UNISA PRM4802 Project Risk and Quality Management Exam Notes

UNISA PRM4802 (Project Risk and Quality Management) is a module that blends risk thinking with quality assurance and improvement practices for projects and programmes. These exam notes explain the core concepts—risk identification, analysis, response planning, monitoring, and quality planning and control—through practical, South African project scenarios. They also highlight how to structure exam answers: definitions first, then process steps, tools, examples, and finally links to standards and governance.

1) Core Concepts in Project Risk Management (PRM4802)

1.1 What “project risk management” means in UNISA PRM4802

In project contexts, risk is not just “uncertainty.” In PRM4802, you should treat risk as a condition or event that, if it occurs, affects project objectives (scope, time, cost, quality, safety, stakeholder satisfaction, compliance, and benefits). A key exam point: risk is measured by both probability and impact, not by impact alone.

A typical UNISA-style framing is:

  • Risk: the possibility of an event affecting objectives.
  • Issue: something that has already happened (risk becomes issue).
  • Threat: a risk that negatively affects objectives.
  • Opportunity: a risk that positively affects objectives.
  • Residual risk: risk remaining after responses.
  • Risk exposure: an overall measure of risk level (often probability × impact).
  • Risk appetite/tolerance: the level of risk the organisation is willing to accept.

In answers, always connect risk management to decision-making: risk management enables selecting responses that keep the project within acceptable bounds.

1.2 Risk management objectives and where it fits in the project life cycle

Risk management should occur across the project life cycle—not only at the start. You should mention that it aligns with governance and the broader planning cycle:

  1. Initiation & baseline planning
    • Create risk management plan and initial risk register.
  2. Planning
    • Analyse risks, decide responses, assign owners, define monitoring thresholds.
  3. Execution
    • Implement risk responses and collect new risk information.
  4. Monitoring & controlling
    • Track risks, detect changes, update probabilities/impacts, close resolved risks.
  5. Closing
    • Capture lessons learned; update organisational risk knowledge.

Exam markers like a clear loop: plan → do → check → act. Quality management similarly follows a continuous improvement logic.

1.3 Risk categories you must be able to identify quickly

A common exam approach is to classify risks. Typical categories include:

  • Technical risks (design complexity, technology maturity, integration issues)
  • Schedule/time risks (resource availability, procurement delays, dependency slippage)
  • Cost risks (inflation, exchange rates, under-estimated labour/materials)
  • Scope risks (scope creep, unclear requirements, changing stakeholder needs)
  • Quality risks (defects, rework, failure to meet specs/standards)
  • Health & Safety risks (site hazards, contractor safety non-compliance)
  • Legal/regulatory risks (permits, compliance requirements, approvals)
  • Stakeholder risks (communication breakdowns, resistance, governance failures)
  • Procurement/vendor risks (supplier performance, lead times, contract disputes)
  • Environmental risks (weather events, site impacts, waste management)

In South Africa, exam scenarios often involve:

  • procurement and contractor performance,
  • regulatory approvals (municipal/national),
  • supply chain volatility (materials),
  • safety risks (construction environments),
  • community/stakeholder constraints.

1.4 Stakeholders and “risk ownership”

A major concept: a risk owner should be assigned to each significant risk. In UNISA exams, “ownership” means:

  • accountable person/unit for monitoring that risk,
  • authority to initiate response actions,
  • responsibility to keep the risk register updated.

In good answers, you distinguish:

  • Project Manager (often coordinates risk process),
  • Functional leads (technical owner for technical risks),
  • Procurement lead (vendor/procurement risks),
  • Quality manager (quality-related risks),
  • HSE officer (safety risks),
  • Contracts/legal (compliance and contractual risks).

