Skip to content

Project Management Mastery / Chapter 22

Manage Risk, Opportunity, and Uncertainty

Risk management is a decision system, not a document, and a document with no decision attached to it decays. At KijaniPay the register has not been touched since August, and the gate-release review on 8 December finds three months of evidence missing from it — the opening scene of a chapter that teaches the six words of uncertainty (risk, issue, assumption, constraint, ambiguity, variability), the cause–event–effect spine that makes a vague risk ownable, the bow tie with its preventive and recovery controls, the arithmetic that compares deploying the fix now against holding until January, the appetite that sets thresholds per value dimension, and the wiring that keeps the register where the next decision finds it.

Chapter 22: Manage Risk, Opportunity, and Uncertainty

The register had not been touched since August

It is 8 December at KijaniPay, and the gate-release review has been called for nine. The fix landed on 5 December, three weeks after the 17 November decision that re-anchored the launch: the idempotent re-sweep, the orphan monitor, the interruption tests, twelve million units, on schedule and inside the estimate. Four clean days of the fourteen-day evidence clock have accrued. The automated reconciliation monitor, the instrument Ifeoma’s team wired in so that “clean” would mean measured rather than assumed, has logged seven days of runs without an exception. The cohort that opened on 30 November, capped below the defect’s visible threshold, is paying its first settlements inside the promise. Amara Osei has asked for this meeting because the holiday peak is closing in: growth estimates that the last two weeks of December carry about 60 percent of the month’s merchant onboarding value, and every day the gate stays shut is a day of that value walking past.

Zanele Dlamini asks for the risk picture first, because the decision in front of the room is not whether the fix works. It is what could go wrong if the gate opens, what could go wrong if it stays shut, and a decision that weighs two futures needs both futures named. Kwame Mensah opens the risk register. The register has not been touched since 26 August.

That date is the detail that stops the room. Three months of evidence have passed through the project, and none of it is in the register. The pilot that closed on 15 October with its 8 percent late tail. The campaign that found the defect at 40,000 transactions a day. The re-anchor decision of 17 November, which was, in every practical sense, a risk decision: accept a controlled cohort now, hold the broad launch until the evidence clears. The residual risk that decision created, the orphan window that lives between now and the fix’s proof, with its trigger, the early-close day, and its owner, the engineering lead. The regression risk the fix itself carries. The license the regulator has not yet decided. None of it is in the register. The register’s top row still says, in the passive voice of August, “the settlement vendor may be unable to meet the batch schedule,” with no owner, no trigger, no review date. The second row says “merchant adoption may lag targets,” with no trigger and a status that has said open since July. The third says “the regulator may not approve in time,” which is at least true, and is also the only sentence in the file that a reader could act on.

The register did not decay because anyone was careless. It decayed because nothing was wired to it. The campaign ran on the acceptance matrix. The decision of 17 November ran on the defect trend and the promise. The fix ran on the schedule and the budget. The register was reviewed monthly as a ritual, and a document that is reviewed as a ritual is a document that is not reviewed at all. The project’s real risk information lived everywhere except the place where a risk decision should be able to find it, and the meeting that needed a risk picture got a graveyard.

This chapter is the repair. It teaches the risk system as a decision instrument: the vocabulary that keeps uncertainty from being flattened into one word, the cause-event-effect discipline that makes a risk actable, the lenses that find what the room cannot see, the analysis that sorts what matters, the responses that carry owners and triggers, the arithmetic that compares futures, the appetite that sets thresholds, and the escalation that moves information to authority before it is too late. It also teaches the failure the register on the table embodies, the decay of the system into a document, so that the reader who builds the instrument does not lose it to the ritual that buried this one. Chapter 21 ended by handing the quality system’s residuals to the risk system as its raw material: the known orphan window, the unvalidated row, the carried debt. This is where that handoff lands, and the risk system’s first job is to be the place where the next decision finds what the project already knows.

Six words that claim the same shelf

The register’s first problem is that it called everything risk and treated everything the same. The vocabulary of uncertainty has six words, and they mean six different futures that need six different treatments.

Risk is an uncertain future effect on the objectives. The guidance standard ISO 31000:2018 defines risk as the effect of uncertainty on objectives, and the definition is worth holding in full, because it points both ways: an effect that helps the objectives is a risk as much as one that harms them. An opportunity shares the same shelf as a threat, and both belong in the register. The sweep that might be interrupted, the license that might arrive late, the peak that might be captured: each is a risk in the precise sense of the word.

Issue is a condition that exists now. The reconciliation drift exists now, so it is an issue: it demands resolution, an owner, a date, and an incident record, not a response strategy. The delay that could follow from the bank’s schedule is a risk; the delay that has already happened is an issue. Issues are what risks become when they materialize. The register’s discipline is to promote the materialized risk into the issue log with its evidence, not to keep it as a risk with a climbing likelihood. That is how a register pretends a fire is a forecast.

Assumption is something believed true that has not been verified. Chapter 3 built the assumption inventory with its four evidence strengths, observed, heard from a credible source, analogy, guess, and its standing rule: the highest-scoring assumptions are the project’s real risk register, whether or not they appear there yet. The assumption that the batch window will behave in December as it did in October, the assumption that the cohort cap holds, the assumption that the license decision is imminent because the filing was complete: each is a belief the plan leans on, and each is testable. Assumptions get tests, review dates, and owners. They do not get likelihood ratings.

Constraint is a fixed limit. The budget of 210 million units, the grant window at Northstar, the 99.5 percent reconciliation guardrail, the regulator’s published processing time: these are not uncertain, they are given, and they are managed within, not responded to. The confusion of constraint with risk produces the classic dead row, “the budget may not be enough,” which is not a risk, it is a statement that the plan exceeds a limit, and the response belongs to the plan.

Ambiguity is the situation itself open to more than one interpretation. What the regulator will mean by “settlement provider readiness,” what “adoption” will mean at the sixth clinic, what “launch” means to growth and to compliance, the word the chapter 12 room discovered meant two different readiness thresholds: ambiguity is resolved by discovery, by the probes and prototypes of chapter 6, not by a likelihood rating, because a likelihood rating on an ambiguous event is a guess wearing a number.

Variability is the outcome varying around an expected value in a known way. Durations, costs, volumes, transaction rates: these are distributions, not points. Chapter 15 taught the range and the cone; chapter 38 will teach the forecast. Variability is handled with ranges, reserves, and probabilistic thinking, not with a register row per swing.

