Skip to content

PMI-RMP : Monitor and Close Risks (Domain 5)

PMI – PMI-RMP : Certified Risk Management Professional - Domain 5 - Monitor and Close Risks

30 questionsmedium

Domain 5 of the Risk Management Professional (PMI-RMP) curriculum, “Monitor and Close Risks,” represents a critical phase in the risk management lifecycle, accounting for 19% of the certification examination. This domain focuses on the continuous oversight of identified risks, the evaluation of the effectiveness of implemented risk responses, and the formal closing of risk events once they no longer pose a threat or opportunity. In a modern project environment, which may utilize predictive, agile, or hybrid methodologies, monitoring ensures that risk levels remain within established organizational thresholds and that the project continues to deliver value despite uncertainty.

The primary objective of this domain is to provide the risk professional with the tools and techniques necessary to maintain an accurate and dynamic risk profile. This involves not only tracking known risks but also identifying new risks that emerge as the project progresses. By reconciling performance data, performing variance analysis, and conducting regular risk audits, the risk professional ensures that the project remains resilient and that stakeholders are kept informed of the evolving risk landscape.

Gathering and Analyzing Risk-Relevant Performance Data

The monitoring process begins with the systematic collection of performance data from various project work packages. This data serves as the raw material for understanding how uncertainty is affecting project progress. The risk professional must reconcile performance reports to determine if the work being performed aligns with the risk management plan and the overall project baseline.

Data gathering often involves the Project Management Information System (PMIS), which tracks schedule progress, cost expenditures, and resource utilization. In this context, metrics are used to evaluate the status of risk-related activities. For instance, if a risk response was designed to mitigate a technical threat, the risk professional examines telemetry data or technical performance metrics to verify if the mitigation is working as intended. Gathering this data requires collaboration with work package owners and financial controllers to ensure that the information is accurate and reflects the current state of project execution.

In agile and hybrid environments, this data gathering is more iterative. Rather than relying on monthly status reports, risk data is captured during daily stand-ups and sprint reviews. The focus remains on whether the team is encountering roadblocks (threats) or finding ways to accelerate delivery (opportunities). Regardless of the lifecycle, the goal is to obtain a clear, data-driven picture of how risks are materializing and how the project’s risk exposure is changing over time.

Reconciling Progress: Variance and Trend Analysis

Once performance data is gathered, the risk professional must perform variance and trend analysis to determine the health of the project’s risk profile. Variance analysis involves comparing the actual results of the project against the planned baseline. Significant deviations in cost or schedule often indicate that risks are occurring or that the current risk responses are ineffective.

Trend analysis looks backward at historical information and forward at forecasted data to identify patterns. For example, if the project consistently shows a negative cost variance over several reporting periods, the risk professional may identify a trend suggesting that the initial risk analysis underestimated the impact of market volatility or technical complexity. By analyzing these trends, the professional can forecast whether the project is likely to remain within its risk thresholds or if proactive adjustments are required.

Quantitative techniques, such as sensitivity analysis or Monte Carlo simulations, are often revisited during the monitoring phase to update forecasts. These tools help determine the probability of meeting project objectives based on current performance trends. If the variance is outside of acceptable limits, it may trigger a formal risk reassessment or a request for a change through the project’s change control system.

Monitoring Residual Risks

Even when a risk response is successfully implemented, the threat or opportunity rarely disappears entirely. Residual risks are those risks that remain after a response has been executed. For instance, if a project team decides to mitigate a technical risk by using a more experienced vendor, a residual risk may still exist regarding the vendor’s ability to meet a highly aggressive schedule.

The risk professional must document these residual exposures in the risk register and continue to track them. It is essential to communicate to stakeholders that while the primary risk has been addressed, the project is not entirely free of that specific uncertainty. Monitoring residual risks ensures that the project team is not caught off guard by the remaining elements of a threat that was previously thought to be “handled.”

The assessment of residual impact involves evaluating whether the remaining exposure still aligns with the organizational risk appetite. If the residual risk exceeds established thresholds, additional responses may be required, or the risk may need to be escalated to senior management.

Secondary Risks and Response Impacts

A unique challenge in risk monitoring is the emergence of secondary risks. These are risks that arise as a direct result of implementing a risk response. For example, if a project team chooses to “Transfer” a risk by purchasing insurance or outsourcing work, a secondary risk might emerge in the form of contract disputes or the financial instability of the chosen partner.

Identifying secondary risks requires a vigilant and critical assessment of every action taken by the risk team. During risk reviews, the professional must ask: “What new threats have we created by attempting to solve this one?” The impact of these secondary risks must be assessed against project objectives like scope, schedule, and cost.

By monitoring the effectiveness of responses and the subsequent secondary risks, the risk professional maintains the integrity of the project plan. If a response creates more threats than it solves, it may be necessary to improvise or revert to a fallback plan. Effective monitoring captures these dynamics early, preventing a cascade of new issues from overwhelming the project.

Documenting and Closing Expired Risks

A crucial but often overlooked task in Domain 5 is the formal closing of risks. A risk is considered expired when the time frame in which it could occur has passed or the conditions that would trigger it are no longer possible. For instance, a risk related to the delivery of a specific piece of equipment expires once that equipment is safely on-site and verified.

Closing expired risks is essential for accurate reporting. Keeping hundreds of inactive risks in the register creates “noise” that can obscure significant, current threats. When a risk is closed, the risk professional should update its status in the risk register and communicate this to the relevant stakeholders.

