III.5 — Plan and Manage Risk
III.5 · Last updated: 24/08/2026
Where this task sits
III.5 — Plan and manage risk is a task in the Business Environment domain of the 2026 ECO. That domain carries 26% of the exam and holds eight tasks.
In the 2021 ECO, this topic was somewhere else entirely.
The move: from II.3 to III.5
| 2021 | 2026 | |
|---|---|---|
| Number | II.3 | III.5 |
| Domain | Process | Business Environment |
| Title | Assess and manage risks | Plan and manage risk |
Two things changed at once: the domain and the title. The shift from assess to plan looks small but moves the emphasis — from evaluating risks one at a time toward establishing an approach to risk up front.
That emphasis matches how the PMBOK® Guide frames the subject: the Risk performance domain describes managing risk as a way of creating project resilience, and argues for planning ahead paired with adaptive, flexible response mechanisms for when risks do occur (PMBOK® 8, Guide p. 92 — §2.7).
Why the domain change matters
Treat risk as a Process topic and you have placed it inside a domain weighted at 41%. In 2026 risk belongs to Business Environment, weighted at 26%, alongside compliance, governance, organizational change and external business environment shifts.
If you build your study plan around domain weights, where these topics count directly affects how many hours you give them.
🔴 Do not trust the number
This task is one of the clearest examples of number reuse in the 2026 ECO. In an older source:
- If it says II.3 and the topic is risk → the source is from 2021; that number now belongs to value-based delivery.
- If it says III.5 but the topic is not risk → also 2021, because that number belonged to a different task then.
Map material by title, never by number. The general form of this trap, with more examples, is in What changed in the 2026 PMP exam.
Risk runs both ways: threat and opportunity
This is the distinction most often missed under exam conditions. The PMBOK® Guide defines a risk as an uncertain event or condition that, should it occur, has a positive or negative effect on one or more project objectives (PMBOK® 8, Guide p. 272, glossary).
The Guide names the two directions separately: risks that could do harm are threats — delays, cost overruns, reputational damage — while those that could help are opportunities, such as increased market share, cost savings or a positive environmental impact (PMBOK® 8, Guide p. 93).
The practical consequence: "risk management" is not only about warding off bad outcomes. An option that proposes acting on an opportunity is not wrong by virtue of being positive.
Four classes of risk — and how they map to reserves
The Guide sorts risks into four boxes (PMBOK® 8, Guide p. 93, Figure 2-46):
| Class | Meaning |
|---|---|
| Known-known | Facts and requirements. Managed as part of scope — not a risk |
| Known-unknown | The classic risk: knowledge exists to identify probability and impact |
| Unknown-known | The knowledge exists in the community but not within the team doing the work |
| Unknown-unknown | Emergent risk; the knowledge does not exist in the sphere of influence |
That classification connects directly to the budget side:
- A contingency reserve is time or money allocated in the schedule or cost baseline for known risks that have active response strategies (PMBOK® 8, Guide p. 60; also Guide p. 192 and the glossary at Guide p. 266). It sits inside the cost baseline.
- A management reserve is held to cover unknown risks (PMBOK® 8, Guide p. 102) and sits outside it: the cost baseline excludes management reserves and can be changed only through formal change control (PMBOK® 8, Guide p. 118).
So the answer to "which reserve?" follows from which box the risk falls into.
Where qualitative and quantitative analysis part ways
The Guide treats risk analysis not as a single step but as an iterative process combining qualitative and quantitative actions. Qualitative analysis runs throughout the project, evaluating individual risks by assessing their probability of occurrence and their impact (PMBOK® 8, Guide p. 96).
In exam questions the distinction usually turns on this: do you have a list of risks that needs prioritising, or do you need to put numbers on the aggregate effect against project objectives?
When a risk becomes an issue
ECO task III.4 — Remove Impediments and Manage Issues explicitly asks you to recognise when a risk has become an issue — so these two tasks sit next to each other in practice.
The Guide's distinction is clean: an issue is a current condition or situation that has already occurred or is still occurring, and may demand immediate attention; a risk is a potential future problem that has not yet happened. An issue may well have arisen from a poorly managed risk (PMBOK® 8, Guide p. 93).
There is also overall risk — the effect of uncertainty on the project as a whole. Responses are the same as for individual threats and opportunities, only applied to the whole project rather than a specific event; and where overall risk runs too high, the organization may choose to cancel the project (PMBOK® 8, Guide p. 93).
About the citations
Every page number above refers to the PMBOK® Guide, Eighth Edition (PMBOK® 8); references to the 2026 ECO are marked "ECO" separately.
⚠️ PMBOK® 8 contains two separate books in one volume, and their page numbering is independent:
- The Standard for Project Management — cited as Standard p. X
- A Guide to the Project Management Body of Knowledge — cited as Guide p. X
All citations on this page come from the second part, the Guide. The numbers are the book's printed page numbers.
This page describes the book; it does not replace it.