The failure is the kitchen drawer: everything goes into the one register, the issue that exists, the assumption that might be wrong, the constraint that was exceeded, the ambiguity that was never discovered, the variability that will not hold still, and the risk that might actually happen. A drawer cannot act on any of them. The register holds one kind of thing, the uncertain future effect, and the other five need their own homes: the issue log, the assumption inventory, the constraints list, the discovery backlog, the range and the reserve. The field signal that the drawer has opened is a register whose rows ask for different verbs, resolve this, test that, design within, discover, estimate, respond, and a risk review that reads them all aloud with the same cadence. That is how the review becomes a parade instead of a decision. The meeting on 8 December could not see its own risk picture because the picture had been filed in six different rooms, and the register, the one place the meeting looked, held the leftovers.

A risk is a story with a spine

The register’s second problem is that its sentences are moods, not stories. “The bank may be slow and merchants will complain.” “The corridor could be delayed by the flood plain.” “Adoption might be lower than expected.” Each of these names a vague event and a vague effect, and none of them can be analyzed, owned, responded to, or escalated, because none of them says why. The discipline that repairs this is the cause-event-effect statement: one cause, the condition that makes the event possible; one event, the uncertain future occurrence; one effect, what it would cost or change on the objectives. The risk that can be acted on is a story with a spine, and the spine runs from cause through event to effect, with the response acting on the cause or the effect, never on the mood.

The campaign evidence rewrites KijaniPay’s dead row in one pass. The August sentence, “the settlement vendor may be unable to meet the batch schedule,” becomes: because the bank’s batch window closes early on some days and the reconciliation sweep was not idempotent, the sweep can be interrupted mid-run, leaving transactions pending, exceptions growing, merchant funds missing the 24-hour promise, and the 99.5 percent guardrail breached on those days. That sentence is a different instrument entirely. The cause names a mechanism the project can inspect, the idempotency defect, and a trigger it cannot control, the bank’s calendar. The distinction matters: the fix of 5 December worked on the mechanism, while the trigger remains on Savanna’s side of the contract from chapter 20. The event names the moment to watch. The effect names the promise at stake, so that anyone who reads the row knows why it matters without rereading the charter. The response writes itself: fix the mechanism, monitor the event, hold the promise.

The discipline has three rules that the cases enforce. First, one spine per row. A row with three causes and two effects is not a risk, it is a cluster, and a cluster cannot be owned: split it, or draw the bow tie of the next section and let the cluster become a diagram with one owner per arm. Second, the cause is not the fault. Cause-event-effect is a description of mechanism, not an allocation of blame, and the row that reads “the vendor is unreliable” is a verdict, not a cause; the cause is the observable condition, the early-close days, the unverified road, the classroom-only training, the rule untested at volume. Third, the effect is stated against the objectives, in the currency of the success profile from chapter 2: money delayed, days lost, a guardrail breached, a license narrative damaged, a dimension of success failed. An effect that cannot be attached to a named objective is a worry, and the worry belongs in the drawer, not the register.

The rewrite test is brutal and fair: if you cannot say what you would do differently having read the row, the row has not been written yet. The vagueness is not a prose problem, it is a thought problem, and the reason competent people leave risks vague is that a vague risk cannot be assigned, which means no one can be held to it. The mastery drill at the end of this chapter is built from exactly this test, and the standard to apply there is the one the campaign applied: the rewritten row must name the mechanism, the trigger, the promise, and the owner, in one pass. When every row on the register passes that test, the register stops being a record of fears and becomes a work plan for the future.

The bow tie shows where the controls bite

The cause-event-effect spine becomes a picture in the bow tie, the analysis form that the companion standard IEC 31010:2019, Risk management: Risk assessment techniques, catalogs among the field’s analytical methods. The bow tie draws the spine sideways: the causes enter from the left, the event sits in the center, the consequences exit to the right, and the controls sit on the arms. Preventive controls stand between the causes and the event, where they stop the event or reduce its chance; recovery controls stand between the event and the consequences, where they limit the damage once it has happened. The bow tie’s teaching is the placement: a control on the wrong arm is a control in the wrong place, and the figure makes that visible in a way a list never can.

Figure 22.1: The bow tie for the orphan-window risk at KijaniPay. The event in the center: the reconciliation sweep is interrupted mid-run. Three causes enter from the left: the bank’s batch window closes early; the sweep is not idempotent, so a retried run skips the pending transactions; and a release deploys a change to the sweep without the interruption test. Preventive controls sit on the cause arms: the batch-window schedule monitor that predicts early-close days; the idempotent re-sweep with its unit and integration tests, the fix of 5 December; the interruption test in the regression suite, the lesson the campaign paid for. Three consequences exit to the right: exceptions grow and the settlement team absorbs hours of investigation; merchant funds miss the 24-hour promise; the 99.5 percent reconciliation guardrail breaches and the regulatory narrative is damaged. Recovery controls sit on the consequence arms: the orphan monitor that flags pending transactions within minutes; the manual re-sweep and the settlement team’s exception shifts; the cohort cap that holds volume below the defect’s visible threshold; and the communication plan that tells the cohort what happened before they ask.

The bow tie is the chapter’s primary visual, and it is worth reading twice, because it carries the whole argument. The left arm is where prevention money goes, and the campaign’s lesson is that the mechanism control, the idempotent sweep, was missing while the trigger control, negotiating the bank’s calendar, was the only one anyone discussed, which is why the defect survived the pilot and reached the campaign. The right arm is where recovery money goes, and the honest project plans both arms, because no control is perfect, and the controls that matter most are the ones tested under the conditions the bow tie names. The 5 December fix added controls to both arms, and the fourteen-day clock exists to prove that the left arm holds.

The bow tie also shows what the register cannot: that risks are connected through shared causes and shared events. The early-close day is one trigger driving the reconciliation failure, the exception load, the merchant complaints, and the regulatory narrative; a register with four separate rows for those four effects will rate them separately, and the room will argue about four likelihoods instead of noticing the one condition. The bow tie for the system, several events sharing causes, is chapter 3’s systems thinking in risk form; the analysis must go beyond the single row to see it. At BlueLine the same flood season drives the drainage approval delay, the lost construction window, and the political exposure; at Northstar the same grant window drives the supplier decision, the convoy schedule, and the scope of what can be moved. The risk that is only ever analyzed as a row will be managed as a row, which is how a single point of failure hides inside an average.

Finding the risks the room cannot see

Identification is the step that determines everything downstream, and it fails most often not because the room is short of risks but because it is short of lenses. A project’s risks are not sitting in the room’s memory. They are distributed across the work, the interfaces, the assumptions, the history, and the world, and the craft is to walk the sources systematically instead of brainstorming once.