Furthermore, closing a risk often involves financial and resource management. If contingency reserves were set aside for a specific threat, those funds should be released back into the project budget or the organizational pool once the risk has expired. This process of “cleaning” the risk register ensures that the project’s risk exposure is never artificially inflated and that management has a realistic view of the project’s financial health.

Updating Relevant Project Artifacts

As the project progresses, the risk management lifecycle generates a significant amount of information that must be reflected in official project documents. The risk register is the primary document requiring constant updates, including changes in risk probability, impact, urgency, and response status.

However, the risk professional’s documentation duties extend beyond the risk register. Other key artifacts include:

  • Change Logs: If a risk response necessitates a change to the project’s scope, schedule, or budget, this must be formally recorded in the change log following approval.
  • Lessons Learned Register: Throughout the monitoring phase, the team discovers what worked and what didn’t. Capturing these insights in real-time is vital for future project phases and organizational knowledge.
  • Risk Breakdown Structure (RBS): As new categories of risk are identified during monitoring, the RBS may need to be expanded to ensure comprehensive categorization.
  • Project Management Plan: Monitoring may reveal the need to adjust risk roles, responsibilities (RACI), or the frequency of risk reviews, requiring updates to the subsidiary risk management plan.

Updating these documents ensures that there is a “single source of truth” for the project and that all team members are operating with the most current information.

Risk Audits: Evaluating Process Effectiveness

While status reviews focus on the risks themselves, risk audits focus on the effectiveness of the process. A risk audit is a structured review that assesses how well the team is identifying, analyzing, and responding to uncertainty. The audit determines if the risk management strategy established in Domain 1 is actually being followed and if it is producing the desired results.

Risk audits can be conducted by internal team members or external specialists. They examine whether risk identification exercises are sufficiently frequent, if qualitative and quantitative scoring is consistent, and if risk owners are actively managing their assigned tasks.

The output of a risk audit is a set of recommendations for improving the risk process. For example, an audit might reveal that the team is excellent at identifying technical risks but frequently misses external or environmental threats. By identifying these systemic weaknesses, the risk professional can coach the team and adjust the strategy to enhance organizational resilience.

Monitoring Project-Wide Risk Levels and Exposure

Risk management is not just about individual events; it is about the aggregate risk level of the entire project. The risk professional must monitor the overall project risk exposure to ensure it does not exceed the organization’s capacity to absorb loss. This project-wide view considers the combined impact of all threats and opportunities.

Monitoring project-wide risk involves summarizing data into high-level reports for senior stakeholders. Tools such as risk burndown charts (common in agile environments) or S-curves (common in predictive environments) are used to illustrate whether the total risk level is increasing or decreasing over time.

This high-level monitoring also looks at the materialization of project benefits. If the total risk exposure becomes too high, the project may no longer be a viable investment for the organization. By providing this information to sponsors and steering committees, the risk professional supports strategic decision-making and ensures that the project remains aligned with organizational goals.

Risk Monitoring in Agile, Hybrid, and Predictive Lifecycles

The approach to monitoring risks must be tailored to the project delivery methodology. In predictive (waterfall) environments, monitoring is often more formal, utilizing scheduled status meetings, baseline-allocated contingency reserves, and structured probability-impact matrices. The focus is on maintaining the baseline and managing deviations through a central change control board.

In agile environments, risk monitoring is decentralized and continuous. Agile teams address uncertainty through daily stand-ups and sprint retrospectives. Rather than a static risk register, agile projects may use visual boards and backlogs to track operational and technical threats. The “servant leader” or risk professional in an agile context focuses on removing “impediments,” which are effectively materialized risks.

Hybrid environments combine these approaches, perhaps using agile ceremonies for technical execution while maintaining a traditional risk register for high-level contract or environmental risks. Regardless of the lifecycle, the fundamental task remains the same: ensure that uncertainty is transparently tracked and that the project team is empowered to respond effectively.

Communication and Stakeholder Engagement in Monitoring

Effective risk monitoring is impossible without constant communication. The risk professional acts as a facilitator, ensuring that stakeholders at all levels understand the current risk status. This requires tailoring communication to the audience; for example, technical teams need detailed data on specific work package variances, while executives require summarized reports on overall risk exposure and reserve status.

Stakeholder engagement also involves managing risk attitudes. If stakeholders become too complacent or, conversely, overly risk-averse, the risk professional must intervene to realign expectations with the project’s strategic objectives. By fostering a culture of risk awareness, the professional ensures that team members feel empowered to report new threats and triggers immediately rather than waiting for a formal review.

Using tools like the RACI matrix during the monitoring phase helps clarify accountability. When a risk trigger is reached, there should be no confusion about who is responsible for executing the response. Monitoring ensures that these lines of accountability remain clear throughout the project’s duration.

Summary of Domain 5 Tasks and Objectives

Task IDOfficial Task StatementCore Monitoring Focus
Task 1Gather and analyze performance dataMetrics from work packages; baseline variance analysis.
Task 2Monitor residual and secondary risksTracking remaining exposure and new threats from responses.
Task 3Update relevant project documentsRefreshing registers, change logs, and lessons learned.
Task 4Monitor project risk levelsConducting risk audits, reviews, and stakeholder reporting.

Domain 5 serves as the “control center” of the risk management lifecycle. It requires the professional to be both a data analyst—interpreting variances and trends—and a strategic communicator—keeping stakeholders informed and aligned. By successfully executing the tasks in this domain, a risk professional protects organizational assets and ensures that the project maximizes value delivery even in volatile environments.


Short Answer Questions

1. What is the primary difference between a risk audit and a risk review? Answer: A risk audit evaluates the effectiveness of the risk management process and strategy, whereas a risk review focuses on assessing the status and priority of individual risks in the register. The audit is a governance activity, while the review is a tactical tracking activity.

