UJ’s Project Risk Management module (PRM3BB3) builds the practical skills you need to identify, analyse, evaluate, and respond to project risks using structured risk management processes, evidence-based decision-making, and disciplined documentation. In the South African university context, students typically face questions that test both theory (risk concepts, risk response strategies, risk ownership) and applied reasoning (risk registers, probability–impact scoring, scenario analysis, and interpreting controls). This guide focuses specifically on what is commonly assessed in UP/UNISA/CUT-style risk and project management papers, with strong emphasis on exam-ready structures, step-by-step methods, and worked examples.
How PRM3BB3 Fits the Project Risk & Quality Management Course (UJ Focus + Typical Exam Patterns)
What “Project Risk Management” Usually Means in PRM3BB3
In a UJ module like PRM3BB3, “risk” is not treated as vague uncertainty. It is treated as an event or condition that, if it occurs, could have a positive or negative effect on project objectives such as scope, schedule, cost, quality, safety, and compliance. Exam questions often expect you to distinguish:
- Risk (uncertain event/condition)
- Issue (problem that has already happened)
- Threat (negative risk)
- Opportunity (positive risk)
- Uncertainty (broader ambiguity—often handled by defining risks)
A strong exam answer typically begins with a definition and quickly connects it to project objectives. Many students lose marks by giving only generic definitions instead of using them to structure a response plan or register.
Common UJ PRM3BB3 Assessment Skills
While exact assessment rubrics vary by lecturer, the module is commonly assessed through tasks that require:
- Risk identification using structured techniques (e.g., brainstorming, checklists, interviews).
- Risk classification (e.g., technical, schedule, cost, external/regulatory, procurement).
- Risk analysis:
- qualitative (probability–impact scoring),
- semi-quantitative (risk scoring matrices),
- quantitative (expected monetary value, scenario-based methods).
- Risk evaluation (prioritising risks that matter most).
- Risk response planning:
- avoid,
- mitigate,
- transfer,
- accept,
- exploit,
- share,
- enhance,
- contingencies and triggers.
- Risk monitoring and control:
- risk audits,
- tracking trigger thresholds,
- updating the risk register.
Linking Risk Management to Project Quality
Even though PRM3BB3 is risk-focused, exam questions often integrate quality because quality failures often create project risks (rework, defects, compliance issues). Quality risk themes you should be ready to connect:
- Specification risk: wrong requirements lead to rework.
- Process risk: inadequate processes create defects.
- Supplier/contractor quality risk: poor workmanship or materials.
- Inspection/acceptance risk: weak acceptance criteria cause “latent defects.”
A high-scoring answer typically frames risk responses in quality language:
- quality standards,
- verification and validation,
- inspection plans,
- measurable acceptance criteria,
- corrective actions integrated into risk treatment.
Typical South African Exam Style Prompts
UJ modules often use prompts similar to those seen across SA universities (e.g., UNISA project management or risk modules, and CUT operations/project management exams). You may see questions like:
- “Identify and justify at least 8 risks for this scenario.”
- “Create a risk register with probability, impact, rating, and response.”
- “Choose a risk response strategy and explain why it is suitable.”
- “Explain how you would monitor and control risks during execution.”
- “Distinguish between risk, issue, and opportunity.”
- “Use a risk matrix to prioritise risks and justify top 3 decisions.”
When reading such questions, the key is to keep your answer structured and measurable. Examiners commonly award marks for:
- correct identification of risks,
- coherent scoring logic,
- plausible response strategies,
- strong linking of risk ownership and triggers to monitoring.
Core Concepts, Definitions, and Risk Management Frameworks (What You Must Get Right in Exams)
Risk vs Issue vs Uncertainty (Exam-Grade Distinctions)
These distinctions are frequent exam traps. Use the following approach:
- Risk: may occur in the future; uncertainty remains.
- Issue: occurred already; uncertainty ended; needs issue resolution.
- Uncertainty: broad unknowns; may or may not be captured as risks depending on impact and likelihood.
Example (construction project in Johannesburg):
- Risk: “Supply chain disruptions may delay cement deliveries.”
- Issue: “Cement order did not arrive and construction crew is idle today.”
- Uncertainty: “We are unsure whether there will be load-shedding during the construction window.”
- You convert uncertainty into a risk if you can assess probability and impact.
In your exam answers, you should explicitly state why something is an issue rather than a risk. This is where many students lose marks by using “risk” vocabulary for already-realised problems.
Risk Appetite and Risk Tolerance (And Why It Matters)
Risk management in real projects is guided by how much risk the organisation is willing to accept.
- Risk appetite: overall philosophy (e.g., “we are willing to accept moderate risk to maintain schedule”).
- risk tolerance: limits for specific objectives (e.g., “cost overrun tolerance is 3%”).
In exams, even if the question doesn’t explicitly use these terms, you can earn marks by showing that you understand that not all risks are treated the same. For instance:
- High-impact, high-likelihood risks exceed tolerance → require treatment or escalation.
- Low-level risks within tolerance → may be accepted with monitoring.
- Opportunities may be pursued if they align with appetite.
Risk Ownership and Accountability
A risk register without clear ownership is often marked down. Risk ownership means an identified person/team accountable for:
- ensuring response actions occur,
- monitoring risk indicators,
- updating likelihood and impact,
- escalating changes.
Common ownership roles:
- Project Manager (overall accountability)
- Functional leads (technical, procurement, QA)
- Contract or supplier manager (contractual risks)
- Health & Safety officer (safety risks)
- Financial controller (cost and budget risks)
In a strong exam answer, you should link ownership to risk type. For example:
- schedule risk → owned by project scheduling lead,
- procurement quality risk → owned by supplier quality manager,
- regulatory compliance risk → owned by compliance officer.
