← ArticlesThreat and Opportunity Response StrategiesProject Delivery · RiskLesson 1/7← PrevNext →
GuidePublished 13 Aug 202613 min readBy Kevin Joginrisk responsethreat strategiesopportunity strategiesrisk acceptance

Project Delivery · Project Risk Management

Threat and Opportunity Response Strategies

A balanced guide to avoiding, transferring or sharing, mitigating or enhancing, exploiting and accepting project uncertainty.

14 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

A balanced guide to avoiding, transferring or sharing, mitigating or enhancing, exploiting and accepting project uncertainty. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Confirm the risk and objective
  • Generate threat and opportunity options
  • Compare effectiveness and ownership
  • Select combined strategies
  • Document residual and secondary risk
  1. Confirm the risk and objective
  2. Generate threat and opportunity options
  3. Compare effectiveness and ownership
  4. Select combined strategies
  5. Document residual and secondary risk

Why Analysis Without Action Is Wasted Effort

A beautifully constructed risk register, a meticulously populated probability-impact matrix, and a professionally executed Monte Carlo simulation are all worthless if they do not lead to concrete, actionable response strategies that change the project's risk profile. The corresponding activity in the earlier process model — Plan Risk Responses — is where risk management transitions from analysis to action. It is the process of developing options and actions to enhance opportunities and reduce threats to project objectives.

Every response strategy must satisfy five criteria to be effective: it must be appropriate to the significance of the risk, cost-effective in meeting the challenge, realistic within the project context, agreed upon by all parties involved, and owned by a responsible person. A response that is theoretically elegant but practically unaffordable, or one that no individual is accountable for implementing, will fail when the risk materialises.

What Is the corresponding activity in the earlier process model — Plan Risk Responses?

Inputs Tools & Techniques Outputs
Risk Management Plan Strategies for Negative Risks or Threats Project Management Plan Updates
Risk Register Strategies for Positive Risks or Opportunities Project Document Updates
Contingent Response Strategies
Expert Judgment

The process takes the prioritised, analysed risk register and assigns a specific response strategy — along with an owner, budget, timeline, and trigger conditions — to each risk that warrants action.

How It Works: Four Strategies for Threats

When a risk represents a threat — an uncertain event that would negatively impact project objectives if it occurred — the project team selects from four possible strategies:

1. Avoid — Eliminate the Risk Entirely

Avoidance involves taking action to reduce the probability of the risk and/or its impact to zero. This typically means changing the project plan to circumvent the risk entirely — altering scope, schedule, strategy, or approach to remove the source of uncertainty.

Avoidance is the most decisive strategy, but it is not always possible. Some risks are inherent to the project scope and cannot be eliminated without fundamentally changing what the project delivers.

2. Transfer — Shift the Liability

Transfer involves shifting the management burden and financial impact of a risk to a third party. It does not eliminate the risk — it simply ensures that if the risk materialises, someone else bears the consequences.

Common transfer mechanisms include:

Mechanism How It Works Defence Context
Insurance The insurance company assumes financial liability in exchange for a premium Construction all-risk insurance covering physical damage during facility build
Fixed-Price Contracts The contractor assumes cost overrun risk in exchange for a price premium Fixed-price subcontract for hull fabrication — the subcontractor bears the cost risk of material price increases
Performance Bonds A surety guarantees the contractor's performance; if the contractor fails, the surety pays Performance bond on a critical subsystem supplier ensuring delivery of a qualified product
Warranties and Guarantees The supplier assumes post-delivery risk of defects or failures Extended warranty on a propulsion system covering defects discovered during the first 5,000 operating hours

3. Mitigate — Reduce Probability and/or Impact

Mitigation involves taking early action to reduce the probability of the risk occurring, its impact if it does occur, or both. Mitigation does not eliminate the risk — it reduces it to an acceptable level.

