Risk Response Planning: How to Plan Risk Responses in Projects
Risk response planning decides what the team does about each prioritized risk before it happens. In the PMBOK Guide Sixth Edition the process is called Plan Risk Responses. It turns a ranked risk register into owned, funded, scheduled actions.
This guide walks through the process: where it fits, its inputs, techniques, and outputs, a step-by-step method, a response plan template, and the exam angle.
What Is Risk Response Planning in Projects?
Risk response planning is the process of developing response options, selecting a strategy for each prioritized risk, and agreeing on actions, owners, and funding. The PMBOK Guide names it Plan Risk Responses. Its output is a set of planned responses in the project documents.
A risk response plan is not a single document. It is the sum of the response entries in the risk register, the risk report, and the updated management plans and baselines. The process runs throughout the project, not once. Each new risk and each change in exposure reopens it.
The key benefit is action with resources behind it. A risk with a rating and no response is a known problem with no plan.
Where Does Plan Risk Responses Fit in the Risk Process?
Plan Risk Responses is the fifth of 7 risk processes in the PMBOK Guide Sixth Edition. It follows qualitative and quantitative analysis. Implement Risk Responses executes its plans, and Monitor Risks tracks the results. It belongs to the planning process group.
| # | Process | Process group | Role |
| 11.1 | Plan Risk Management | Planning | Sets approach, thresholds, and roles |
| 11.2 | Identify Risks | Planning | Creates the register and the report |
| 11.3 | Perform Qualitative Risk Analysis | Planning | Rates probability and impact |
| 11.4 | Perform Quantitative Risk Analysis | Planning | Prices risk numerically |
| 11.5 | Plan Risk Responses | Planning | Chooses strategies and actions |
| 11.6 | Implement Risk Responses | Executing | Carries out the planned responses |
| 11.7 | Monitor Risks | Monitoring and controlling | Tracks risks and response results |
Planning decides. Implementing acts. A team that plans well and never implements has documents and no protection.
What Are the Inputs to Plan Risk Responses?
The inputs are the risk management plan, the cost baseline, the resource management plan, and project documents such as the risk register, risk report, schedule, stakeholder register, and lessons learned register. The register supplies the prioritized risks that need responses.
| Input group | Items | What the process takes from it |
| Project management plan | Risk management plan, resource management plan, cost baseline | Thresholds, roles, authority levels, reserve limits |
| Project documents | Risk register, risk report, project schedule, team assignments, resource calendars, stakeholder register, lessons learned register | Prioritized risks, available people, earlier response results |
| Enterprise environmental factors | Risk appetite and tolerance, regulations, market conditions | Limits on which responses are acceptable |
| Organizational process assets | Response templates, past risk data, escalation procedures | Proven responses and required formats |
The risk management plan matters most. Its authority levels decide which responses the project manager approves and which go to the sponsor.
What Tools and Techniques Does the Process Use?
The process uses expert judgment, interviews, facilitation, and decision-making techniques, plus specific tools: strategies for threats, strategies for opportunities, contingent response strategies, strategies for overall project risk, and data analysis such as alternatives analysis and cost-benefit analysis.
| Technique | Use |
| Expert judgment | Advice on feasible responses from people with technical or past-project experience |
| Interviews | One-to-one sessions with risk owners and specialists |
| Facilitation | Workshops that generate and compare response options |
| Multicriteria decision analysis | Scoring options against agreed criteria |
| Strategies for threats | Escalate, avoid, transfer, mitigate, accept |
| Strategies for opportunities | Escalate, exploit, share, enhance, accept |
| Contingent response strategies | Responses that run only when a trigger fires |
| Strategies for overall project risk | Responses aimed at the project’s total exposure |
| Alternatives analysis | Compares candidate responses |
| Cost-benefit analysis | Tests whether a response earns its cost |
The cost-benefit test uses expected monetary value. PMTI’s guide What is Expected Monetary Value in Project Management? explains the calculation. Example: a 30% risk with a $60,000 impact has an EMV of $18,000. A $7,000 response cuts the probability to 10%, so EMV falls to $6,000. The reduction is $12,000. Divide the reduction by the cost: $12,000 ÷ $7,000 is 1.7, and the net benefit is $5,000. Fund the response.
Score each option against 6 criteria: effectiveness, cost, feasibility, time to implement, secondary risks created, and stakeholder acceptance.
What Are the Outputs of Plan Risk Responses?
The outputs are change requests, updates to the project management plan and its baselines, and updates to project documents: the risk register, risk report, assumption log, cost forecasts, project schedule, team assignments, and lessons learned register.
| Output group | Items |
| Change requests | Requests to alter baselines or plans to fit the responses |
| Project management plan updates | Schedule, cost, quality, resource, and procurement management plans; scope, schedule, and cost baselines |
| Project documents updates | Assumption log, cost forecasts, lessons learned register, project schedule, project team assignments, risk register, risk report |
PMTI’s guide What is a Risk Register in Project Management? covers the register layout. After this process the register also holds each risk’s agreed strategy, actions, triggers, contingency and fallback plans, owners, and residual and secondary risks. The risk report gains the agreed responses and owners for the high-priority risks.
How Do You Plan Risk Responses Step by Step?
Plan responses in 8 steps: rank the risks, convene owners and experts, generate options, evaluate them, select a strategy, define actions with owners and triggers, fund and schedule the actions, and obtain approval. Then record the residual and secondary risks.
- Rank the risks from the register by score, and start with those above the threshold.