2. Why is it important to monitor secondary risks after implementing a risk response? Answer: Secondary risks are new threats that occur as a direct consequence of a response action. Monitoring them ensures that the solution to one problem does not create a new, potentially more severe issue for the project.

3. When should a risk be formally “closed” in the risk register? Answer: A risk should be closed when the time window for its occurrence has passed or when the project conditions that would enable the risk no longer exist. This maintains an accurate and focused risk register by removing irrelevant data.

4. How does variance analysis contribute to risk monitoring? Answer: Variance analysis compares actual project performance against the planned baseline to identify deviations. Significant variances often serve as indicators that risks have materialized or that existing response strategies are failing.

5. What is a “residual risk”? Answer: A residual risk is the level of uncertainty that remains even after a formal risk response has been successfully implemented. It represents the “leftover” exposure that the project must still acknowledge and track.

6. What role does the change log play in Domain 5? Answer: The change log records any adjustments to the project plan, scope, or budget that result from risk response actions. This ensures that all risk-driven modifications are formally authorized and integrated into the project documentation.

7. How do agile teams typically monitor risks without a traditional risk register? Answer: Agile teams monitor risks through iterative ceremonies like daily stand-ups, sprint reviews, and retrospectives, often using visual impediments boards or burn-down charts to track threats in real-time. This allows for rapid adaptation rather than waiting for monthly reports.

8. What should happen to contingency reserves when a risk expires? Answer: When a risk expires, the contingency reserves specifically allocated for that risk should be released back to the project budget or organizational pool. This ensures that the financial resources are managed efficiently and are available for other project needs.

9. What is a “risk trigger”? Answer: A risk trigger is an early warning indicator or a specific condition that signifies a risk is about to occur or has occurred. Monitoring triggers allows the project team to implement responses proactively rather than reactively.

10. How does a risk professional determine if project-wide risk levels are acceptable? Answer: The risk professional compares the aggregate risk exposure of the project against the organization’s established risk appetite and thresholds. If the total exposure exceeds these boundaries, the project may need to be escalated or re-evaluated for strategic alignment.


Scenario and Design Questions

1. Design a risk monitoring report for an executive steering committee. Requirement: The design should specify which high-level metrics (e.g., aggregate exposure, reserve status, major threats) should be included and explain why these are prioritized over detailed technical risk data.

2. A project team implements a “Transfer” strategy by outsourcing a critical software component. Identify three possible secondary risks and design a monitoring plan for them. Requirement: The plan must include specific triggers for the secondary risks (e.g., vendor performance metrics) and define how often these should be reviewed.

3. You are a risk professional in a hybrid project where the hardware is managed via waterfall and the software via agile. Propose a framework for reconciling risk data from these two different lifecycles. Requirement: Describe how you would integrate agile impediments into a traditional risk register and how the frequency of monitoring would be coordinated.

4. During a risk audit, you discover that 40% of the risks in the register have already passed their window of occurrence but are still marked as “Open.” Create a remediation plan. Requirement: Detail the steps for closing the risks, releasing reserves, and updating the lessons learned to prevent this lack of maintenance in the future.

5. A project shows a consistent 15% cost variance over the last three months, though no individual risks have been reported as “Materialized.” Analyze this trend and suggest a risk monitoring action. Requirement: Explain whether this situation suggests a failure in identification, a failure in qualitative analysis, or the presence of a “risk trend,” and what tools you would use to investigate.


Glossary of Key Terms

  • Baseline: The approved version of a work product, such as the project schedule or budget, used as a starting point for comparison during variance analysis.
  • Contingency Reserve: Funds or time set aside within the project baseline specifically for “known-unknowns” or identified risks that may occur.
  • Management Reserve: A portion of the budget or schedule held by senior management for “unknown-unknowns” or risks that were not identified in the planning phase.
  • Monte Carlo Simulation: A computerized mathematical technique that accounts for risk in quantitative analysis and decision-making by running thousands of scenarios to show a range of possible outcomes.
  • PESTLE: A strategic tool (Political, Economic, Social, Technological, Legal, Environmental) used during risk re-evaluation to analyze the external environment for emerging threats or opportunities.
  • Probability and Impact (P-I) Matrix: A grid used during monitoring to map the likelihood of a risk occurring and the severity of its consequence, helping to prioritize the team’s focus.
  • RACI Matrix: A responsibility assignment chart (Responsible, Accountable, Consulted, Informed) used to clarify roles for risk monitoring and response execution.
  • Residual Risk: The remaining risk exposure that exists after a risk response strategy has been implemented.
  • Risk Appetite: The degree of uncertainty an organization or individual is willing to accept in anticipation of a reward.
  • Risk Audit: A formal assessment of the efficiency and effectiveness of the risk management process throughout the project lifecycle.
  • Risk Breakdown Structure (RBS): A hierarchical representation of potential sources of risk, used during monitoring to ensure all categories of uncertainty are being tracked.
  • Risk Burndown Chart: A visual tool used primarily in agile projects to show how the total risk exposure is decreasing (or increasing) over time.
  • Risk Register: A living document that serves as the central repository for all identified risks, including their owners, triggers, status, and responses.
  • Risk Threshold: The specific point at which a stakeholder or organization will take action based on the level of risk exposure.
  • Secondary Risk: A new risk that arises as a direct consequence of an implemented risk response.
  • Sensitivity Analysis: A technique used to determine which individual risks have the potential for the greatest impact on project outcomes, often visualized using a Tornado Diagram.
  • SWOT Analysis: A technique for assessing Strengths, Weaknesses, Opportunities, and Threats; used in monitoring to re-evaluate the project’s internal and external environment.
  • Trend Analysis: The practice of collecting information and attempting to spot a pattern or forecast future performance based on historical data.
  • Variance Analysis: The process of quantifying the difference between actual project performance and the planned baseline to identify potential risk events.
  • Work Package: The lowest level of the Work Breakdown Structure (WBS) for which cost and duration are estimated and managed; the primary source for risk performance data.

