Change Management Risk Assessment & Management 4 — Questions and Answers
Question 1: Which ITIL concept defines the acceptable risk level for approving a change without escalation?
- Service level agreement
- Change authorization threshold (Correct answer)
- Risk tolerance band
- Operational baseline
Correct answer: Change authorization threshold
A change authorization threshold specifies the risk level at which a change can be approved at a given authority level without escalation.
Question 2: A post-implementation review reveals a risk that was never identified before the change went live. What process improvement does this finding most directly support?
- Enhancing the risk identification techniques used in planning (Correct answer)
- Increasing the change budget for contingency reserves
- Reducing the number of stakeholders in the approval process
- Shortening the change implementation window
Correct answer: Enhancing the risk identification techniques used in planning
An unidentified risk surfacing post-implementation indicates a gap in the risk identification process, calling for improved techniques such as broader stakeholder input or checklists.
Question 3: What is the role of a 'risk owner' in a change initiative?
- To fund all risk response activities from their departmental budget
- To monitor the risk and ensure the agreed response is executed (Correct answer)
- To veto any change that exceeds acceptable risk thresholds
- To document risks in the register on behalf of the project manager
Correct answer: To monitor the risk and ensure the agreed response is executed
The risk owner is accountable for monitoring the specific risk and ensuring the defined response plan is carried out effectively.
Question 4: During a risk assessment for a cloud migration, the team identifies data sovereignty laws as a concern. Which risk category best describes this?
- Operational risk
- Compliance and regulatory risk (Correct answer)
- Financial risk
- Reputational risk
Correct answer: Compliance and regulatory risk
Data sovereignty laws are legal and regulatory requirements, placing this risk firmly in the compliance and regulatory category.
Question 5: A change manager wants to quantify the combined effect of multiple risks on the project schedule. Which technique is most appropriate?
- Qualitative risk matrix
- Monte Carlo simulation (Correct answer)
- PESTLE analysis
- Delphi technique
Correct answer: Monte Carlo simulation
Monte Carlo simulation runs thousands of scenarios combining multiple risk variables to produce a probability distribution of schedule outcomes.
Question 6: Which statement best describes the 'risk tolerance' of an organization as it relates to change management decisions?
- The maximum financial loss the organization can absorb before insolvency
- The degree of variability in outcomes the organization is willing to accept (Correct answer)
- The number of simultaneous changes the organization can manage
- The time limit for implementing any given change
Correct answer: The degree of variability in outcomes the organization is willing to accept
Risk tolerance defines how much variation from expected outcomes an organization can accept, guiding how aggressively changes are pursued.
Question 7: A critical dependency between two concurrent changes is discovered during risk assessment. What is the best response?
- Proceed independently, as parallel changes are standard practice
- Coordinate the changes and assess the combined risk of the dependency (Correct answer)
- Cancel both changes until the dependency is resolved
- Transfer the risk to the vendor managing one of the changes
Correct answer: Coordinate the changes and assess the combined risk of the dependency
Dependency between concurrent changes creates compounded risk that must be assessed holistically and coordinated to prevent cascading failures.
Which ITIL concept defines the acceptable risk level for approving a change without escalation?