PMI-RMP : Risk Identification (Domain 2)
PMI – PMI-RMP : Certified Risk Management Professional - Domain 2 - Risk Identification
Risk identification is the foundational activity of the risk management lifecycle, serving as the critical juncture where uncertainty is converted into documented, actionable data. Within the Project Management Institute’s Risk Management Professional (PMI-RMP) framework, Domain 2 represents approximately 23% to 30% of the total examination content. This weighting underscores the reality that a project team cannot analyze, respond to, or monitor a risk that has not first been identified.
The primary objective of this domain is to systematically surface both threats—uncertain events that could negatively impact project objectives—and opportunities, which are uncertain events that could offer beneficial outcomes. This guide provides a deep exploration of the tasks, techniques, and documentation required to master this domain, focusing on structured identification exercises, analytical frameworks, and the development of the project risk register.
Tactical Execution of Risk Identification Exercises
The first task in Domain 2 involves conducting risk identification exercises. This is not a one-time event but an iterative process that must occur throughout the project lifecycle. In modern project environments, identification leverages a mix of human expertise and data-driven analysis.
Facilitation through Meetings and Interviews
Structured meetings, focus groups, and interviews are the primary vehicles for risk identification. Facilitators must engage Subject Matter Experts (SMEs) and key stakeholders to extract diverse perspectives on uncertainty. These sessions often involve:
- Structured Interviews: Targeted discussions with SMEs to identify technical, environmental, or organizational risks based on their specialized experience.
- Focus Groups: Collaborative sessions that bring together stakeholders to discuss specific areas of concern, such as supply chain vulnerabilities or regulatory changes.
- Document and Data Analysis: Practitioners must analyze project documents, audio transcripts, telemetry data, and historical records to understand the business context and identify patterns that suggest emerging risks.
Distinguishing Threats and Opportunities
A sophisticated risk professional treats identification as a dual-pathway process. Every uncertainty identified must be classified as either a threat or an opportunity.
- Threats: These require strategies such as avoidance, mitigation, or transfer to protect project value.
- Opportunities: These require strategies like exploitation, enhancement, or sharing to maximize organizational benefits. Identifying opportunities is often more challenging than identifying threats, as project teams are naturally inclined toward protective thinking. However, the PMI-RMP curriculum emphasizes that capturing opportunities is just as vital for value delivery as mitigating threats.
Advanced Qualitative Techniques: The Delphi Method
One of the most rigorous techniques used in risk identification is the Delphi technique. This method is specifically designed to reach a consensus among a group of experts while minimizing the negative effects of group dynamics, such as “groupthink” or the dominance of a single loud voice.
The Iterative Consensus Process
The Delphi technique involves the following steps:
- Selection of Experts: A group of SMEs is chosen to provide input on project risks.
- Anonymous Questionnaires: Experts are asked to identify risks independently and anonymously via questionnaires.
- Iteration and Feedback: A facilitator compiles the responses and provides a summary to the group. The experts are then asked to review the group’s findings and refine their own perspectives in a second round of questioning.
- Consensus Building: This process continues until the experts reach a stable consensus on the most significant risks facing the project.
By maintaining anonymity throughout the process, the Delphi technique ensures that every expert’s opinion is weighted equally, leading to a more objective and comprehensive list of identified risks.
Strategic Brainstorming and Interactive Discovery
Brainstorming remains the most common technique for risk identification due to its ability to generate a high volume of ideas in a short period. However, for a brainstorming session to be effective in a professional risk environment, it must be carefully facilitated.
Facilitating Effective Brainstorming
A successful brainstorming session should involve a multi-disciplinary team to ensure that all aspects of the project (technical, legal, financial, etc.) are covered. The facilitator’s role is to:
- Encourage Uninhibited Thinking: Every idea should be captured without immediate judgment or analysis.
- Use Prompt Lists: To prevent the team from stalling, facilitators use prompt lists or the Risk Breakdown Structure (RBS) to trigger ideas in specific categories.
- Categorize Output: Once the session is complete, the identified risks are grouped into categories for further examination.
In Agile and hybrid environments, brainstorming is often integrated into recurring ceremonies, such as sprint planning or daily stand-ups, ensuring that new uncertainties are surfaced as the project evolves.
Structural Frameworks: Prompt Lists and Checklists
To ensure that the risk identification process is exhaustive and consistent, practitioners utilize structured aids known as prompt lists and checklists. These tools help the team avoid the oversight of common or recurring risks.
The Role of Prompt Lists
A prompt list is a predetermined set of risk categories that provides a framework for the team to identify risks. Common frameworks used as prompt lists include:
- PESTLE: Political, Economic, Social, Technological, Legal, and Environmental.
- TECOP: Technical, Environmental, Commercial, Operational, and Political.
- VUCA: Volatility, Uncertainty, Complexity, and Ambiguity.
Using these lists ensures that the team looks beyond the immediate technical details of the project to consider broader environmental and organizational factors.
