Risk management in portfolios, programs, and projects follows one PMI reference: The Standard for Risk Management in Portfolios, Programs, and Projects, published in 2019 and reissued in September 2024 as a practice guide. It defines core principles, a risk management life cycle, and tier-specific guidance inside an enterprise risk management approach.
On July 23, 2026, the Government Accountability Office published its 18th annual assessment of NASA’s major projects: 36 efforts carrying at least $70 billion in life-cycle costs, with cumulative overruns near $4.7 billion and 14 years of accumulated delay. One capsule, Orion, accounts for almost 75% of those cumulative overruns.
| Risk Management in Portfolios, Programs, and Projects: Key Takeaways |
| The Standard for Risk Management in Portfolios, Programs, and Projects (PMI, 2019, ANSI-approved) is current today as the September 2024 practice guide reissue. |
| It is a PMI publication, not ISO 31000; the two align by design, with ISO or COSO setting the enterprise criteria the three tiers consume. |
| GAO’s July 2026 NASA assessment shows the stakes: 36 major projects, $70B+ life-cycle cost, $4.7B cumulative overruns, 14 years of delay (GAO-26-108556). |
| Each tier asks a different risk question: portfolios test strategic fit and appetite, programs test combined benefits, projects test schedule, cost, and scope. |
| The life cycle runs plan, identify, analyze qualitatively and quantitatively, respond, and monitor, with escalation connecting the three tiers. |
| PMI-RMP is the matching credential, and a mid-size PMO can stand up the three-tier skeleton in about 90 days. |
That is what portfolio risk looks like when it is managed project by project. PMI wrote its standard for exactly this failure mode, and this guide explains what the standard says, what replaced it in 2024, and how to run its life cycle at all three tiers.
What the Standard for Risk Management in Portfolios, Programs, and Projects Is Now
The Project Management Institute published The Standard for Risk Management in Portfolios, Programs, and Projects in 2019 as an ANSI-approved American National Standard, expanding its 2009 Practice Standard for Project Risk Management beyond single projects. It is the reference behind the risk questions on PMI’s certification exams.
In September 2024, PMI folded the content into Risk Management in Portfolios, Programs, and Projects: A Practice Guide, aligned with the PMBOK Guide Seventh Edition. Buyers searching for the 2019 book should know the practice guide is the current edition of the same material.
One correction to a common mix-up, including in the earlier version of this article: this standard is not ISO 31000. ISO 31000 is the sector-neutral international risk standard; PMI’s document applies comparable thinking specifically to portfolio, program, and project work, and the two read well together.
| Edition | Year | What changed |
| Practice Standard for Project Risk Management | 2009 | Project-only scope, process focus |
| The Standard for Risk Management in Portfolios, Programs, and Projects | 2019 | Three tiers, ERM context, ANSI approval |
| PMBOK Guide Seventh Edition | 2021 | Principles-based frame the risk guide now aligns to |
| Risk Management in Portfolios, Programs, and Projects: A Practice Guide | 2024 | Current edition; working examples and a full case study |

Figure 1. Fifteen years of PMI risk references: the 2019 standard’s content now lives in the 2024 practice guide.
Why Tiered Risk Discipline Matters: NASA’s $70 Billion Lesson
GAO’s finding is not that NASA runs projects badly; it is that risk concentrates. Two of 18 development-stage projects drove the year’s schedule slips, three drove $501.4 million of new cost growth, and Orion alone carries roughly three quarters of the portfolio’s cumulative overruns.

Figure 2. Four numbers from GAO-26-108556: portfolio-level exposure that no single project report would show.
A project view would call most of that portfolio healthy, and a portfolio view cannot. Concentration is a portfolio-tier signal: it shows up only when someone owns the aggregate picture, compares exposure against a stated appetite, and reallocates before the annual report does it for them.
GAO pairs its assessments with method guides federal programs are measured against, and both are free. The Cost Estimating and Assessment Guide and the Schedule Assessment Guide are the de facto US benchmarks for quantifying cost and schedule risk on large programs.