1.5 Probability and impact: common scales and how to use them in exams

Most exam questions expect you to apply a qualitative or semi-quantitative scale. A standard approach:

  • Probability scale (e.g., 1–5):
    1 = Very unlikely
    2 = Unlikely
    3 = Possible
    4 = Likely
    5 = Almost certain

  • Impact scale (e.g., 1–5):
    1 = Negligible
    2 = Minor
    3 = Moderate
    4 = Major
    5 = Severe

Then compute a risk rating:

  • Risk score = Probability × Impact

Example (for explanation):

  • A risk with Probability 4 (likely) and Impact 3 (moderate) → score = 12.
  • Another with Probability 3 and Impact 4 → score = 12.
    These may require different responses (you can’t treat them as identical because response drivers differ).

Important: if you provide a risk matrix, be consistent with your scale interpretation in all later references.

1.6 Risk registers and risk documentation

A risk register is central. It typically includes:

  • Risk ID (unique)
  • Description (what event, what cause, what effect)
  • Category (technical, schedule, etc.)
  • Cause(s)
  • Consequence(s)
  • Probability rating
  • Impact rating
  • Risk score / risk level (e.g., low/medium/high)
  • Risk response strategy (avoid, mitigate, transfer, accept, exploit)
  • Response owner
  • Target date (when response is expected to be effective)
  • Contingency plan (what to do if risk materialises)
  • Status (open/closed/on watch)
  • Triggers (leading indicators)
  • Residual risk after response

Exams often reward students for including triggers and contingency actions, not only response strategy labels.

1.7 Common exam pitfalls in risk management answers

Avoid:

  • Only listing risks without analysis.
  • Missing difference between risk and issue.
  • Not stating risk owners.
  • No monitoring plan/triggers.
  • Confusing quality risks (defects, non-conformance) with general project uncertainty.

Strong answers:

  • show structured thinking,
  • use tools logically (matrix, register, response planning),
  • link risk management to quality assurance and project governance.

2) Risk Identification, Analysis, Response Planning & Monitoring

2.1 Risk identification: methods and how to describe them

Risk identification is the discovery phase. In a PRM4802 exam response, you can describe techniques such as:

  1. Brainstorming / workshops
    • Invite PM, designers, engineers, procurement, quality, HSE.
  2. Interviews
    • Structured interviews with subject matter experts.
  3. Checklists
    • Use historical data and standard risk categories.
  4. Document review
    • Review contracts, scope statements, assumptions, baseline schedules.
  5. Lessons learned from similar projects
    • Organisational knowledge base.
  6. Assumption analysis
    • Risks often stem from weak or uncertain assumptions.
  7. SWOT analysis (sometimes used for opportunities/threats)
  8. Root cause analysis for known problem patterns

In South African project settings, identification often leverages:

  • contractor performance histories,
  • supplier lead-time reliability,
  • local procurement constraints,
  • permit/inspection cycles,
  • community engagement realities.

2.2 Example: identifying risks for a municipal water infrastructure upgrade in South Africa

Consider a hypothetical project: upgrading pipelines for improved water supply in a municipality. Although this is an exam scenario, it mirrors typical contexts.

Potential assumptions:

  • Materials will arrive on time from suppliers.
  • Weather conditions will be typical.
  • Municipal permits will be approved within expected timelines.
  • Contractor capacity is sufficient.

From these assumptions, you identify risks:

  • Procurement delay (supplier lead-time overrun).
  • Rain/wet season delays (work stoppages, safety hazards).
  • Permit approval delay (inspection/approval backlog).
  • Rework risk (quality of installation affects future leakage rates).
  • Stakeholder disruption (community complaints about roadworks).

Notice the exam-friendly logic: Assumption → potential failure mode → risk event → effect on objectives.

2.3 Risk analysis: qualitative vs quantitative approaches

You should explain that risk analysis can be:

  • Qualitative
    • Use probability/impact scales and matrices.
  • Quantitative
    • Use numerical methods like expected monetary value, simulation (Monte Carlo), or decision tree analysis.
    • Quantitative analysis is often used for high-impact/complex decisions.

In many UNISA exam questions, qualitative/semi-quantitative is expected. If a question asks for numbers, you use the probability/impact logic; if it asks for deeper modelling, you describe quantitative methods conceptually.

