On 29 April 2007 a tanker fire collapsed a section of the MacArthur Maze interchange in Oakland, California. Caltrans wrote a $200,000-per-day early-completion bonus into an $867,075 repair contract, capped at $5 million, with a matching daily penalty for lateness.
C.C. Myers reopened Interstate 580 on the evening of 24 May and collected the full cap. That is what positive risk looks like when an organization deliberately engineers it into a project rather than standing back and waiting to get lucky.
Almost no project team does this. The standards have required attention to upside for years, and the registers we review still record threats in one column and nothing at all in the other, which is the gap this guide closes.

Project professionals believe they capture opportunities. Measured exploitation rates tell a different story.
What Positive Risk Actually Means Under the Standards
Positive risk is not optimism, and it is not the absence of a threat. It is an uncertain event that would help the project if it occurred, carrying the same three attributes as any threat: a cause, a probability and a quantified effect.
ISO 31000:2018 defines risk as the effect of uncertainty on objectives, and its first note is unambiguous. An effect is a deviation from the expected, and it can be positive, negative or both, and can address, create or result in opportunities and threats.
PMI reaches the same place through different wording. Its Lexicon of Project Management Terms defines a risk as an uncertain event with a positive or negative effect on objectives, an opportunity as a risk with a positive effect, and a threat as one with a negative effect.
| What positive risk is not | What positive risk is |
| Optimism, or a good feeling about the project | An uncertain event with a named cause and a quantified upside |
| The absence of a threat | A separate register entry with its own probability and value |
| A benefit already in the business case | Value the business case did not assume and does not depend on |
| Scope creep by another name | An outcome the sponsor would fund a response to capture |
| Something to note and move on from | An entry with an owner, a date and a budget line |
The fourth row is the one that settles most arguments in a workshop. If nobody would spend real money to make it more likely, then it is not a positive risk you are managing, it is a pleasant thought that somebody wrote down.
The Evidence That Positive Risk Gets Recorded and Then Ignored
Practitioners generally believe they handle this well. An Association for Project Management survey of its corporate members found more than 70 percent believed they were effective at capturing opportunities, while over 60 percent still associated the word risk exclusively with negative outcomes.
Register data flatly contradicts that self-assessment. A peer-reviewed study of twelve separate projects, each above USD 100 million in value, found that opportunities made up just 15.5 percent of identified uncertainties, thirty-five entries against a total of two hundred and twenty-six.

Across 226 identified uncertainties, only 35 were opportunities and only nine were ever exploited.
The attrition after identification is worse than the identification rate itself. Of those thirty-five opportunities only nine were ever exploited, so roughly three quarters of the positive risk these teams managed to name went on to produce nothing at all.
One project in that study identified twenty-eight threats and not a single opportunity. The authors also observed workshops producing eight to ten times as many threats as opportunities, which is a facilitation problem rather than a feature of the projects.

Threat impact ran eight to ten times the opportunity value realised on the same portfolio.
Read that asymmetry carefully, because it is easy to misread and frequently is. It shows what teams actually captured rather than what was available to them, so it measures the effort spent on each side of the ledger rather than the underlying distribution of upside.
The Positive Risk Response Strategies, as PMI Defines Them Today
Most articles on positive risk describe five opportunity strategies facing five threat strategies in a neat and reassuring symmetry. That symmetry is tidier than the source material actually supports, and checking the current definitions is worth the two minutes it takes.

Three strategies are opportunity-specific, three are threat-specific, and two carry a single shared definition.
| Strategy | PMI definition | What it looks like on a real project |
| Exploit | Act to ensure the opportunity occurs | Restructure the schedule so the favourable weather window is used, not hoped for |
| Enhance | Increase the probability of occurrence or impact | Fund early supplier involvement to raise the chance of a design saving |
| Share | Allocate ownership to the third party best able to capture it | Gain-share clause giving the contractor a cut of savings they generate |
| Escalate | Transfer ownership to a relevant party in the organization | Route a cross-programme opportunity to the portfolio board, off the project register |
| Accept | Acknowledge the risk and take no action unless it occurs | Log the favourable currency movement, bank it if it lands, spend nothing chasing it |
Escalate and accept carry one definition each in the current Lexicon rather than separate opportunity and threat versions. A positive risk that is escalated leaves your register entirely, which teams often record as closure when it is nothing of the kind.
