This guide defines each type, shows how to identify and record them, and explains how each is analyzed, answered, and tested on the PMP exam.
What Is the Difference Between Event Risk and Non-Event Risk?
Event risk is a discrete future event that either occurs or does not. Non-event risk is uncertainty in the plan itself: variability when the range is known but the outcome is not, ambiguity when knowledge is missing. Events are rated. Non-events are modeled or investigated.
| Attribute | Event risk | Variability risk | Ambiguity risk |
| Nature | A specific event | Uncertain value inside a known range | Lack of knowledge or understanding |
| Core question | Will it happen? | Where within the range will the result land? | What do we not know yet? |
| Example | A key supplier goes bankrupt | Team productivity runs 80% to 120% of plan | The integration approach for a legacy system is not understood |
| Typical analysis | Probability and impact, EMV | Simulation, three-point estimates | Knowledge-gap analysis |
| Typical response | Avoid, transfer, mitigate, accept | Reduce the spread, hold reserve by confidence level | Fill the gap: expert input, prototype, incremental delivery |
| Recorded as | “If X occurs, then Y” | “Uncertainty in the range of X” | “Uncertainty about X” |
What Is an Event Risk?
An event risk is a specific, uncertain future event that has not yet happened. If it occurs, it affects one or more project objectives, and it becomes a risk event. The team then handles it as an issue.
Three terms need care. A risk is the uncertainty. A risk event is the occurrence of that uncertainty. An issue is the current condition the occurrence creates.
Examples: a supplier files for bankruptcy, a key engineer resigns, a regulator issues a new rule, a storm closes the site. Each one is discrete. It happens or it does not.
Event risks fit the standard tools. The team writes a risk statement, rates probability and impact, chooses a strategy, sets a trigger, and assigns an owner. PMTI’s guide What is Expected Monetary Value in Project Management? shows how to price an event risk: probability times impact.
What Is a Non-Event Risk?
A non-event risk is uncertainty that is not a discrete event. It comes from the characteristics of the plan or from gaps in knowledge. The PMBOK Guide Sixth Edition names 2 types: variability risk and ambiguity risk.
Non-event risks are subtler than event risks because nothing dramatic triggers them. An estimate that is too narrow, a requirement that nobody has clarified, and a technology that nobody has tested are all non-event risks.
PMI has not added event risk, non-event risk, variability risk, or ambiguity risk to its online lexicon. The terms come from the PMBOK Guide’s risk chapter. Expect the wording to evolve.
What Is Variability Risk?
Variability risk is uncertainty about a key characteristic of a planned event, activity, or decision. The possible range is known, and the exact outcome is not. Examples include productivity, defect counts, weather delays, and exchange rates. Simulation models the range.
Statisticians call this aleatoric uncertainty, after the Latin for a game of dice: the outcomes are known, and the roll is not.
| Source | Known range | Uncertain outcome |
| Task cost | $40,000 to $80,000 | Where the actual cost lands |
| Team productivity | 80% to 120% of plan | Sprint-to-sprint output |
| Defects in testing | 5 to 25 per release | How many appear |
| Exchange rate | Normal band for the year | The rate on the purchase date |
Example: a work package has an optimistic cost of $40,000, a most likely cost of $50,000, and a pessimistic cost of $80,000. The triangular estimate is $56,667. The beta estimate is $53,333. The beta standard deviation is $6,667. A Monte Carlo run over many such items returns confidence levels for total cost.
Respond in 2 ways. Reduce the spread with standardization, process improvement, and better data. Fund the remaining spread with a reserve sized at a confidence level the sponsor accepts.
What Is Ambiguity Risk?
Ambiguity risk is uncertainty about the future that comes from lack of knowledge or understanding. Examples include unclear requirements, an unproven technical solution, future regulation, and systemic complexity. The response is to find out: close the knowledge gap.
Statisticians call this epistemic uncertainty. No probability distribution exists, because the outcomes themselves are unknown.
Close the gap with 5 techniques:
- Consult experts who know the area.
- Benchmark against similar projects and their lessons learned.
- Build a prototype or proof of concept.
- Deliver in increments, and learn from each release.
- Record the unknown in the assumption log with a date to resolve it.
Ambiguity shrinks as knowledge grows. A team that sets a date to answer each unknown watches the risk fall.
What Is Emergent Risk, and How Does Project Resilience Address It?
Emergent risk appears only after the project starts. The team cannot name it in advance. The PMBOK Guide answers it with project resilience: right contingency, flexible processes, an empowered team, frequent review of warning signs, and clear stakeholder input on scope.
Resilience is capacity, not a list of risks. It is the ability to absorb a surprise and adjust.
| Resilience feature | What it provides |
| Right level of contingency | Money and time to absorb the unexpected |
| Flexible processes | Room to change the plan without a rebuild |
| Empowered team | Fast decisions close to the work |
| Frequent review of early warning signs | Early detection of a new pattern |
| Clear stakeholder input on scope | Quick agreement on trade-offs |
How Do You Identify Non-Event Risks?