2.3.1 Semi-quantitative example with a risk matrix

Assume three risks are identified for a project:

  • R1 Procurement delay

    • Probability = 4 (likely)
    • Impact = 3 (moderate: schedule slip)
    • Score = 12 (High/Medium depending on your threshold)
  • R2 Design changes

    • Probability = 3 (possible)
    • Impact = 4 (major: rework and cost increase)
    • Score = 12
  • R3 Weather disruption

    • Probability = 2 (unlikely)
    • Impact = 4 (major: safety stop and rework)
    • Score = 8

If your threshold defines:

  • 1–7 = Low
  • 8–12 = Medium
  • 13–25 = High

Then R1 and R2 are Medium (score 12), and R3 is Low to Medium (score 8). Your selection of thresholds must be consistent with later “risk ranking” statements.

2.4 Risk response planning: strategies and when to use them

In PRM4802, responses typically include:

  • Avoid: eliminate the risk by changing the plan.
  • Mitigate: reduce probability and/or impact.
  • Transfer: shift risk to another party (insurance, contracts).
  • Accept: acknowledge risk; no action beyond monitoring.
  • Exploit (for opportunities): increase probability/impact of beneficial events.
  • Share (for opportunities): partner collaboration to capture benefits.
  • Enhance (for opportunities): strengthen conditions that lead to positive outcomes.

2.4.1 Distinguish mitigation from contingency

A common exam weakness is mixing these up:

  • Mitigation: actions taken before the risk occurs (reduce likelihood or impact).
  • Contingency: actions planned if the risk occurs (fallback plan).

In exam answers, you should provide both where appropriate.

2.5 Response planning: build a structured “if-then” logic

Strong exam answers often use conditional statements. Example logic:

  1. If supplier lead-time exceeds 15 business days,
  2. Then activate expedited shipping or alternate supplier,
  3. And update schedule baseline,
  4. And notify stakeholders using the communication plan.

This leads to good risk register entries:

  • triggers,
  • contingency actions,
  • response owners,
  • target dates.

2.6 Example: response strategies for a transport infrastructure project

Imagine a project involving construction of a road section with a contractor-based model.

Risks:

  • R4 Quality non-conformance (e.g., asphalt thickness or compaction not meeting specs)
  • R5 Labour shortages (late availability of subcontractors)
  • R6 Material price escalation (bitumen and aggregates)
  • R7 Safety incidents (falls, machine hazards)

Responses:

  • R4: mitigate via enhanced QA inspections, compaction testing schedule, independent sampling, and corrective action procedure.
  • R5: mitigate via resource planning, contracting additional subcontractor capacity, and reviewing critical path dependencies.
  • R6: mitigate via price escalation clauses, early procurement of materials, and cost contingency.
  • R7: mitigate via HSE training, toolbox talks, hazard identification, site safety audits, and strict compliance controls; sometimes accept with strong controls if probability is low and impacts are manageable.

Notice that “quality response” is not only about schedule or cost—it’s tied to quality plans and standards.

2.7 Risk monitoring and controlling: what to track during execution

Risk monitoring means:

  • track risk triggers,
  • review risk status (probability/impact changes),
  • ensure response actions are executed,
  • identify new risks as project conditions change,
  • report risk information in project reporting cycles.

Key elements include:

  • Risk reviews (weekly/bi-weekly depending on project intensity)
  • Status updates in project governance meetings
  • Trend analysis (e.g., increasing frequency of defects)
  • Residual risk assessment after response actions
  • Escalation thresholds (when management must be informed)

2.7.1 Leading indicators and triggers (must be explicit)

Triggers are early signals that a risk is becoming more likely or more severe. Examples:

  • Procurement delay risk trigger:
    • “supplier confirms ship date slipping by more than 5 business days”
  • Quality risk trigger:
    • “test results show compaction below threshold for two consecutive samples”
  • Safety risk trigger:
    • “near-miss incident count increases above baseline average for the last 2 weeks”

In exam answers, specifying triggers earns marks because it demonstrates monitoring competence.