How to Identify Positive Risk Without Drifting Into Wishful Thinking
The reason positive risk columns stay empty is rarely philosophical. Standard identification prompts are written in the language of failure, so failure is what they return, and a workshop asking only what could go wrong will never surface what might go unexpectedly right.
| Prompt that produces threats | Prompt that produces positive risk |
| What could delay us? | What would have to be true for us to finish a month early? |
| Which supplier might fail? | Which supplier could do more than the contract asks, and what would that be worth? |
| Where might costs overrun? | Which assumption in the estimate is deliberately conservative, and by how much? |
| What could go wrong technically? | What have we learned since the baseline that makes something easier than planned? |
| What are the market threats? | Which market movement would help us, and how would we be positioned to use it? |
Run the right-hand column as a separate session with its own timebox and its own facilitator. Positive risk identification loses every time it competes for airtime inside a threat workshop, because threats feel urgent while opportunities feel optional to everyone in the room.
Our practice is to require a minimum count rather than to encourage. Ask for five opportunities before the session closes, and the discipline works exactly like the structured question sets we use for threats, as our eight-step assessment guide sets out.
Scoring and Quantifying Positive Risk So Finance Takes It Seriously
An opportunity with no number attached will lose to a threat with one, every single time. The fix is to score positive risk on the same anchored scale you already use, and to express its expected value in the same currency.
| Band | Probability anchor | Value anchor | Required response |
| Major | Above 60 percent | Above 5 percent of budget | Funded exploit or enhance action, sponsor visibility |
| Significant | 30 to 60 percent | 1 to 5 percent of budget | Named owner, costed plan, monthly review |
| Moderate | 10 to 30 percent | 0.2 to 1 percent of budget | Tracked, reviewed quarterly, no funding yet |
| Marginal | Below 10 percent | Below 0.2 percent of budget | Accept and monitor, spend nothing chasing it |
Expected monetary value handles both directions perfectly well once you let it. Positive risk carries positive values and threats carry negative ones, so a decision tree that nets the two produces a far truer figure than a contingency calculation built from threats alone.
Quantitative technique matters more to positive risk as project size grows, because small opportunities can be judged and large ones cannot. Our guides to Monte Carlo simulation and the risk matrix template cover the mechanics, and the GAO cost estimating guide remains the reference for federal-grade rigour.
Who Owns a Positive Risk, and Why That Single Question Decides Everything
Threat ownership is uncomfortable, which is precisely why somebody always ends up holding it. Positive risk ownership is pleasant and therefore drifts, and an opportunity that everybody welcomes but nobody owns is the most common way this whole discipline quietly dies.

Identification is the easy stage. Three quarters of named opportunities never reach the fourth.
Ownership of a positive risk only means something when it arrives together with the authority to spend money. Assigning one to somebody who cannot release budget or change the schedule reliably produces a monthly status update rather than a captured benefit.
Governance decides whether that spending authority exists at all, and positive risk is where the answer usually turns out to be no. The three lines model clarifies who challenges the estimate, while risk appetite statements should say what the organization is willing to spend pursuing upside, not merely what it will tolerate losing.
Appetite is where most frameworks fall silent on positive risk altogether. The Institute of Risk Management describes appetite as balancing threats against opportunities, yet the appetite statements we review in practice almost never set any budget at all for pursuing positive risk.
