A project manager is creating the risk management plan. Which document should the project manager reference to identify the risk tolerance of stakeholders?
Trap 1: Project scope statement
The project scope statement defines deliverables and boundaries, not stakeholder risk appetite; that tolerance is recorded in the risk management plan's inputs such as the project charter and stakeholder register. It is tempting because scope drives risk identification, and would be correct when clarifying what work is in scope.
Trap 2: Stakeholder management plan
The stakeholder management plan records engagement approaches and communication needs, not the risk tolerances used to calibrate the risk management plan. Risk tolerance thresholds are documented in the risk management plan itself or the project charter, which is where they would be referenced.
Trap 3: Risk register
The risk register records identified risks, owners and responses; it does not document stakeholder appetite for risk. It is the correct reference for monitoring and reviewing active risks during execution, but risk tolerance thresholds come from the stakeholder analysis captured in the risk management plan inputs.
- A
Project scope statement
Why it fails: The project scope statement defines deliverables and boundaries, not stakeholder risk appetite; that tolerance is recorded in the risk management plan's inputs such as the project charter and stakeholder register. It is tempting because scope drives risk identification, and would be correct when clarifying what work is in scope.
- B
Stakeholder management plan
Why it fails: The stakeholder management plan records engagement approaches and communication needs, not the risk tolerances used to calibrate the risk management plan. Risk tolerance thresholds are documented in the risk management plan itself or the project charter, which is where they would be referenced.
- C
Project charter
The project charter records the sponsor's and key stakeholders' risk appetite and tolerance, since it authorises the project and defines its boundaries. The risk management plan draws those tolerance thresholds from the charter rather than inventing them, making it the correct reference.
- D
Risk register
Why it fails: The risk register records identified risks, owners and responses; it does not document stakeholder appetite for risk. It is the correct reference for monitoring and reviewing active risks during execution, but risk tolerance thresholds come from the stakeholder analysis captured in the risk management plan inputs.