2.8 Integrating risk responses with project governance

Risk management is not separate from management. A good structure is:

  • risk register is maintained by risk owner/team,
  • PM ensures risk reviews occur,
  • quality manager ensures quality-related risks connect to QA/QC plans,
  • procurement ensures contract risk allocation is correct,
  • HSE ensures safety risks follow compliance.

In South African practice, governance often involves:

  • steering committee meetings,
  • project sponsor oversight,
  • internal audit and compliance checks,
  • contractor performance management.

You can score well by explaining how reports flow:

  • from risk owner → PM → steering committee → decision to allocate resources or update baselines.

3) Quality Management in Projects: Planning, Assurance, Control & Improvement

3.1 Quality meaning in project risk and quality management

In PRM4802, “quality” refers to meeting requirements and intended use. The key difference you should be able to explain:

  • Quality management: broader approach that includes planning and improvement.
  • Quality assurance (QA): processes designed to ensure quality requirements will be met.
  • Quality control (QC): inspection/testing to verify outputs meet requirements.
  • Continuous improvement: systematic actions to enhance performance over time.

Quality is also an objective of the project and is linked to risk:

  • poor quality increases rework (cost and schedule risk),
  • quality failures may create stakeholder dissatisfaction and compliance issues.

3.2 Quality planning: turning requirements into measurable acceptance criteria

Quality planning converts requirements into:

  • measurable standards,
  • inspection/test plans,
  • documentation requirements,
  • acceptance criteria.

Typical planning artefacts:

  • Quality management plan (QMP)
  • Quality plan for specific deliverables
  • Inspection and test plan (ITP)
  • Method statements and work instructions
  • Document control procedures
  • Non-conformance and corrective action procedures

3.2.1 Quality requirements example: “thickness and compaction”

Suppose an asphalt installation must meet specific performance requirements. Quality planning translates requirements into:

  • asphalt thickness tolerance (e.g., within specified mm range),
  • compaction method and acceptance thresholds,
  • frequency of lab tests and sampling plans,
  • documentation (test certificates, calibration records for instruments),
  • acceptance criteria for rework or rejection.

In exams, it’s valuable to say: quality planning creates traceability from requirement → test/inspection → decision.

3.3 Quality assurance: preventing defects rather than detecting them late

Quality assurance focuses on systems:

  • training,
  • standard operating procedures,
  • audits,
  • compliance with documented processes,
  • supplier qualification.

QA practices include:

  • internal audits,
  • management reviews of QMS,
  • verification of subcontractor processes,
  • ensuring calibration of measuring equipment,
  • document control and configuration management.

In answers, emphasise that QA reduces the likelihood of defects, which is essentially a mitigation response to quality risks.

3.4 Quality control: verification through inspection, testing, and documentation

Quality control includes the “check” activities:

  • inspections at defined stages,
  • testing of materials and workmanship,
  • reviewing records to confirm compliance.

A QC process is typically:

  1. define acceptance criteria,
  2. perform inspection/testing,
  3. record results,
  4. compare results to criteria,
  5. decide: accept, request rework, or reject,
  6. initiate corrective action for non-conformance.

3.4.1 Example QC workflow for construction deliverables

Stage gates:

  • Base preparation inspection
  • Reinforcement check
  • Pouring/concrete tests (if applicable)
  • Asphalt placement inspection
  • Compaction test verification
  • Final measurements and sign-off

For each stage:

  • inspectors use checklists,
  • tests are logged,
  • results are verified by QC lead,
  • non-conformances go to corrective action process.

3.5 Non-conformance management and corrective action

Non-conformance (NC) means outputs fail to meet requirements. PRM4802 often expects knowledge of:

  • classification of non-conformance (major/minor),
  • containment (stop further work; isolate non-conforming output),
  • root cause analysis (why it happened),
  • corrective action (fix cause),
  • verification of effectiveness,
  • documentation and closure.