The minimum viable structure is the risk breakdown structure (RBS): a simple taxonomy of where risks live, technical, schedule, cost, quality, resources, procurement and suppliers, governance and decisions, legal and regulatory, market and demand, environmental, safety, security and data, change and adoption, political and reputational. The RBS is a prompt, not a bureaucracy: the room walks each cell and asks what could happen there, and the empty cells are findings too, an empty safety cell on a project that moves goods on flooded roads is a signal, not a relief. The secondary lenses are where the identification actually happens: the work breakdown from chapter 14, walked package by package; the interface register from chapter 14, where seam defects live; the assumption inventory from chapter 3, because the highest-scoring assumptions are the risks the room has not yet thought of as risks; the stakeholder map from chapter 9, where the opposition and the silent stakeholders carry their own futures; the defect trend from chapter 21, where the system has already started to speak; and the reference class from chapter 15, the history of comparable projects, the failures this project has not yet had but its class has. The question that opens each lens is the question chapter 3 taught: what would have to be true for this to go wrong, and what would have to be true for it to go better than planned?

The threat bias is the identification failure this chapter warns about, and it has two faces. The first is that the room sees only the downside. An opportunity is a risk with a positive effect, an uncertain future that helps the objectives, and the same ISO definition that covers the threat covers it. The register that holds only threats is half a register. KijaniPay’s campaign is the chapter’s best example. The early-close days, a threat that cost the acceptance campaign, also exposed the idempotency defect before the launch; the pilot data that produced the exceptions became the evidence that re-anchored the launch and saved the promise. The threat contained the opportunity, and the project that never asked “what could this reveal that we needed to know” would have shipped the defect into the peak. The holiday peak itself is an opportunity with a window: it exists only if the evidence holds, and exploiting it is a response, not a hope. At Meridian, the platform migration is a threat to clinical workflow and an opportunity to standardize the six clinics’ processes in a way the paper world never allowed; at BlueLine, the corridor is a threat to 1,400 shops and an opportunity to redesign access the pre-corridor street never offered. The response family for opportunities mirrors the threats: exploit, make the favorable event happen; enhance, raise its chance or its size; share, bring in the partner whose position improves it; accept, let it happen and harvest it. The project that names its opportunities has given the room something the threat-only register never gives it: a reason to want the uncertain future, and the discipline to prepare for it.

The second face of the threat bias is the bias of the loud. The risk workshop collects the risks that someone in the room has already met; the risks nobody has met arrive later, which is the whole problem of the novel. The corrections are cheap: silent writing before the open floor, so the first voices do not anchor the room; the assumption inventory as a source; the reference class, because the failures of comparable projects are the failures this room has not lived through; and the standing question asked at every review: what would make this look foolish in the retrospective? Identification is a cadence, not an event. The first draft of the register is input, deliberately wrong on the side of inclusion, because the analysis step is where the sifting happens.

Likelihood and impact are the beginning

Analysis is where the sifting happens, and the first tool is the classic likelihood-and-impact assessment, usually drawn as a matrix: likelihood on one axis, impact on the other, the cells graded from trivial to severe. The matrix is the minimum viable instrument, and it is also a trap, and the honest chapter teaches both. The mechanics are simple: five-point scales, likelihood from rare to almost certain, impact from negligible to severe, the score a rank that sorts rows into response design, monitoring, or acceptance. The rank is an input to prioritization, not a truth about the world, and the narrative of the cause-event-effect row outranks the cell it lands in, because the cell can be argued about and the spine can be acted on.

The trap has four shapes. The amber swamp: everything lands in the middle band, the room converges on medium, medium, medium, and the review produces no change to any row’s rank, because the middle band is where uncertainty is discharged instead of analyzed. The confidence gambler: the likelihood is stated as a precise number with no evidence behind it, a probability borrowed from the speaker’s certainty, the precise liar from chapter 15 wearing a risk matrix’s clothes. Anchoring and recency: the room rates the risk it recently met higher than the risk it never met, which is how the register learns only the project’s own history. And correlation blindness: the matrix scores each row alone, so the four consequences of the early-close day are four medium rows instead of one severe condition, and the single point of failure hides in the average.

The corrective vocabulary adds two words the matrix does not carry. Proximity is how close in time the event sits: the license decision is weeks away, the flood season is months away, and proximity changes what the risk demands of the plan now. Urgency is how soon the response must start to beat the event: a risk twelve months out with a six-month lead time for its response has high urgency and low proximity, and the matrix that scores only likelihood and impact cannot see the difference. The row carries both, with dates: the trigger date, the date by which the response must be underway, the date by which the risk must be revisited. The sorting rule is honest and useful: the register is sorted first by the effect on the objectives, then by proximity and urgency, and the top of the register is the short list that the leadership actually reviews, the ten risks that can kill or change the value, not the sixty that can bruise it.

The analysis also has a cadence, and the cadence is set by the decisions it feeds, not by the month. A register reviewed monthly because the month has four weeks is a calendar artifact; a register reviewed before every gate, every acceptance decision, every forecast, every escalation, is a decision instrument. The delivery approach changes the form as well as the cadence. Predictive projects review at gates and before every commitment change, leaning on the formal register, the contingency from chapters 15 and 18, and the transfer instruments. Adaptive projects carry the review inside the delivery cadence and the backlog, where a risk-reducing experiment is a backlog item like any other. Hybrid projects split the register by layer: the regulatory and contractual risks on a formal register with gate reviews, the product risks in the backlog with the delivery cadence, and the seam between the layers owned the way chapter 33 will teach. Crisis projects, Northstar’s first days, run the five-risk wall: the top five risks written where everyone can see them, reassessed as information arrives, because the full register is a luxury the emergency cannot afford. None of these is the right way. The right way is the cadence that matches the decision rate, and the failure is the cadence that matches the calendar.

Five moves and a trigger

Analysis sorts; response changes. The response strategies form a small family, and the family name is the action on the cause or the effect: avoid, transfer, mitigate, accept, and for the opportunities, exploit, enhance, share, accept. ISO 31000 describes the treatment options in its own vocabulary, avoiding the risk, removing the source, changing the likelihood, changing the consequences, sharing, and retaining; this family is that logic in a working arrangement. The vocabulary varies across the literature; the logic does not: every response acts on the cause or the effect and leaves something behind.

Avoid means changing the plan so the event cannot happen. At BlueLine, re-routing the eastern segment off the flood plain is avoidance: it costs more now and removes the seasonal risk entirely. Avoidance is the most expensive response and the only one that removes the risk, and its failure mode is avoiding the wrong thing, killing the value to dodge the risk, which is why avoidance decisions belong on the record with the value they protect.

