Risk Response Planning: How to Plan Risk Responses in Projects

Where Does Plan Risk Responses Fit in the Risk Process?
Table of Contents

Risk Response Planning: How to Plan Risk Responses in Projects

Risk response planning decides what the team does about each prioritized risk before it happens. In the PMBOK Guide Sixth Edition the process is called Plan Risk Responses. It turns a ranked risk register into owned, funded, scheduled actions.

This guide walks through the process: where it fits, its inputs, techniques, and outputs, a step-by-step method, a response plan template, and the exam angle.

What Is Risk Response Planning in Projects?

Risk response planning is the process of developing response options, selecting a strategy for each prioritized risk, and agreeing on actions, owners, and funding. The PMBOK Guide names it Plan Risk Responses. Its output is a set of planned responses in the project documents.

A risk response plan is not a single document. It is the sum of the response entries in the risk register, the risk report, and the updated management plans and baselines. The process runs throughout the project, not once. Each new risk and each change in exposure reopens it.

The key benefit is action with resources behind it. A risk with a rating and no response is a known problem with no plan.

Where Does Plan Risk Responses Fit in the Risk Process?

How Do You Plan Risk Responses Step by Step?

Plan Risk Responses is the fifth of 7 risk processes in the PMBOK Guide Sixth Edition. It follows qualitative and quantitative analysis. Implement Risk Responses executes its plans, and Monitor Risks tracks the results. It belongs to the planning process group.

# Process Process group Role
11.1 Plan Risk Management Planning Sets approach, thresholds, and roles
11.2 Identify Risks Planning Creates the register and the report
11.3 Perform Qualitative Risk Analysis Planning Rates probability and impact
11.4 Perform Quantitative Risk Analysis Planning Prices risk numerically
11.5 Plan Risk Responses Planning Chooses strategies and actions
11.6 Implement Risk Responses Executing Carries out the planned responses
11.7 Monitor Risks Monitoring and controlling Tracks risks and response results

Planning decides. Implementing acts. A team that plans well and never implements has documents and no protection.

What Are the Inputs to Plan Risk Responses?

The inputs are the risk management plan, the cost baseline, the resource management plan, and project documents such as the risk register, risk report, schedule, stakeholder register, and lessons learned register. The register supplies the prioritized risks that need responses.

Input group Items What the process takes from it
Project management plan Risk management plan, resource management plan, cost baseline Thresholds, roles, authority levels, reserve limits
Project documents Risk register, risk report, project schedule, team assignments, resource calendars, stakeholder register, lessons learned register Prioritized risks, available people, earlier response results
Enterprise environmental factors Risk appetite and tolerance, regulations, market conditions Limits on which responses are acceptable
Organizational process assets Response templates, past risk data, escalation procedures Proven responses and required formats

The risk management plan matters most. Its authority levels decide which responses the project manager approves and which go to the sponsor.

What Tools and Techniques Does the Process Use?

The process uses expert judgment, interviews, facilitation, and decision-making techniques, plus specific tools: strategies for threats, strategies for opportunities, contingent response strategies, strategies for overall project risk, and data analysis such as alternatives analysis and cost-benefit analysis.

Technique Use
Expert judgment Advice on feasible responses from people with technical or past-project experience
Interviews One-to-one sessions with risk owners and specialists
Facilitation Workshops that generate and compare response options
Multicriteria decision analysis Scoring options against agreed criteria
Strategies for threats Escalate, avoid, transfer, mitigate, accept
Strategies for opportunities Escalate, exploit, share, enhance, accept
Contingent response strategies Responses that run only when a trigger fires
Strategies for overall project risk Responses aimed at the project’s total exposure
Alternatives analysis Compares candidate responses
Cost-benefit analysis Tests whether a response earns its cost

The cost-benefit test uses expected monetary value. PMTI’s guide What is Expected Monetary Value in Project Management? explains the calculation. Example: a 30% risk with a $60,000 impact has an EMV of $18,000. A $7,000 response cuts the probability to 10%, so EMV falls to $6,000. The reduction is $12,000. Divide the reduction by the cost: $12,000 ÷ $7,000 is 1.7, and the net benefit is $5,000. Fund the response.

Score each option against 6 criteria: effectiveness, cost, feasibility, time to implement, secondary risks created, and stakeholder acceptance.

What Are the Outputs of Plan Risk Responses?

The outputs are change requests, updates to the project management plan and its baselines, and updates to project documents: the risk register, risk report, assumption log, cost forecasts, project schedule, team assignments, and lessons learned register.

Output group Items
Change requests Requests to alter baselines or plans to fit the responses
Project management plan updates Schedule, cost, quality, resource, and procurement management plans; scope, schedule, and cost baselines
Project documents updates Assumption log, cost forecasts, lessons learned register, project schedule, project team assignments, risk register, risk report

PMTI’s guide What is a Risk Register in Project Management? covers the register layout. After this process the register also holds each risk’s agreed strategy, actions, triggers, contingency and fallback plans, owners, and residual and secondary risks. The risk report gains the agreed responses and owners for the high-priority risks.

How Do You Plan Risk Responses Step by Step?

How Do You Plan Risk Responses Step by Step?

Plan responses in 8 steps: rank the risks, convene owners and experts, generate options, evaluate them, select a strategy, define actions with owners and triggers, fund and schedule the actions, and obtain approval. Then record the residual and secondary risks.