Root cause analysis may use:

  • 5 Whys,
  • fishbone (Ishikawa),
  • Pareto analysis.

In exam answers, connect NC management to risk:

  • recurring NC indicates systemic risks (training gaps, vendor quality issues, inadequate process control).

3.6 Continuous improvement and the PDCA cycle

A central theme is continuous improvement, commonly expressed as Plan–Do–Check–Act (PDCA):

  • Plan: identify problem, define objectives, plan changes.
  • Do: implement the process change or corrective action.
  • Check: measure results against targets.
  • Act: standardise improvements or iterate with further analysis.

This cycle links strongly with risk monitoring:

  • quality performance data becomes input for quality risks and project risk re-assessment.

3.7 Link between risk management and quality management (must be explicit)

PRM4802 expects you to show integration:

  • Quality planning mitigates quality risk (prevention).
  • QC detects quality issues early, preventing escalation into bigger cost/time risks.
  • Non-conformance trends become risk indicators for future probability/impact changes.
  • Corrective actions reduce residual risk and improve future project performance.

A high-quality exam answer clearly states that risk management and quality management are not separate silos.

4) Tools and Techniques for Integrated Risk & Quality Management (with Practical Scenarios)

4.1 The “integrated” mindset: one register, aligned responses

A frequent exam scenario: students separate quality and risk, but PRM4802 questions typically ask you to integrate. The integrated approach means:

  • quality failures are treated as risk events (or risks that manifest),
  • risk responses include quality assurance and control actions,
  • quality data feeds into risk updates.

A well-structured answer might reference:

  • risk register entries that include quality elements,
  • QA/QC plan updates based on risk assessment outcomes,
  • escalation rules when quality risks exceed tolerance.

4.2 Example integrated scenario: Warehouse construction and commissioning

Consider an exam scenario where a company builds a warehouse for cold storage and then commissions it.

Key quality requirements:

  • insulation performance,
  • refrigeration system performance,
  • air leak prevention,
  • correct installation of temperature monitoring equipment.

Associated risks:

  • R8 Refrigeration installation quality risk
    • probability: possible
    • impact: major (food spoilage risk, compliance risk)
  • R9 Commissioning delay due to calibration/documentation
    • probability: likely
    • impact: moderate-high (schedule slip)
  • R10 Supplier of refrigeration parts
    • probability: possible
    • impact: major (system failure, safety risk)

Responses:

  • QA: supplier qualification checks, calibration verification before delivery and installation, documented method statements.
  • QC: pressure tests, temperature calibration tests, witness inspections at key stages.
  • Risk triggers: calibration drift beyond acceptable tolerance triggers re-testing; repeated QC failures triggers process review.
  • Contingency: alternate equipment, additional commissioning support team, buffer schedule for rework.

This scenario helps you show both risk and quality thinking.

4.3 Quality cost of poor quality (COPQ): prevention, appraisal, and failure costs

A strong quality topic frequently tested is the economics of quality. You can describe:

  • Prevention costs: training, quality planning, QA systems
  • Appraisal costs: inspections, tests, audits
  • Internal failure costs: rework before delivery, waste, scrap
  • External failure costs: warranty claims, returns, penalties, reputational damage

In project terms:

  • investing in prevention and appraisal reduces internal/external failures,
  • reduced failures reduce schedule slippage and cost overruns caused by rework.

Even if a question doesn’t give figures, examiners appreciate that you understand why quality investment can be cost-effective.

4.4 Control charts and inspection sampling (conceptual exam coverage)

Some exam questions ask for the purpose of control charts and statistical sampling. You should state clearly:

  • Control charts monitor process stability over time.
  • Variation within control limits suggests common-cause variation.
  • Signals outside limits suggest special-cause variation (root cause likely needed).

Inspection sampling:

  • reduces inspection load,
  • but must be statistically justified to avoid accepting bad lots.
  • random sampling should be described conceptually.

