5.5. Plan and Manage Risk
💡 First Principle: Risk management is a continuous cycle — identify, analyze, respond, monitor — not a single risk-register document created at kickoff and revisited only when something goes wrong; the enablers explicitly include maintaining and communicating risk status throughout.
Enablers: identify risks, analyze risks, monitor and control risks, develop a risk management plan, maintain a risk register (e.g., poor IT security as an example risk), execute a risk management plan (e.g., risk response for security and managing sustainability risks), and communicate the status of risk impact on the project.
Notice the ECO's own examples explicitly name IT-security risk and sustainability risk — reinforcing that risk management now formally spans beyond classic schedule/cost/scope risk into security and environmental risk categories, consistent with Business Environment's broadened 2026 scope.
⚠️ Exam Trap: Limiting risk-response thinking to schedule and cost impacts only. The 2026 ECO explicitly expects security and sustainability risk categories to be part of your risk register and response planning, not treated as someone else's domain.
Reflection Question: Does your current risk register include security and sustainability risk categories, or only classic schedule/cost/scope risks? What would adding them change about your top risk priorities?