Leveraging Historical Checklists
Checklists are developed based on historical data and lessons learned from previous projects. While they are highly efficient for identifying “known-knowns” or recurring issues, practitioners are cautioned not to rely solely on checklists. Over-reliance can lead to a narrow focus, causing the team to miss unique risks specific to the current project’s environment or technical complexity.
Environmental Analysis through SWOT
The SWOT analysis (Strengths, Weaknesses, Opportunities, and Threats) is a strategic tool that identifies risks by looking at both the internal and external project environment.
Internal vs. External Perspectives
- Strengths and Weaknesses (Internal): These focus on the organization’s capabilities, such as staff expertise, available technology, and financial health. A strength can be leveraged into an opportunity, while a weakness often identifies a cluster of potential threats.
- Opportunities and Threats (External): These focus on the project’s external environment, including market conditions, regulatory changes, and competitor actions.
From Strategy to Risk Identification
In Domain 2, SWOT is used to assess project risk complexity. For example, a project’s “Strength” in having an advanced AI tool might create the “Opportunity” to finish the schedule early, while its “Weakness” in a remote workforce might pose the “Threat” of communication delays. By analyzing the interplay between these quadrants, teams can identify risks that might not surface during a simple brainstorming session.
Root Cause Exploration: The Ishikawa Diagram
The Ishikawa diagram, also known as the Fishbone or Cause-and-Effect diagram, is used in Domain 2 to trace project effects back to their underlying causes. This technique is particularly valuable for identifying risk triggers and root causes.
Constructing the Diagram
The “effect” or potential problem is placed at the head of the “fish.” The “bones” then represent various categories of causes, such as:
- Methods
- Machines
- Materials
- Measurement
- Mother Nature (Environment)
- People
Identifying Hidden Risks
By deconstructing a potential failure (threat) or a potential success (opportunity) into its root causes, the team can identify specific risks associated with each cause. For instance, if the potential effect is “Delayed Product Launch,” the Ishikawa diagram might reveal that a “Material” cause is “Dependency on a single-source supplier,” which is a documented risk. This granular level of analysis is essential for developing effective triggers and response plans.
Validating the Foundation: Assumption and Constraint Analysis
Every project plan is built upon a set of assumptions and is limited by specific constraints. If an assumption is proven false or a constraint becomes overly restrictive, project objectives are at risk.
Analyzing Assumptions
Assumptions are factors that are considered to be true, real, or certain for planning purposes without proof. Task 2 of Domain 2 requires the risk professional to:
- Categorize Assumptions: Group them by project area (e.g., technical assumptions, resource assumptions).
- Assess Stability and Impact: Determine how likely the assumption is to be false and what the impact would be if it were.
- Challenge Stakeholders: Encourage stakeholders to provide evidence for their assumptions, as unvalidated assumptions are one of the most common sources of project failure.
Navigating Constraints
Constraints are limiting factors that affect the execution of a project, such as fixed budgets, hard deadlines, or regulatory requirements. Analysis involves recognizing the relationship between constraints and project objectives. For example, a hard deadline constraint might create a cascade of risks related to resource over-allocation or reduced quality testing.
Establishing Early Warning Systems: Risk Triggers and Thresholds
Once risks are identified, the practitioner must document the context in which they might occur. This involves setting risk triggers and understanding organizational thresholds.
Defining Risk Triggers
A risk trigger, also known as a warning sign or symptom, is an indicator that a risk is about to occur or has already occurred.
- Documentation: Triggers must be clearly documented in the risk register.
- Function: They serve as “early warning systems” that prompt the risk owner to take action or implement a contingency plan. For example, a trigger for the risk of “Labor Strike” might be “Breakdown in union negotiations.”
Risk Thresholds and Compliance
Thresholds represent the level of risk exposure that is acceptable to stakeholders.
- Contextual Assessment: Thresholds are based on the project environment and organizational risk appetite.
- Compliance: Practitioners must document risk compliance thresholds against updated risk data. Stakeholders are empowered to challenge existing thresholds if the project environment shifts significantly, such as during a macroeconomic downturn or a major technical pivot.
Architecture of the Project Risk Register
The ultimate output of Domain 2 is the development of the project risk register. This document serves as the central repository for all risk-related information and must be structured to allow for ongoing analysis and monitoring.
Components of a Professional Risk Register
A comprehensive risk register includes the following metadata for each identified risk:
- Risk ID and Description: A unique identifier and a clear statement of the risk event, its cause, and its potential impact.
- Risk Category: Mapping the risk to the Risk Breakdown Structure (RBS).
- Type: Classification as either a threat or an opportunity.
- Probability and Impact: Initial qualitative estimates of likelihood and severity.
- Urgency and Proximity: How soon the risk might occur and how quickly a response is required.
- Risk Owner: The individual responsible for monitoring the risk and implementing responses.
- Triggers: The specific indicators that the risk is materializing.
Maintaining the Register
The risk register is a living document. As identification exercises are repeated, new risks are added, and expired risks are closed. In modern project management, this register is often part of a digital Project Management Information System (PMIS) that allows for real-time updates and stakeholder transparency.