Transfer means moving the risk to a party that can manage it, by contract, insurance, or partnership. Chapter 20 taught the discipline: transfer only what the counterpart can actually manage, and name the boundary, because a transfer to a party that cannot carry it is a premium paid for a claim returned. The outcome contract with Savanna is the example: the batch-window risk stayed with the bank, where the schedule lives; the reconciliation mechanism stayed with the platform, where the code lives; and the contract named the boundary, so the exceptions have an owner before they become complaints. Transfer changes the carrier, never the risk, and the risk dumper from chapter 20 is this response’s failure pattern.

Mitigate means reducing the likelihood or the impact, and the honest mitigation names which. The interruption test reduces the likelihood of the regression; the cohort cap reduces the impact of the residual orphan window; the super-users at the clinic sites reduce the likelihood of reversion to paper. The mitigation that reduces nothing is response theater, the training course never taken, the insurance never read, and the signal is the response column that says monitor for everything.

Accept means keeping the risk, with an owner, a trigger, a review date, and a named residual. Acceptance is a decision, and the decision is not abandonment. The residual risk is what remains after the response: the regression risk after the fix, the compressed construction season after the re-route decision, the unspent window after the convoy plan. The secondary risk is the risk created by the response itself: the fix creates the regression risk, the re-route creates the opposition to the new alignment, the super-user program creates the dependence on a few named people. The register row that has a response and no residual and no secondary risk is not finished; it is optimistic.

The trigger map is what makes the register actable, and it is the field output this chapter keeps returning to. Each accepted and mitigated risk carries the observable condition that fires the contingent response. At KijaniPay the triggers are concrete: the reconciliation monitor crossing its exception threshold; an early-close day predicted by the batch-window monitor with the orphan count above the floor; the regulator’s decision date passing with no decision; the rolling fraud-loss rate crossing the 0.5 percent guardrail. Each trigger has the response already written, the owner already named, the decision already delegated, so that the moment the trigger fires is a moment of execution, not a moment of rediscovery. The trigger map is one page: trigger, response, owner, date, and the authority that has pre-agreed to the action. The failure is the trigger that is itself a judgment call, “if things look bad,” which is not a trigger, it is a meeting, and the meeting will happen at the worst possible time, which is the point of having written the trigger down.

The response plan is the register’s second half: the first half names the risk, the second half names what will be done about it, by whom, triggered by what, with what residual. And the whole register, first half and second half, is only as good as its owners. The owner is a named person with the authority to act on the response, not the person who wrote the row and not a committee, and the test is the one the register failed in August: if no one can answer “what would change this assessment, and when will you look again,” the row has no owner, it has a caretaker.

The number that hides the shape

Most risks never need a number. The qualitative analysis sorts them, the responses carry them, and the arithmetic is reserved for the few where the stakes and the decision justify it: the risk that changes a gate, the choice between two responses with real money and real futures, the contingency question that chapters 15 and 18 will not answer for you. When the number earns its place, it appears in two forms, the exposure and the tree.

Exposure is the product of likelihood and impact, probability times consequence, and its honest use is comparison, not prediction. The KijaniPay residual before the fix makes it concrete. The cohort runs at 4,000 transactions a day, capped below the defect’s visible threshold. The campaign showed the pattern: on an early-close day, 2.5 percent of transactions fall outside the 24-hour promise, against the 99.5 percent baseline, so on such a day 100 exceptions stand against the baseline 20, 80 extra. At 15 minutes of investigation per exception, the extra load is 1,200 minutes, 20 hours, on that day. The campaign’s fourteen days carried four early-close days, so the frequency runs about 29 percent of days. The expected daily exposure is 0.29 times 20 hours, about 5.8 hours, roughly 41 hours a week, five analyst-days a week, absorbed by a known defect while the fix waited. In merchant money the same arithmetic runs: 4,000 transactions at 3,000 units each is 12 million units a day in motion, and the 100 exceptions on an early-close day delay 300,000 units, an expected 87,000 units a day, about 0.6 million units a week. The money is delayed, not lost, and the honest reading names the visible tip and the invisible mass: the five analyst-days and the delayed funds are the measurable exposure, and the promise breached and the trust spent are the exposure the arithmetic cannot price. Exposure is the comparison surface, and the caveat from chapter 15 applies: never report the product without the shape.

The tree is the second form, and it earns its name: a decision tree draws the decision as a branch, the chance as a circle, the outcomes as the leaves, and folds the uncertainty back into a single comparison, the expected value. It is the instrument for the question the gate-release review actually faces: deploy the fix now and take the regression risk, or hold it and pay the cost of delay.

Figure 22.2: The decision tree for the fix deployment at KijaniPay, drawn in the first week of December. The square on the left is the decision: deploy in the week of 8 December, or hold the fix in staging until January. Each branch reaches a circle, the chance node, with two outcomes and their probabilities. Deploy now: 0.85 probability the regression is clean, the broad launch lands on 22 December after the fourteen clean days, and the December value is realized, 6.0 million units; 0.15 probability a regression defect surfaces, rework and re-verification follow, the broad launch slips to mid-January, the December value is lost, and 1.5 million units of recovery cost are spent, a net of minus 1.5 million. Hold to January: 0.98 probability of a clean regression and a late-January launch worth 2.0 million units; 0.02 probability a defect slips it to February, 1.0 million of value against 0.5 million of recovery, a net of 0.5 million. The expected value of deploying now is 0.85 times 6.0 plus 0.15 times minus 1.5, which is 5.1 minus 0.225, 4.875 million units. The expected value of holding is 0.98 times 2.0 plus 0.02 times 0.5, which is 1.96 plus 0.01, 1.97 million units. The tree says deploy now, by about 2.9 million units.

The tree also says why it says that, which is the discipline that makes the arithmetic honest: the decision survives its own sensitivity. If the regression probability is not 0.15 but 0.30, the expected value of deploying now is 0.7 times 6.0 plus 0.3 times minus 1.5, 4.2 minus 0.45, 3.75 million, still well ahead of holding. The arithmetic flips only when the regression probability passes about 46 percent, and even then the two branches are equal: 6.0 times 0.46 minus 1.5 times 0.54 is 2.76 minus 0.81, 1.95 million, the same as holding. If the December value is not 6.0 million but 3.0 million, deploying now is worth 0.85 times 3.0 minus 0.225, 2.325 million, still ahead; the hold wins only if the December value falls below about 2.6 million. The tree is robust to the room’s plausible disagreements, and that robustness is information: the decision between the branches is not being made by a fragile assumption, it is being made by the real difference, the value of the December window against a regression risk the team has evidence to bound. And the mitigations that cut the 0.15, the canary deployment that rolls the fix to a staged slice first, the staged volume, the rehearsed rollback, the automated monitor, change the tree’s inputs, which is the point of mitigation in arithmetic.

