Risk Analysis turns the register from a list into a priority order. The domain has three tasks: qualitative analysis, quantitative analysis, and a standing task to keep identifying threats and opportunities as understanding deepens[1]. The exam tests this domain heavily and with numbers: expected monetary value, decision trees and Monte Carlo interpretation all appear, so each is worked step by step below.
3.1 Perform qualitative analysis
Qualitative analysis prioritizes risks quickly, using judgment on defined scales. The outline's enablers are to classify risks nominally in the RBS using the categories from the risk management plan[1]; estimate each risk's impact on schedule, budget, resources and scope[1]; prioritize by impact and urgency[1]; apply the risk matrices, built on an agreed assessment approach, historical information, definitions of probability and impact, risk categories and pre-established criteria[1]; perform an ordinal classification[1]; and coach stakeholders on categorization[1].
The probability–impact matrix. Each risk is rated for probability and impact and plotted on a probability–impact matrix[2]; multiplying the two scale values shows whether it is low, moderate or high[2]. Risks with high probability and high impact plot in the red, high-priority zone of the usual red-yellow-green matrix[3], and a project with many of them carries high exposure[3].
Scales first. NIST describes qualitative assessment as using non-numerical levels such as very low to very high[4]. Its strength is communicating risk results to decision makers[4]; its weakness is that, unless each value is clearly defined, different experts can produce significantly different results[4]. That is why the scale definitions are agreed, usually in the risk management plan, before anyone rates a risk[3].
Nominal and ordinal. Nominal classification sorts risks into named categories, such as the RBS areas. Ordinal classification ranks them in order (first, second, third) without saying how far apart they are. Nominal says what kind; ordinal says what order.
The trap. Urgency is a prioritization factor alongside impact[1]: a risk that could occur next week outranks an otherwise identical risk that could occur next year, because there is less time to respond. And quantitative analysis is applied to the risks qualitative analysis has promoted, not to the whole register[2].
3.2 Perform quantitative analysis
Quantitative analysis puts numbers on the short list. The outline's enablers are to analyze risk data and process performance against established metrics, analyze the project's general risks, and perform forecast and trend analysis[1]; perform sensitivity analysis, naming Monte Carlo, decision trees, critical path and expected monetary value[1]; and perform risk weighting and calculate risk priority[1]. NIST notes that quantitative assessment uses numbers whose meaning holds outside the assessment[4] and most effectively supports cost-benefit analysis of alternative responses[4].
Expected monetary value (EMV). Multiply the probability of the risk event by its monetary impact[5]. A PMI article works the classic example: an 80% chance of rain would cancel an event and cost $30,000 in revenue[5], so the EMV is 0.80 × $30,000 = $24,000. The article's warning is the exam's favourite trap: $24,000 is the value of the risk, but if it rains the project loses the full $30,000[5]. EMV can be lowered by changing the probability, the impact or both[5], and it is only as good as the probability and impact estimates behind it[5].
Signs and sums. This book writes threats as negative values and opportunities as positive ones, so that a set of risks can be added. A threat with 25% probability and a $40,000 impact is −$10,000; an opportunity with 50% probability and a $30,000 benefit is +$15,000; together they are +$5,000.
Decision trees. Decision trees create EMVs for multiple options[5]. A decision tree displays the expected consequences of every alternative by working through its chance nodes and weighting the possible outcomes[6]: each outcome's value is multiplied by its probability[7], and the standard tree chooses the option with the highest EMV[7].
Worked example. Option A has an 80% chance of a $30,000 gain and a 20% chance of a $10,000 loss: (0.8 × 30,000) + (0.2 × −10,000) = 24,000 − 2,000 = $22,000. Option B is a certain $18,000 gain. On EMV the tree picks Option A. A risk-averse organization may instead weight large losses more heavily and choose differently[7]. That is a legitimate choice, but it is not the EMV answer.
Monte Carlo simulation. The analyst gives optimistic, most likely and pessimistic estimates, assigns each a distribution, and runs many simulations[5]; a triangular distribution needs only the minimum, most likely and maximum[2]. The output is a cumulative probability curve linking each date or cost to its probability of being achieved[8], so results are reported with a confidence level[2]. A 90% confidence level is the same as 10% uncertainty[9]. Management then chooses the confidence it will plan to, which is a risk threshold[8]. One study found a deterministic critical-path schedule had less than a 10% chance of being met[8], which is why a single-point date is not a plan.
Sensitivity analysis finds which uncertain inputs contribute most to the outcome[9], so effort goes where it changes the answer.
