PMI-RMP - PMI Risk Management Professional The Risk Register Questions and Answers 1 — Questions and Answers
Question 1: A project manager is facilitating a risk identification workshop. The team identifies a potential risk, its cause, and its potential impact on the project schedule. According to the PMBOK® Guide, what is the most appropriate next step for the project manager regarding this newly identified risk?
- Develop a comprehensive risk response plan immediately.
- Perform a quantitative analysis to determine the exact financial impact.
- Add the risk, along with its characteristics, to the risk register. (Correct answer)
- Escalate the risk to the project sponsor for awareness and direction.
Correct answer: Add the risk, along with its characteristics, to the risk register.
The risk register is the primary output of the Identify Risks process and serves as a central repository for all identified risks. The immediate first step after identifying a risk is to document it in the risk register. Subsequent processes like analysis (Qualitative and Quantitative), response planning, and escalation will follow after the risk has been formally logged.
Question 2: During the Plan Risk Responses process, the project team decides to purchase insurance for a critical piece of equipment to protect against potential failure. This response, however, introduces a new risk related to the insurance provider's potential insolvency. In the context of the risk register, this new risk is BEST described as a:
- Residual risk
- Secondary risk (Correct answer)
- Contingency risk
- Transferred risk
Correct answer: Secondary risk
A secondary risk is a new risk that arises as a direct result of implementing a risk response. In this scenario, the response was to transfer the risk via insurance, and the secondary risk is the potential failure of the insurance provider. This new risk must be added to the risk register and managed accordingly.
Question 3: A project manager is preparing a high-level presentation for the steering committee. The presentation needs to provide a snapshot of the overall project risk exposure and a summary of the top five threats and opportunities. Which of the following is true regarding the documents used?
- The risk register and risk report are identical documents used for this purpose.
- The risk register is a detailed log of all risks, while the risk report summarizes this information for stakeholder communication. (Correct answer)
- The risk report is the primary input for creating the detailed risk register.
- The risk register is used for opportunities, while the risk report is used exclusively for threats.
Correct answer: The risk register is a detailed log of all risks, while the risk report summarizes this information for stakeholder communication.
The risk register is a comprehensive document that lists and tracks all identified individual risks and their details. The risk report, on the other hand, is a summary-level document that provides an overview of overall project risk and key individual risks, tailored for communication with stakeholders like a steering committee. The risk report is derived from the detailed information in the risk register.
Question 4: While reviewing the risk register for a software development project, a stakeholder points to an entry that describes a specific, observable event: 'The lead developer gives two weeks' notice.' This event, if it occurs, will activate the response plan for the risk 'Loss of key personnel.' What is this event formally known as in the risk register?
- A risk impact
- A risk source
- A risk trigger (Correct answer)
- A residual risk
Correct answer: A risk trigger
A risk trigger, also known as a warning sign, is a specific event or condition that indicates a risk is about to occur or has already occurred. These triggers are documented in the risk register to facilitate proactive risk monitoring and prompt implementation of response plans.
Question 5: Which of the following elements is typically added to the risk register as an output of the Perform Qualitative Risk Analysis process?
- Secondary risks and fallback plans
- Probabilistic analysis of project objectives (e.g., Monte Carlo analysis)
- A list of identified risks and their potential causes
- Risk probability, impact, score, and priority (Correct answer)
Correct answer: Risk probability, impact, score, and priority
The Perform Qualitative Risk Analysis process assesses the probability of occurrence and potential impact of identified risks. The outputs of this process, which are used to update the risk register, include the assessed probability and impact values, a calculated risk score or rating, and the resulting priority of the risk.
Question 6: A project is in its execution phase when an unexpected problem occurs for which no risk was identified in the risk register. The project team quickly implements a solution. How should this event and its solution be documented for risk management purposes?
- The event should be added to the risk register as a closed risk.
- A change request should be submitted to update the risk management plan.
- The solution implemented is a workaround and should be documented in the risk register or lessons learned.
- The event should be logged in the issue log, not the risk register, as it has already occurred. (Correct answer)
Correct answer: The event should be logged in the issue log, not the risk register, as it has already occurred.
A key distinction in project management is between a risk (an uncertain future event) and an issue (a current problem or event that has already occurred). Since the problem has already happened, it is an issue and should be recorded in the issue log. The risk register is forward-looking and tracks potential future events. The reactive solution is a workaround, and documenting it is important for knowledge management.
A project manager is facilitating a risk identification workshop.
The team identifies a potential risk, its cause, and its potential impact on the project schedule.
According to the PMBOK® Guide, what is the most appropriate next step for the project manager regarding this newly identified risk?