Writing Positive Risk Into Contracts, the Way Caltrans Did
The MacArthur Maze repair worked because the positive risk was contractual rather than aspirational. A $200,000 daily bonus set against an $867,075 contract made early delivery worth vastly more than the underlying work, and the contractor responded rationally to that arithmetic.
| Mechanism | How it captures positive risk | What to watch |
| Early completion bonus | Pays the supplier to exploit a schedule opportunity you cannot access directly | Cap it, and pair it with a matching lateness penalty |
| Gain-share clause | Shares savings the contractor generates, so both parties enhance the same outcome | Define the baseline precisely or the saving becomes contested |
| Target cost with pain and gain | Aligns cost outcomes in both directions across the whole contract | Requires open-book cost data and audit rights |
| Early supplier involvement | Buys access to design improvements before the baseline locks | Pay for it explicitly; free advice arrives after the decision |
| Option to expand scope | Preserves the right to buy more if conditions turn favourable | Price the option, and set an expiry date on it |
Incentives transfer positive risk to whoever can act on it, which is the share strategy in contractual form. A comparable structure on the I-35W bridge replacement followed the same logic, with the federal oversight report recording a $233,763,000 bid awarded in October 2007.
Be careful about the direction any incentive pushes behaviour. A bonus rewarding speed on work where quality failure would be catastrophic buys you a schedule opportunity and a safety threat in the very same clause, and the second of those is rarely priced.
Why Base Rates Make Positive Risk Management Non-Optional
There is a harder argument for this than fairness to the upside, and it comes from the outcome data. Projects that finish well are genuinely rare, so any team relying on threat avoidance alone is playing for a narrow band of outcomes.

Base rates from a database of more than 16,000 projects across 136 countries.
Bent Flyvbjerg’s Oxford database puts 8.5 percent of projects on budget and on time, and 0.5 percent on budget, on time and delivering the promised benefits. Threat management alone moves a project toward the first figure and not the second.
The distribution of outcomes is also lopsided in a way that matters here. His work on fat-tailed IT project outcomes across 5,392 projects, extended in a 2026 analysis of twenty-three project types, shows extreme downside outcomes dominating the distribution across almost every category examined.
We would not claim this research quantifies thin upside, because it does not. It establishes that clean success is rare, which is a reason to pursue every advantage a project can find rather than evidence about how much upside exists.
Where Positive Risk Programmes Stall, and How to Unstick Them
Teams that decide to manage positive risk properly usually fail in one of a small number of entirely predictable ways. Each of those failures has a specific fix available, and not one of them requires buying new software to solve.
| What you observe | What is actually happening |
| The opportunity column is empty | Identification prompts are written in the language of failure |
| Opportunities are logged but never scored | No agreed value anchors, so they cannot compete for funding |
| Every opportunity is owned by the project manager | Ownership was assigned by default rather than by ability to act |
| Benefits already in the business case appear as opportunities | The register is being padded and will not survive audit |
| Opportunities closed as escalated | The entry left your register and nobody at portfolio level picked it up |
| The same opportunities recur every reporting cycle | Nothing was funded, so nothing changed between reviews |
The last row is by far the most common in the reviews we run. A positive risk that survives four consecutive monthly reports without a funded action is not being managed at all, and the honest response is to close it or to pay for it.
The padding problem described in the fourth row deserves particular attention from anyone reviewing a register. Recording planned benefits as positive risk inflates the register and destroys its credibility with finance, which then quietly discounts every genuine entry alongside the invented ones.
The Positive Risk Questions Project Teams Keep Asking
Is Positive Risk the Same Thing as an Opportunity?
In PMI’s terminology an opportunity is a risk with a positive effect on objectives, so the terms are used interchangeably in practice. ISO 31000 reaches the same position by defining risk as an effect of uncertainty that may be positive, negative or both.
Should Positive Risk Sit in the Same Register as Threats?
Yes, in one register with a type column, because separate documents guarantee the positive risk log becomes the one nobody ever opens. Use the same scoring scale for both so that the two can be compared and ranked against each other honestly.
How Many Positive Risks Should a Project Register Hold?
