5.22 Plan Risk Responses

5.22 Plan Risk Responses
Inputs Tools & Techniques Outputs

Replace this with term.

Purpose & When to Use

Plan Risk Responses turns analyzed risks into clear, owned actions. Use it after you have identified risks and completed qualitative and, when needed, quantitative analysis. Revisit it throughout the project as risks change, new risks appear, or assumptions shift.

  • Convert risk ratings into specific response strategies and actions for threats, opportunities, and overall project risk.
  • Assign risk owners and action owners, with timing, budgets, and success criteria.
  • Integrate responses into scope, schedule, cost, procurement, quality, and communications plans.
  • Plan contingency and fallback actions, and document residual and secondary risks.
  • Update the risk register and risk report, and obtain approvals through change control when baselines are affected.

Mini Flow (How It’s Done)

  • Review inputs: risk management plan, risk register and report, analysis results, stakeholder risk attitudes, and constraints.
  • Prioritize what to address now based on exposure, urgency, and manageability.
  • Select strategies for threats: avoid, reduce, transfer, accept, or escalate when outside the project scope or authority.
  • Select strategies for opportunities: exploit, enhance, share, accept, or escalate when outside the project scope or authority.
  • Address overall project risk using strategies such as shaping the approach, buffering with reserves, or changing scope or delivery strategy.
  • Design specific actions for each selected strategy, define triggers and early warning indicators, and estimate effort and cost.
  • Assign a risk owner and an action owner, and set due dates and measures of success.
  • Assess residual risk and identify secondary risks created by the response, adding them to the register.
  • Integrate responses into plans and baselines, raising change requests when schedule, cost, or scope is impacted.
  • Communicate the plan, gain agreement from stakeholders, and capture updates in the risk register and risk report.
  • Plan how responses will be monitored during execution and define when fallback actions will be deployed.

Quality & Acceptance Checklist

  • Each high-priority risk has a chosen strategy and specific, feasible actions.
  • Risk owners and action owners are named, with dates and success criteria.
  • Triggers and monitoring indicators are defined and measurable.
  • Budget and schedule impacts are estimated, funded, and approved if baselines change.
  • Residual risk is evaluated and documented after the planned response.
  • Secondary risks from responses are identified and added to the register.
  • Contingency and fallback plans are documented for significant risks.
  • Responses align with stakeholder risk appetite, thresholds, and contractual obligations.
  • Actions are integrated into scope, schedule, cost, and procurement plans as tasks and reserves.
  • Opportunities are addressed with the same rigor as threats where value exists.
  • Communication and reporting needs for each key risk are defined.
  • Approvals are obtained and recorded through the change control process when needed.

Common Mistakes & Exam Traps

  • Writing vague responses instead of concrete actions with owners and dates.
  • Ignoring opportunities or treating them as low priority by default.
  • Skipping change control when responses affect scope, schedule, or cost.
  • Confusing planning responses with implementing them; execution happens later.
  • Assuming the project manager is the owner for all risks instead of assigning the best owner.
  • Using only acceptance for high-exposure risks without rationale or contingency.
  • Mixing up escalate versus transfer; escalate moves the risk to higher authority, transfer shifts liability to a third party.
  • Adding contingency reserves without analysis or approvals.
  • Forgetting to capture residual and secondary risks created by responses.
  • Not updating the risk register and risk report after selecting responses.

PMP Example Question

A high-impact supplier risk sits outside the project manager’s authority to change. What is the best response strategy?

  1. Transfer the risk by purchasing insurance.
  2. Accept the risk and add a management reserve.
  3. Escalate the risk to the sponsor or portfolio governance.
  4. Mitigate the risk by adding inspection steps.

Correct Answer: C — Escalate the risk to the sponsor or portfolio governance.

Explanation: When the project team lacks authority to address the cause, the appropriate strategy is to escalate so it can be handled at the right level. Transfer and mitigate require authority over contracts or processes the team does not control.

Agile Project Management & Scrum — With AI

Ship value sooner, cut busywork, and lead with confidence. Whether you’re new to Agile or scaling multiple teams, this course gives you a practical system to plan smarter, execute faster, and keep stakeholders aligned.

This isn’t theory—it’s a hands-on playbook for modern delivery. You’ll master Scrum roles, events, and artifacts; turn vision into a living roadmap; and use AI to refine backlogs, write clear user stories and acceptance criteria, forecast with velocity, and automate status updates and reports.

You’ll learn estimation, capacity and release planning, quality and risk management (including risk burndown), and Agile-friendly EVM—plus how to scale with Scrum of Scrums, LeSS, SAFe, and more. Downloadable templates and ready-to-use GPT prompts help you apply everything immediately.

Learn proven patterns from real projects and adopt workflows that reduce meetings, improve visibility, and boost throughput. Ready to level up your delivery and lead in the AI era? Enroll now and start building smarter sprints.



Launch your Agile career!

HK School of Management helps you master Agile and Scrum—faster. Learn practical playbooks, AI-powered prompts, and real-world workflows to plan smarter, deliver sooner, and keep stakeholders aligned. For the price of lunch, you’ll get templates, tools, and step-by-step guidance to level up your projects. Backed by our 30-day money-back guarantee—zero risk, clear path to results.

Learn More