Accept or Mitigate. There is no try, er... Avoid or Transfer...
The four traditional risk responses aren't correct. Kinda.
Project management is rife with what I call MMBPs, or Myths, Misunderstandings, and Bad Practices. These are common and persistent bits of “conventional wisdom” in project management that are taught, repeated, and passed down, but don’t actually hold up once you look closely. Both new and experienced PMs fall prey to MMBPs. For example, the conventional wisdom of “four risk responses” is one of these common misunderstandings.
“(Real) risk comes from not knowing what you’re doing.” — Warren Buffett
What’s the Myth:
Almost every PM and Risk Management training program teaches the same thing: when you identify a threat, you have four responses available (a/k/a “treatments”) to consider applying: Avoid, Transfer, Mitigate, or Accept.
This four-response idea is repeated so often that nobody questions it anymore.
But it’s wrong. You don’t have four options. You actually only have two options: accept or mitigate.
Why It’s Wrong:
Every risk is quantifiable by two numbers: probability and impact. This is true for both negative risks (threats) and positive risks (opportunities). Probability is a measure of how likely the risk will materialize (i.e., be “realized”). Impact is a measure of how big an effect, good or bad, the realized risk will have on the project. If you multiply probability and impact, you get risk exposure.
For negative risks, we want to minimize exposure. For positive risks, we want to maximize exposure. In both cases, we evaluate each risk and, where appropriate, strive to change its probability and/or impact. For threats, taking action to reduce probability and/or impact is called mitigation. (For opportunities, taking action to increase probability and/or impact is called enhancement.)
Once you see risks this way, the “four responses” fall apart.
Mitigate means reducing probability and/or impact by some amount, not necessarily to zero. But if we can drive the probability to zero, we’ve actually avoided the threat. For example, our team made a design change that completely removed a technical threat. We’ve made the likelihood of the technical threat zero, so we’ve “avoided” the threat. But this really is just mitigation in the extreme.
Similarly, transferring a threat just means eliminating the impact from your project and putting somewhere else (e.g., onto an insurer, a subcontractor, a partner). The threat is still real, but if it materializes, it won’t impact you. I.e., you’ve driven the direct project impact to zero, therefore “transferring” the threat off your project. But again, this is just mitigation in the extreme.
Both avoidance and transference are just edge cases of mitigation, which by definition is the act of reducing probability and/or impact.
Said another way, Avoid and Transfer aren’t separate categories. Calling them their own responses is like calling a square and a rectangle two different geometrical shapes. A square is just a special type of rectangle (one whose side ratios have been pushed to the extreme). Avoid and Transfer work the same way: they’re no different from mitigation; they’re just mitigation where probability or impact has been pushed all the way to zero.
So, really, there are only two fundamental choices when facing a risk:
Accept the risk as-is.
Mitigate it (reduce probability, reduce impact, or both).
How to Actually Do This:
When you identify a threat, and after you’ve estimated its probability and impact, you should always ask these two questions in this order:
Can/should/must we accept it? If probability × impact is low enough already, it’s probably not worth spending time or money on to make it smaller; just accept it and move on. Sometimes the calculus is more forced: there’s genuinely nothing that will move probability or impact, or the cost of trying to mitigate exceeds the exposure itself. Either way, the answer is the same: accept it and make sure your contingency reserves cover the residual risk exposure.
If you can’t/shouldn’t/mustn’t accept the risk, how do we mitigate it? Can we cost-effectively reduce the probability? The impact? Both? Push each as far as you appropriately can. If you can push probability to zero, great, you’ve “avoided” the threat altogether. Similarly, if you can push the impact of the threat on your project to zero, great, you’ve “transferred” it. Either way, you were just mitigating; you simply mitigated hard enough to hit an edge case.
Example:
We’re adding an extension onto a house. A threat has been identified: “If heavy rain occurs on concrete foundation pour day, we would have to cancel the pour and would experience a schedule delay.”
Following the two-step process above, our first question when facing a new risk like this should always be whether we can/should/must accept this risk as-is or not? If the likelihood of rain is low and the impact is just a lost day or two, we can probably just accept the risk as-is. Or, if the cost of rescheduling is high and there’s nothing we can do to eliminate the threat of rain, we might have to accept the risk as-is.
But imagine it’s the rainy season, and contractors are very busy and backlogged. A schedule delay of even one day could lose our spot in the concrete contractor’s work queue, which could turn a one-day rain delay into weeks or months of actual schedule slippage. Here, we need to consider mitigating the threat. If there’s any chance of re-planning our schedule to move this aspect of the work into a dry period, driving the probability toward zero, we should consider it.
Similarly, we could reduce the impact of rain on the work by, say, spending money to build a temporary tarp structure to cover the work, which would allow us to work regardless of the rain. Here, we could drive the impact of rain to zero. We “avoid” the impact, but really we just mitigated it.
Bottom Line:
Okay, I’ll admit that this isn’t really a big deal, and I’m being a little finicky and precious with the terminology… but I believe in using words precisely. This is especially important in our profession of project management. If someone continues to use the conventional 4-responses-to-a-threat approach in their risk management processes, will it matter? Not directly, no, but too often we take things as fact without really understanding what we’re doing. When you say you’re going to avoid a risk, what you’re really doing is simply mitigating it by driving down its probability. As long as you understand that, you can use whatever terminology you want.
Bottom line: we either accept risks or we mitigate them. Everything else is just fancy words for the same thing: mitigation.