Leaderboard

No scores saved yet. Be the first!

30 Questions — PMI – PMI-RMP : Certified Risk Management Professional - Domain 5 - Monitor and Close Risks

Expand any question to reveal the correct answer and explanation.

  1. 1 During a monthly project status review, the risk manager identifies that several work packages have exceeded their planned durations, but no risks were triggered. Which action should the project manager take to fulfill the 'Gather and analyze performance data' task in Domain 5?

    Focus on the technique used to compare actual performance metrics with the intended project baseline.

    Perform a variance analysis to reconcile work package data against the risk baseline.

    This technique allows the practitioner to determine if project performance deviates from the risk baseline, indicating potentially unidentified risks or poorly assessed triggers.

    • Immediately update the risk register with new threats related to schedule slippage.

      While updating the register is eventually necessary, the performance data must first be analyzed to understand the cause and magnitude of the deviation.

    • Execute the contingency plan for schedule delays as a proactive measure.

      Contingency plans should only be executed when specific risk triggers are met, rather than as a general reaction to performance variance without further analysis.

    • Request a project-wide risk audit to evaluate the integrity of the Risk Management Plan.

      A risk audit is a high-level process used to evaluate the effectiveness of the entire risk process, which is excessive for reconciling specific work package variances.

  2. 2 A project team implements a 'Transfer' strategy by hiring a third-party vendor to handle specialized technical components. During the monitoring phase, the vendor reports a delay due to their internal logistics. This new threat is classified as which of the following?

    Think about the specific term for risks that are birthed by the response actions taken for another risk.

    A secondary risk.

    Secondary risks are those that arise as a direct consequence of implementing a specific risk response strategy.

    • A residual risk.

      Residual risks are the portions of the original risk that remain after a response is implemented, rather than new risks introduced by the response itself.

    • A workaround.

      A workaround is an unplanned response to a risk that has occurred, whereas this describes the nature of the risk event itself.

    • An unidentified risk.

      While it may have been unforeseen, the standard classification for risks generated by a response is more specific than just being unidentified.

  3. 3 As a project approaches its mid-way milestone, the risk professional notes that a high-impact risk associated with the procurement phase is no longer relevant because all contracts have been signed and locked. What is the most appropriate step in Domain 5?

    Consider the procedural requirement for managing risks that are tied to specific completed project events.

    Retire the risk in the risk register and document lessons learned.

    Ongoing monitoring requires identifying expired risks and formally closing them to maintain an accurate view of project risk exposure.

    • Keep the risk open until project closure to ensure historical traceability.

      Maintaining expired risks in an active status inflates the overall risk level and obscures the current reality of the project's exposure.

    • Reallocate the contingency reserves tied to this risk to the management reserve.

      Management reserves are typically controlled at the organizational level and intended for unknown unknowns; contingency reserves for closed risks are usually released or redirected based on specific governance.

    • Delete the risk entry from the register to simplify reporting for stakeholders.

      Risk entries should never be deleted; they must be closed and archived to provide an audit trail and data for future benchmarking.

  4. 4 A risk audit is scheduled for a project with high technical complexity. Which of the following best describes the objective of this audit within 'Monitor and Close Risks'?

    Differentiate between evaluating the risk events themselves and evaluating the quality of the project's risk framework.

    To evaluate the effectiveness of the risk management processes and response actions.

    Risk audits examine the team's ability to identify risks and the success of the responses implemented to handle them.

    • To update the probability and impact scores for all active risks in the register.

      Updating scores is part of a risk reassessment, which focuses on the risks themselves rather than the process used to manage them.

    • To calculate the final Expected Monetary Value ($EMV$) of the project's remaining exposure.

      EMV calculations are an analytical task within the analysis domain, whereas an audit focuses on process governance and effectiveness.

    • To determine which team members are responsible for missed risk triggers.

      Audits are intended to improve processes and effectiveness rather than to assign personal blame for specific risk occurrences.

  5. 5 A project manager is analyzing the risk burndown chart and notices that the total risk exposure is increasing even though several high-priority threats have been avoided. What is the most likely conclusion for Domain 5 analysis?

    Think about how 'inventory' of project risk behaves when the identification rate exceeds the closure rate.

    New risks or secondary risks are being identified faster than existing risks are being closed.

    An upward trend in a burndown chart indicates that the rate of risk discovery or emergence is outpacing the rate of risk resolution.

    • The project is currently in the 'Storming' phase of team development.

      While team dynamics impact risk, a burndown chart is a direct quantitative metric of risk exposure rather than a tool for assessing team stages.

    • The risk thresholds were set too low, triggering unnecessary response actions.

      Low thresholds would likely lead to more closed risks (as they are addressed quickly), not necessarily an increase in overall exposure.

    • The $P \times I$ matrix was incorrectly calibrated during the planning phase.

      Calibration errors would cause static issues with scoring but wouldn't typically cause a rising trend in exposure unless identification practices were also flawed.

  6. 6 When reconciling work package performance data against the project baseline, a practitioner identifies a consistent $10\%$ cost variance ($CV$) in technical tasks. What should be the subsequent action in Task 1 of Domain 5?