The Principles and the Risk Management Life Cycle
The practice guide opens with principles before process: risk work exists to create and protect value, lives inside everyday decisions, and must be tailored to each tier’s context. The framing deliberately echoes the risk management process ISO and COSO describe, which eases cross-walking.
| Life cycle stage | What happens | Artifact produced |
| Plan risk management | Decide approach, roles, and thresholds per tier | Risk management plan |
| Identify risks | Surface threats and opportunities against objectives | Register entries with owners |
| Qualitative analysis | Prioritize by probability and impact against criteria | Ranked register |
| Quantitative analysis | Model aggregate exposure where the numbers justify it | Contingency and reserve figures |
| Plan and implement responses | Choose and execute named response strategies | Response plans with dates |
| Monitor risks | Track exposure, triggers, and response effectiveness | Updated register and reports |
Quantitative analysis is the stage teams skip most and the one big programs need most. Techniques like Monte Carlo simulation turn a ranked register into confidence levels on cost and schedule, which is how a program justifies its reserves to a board or an appropriator.
The response vocabulary runs in two directions, because the standard treats opportunity as risk with a positive sign. Threat responses and opportunity responses mirror each other, and a written plan should name which strategy each priority risk is getting in the register:
- Threats: avoid, transfer, mitigate, accept, or escalate to the tier that can act
- Opportunities: exploit, share, enhance, accept, or escalate upward the same way
- Escalation is the tier connector: project risks that threaten program benefits move up
- Acceptance needs an owner and a review date like every other response
How Risk Management in Portfolios Differs from Programs and Projects
Effective risk management in portfolios asks a different question than project risk work, and the standard is organized around that difference. Each tier gets its own chapter because each optimizes for something different: strategic fit, combined benefits, or a specific deliverable.

Figure 3. One escalation path connects the three tiers; each tier owns a different risk question.
| Tier | Core risk question | Typical tools |
| Portfolio | Does the investment mix still serve strategy within appetite? | Appetite statements, capacity models, ERM dashboards |
| Program | Will interdependent components deliver the promised benefits? | Interdependency maps, benefit registers, escalation logs |
| Project | Will this scope land on time, on budget, at quality? | Risk register, reserves, a project risk management plan |
Tier boundaries are where real programs leak. In our PMO advisory work the common failure is a beautiful project risk management plan feeding nothing above it, so program-level interdependencies and portfolio concentration, the NASA pattern, stay invisible until the year-end review lands.
Where ISO 31000 and COSO Fit Alongside the PMI Standard
Most US organizations already run something at enterprise level, and the practice guide assumes it. It positions tier risk work inside an enterprise risk management approach, which in practice means ISO 31000 or COSO ERM sets the criteria the tiers consume; we compared the two for that enterprise job.
| Question | PMI practice guide | ISO 31000:2018 | COSO ERM 2017 |
| Scope | Portfolios, programs, projects | Whole organization | Whole organization, strategy-led |
| Certifiable | No; PMI-RMP certifies people | No | No |
| Risk upside | Opportunities managed explicitly | Uncertainty includes upside | Opportunity in strategy setting |
| Best used for | Delivery organizations | Enterprise risk criteria | Board and audit reporting |
Assessment technique depth comes from IEC 31010, and person-level credentialing from the PMI-RMP, which we compared against the PMP for risk-heavy roles. The stack works best when each document does its one job: PMI for delivery tiers, ISO for enterprise criteria, COSO for governance reporting.
Building the Program: Artifacts, Registers, and Metrics
Standards only matter when they become artifacts someone maintains. Start with a risk register template built around the fields the life cycle actually needs, wire each tier’s escalations into it, and surface the aggregate on ERM dashboards leadership already reads.
| Artifact | Tier | Refresh cadence |
| Risk appetite statement | Portfolio | Annual, plus strategy changes |
| Capacity and concentration view | Portfolio | Quarterly |
| Interdependency and escalation log | Program | Monthly |
| Benefit-risk register | Program | Monthly |
| Project risk register with reserves | Project | Every status cycle |
| KRI set per tier | All three | With each report |
Measurement is what keeps the cadence honest. Tier-appropriate key risk indicators, a screening questionnaire for intake, and an assessment rhythm tied to stage gates beat any annual workshop, and the register data eventually justifies better tooling from the ERM software market.