The numbers rule has three cautions, and the chapter states them before the worked examples, because the reader will meet this arithmetic in real rooms. First, the expected value is a long-run average: if this decision repeated a thousand times, deploying now would average 4.875 million, and the project gets one draw, not a thousand, so the tree compares futures, it does not choose them. Second, the probabilities are estimates, and an estimate is only as good as its evidence: the 0.85 regression-clean figure is a judgment built from the test history and the change’s complexity, not a measurement, and the register row must say so, or the number is the confidence gambler’s. Third, the numbers do not carry the guardrail. The merchant promise and the fraud-loss threshold are nonnegotiables from chapter 2, and no expected value licenses a known breach. That is the same discipline chapter 4 taught about do-no-harm: the floor is not a probability, it is a floor. One more caution, and it is human rather than mathematical. The 0.15 branch will feel heavier than the arithmetic, because losses weigh roughly twice as heavily as gains of the same size in human decisions, the finding of Daniel Kahneman and Amos Tversky’s prospect theory, published in Econometrica in 1979. The room that feels the 1.5 million loss more than the 4.875 million expectation is not wrong, it is human, and the appetite conversation is where the feeling gets a name and a threshold instead of a veto.

Appetite is a governance decision

The tree compares futures; the appetite chooses between them. Risk appetite is the amount and type of risk an organization is willing to pursue or retain, the ISO 31000 vocabulary for the quantity that every probability sits against. The appetite is not a number on a scale. It is a governance decision, made by the sponsor and the leadership, stated per value dimension, and recorded, because the register’s likelihoods are meaningless without the threshold that says what they are allowed to mean.

The success profile from chapter 2 is the map for the appetite statement. KijaniPay’s profile named rapid market entry, fraud control, merchant adoption, and regulatory confidence, and the appetite is different on each dimension. On the merchant promise, the 99.5 percent reconciliation guardrail, the appetite is near zero: no known breach is acceptable, which is why the 17 November re-anchor chose the cohort over the full-volume launch, and why the fourteen-day evidence rule is not a schedule that can be renegotiated for the peak. On market-entry timing, the appetite is higher: the project accepted a controlled cohort before the fix was proven, trading a bounded residual for the December window. On the fraud-loss dimension, the 0.5 percent guardrail sets the same near-zero floor. The appetite statement is the charter from chapter 8 catching up with the governance: the charter named the top risks the sponsor accepted, and the appetite statement makes the acceptance explicit and reviewable, one page, per dimension, with the threshold that triggers action and the escalation path when the threshold is approached. The vocabulary separates the machinery: tolerance is the acceptable deviation around the objective, the band inside the guardrail; threshold is the level that triggers action, the monitor crossing its line; appetite is the posture, and tolerance and threshold are the machinery that enforces it.

The escalation is where appetite becomes behavior, and it has a quality standard that the register’s August failure shows from the negative. The escalation moves information to authority before it is too late, and the information arrives in the shape the chapter has built: the cause-event-effect row, the exposure, the response options with their owners and triggers, and the decision the project needs from the authority, the authority granted, the resource released, the threshold moved, the trade named. The escalation that arrives without the decision it needs is news; the escalation that arrives with options and a recommendation is a decision under construction. The discipline from chapter 12 applies with full force: the MUM effect, the measurable reluctance to transmit undesirable information, is why escalations are late, and the late escalation has already made everyone’s decisions for them, the transfer of cost that chapter 4 called the ethics of bad news. Said early, the license delay is information: the communication plan shifts, the cohort scope adjusts, the regulator’s office is called. Said late, the same fact is a betrayal with no options left. The project leader’s test for escalation timing is the same test the register applies to its rows: what would the authority do differently if it knew this now, and what will it be able to do if it finds out later.

The escalation also names its path, per the governance map from chapter 8: which risk rises to the steering committee, which to the sponsor, which stays with the team, because the appetite is set at the level that owns the dimension. The merchant promise at KijaniPay belongs to the sponsor and the leadership; the regression risk belongs to the engineering lead; the license belongs to compliance and the sponsor. The risk that crosses levels is the one that changed the value, not the one that changed the schedule, and the register’s top ten is the crossing list. The appetite statement is reviewed when the evidence changes: the campaign changed KijaniPay’s appetite on merchant onboarding, and the re-anchor was the appetite conversation made visible. A risk appetite that never moves is either a lucky document or a dead one.

The burndown and the dying register

The register decays, and the chapter has watched it decay on its own opening table. The decay is not a failure of diligence. It is a structural feature of a document with no decision attached to it. A document that exists to be maintained decays; a document that exists to be decided against survives. The failure pattern has five characters, and naming them is the failure-aware discipline.

The registrar maintains the register as ritual: the monthly update, the meeting read-aloud, the statuses refreshed, nothing changed, no decision taken. The signal is the register that grows and never shrinks, and the cost is the false assurance, the green status that the checkbox verifier from chapter 21 wears in risk clothes.

The vault keeper protects the register from challenge: the risks are private, the analysis is expert, the room is told the score, and the register becomes a tool of control rather than a system of decisions. The signal is the risk review where one person reads and everyone else nods.

The confidence gambler turns assessments into certainties: the 0.15 regression figure becomes “we are 85 percent safe,” the likelihood is carried to two decimal places no evidence supports, and the plan is bet on a number that was always a judgment. The signal is the register where every probability is precise and no probability has a source.

The risk evader accepts everything: the response column says accepted for every row, the triggers never fire, the residual is never named, and acceptance, which is a decision with an owner and a review date, becomes a dump for unmanaged risk. The signal is the acceptance that is never revisited.

And the amber swamp floods the register with mediums: every risk rated medium so that nothing escalates, the matrix a horizontal bar chart of one color, the leadership comfortable and the project unprotected. The signal is the review that changes nothing.

The repair has six moves, and the first is the burndown. The risk burndown plots the total exposure of the open risks over time, the sum of probability times impact across the register, or the count of open high-ranked risks, and it gives the risk system what the defect trend gave the quality system in chapter 21: a picture of the pattern instead of a pile of incidents.

Figure 22.3: The risk burndown at KijaniPay from 17 November to 20 December. The line starts high: the orphan window, the regression risk, the license, the adoption risk, the peak window. It falls in steps as the re-anchor decision caps the cohort, the fix lands on 5 December, the clean days accrue, and the peak value is secured. Two lines stay: the license, pending the regulator’s calendar, and the adoption evidence, pending the cohort’s performance. The burndown answers the question the gate review should ask first: is the total exposure falling, and is it falling for the reasons we think? The burndown that is flat while the team reports green is the whole chapter’s early warning, the same shape as the defect trend that stayed green while the promise drifted.

