, and route an aggregate exposure to escalation with the reasons stated.
- Rubric milestone 1: layer label correct on at least 8 of 10 risks (a learning milestone, not a passing prediction).
- Rubric milestone 2: response matches the risk's sign and the stem's stated constraint; transfer is never chosen when the stem stresses reputational impact.
- Rubric milestone 3: aggregate exposures routed to the risk report, escalation, or management reserve; single events routed to the register with an owner.
- Rubric milestone 4: EMV includes both probability and impact in every branch, response costs are subtracted before comparing, and any secondary risk created by the chosen response is named.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