Ninety days is enough to stand the three-tier skeleton up in a mid-size organization, provided the first month is spent on decisions, and not on software. Five moves set the foundation and each produces an artifact a stage gate can check:
- Write the portfolio risk appetite in dollars and thresholds everyone can test against
- Pick one register format and one scoring scale for all three tiers
- Name a risk owner per tier, with escalation rights written down
- Baseline current exposure with a proper risk assessment and a nine-step review on running projects
- Schedule quantitative analysis only for the programs whose reserves need defending
Lessons from Programs That Failed
The GAO archive doubles as a casebook of what sinks tiered risk programs, and the private-sector versions rhyme. Six patterns repeat across the post-mortems we read and the reviews we run, each with a fix that costs less than the failure.
| Failure pattern | How it shows up | Countermeasure |
| Tier blindness | Healthy project reports, sick portfolio | A concentration view someone owns |
| Optimism-priced reserves | Contingency set by negotiation | Quantitative analysis at stage gates |
| Register theater | Registers updated for audits only | Owners and dates on every entry |
| Escalation without rights | Risks raised, nobody empowered | Written escalation authority per tier |
| Opportunity neglect | Only threats ever tracked | Positive risk strategies in the same register |
| One-time planning | Risk plan written at kickoff, frozen | Refresh triggers tied to change events |
Common Risk Management in Portfolios Questions Practitioners Ask
Is the Standard for Risk Management in Portfolios, Programs, and Projects still current?
The 2019 standard’s content now lives in Risk Management in Portfolios, Programs, and Projects: A Practice Guide, published by PMI in September 2024 and aligned to the PMBOK Guide Seventh Edition. Buy or download the practice guide; treat 2019 copies as a superseded edition.
Is risk management in portfolios the same as enterprise risk management?
No; portfolio risk management governs a set of investments against strategy and appetite, while enterprise risk management covers every risk the organization carries, including operations, compliance, and finance. PMI’s practice guide deliberately nests the portfolio tier inside the wider ERM approach.
Does risk management in portfolios, programs, and projects align with ISO 31000?
Yes, by design. PMI frames its principles and life cycle to sit comfortably inside an ISO 31000 or COSO ERM environment, so enterprise criteria flow down and tier exposures roll up. The documents differ in scope, with PMI specific to delivery work.
What certification covers risk management in portfolios, programs, and projects?
The PMI-RMP, Risk Management Professional, is the dedicated credential, and the practice guide is core reading for it. Portfolio and program managers usually add it on top of a PfMP, PgMP, or PMP, since the risk credential is a specialization.
How does risk management in portfolios handle positive risk?
The practice guide treats opportunity as risk with beneficial impact and gives it mirrored response strategies: exploit, share, enhance, and accept. At portfolio tier that means deliberately funding uncertain but high-upside work, sized so a failure stays inside the stated appetite.
How do I start risk management in portfolios with a small PMO?
Start with one register format, one scoring scale, and a written portfolio appetite; those three artifacts create the shared language everything else needs. Add program interdependency tracking next, then quantitative analysis only where reserves face challenge. Ninety days covers the skeleton for most mid-size PMOs.
Where PMI’s Risk Standards Go Next
PMI’s direction of travel is visible in the 2024 reissue: principles over procedure, tighter PMBOK Seventh Edition alignment, and a practice-guide format PMI can refresh faster than an ANSI standard cycle. Expect updates to track PMBOK revisions from here, on shorter cycles.
Scrutiny is heading the other direction too. GAO now publishes annual portfolio assessments across agencies, boards have normalized asking for aggregate exposure, and the AICPA’s 2025 oversight survey found only 35% of US organizations with complete ERM processes, which leaves tier-level risk data as the differentiator.
If you run a PMO, a program office, or a portfolio board, the sequence in this guide is deliberately small: appetite, one register, owners, escalation rights, then quantitative depth where reserves face challenge. Our services cover exactly those buildouts; contact us before your next stage gate and bring the register you have, whatever shape it is in.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.