Risk Identification in Agile, Predictive, and Hybrid Environments
The approach to identifying risks varies significantly depending on the project delivery framework. Practitioners must be adept at tailoring identification activities to the chosen lifecycle.
Predictive (Waterfall) Environments
In traditional environments, risk identification is heavily front-loaded. Detailed workshops are held during the planning phase to create a robust risk register that is then managed against a baseline. Formal tools like SWOT and Delphi are frequently used during these early stages.
Agile and Iterative Environments
In Agile, risk is managed as a dynamic variable. Identification is integrated into the following ceremonies:
- Backlog Refinement: The team identifies technical or business risks associated with specific user stories.
- Sprint Planning: Potential impediments for the upcoming iteration are surfaced.
- Daily Stand-ups: Emerging threats or “blockers” are discussed collaboratively.
- Retrospectives: The team reflects on past risks and identifies improvements for the next cycle.
Agile teams often use visual tools, such as risk burn-down charts or visual boards, rather than static registers, to maintain high visibility and enable rapid adaptation.
Hybrid Environments
Hybrid projects combine these approaches, often using formal risk registers for high-level strategic risks (Waterfall) while utilizing iterative ceremonies for tactical, team-level identification (Agile).
Study Exercises: Short-Answer Questions
1. What is the primary difference between a threat and an opportunity in the context of risk identification? Answer: A threat is an uncertain event that would have a negative impact on project objectives if it occurs, while an opportunity is an uncertain event that would have a positive or beneficial impact. The logic is that risk management must address the entire spectrum of uncertainty, both to protect value and to create it.
2. Why is anonymity a critical component of the Delphi technique? Answer: Anonymity prevents groupthink and ensures that the influence of high-ranking or vocal individuals does not bias the results. This logic ensures that the consensus reached is based on the objective expertise of all participants rather than social or organizational pressure.
3. In a SWOT analysis, how do “Weaknesses” relate to the identification of project threats? Answer: Internal weaknesses often identify areas of vulnerability that external threats can exploit. The logic is that by acknowledging internal gaps (like lack of staff experience), the team can proactively identify specific threats (like schedule delays due to a learning curve).
4. What is a “risk trigger” and what is its role in the project risk register? Answer: A risk trigger is a specific indicator or warning sign that a risk is occurring or is about to occur. Its logic is to serve as a functional cue for the risk owner to execute a pre-planned response or contingency plan.
5. How does a prompt list such as PESTLE assist the risk identification process? Answer: PESTLE provides a structured framework of categories (Political, Economic, etc.) to ensure the team considers risks across the entire project environment. The logic is to prevent “tunnel vision” by prompting the team to look beyond technical project details.
6. What is the main risk associated with an unvalidated project assumption? Answer: If an assumption is proven false, it can invalidate the entire project plan, leading to schedule overruns, budget failures, or scope issues. The logic is that assumptions are inherent sources of uncertainty and must be tested for stability and impact.
7. How does an Ishikawa diagram help in identifying risk triggers? Answer: By tracing an effect back to its root causes, the diagram identifies the specific events or conditions (causes) that lead to a risk. The logic is that these root causes often become the “triggers” monitored in the risk register.
8. What is the purpose of “Constraint Analysis” in Domain 2? Answer: Constraint analysis identifies limiting factors, such as fixed budgets or hard deadlines, that restrict project execution. The logic is that these boundaries are significant sources of risk, as any pressure on a constraint can force compromises in other project objectives like quality or scope.
9. Why should a project risk register include a “Risk Owner” for every identified risk? Answer: Assigning an owner ensures human accountability for monitoring the risk and implementing its response. The logic is that without a clear owner, identified risks may be ignored, leading to a failure in the monitoring and response phases of the lifecycle.
10. How is risk identification handled differently in an Agile environment compared to a Predictive environment? Answer: In Agile, identification is iterative and integrated into daily and sprint-based ceremonies, whereas in Predictive, it is often a more formal, front-loaded process. The logic is that Agile addresses uncertainty through continuous adaptation, while Predictive emphasizes structured upfront planning to minimize changes.
Scenario Design: Open-Ended Challenges
Scenario 1: The Expert Dominance Challenge You are facilitating a risk identification workshop for a high-stakes infrastructure project. Two senior engineers are dominating the conversation, and younger team members are hesitating to share their concerns. Design a strategy using specific Domain 2 techniques to ensure all voices are heard and hidden risks are surfaced.
Scenario 2: The False Assumption Crisis A project team assumed that a specific third-party API would be available by the start of the second sprint. It has just been announced that the API release is delayed by three months. Explain how a robust Assumption and Constraint Analysis conducted during the identification phase could have prepared the team for this scenario, and what the risk register entries should have looked like.
Scenario 3: The Missed Opportunity During a project to develop a new software application, the team identifies a “Threat” that the current server capacity might be insufficient. However, they fail to see the “Opportunity” that upgrading the servers could allow for a high-margin “Premium” version of the app to be launched simultaneously. Create a SWOT-based exercise that would have helped the team identify this opportunity during the identification phase.
