What Is Risk Response Planning

Photo of author
Written By Chris Ekai

Risk response planning is the step that turns a scored risk register into commitments: for each risk, one chosen response, a named owner, a trigger that fires it, funding to run it, and the residual exposure the organization accepts. It closes the gap between knowing a risk exists and having decided what happens when it arrives.

At 23:21 on 20 March 2025, a transformer at the North Hyde substation in west London caught fire. Heathrow closed for the whole of the next day, cancelling more than 1,300 flights and disrupting 270,000 journeys, the airport’s first full shutdown in fifteen years.

The response worked. The Kelly Review, published 28 May 2025 by Ruth Kelly with Joan MacNaughton and Mark Brooker, found the airport had contingency plans in place and that alternative choices on the day would not have materially changed the outcome.

Risk Response Planning: Key Takeaways
Risk response planning converts a scored register into owned commitments: one response per risk, a named owner, a trigger condition, a funded action, and the residual risk you accept afterwards.
Eight responses exist, not four. Threats get avoid, transfer, mitigate, or accept. Opportunities get exploit, share, enhance, or accept, and most registers ignore the second row entirely.
Heathrow’s closure on 21 March 2025 cancelled more than 1,300 flights and disrupted 270,000 journeys. The Kelly Review found the contingency plans and the decisions were sound.
The failure sat upstream: an elevated moisture reading logged in July 2018 never led to the bushing being replaced. Choosing a response and executing one are separate acts.
Contingency reserve covers identified risks and belongs to the project manager. Management reserve covers unknown risks and belongs to the sponsor, outside the cost baseline.
Every response creates secondary risk and leaves residual risk. A plan that never records either is describing a project that does not exist.

The failure sat seven years upstream. The National Energy System Operator’s final report traced the fire to an elevated moisture reading logged in oil samples in July 2018, after which the bushings were never replaced. Somebody identified the risk seven years early and nobody executed the response, which is the exact gap this discipline exists to close.

What Is Risk Response Planning

Figure 1. One closure, four numbers, and a seven-year gap between the warning and the failure.

What Risk Response Planning Produces

Risk response planning sits between assessment and monitoring in the standard five-step process. Assessment tells you which risks matter and monitoring tells you whether anything changed. Response planning is the step in between, where a named person commits to a specific action, on a specific budget, by a specific date.

The output is not a narrative. It is a set of fields attached to every red-zone entry on the register. A risk register missing any of these fields has recorded an intention, and intentions do not survive contact with a 02:00 incident call.

Field What it answers Failure mode when it is blank
Chosen response Avoid, transfer, mitigate, accept, or the opportunity equivalent The risk defaults to accepted without anyone deciding
Named owner Which single person acts Committee ownership, so nobody acts
Trigger condition What observable event starts the response The response fires late, or during the post-mortem
Funded action What gets done, with what budget A good plan with no money behind it
Residual risk What exposure remains after the response False comfort at the governance meeting
Review date When the entry gets re-scored A 2018 finding still open in 2025

That last row is the Heathrow lesson in a single line. The organization had identified the exposure and had contingency plans for the consequence, yet the treatment for the cause carried no owner, no trigger, and no closure date that anyone enforced.

Why a Register Without Responses Is Just a List

Registers are cheap to produce and easy to admire at a steering meeting. The expensive part is the column that says what happens next. ISO 31000 treats risk treatment as a distinct activity for that reason, carrying its own plan, its own resources, and its own line of accountability.

The distinction matters commercially. A listed risk with no response is an accepted risk that nobody priced, and accepted risks with no reserve behind them become emergency spending at crisis rates. Our guide to why risk management is important quantifies that gap across sectors.

Recovery capability is the other half. The Business Continuity Institute’s reading of the Kelly Review draws the same conclusion practitioners drew watching the runways empty: plans that cover consequence still need plans that attack cause. The two are funded from different budgets by different people.

The Eight Risk Response Strategies

Most articles on risk response planning list four strategies and stop. Four cover threats only, and half the register goes unmanaged as a result, because positive risk needs owners and triggers exactly as threats do. The upside column is where competitive advantage is captured or quietly forfeited.

What Is Risk Response Planning

Figure 2. Four responses for threats, four for opportunities. Every register entry takes exactly one.

Response When it fits Worked example
Avoid Exposure exceeds any available reward Drop the single-supplier design before contract award
Transfer A counterparty prices or absorbs it better Builder’s risk cover; liquidated damages in the subcontract
Mitigate Control cost sits below expected loss reduction Second power feed; replace the bushing flagged in inspection
Accept Residual exposure is small and priced Minor weather days absorbed by schedule float
Exploit Make an upside certain rather than likely Lock the early-completion bonus by adding a shift
Share Partner captures value you cannot alone Joint venture to bid work beyond your bonding capacity
Enhance Raise likelihood or size of a gain Fund the pilot that unlocks the volume discount
Accept (upside) Take the gain if it arrives, spend nothing Favourable exchange rate movement, unhedged

The PMI standards library formalizes this split, and the same logic runs through risk management techniques at every altitude, from a single work package to an enterprise portfolio. Recording the strategy name matters far less than recording who owns it, what fires it, and what it costs to run.

Choosing Between Them Without Guessing

Selection stops being a debate once the exposure is priced. Take a single-point power supply on a $12 million data-centre fit-out: 30% likelihood of a multi-day outage during commissioning against a $2 million impact, which puts expected loss at $600,000 before any response is chosen.

What Is Risk Response Planning

Figure 3. Response cost plus residual loss, not response cost alone, is what decides.

Accepting costs nothing today and carries the full $600,000 expected loss. A dual feed costs $180,000 and cuts residual exposure to $90,000, giving $270,000 all in. Insurance at $95,000 still leaves $240,000 of uncovered delay, while resiting the plant removes the risk outright at $900,000.

Mitigation wins on total cost, and the table makes that defensible to a sponsor who only sees the $180,000 line item. Quantitative risk tools scale this to portfolios, and the eight-step project risk assessment produces the likelihood and impact inputs the arithmetic depends on.

Contingency Reserve and Management Reserve Are Not the Same Money

Funding is where response plans quietly die, usually because two different reserves get treated as one pot of money. Getting the distinction right is what lets a project manager act on the day of the event without first convening a steering group to argue about whose budget it was.

Contingency reserve Management reserve
Covers Identified risks with planned responses Unknown risks and unforeseeable work
Controlled by The project manager The sponsor or governance board
Sits Inside the cost baseline Outside the cost baseline
Released by The trigger in the response plan A formal change request
Sized by Summed expected values of register entries Organizational policy, often a flat percentage

 

What Is Risk Response Planning

Figure 4. Two reserves, two owners; only the contingency reserve sits inside the cost baseline.

Blurring the two produces the familiar deadlock: the risk fires, the response exists, and the money needs three signatures nobody can collect at 02:00. Our project risk management plan guide sets out the drawdown rules that prevent it, along with the escalation thresholds that decide when the sponsor genuinely does need to be woken.

Secondary and Residual Risk: What Your Response Creates

Every response reshapes the risk picture, which is the part most registers get wrong. Two distinct artifacts come out of that change, and competent plans record both of them while weak plans record neither and report the risk as resolved.

The two are easy to separate once they are named, and the separation matters because each carries a different owner and a different review cycle. Both belong on the same register as the original entry, scored the same way and reported beside it:

  • Residual risk is what remains after the response runs. Insure a $2 million exposure with a $250,000 deductible and $250,000 is residual, sitting on the register with an owner.
  • Secondary risk is what the response itself introduces. Transfer to a subcontractor and you have created counterparty credit risk that did not exist before.

Both belong on the register as ordinary entries, scored and owned. A risk mitigation plan that reports a risk as closed once a control is installed has confused activity with exposure, and governance reads the green status as safety it does not have.

Triggers, Owners, and the Test That Proves It Works

A response with no trigger runs late by definition, because somebody first has to notice the problem and then win an argument about whether it counts. Triggers convert judgment into observation: a threshold crossed, a date passed, a supplier credit rating downgraded.

Five conditions separate a plan that actually fires from a document somebody discovers during the post-mortem review. Each of them is cheap to put in place at approval time, and painful to retrofit in the middle of a live incident:

  • A trigger stated as an observable fact: two consecutive missed milestones, a supplier downgrade, a threshold crossed. “If things look bad” is a feeling, and feelings do not fire responses.
  • A single named owner with authority to spend the reserve, plus a named deputy for the 02:00 case.
  • A key risk indicator (KRI) trending on a dashboard someone reads weekly.
  • A rehearsal at least annually, following NIST SP 800-61 Revision 3 for cyber events or CISA’s incident response basics for a lighter start.
  • A post-exercise fix list with dates, because an untested plan and a failed test are the same thing until someone closes the actions.