If numbers are given, apply the logic; if not, explain purpose and limitations.

4.5 Acceptance criteria and “fit for purpose”

Quality isn’t just compliance; it’s meeting intended use. In exam answers, mention:

  • “fit for purpose” means deliverables meet performance needs,
  • acceptance criteria should be clear and measurable,
  • stakeholder requirements must be captured early to avoid later rework (scope-quality risk).

4.6 Risk tools that link to quality outcomes

Here are practical tools you can mention and relate to quality:

  • Cause-and-effect diagrams for root causes of defects.
  • Pareto analysis to focus on the most frequent defect types (80/20 logic).
  • Failure Mode and Effects Analysis (FMEA)
    • identify potential failure modes,
    • assess severity, occurrence, detection,
    • prioritise actions by risk priority number.
  • Fault Tree Analysis or event-based logic in complex systems (if asked).

Even when not asked by name, you can show understanding: identify failure modes, analyse causes, set controls and detectability measures.

4.7 Decision-making with risk and quality: trade-offs

Sometimes the project must trade:

  • schedule vs quality,
  • cost vs quality,
  • speed vs inspection depth.

In exam answers, show you know that:

  • reducing inspection (cutting appraisal costs) can increase failure costs,
  • skipping QA steps increases probability of rework,
  • schedule acceleration can introduce process shortcuts that increase defect probability.

A balanced answer includes:

  • mention risk appetite,
  • propose balanced strategies,
  • insist on critical path quality gates and stage inspections.

4.8 Mini case study: defect recurrence in a contractor-led project

Suppose a contractor has repeated non-conformance on concrete curing procedures. QC finds issues in two consecutive months, causing rework. The integrated risk-quality interpretation:

  • Quality risk: increased probability of future defective pours.
  • Root cause might be:
    • training gap,
    • missing work instructions,
    • wrong curing materials,
    • inadequate supervision.

Actions:

  • corrective action: training + revised method statement,
  • QA: audit contractor adherence to curing plan,
  • QC: increased test frequency for next pours,
  • risk monitoring: set trigger for third recurrence; if it occurs, escalate to contract management.

This is exam gold because it demonstrates feedback loops between QC findings and risk reassessment.

5) Exam Answer Frameworks, Calculations, Standards, and South Africa-Linked Scenarios

5.1 How to structure PRM4802 exam answers for maximum marks

A reliable exam structure:

  1. Define the term (risk/quality/QA/QC/non-conformance).
  2. Explain the process (steps in risk management or quality management).
  3. Name tools/artefacts (risk register, risk matrix, triggers, ITP/QMP).
  4. Apply to a scenario (provide example risks and responses).
  5. Include monitoring and governance (reviews, escalation, documentation).
  6. Link risk and quality where relevant.
  7. Conclude with practical significance.

For 10–15 mark questions, a good time allocation:

  • 2–3 marks: definitions and purpose,
  • 5–7 marks: step-by-step process,
  • 3–5 marks: tools and scenario application,
  • 1–2 marks: integration and conclusion.

5.2 Risk calculation: expected value style (when numbers appear)

If an exam includes numerical risk modelling (expected cost impacts), you can use:

  • Expected impact = Probability × Impact (in cost or time units)

If there are multiple risks, you may compute total expected impact:

  • Total expected impact = sum of expected impacts
    Then you can compare with contingency budgets.

Be careful: if you used probability as a percentage in one place, keep it as the same unit everywhere. Use clear formatting in your answer.

5.3 Worked example: risk response budgeting with consistent numbers

Assume a project has two major risks with cost impact estimates:

  • R1: Procurement delay

    • Probability = 0.3
    • Cost impact if it occurs = R500,000
    • Expected cost = 0.3 × 500,000 = R150,000
  • R2: Quality rework due to non-conformance

    • Probability = 0.2
    • Cost impact if it occurs = R800,000
    • Expected cost = 0.2 × 800,000 = R160,000

Total expected cost = R150,000 + R160,000 = R310,000

If management sets a risk contingency of R350,000, you can comment:

  • contingency exceeds expected cost by R40,000,
  • but expected cost is not the worst case, so contingency is about balancing cost vs risk tolerance.