Scenario 4: The Vague Trigger A risk register entry for a construction project lists “Bad Weather” as a risk, but it has no specific trigger. When a week of heavy rain occurs, the team is confused about when to stop work and when to implement the contingency plan. Design a specific set of risk triggers and thresholds for this scenario that would provide clear guidance to the project manager.
Scenario 5: The Static Register Pitfall A project manager created a comprehensive risk register at the start of a year-long project but has not updated it in six months. A major technological shift has occurred in the industry, making the project’s original hardware choice obsolete. Describe the identification activities that should have been occurring to prevent this “static register” failure, specifically referencing the role of iterative identification and environmental scanning.
Glossary of Key Terms
- Assumption: A factor in the planning process considered to be true, real, or certain without proof or demonstration.
- Brainstorming: A general data-gathering and creativity technique used to identify risks, ideas, or solutions to issues by using a group of team members or subject matter experts.
- Checklist: A list of items, actions, or points to be considered, often developed based on historical information and knowledge from previous similar projects.
- Constraint: A limiting factor that affects the execution of a project, program, portfolio, or process.
- Delphi Technique: An information-gathering technique used as a way to reach a consensus of experts on a subject while maintaining their anonymity.
- Ishikawa Diagram: A visualization tool for categorizing the potential causes of a problem in order to identify its root causes; also known as a Fishbone or Cause-and-Effect diagram.
- Opportunity: A risk that would have a positive effect on one or more project objectives.
- Prompt List: A predetermined list of risk categories used as a tool to aid the project team in the risk identification process.
- Risk Appetite: The degree of uncertainty an organization or individual is willing to accept in anticipation of a reward.
- Risk Breakdown Structure (RBS): A hierarchical representation of potential sources of risk used to categorize and organize risks.
- Risk Identification: The process of determining which risks may affect the project and documenting their characteristics.
- Risk Owner: The person responsible for monitoring a specific risk and for selecting and implementing an appropriate risk response strategy.
- Risk Register: A repository in which outputs of risk management processes are recorded, including identified risks, analysis results, and response plans.
- Risk Threshold: The level of risk exposure above which a specific action is required, or below which the risk is acceptable.
- Risk Trigger: An event or situation that indicates that a risk is about to occur or has occurred; often used as a signal to implement a contingency plan.
- SWOT Analysis: An analysis of Strengths, Weaknesses, Opportunities, and Threats used to evaluate the internal and external environment of a project.
- Threat: A risk that would have a negative effect on one or more project objectives.
- Urgency: A measure of how quickly a risk response needs to be implemented in order to be effective.
Leaderboard
No scores saved yet. Be the first!
30 Questions — PMI – PMI-RMP : Certified Risk Management Professional - Domain 2 - Risk Identification
Expand any question to reveal the correct answer and explanation.
-
1 A project manager is reviewing a list of project assumptions and realizes that a critical assumption regarding the availability of an offshore test environment has not been validated. According to the current PMI-RMP blueprint for Task 2 of Risk Identification, what is the most appropriate next step for the team?
Consider the collaborative responsibility of stakeholders in validating project boundaries.
Encourage stakeholders to challenge the assumption to uncover underlying uncertainties.
Task 2 enablers specifically highlight that stakeholders should be empowered to challenge assumptions to expose hidden risks.
-
✗ Convert the unvalidated assumption into a project constraint to ensure it is managed as a known-known.
Constraints are fixed limitations, and converting an uncertainty into a certainty without validation ignores the underlying risk.
-
✗ Perform a quantitative analysis to determine the cost impact of the assumption being false.
Quantitative analysis occurs after risks have been identified and qualified; the immediate identification task is to validate the assumption.
-
✗ Immediately move the assumption to the risk register as a high-priority threat.
While it may become a risk, it first requires categorization and assessment to determine if it meets the criteria for the register.
-
-
2 During a risk identification workshop for a complex hybrid project, the team decides to use the Delphi technique. What is the primary reason for choosing this method over traditional brainstorming to surface potential threats?
Think about how anonymity impacts the quality of expert contributions.
It reduces the influence of dominant personalities and prevents groupthink through anonymity.
The Delphi technique uses anonymous experts to ensure that biased or powerful individuals do not unfairly sway the identification of risks.
-
✗ It allows for rapid, face-to-face consensus building among team members.
Traditional brainstorming is face-to-face, whereas Delphi is designed to avoid the pressures of direct interaction.
-
✗ It provides a hierarchical breakdown of risks based on their source within the organization.
This describes a Risk Breakdown Structure (RBS), which is a tool for categorization rather than a method for gathering expert opinion.
-
✗ It is the only method that integrates probability and impact scores into the identification phase.
Identification focuses on surfacing the risk; probability and impact scoring are primary components of qualitative and quantitative analysis.