    Consider the logical progression from identifying a local deviation to understanding its global project impact.

    Analyze the impact of this variance on the overall project risk exposure to the enterprise.

    Performance data from work packages must be scaled up to evaluate how local variances affect the project's total risk profile and alignment with enterprise goals.

    • Update the Risk Breakdown Structure ($RBS$) to include a new category for cost overruns.

      The RBS is a structural tool for categorization and is generally not updated based on specific performance variances of a single work package.

    • Immediately request an increase in management reserves to cover the deficit.

      Management reserves are for 'unknown unknowns,' and a $10\%$ variance in known work packages suggests a performance issue or a 'known unknown' contingency issue.

    • Revise the Risk Management Plan to increase the frequency of qualitative analysis.

      Increasing the frequency of meetings does not address the underlying analysis of the current performance variance or its impact.

  7. 7 A risk professional is updating the lessons learned repository after a major risk event was successfully mitigated. Why is this action critical to Task 3 of Domain 5?

    Look for the value this action provides to the 'Enterprise Risk Management' framework as a whole.

    It ensures that the knowledge gained is archived for the benefit of future projects and the organization.

    Capturing lessons learned during monitoring and closure is essential for organizational process asset improvement and risk maturity.

    • It serves as the formal approval document for the closure of that specific risk.

      Closure approval is typically tracked in the risk register or through a change board, while lessons learned are focused on knowledge transfer.

    • It is a mandatory requirement for recalculating the project's standard deviation ($\sigma$).

      Standard deviation calculations are mathematical tasks within quantitative analysis and do not rely on the lessons learned repository.

    • It provides a legal record to protect the project manager from accountability for the risk realization.

      The purpose of risk documentation is proactive management and learning, not individual legal protection or the deflection of accountability.

  8. 8 During a risk reassessment, the team determines that an 'Accept' strategy for a specific technical threat is no longer viable because the potential impact has grown beyond the risk threshold. What should the project manager do next?

    Consider what happens to a risk strategy when it is no longer aligned with the defined boundaries of risk tolerance.

    Identify and plan a new risk response strategy to address the increased exposure.

    Monitoring requires continuous evaluation of strategy effectiveness; if a risk exceeds thresholds, the current strategy must be replaced.

    • Update the risk threshold to accommodate the new impact level.

      Thresholds are established based on organizational appetite and should not be moved just to 'make room' for growing project risks.

    • Close the risk in the register and open a new one with the updated impact details.

      Risks should be updated and tracked throughout their lifecycle rather than being closed and reopened for changes in attribute values.

    • Perform a Monte Carlo simulation to justify the current 'Accept' strategy to stakeholders.

      Simulations help understand probability distributions but cannot validate a strategy that violates pre-defined organizational thresholds.

  9. 9 Which of the following is a key enabler for Task 4: 'Monitor project risk levels'?

    Look for the activity that involves a periodic check of current project status against the plan.

    Conducting regular risk status reviews and audits to evaluate risk levels.

    Ongoing assessments via reviews and audits are primary mechanisms for validating that the project remains within acceptable risk boundaries.

    • Developing a hierarchical Risk Breakdown Structure ($RBS$).

      Developing the RBS is a planning and identification activity (Domain I and II) rather than an active monitoring task.

    • Defining the specific roles and responsibilities in a $RACI$ chart.

      Establishing roles and responsibilities is a foundational governance task in the strategy and planning phase.

    • Drafting the initial Risk Management Plan ($RMP$) for the project sponsor.

      Drafting the RMP is the core output of the strategy and planning phase, providing the guide for monitoring, but is not the monitoring act itself.

  10. 10 A project manager is monitoring a risk that was 'Mitigated' earlier in the project. The mitigation cost was higher than expected, but the risk impact was successfully reduced. How should this be handled in the 'Monitor and Close Risks' domain?

    Focus on the analytical step of assessing the 'value for money' of a completed risk action.

    Evaluate the cost-benefit effectiveness of the response and update the risk register.

    Monitoring includes assessing whether the responses implemented were worth the investment and capturing that data for future analysis.

    • Transfer the excess cost to the management reserve since the risk was successfully handled.

      Management reserves are not for cost overruns on known risk responses; these costs should be reconciled against the project budget or contingency.

    • Close the risk immediately to reflect the successful reduction of the impact.

      A risk should only be closed if it is no longer a threat; if residual risk remains after mitigation, it must still be monitored.

    • Update the project charter to reflect the new budget baseline after the mitigation expenditure.

      The project charter is a high-level document rarely updated for tactical budget variances; budget updates happen in the project management plan and cost baselines.

  11. 11 While gathering performance data, a project manager identifies that a risk trigger has occurred, but the associated threat did not materialize as expected. What is the most appropriate documentation update for Task 3?

    Consider how the project manager uses actual events to improve the predictive accuracy of their tools.

    Update the risk register to refine the trigger definition and record the actual outcome.

    Updating triggers based on real-world occurrences improves the precision of the monitoring process for the remainder of the project.

    • Remove the trigger from the risk register since it yielded a false positive.

      A 'false positive' trigger is still valuable data that should be refined rather than deleted, as the threat may still exist under different conditions.

    • Immediately recalculate the three-point estimate for all remaining work packages.

      One mismatched trigger event does not necessarily invalidate the duration or cost estimates of the entire project.

    • Report to stakeholders that the risk has been successfully avoided.

      Avoidance is a proactive planning strategy; if a trigger was hit and nothing happened, it is a monitoring anomaly, not the result of an 'Avoid' strategy.