There is no correct ratio, but a register where opportunities fall below roughly a fifth of entries usually reflects the workshop rather than the project. Published research found opportunities at 15.5 percent of identified uncertainties, which the authors treated as a shortfall.
Who Approves Spending Money to Pursue a Positive Risk?
Whoever holds the contingency or the change budget, which is normally the sponsor rather than the project manager. If nobody in the governance chain can approve such spending, the organization has not genuinely adopted positive risk management whatever its policy document says.
Does Positive Risk Apply to Agile Delivery?
Positive risk applies more naturally in agile than in waterfall, because iterative delivery creates repeated decision points where new information can be exploited. The discipline still has to be deliberate, since a backlog refinement session is not an opportunity identification session.
What Is the Difference Between Positive Risk and a Project Benefit?
A benefit is committed in the business case and the project is accountable for delivering it. A positive risk is uncertain, was not assumed in the baseline, and requires a specific response to convert it into value the business case never counted on.
How Do You Report Positive Risk to a Steering Committee?
Report the expected value of positive risk alongside threat exposure so the net position is visible, and name the funded actions together with their owners. Boards discount opportunity reporting very quickly when it arrives as narrative rather than as numbers they can challenge.
The Standards Horizon for Positive Risk Through 2028
Two standards revisions now in motion will change how positive risk is documented over the next two years. Both are worth tracking closely if your own methodology cites either standard by edition number, as the overwhelming majority of methodologies still do.
ISO 31000 is currently under revision, with a third edition now in development that will replace the text entirely. The 2018 edition was reviewed and confirmed as current in 2023, and it remains the operative reference until the new edition publishes.
PMI moved first on this front, and by a clear margin. The PMBOK Guide eighth edition arrived on 13 November 2025, reintroducing process groups as focus areas across seven performance domains, so methodology documents citing the sixth edition structure are now two revisions behind.
The underlying vocabulary has shifted too, and it catches a great many people out. ISO Guide 73 has been withdrawn and superseded by ISO 31073:2022, so any risk policy still citing Guide 73 as its source of definitions is quietly citing a withdrawn document.
Demand for this particular capability is not seriously in question. PMI’s talent gap research projects millions of new project professionals needed across this decade, and positive risk management is the corner of the discipline where genuinely competent practitioners remain scarce.
The Bottom Line on Positive Risk
Score positive risk on the same scale as threats, in the same register, with the same demand for a named owner and a dated action. An opportunity nobody will fund is not being managed, whatever the register says about it.
Start with one session this month. Ask your team what would have to be true to finish early, require five answers with numbers attached, and check whether a single one of them survives to next quarter with funding behind it.
The professional bodies are aligned on positive risk even where day-to-day practice is not. APM defines risk management as optimising success by minimising threats and maximising opportunities, which is positive risk stated as doctrine, and its body of knowledge carries generic response strategies for both.
We build and run positive risk cycles for delivery organizations, including the awkward part where somebody senior has to actually fund an opportunity. Explore our advisory services or get in touch to discuss a review, and our assessment templates cover the documentation.
Route the output somewhere it will be seen rather than into a slide. Feed entries into a KPI dashboard, track them using indicators from the KRI directory, and hold them inside the risk management process you already run.
Then connect positive risk to the rest of the project risk discipline surrounding it. Our published work covering the project risk management plan, risk mitigation and the risk management lifecycle all cover the threat side of the ledger in exactly the same detail.
Larger and more entangled programmes need heavier machinery than a single positive risk register can provide. Our detailed guides to managing risks in complex projects, supply chain risk heat mapping and ISO 31000 against COSO ERM all address problems at that considerably larger scale.
Several further resources close the loop for practitioners building positive risk capability internally from scratch. Our guides to what a risk assessment is, the complete assessment guide, ISO 31000 and risk management certifications all reinforce the same discipline.
Resilience and sustainability work both benefit from the identical two-directional reframing that positive risk demands of a team. Our coverage of business resilience, business continuity programmes and ESG risk assessment each treats uncertainty as genuinely two-directional throughout the analysis.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.