-
-
3 You are developing the project risk register and need to include a field that measures how soon a risk might occur. Which meta-data attribute specifically refers to this time-based factor?
Distinguish between the timing of the event itself and the timing of the required response.
Proximity
Proximity is a specific risk attribute that describes the period of time before a risk might materialize.
-
✗ Urgency
Urgency refers to the period of time within which a response must be implemented, which may differ from when the risk occurs.
-
✗ Dormancy
Dormancy refers to the time that may elapse after a risk has occurred but before its impact is discovered.
-
✗ Propinquity
Propinquity measures the degree to which a risk is perceived to matter by one or more stakeholders.
-
-
4 A risk professional is assessing the 'cascade effect' of project stakeholder holiday schedules on project timelines. This activity is a core enabler of which Risk Identification task?
Focus on how fixed project limitations influence the emergence of uncertainty.
Examine assumption and constraint analyses
Blueprints for Task 2 specifically mention recognizing the relationship between constraints (like holiday schedules) and project objectives to predict cascade effects.
-
✗ Conduct risk identification exercises
While related, this general task focuses more on the methods of surfacing risks like interviews or brainstorming.
-
✗ Document risk triggers and thresholds
Triggers are early warning indicators, whereas holiday schedules are constraints that act as the source of potential risk.
-
✗ Develop risk register
The register is the output where the identified relationship is recorded, but the analysis of the cascade effect is part of Task 2.
-
-
5 Which of the following is considered a 'Physical' risk trigger according to industry-expert Carl Pritchard's framework for applying thresholds?
Look for a trigger that involves tangible, environmental conditions.
A sequence of five consecutive days of rainfall at a construction site.
Physical triggers are tangible environmental or material conditions that serve as early warning signs for risk events.
-
✗ A project team member reporting a feeling of burnout during a standup.
This would be categorized as a stakeholder-driven or behavioral indicator rather than a physical one.
-
✗ The project's Cost Performance Index (CPI) dropping to $0.85$.
This is a performance-based or metric-driven trigger, typically derived from data analysis.
-
✗ A change in national trade laws that affects supply chain logistics.
This is an external environmental factor (PESTLE), which acts as a driver of risk rather than a specific physical trigger.
-
-
6 An Agile team is identifying risks during iterative backlog refinement. They choose to track a specific technical uncertainty on a visual burn-down chart rather than a formal risk register. Why is this approach consistent with Agile risk management?
Think about the iterative and adaptive nature of risk tracking in non-predictive lifecycles.
It treats risk as a dynamic variable integrated into the iterative lifecycle.
Agile methodologies emphasize visual, collaborative boards to address threats in real time as they emerge during sprints.
-
✗ Agile environments do not allow for the use of traditional risk registers.
Agile teams can use registers, but they often prioritize visual, dynamic tracking tools for real-time adaptation.
-
✗ Burn-down charts are the only tools capable of calculating Expected Monetary Value (EMV).
EMV is a quantitative analysis tool and is not typically a native feature of a standard burn-down chart.
-
✗ It ensures that the Project Manager remains the sole owner of all identified risks.
Agile emphasizes collective team responsibility for risks, rather than centralized ownership by a project manager.
-
-
7 When utilizing a prompt list such as PESTLE during a risk identification session, what is a common pitfall that a risk professional must mitigate?
Consider the limitations of using fixed frameworks to identify unique or emerging uncertainties.
Relying too heavily on the list and missing risks that do not fit the pre-defined categories.
Over-reliance on standardized lists can lead to cognitive blind spots regarding 'unknown-unknowns' or unique project risks.
-
✗ The inability to use PESTLE in projects that utilize waterfall methodologies.
PESTLE is a versatile tool applicable across all project lifecycles, including predictive environments.
-
✗ PESTLE is only effective for identifying opportunities, not threats.
PESTLE is designed to scan the environment for both threats and opportunities across its various categories.
-
✗ The method requires complex statistical modeling that slows down the identification process.
PESTLE is a qualitative brainstorming tool and does not involve statistical modeling.
-
-
8 While developing the risk register, the team identifies a risk and assigns it an attribute called 'Connectivity.' What does this attribute help the team understand?
Think about the interdependencies within a web of potential project uncertainties.
The extent to which a risk is linked to other individual risks.
Connectivity is a meta-data attribute that identifies dependencies and relationships between different risks in the register.
-
✗ The ease with which a risk can be managed by the project team.
Manageability is the attribute used to describe the ease of monitoring or responding to a risk.
-
✗ The time required to detect that a risk event has occurred.
This attribute is known as Detectability or Dormancy.
-
✗ The total number of stakeholders affected by a single risk event.
This describes stakeholder impact or salience rather than the connectivity of the risk itself.
-
-
9 A risk manager is conducting a 'nominal classification' of risks in the Risk Breakdown Structure (RBS). Which domain task are they primarily supporting during this phase?
Identify the phase where raw identified data is initially organized for prioritization.
Task 1: Perform qualitative analysis
Qualitative analysis involves performing nominal classifications in the RBS using the categories defined in the risk management plan.
