As part of the project plan development for a modification to a legacy system, you need to explain to management what project risk management is all about. What explanation would you give to management?

Project risk management is an important aspect of project management. According to the Project Management Institute's PMBOK, Risk management is one of the ten knowledge areas in which a project manager must be competent. Project risk is defined by PMI as, "an uncertain event or condition that, if it occurs, has a positive or negative effect on a project’s objectives."[1]

Project risk management remains a relatively undeveloped discipline, distinct from the risk management used by Operational, Financial and Underwriters' risk management. This gulf is due to several factors: Risk Aversion, especially public understanding and risk in social activities, confusion in the application of risk management to projects, and the additional sophistication of probability mechanics above those of accounting, finance and engineering.

With the above disciplines of Operational, Financial and Underwriting risk management, the concepts of risk, risk management and individual risks are nearly interchangeable; being either personnel or monetary impacts respectively. Impacts in project risk management are more diverse, overlapping monetary, schedule, capability, quality and engineering disciplines. For this reason, in project risk management, it is necessary to specify the differences (paraphrased from the "Department of Defense Risk, Issue, and Opportunity Management Guide for Defense Acquisition Programs"):

    Risk Management: Organizational policy for optimizing investments and (individual) risks to minimize the possibility of failure.
    Risk: The likelihood that a project will fail to meet its objectives.
    A risk: A single action, event or hardware component that contributes to an effort's "Risk."