2.2.3. Analyzing and Prioritizing Risk
💡 First Principle: Every identified risk gets rated; only a few get modeled. Qualitative analysis is a fast, subjective rating applied to every risk to decide which ones deserve attention — quantitative analysis is optional numeric modeling applied only to the handful that already made the cut. Candidates lose points by treating these as two names for the same step.
Section 2.2.2 said the risk register captures each risk's "likelihood and impact." This section covers where those two values actually come from, because the exam tests the distinction between the two ways of producing them far more often than it tests the register itself.
| Qualitative risk analysis | Quantitative risk analysis | |
|---|---|---|
| Question it answers | "Which risks matter most?" | "What is the combined effect on cost or schedule?" |
| How it works | Rates each risk on probability and impact using a defined scale | Models the numbers to produce a range of outcomes |
| Typical techniques | Probability and impact matrix, risk categorization, urgency assessment | Monte Carlo simulation, expected monetary value, decision tree, sensitivity analysis |
| Applied to | Every identified risk | A shortlist that qualitative analysis already prioritized |
| Always performed? | Yes, on essentially every project | No — optional, and usually reserved for large or complex projects |
| Output | A prioritized risk list | A probability distribution or a monetary figure |
Qualitative analysis: rating and ranking. The workhorse tool is the probability and impact matrix, a grid that crosses how likely a risk is against how much damage it would do. A risk rated high probability / high impact lands in the red corner and gets attention first; low/low goes on a watch list. Multiplying the two ratings gives a risk score used to rank the register. The whole exercise is quick, needs no specialist software, and is repeated every time the register is reviewed — which is why it happens on every project regardless of size.
⚠️ Exam Trap: Numbers do not make an analysis quantitative. A probability and impact matrix that rates risks 1 through 5 is still qualitative — a 4 means "someone judged this fairly likely," not "this was measured." The distinction is subjective rating versus numeric modeling, not the presence of digits.
Quantitative analysis: modeling the numbers. Where qualitative analysis ranks risks against each other, quantitative analysis asks what they add up to across the project as a whole. Three techniques account for nearly every exam question on this:
- Monte Carlo simulation runs the project's cost or schedule model thousands of times, each run drawing a different value from the range estimated for each activity. The output isn't a single date — it's a distribution, which lets a team say something like "we have an 85% confidence of finishing on or before 14 March." This is the technique most often named as the example of quantitative analysis, and the one the exam reaches for when it wants to test whether you can tell the two analyses apart.
- Expected monetary value (EMV) multiplies a risk's probability by its impact in currency. A 30% chance of a $50,000 rework carries an EMV of −$15,000. EMV is what populates the branches of a decision tree when a team is choosing between options that each carry different risks.
- Sensitivity analysis asks which single variable moves the outcome most, holding the others steady. Its usual visual is a tornado diagram, whose bars are sorted longest-first so the variables with the greatest influence sit at the top.
⚠️ Exam Trap: Quantitative analysis is not performed on every project, and never on every risk. It is resource-intensive and follows qualitative analysis, operating only on the shortlist qualitative analysis produced. An answer choice claiming a team should run a Monte Carlo simulation across the entire risk register before prioritizing anything has the order backwards.
Where the money for risk sits. Analysis produces two different pots of money, and the exam tests which one a scenario is describing. A contingency reserve covers identified risks — the ones already in the register with an assessed probability and impact. It sits inside the cost baseline, and the project manager can generally draw on it without going back for approval. A management reserve covers unknown risks, the ones nobody anticipated. It sits outside the cost baseline but inside the total project budget, and using it normally requires management or sponsor approval — and, because it changes the baseline, a change request.
⚠️ Exam Trap: "The risk was in the register and its response cost more than expected" points to the contingency reserve. "Something nobody had identified happened" points to the management reserve. Watch for scenarios describing a project manager unilaterally spending management reserve — that authority almost always sits above the PM.
Why the order matters more than the vocabulary. It's tempting to memorize the two definitions and stop, but nearly every scenario question on this topic turns on sequence rather than on naming: identify before you analyze, analyze qualitatively before you analyze quantitatively, and analyze before you plan a response. A scenario describing a team that discovers a risk and immediately buys insurance against it has skipped the analysis that would tell them whether the risk was worth insuring — and that skipped step, not the insurance, is what the question is testing.