-
✗ Task 1: Conduct risk identification exercises
Identification focuses on surfacing the risks, while nominal classification is a sorting step that often leads into analysis.
-
✗ Task 4: Develop risk register
While the classification is recorded in the register, the act of performing the classification is part of the analysis task.
-
✗ Task 2: Examine assumption and constraint analyses
Assumption analysis is about validating boundaries, not classifying risks within a formal hierarchy.
-
-
10 In the context of Risk Identification, what is the primary distinction between a project constraint and a project risk?
Think about the role of certainty versus uncertainty in project planning.
Constraints are known-knowns that limit project options, whereas risks are uncertain events.
Constraints are pre-existing certainties (like a fixed budget), while risks are uncertainties that may or may not occur.
-
✗ Constraints are threats, while risks can be either threats or opportunities.
Both constraints and risks can be viewed negatively, but their distinction lies in their degree of certainty.
-
✗ Risks are documented in the risk register, while constraints are only documented in the project charter.
Both can appear across multiple documents, including the risk management plan and assumption log.
-
✗ Constraints are identified using SWOT analysis, while risks are identified using PESTLE.
SWOT and PESTLE are both tools used to identify both constraints and risks simultaneously.
-
-
11 A team is using a 'Tree Diagram' to assess the complexity of identified risks. This specific activity is listed as an enabler for which task in the PMI-RMP outline?
Focus on how structured diagrams help visualize the intricate nature of multi-tier objectives.
Identify threats and opportunities
Domain III, Task 3 explicitly lists using Tree Diagrams, SWOT, and Ishikawa as enablers to assess project risk complexity.
-
✗ Conduct risk identification exercises
Identification exercises typically use Delphi, brainstorming, and interviews; Tree Diagrams are used more for analyzing the structure of identified risks.
-
✗ Perform quantitative analysis
While related to decision trees, the use of a Tree Diagram to assess complexity is a broader analytical identification task.
-
✗ Develop risk register
The register captures the results but the enabler for complexity assessment via Tree Diagrams is found in the analysis domain.
-
-
12 During the 'Develop Risk Register' task, a risk professional identifies that a specific risk is 'External' and 'Contractual.' Which risk attribute category are they defining?
Identify the field used to distinguish the source and accountability for a risk.
Risk Origin and Ownership
Establishing where a risk comes from (internal/external) and who is responsible for it is a requirement for Task 4.
-
✗ Risk Urgency and Proximity
These attributes refer to the timing of the risk, not its source or contractual nature.
-
✗ Risk Probability and Impact
These refer to the likelihood and consequence of the risk, not its origin.
-
✗ Secondary and Residual Risk
These categories refer to risks that remain after a response or are created by the response itself.
-
-
13 An unvalidated assumption is categorized by David Hillson as what type of risk?
Consider knowledge that exists within the project context but has not yet been formally acknowledged or verified.
Unknown-Known
Unknown-knowns represent knowledge that is available but not yet recognized or integrated into the current project plan, often manifesting as unvalidated assumptions.
-
✗ Known-Known
Known-knowns are certainties or facts that are already established.
-
✗ Unknown-Unknown
Unknown-unknowns are emergent risks that cannot be predicted at all through identification sessions.
-
✗ Known-Unknown
Known-unknowns are identified risks that have been documented in the register but whose outcome is uncertain.
-
-
14 Which identification technique involves gathering preliminary documents like historical databases, industry benchmarks, and lessons learned before conducting a stakeholder workshop?
Identify the foundational task that uses existing organizational data to prepare for identification.
Preliminary Document Analysis
Domain I, Task 1 focuses on gathering and reviewing historical data and benchmarks to establish a baseline before risk identification starts.
-
✗ SWOT Analysis
SWOT is a brainstorming technique used to identify strengths, weaknesses, opportunities, and threats, usually during a workshop.
-
✗ Delphi Technique
Delphi uses expert feedback in rounds and does not inherently describe the initial collection of historical documents.
-
✗ Constraint Analysis
Constraint analysis evaluates project limitations rather than reviewing historical organizational data.
-
-
15 A risk statement that reads 'Because we are using a new vendor, there is a risk that the API integration may be delayed, resulting in a schedule slippage' is an example of which identification meta-data structure?
Analyze the components of the sentence that link the source of uncertainty to its potential outcome.
Cause-Risk-Effect
Standard risk statements are structured to show the source (Cause), the uncertainty (Risk), and the consequence (Effect).
-
✗ Probability-Impact-Urgency
These are scoring metrics for prioritizing the risk, not the syntax for describing it.
-
✗ Trigger-Threshold-Response
These are monitoring components, whereas the question asks for the identification structure of the statement.
-
✗ Threat-Opportunity-Origin
These are classifications for the risk, but they do not describe the sentence syntax shown.
-
-
16 When documenting risk triggers and thresholds (Task 3), a risk professional must ensure they assess and document which of the following to improve traceability?
Focus on the specific tactical components that signal the potential onset of a risk event.
