Developing a Project Risk Management Plan
Welcome to Risk & Contingency. A beginner's guide to developing a project risk management plan — the document that decides, up front, how risk will be identified, analyzed, treated, and monitored throughout the project. Built on AACE International RP 72R-12.
What the risk management plan is
This opens the Risk & Contingency track. Foundations introduced risk management as a discipline (the identify→analyze→respond→monitor cycle); this track goes deep — qualitative and quantitative analysis, contingency, Monte Carlo, integrated cost-schedule risk. And like every discipline in this curriculum, it starts with a plan that sets up how it will be done.
Why plan risk management
- Sets the process & methods — Defines how risks will be identified and analyzed — qualitative, quantitative, or both — so the approach fits the project.
- Assigns ownership — Names who runs risk management and who owns each risk — so it actually happens, rather than being everyone's job and no one's.
- Sets risk appetite & thresholds — Defines how much risk is acceptable and what triggers escalation — the yardstick for every later decision.
- Establishes cadence — Sets when risks are reviewed and reported, so the risk register stays alive instead of going stale after kickoff.
What goes into the plan
| Element | What it defines |
|---|---|
| Objectives & scope | What risk management aims to achieve on this project |
| Process | Identify → analyze → treat → monitor, and how each is done |
| Methods & tools | Qualitative matrix, quantitative (Monte Carlo), the register |
| Roles & responsibilities | Who facilitates, who owns risks, who decides |
| Risk appetite & thresholds | Acceptable risk levels and escalation triggers |
| Cadence & reporting | Review frequency and how risk is reported |
Using the risk plan
Develop the risk plan at project setup, scaled to the project's size and uncertainty — a small project needs a light plan, a complex one a rigorous, quantitative approach. Define the process, methods, roles, thresholds, and cadence; get it agreed; then run the cycle on schedule through execution. As with project controls, the value isn't the document — it's living by it every cycle.
Nine things to remember
- The risk plan defines how risk management will be conducted — set up before execution.
- A plan turns reaction into management — prepared, not surprised.
- It sets the process, methods, roles, thresholds, and cadence.
- Risk management is a cycle, not an event — identify → analyze → treat → monitor.
- A register without a process dies — the plan commits you to repeating the cycle.
- Assign ownership — every risk needs an owner, or it's no one's job.
- Set risk appetite & thresholds — the yardstick for every later decision.
- Scale the plan to the project — light for small, rigorous/quantitative for complex.
- Risk connects to everything — contingency, EVM reserves, and business decisions.
Glossary
- Cadence
- The rhythm of risk review and reporting.
- Qualitative analysis
- Ranking risks by probability and impact.
- Quantitative analysis
- Modelling numerical risk effects (e.g., Monte Carlo).
- Risk
- An uncertain event affecting objectives if it occurs.
- Risk appetite
- How much risk an organization will accept.
- Risk management plan
- The document defining how risk will be managed.
- Risk register
- The living list of risks, analysis, owners, and responses.
- Threshold
- The level that triggers escalation or action.