In later narrative parts of the answer, keep these values consistent.

5.4 Quality management budgeting logic: why prevention and appraisal can reduce failure costs

In exam questions about cost of quality (COPQ), you can state:

  • prevention and appraisal costs are deliberate spending,
  • failure costs rise when defects escape or when correction occurs late,
  • therefore an optimal balance is to reduce failure costs by improving prevention and appraisal.

If the question gives categories, apply them correctly. If it doesn’t, explain conceptually and use typical examples:

  • training and process controls (prevention),
  • inspections and lab testing (appraisal),
  • rework and scrap (internal failure),
  • customer claims and penalties (external failure).

5.5 Standards and compliance: how to mention them without getting lost

PRM4802 often expects students to connect to established quality and risk frameworks conceptually. You should mention standards/approaches generally, focusing on what they require:

  • Quality management systems emphasise documentation, process control, audit, and improvement.
  • Risk management emphasises structured identification, analysis, response planning, and monitoring.

In exam answers, you can use phrases like:

  • “align quality planning with organisational quality management system requirements,”
  • “ensure risk register is integrated into project reporting and governance,”
  • “support compliance with applicable regulations and contract requirements.”

You should avoid making up specific standard clause numbers unless the exam question provides them.

5.6 South Africa-linked project examples you can reuse in exams (without changing facts)

Because UNISA students often need locally relevant scenarios, use consistent archetypes:

5.6.1 Construction and infrastructure delivery

Typical risks:

  • weather and site access,
  • supplier lead times,
  • permit/inspection cycles,
  • safety incidents,
  • defects and rework.

Typical quality controls:

  • stage inspections,
  • lab test records,
  • calibration checks,
  • non-conformance management.

5.6.2 ICT or systems delivery (software/system projects)

Typical risks:

  • requirement volatility,
  • integration delays,
  • vendor dependencies,
  • performance shortfalls,
  • security and compliance issues.

Quality management:

  • acceptance testing criteria,
  • defect management,
  • QA reviews and traceability (requirements → tests),
  • change control and configuration management.

5.6.3 Service delivery and operations

Typical risks:

  • resource constraints,
  • process non-adherence,
  • stakeholder dissatisfaction,
  • compliance failures.

Quality:

  • SOPs, audits, service-level measurement,
  • corrective actions and improvement cycles.

In an exam, you can select one archetype and develop a full risk-quality response around it.

5.7 Likely UNISA-style question patterns and “model elements” to include

Here are patterns and what examiners typically look for:

Pattern A: “Discuss the steps in risk management and justify responses”

Include:

  • planning phase,
  • identification methods,
  • qualitative/quantitative analysis,
  • response strategies,
  • monitoring/triggers,
  • risk register governance.

Pattern B: “Explain quality assurance vs quality control”

Include:

  • definitions,
  • examples of QA (audits, training, process adherence),
  • examples of QC (inspection, testing, acceptance),
  • link to quality costs and continuous improvement.

Pattern C: “Create a risk register entry for given scenario”

Include:

  • risk description with cause and effect,
  • category,
  • probability and impact,
  • score,
  • response strategy,
  • owner,
  • trigger,
  • contingency plan.

Pattern D: “Link risk and quality management”

Include:

  • quality problems as risks,
  • QC results updating risk,
  • corrective actions reducing residual risk,
  • integrated reporting and governance.

5.8 Sample exam-style risk register entries (ready-to-adapt)

Below are entries written in a style you can mimic. Keep your wording concise in the exam, but include all essential fields.