Mitigation Approach What It Targets Defence Manufacturing Example
Reduce probability Makes the risk event less likely to occur Conducting additional prototype testing before committing to a production design — reducing the probability of production-stage design rework
Reduce impact Limits the damage if the risk event occurs Pre-qualifying an alternative titanium supplier so that if the primary supplier fails, the schedule impact is weeks rather than months
Reduce both Addresses probability and impact simultaneously Implementing a comprehensive welding quality programme with enhanced NDE inspection — reducing both the probability of defects and the impact of any defects that occur (caught earlier, fixed cheaper)

Mitigation is the most commonly applied strategy and the one that demands the most creativity and engineering judgment. The project manager must balance the cost of mitigation against the expected cost of the risk — a mitigation action that costs more than the expected value of the risk it addresses is not cost-effective.

4. Accept — Acknowledge and Prepare

Acceptance is the strategy chosen when the team decides to take no proactive action to address a risk, either because the risk is assessed as low-priority or because the cost of any other strategy would be disproportionate to the risk itself.

Acceptance comes in two forms:

Passive acceptance — the team simply acknowledges the risk and decides to deal with it if and when it occurs, without pre-planning a specific response. Active acceptance — the team establishes a contingency reserve (time, money, or resources) that will be deployed if the risk materialises. This is the more disciplined form of acceptance and is appropriate for risks that are well-understood but deemed too expensive or impractical to avoid, transfer, or mitigate.

How It Works: Four Strategies for Opportunities

When a risk represents an opportunity — an uncertain event that would positively impact project objectives if it occurred — the project team selects from four parallel strategies:

1. Exploit — Make It Happen

Exploitation aims to ensure that the opportunity is realised with certainty. This involves taking decisive action to capture the upside potential.

2. Share — Partner for Mutual Benefit

Sharing involves allocating some or all of the ownership of the opportunity to a third party who is best able to capture it for the benefit of the project. Sharing mechanisms include:

3. Enhance — Increase the Odds

Enhancement increases the probability that the opportunity will occur, its positive impact if it does, or both.

4. Accept — Be Ready If It Comes

Acceptance of an opportunity means being willing to take advantage of it if it materialises, but not actively pursuing it. This is appropriate for opportunities with low probability or where the cost of exploitation, sharing, or enhancement exceeds the expected benefit.

Contingent Response Strategies

Contingent response strategies are a special category of response that bridges the gap between proactive planning and reactive execution. A contingent response is a pre-planned action that is only triggered when specific predefined conditions are met.

The key characteristics of contingent responses are:

Pre-planned: The response is designed and resourced in advance, not improvised in the heat of a crisis. Conditional: The response is only activated when a specific trigger event occurs — a leading indicator that the risk is about to materialise. Time-sensitive: There must be sufficient warning between the trigger event and the risk impact to allow the response to be implemented effectively.

The Mirror Symmetry: Threats and Opportunities Side by Side

The four threat strategies and four opportunity strategies are mirror images of each other, reflecting the dual nature of risk as both downside and upside uncertainty:

Threat Strategy Action ↔︎ Opportunity Strategy Action
Avoid Eliminate the risk entirely ↔︎ Exploit Ensure the opportunity is realised
Transfer Shift liability to third party ↔︎ Share Allocate to partner best able to capture
Mitigate Reduce probability/impact ↔︎ Enhance Increase probability/impact
Accept Acknowledge with contingency ↔︎ Accept Be ready to take advantage

This symmetry is not just conceptual elegance — it reminds the project manager that every risk assessment should consider both the threat and opportunity dimensions. A regulatory change, for example, might threaten the current design approach while simultaneously creating an opportunity to leapfrog competitors by adopting a more advanced solution ahead of the compliance deadline.

How It Works: Outputs

Project Management Plan Updates

The risk management plan itself may need modification as response strategies are developed. Response strategies that involve scope changes, additional procurement, or schedule modifications will ripple into the schedule management plan, cost management plan, and procurement management plan.

