KEVOS
ArticlesServicesCase studiesAboutContact
ArticlesServicesCase studiesAboutContact
← ArticlesRisk — Three Levels & Quant ToolsProject Delivery · RiskLesson 17/31← PrevNext →
GuidePublished 12 Aug 2026Updated 13 Aug 20268 min readBy Kevin Jogin
On this page

Ask about this page

KEVOS AIRisk — Three Levels & Quant Tools

KEVOS knowledge first · trusted web sources when needed

Risk — Three Levels & Quant Tools

POSTER 13
Section 4 · Risk Management — Scaling & Quantifying

Risk Across the Three Levels & Quantitative Tools

This standard's signature idea: risk is managed at project, program and portfolio levels — each with a different focus and horizon — and risks cascade and escalate between them. Below: what risk means at each level, plus the quantitative tools that turn uncertainty into numbers.

Visual Map — One Risk Discipline, Three Altitudes

LevelRisk is about…Primary focusHorizonOwner
PortfolioStrategic objectives & the balance/mix of components; aggregate exposure vs risk capacityDoing the right mixLong / strategicPortfolio governance
ProgramRisks between components & their interdependencies; threats to benefits & integrationCoordinated benefitsMediumProgram manager
ProjectRisks to scope, schedule, cost, quality of a specific deliverableReliable deliveryShort / tacticalProject manager

Escalation & cascade: a project risk beyond the PM's authority escalates up to program or portfolio; strategic decisions and constraints cascade down. Consolidated reporting rolls individual risks into an overall picture at each level.

Expected Monetary Value (EMV)

EMV = Σ (probability × impact); impacts are signed (− threat, + opportunity).

  • Threat: 20% × (−$500k) = −$100k
  • Opportunity: 30% × (+$200k) = +$60k
  • Net EMV = −$40k → size the contingency accordingly.

Feed EMVs into a decision tree to choose the option with the best expected value (e.g. build vs buy).

Modelling Overall Risk

  • Monte Carlo: simulate thousands of runs → a range & confidence (e.g. P80 cost/finish).
  • Sensitivity / tornado: rank which risks swing the outcome most.
  • Decision tree: compare options by EMV under uncertainty.
  • Outputs justify reserves and feed the cost baseline (EVM).

Probability & Impact Matrix (Qualitative)

Prob ↓ / Impact →LowMediumHigh
HighMediumHighHigh
MediumLowMediumHigh
LowLowLowMedium

Score = probability × impact → a priority that drives response order & depth.

Exam Concepts

  • Portfolio = strategic / aggregate; program = interdependencies & benefits; project = delivery.
  • Risk capacity (portfolio) sets the ceiling that appetite sits within.
  • Escalate up, cascade down; aggregate vs individual risk.
  • EMV, Monte Carlo & decision trees are quantitative.

Executive View

  • Portfolio risk is a strategy & capacity conversation, not a register.
  • Consolidated, roll-up reporting gives the board one risk picture.

Industry Example — A Defence Prime

Defence
  • Portfolio: balance the mix of bids & live programs against capacity.
  • Program: integrate ship + combat system + training so the capability benefit lands.
  • Project: deliver the radar subsystem on cost & to spec.

Memory Hooks

  • Portfolio = right mix · Program = right benefits · Project = right delivery.
  • "Risk rolls up; response rolls down."
  • Reserves: contingency = knowns I control; management = unknowns the boss controls.
60-sec Review Risk focus at each level Escalate up vs cascade down Compute a 2-line EMV What Monte Carlo gives you Capacity vs appetite
PMI Visual Wall · Poster 13 · Risk — Three Levels & Quantitative Tools · original instructional design · A3 landscape

Handbook application: from concept to controlled practice

Purpose. This expanded section turns the original page into a practical handbook. It preserves the supplied material and adds a repeatable way to apply, check and review Risk — Three Levels & Quant Tools. It does not replace a contract, legislation, a controlled standard, competent engineering judgement or specialist advice.

The operating aim is to convert the subject into a governed decision, owned work, usable evidence and a reviewable outcome. Read the original explanation first, then use the workflow and checks below to convert knowledge into evidence.

Use Risk — Three Levels & Quant Tools as a decision instrument rather than an administrative form. The subject terms—risk, three, levels, tools, quant—need an explicit connection to the project objective, business value and stakeholder commitments. Before completing the artefact, write one sentence stating who will use it, what decision it supports and when that decision is required.

Apply a disciplined information model. Separate facts supported by evidence, forecasts derived from a method, assumptions awaiting validation, constraints that limit choice, risks that may occur, issues that already exist and actions assigned to people. Each material entry should have an owner, date, status and next review point. Where probability or impact scores are used, define the scale so different reviewers interpret it consistently.

A baseline is useful only when changes are visible. Give the artefact an identifier, version, approval state and effective date. Define which changes require reapproval, how superseded versions are retained and where supporting evidence is stored. During reviews, focus on exceptions, decisions and trends rather than reading every field aloud. Record the decision and rationale, not merely that a meeting occurred.

Close the loop beyond delivery. Confirm acceptance criteria, unresolved items, transferred responsibilities and operational ownership. Where benefits are expected, identify the outcome measure, baseline, target, observation period and owner who remains accountable after the project team disbands. Lessons should describe the condition, consequence and reusable action; a generic statement such as “communicate better” cannot improve the next project.

