Process

Risk Management: Plan for the Probable Before It Becomes Actual

A risk is a probability to manage; an issue is a reality to fix: do not confuse them.

Updated 2026·4 min read
  • Green — Low severity
  • Yellow — Medium severity
  • Red — High severity

A risk is a possible future event, whereas an issue is an event that has already occurred, and confusing the two is a common error. Risks are analyzed qualitatively by ranking them by probability and impact, then quantitatively when needed by estimating their numeric effect. Threats have five strategies: avoid, mitigate, transfer, accept, and escalate; opportunities likewise: exploit, enhance, share, accept, and escalate. All of this is documented in the risk register, which is continuously updated.

Common mistake

Treating risks as threats only. Opportunities are positive risks to be managed too.

Plan for the probable before it becomes actual.

Ready to start serious PMP prep?

Subscribe now
Read the details

Risk management begins with identifying risks, then analyzing them qualitatively by ranking them by probability and impact, then quantitatively when needed to estimate their numeric effect on objectives. A response is chosen for each significant risk: for threats, avoid, mitigate, transfer, accept, or escalate; for opportunities, exploit, enhance, share, accept, or escalate, with escalation used for what falls outside the project's scope or the manager's authority. The risk register remains a living document reviewed regularly, as new risks emerge and existing estimates change throughout the project life cycle.

Frequently asked questions

What is the difference between a risk and an issue?

A risk is a potential event that may occur; an issue is an event that has already happened.

What is the difference between qualitative and quantitative risk analysis?

Qualitative ranks risks by probability and impact; quantitative estimates their impact numerically when needed.

What are the threat response strategies?

Five strategies: avoid, mitigate, transfer, accept, and escalate.

What are the opportunity response strategies?

Five strategies: exploit, enhance, share, accept, and escalate.

Is a risk always negative?

No; opportunities are positive risks that are also managed, not ignored.

Where are risks documented?

In the risk register, which is updated continually throughout the project life cycle.