Project Risk Management Risk Appetite, Tolerance & Governance 1 — Questions and Answers
Question 1: Which term describes the amount and type of risk an organization is willing to accept in pursuit of its objectives?
- Risk appetite (Correct answer)
- Risk threshold
- Risk velocity
- Risk exposure
Correct answer: Risk appetite
Risk appetite is the broad level of risk an organization is prepared to accept before action is needed, reflecting its strategic stance toward uncertainty.
Question 2: How does risk tolerance differ from risk appetite?
- Risk tolerance is the acceptable variance around specific objectives, while risk appetite is the broader strategic willingness to accept risk (Correct answer)
- They are interchangeable terms in project risk management
- Risk tolerance applies only to financial risks
- Risk appetite is set by the project team, not the organization
Correct answer: Risk tolerance is the acceptable variance around specific objectives, while risk appetite is the broader strategic willingness to accept risk
Risk appetite is the overarching strategic stance, while risk tolerance defines the acceptable range of variation around a specific objective or metric.
Question 3: Who is primarily responsible for defining an organization's risk appetite?
- Senior leadership and the board of directors (Correct answer)
- The project manager
- Individual risk owners
- The project management office (PMO)
Correct answer: Senior leadership and the board of directors
Risk appetite is a strategic decision made at the organizational level by senior leaders and the board, reflecting corporate culture and strategic objectives.
Question 4: A project team identifies a risk that falls within the organization's risk tolerance. What is the appropriate response?
- Accept the risk and monitor it passively (Correct answer)
- Escalate it immediately to the sponsor
- Apply an aggressive mitigation strategy
- Transfer the risk to a third party
Correct answer: Accept the risk and monitor it passively
Risks within tolerance levels are acceptable and typically require only monitoring, as they do not exceed the boundaries the organization has set.
Question 5: Which governance body is typically responsible for overseeing risk management practices on large projects?
- Risk management committee or steering committee (Correct answer)
- The project scheduler
- Individual team leads
- The client's procurement department
Correct answer: Risk management committee or steering committee
A risk management committee or steering committee provides governance oversight, ensures risk policies are followed, and makes decisions on risks beyond project authority.
Question 6: What document formally establishes how risk appetite and thresholds are applied within a project?
- Risk management plan (Correct answer)
- Project charter
- Risk register
- Communications management plan
Correct answer: Risk management plan
The risk management plan defines risk thresholds, tolerance levels, and governance structures that guide how risks are managed throughout the project.
Which term describes the amount and type of risk an organization is willing to accept in pursuit of its objectives?