Risk triggers, causes, and timing.
Task 3 of Risk Identification specifically requires documenting triggers along with their underlying causes and estimated timing.
-
✗ The Risk Appetite of the senior sponsor.
Risk appetite is a strategic threshold defined in Domain I, not a tactical trigger for a specific risk.
-
✗ The final Expected Monetary Value (EMV) of the project.
EMV is a cumulative quantitative figure and is not used to document individual risk triggers during identification.
-
✗ The Monte Carlo simulation output for the schedule.
This is an output of quantitative analysis used for forecasting, not a documentation requirement for triggers.
-
-
17 A team is using a Failure Mode and Effects Analysis (FMEA) approach within their risk register. Which additional attribute must be added to the register to accommodate this method?
Identify the attribute that measures the team's ability to notice a risk before it impacts the project.
Detectability
FMEA incorporates Detectability alongside Probability and Impact to calculate a Risk Priority Number (RPN).
-
✗ Strategic Impact
Strategic impact is a high-level assessment of alignment with business goals, not specific to FMEA.
-
✗ Proximity
Proximity refers to timing and is a standard risk attribute regardless of whether FMEA is used.
-
✗ Manageability
Manageability describes how easily a risk can be monitored, but it is not one of the core three metrics of FMEA.
-
-
18 Which of the following would be categorized as an 'Unknown-Unknown' during a risk identification exercise?
Consider risks that reside outside the limits of predictive or proactive identification methods.
An emergent risk that cannot be proactively identified before it occurs.
Unknown-unknowns are risks that are impossible to predict during standard identification sessions and are usually covered by management reserves.
-
✗ A risk that was identified but determined to have a low probability.
This is a 'Known-Unknown' because it was identified and documented.
-
✗ A hidden project dependency found during assumption analysis.
Once found during analysis, this becomes a 'Known-Unknown' or an identified risk.
-
✗ A risk that has occurred in the past on similar projects.
Past risks are 'Known-Knowns' (if they are facts of history) or 'Known-Unknowns' if they are applied to the current project.
-
-
19 What is the primary objective of Task 2 in Domain II: Examine assumption and constraint analyses?
Focus on the verification of the foundational beliefs used to build the project plan.
To identify hidden risks by verifying planning boundaries and dependencies.
Assumption analysis uncovers risks by testing whether the beliefs held during planning are actually true.
-
✗ To calculate the statistical likelihood of achieving the project deadline.
This is the goal of quantitative analysis, not assumption and constraint analysis.
-
✗ To select the most appropriate response strategy for identified threats.
Response strategy selection is the focus of Domain IV: Risk Response.
-
✗ To categorize risks according to the Risk Breakdown Structure (RBS).
Categorization is part of the Risk Register development and qualitative analysis tasks.
-
-
20 During risk identification, a risk manager identifies a potential positive outcome. This is formally documented in the risk register as a/an:
Think about the dual nature of risk as defined by the PMI.
Opportunity
An opportunity is an uncertain event that, if it occurs, has a positive effect on one or more project objectives.
-
✗ Enhancement
Enhancement is a response strategy for an opportunity, not the term for the opportunity itself.
-
✗ Secondary Benefit
Secondary benefits are not standard PMI terminology; positive risks are always referred to as opportunities.
-
✗ Fallback Plan
A fallback plan is a response developed for when a primary risk response fails.
-
-
21 You are assessing the risk associated with a constraint that dictates the project must use a specific legacy database. This assessment is a part of which task?
Look for the task that focuses on testing the impacts of project limitations.
Examine assumption and constraint analyses
Task 2 of Domain II explicitly involves categorizing and assessing the risk associated with project constraints.
-
✗ Document risk triggers and thresholds
While the legacy database might have triggers, the assessment of the constraint itself is Task 2.
-
✗ Develop risk register
The register stores the result, but the assessment process is part of Task 2.
-
✗ Perform qualitative analysis
Qualitative analysis prioritizes identified risks, while Task 2 identifies them through constraint evaluation.
-
-
22 The 'Propinquity' of a risk refers to:
Consider the psychological or perceived relevance of an uncertainty to those involved.
The degree to which a risk matters to stakeholders.
Propinquity is a subjective attribute measuring the perceived importance or 'closeness' of a risk to stakeholders.
-
✗ The time until a risk event occurs.
This is the definition of Proximity.
-
✗ The complexity of the response strategy required.
This would be categorized under manageability or complexity attributes.
-
✗ The geographical distance of the risk event from the project site.
While the name sounds physical, in risk management, it refers to stakeholder perception.
-
-
23 Which task in the Risk Identification domain involves 'analyzing documents, audio transcripts, telemetry data, and understanding business context'?
Identify the primary task that involves comprehensive data gathering from non-traditional project sources.
Conduct risk identification exercises
This task enabler specifically includes analyzing various data sources, such as audio and telemetry, to uncover potential risks.
-
✗ Examine assumption and constraint analyses
This task focuses on the assumption and constraint logs specifically, rather than a broad analysis of telemetry or transcripts.
