72R-12Beginner12 min read

Developing a Project Risk Management Plan

Welcome to Risk & Contingency. A beginner's guide to developing a project risk management plan — the document that decides, up front, how risk will be identified, analyzed, treated, and monitored throughout the project. Built on AACE International RP 72R-12.

What the risk management plan is

This opens the Risk & Contingency track. Foundations introduced risk management as a discipline (the identify→analyze→respond→monitor cycle); this track goes deep — qualitative and quantitative analysis, contingency, Monte Carlo, integrated cost-schedule risk. And like every discipline in this curriculum, it starts with a plan that sets up how it will be done.

Why plan risk management

  • Sets the process & methods — Defines how risks will be identified and analyzed — qualitative, quantitative, or both — so the approach fits the project.
  • Assigns ownership — Names who runs risk management and who owns each risk — so it actually happens, rather than being everyone's job and no one's.
  • Sets risk appetite & thresholds — Defines how much risk is acceptable and what triggers escalation — the yardstick for every later decision.
  • Establishes cadence — Sets when risks are reviewed and reported, so the risk register stays alive instead of going stale after kickoff.

What goes into the plan

ElementWhat it defines
Objectives & scopeWhat risk management aims to achieve on this project
ProcessIdentify → analyze → treat → monitor, and how each is done
Methods & toolsQualitative matrix, quantitative (Monte Carlo), the register
Roles & responsibilitiesWho facilitates, who owns risks, who decides
Risk appetite & thresholdsAcceptable risk levels and escalation triggers
Cadence & reportingReview frequency and how risk is reported

Using the risk plan

Develop the risk plan at project setup, scaled to the project's size and uncertainty — a small project needs a light plan, a complex one a rigorous, quantitative approach. Define the process, methods, roles, thresholds, and cadence; get it agreed; then run the cycle on schedule through execution. As with project controls, the value isn't the document — it's living by it every cycle.

Nine things to remember

  1. The risk plan defines how risk management will be conducted — set up before execution.
  2. A plan turns reaction into management — prepared, not surprised.
  3. It sets the process, methods, roles, thresholds, and cadence.
  4. Risk management is a cycle, not an event — identify → analyze → treat → monitor.
  5. A register without a process dies — the plan commits you to repeating the cycle.
  6. Assign ownership — every risk needs an owner, or it's no one's job.
  7. Set risk appetite & thresholds — the yardstick for every later decision.
  8. Scale the plan to the project — light for small, rigorous/quantitative for complex.
  9. Risk connects to everything — contingency, EVM reserves, and business decisions.

Glossary

Cadence
The rhythm of risk review and reporting.
Qualitative analysis
Ranking risks by probability and impact.
Quantitative analysis
Modelling numerical risk effects (e.g., Monte Carlo).
Risk
An uncertain event affecting objectives if it occurs.
Risk appetite
How much risk an organization will accept.
Risk management plan
The document defining how risk will be managed.
Risk register
The living list of risks, analysis, owners, and responses.
Threshold
The level that triggers escalation or action.

Check your understanding

1A project risk management plan defines:
2Risk management is most effective when it is:
3A good risk plan assigns: