4Risk & procurement management
- 4.1Risk identification & analysis
Covers identifying risks and recording them in a risk register, qualitative risk analysis (a probability/impact matrix) that ranks risks by multiplying probability and impact, and quantitative risk analysis (expected monetary value (EMV), decision trees) that translates risk into monetary terms to judge whether a response is worthwhile, building judgment for deciding which risks a limited contingency budget should be allocated to.
- 4.2Selecting risk response strategies
Covers the four threat response strategies (avoid, transfer, mitigate, accept) for negative-impact risks and the four opportunity response strategies (exploit, share, enhance, accept) for positive-impact risks, building judgment for choosing among them based on cost-effectiveness, alongside secondary risk created by a response, residual risk remaining after a response, and contingency plans for unforeseen events.
- 4.3Procurement and contract types
Covers make-or-buy analysis, which judges whether to perform work internally or outsource it, and builds judgment for choosing among fixed-price (FP) contracts, cost-reimbursable (cost-plus) contracts, and time-and-materials (T&M) contracts—each with a different risk-bearing profile—based on how firm the requirements are.
- 4.4Conducting procurements & supplier management
Covers RFI for gathering information on prospective vendors, RFP for soliciting proposals, weighted supplier selection criteria, and the post-contract flow of contract administration, change management, and claims administration, building judgment for supplier selection and contract management suited to the situation.