Step-by-step operating method

  1. Clarify the decision. Name the outcome, sponsor, affected stakeholders and decision that this work must enable.
  2. Set boundaries. Record scope, assumptions, constraints, dependencies, tolerances and escalation conditions.
  3. Plan the evidence. Define deliverables, measures, owners, due dates and acceptance criteria before execution.
  4. Control delivery. Compare actual performance with the baseline, assess changes and manage risks and issues explicitly.
  5. Close the loop. Confirm acceptance, transfer ownership, capture lessons and track benefits beyond handover.

Completion and governance protocol

Start with a short drafting workshop involving the accountable owner and the people who hold the evidence. Complete high-consequence fields first: objective, scope, owner, baseline, acceptance, dependencies and escalation. Mark unknowns as assumptions or actions rather than hiding them behind vague prose. Circulate a review draft, resolve conflicting interpretations, baseline the approved version and place the next review date in an owned schedule.

Information typeMinimum useful contentReview test
OutcomeObservable change and intended recipientNot merely a deliverable or activity
MeasureDefinition, baseline, target, frequency and sourceTwo reviewers would calculate it the same way
OwnershipOne accountable role plus contributors and approverAuthority matches responsibility
UncertaintyAssumption, risk or issue with response and triggerStatus reflects current reality
ControlVersion, approval, review date and change ruleCurrent baseline is identifiable

Common failure modes and recovery actions

1. Watch for

Producing a document with no named decision or accountable owner.

Recovery: Return to the governing definition or requirement and restate the decision in one sentence.

2. Watch for

Mixing risks, current issues, assumptions and actions in one unstructured list.

Recovery: Separate evidence from assumption, assign an owner and set a date for validation.

3. Watch for

Measuring activity or output while leaving the intended outcome undefined.

Recovery: Run a small counterexample, boundary test, pilot or independent check before proceeding.

4. Watch for

Accepting changes without evaluating effects on value, scope, schedule, cost and risk.

Recovery: Record the consequence, decision and rationale, then update the controlled baseline.

5. Watch for

Closing the project at delivery even though benefit ownership has not transferred.

Recovery: Escalate when the issue affects safety, compliance, acceptance, material value or an agreed tolerance.

Review checklist

  • Which decision or commitment does this artefact support?
  • Who owns each action, risk, acceptance and post-project benefit?
  • What is the baseline and what variance triggers escalation?
  • Where is the evidence that the result was accepted and transferred?
  • Are mandatory requirements distinguished from recommendations and illustrative values?
  • Are sources, assumptions, units, dates and versions recorded closely enough to reproduce the decision?
  • Have safety, legal, ethical, stakeholder and operational consequences been considered at the appropriate level?
  • Is there a named owner and a trigger for review, escalation, change or retirement?

Questions for deeper application

What is the most important distinction a practitioner must preserve when applying Risk — Three Levels & Quant Tools?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

Which assumption about risk would change the result most if it proved false?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

What evidence would allow an independent reviewer to reproduce or challenge the conclusion?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

Which boundary, exception or failure case has not yet been tested?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

What must be handed over, monitored or reviewed after the immediate work is complete?

Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.

Authoritative references and use notes

The sources below were selected as institutional or primary guidance for the broader practice. They support the handbook method; they do not imply that every statement or clause in a source applies to every project. Confirm the current edition, jurisdiction, contract and application before treating any requirement as mandatory.

  • Risk Management in Portfolios, Programs, and Projects: A Practice Guide — Project Management Institute. Used for risk practices across portfolios, programs and projects. Accessed 2026-08-13.
  • ISO 31000 family — Risk management — International Organization for Standardization. Used for principles and guidance for enterprise risk management. Accessed 2026-08-13.

Implementation record: minimum fields

Create a compact record alongside the work. Include the purpose, context, responsible owner, stakeholders or affected users, inputs and sources, assumptions, method, acceptance or decision criteria, result, limitations, approval status, version and next review trigger. A reader should be able to understand not only what was concluded but why it was reasonable at the time.

Use plain language for decisions and reserve technical notation for places where it improves precision. Link every conclusion to the evidence that supports it. Where a source is secondary, old, proprietary or outside the applicable jurisdiction, note that limitation. Never silently turn a typical value, worked example, recommendation or software default into a mandatory requirement.

Handover and continual improvement

Before closing the work, identify what remains uncertain and who owns it. Transfer calculations, source records, models, approvals, test evidence, open actions and operating limits together. Agree how future users will recognise that the context has changed. Typical triggers include a new requirement, changed load or population, supplier or software revision, incident, repeated exception, capability shift, audit finding or adverse trend.

At the next review, compare the original assumptions with actual outcomes. Retain decisions that remain supported, correct weak controls and retire content that no longer reflects current practice. This feedback step converts a static article or template into a learning system and prevents old examples from becoming accidental policy.

Continue learning

Policy ValidationGuide · RiskActor–Critic MethodsGuide · RiskRisk — Process & ResponsesGuide · RiskNEXT LESSON →Exploration & ExploitationGuide · Risk
KEVOS · Engineering, manufacturing and project improvement
ArticlesServicesCase studiesAboutContact
© 2026 KEVOS®