The other five moves: the register shrinks, and rows close with evidence, not with age, because a risk that materialized becomes an issue, a risk retired by evidence becomes a line in the lessons record, and a register that never shrinks is a register that never learns. The review runs at decision cadence, before gates and forecasts and escalations, not by the calendar. The top ten is the one page the leadership actually sees; the sixty below it are the team’s working file. Every row’s owner can answer the change question. And the register is wired to the decisions it feeds, so the document cannot drift from the work. The test is the one the opening failed: a new piece of risk information arrives, and the question is whether the register is where the next decision finds it. When the register is wired, the answer is yes, and the wiring is what keeps the registrar out of the room.

The machine drafts the future; the people own it

The machine can do real work in the risk system, and the boundary is the same one the book has drawn since the estimation chapter: the machine drafts, clusters, and summarizes; the people own the judgment, the appetite, and the signature. The machine can draft cause-event-effect statements from issue logs and incident reports, cluster a document store into candidate risk themes, flag register decay, rows without owners, without triggers, without review dates, generate the scenario prompts the next chapter will need, and draft the one-page top ten from a crowded register. Each of these is a draft or a signal until verified.

The verification is human, and it has three nonnegotiables. First, the sensitivity boundary from chapter 16 holds: merchant transaction data, settlement records, banking partner terms, regulatory filings, do not enter unapproved systems, and no analysis runs on data whose access rules have not been approved. Second, the machine cannot set the appetite, because the appetite is a value judgment held by the sponsor and the stakeholders, not a property of the text, and a generated risk list without an appetite statement is a list of futures with no permission to act. Third, the machine cannot own a response or sign an escalation, because ownership is an acceptance of obligation and an escalation is a claim on authority, both human acts, and a register row that shows a generated owner is the precise liar at speed. The machine’s draft of the register is a starting point for the room, and the room’s review is where the draft becomes a decision instrument, the same division of labor the acceptance campaign proved: the harness found the defect, and the people decided what the defect meant for the promise.

Practice

One. A quick classification. For each statement, name the term that fits best, risk, issue, assumption, constraint, ambiguity, or variability, and say what treatment it demands. (a) “The regulator’s published processing time is eight weeks, and the decision has not arrived.” (b) “The batch window will behave in December as it did in October.” (c) “The sweep might be interrupted by an early close.” (d) “Reconciliation must stay at or above 99.5 percent.” (e) “We are not sure what adoption will mean at the sixth clinic.” (f) “The volume could run anywhere from 4,000 to 40,000 transactions a day.”

(a) is a constraint, the published processing time is given, and the treatment is to plan within it, the trigger date and the escalation; the decision that has not arrived is a separate matter. (b) is an assumption, believed and unverified, testable with the batch-window monitor, and it carries an owner and a review date. (c) is a risk, an uncertain future effect with a cause, and it demands a cause-event-effect row, a response, and an owner. (d) is a constraint with a threshold, the guardrail from chapter 2, managed within, never traded. (e) is ambiguity, multiple possible meanings of the objective, and the treatment is discovery, the probes and prototypes of chapter 6, not a likelihood rating. (f) is variability, a range around an expected value, and the treatment is a range, a reserve, and a forecast, the material of chapters 15 and 38, not a register row per swing. The trap is treating all six with the same register, the kitchen drawer, which is the first failure this chapter named.

Two. A numbers drill: the exposure and the tree. Reproduce the chapter’s arithmetic, then extend it. (a) With the cohort capped at 4,000 transactions a day, confirm the expected weekly settlement-team load from the orphan window, 0.29 times 20 hours a day, and restate it in analyst-days. (b) Recompute the expected weekly analyst-days if the cap holds at 2,000 transactions a day and if it leaks to 6,000. (c) Recompute if the early-close frequency runs 2 of 14 days instead of 4 of 14. (d) Confirm the decision tree’s two expected values and the flip points, the regression probability near 46 percent and the December value near 2.6 million units. (e) State what changes in the tree if the mitigation cuts the regression impact from 1.5 million to 0.5 million units.

(a) 0.29 times 20 hours is 5.8 hours a day, about 41 hours a week, five analyst-days. (b) At 2,000 transactions a day, an early-close day leaves 50 exceptions against the baseline 10, 40 extra, 10 hours, expected 2.9 hours a day, about 20 hours a week, 2.5 analyst-days. At 6,000, 150 exceptions against 30, 120 extra, 30 hours, expected 8.7 hours a day, about 61 hours a week, 7.6 analyst-days: the exposure scales with the cap, which is why the cap is a control and why its leakage is the trigger. (c) At 2 of 14 days, the frequency is about 14 percent, 0.14 times 20 hours, 2.8 hours a day, about 20 hours a week, 2.5 analyst-days; at 6 of 14, about 43 percent, 8.6 hours a day, about 60 hours a week, 7.5 analyst-days: the frequency belongs to the partner’s calendar, and the contract from chapter 20 is the only lever the project has on it. (d) The tree’s arithmetic is reproduced in the chapter; the flip points come from solving 6.0 times p minus 1.5 times (1 minus p) equals 1.97, which gives p near 0.46, and 0.85 times V minus 0.225 equals 1.97, which gives V near 2.58, about 2.6 million. (e) If the mitigation cuts the regression impact to 0.5 million, deploying now is worth 0.85 times 6.0 minus 0.15 times 0.5, 5.1 minus 0.075, 5.025 million, and the flip probability rises to where 6.0 times p minus 0.5 times (1 minus p) equals 1.97, 6.5 times p equals 2.47, p near 0.38, which is the arithmetic of why mitigation is the honest lever: it changes the decision’s robustness, not just its score.

Three. A field drill: build the living register for your own project. Take the work you lead or know best. (a) Write the six vocabulary words and sort the project’s current uncertainty into them, one page, no more. (b) Rewrite the five risk statements on your current register into cause-event-effect form, one spine per row, with the effect stated against a named objective. (c) For the top three, draw a mini bow tie: causes, preventive controls, event, recovery controls, consequences. (d) Choose the response for each, avoid, transfer, mitigate, accept, and for at least one opportunity, exploit, enhance, share, or accept, and name the trigger, the owner, the residual, and the secondary risk. (e) Write the appetite statement for one value dimension and the threshold that escalates it.