Identify non-event risks with questions, not event lists. Ask which estimates are single points, which requirements are unclear, which technology is unproven, and which assumptions lack evidence. Use the assumption log, estimate ranges, requirements reviews, and prompt lists.
| Prompt | Non-event type | Example register entry |
| Which estimates rest on a single number? | Variability | Uncertainty in the range of integration effort |
| How far can productivity swing? | Variability | Uncertainty in sprint output |
| Which requirements have no acceptance criteria? | Ambiguity | Uncertainty about reporting requirements |
| Which technology has no track record here? | Ambiguity | Uncertainty about platform scalability |
| Which assumptions lack evidence? | Ambiguity | Uncertainty about the vendor’s delivery capacity |
| Which regulations are still in draft? | Ambiguity | Uncertainty about pending privacy rules |
VUCA stands for volatility, uncertainty, complexity, and ambiguity. Each prompt list suggests sources of overall project risk that the team can turn into questions.
How Do You Analyze and Respond to Each Type?
Analyze event risks with probability and impact. Model variability risks with simulation and three-point estimates. Investigate ambiguity risks by defining the knowledge gap and its resolution date. Respond to each type with the tool that fits its nature.
| Type | Analysis | Response | Reserve link |
| Event | Probability and impact matrix, EMV | Avoid, transfer, mitigate, accept, or the opportunity strategies | Contingency reserve from summed EMVs |
| Variability | Three-point estimates, sensitivity analysis, Monte Carlo | Reduce spread, then reserve at a confidence level | Contingency reserve from the confidence-level gap |
| Ambiguity | Knowledge-gap analysis, assumption review | Expert input, prototype, incremental delivery | Time and money for the investigation |
| Emergent | Early-warning review | Resilience, flexible plans | Management reserve for unidentified risks |
The 8 response strategies from the PMBOK Guide apply to event risks. Variability and ambiguity risks need the tools in the table, which the strategy list does not cover.
How Do You Record Non-Event Risks in the Risk Register?
Record each non-event risk as a statement of uncertainty, with a type, a range or a knowledge gap, an owner, and a response. Add a type column to the register with 3 values: event, variability, and ambiguity.
PMTI’s guide What is a Risk Register in Project Management? covers the register layout. Example rows:
| ID | Type | Statement | Measure | Owner | Response |
| R7 | Event | Key supplier delivers late | Probability 40%, impact $50,000 | Procurement lead | Mitigate: qualify a second supplier |
| V3 | Variability | Uncertainty in integration effort | Range 400 to 900 hours | Tech lead | Three-point estimate, reserve at the 80% level |
| A2 | Ambiguity | Uncertainty about the legacy billing interface | Knowledge gap, resolve by week 6 | Architect | Prototype the interface, then re-estimate |
Every figure in the rows is an example. An event row carries probability and impact. A variability row carries a range. An ambiguity row carries a date to close the gap.
How Do Event and Non-Event Risks Combine Into Overall Project Risk?
Overall project risk is the effect of all uncertainty on the project as a whole. It includes individual event risks and non-event uncertainty. A simulation combines them: event risks as probability-weighted jumps, variability as distributions, and ambiguity as widened ranges.
The individual risk list cannot answer the sponsor’s question, “How risky is the project?” The overall view can. A Monte Carlo model that includes only event risks understates exposure, because it ignores estimate spread. The risk report carries the overall result to the sponsor.
How Do Event and Non-Event Risks Work in Agile and Hybrid Projects?
Agile and hybrid teams handle ambiguity through short iterations, spikes, and backlog refinement. They handle variability with velocity ranges and event risks on a risk board. Each iteration converts unknowns into working results, so learning replaces guessing.
- Run a spike, a short time-boxed investigation, to close an ambiguity risk.
- Forecast with a velocity range, not a single number, to show variability.
- Refine the backlog often, so unclear items are clarified before commitment.
- Keep a risk board for discrete event risks.
Approximately 60% of the July 2026 PMP exam targets agile or hybrid approaches, so exam scenarios use both vocabularies.
How Are Event and Non-Event Risks Tested on the PMP Exam?
PMP questions test the type from the wording. A specific occurrence points to an event risk. A known range with an unknown result points to variability risk. Missing knowledge points to ambiguity risk. Expect the matching response: strategy, simulation, or investigation.
| Scenario cue | Answer |
| A supplier is at risk of bankruptcy | Event risk |
| Productivity varies above and below the estimate | Variability risk |
| The team lacks knowledge of a regulation still in draft | Ambiguity risk |
| The best way to model a range of outcomes | Monte Carlo simulation |
| The best way to reduce ambiguity | Expert input, prototype, or incremental delivery |
| A risk that appears only after the project begins | Emergent risk, handled by resilience |
| When the event occurs | Risk event, then an issue |
Ask whether the uncertainty is an event, a range, or a gap.
PMTI’s Project Risk Management Course (24 PDUs) covers project risk management in depth for middle and upper management. Max Wideman, a PMI Fellow who led the first PMBOK Guide effort, designed the course and delivers it online.