Risk Identification and Risk Management: What’s the Difference?

Risk Identification and Risk Management

Risk identification and risk management are both important. You’ve identified the risks on your project, but that doesn’t mean you’re managing them. If you’re working in an earned value management environment or perhaps preparing for an Integrated Baseline Review (IBR), then it’s really important to show you can do both.

Even if you’re not managing your project to EVM guidelines, you’re still adding risk if you tick the risk identification box but fall short on follow-through (see what we did there?!).

In this article, we’ll summarize the difference between risk identification and risk management so you can be confident that you’re doing both well.

What is risk identification?

Risk identification is the process of uncovering and documenting what could go wrong.

It’s also worth noting that risk management isn’t just about stopping bad things from happening. Positive risks — or opportunities — should be tracked too. These might include favourable currency shifts, early task completions, or unexpected capacity. Identifying and planning to exploit them shows maturity and can give your project a competitive edge. However, in our experience, senior leaders are more interested in the risks that might derail the project, so often teams default to talking about what might go wrong.

You identify risks by using tools and techniques like brainstorming, checklists, assumptions analysis, and historical data from other projects. Typically, you’ll do this by yourself as the project manager and also with the team in workshops or team meetings.

The output of this thought process and conversations is a risk register or log — but that’s only the starting point.

We often see project managers who think the job is done once risks are captured, but that’s not the best way to deal with risk on your project.

What is risk management?

Risk management is the full lifecycle: planning responses, assigning ownership, monitoring, reviewing, and closing when the risk has either materialized (oops) or passed (phew).

IBR reviewers are looking for evidence that risks are actively tracked and controlled. In other words, that those risks you identified are being monitored and that you have action plans to make sure they don’t get worse and threaten to derail your project.

Good risk management is proactive, not reactive. It’s part of broader project controls, like EVM metrics and baseline performance. If you aren’t managing risks, you’re moving further and further away from a realistic schedule.

You might have a dedicated risk manager on the team, but it’s often down to the project manager to make sure that risk management is happening.

Why the distinction matters for your IBR (or other project audit)

So, when you are preparing for or going into an IBR or any other type of project audit, you’ll want to be able to speak knowledgably about both the identification steps you’ve taken as a team and how those risks are being actively managed.

Auditors want to see a living system, not a static list. Reviewers will spot whether active management is happening, and if they don’t think it is, it undermines confidence in the whole delivery plan.

Here’s an example:

  • Risk identified: “Key supplier may deliver the product later than expected.”
  • Risk managed: “Alternative supplier shortlisted, schedule adjusted with contingency, ongoing conversations with supplier to get early warning of supply chain issues.”

The documentation you prepare for this will include risk response plans, owner accountability, and evidence of follow-up.

How to move from risk identification to active risk management

If you’re doing the identification piece but falling behind on the risk management, here are some simple steps to get back on track.

  1. Assign risk owners. Give every risk a named person who will be responsible for managing and tracking it.
  2. Rate probability and impact (using qualitative or quantitative measures). This gives you a prioritization score so you know which risks you should be spending most of your effort on.
  3. Define response strategy (for example, avoid, mitigate, transfer, accept). Decide how you are going to manage the risk. The most common form of risk management is mitigation, where you create an action plan which minimizes the impact or probability, or both, of the risk.
  4. Track regularly (e.g. via risk meetings or RAID log). As the project manager, you are responsible for making sure this happens and that risk owners are bringing updates.
  5. Review impact on scope, cost, schedule. Take into account the impact on earned value for your project. Build in a risk budget or contingency if needed.

Invite team members to take turns leading risk updates during project meetings. It keeps ownership visible and reinforces shared accountability for managing uncertainty, because it should be everyone’s job.

Use your WBS and control accounts to anchor risk responses to specific deliverables. This can make it easier to cross-reference risks and also close them once the deliverable is completed.

What good looks like

Good risk management has the following aspects:

  • Risks linked to control accounts or work packages.
  • Regular updates and changing status as work on the management plan gets completed.
  • Visibility in project reporting and dashboards (mainly for the high ranked risks that need to be brought to management attention).
  • Inclusion in team discussions, not just formal project management updates.

The more you see these things embedded, the more useful risk management will be for ongoing project governance. And it will help your project shine at IBR or audit as well.

To summarize, identifying risks is essential — but that really is only the first step in the whole process of managing risk throughout the project lifecycle. Effective projects embed risk identification and risk management into planning and delivery from day one.

If your risk log hasn’t been updated since you sat down for planning workshops, now’s the time to revisit it. Going forward, block out some time in the team calendar for regular risk reviews and you’ll be well on the way to building great risk identification and risk management habits.