  1. Rank the risks from the register by score, and start with those above the threshold.
  2. Convene each risk owner with the experts who know the risk.
  3. Generate 2 or 3 response options per risk, for threats and opportunities alike.
  4. Evaluate the options with cost-benefit analysis and the 6 criteria.
  5. Select 1 strategy per risk, and note any second strategy for the fallback.
  6. Define the actions, and give each an owner, a due date, and a trigger when the response is contingent.
  7. Price and schedule the actions, and add them to the cost and schedule baselines or to the reserve plan.
  8. Obtain approval at the required authority level, and record the decision in the register.

After step 8, list the residual risk that remains and the secondary risk that the response creates. A response that creates a bigger risk than it removes fails the evaluation.

Not every risk needs a costly response. Low-priority risks go on a watch list with passive acceptance.

What Goes Into a Risk Response Plan?

A risk response plan entry holds the risk, the strategy, the actions, the owner, the trigger, the cost and schedule impact, the contingency and fallback plans, and the residual and secondary risks. One entry exists for each risk that receives a response.

Example entry:

Field Entry
Risk R7 Key supplier delivers late
Score Probability 40%, impact $50,000, EMV $20,000
Response type Proactive, with a contingent backup
Strategy Mitigate
Actions Qualify a second supplier by week 6
Owner Procurement lead
Cost and schedule $8,000; 2 weeks of procurement effort
Trigger Supplier misses a milestone by 5 days
Contingency plan Order from the second supplier
Fallback plan Rent equivalent components at spot price
Residual risk Second supplier’s quality is unproven
Secondary risk Qualification effort delays the test schedule
Approver Project manager, within authority

Every figure in the example is illustrative. Replace it with project data.

How Do You Fund and Schedule the Responses?

Proactive responses become activities in the schedule and the cost baseline. Contingent responses sit in the plan as conditional activities and draw on the contingency reserve when the trigger fires. Unidentified risks draw on the management reserve with approval.

Response type Where it lives Funded from
Proactive (runs now) Work breakdown structure, schedule, cost baseline Cost baseline
Contingent (runs on a trigger) Conditional activities, marked so the team does not run them early Contingency reserve
Response to an unidentified risk Issue log and change request Management reserve, with approval

Any response that changes a baseline needs a change request. Route it through change control before the team commits the money.

Who Plans and Approves the Responses?

The risk owner proposes the response, and the project manager facilitates the planning. Experts and the team supply options. The project manager approves responses within their authority. The sponsor approves those above it, and the change control board approves baseline changes.

Role Duty
Risk owner Proposes the response, then carries it out
Project manager Facilitates, integrates the responses, and approves within authority
Team and experts Generate and test options
Sponsor Approves responses above the project manager’s authority and funds the management reserve
Change control board Approves changes to baselines

The risk management plan sets the authority levels. Read them before planning, because they decide who signs.

Which of These Is Not a Risk Response?

Ignoring a risk is not a response. The 8 recognized strategies are escalate, avoid, transfer, mitigate, accept, exploit, share, and enhance. A strategy used on the wrong risk type is also wrong: exploit, share, and enhance do not answer threats.

Item A valid response? Why
Ignore or deny the risk No No decision, no owner, no plan
Avoid, transfer, mitigate Yes, for threats only Threat strategies
Exploit, share, enhance Yes, for opportunities only Opportunity strategies
Escalate Yes, for both Hands the risk to a higher authority
Accept Yes, for both A recorded decision, passive or active
Monitoring and reporting No Support activity, not a strategy
Contingency plan Yes, as part of a strategy The prepared action under active acceptance or a contingent response

Exam-style example: “Which is not a strategy for a negative risk: avoid, transfer, enhance, or accept?” The answer is enhance.

How Does Risk Response Planning Work in Agile and Hybrid Projects?

Agile and hybrid teams plan responses on a shorter cycle. Risks and response actions enter the backlog, the team plans them in sprint planning, and the product owner approves trade-offs. Contingent responses become reserved capacity.

  • Add response actions to the backlog as items with owners.
  • Plan the top risk responses at each sprint and release planning session.
  • Reserve sprint capacity or a release buffer for contingent responses.
  • Review response results at each retrospective, and re-plan the ones that failed.

Approximately 60% of the July 2026 PMP exam targets agile or hybrid approaches, so exam scenarios use both vocabularies.

How Is Plan Risk Responses Tested on the PMP Exam?

PMP questions test the position of the process, its outputs, and the difference between planning and implementing. Plan Risk Responses follows quantitative analysis, belongs to the planning group, and produces change requests and document updates. Implement Risk Responses carries the plans out.

Scenario cue Answer
The next risk process after quantitative analysis Plan Risk Responses
The team chooses a strategy and assigns an owner Plan Risk Responses
The team runs an agreed response Implement Risk Responses
A response changes the cost baseline Change request from Plan Risk Responses
The team funds known risks Contingency reserve
A threat exceeds the project manager’s authority Escalate
The response creates a new risk Secondary risk, recorded in the register

Read whether the question asks who decides or who acts. Deciding is planning. Acting is implementing.

PMTI’s Project Risk Management Course (24 PDUs) covers project risk management in depth for middle and upper management. Max Wideman, a PMI Fellow who led the first PMBOK Guide effort, designed the course and delivers it online.

 

Picture of Yad Senapathy

Yad Senapathy

Founder & CEO of PMTI with 20+ years in project management. He has contributed to the PMBOK® Guide & developed multiple certification programs including PMP and CAPM.
Yad Senapathy
Yad Senapathy

Your project managers will be trained on the PMI PMBOK Guide's best practices and ethics. They'll understand the framework of a successful project from initiating to close.

Share this article
Twitter
Facebook
Linkedln
whatsapp
telegram
pinterest
Get in Touch With Us