PMI-RMP Risk Appetite and Tolerance 1 — Questions and Answers
Question 1: How is risk appetite best defined in the PMI-RMP framework?
- The amount of risk an organization is willing to pursue to achieve objectives (Correct answer)
- The total budget allocated for risk contingency
- The number of risks identified in the risk register
- The probability that all risks will occur
Correct answer: The amount of risk an organization is willing to pursue to achieve objectives
Risk appetite is the degree of uncertainty an organization is willing to accept in pursuit of its strategic goals.
Question 2: Risk tolerance differs from risk appetite in that risk tolerance refers to:
- Long-term strategic risk preferences
- The acceptable variation around a specific objective or threshold (Correct answer)
- The risk identified in the risk register
- The risk owner's personal opinion
Correct answer: The acceptable variation around a specific objective or threshold
Risk tolerance is the measurable boundary of acceptable deviation from a specific objective, making it more tactical than appetite.
Question 3: Who is primarily responsible for defining an organization's risk appetite?
- Individual project managers
- Senior leadership and the board of directors (Correct answer)
- The project team
- External auditors
Correct answer: Senior leadership and the board of directors
Risk appetite is a strategic governance decision set by senior leadership and the board, reflecting the organization's overall values and objectives.
Question 4: A project sponsor states the project can tolerate a cost overrun of up to 10% but no more. This is an example of:
- Risk appetite
- Risk threshold (Correct answer)
- Risk transfer
- Risk avoidance
Correct answer: Risk threshold
A specific, measurable boundary (10% cost overrun) represents a risk threshold, which operationalizes risk tolerance for a particular objective.
Question 5: When a risk exceeds the defined risk threshold, what action should the project manager take?
- Ignore it until the next reporting period
- Escalate to the appropriate authority per the risk management plan (Correct answer)
- Immediately close the project
- Delete the risk from the register
Correct answer: Escalate to the appropriate authority per the risk management plan
Threshold breaches trigger escalation to ensure that risks beyond the project team's authority receive appropriate senior-level attention.
Question 6: How does a risk-averse organization's behavior differ from a risk-seeking organization?
- A risk-averse organization pursues high-uncertainty projects for maximum gain
- A risk-averse organization prefers lower uncertainty even at the cost of potential gains (Correct answer)
- Both behave identically
- A risk-averse organization ignores risk management
Correct answer: A risk-averse organization prefers lower uncertainty even at the cost of potential gains
Risk-averse organizations are more comfortable accepting lower returns in exchange for greater certainty and reduced exposure.
How is risk appetite best defined in the PMI-RMP framework?