Reserves. Contingency is an amount added to the base cost estimate to cover estimate uncertainty and risk exposure[10]; summed EMVs and simulation results are common inputs to its size. Management reserve is different: it covers events that cannot be specifically anticipated when costs are approved[11].
The trap. Numbers do not make judgment objective. NIST warns that the rigor of quantification is significantly lessened when subjective determinations are buried inside it[4].
3.3 Identify threats and opportunities
Analysis keeps feeding identification. The outline's enablers are to assess project risk complexity, naming SWOT analysis, Ishikawa and tree diagrams[1]; perform an impact analysis on objectives (scope, schedule, cost, resources, quality, stakeholders)[1]; assess project compliance objectives against organizational strategic objectives, including procedures, governance and regulatory governance[1]; and empower stakeholders to identify threats and opportunities independently[1].
How it is tested. Questions ask which tool fits: an Ishikawa (cause-and-effect) diagram for root causes[2], SWOT for a structured internal and external view, a tree diagram for breaking a complex risk down. Or they describe a compliance conflict and ask what to assess: the project's compliance objectives against the organization's strategy and governance.
Key numbers & deadlines
| Figure | Value |
|---|---|
| Domain weight | 23% of scored items[1] |
| EMV | Probability × monetary impact[5] |
| Confidence level | 90% confidence = 10% uncertainty[9] |
| Retakes | Up to three attempts within the one-year eligibility period[1] |
Key takeaways
- Qualitative first: agree the scales, rate probability and impact, plot on the matrix, and add urgency. Nominal sorts by category; ordinal ranks by order.
- EMV = probability × impact. It is the value of the risk, not what happens if it occurs.
- Decision trees pick the option with the highest EMV; a risk-averse organization may weight large losses more.
- Monte Carlo gives a cumulative probability curve; read results with their confidence level, and choose the confidence to plan to.
- Contingency covers identified risk and estimate uncertainty; management reserve covers what cannot be anticipated.
Chapter 3 quiz — 21 questions
Choose the single best answer for each question.
1. A risk is rated high probability and high impact on the project's probability-impact matrix. Where does it plot?
- A. In the green, low-priority zone
- B. In the yellow zone by default
- C. Outside the matrix
- D. In the red, high-priority zone
2. Before anyone rates a risk on the probability-impact matrix, what must the team agree on?
- A. The contingency reserve amount
- B. What each scale value means
- C. The names of all risk owners
- D. The final delivery date
3. Two experienced engineers rate the same risk "low" and "high" on the qualitative scale. What is the most likely cause?
- A. Qualitative analysis never works
- B. The scale values were not defined
- C. The risk is really two risks
- D. They used different registers
4. A risk manager sorts risks into environment, organizational, project management and technical categories from the plan. What is this?
- A. Ordinal classification
- B. Sensitivity analysis
- C. Risk weighting
- D. Nominal classification
5. The team ranks its top ten risks from first to tenth without saying how much worse one is than the next. What is this?
- A. Ordinal classification
- B. Monte Carlo analysis
- C. Cardinal measurement
- D. Nominal classification
6. Two risks have identical probability and impact ratings, but one could occur next week and the other next year. Which should rank higher?
- A. Neither; timing is irrelevant
- B. The next-week risk
- C. The one next year
- D. They must rank equally
7. What does NIST identify as the main strength of qualitative risk assessment?
- A. Clear communication of results
- B. It removes expert judgment
- C. It replaces the risk register
- D. It gives precise dollar values
8. An outdoor event has an 80% chance of rain, which would cancel it and lose $30,000 in revenue. What is the expected monetary value of the rain risk?
- A. $24,000
- B. $37,500
- C. $6,000
- D. $30,000
9. A threat has 25% probability and a $40,000 impact. An opportunity has 50% probability and a $30,000 benefit. Writing threats as negative, what is their combined EMV?
- A. +$5,000
- B. −$25,000
- C. +$70,000
- D. +$25,000
10. Three threats have EMVs of −$8,000, −$12,000 and −$5,000. What do these figures most directly inform?
- A. The management reserve, about $25,000
- B. The contingency reserve, about $25,000
- C. The base estimate, about $8,000
- D. The profit margin, about $25,000
11. Option A: 80% chance of a $30,000 gain and 20% chance of a $10,000 loss. Option B: a certain $18,000 gain. Which option does an EMV-based decision tree choose?
