Project Risk Management Risk Identification Techniques 5 — Questions and Answers
Question 1: A project team realizes that a key vendor's financial instability is a risk they nearly overlooked. Which risk identification approach would BEST help capture external supply chain risks systematically?
- Internal brainstorming only
- Environmental scanning and external stakeholder interviews (Correct answer)
- Reviewing only the project scope statement
- Analyzing the team's communication plan
Correct answer: Environmental scanning and external stakeholder interviews
Environmental scanning and interviews with external stakeholders (e.g., vendors, regulators) surface risks outside the project team's direct view.
Question 2: What is the PRIMARY output of the Identify Risks process according to the PMBOK Guide?
- Risk management plan
- Risk register (Correct answer)
- Risk report
- Issue log
Correct answer: Risk register
The risk register is the primary output of the Identify Risks process, documenting identified risks, potential risk owners, and preliminary responses.
Question 3: A project manager for a software project asks each team member to independently write risk ideas before sharing them with the group, then facilitates a structured discussion. This describes the:
- Delphi technique
- Nominal group technique (Correct answer)
- Affinity diagram technique
- Crawford slip method
Correct answer: Nominal group technique
The nominal group technique uses silent individual idea generation followed by structured group discussion, balancing independence and collaboration to improve risk coverage.
Question 4: Why is it important to identify BOTH threats and opportunities during the risk identification process?
- Opportunities offset threats and eliminate the need for contingency reserves
- Risk management covers all uncertain events, and opportunities can be exploited to benefit the project (Correct answer)
- Regulatory bodies require equal numbers of threats and opportunities in the risk register
- Identifying opportunities is mandatory only for government projects
Correct answer: Risk management covers all uncertain events, and opportunities can be exploited to benefit the project
Modern risk management recognizes that uncertainty can have positive outcomes (opportunities) as well as negative ones (threats), and both deserve proactive management.
Question 5: A risk identified as 'unclear regulatory requirements may change scope' is best categorized under which Risk Breakdown Structure (RBS) category?
- Technical risks
- External risks (Correct answer)
- Organizational risks
- Project management risks
Correct answer: External risks
Regulatory and legal risks originate outside the project organization and are classified under external risks in a standard RBS.
Question 6: Which of the following represents a risk that would MOST likely be identified through assumption analysis but MISSED by a standard checklist?
- Weather delays on an outdoor construction project
- A key technology vendor remaining solvent through project completion (Correct answer)
- Budget overruns due to scope creep
- Schedule slippage from resource unavailability
Correct answer: A key technology vendor remaining solvent through project completion
Assumption analysis uncovers risks tied to project-specific assumptions (like vendor solvency) that are unique to the current context and absent from generic checklists.
Question 7: During risk identification, a project team discovers a risk and immediately begins debating mitigation strategies. The project manager should:
- Encourage the discussion since mitigation and identification should happen simultaneously
- Redirect the team to complete identification first, then address responses in risk analysis and planning (Correct answer)
- Cancel the risk identification session and move to risk response planning
- Ask only senior members to discuss mitigation while others continue identifying
Correct answer: Redirect the team to complete identification first, then address responses in risk analysis and planning
Jumping to responses during identification derails the process; risks should be fully captured before moving to qualitative/quantitative analysis and response planning.
A project team realizes that a key vendor's financial instability is a risk they nearly overlooked.
Which risk identification approach would BEST help capture external supply chain risks systematically?