Skip to content

Strategic Business Leader · Leading and managing projects

Project Risk Management and Control for ACCA SBL

Updated 11 October 2026 · Fact-checked

Project risk management means identifying risks to a project's objectives, assessing their likelihood and impact, choosing a response (avoid, reduce, transfer or accept) and reviewing them throughout. Project control means comparing actual progress with the plan on time, cost, scope and quality, then taking corrective action. In SBL, apply both to the case.

Understand Project Risk Management and Control

A project is a temporary effort with a defined scope, budget, timescale and quality standard. A project risk is an uncertain event or condition that, if it happens, affects one or more of those objectives. It can be a threat (delay, overspend) or an opportunity (a cheaper supplier, an early finish).\n\nProject risk is not the same as business risk. Business risk relates to the organisation's strategy and operations as a whole, such as competitors, demand or regulation. Project risk relates to delivering one project. The two link: a late or failed project can damage strategy, and a strategic change can create project risk. In SBL, show that link.\n\nRisk management is a cycle. You identify risks (workshops, checklists, past projects, stakeholder input, PESTEL, SWOT). You assess them by likelihood and impact, often on a risk register or a likelihood-impact grid. You respond to them and then monitor and review. Typical sources of project risk are unclear scope, poor estimates, weak sponsorship, resource shortages, technology, suppliers, stakeholder resistance and external change.\n\nControl is the second half. A baseline plan sets the agreed schedule, budget and quality targets. You track actual progress against it through progress reports, milestones, budget-to-actual reviews, earned value, Gantt charts and critical path updates, and steering group meetings. Where there is a variance, you find the cause and decide on action, such as adding resources, re-scoping, re-planning or escalating.\n\nChange control matters too. Scope creep is uncontrolled growth in scope. Any change request should be assessed for its effect on time, cost, quality and risk, and formally approved before it is made. Good control also needs clear roles: the project manager runs the project day to day, the sponsor owns the business case, and a steering committee oversees it.

Key rules to remember

Risk exposure
Risk exposure = likelihood of the risk × impact if it occurs
Used to rank risks. Likelihood can be a probability or a high/medium/low score. Impact can be in money or a score.
Risk responses (TARA)
Transfer | Avoid | Reduce | Accept
Choose one for each threat. Transfer through insurance or contracts, avoid by not doing the activity, reduce through controls, accept and monitor if the exposure is within appetite.
Cost variance
Cost variance = budgeted cost of work done − actual cost of work done
A negative figure means overspend. Use only if the question gives earned value data.
Schedule variance
Schedule variance = budgeted cost of work done − budgeted cost of work planned
A negative figure means behind schedule.
Control loop
Plan → Measure actual → Compare to baseline → Investigate variance → Correct and re-plan
The structure for any project control answer.

How to solve Project Risk Management and Control questions

Use this method for any question on project risk or control. Always tie each point to the facts in the scenario.

  1. 1Read the requirement. Decide whether it asks you to identify risks, assess them, recommend responses, or design monitoring and control.
  2. 2Define the project objectives from the case: time, cost, scope, quality and the business benefit.
  3. 3Identify risks from the scenario facts, and group them (technical, people, supplier, external, stakeholder). Separate project risks from wider business risks.
  4. 4Assess each main risk by likelihood and impact, and say which ones are most serious and why.
  5. 5Recommend a specific response for each, using TARA, and link it to the risk appetite of the organisation.
  6. 6Set out how you will monitor and control: baseline, milestones, reports, variance analysis, change control and escalation to a sponsor or steering group.
  7. 7Add professional skills: a balanced view, scepticism about estimates and reports, and a clear recommendation in the format requested (report, memo, briefing).

Quickest way: Risk, response, review in three lines

When to use it: Use this when time is short and you must produce a structured plan of points in a few minutes.

  1. For each risk write: risk from the case, rating (likelihood and impact), response.
  2. Add one control for each objective: time (milestones), cost (budget review), quality (acceptance tests), scope (change control).
  3. Finish with who reviews it and how often, such as a weekly project meeting and monthly steering group, and what triggers escalation.

Common mistakes in Project Risk Management and Control

  • Listing generic risks that could apply to any project.

    Students recall a textbook list instead of reading the case.

    Fix: Quote or paraphrase a fact from the scenario for each risk, then explain the effect on the project.

  • Confusing project risk with business risk.

    Both use the same vocabulary and the terms are used loosely.

    Fix: State the difference briefly: project risk affects delivery of the project, business risk affects the organisation's strategy. Then show how one feeds the other.

  • Identifying risks but not assessing or responding to them.

    Identification feels easy and is the first thing students think of.