Project Document Updates

The risk register is updated to include, for each prioritised risk:

Common Pitfalls

Selecting a strategy without costing it. Every response strategy has a cost — even acceptance (through contingency reserves). If the cost of mitigation exceeds the EMV of the risk, the strategy is not economically rational unless non-financial factors (safety, reputation, regulatory compliance) override the financial calculus. Failing to assign a risk owner. A response strategy without an accountable individual is a response strategy that will not be executed. The risk owner must have the authority, resources, and accountability to implement the response when required. Ignoring secondary risks. Every response strategy can introduce new risks. Transferring risk through a fixed-price contract may introduce a secondary risk that the contractor cuts quality. Mitigating a schedule risk by adding overtime may introduce a secondary risk of workforce fatigue and error rates. These secondary risks must be identified, assessed, and added to the register. Defaulting to acceptance for everything. Acceptance is the easiest strategy to "implement" because it requires no immediate action. Lazy risk management manifests as a register full of "accepted" risks with poorly sized contingency reserves. True acceptance is a deliberate, informed decision — not the absence of a decision. Treating response planning as a one-time event. As the project progresses and the risk landscape evolves, response strategies must be reviewed and updated. A mitigation strategy that was appropriate during the design phase may be irrelevant during the integration phase.

Key Takeaways

From Strategy to Documentation: Controls and Treatment Plans

The Controls Register — Documenting What's Already in Place

Before planning new responses, the project team must understand what controls are already in place and whether they are working. The Controls Register is the document that captures this information.

The Controls Register structure is straightforward:

Column Purpose
Ref Cross-reference to risk register entry
The Risk Risk event title
Details of Existing Controls Complete description of each control measure currently in place

The value of the Controls Register lies in forcing an honest assessment of current risk exposure. Many project teams discover, when they actually document existing controls, that:

Worked Example — Site Security Controls

Consider the "Trespassers" risk from a construction site. The Controls Register documents four existing controls:

Ref Risk Control Description
P1 Trespassers All visitors to the Site are required to report to the office
P1 Trespassers No trespassing signs located around site perimeter
P1 Trespassers Staff requested to ensure all buildings are locked when not occupied
P1 Trespassers Site fitted with intruder alarms and exterior security lighting

These controls fall into two categories:

Preventive controls (reduce the likelihood of the risk occurring):

Detective controls (reduce the time to detect and respond when the risk occurs):

The risk register's assessment that implementation is "Inadequate" might reflect that staff are not consistently locking buildings, that the visitor reporting requirement is not enforced at all entry points, or that the intruder alarm system has not been tested recently. This assessment drives the need for a Treatment Plan.

The Treatment Plan — Documenting What Will Be Done

The Risk Treatment Plan documents the response actions for risks that require further intervention beyond existing controls. It is the action plan that closes the gap between current residual risk and the target risk level.

The Treatment Plan structure captures the full decision-making chain:

Column Purpose
Ref Cross-reference to risk register
The Risk Risk event title
Possible Treatment Options All options considered — not just the preferred one
Preferred Options The selected treatment approach
Cost/Benefit Assessment & Resource Requirement Economic justification
Risk Rating After Treatment Expected residual risk level post-implementation
Responsible Officer Named individual accountable for implementation
Timeline Implementation schedule
Outcome from Action Documented result after implementation

Worked Example — Trespasser Treatment Plan

For the P1 Trespassers risk, the Treatment Plan documents four treatment options:

Treatment 1 — Security Guards at Events

Treatment 2 — Comprehensive Visitor Management Policy

Treatment 3 — Equipment Security

Treatment 4 — Physical Security Upgrades

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Confirm the risk and objective is defined, owned, evidenced and linked to the relevant project decision.
Check 02Generate threat and opportunity options is defined, owned, evidenced and linked to the relevant project decision.
Check 03Compare effectiveness and ownership is defined, owned, evidenced and linked to the relevant project decision.
Check 04Select combined strategies is defined, owned, evidenced and linked to the relevant project decision.
Check 05Document residual and secondary risk is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

NEXT LESSON →Project Risk Treatment and Action PlansGuide · RiskRisk Controls and Defence in DepthGuide · RiskRisk Triggers, Contingencies and Early WarningGuide · RiskRisk Monitoring, Reporting and ControlGuide · Risk