  12. 12 In an Agile project environment, the team identifies a 'technical debt' risk that has grown significantly over the last three sprints. Which Domain 5 activity best describes the team's response in the next retrospective?

    Think about how agile teams use their recurring meetings to pivot based on emerging uncertainty.

    Analyzing performance data and monitoring the project risk level to adapt the backlog.

    Agile monitoring involves using iterative reviews (retrospectives) to assess current risk levels and integrate adjustments directly into the workflow.

    • Performing a detailed quantitative sensitivity analysis using a Tornado diagram.

      Tornado diagrams are sophisticated quantitative tools typically used in predictive or hybrid environments for numerical modeling, rather than standard agile retrospectives.

    • Updating the project's static Risk Management Plan ($RMP$) to change the audit frequency.

      Agile environments favor dynamic, visual tracking over formal, static plan updates for tactical risk shifts like technical debt.

    • Moving the risk to the 'Closed' status because technical debt is an operational issue, not a project risk.

      Technical debt is a major source of project uncertainty that impacts quality and schedule, making it a critical risk to monitor.

  13. 13 A risk audit reveals that the risk register has not been updated in sixty days, despite several major project milestones being completed. This finding impacts which specific monitoring parameter?

    Determine if this issue is about the risks themselves or the 'how' and 'when' of the management system.

    The effectiveness of the risk management process.

    A failure to keep the register current is a governance and process failure, indicating the risk management framework is not being applied correctly.

    • The quantitative accuracy of the Beta distribution estimates.

      While the inputs to those estimates might be old, the finding itself is about process compliance, not the mathematical validity of a specific distribution.

    • The individual performance score of the risk owner.

      Risk audits are process-focused and organizational rather than personal performance appraisals for single individuals.

    • The project's risk appetite levels.

      Appetite is an organizational preference for risk-taking; the failure to update a document does not change the organization's inherent appetite.

  14. 14 During the final phase of a project, a risk professional is asked to 'close out expired risks.' Which of the following activities is NOT part of this specific task in Domain 5?

    Distinguish between actions that look forward at new threats and actions that finalize the records of past ones.

    Performing an initial Qualitative Analysis on newly identified threats.

    Closing expired risks is a retrospective/monitoring task, while performing an initial analysis is part of the Risk Identification and Analysis domains (II and III).

    • Releasing unused contingency reserves back to the project budget.

      Releasing funds tied to expired risks is a standard part of the monitoring and closure lifecycle.

    • Updating the risk register status to 'Closed' or 'Expired'.

      Marking risks as closed is the fundamental administrative act of retiring a risk entry.

    • Summarizing risk data for the final lessons learned report.

      Aggregating data from expired risks is essential for documenting the full history of the project's uncertainty management.

  15. 15 Which document is most likely to be updated after a variance analysis in Domain 5 shows that a work package is consistently falling behind its risk-adjusted schedule?

    Identify the primary 'live' document used to track the specific status and attributes of project threats and opportunities.

    The Risk Register.

    The register must be updated to reflect changes in risk status, new triggers, or adjusted probability/impact based on actual performance data.

    • The Project Charter.

      The charter is a high-level authorization document and is rarely updated for operational variances or risk-level shifts.

    • The Risk Management Plan ($RMP$).

      The RMP describes the 'how' of risk management; specific data about a work package is captured in the register, not the methodology plan.

    • The Stakeholder Engagement Plan.

      While stakeholders might need to be informed, the primary repository for the technical risk data itself is the risk register.

  16. 16 A project manager is monitoring residual risks after the implementation of a mitigation strategy. The residual risk is found to exceed the project's risk threshold. What is the most compliant response per Domain 5?

    Focus on the governance requirement for transparency when project boundaries are crossed.

    Report the risk level to key stakeholders and propose additional response actions.

    Monitoring project risk levels requires reporting thresholds violations and initiating further management actions to bring the project back into alignment.

    • Accept the risk level, as it is the 'leftover' portion after a valid mitigation attempt.

      Residual risks cannot be passively accepted if they exceed the established risk thresholds defined in the planning phase.

    • Immediately move the project to the 'Closure' phase to avoid further exposure.

      Prematurely closing a project without finishing the scope is an extreme reaction that should be preceded by attempts to manage the risk.

    • Re-allocate the management reserve to lower the risk score.

      Financial reserves do not change the inherent $P \times I$ score of a risk; they only provide the means to pay for it if it occurs.

  17. 17 During Task 1 of Domain 5, a risk professional performs a 'Trend Analysis' on the project's risk indicators. What is the primary purpose of this activity?

    Think about the benefits of observing the 'direction' and 'momentum' of risk data across the project lifecycle.

    To identify if the overall project risk exposure is improving or deteriorating over time.

    Trend analysis helps practitioners see patterns in risk data, allowing for more proactive adjustments to the risk strategy.

    • To determine the exact Expected Monetary Value ($EMV$) at a single point in time.

      EMV is a 'snapshot' calculation of average outcome, while trend analysis looks at changes across multiple intervals.

    • To categorize the risks within the Risk Breakdown Structure ($RBS$).

      Categorization (Domain III) is the grouping of risks, whereas trend analysis (Domain V) is the tracking of their behavior over time.

    • To identify which stakeholders are most likely to resist the Risk Management Plan.

      Stakeholder resistance is addressed through stakeholder analysis and engagement strategies, not through quantitative risk trend analysis.

  18. 18 While monitoring project risk levels, the practitioner notes that the probability of a high-impact threat has decreased from $0.8$ to $0.2$ because of a change in organizational policy. What action should be taken in Task 4?

    Consider the simplest administrative step required to reflect a change in the severity of a tracked item.