The drill succeeds when every row passes the rewrite test, you can say what you would do differently having read it, and each row has an owner who can answer the change question, what would change this assessment, and when will you look again. The most common failure is the kitchen drawer, rows of different kinds mixed in one list, and the repair is the six-way sort. The second failure is the response column that says monitor for everything, and the repair is the trigger map, one page, trigger, response, owner, date. The third failure is the appetite statement that is a mood, “we are risk averse,” and the repair is the per-dimension threshold, the near-zero appetite on the promise, the higher appetite on timing, each stated so that a monitor crossing a line means something.

Four. A decision room: the gate-release review. It is 8 December at KijaniPay, and the facts are the chapter’s: the fix landed 5 December, four clean days have accrued, the reconciliation monitor has seven days of logs, the regression suite is green, the license decision is still pending on the regulator’s clock, and growth estimates that the last two weeks of December carry about 60 percent of the month’s onboarding value. The options: (a) proceed as planned, full volume gated on the full fourteen clean days, broad launch on 22 December; (b) proceed, but release the gate at ten clean days, broad launch on 18 December, capturing most of the final peak week, with the regression risk monitored; (c) hold the fix in staging until January, run a longer regression and a second volume campaign, broad launch late January; (d) proceed at fourteen days and add a constrained December program, the existing cohort expanding within the licensed scope while the broad launch waits. Decide what Zanele should recommend, what she should refuse, what the risk record must carry, and what evidence would change your answer.

The defensible answer is (d), with the reasoning of the tree and the appetite statement: the tree says the deploy is worth its regression risk, the appetite statement says the merchant promise is a near-zero-appetite dimension, and (d) holds both, the December value captured within the constraint and the fourteen-day evidence rule unbroken. The refusal is (b): releasing the gate at ten clean days renegotiates the evidence rule mid-clock for a few days of value, and the rule was the price of the re-anchor, the protection that let the cohort launch at all; a threshold that moves when the calendar presses is not a threshold, it is a mood, the amber swamp’s cousin. The refusal is also (c) if it is chosen without the tree: holding costs about 2.9 million units of expected value to avoid a regression risk the team has evidence to bound. The record must carry: the residual regression risk with its trigger, the reconciliation monitor crossing its exception threshold, its owner, the engineering lead, and its contingent response, the canary rollback; the license risk with its trigger date and its owner, Thandi; the appetite statement per dimension, the near-zero appetite on the promise, the bounded appetite on timing; and the escalation path, who the monitor breach reaches and what decision they are authorized to take. The evidence that would change the answer: if the regression suite had already run fourteen days in production-like conditions, the fourteen-day rule is satisfied by evidence and the broad launch moves up, which is (d) with the accelerator; if the regulator gives a decision date inside the fortnight, the license risk recedes and the December program expands with the licensed scope; if the cohort data shows the cap leaking, the promise is breached by the program itself, and (c) re-enters, because the near-zero appetite does not bargain. Credit belongs to any answer that keeps the promise and the evidence rule intact, captures the December value within the constraint, and records the risks with triggers, owners, and pre-agreed actions.

Five. The mastery drill: the vague statement and the spine. Rewrite each of the six statements into cause-event-effect form, then name the response, the trigger, the owner, and the residual risk. (a) “The bank might be slow and merchants will complain.” (b) “Adoption of the new platform might be lower than expected.” (c) “The corridor could be delayed by the flood plain.” (d) “The relief trucks might not get through.” (e) “Fraud losses could get out of hand.” (f) “We might lose a key person.”

(a) The campaign rewrote this row already: because the batch window closes early and the sweep is not idempotent, the sweep can be interrupted, leaving transactions pending and the 99.5 percent guardrail breached on those days. Response: the fix, mitigation of the mechanism; trigger: the monitor’s exception threshold or a predicted early-close day; owner: the engineering lead; residual: the regression risk of the fix itself. (b) At Meridian: because training is classroom-based and super-users are not rostered at the clinic sites during go-live, staff may revert to paper under workload pressure, and data quality and clinical workflow risk follow. Response: mitigate by rostering super-users and rehearsing go-live; trigger: the adoption metric crossing its threshold in the first go-live weeks; owner: the clinical adoption lead, the role chapter 8 found missing; residual: the clinics where the super-user ratio still lags. (c) At BlueLine: because the eastern segment sits on the flood plain and the drainage approval has no committed decision date, the flood-season construction window may be lost, slipping the segment a season and adding cost and political exposure. Response: mitigate by front-loading the drainage design, avoid by re-routing if the arithmetic allows; trigger: approval not issued by the decision date; owner: the consent manager; residual: a compressed construction season with its own weather risk. (d) At Northstar: because the northern route is unverified after the flood and the carrier’s safety record is thin, a convoy may be delayed or fail mid-route, leaving the hub short of tonnage and the grant window unspent. Response: avoid by using verified carriers and alternate routes, mitigate with scouts and checkpoints; trigger: a convoy missing its checkpoint time; owner: Mateo Herrera, the field logistics coordinator; residual: the speed trade-off of the alternate route. (e) At KijaniPay: because the fraud rules are validated against synthetic traffic and not real merchant behavior at volume, losses may breach the 0.5 percent guardrail during the peak, damaging the license narrative and merchant trust. Response: mitigate with the volume test and real-time loss monitoring; trigger: the rolling loss rate crossing the guardrail; owner: Kwame Mensah; residual: the window between detection and rule update. (f) Because the settlement engineer is the single point of knowledge on the banking interface, a resignation during the fix window would slip the fix and restart the clean-days clock. Response: mitigate with documentation and pair work, the chapter 19 discipline; trigger: notice given or the knowledge-transfer checklist behind; owner: the engineering lead; residual: reduced throughput while the replacement ramps. The unsafe answer is accepting any of the six as written, because a vague risk cannot be owned, and the whole drill’s test is the rewrite test: after rewriting, you can say what you would do differently.

Six. The transfer question. On the project you lead, where is the kitchen drawer, the one list holding issues, assumptions, constraints, and risks together, and what would the six-way sort reveal? Which row on your register fails the rewrite test, no mechanism, no trigger, no named objective in the effect, and what would the rewritten row say? Where is your risk information actually living, the acceptance matrix, the defect trend, the decision log, the heads of the people who met it, and what would it take for the register to be where the next decision finds it? And when did you last watch the burndown move, and was it falling for the reason you think?