- A. Option B, EMV $18,000
- B. Option A, EMV $30,000
- C. Option A, EMV $22,000
- D. Option B, because it has no loss
12. A Monte Carlo cost simulation shows an 80% probability of finishing within $2.1 million. What does this mean?
- A. The most likely cost is $1.68M
- B. The budget cannot be exceeded
- C. A 20% chance of exceeding $2.1M
- D. The cost will be exactly $2.1M
13. What does an analyst supply for each uncertain task before running a Monte Carlo simulation?
- A. A probability-impact rating
- B. A single best estimate
- C. A range and a distribution
- D. An owner and a due date
14. A risk manager wants to know which uncertain inputs contribute most to the chance of missing the launch date. Which analysis answers this?
- A. Assumption analysis
- B. Ordinal classification
- C. Stakeholder analysis
- D. Sensitivity analysis
15. Why is quantitative analysis usually applied only to some risks, rather than the whole register?
- A. Rules forbid quantifying minor risks
- B. Tools handle only ten risks
- C. It follows qualitative prioritization
- D. Qualitative ratings are always wrong
16. According to NIST, what does quantitative risk assessment support most effectively?
- A. Cost-benefit analysis of responses
- B. Assigning risk owners
- C. Writing the communication plan
- D. Building the RBS
17. A risk is rated 0.7 for probability and 0.4 for impact on numeric scales. What is its probability-impact score?
- A. 0.7
- B. 0.3
- C. 1.1
- D. 0.28
18. Integration keeps failing and the team wants the root causes, not just a list of failures. Which tool fits best?
- A. An Ishikawa diagram
- B. A RACI chart
- C. A burndown chart
- D. A probability-impact matrix
19. A new data-protection regulation conflicts with the current project plan. What should the risk manager assess?
- A. Whether it can wait until closeout
- B. Compliance objectives against strategy
- C. Compliance officers' attitudes
- D. Only the cost of complying
20. A manager says a quantitative model makes the team's risk judgments objective. What does NIST warn?
- A. Qualitative results are useless
- B. Hidden judgments weaken it
- C. Models are always objective
- D. Numbers remove uncertainty
21. A decision tree favours a high-EMV option that carries a small chance of a ruinous loss. The organization is strongly risk-averse. What does published guidance say?
- A. It may weight large losses more
- B. Decision trees cannot show losses
- C. It should average the two options
- D. It must follow the highest EMV
Answer key & explanations — Chapter 3
1. D. Risks with high probability and high impact plot in the high-priority area of a matrix whose zones use a red-yellow-green traffic-light system. A project with many such risks carries high exposure.[3]
2. B. NIST warns that unless each value is clearly defined, different experts can produce significantly different results, and the outline builds the risk matrices on agreed definitions of probability and impact. The scale definitions usually sit in the risk management plan.[1, 3, 4]
3. B. NIST names this as the weakness of qualitative assessment: unless each value is clearly defined or illustrated, experts relying on their own experience can produce significantly different results. The fix is to define the scale, not to abandon the method.[4]
4. D. The outline describes nominal classification of risks in the RBS using the classifications from the risk management plan, such as environment, organizational, project management and technical. Ordinal classification would rank them in order.[1]
5. A. Ranking in order without measuring the gaps is ordinal, and the outline lists performing an ordinal classification as part of qualitative analysis. Nominal classification sorts risks into named categories without ranking them.[1]
6. B. The outline prioritizes risks by impact and urgency. With identical ratings, the earlier risk leaves less time to respond, so its urgency ranks it higher. NASA forwards urgent risks straight to planning so that a timely response can be put in place.[1, 9]
7. A. NIST describes qualitative assessment as using non-numerical levels such as very low to very high and says it supports communicating risk results to decision makers. Precise monetary values come from quantitative assessment.[4]
8. A. EMV = probability × impact = 0.80 × $30,000 = $24,000. The $30,000 figure is the loss if it actually rains; EMV is the probability-weighted value used to compare options.[5]
9. A. Threat: 0.25 × −$40,000 = −$10,000. Opportunity: 0.50 × $30,000 = +$15,000. Sum: −$10,000 + $15,000 = +$5,000. The +$70,000 answer adds the impacts without applying the probabilities.[5]
10. B. Contingency is added to the base estimate to cover risk exposure and estimate uncertainty, and the summed EMVs of identified threats, $8,000 + $12,000 + $5,000 = $25,000, are a common input to it. Management reserve covers events that cannot be anticipated, so identified risks do not size it.[5, 10, 11]