Continuity work carries the same requirement. ISO 22301 makes exercising a requirement, and the structure in our business continuity plan components guide maps directly onto response planning at incident scale. Continuity teams and project risk teams should be reading the same trigger lists.

Federal guidance is free and specific here. Ready.gov’s business continuity material, the companion risk assessment pages, and OSHA’s emergency preparedness guidance all supply testable templates at no cost. That removes the last remaining excuse for an unrehearsed plan, which is that building one properly was going to be expensive.

Lessons From Plans That Failed When Tested

Response plans fail in patterns, and those patterns repeat across sectors in the risk management examples we track. They show up in identical shapes whether the project is a refinery turnaround or a software migration. Each one has a fix that costs less than the failure it prevents.

Trap How it shows up The fix
Response chosen, never executed A 2018 inspection finding open in 2025 Closure dates enforced at governance, not suggested
Owner is a department Everyone assumed someone else acted One name, one deputy, on the register
No trigger Response starts after the impact Observable threshold agreed at approval
Reserve unfunded Plan exists, money needs a committee Contingency drawdown rules signed in advance
Residual risk unrecorded Board sees green, exposure is amber Residual scored and reported beside the original
Never rehearsed First run happens during the incident Annual exercise with a dated fix list
Opportunities ignored Only threats have owners Upside entries carry owners and expiry dates

The first row is the expensive one, and the hardest to see from inside a governance pack. Heathrow’s own commentary, and the expert panel convened after the closure, both land on execution as the weak link, which matches what we see in maturity assessments across project portfolios.

Risk Response Planning: Your Questions Answered

What is risk response planning in project management?

It is the process of deciding what happens for each risk on the register: one response strategy, a named owner, a trigger condition, funded action, and the residual risk accepted afterwards. It sits between risk assessment and monitoring, and its output is a set of commitments with dates.

What are the risk response strategies?

Eight, not the four that most guides list. Threats take avoid, transfer, mitigate, or accept, while opportunities take exploit, share, enhance, or accept. Every register entry gets exactly one strategy, and recording the owner and the trigger matters considerably more than the label attached to it.

What is the difference between contingency reserve and management reserve?

Contingency reserve funds identified risks with planned responses, sits inside the cost baseline, and the project manager releases it against a trigger. Management reserve funds unknown risks, sits outside the baseline, and needs a formal change request from the sponsor.

What is residual risk in a risk response plan?

Residual risk is the exposure left after the response runs. Insure a $2 million risk with a $250,000 deductible and $250,000 remains residual. It stays on the register with an owner, because reporting a risk as closed once a control exists overstates the protection.

How often should a risk response plan be reviewed?

Re-score monthly, review responses at every phase gate, and reassess immediately after any incident or trigger event. The Heathrow case shows the cost of the alternative: a finding logged in July 2018 was still unactioned when the transformer failed in March 2025.

Who owns a risk response in practice?

One named individual with the authority to spend the contingency reserve, plus a named deputy for out-of-hours events. Departmental ownership fails predictably: a response that belongs to everyone gets started by nobody, usually until the impact has landed and the cost has multiplied.

Where Response Planning Is Heading Next

Three shifts are already visible across the sectors we work in. Regulators increasingly ask to see the response, not the register: NIST’s Cybersecurity Framework and its incident-response profile both push organizations to evidence rehearsed recovery, and examiners increasingly ask for the exercise report by name.

Infrastructure interdependency is the second. Heathrow lost power because one substation failed, and the Kelly Review’s recommendations centre on energy resilience well beyond the airport fence. Expect response plans to be judged increasingly on the assumptions they make about suppliers and utilities you do not control and cannot inspect.

Third, execution evidence is becoming the audit artifact. A closure date, a signed drawdown, an exercise report with dated fixes: these now carry more weight with examiners than the elegance of the register itself, and COSO’s ERM guidance pushes the same direction at enterprise level.

If your register has scores but empty response columns, that is the gap to close before your next phase gate. Our risk advisory services build the response plans, triggers, and reserve rules with your team; contact us to scope it. A response nobody owns is a finding waiting seven years to be read.