Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.2.3. Analyzing and Prioritizing Risk

💡 First Principle: Every identified risk gets rated; only a few get modeled. Qualitative analysis is a fast, subjective rating applied to every risk to decide which ones deserve attention — quantitative analysis is optional numeric modeling applied only to the handful that already made the cut. Candidates lose points by treating these as two names for the same step.

Section 2.2.2 said the risk register captures each risk's "likelihood and impact." This section covers where those two values actually come from, because the exam tests the distinction between the two ways of producing them far more often than it tests the register itself.

Qualitative risk analysisQuantitative risk analysis
Question it answers"Which risks matter most?""What is the combined effect on cost or schedule?"
How it worksRates each risk on probability and impact using a defined scaleModels the numbers to produce a range of outcomes
Typical techniquesProbability and impact matrix, risk categorization, urgency assessmentMonte Carlo simulation, expected monetary value, decision tree, sensitivity analysis
Applied toEvery identified riskA shortlist that qualitative analysis already prioritized
Always performed?Yes, on essentially every projectNo — optional, and usually reserved for large or complex projects
OutputA prioritized risk listA probability distribution or a monetary figure

Qualitative analysis: rating and ranking. The workhorse tool is the probability and impact matrix, a grid that crosses how likely a risk is against how much damage it would do. A risk rated high probability / high impact lands in the red corner and gets attention first; low/low goes on a watch list. Multiplying the two ratings gives a risk score used to rank the register. The whole exercise is quick, needs no specialist software, and is repeated every time the register is reviewed — which is why it happens on every project regardless of size.

⚠️ Exam Trap: Numbers do not make an analysis quantitative. A probability and impact matrix that rates risks 1 through 5 is still qualitative — a 4 means "someone judged this fairly likely," not "this was measured." The distinction is subjective rating versus numeric modeling, not the presence of digits.

Quantitative analysis: modeling the numbers. Where qualitative analysis ranks risks against each other, quantitative analysis asks what they add up to across the project as a whole. Three techniques account for nearly every exam question on this:

  • Monte Carlo simulation runs the project's cost or schedule model thousands of times, each run drawing a different value from the range estimated for each activity. The output isn't a single date — it's a distribution, which lets a team say something like "we have an 85% confidence of finishing on or before 14 March." This is the technique most often named as the example of quantitative analysis, and the one the exam reaches for when it wants to test whether you can tell the two analyses apart.
  • Expected monetary value (EMV) multiplies a risk's probability by its impact in currency. A 30% chance of a $50,000 rework carries an EMV of −$15,000. EMV is what populates the branches of a decision tree when a team is choosing between options that each carry different risks.
  • Sensitivity analysis asks which single variable moves the outcome most, holding the others steady. Its usual visual is a tornado diagram, whose bars are sorted longest-first so the variables with the greatest influence sit at the top.

⚠️ Exam Trap: Quantitative analysis is not performed on every project, and never on every risk. It is resource-intensive and follows qualitative analysis, operating only on the shortlist qualitative analysis produced. An answer choice claiming a team should run a Monte Carlo simulation across the entire risk register before prioritizing anything has the order backwards.

Where the money for risk sits. Analysis produces two different pots of money, and the exam tests which one a scenario is describing. A contingency reserve covers identified risks — the ones already in the register with an assessed probability and impact. It sits inside the cost baseline, and the project manager can generally draw on it without going back for approval. A management reserve covers unknown risks, the ones nobody anticipated. It sits outside the cost baseline but inside the total project budget, and using it normally requires management or sponsor approval — and, because it changes the baseline, a change request.

⚠️ Exam Trap: "The risk was in the register and its response cost more than expected" points to the contingency reserve. "Something nobody had identified happened" points to the management reserve. Watch for scenarios describing a project manager unilaterally spending management reserve — that authority almost always sits above the PM.

Why the order matters more than the vocabulary. It's tempting to memorize the two definitions and stop, but nearly every scenario question on this topic turns on sequence rather than on naming: identify before you analyze, analyze qualitatively before you analyze quantitatively, and analyze before you plan a response. A scenario describing a team that discovers a risk and immediately buys insurance against it has skipped the analysis that would tell them whether the risk was worth insuring — and that skipped step, not the insurance, is what the question is testing.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder20 professional certifications