    Update the risk level in the status report and adjust the priority in the risk register.

    Monitoring involves adjusting the focus and priority of risk efforts based on current, validated data.

    • Delete the risk since a probability of $0.2$ is considered insignificant.

      A $20\%$ probability of a high-impact event is still a valid project risk that must be tracked, not deleted.

    • Move the risk to the management reserve list as it is now an 'unknown' factor.

      The risk is still a 'known' uncertainty; management reserves are for items that have not yet been identified.

    • Request a full quantitative analysis using a Monte Carlo simulation to verify the $0.2$ score.

      While simulations are useful, the primary monitoring task is updating the register and reports based on the newfound information.

  19. 19 A risk audit finds that a 'Mitigate' response was implemented for a threat, but the project manager did not track the resulting 'Secondary Risks.' Why is this a failure in Domain 5?

    Think about the total 'ecosystem' of project uncertainty and how responses might disturb it.

    Secondary risks can introduce new threats that negate the benefits of the original mitigation.

    Monitoring must encompass both the intended and unintended consequences of risk responses to ensure project objectives remain protected.

    • Secondary risks are always higher in impact than the original risks.

      Secondary risks can be of any magnitude; they are simply risks that occur because of a previous response implementation.

    • The Risk Management Plan ($RMP$) requires all secondary risks to be transferred to vendors.

      The strategy for a secondary risk is determined individually; there is no universal requirement to transfer them.

    • Secondary risks are actually 'Issues' and must be moved to the issue log immediately.

      Secondary risks are still uncertainties (risks) until they actually happen; if they happen, they become issues.

  20. 20 As part of the 'Monitor and Close Risks' domain, a project manager conducts a final reconciliation of the contingency reserve. If funds remain at project closure, what is the best procedural step?

    Consider the requirement for transparency and accountability during the final financial stages of a project.

    Record the unused reserve as a positive variance and include it in the final report to stakeholders.

    Unused contingency reserves should be reconciled and reported as part of the formal project closure and financial performance evaluation.

    • Incentivize the team with the remaining funds for their excellent risk management performance.

      Contingency reserves are project funds meant for risk mitigation, not for team bonuses or incentives unless explicitly authorized by governance.

    • Transfer the remaining funds to a new project to provide an initial contingency buffer.

      Project budgets are generally specific to a project; transferring funds across projects requires formal organizational approval and accounting.

    • Hide the remaining funds in the budget to provide a 'safety net' for the first year of operations.

      Hiding funds is a violation of project transparency and ethical standards; all reserves should be formally reconciled.

  21. 21 A project manager is performing 'Variance Analysis' on a work package and finds that the $SPI$ is $0.85$. How should this be evaluated through the lens of Domain 5?

    Look for the connection between standard project performance metrics and the materialization of uncertainty.

    The schedule variance may indicate that risks related to technical complexity or resource availability are materializing.

    Performance variances (like a low SPI) are often indicators of underlying risk events or poorly estimated uncertainties.

    • The $SPI$ of $0.85$ proves that the 'Avoid' strategy used earlier in the project was successful.

      An SPI of $0.85$ indicates the project is behind schedule, which suggests the opposite of a completely 'successful' risk-free outcome.

    • The variance means that the project risk level has automatically exceeded the risk appetite.

      Variance is a performance metric; whether it exceeds appetite depends on the specific thresholds defined in the planning phase.

    • The project manager should immediately update the $RACI$ chart to find who is responsible for the $SPI$ drop.

      The RACI chart establishes roles but does not change based on a single performance metric variance during the monitoring phase.

  22. 22 Task 3 of Domain 5 involves 'Providing information required to update relevant project documents.' Which of the following is the most critical document to refresh during this task?

    Think about the document that captures modifications to the project scope, schedule, or cost that may be driven by risk events.

    The Change Log.

    Risk responses often lead to project changes; ensuring these are recorded in the change log maintains consistency between risk and change management.

    • The Project Charter.

      The charter is typically not updated based on the iterative monitoring of project risks.

    • The Business Case.

      The business case is an high-level justification document used for authorization, rather than an operational tracking document for risk monitoring.

    • The Organizational Process Assets ($OPA$).

      While the OPA is eventually updated (at the end), it is not the primary project-specific document refreshed during ongoing risk task monitoring.

  23. 23 A risk audit report highlights that several risk owners were not aware of their responsibilities. Which Domain 5 Task does this finding primarily address?

    Identify the domain task that provides oversight on the health and application of the risk framework.

    Monitor project risk levels.

    Monitoring project risk levels includes auditing the effectiveness of the entire management system, including the communication of roles and responsibilities.

    • Gather and analyze performance data.

      This task focuses on quantitative performance metrics (like variance) rather than the qualitative audit of stakeholder role awareness.

    • Develop risk register.

      Developing the register is an identification task (Domain II) performed earlier in the lifecycle.

    • Plan risk response.

      Planning responses occurs in Domain IV; the finding about owner awareness during the execution phase is a monitoring/audit outcome.

  24. 24 During a project phase-gate review, the practitioner is tasked with 'closing expired risks.' Which of the following is a byproduct of this task?

    Look for the specific administrative record that shows a reduction in the count of active project concerns.

    An update to the risk register that reflects the retirement of non-relevant threats.

    Formally retiring risks ensures the register accurately reflects only the uncertainties that still pose a threat or opportunity to the project.

    • A new hierarchical Risk Breakdown Structure ($RBS$).

      The RBS is created in planning and is generally not 'produced' by the act of closing expired risks.

    • A set of initial probability and impact scores for the next project phase.