    Fix: For every risk, give a rating and a response. Prioritise the top few risks rather than listing everything.

  • Treating control as only checking the budget.

    Cost is the most visible measure.

    Fix: Cover time, cost, scope, quality and benefits, and explain the action taken when a variance appears.

  • Suggesting responses that do not fit the risk, such as insuring against a risk that is a poor-quality plan.

    TARA is memorised without thinking about what each response can do.

    Fix: Ask whether the risk can really be transferred, avoided or reduced. Use insurance or fixed-price contracts only for risks a third party can bear.

  • Ignoring professional skills and the audience.

    Students focus on technical content only.

    Fix: Use the requested format, give a clear recommendation and show balance, such as the cost of a control compared to the risk.

Worked examples

Example 1

Medira Co is building a new patient records system across five hospitals. The project is two months behind plan. The main software supplier is a small firm that has lost two senior developers. Hospital managers keep asking for extra features. Advise the board on the main project risks and how to respond.

Show the solution
  1. Identify the risks from the case: supplier capability (loss of developers), schedule slippage already under way, and scope creep from the hospital managers.
  2. Assess them: supplier failure has medium likelihood but high impact because the whole system depends on it. Scope creep has high likelihood and is already adding time and cost. The delay is a current issue, not a risk, so it needs corrective action now.
  3. Respond to supplier risk by reducing it: ask for a staffing plan and key-person cover, add contract clauses for penalties and code escrow, and identify an alternative supplier as a fallback. Transfer some risk through a fixed-price contract for defined work.
  4. Respond to scope creep by avoiding uncontrolled change: set up formal change control where every request is assessed for time, cost and risk and approved by the steering group.
  5. Control the delay: re-baseline the plan with realistic estimates, find the critical path, and consider adding resources or phasing roll-out hospital by hospital.
  6. Monitor weekly through progress reports and milestones, with escalation to the sponsor if slippage grows further.

Answer: The main risks are supplier capability, scope creep and the existing delay. Reduce supplier risk through contract terms and a fallback, control scope through formal change control, and recover the schedule by re-planning and phasing, with weekly monitoring and escalation to the steering group.

Example 2

A project has a budget of $400,000 for the work planned to date. The work actually completed is worth $360,000 at budgeted cost. Actual spend to date is $390,000. Calculate the schedule and cost variances and explain what they tell the project manager.

Show the solution
  1. Budgeted cost of work planned = $400,000. Budgeted cost of work done (earned value) = $360,000. Actual cost = $390,000.
  2. Schedule variance = 360,000 − 400,000 = −$40,000. The project is behind schedule by work worth $40,000.
  3. Cost variance = 360,000 − 390,000 = −$30,000. The project has spent $30,000 more than the budgeted value of the work done.
  4. Interpretation: the project is both late and over budget, so it is not just a timing problem. The cause may be poor estimates, rework or low productivity.
  5. Action: investigate causes, review the remaining estimate, check if the risk register needs updating, and report to the steering group with options such as re-scoping, adding resources or re-baselining.

Answer: Schedule variance is −$40,000 (behind schedule) and cost variance is −$30,000 (overspent). The project manager should find the causes, re-forecast the final cost and date, and escalate with options.

Exam tips

  • Link every risk and control to the case facts. Generic lists score poorly.
  • Show the difference between project risk and business risk when the requirement mentions strategy or the board.
  • Prioritise: discuss the two or three most serious risks in depth rather than ten in a line each.
  • Where a task asks for monitoring, name specific tools and the action taken on variances, not just 'review progress'.
  • Write in the format requested and end with a clear recommendation to earn professional skills marks.

Practice questions from Leading and managing projects

Project Risk Management and Control in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Project Risk Management and Control: frequently asked questions

What is the difference between project risk and business risk?

Project risk is uncertainty that affects a project's time, cost, scope or quality. Business risk affects the organisation's strategy and operations as a whole. They overlap, because a failed project can harm the business, and business conditions can create project risk.

How do you monitor and control a project in the SBL exam?

Compare actual progress with the baseline plan using milestones, budget reports and quality checks. Investigate any variance and take corrective action. Use change control for scope changes and escalate serious issues to the sponsor or steering group.

What are the main responses to project risk?

The four responses are transfer, avoid, reduce and accept (TARA). Choose the one that suits the risk and the organisation's appetite. For example, reduce supplier risk through contract terms and a fallback supplier.

Do I need to calculate earned value in SBL?

Calculations are rare in SBL, which is mostly narrative and case based. Know the idea of schedule and cost variance so you can interpret figures if they are given. Spend most of your effort on applying risk and control concepts to the scenario.