Entry Example 1: Quality rework due to non-conformance

  • Risk ID: R-QC-01
  • Description: Work does not meet specification requirements, leading to defects and rework.
  • Cause(s): Inadequate process adherence; insufficient training; calibration gaps.
  • Consequence(s): Increased cost, schedule delay, stakeholder dissatisfaction, potential compliance issues.
  • Category: Quality risk (and schedule/cost knock-on risk)
  • Probability rating: 3 (possible)
  • Impact rating: 4 (major)
  • Risk score: 12
  • Response strategy: Mitigate
  • QA actions: process audits; training refresh; document control; calibration verification.
  • QC actions: stage inspections; test sampling; acceptance criteria checks; record review.
  • Owner: Quality Manager
  • Trigger: two consecutive non-conformance test failures or missing calibration records.
  • Contingency: stop-work for affected areas; corrective action; rework plan; re-inspection prior to sign-off.

Entry Example 2: Procurement delay

  • Risk ID: R-PROC-02
  • Description: Supplier lead time exceeds planned schedule, causing downstream work stoppage.
  • Cause(s): logistics disruptions; supplier capacity constraints; incomplete documentation.
  • Consequence(s): schedule slip; increased cost due to expediting; potential quality compromise due to rushed work.
  • Category: Procurement/schedule risk
  • Probability rating: 4 (likely)
  • Impact rating: 3 (moderate)
  • Risk score: 12
  • Response strategy: Mitigate + Transfer (where contract permits)
  • Mitigation: early ordering; alternate supplier qualification; expediting plan.
  • Transfer: include liquidated damages/penalties or supply contract clauses where feasible.
  • Owner: Procurement Lead
  • Trigger: confirmed delivery date slips by more than 5 business days.
  • Contingency: activate alternate supplier; revise schedule baseline; communicate impacts via change control.

These entries demonstrate the integrated approach: procurement delay risks can indirectly create quality risks if work is rushed.

5.9 Putting it together: a full integrated mini-answer (template)

In some exams, you may be asked to “discuss” using a scenario. A compact template:

  1. State definitions: risk, risk management, quality assurance, quality control, non-conformance.
  2. Explain process: risk identification → analysis → response planning → monitoring; and quality planning → QA → QC → corrective action.
  3. Provide a scenario application:
    • list 3–5 risks,
    • for each: give probability/impact and a response,
    • include triggers and owners.
  4. Demonstrate integration:
    • quality findings update risk register,
    • risk mitigation includes QA/QC steps,
    • residual risk is monitored.
  5. Conclude with governance:
    • risk reviews,
    • reporting,
    • lessons learned.

Use consistent language and make sure the scenario logic is consistent throughout.

5.10 Final checklist for exam performance

Before submitting your exam response, ensure it includes:

  • At least one definition (risk and quality terms).
  • Clear process steps (not just definitions).
  • Tools/artefacts (risk register, risk matrix, QMP/QC plan/ITP, triggers).
  • Ownership and monitoring (owners, triggers, reviews, escalation).
  • Integration between risk and quality.
  • Scenario application with realistic responses.

Consistency Note on Numbers

The risk calculation example in Section 5.3 uses:

  • R1 expected cost = R150,000
  • R2 expected cost = R160,000
  • Total expected cost = R310,000
  • Contingency set at R350,000
    These values are not reused elsewhere with different meanings.

Quick Summary of Key Exam Themes (for revision recall)

  • Risk management: structured identification, analysis (probability/impact), response planning, monitoring with triggers, risk register governance.
  • Quality management: quality planning (acceptance criteria), QA systems to prevent defects, QC testing/inspection to verify requirements, non-conformance handling and continuous improvement (PDCA).
  • Integration: quality failures are risk events; QC results feed risk updates; corrective actions reduce residual risk.
  • Answer technique: definitions + process + tools + scenario + monitoring + governance.

End of PRM4802 Exam Notes (South Africa University Notes Style)

These notes are designed to support exam writing for UNISA PRM4802 Project Risk and Quality Management, aligning risk and quality thinking into a single coherent project management competency.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare