Risk Mitigation

A key step in risk management where the team designs and chooses a suitable response to a risk, aiming to reduce its likelihood, its impact, or both.

Key Points

  • Focuses on lowering a risk's probability and/or impact, not eliminating all uncertainty.
  • Involves selecting and planning concrete actions (e.g., spikes, tests, redundancy, training).
  • Actions are documented in the risk response plan and tracked in the risk register with owners and dates.
  • Results are monitored; residual and secondary risks are identified and managed.

Example

An agile team foresees a risk that a new encryption library could slow response times. They mitigate the risk by scheduling an early technical spike, adding automated performance tests to the CI pipeline, and setting a performance budget for each story. This reduces the chance and impact of performance degradation.

PMP Example Question

Which action best illustrates risk mitigation for a high-likelihood performance risk on an agile project?

  1. Set aside extra funds to cover potential rework if the risk occurs.
  2. Add early performance testing, run a spike to validate the approach, and optimize code paths.
  3. Purchase insurance to cover financial losses if the system performs poorly.
  4. Cancel the feature that might cause performance issues.

Correct Answer: B — Proactive steps to reduce the risk's likelihood and impact

Explanation: Mitigation reduces probability and/or impact through preventive actions (e.g., tests, spikes, optimization). Reserve funding is acceptance, insurance is transfer, and canceling the feature is avoidance.

AI Systems with Claude, for Scrum Masters and Project Managers

Most AI pilots in project management do not fail on the model. They fail because somebody pointed the thing at a decision instead of at a task. This course is built around that distinction, and around the work that follows once you get it right.

Seven sections, taught against one running project from the first lecture to the last. You watch a system get built, then you build the same one against your own sprint. Nothing here is a demo that works only on the example.

You finish with five working systems and you keep them. The sprint report machine turns your board export and standup notes into the report you currently write by hand. The retro intelligence system tells you what the team keeps saying, not just what it said this time. The stakeholder comms engine drafts the update in the register the audience expects. The backlog health monitor flags the quiet decay nobody has time to check for. The risk and dependency tracker follows the chains that actually bite.

Seventy-six working files ship with it, across four sections, so every system is built against real sprint data rather than material invented for a slide. Four sprints of retrospectives, board exports, standup notes, backlog and risk data.

Explore the Course


Lead with clarity, influence, and outcomes.

HK School of Management offers a practical Leadership for Project Managers course for real projects, tight deadlines, and cross-functional teams. Learn to set direction, align stakeholders, and drive commitment without relying on title. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Learn More