11. C. Option A: (0.8 × $30,000) + (0.2 × −$10,000) = $24,000 − $2,000 = $22,000, which beats Option B's $18,000. The standard decision tree picks the highest EMV; $30,000 is only Option A's best case.[7]
12. C. Monte Carlo output is a cumulative probability curve, so each value is read with its confidence level. An 80% confidence of staying within $2.1 million leaves a 20% chance of exceeding it, just as 90% confidence equals 10% uncertainty.[2, 8, 9]
13. C. Monte Carlo lets the analyst specify optimistic, most likely and pessimistic estimates and assign a distribution curve before running the simulations. A triangular distribution needs only the minimum, most likely and maximum.[2, 5]
14. D. Sensitivity studies determine which events and parameters in the model are the most important contributors to a performance risk, and the outline lists sensitivity analysis under quantitative analysis.[1, 9]
15. C. Quantitative analysis is driven by the results of qualitative analysis and focuses on the areas it flagged. That concentrates the effort where it changes decisions.[2]
16. A. NIST says quantitative assessment most effectively supports cost-benefit analyses of alternative risk responses or courses of action. The RBS and communication plan are planning artifacts.[4]
17. D. The score multiplies the scale values: 0.7 × 0.4 = 0.28, which places the risk as low, moderate or high on the matrix. Adding them (1.1) is the classic error.[2]
18. A. Cause-and-effect (Ishikawa) diagrams support analysis of a risk's root cause, and the outline names Ishikawa among the tools for assessing project risk complexity. A probability-impact matrix prioritizes risks but does not explain their causes.[1, 2]
19. B. The outline asks for project compliance objectives to be assessed against organizational strategic objectives, including procedures, governance and regulatory governance. Reducing it to cost misses the governance question.[1]
20. B. NIST warns that the rigor of quantification is significantly lessened when subjective determinations are buried within quantitative assessments. EMV is likewise only as good as its probability and impact inputs.[4, 5]
21. A. The standard tree chooses the highest EMV, but a PMI paper notes that risk-averse organizations tend to maximize expected utility, which can give serious negative weight to large losses. The EMV answer and the risk-averse choice can legitimately differ.[7]
Sources cited in this excerpt
- PMI Risk Management Professional (PMI-RMP) Exam Content Outline and Specifications, Updated January 2023. https://www.pmi.org/-/media/pmi/documents/public/pdf/certifications/risk-management-exam-outline_updated-2024.pdf
- How to link the qualitative and the quantitative risk assessment (PMI Learning Library). Project Management Institute (text captured from the Internet Archive copy of the PMI Learning Library page). https://www.pmi.org/learning/library/link-qualitative-quantitative-risk-assessment-7375
- Weight loss for risky projects | PMI. https://www.pmi.org/learning/library/weight-loss-for-risky-projects-9879
- NIST Special Publication 800-30 Revision 1, Guide for Conducting Risk Assessments. https://csrc.nist.gov/pubs/sp/800/30/r1/final
- Using decision models in the real world (PMI Learning Library). Project Management Institute (text captured from the Internet Archive copy of the PMI Learning Library page). https://www.pmi.org/learning/library/expected-monetary-value-choices-risk-impact-3490
- NASA Systems Engineering Handbook, NASA/SP-2016-6105 Rev2. National Aeronautics and Space Administration, 2016. https://www.nasa.gov/wp-content/uploads/2018/09/nasa_systems_engineering_handbook_0.pdf
- Decision tree analysis for the risk averse organization (PMI Learning Library). Project Management Institute (text captured from the Internet Archive copy of the PMI Learning Library page). https://www.pmi.org/learning/library/decision-tree-analysis-expected-utility-8214
- Delphi: a schedule risk assessment approach (PMI Learning Library). Project Management Institute (text captured from the Internet Archive copy of the PMI Learning Library page). https://www.pmi.org/learning/library/delphi-schedule-risk-assessment-approach-3621
- NASA Risk Management Handbook, NASA/SP-2011-3422, Version 1.0. National Aeronautics and Space Administration, 2011-11. https://ntrs.nasa.gov/citations/20120000033
- Contingency - Are you Covered? (PMI Learning Library). Project Management Institute (text captured from the Internet Archive copy of the PMI Learning Library page). https://www.pmi.org/learning/library/contingency-are-covered-6099
- Project reserves : a key to managing cost risks (PMI Learning Library). Project Management Institute (text captured from the Internet Archive copy of the PMI Learning Library page). https://www.pmi.org/learning/library/project-reserves-managing-cost-risks-5726