The durable principle: risk management is a decision system, not a document, and the decision system runs on cause-event-effect spines, owned responses with triggers, an appetite stated per value dimension, and a review cadence set by the decisions it feeds. Uncertainty has six shapes, risk, issue, assumption, constraint, ambiguity, variability, and only the first belongs in the register. But the first has two faces, the threat and the opportunity, and the register that carries only threats is half a register. Name the mechanism, name the trigger, name the promise, name the owner, and the register will carry a decision; leave the row vague, and it will carry nothing but the meeting’s time. The arithmetic compares futures, the expected value and the tree, and the shape and the guardrail decide, because the appetite is the threshold that says what the probabilities are allowed to mean. The most common next failure is the one this chapter’s opening table embodied: the system is built, the campaign passes, the gate opens, and the register drifts back to ritual, updated monthly, read aloud, deciding nothing, until the next piece of evidence finds the document that missed the last three months. The control is the cadence and the wiring: the register reviewed when decisions are made, the burndown watched on the same rhythm as the schedule and the money, the rows closed with evidence and opened with spines. And the discipline has a frontier this chapter has only pointed at: the register names the risks the project can name, and some futures cannot be named in advance, the systemic disruption, the simultaneous failure, the condition nobody in the room has met. That is why the next chapter moves beyond the register to scenarios, stress tests, and the resilience that prediction cannot buy.

Notes

  • The composite cases remain author-created illustrative material. The KijaniPay gate-release review of 8 December, the fix landing on 5 December with the idempotent re-sweep, the orphan monitor, and the interruption tests at 12 million units and three weeks, the fourteen-day evidence clock with four clean days accrued by 8 December, the seven-day reconciliation monitor log, the cohort capped below the defect’s visible threshold from 30 November, the register last touched on 26 August, and all named characters and roles are the author’s teaching constructions consistent with the facts established in earlier chapters: the settlement promise of funds within 24 hours for 99.5 percent of merchant accounts and the 0.5 percent fraud-loss guardrail from chapters 2 and 17; the pilot of 400 merchants closing 15 October with the 8 percent late tail, from chapter 20; the campaign evidence, 98.9 percent average against the 99.5 percent promise, the early-close days, the non-idempotent sweep, and the orphaned pending ledger, from chapter 21; the 17 November re-anchor decision, the controlled cohort, and the fourteen-consecutive-clean-days gate, from chapter 21; the Savanna outcome-based contract with the boundary of responsibility, from chapter 20; the budget of 210 million units, from chapter 16; and the growth estimate that the last two weeks of December carry about 60 percent of the month’s onboarding value, the 6.0 million-unit December value, the 2.0 million-unit January value, the 1.5 million and 0.5 million recovery costs, and the 0.85 and 0.15 and 0.98 and 0.02 probabilities, all introduced here as explicit estimates for teaching, labeled as judgments in the text rather than measurements. The chapter’s arithmetic is reproducible from the text: at 4,000 transactions a day, an early-close day leaves 100 exceptions against the baseline 20, 80 extra, 20 hours; the campaign’s 4 of 14 early-close days give a frequency near 0.29; the expected daily load is 0.29 times 20 hours, about 5.8 hours, about 41 hours a week, five analyst-days; 4,000 transactions at 3,000 units is 12 million units a day in motion, 100 exceptions delay 300,000 units per early-close day, expected 87,000 units a day, about 0.6 million units a week; the decision tree’s expected values are 0.85 times 6.0 plus 0.15 times minus 1.5, 4.875 million, and 0.98 times 2.0 plus 0.02 times 0.5, 1.97 million; the probability flip point solves 6.0p minus 1.5(1 minus p) equals 1.97, giving p near 0.46, and the value flip point solves 0.85V minus 0.225 equals 1.97, giving V near 2.58; with the mitigation cutting the regression impact to 0.5 million, the deploy-now value is 5.025 million and the flip probability solves 6.5p equals 2.47, p near 0.38; the exercise extensions at 2,000 and 6,000 transactions a day and at 2 of 14 and 6 of 14 early-close days reconcile to the stated analyst-day figures.
  • The risk vocabulary follows primary sources in the author’s own words. ISO 31000:2018, Risk management: Guidelines, published by the International Organization for Standardization, defines risk as the effect of uncertainty on objectives and risk appetite as the amount and type of risk that an organization is willing to pursue or retain; its risk management process runs from establishing context and risk criteria through risk assessment, identification, analysis, and evaluation, to risk treatment and monitoring and review, and its treatment options include avoiding the risk, taking or increasing risk to pursue an opportunity, removing the source of risk, changing the likelihood, changing the consequences, sharing the risk, and retaining it; the chapter’s five-move family, avoid, transfer, mitigate, accept, is this book’s working arrangement of that treatment logic, not a reproduction of the standard’s text. IEC 31010:2019, Risk management: Risk assessment techniques, the companion standard to ISO 31000, catalogs the field’s analytical methods, including bow tie analysis, and the chapter’s bow tie follows that method’s structure of causes, event, preventive controls, consequences, and recovery controls, drawn and explained in the author’s own words. ISO 21502:2020, Project, programme and portfolio management: Guidance on project management, includes risk management among the practices of project management, treated generally here. The PMBOK Guide, Eighth Edition (Project Management Institute, November 2025) addresses risk within its performance domains, per the book’s reference baseline of 1 August 2026; this book describes the ideas in its own words and remains independent of PMI and the standards bodies.
  • The loss-aversion claim follows Daniel Kahneman and Amos Tversky, “Prospect Theory: An Analysis of Decision under Risk,” Econometrica 47(2), 1979, which found that losses loom larger than gains of the same magnitude in human decision making under risk; the chapter states the finding’s rough scale (“about twice”) as a directional description, not a measured constant. The reference class for comparable projects follows the reference-class forecasting material established in chapter 15, which drew on the Lovallo and Kahneman article in Harvard Business Review, 2003, and on the infrastructure overrun evidence of Bent Flyvbjerg, Mette K. Skamris Holm, and Søren L. Buhl, “Underestimating Costs in Public Works Projects: Error or Lie?” Journal of the American Planning Association 68(3), 2002; this chapter builds on that material rather than repeating it. The MUM effect reference follows the Rosen and Tesser studies of 1970 as established in chapter 12.
  • The chapter’s cross-references to chapters 2, 3, 4, 6, 8, 9, 12, 14, 15, 16, 18, 19, 20, and 21, and the previews of chapters 23, 33, and 38, follow the book’s outline. The failure characters, the registrar, the vault keeper, the confidence gambler, the risk evader, and the amber swamp, are the author’s own constructions, consistent with the failure-aware teaching style established in chapters 17 through 21. The six-word vocabulary, the kitchen drawer, the cause-event-effect spine, the rewrite test, the trigger map, the risk burndown, and the five-risk wall are the author’s method-neutral working instruments and names. The KijaniPay data-sensitivity discipline, that merchant transaction data, settlement records, banking partner terms, and regulatory filings do not enter unapproved systems, follows the data-boundary facts established in chapter 16. No proprietary certification manual, commercial text, or framework guide is reproduced or paraphrased here.