-
✗ Document risk triggers and thresholds
Triggers are indicators, while the question describes a broad identification technique using various media.
-
✗ Develop risk register
The register captures the output of the analysis but does not describe the act of analyzing transcripts.
-
-
24 In the risk register (Task 4), which of the following is required to establish 'Risk Origin'?
Consider the basic classification that identifies the source environment of the risk.
Classifying the risk as either Internal or External.
Task 4 blueprints require establishing the origin and ownership, specifically identifying if a risk is internal or external.
-
✗ Identifying whether the risk is a threat or an opportunity.
While required, this classifies the nature of the risk, not its origin.
-
✗ Assigning a specific Monte Carlo probability percentage.
This is a quantitative analysis activity, not a basic origin classification in the register.
-
✗ Defining the Cost Performance Index (CPI) of the project.
CPI is an earned value metric used for performance monitoring, not for identifying a risk's origin.
-
-
25 What is the primary role of a 'Risk Trigger' during the project lifecycle?
Think about the tactical signals used by project teams to activate response plans.
To serve as an early warning indicator that a risk is about to occur.
A trigger is a condition or event that signals that a risk event is imminent or has already happened.
-
✗ To calculate the probability of a risk event in a quantitative model.
Probabilities are calculated based on data; triggers are indicators that the event is becoming more likely or is occurring.
-
✗ To define the strategic risk appetite of the organization.
Appetite is defined at the planning stage for the whole organization, not for individual risks during identification.
-
✗ To act as a secondary risk arising from a response action.
Secondary risks are themselves risks, whereas triggers are signs or signals.
-
-
26 A risk manager is performing 'Dormancy' analysis. What are they trying to determine?
Focus on the time delay between the event's occurrence and its visible consequence.
The period of time after a risk occurs but before its impact is discovered.
Dormancy refers to the 'lead time' for observing the impact of an event that has already transpired.
-
✗ How much time is available to respond to an event once identified.
This is the definition of Urgency.
-
✗ The probability that a risk will return after being mitigated.
This describes residual risk or risk recurrence, not dormancy.
-
✗ The closeness of the risk to the project's critical path.
This would be an analysis of schedule proximity or connectivity.
-
-
27 When documenting risks in the register, 'Urgency' is distinct from 'Proximity' because:
Consider the difference between when you need to act and when the event occurs.
Urgency measures the response time, while Proximity measures the event time.
Urgency is the window for action; Proximity is when the event itself is expected to happen.
-
✗ Urgency is qualitative, while Proximity is quantitative.
Both can be assessed qualitatively (High/Low) or quantitatively (Days/Weeks).
-
✗ Urgency applies only to threats, while Proximity applies only to opportunities.
Both attributes apply to all risks regardless of their positive or negative impact.
-
✗ Urgency refers to stakeholder perception, while Proximity is a factual timeline.
Propinquity refers to perception; Proximity is a timing estimate.
-
-
28 According to the Domain II blueprint, what is the role of 'telemetry data' in risk identification?
Think about how automated or remote data feeds contribute to discovering project uncertainties.
It provides a data source for understanding business context and uncovering risks.
Task 1 enablers mention analyzing telemetry data to help identify risks in a business context.
-
✗ It is used exclusively to calculate management reserves.
Management reserves are for unknown-unknowns; telemetry is used to identify specific, observable risks.
-
✗ It is a qualitative tool used for Delphi round consensus.
Telemetry is quantitative or objective data, whereas Delphi is a qualitative expert opinion method.
-
✗ It acts as a substitute for stakeholder interviews.
Telemetry is a supplement to, not a replacement for, human expertise in risk identification.
-
-
29 A team is assessing 'Detectability' within their risk identification register. This attribute measures:
Think about how obvious or hidden a risk event remains at the moment of onset.
The ease with which the occurrence of a risk can be observed and recognized.
Detectability measures the probability that a risk event will be noticed when it happens.
-
✗ The likelihood that a risk will occur during the project.
This is the definition of Probability.
-
✗ The distance of a risk's origin from the project's internal environment.
This describes risk origin/ownership (Internal/External).
-
✗ The impact of the risk on the project's critical success factors.
This is known as strategic impact or severity.
-
-
30 What is the primary output of Task 4 in Domain II: Develop risk register?
Focus on the initial capture and documentation of the threats and opportunities discovered.
A structured repository capturing risk descriptions, origins, and preliminary attributes.
The goal of Task 4 is to develop the risk register by analyzing validity, attributes, origin, and classification.
-
✗ A prioritized list of risks with calculated Monte Carlo probabilities.
Prioritization and Monte Carlo calculations are outputs of Domain III: Analysis, not identification.
-
✗ A formal Risk Management Plan (RMP) approved by the sponsor.
The RMP is the output of Domain I: Strategy and Planning.
-
✗ A set of response strategies like Avoid, Transfer, and Mitigate.
Response strategies are the primary output of Domain IV: Risk Response.
-