      Closing old risks is distinct from the identification and initial scoring of new risks for upcoming project phases.

    • The formal project charter for the operational maintenance phase.

      Risk closure is a project management task; drafting a charter for a separate operational phase is typically a senior management or sponsor duty.

  25. 25 When monitoring 'Residual Risks,' the project team realizes that a threat they 'Mitigated' still has a high enough impact to trigger an 'Avoid' strategy. What is the correct protocol in Domain 5?

    Identify the need for agility in response selection when the current management status is no longer compliant with safety levels.

    The team should reassess the risk and change the response strategy to 'Avoid' if feasible.

    Monitoring requires the flexibility to escalate or change response strategies if the residual risk remains unacceptable.

    • The team must stick to the original 'Mitigate' strategy to maintain the project baseline.

      Baselines should not prevent necessary adjustments to risk strategies when existing ones are proven insufficient.

    • The team should automatically escalate the risk to the project sponsor for acceptance.

      Escalation to a sponsor for 'acceptance' is a last resort and should only occur if the team cannot find a way to manage the risk within their authority.

    • The team should use the 'Transfer' strategy, as residual risk is always the vendor's responsibility.

      The choice of strategy (Avoid, Transfer, Mitigate, etc.) depends on the context and is never automatically assigned to a single type.

  26. 26 A risk professional is using 'Trend Analysis' to compare $EMV$ results over the last four reporting periods. If the $EMV$ is trending downwards (becoming less negative), what does this most likely signify?

    Focus on the mathematical meaning of the Expected Monetary Value when viewed as a time-series dataset.

    The total expected financial impact of the project's threats is decreasing.

    A less negative EMV indicates that the aggregate probability and impact of project threats are being successfully managed or retired.

    • The project is guaranteed to finish under budget.

      EMV is a statistical average based on probability; it does not guarantee a specific budget outcome, as it only accounts for 'known unknowns'.

    • The project team has stopped identifying new risks to keep the scores looking positive.

      While this is a possible 'bad behavior,' it is not the primary or expected meaning of a downward EMV trend in a healthy project.

    • The organization's risk appetite has increased significantly.

      The EMV trend reflects the project's data, not the organization's strategic preferences for risk-taking.

  27. 27 In Task 4 of Domain 5, what is the role of 'Risk Reassessments' compared to 'Risk Audits'?

    Differentiate between evaluating the 'things' we are managing and the 'way' we are managing them.

    Reassessments focus on the project's individual risks, while audits focus on the management process.

    Reassessments look at the status and attributes of threats/opportunities; audits look at the compliance and quality of the risk framework.

    • Reassessments are performed by external vendors, while audits are performed internally.

      Both reassessments and audits can be internal or external, depending on organizational policy and project complexity.

    • Reassessments are only for 'Opportunities', while audits are only for 'Threats'.

      Both techniques are applied broadly across the entire spectrum of project uncertainties, including both positive and negative risks.

    • Reassessments occur during planning, while audits occur during monitoring.

      Both are monitoring and control activities; reassessments are done regularly to keep the register current.

  28. 28 A project manager is analyzing a 'Risk Dot Plot' as part of the monitor phase. Which risk attribute is most likely to determine the 'urgency' of a response action in this context?

    Consider the temporal dimension of a risk and how it impacts the team's prioritization during status reviews.

    Risk proximity.

    Proximity refers to how soon a risk might occur; high-proximity risks require more urgent monitoring and response actions.

    • Risk origin.

      Whether a risk is internal or external (origin) does not necessarily dictate how urgently it must be addressed.

    • Risk owner's experience level.

      While the owner's skill matters, urgency is an attribute of the risk event itself, specifically when it is expected to happen.

    • The number of enablers identified in the $ECO$.

      Enablers are descriptive components of professional practice, not attributes of a specific project threat.

  29. 29 During the monitoring of a hybrid project, the team notes that a risk trigger was missed because it was not integrated into the Kanban board. What should be done to 'Update relevant project documents' (Task 3)?

    Focus on the need for consistency across different tracking artifacts in a multi-framework environment.

    Refresh the risk register and update the visual monitoring tools to include current risk triggers.

    Monitoring in hybrid/agile projects requires synchronizing formal registers with day-to-day visual tracking boards.

    • Replace the Kanban board with a traditional Waterfall Risk Management Plan.

      The failure of a single trigger does not invalidate the entire project delivery methodology.

    • Perform a sensitivity analysis using a Tornado diagram for the Kanban throughput.

      Tornado diagrams are for modeling cost/schedule sensitivities, not for tactical trigger integration on a visual board.

    • Inform the stakeholders that visual boards are not suitable for high-risk projects.

      Visual boards are highly effective for risk tracking if used correctly; the problem is the missing data, not the tool itself.

  30. 30 Which of the following best represents the completion of Domain 5: 'Monitor and Close Risks' for a specific project phase?

    Look for the ultimate goal of preserving 'institutional memory' related to uncertainty and its management.

    Archiving the risk repository and capturing lessons learned for the organization's knowledge base.

    Successful closure involves ensuring that all risk-related data and experience are preserved for future use within the enterprise.

    • Drafting the initial Probability and Impact ($P-I$) matrix for the next project.

      Creating matrices for future, unrelated projects is a separate planning activity and not part of the current project's monitoring and closure.

    • Spending the remaining management reserve on high-end project closure celebration.

      Management reserves are for risk management; using them for celebrations is a misuse of organizational funds.

    • Sending a survey to the vendors to evaluate their risk management competency.

      While useful, vendor appraisal is part of procurement closure, not the core activity of closing out project risk monitoring.