- Convene each risk owner with the experts who know the risk.
- Generate 2 or 3 response options per risk, for threats and opportunities alike.
- Evaluate the options with cost-benefit analysis and the 6 criteria.
- Select 1 strategy per risk, and note any second strategy for the fallback.
- Define the actions, and give each an owner, a due date, and a trigger when the response is contingent.
- Price and schedule the actions, and add them to the cost and schedule baselines or to the reserve plan.
- Obtain approval at the required authority level, and record the decision in the register.
After step 8, list the residual risk that remains and the secondary risk that the response creates. A response that creates a bigger risk than it removes fails the evaluation.
Not every risk needs a costly response. Low-priority risks go on a watch list with passive acceptance.
What Goes Into a Risk Response Plan?
A risk response plan entry holds the risk, the strategy, the actions, the owner, the trigger, the cost and schedule impact, the contingency and fallback plans, and the residual and secondary risks. One entry exists for each risk that receives a response.
Example entry:
| Field | Entry |
| Risk | R7 Key supplier delivers late |
| Score | Probability 40%, impact $50,000, EMV $20,000 |
| Response type | Proactive, with a contingent backup |
| Strategy | Mitigate |
| Actions | Qualify a second supplier by week 6 |
| Owner | Procurement lead |
| Cost and schedule | $8,000; 2 weeks of procurement effort |
| Trigger | Supplier misses a milestone by 5 days |
| Contingency plan | Order from the second supplier |
| Fallback plan | Rent equivalent components at spot price |
| Residual risk | Second supplier’s quality is unproven |
| Secondary risk | Qualification effort delays the test schedule |
| Approver | Project manager, within authority |
Every figure in the example is illustrative. Replace it with project data.
How Do You Fund and Schedule the Responses?
Proactive responses become activities in the schedule and the cost baseline. Contingent responses sit in the plan as conditional activities and draw on the contingency reserve when the trigger fires. Unidentified risks draw on the management reserve with approval.
| Response type | Where it lives | Funded from |
| Proactive (runs now) | Work breakdown structure, schedule, cost baseline | Cost baseline |
| Contingent (runs on a trigger) | Conditional activities, marked so the team does not run them early | Contingency reserve |
| Response to an unidentified risk | Issue log and change request | Management reserve, with approval |
Any response that changes a baseline needs a change request. Route it through change control before the team commits the money.
Who Plans and Approves the Responses?
The risk owner proposes the response, and the project manager facilitates the planning. Experts and the team supply options. The project manager approves responses within their authority. The sponsor approves those above it, and the change control board approves baseline changes.
| Role | Duty |
| Risk owner | Proposes the response, then carries it out |
| Project manager | Facilitates, integrates the responses, and approves within authority |
| Team and experts | Generate and test options |
| Sponsor | Approves responses above the project manager’s authority and funds the management reserve |
| Change control board | Approves changes to baselines |
The risk management plan sets the authority levels. Read them before planning, because they decide who signs.
Which of These Is Not a Risk Response?
Ignoring a risk is not a response. The 8 recognized strategies are escalate, avoid, transfer, mitigate, accept, exploit, share, and enhance. A strategy used on the wrong risk type is also wrong: exploit, share, and enhance do not answer threats.
| Item | A valid response? | Why |
| Ignore or deny the risk | No | No decision, no owner, no plan |
| Avoid, transfer, mitigate | Yes, for threats only | Threat strategies |
| Exploit, share, enhance | Yes, for opportunities only | Opportunity strategies |
| Escalate | Yes, for both | Hands the risk to a higher authority |
| Accept | Yes, for both | A recorded decision, passive or active |
| Monitoring and reporting | No | Support activity, not a strategy |
| Contingency plan | Yes, as part of a strategy | The prepared action under active acceptance or a contingent response |
Exam-style example: “Which is not a strategy for a negative risk: avoid, transfer, enhance, or accept?” The answer is enhance.
How Does Risk Response Planning Work in Agile and Hybrid Projects?
Agile and hybrid teams plan responses on a shorter cycle. Risks and response actions enter the backlog, the team plans them in sprint planning, and the product owner approves trade-offs. Contingent responses become reserved capacity.
- Add response actions to the backlog as items with owners.
- Plan the top risk responses at each sprint and release planning session.
- Reserve sprint capacity or a release buffer for contingent responses.
- Review response results at each retrospective, and re-plan the ones that failed.
Approximately 60% of the July 2026 PMP exam targets agile or hybrid approaches, so exam scenarios use both vocabularies.
How Is Plan Risk Responses Tested on the PMP Exam?
PMP questions test the position of the process, its outputs, and the difference between planning and implementing. Plan Risk Responses follows quantitative analysis, belongs to the planning group, and produces change requests and document updates. Implement Risk Responses carries the plans out.
| Scenario cue | Answer |
| The next risk process after quantitative analysis | Plan Risk Responses |
| The team chooses a strategy and assigns an owner | Plan Risk Responses |
| The team runs an agreed response | Implement Risk Responses |
| A response changes the cost baseline | Change request from Plan Risk Responses |
| The team funds known risks | Contingency reserve |
| A threat exceeds the project manager’s authority | Escalate |
| The response creates a new risk | Secondary risk, recorded in the register |
Read whether the question asks who decides or who acts. Deciding is planning. Acting is implementing.
PMTI’s Project Risk Management Course (24 PDUs) covers project risk management in depth for middle and upper management. Max Wideman, a PMI Fellow who led the first PMBOK Guide effort, designed the course and delivers it online.