Risk Management Process (A Practical PRM3BB3 Workflow)
A widely accepted project risk management flow (consistent with many SA curricula and international standards) is:
- Plan Risk Management
- Identify Risks
- Analyse Risks
- Evaluate Risks
- Plan Risk Responses
- Implement Responses
- Monitor and Review Risks
Exams typically test your ability to apply these steps sequentially, rather than jumping straight to “responses.”
Plan Risk Management: What to Include in Your Answer
When asked “plan risk management,” students often respond vaguely. Use an exam-ready checklist:
- Risk management methodology (qualitative vs quantitative)
- Definitions (probability scale, impact scale, rating formula)
- Templates (risk register fields)
- Roles and responsibilities
- Reporting frequency (e.g., weekly risk review during execution)
- Risk categories to structure identification
- Escalation criteria (e.g., risks above rating threshold go to steering committee)
- Budgeting for contingency reserves and management reserves
A strong answer includes the reasoning behind choices. For example:
- Qualitative scoring is chosen when data is limited, time is short, or the project is small.
Risk Categories: How to Avoid Random, Unstructured Risks
Risk identification improves when you use categories. A useful exam categorisation is:
- Project management risks: planning errors, weak governance, poor stakeholder management.
- Technical risks: design complexity, technology immaturity.
- Schedule risks: dependencies, approvals, labour availability.
- Cost risks: inflation, scope creep, resource cost increases.
- Quality risks: defects, non-compliance, insufficient QA/QC.
- Safety and environmental risks: accidents, permits, hazardous materials.
- Procurement/contract risks: supplier performance, contract gaps.
- External risks: political/regulatory changes, economic fluctuations, utilities disruptions.
When you write your risk register, label each risk with a category. That makes your answer more “professional” and helps exam markers see you understand structure.
Risk Identification and Risk Analysis Using Scoring Matrices and Registers (Worked Examples for PRM3BB3)
Building an Exam-Ready Risk Register (Fields That Usually Earn Marks)
A typical risk register table includes:
- Risk ID
- Risk statement (event/condition and effect)
- Category
- Owner
- Probability (P)
- Impact (I)
- Risk score (e.g., P × I)
- Risk rating band (Low/Medium/High)
- Risk response strategy
- Planned actions
- Contingency plan / fallback actions
- Triggers (indicators for monitoring)
- Status (Open/Closed/Monitoring)
- Review date
Even if the exam doesn’t specify all fields, you should include the most likely ones. The key is consistency: the probability scale and impact scale must match throughout your response.
Probability–Impact Matrices: How to Score Correctly
You must be consistent. A common scoring model is:
- Probability scale: 1–5
1 = very low, 5 = very high - Impact scale: 1–5
1 = negligible, 5 = severe
Risk score = P × I ranges from 1 to 25.
A typical rating approach:
- 1–5 = Low
- 6–12 = Medium
- 13–25 = High
Your exam answers should justify the rating threshold if prompted. If not prompted, you can still state it clearly at the start of the risk scoring section.
Worked Example Scenario: University Infrastructure Upgrade (Exam-Style)
Consider a fictional but realistic scenario relevant to South African project contexts:
Scenario: A project to upgrade a campus laboratory facility at a South African university. The lab requires new electrical systems, ventilation upgrades, and compliance documentation. The project timeline is 20 weeks and the project budget is R 2,000,000. Procurement involves two major suppliers:
- Supplier A: electrical components
- Supplier B: ventilation equipment
Risks must be identified and prioritised.
Step 1: Identify Risks (At Least 8, with Categories)
Below are example risks written in a standard “event → effect” form.
| Risk ID | Risk statement | Category |
|---|---|---|
| R1 | Delayed supplier deliveries from Supplier A may delay installation activities. | Procurement/Schedule |
| R2 | Unplanned load-shedding may interrupt electrical testing and extend commissioning time. | External/Schedule |
| R3 | Design documentation errors may require rework and lead to quality deviations. | Technical/Quality |
| R4 | Ventilation equipment lead times from Supplier B may exceed plan, impacting commissioning. | Procurement/Schedule |
| R5 | Failure to obtain updated compliance certificates on time may delay lab handover. | Regulatory/Compliance |
| R6 | Inadequate QA/QC on installation may result in defects and rework. | Quality |
| R7 | Labour availability constraints may reduce productivity and shift the critical path. | Resource/Schedule |
| R8 | Currency fluctuations affecting imported components may cause cost overruns. | Cost/External |
You can adapt these to any exam scenario, but maintain the structure.
Step 2: Assign Probability and Impact (Consistent Scales)
Assume probability and impact ratings are:
- Probability: 1 (Very Low) to 5 (Very High)
- Impact: 1 (Very Low Effect) to 5 (Severe Effect)
Now assign plausible ratings based on scenario characteristics:
- R1: Supplier A delays are moderately likely: P=3, impact on schedule is high: I=4
- R2: Load-shedding is unpredictable but common enough: P=3, impact on testing and commissioning: I=3
- R3: Design documentation errors are possible due to contractor coordination: P=2, impact: I=4
- R4: Supplier B lead times risk is higher: P=4, impact: I=4
- R5: Compliance certificates risk is significant due to administrative lead times: P=3, impact: I=5
- R6: QA/QC failure risk: P=2, impact: I=4
- R7: Labour constraints: P=3, impact on productivity: I=3
- R8: Currency fluctuations affecting imported components: P=2, impact: I=4
Compute risk scores:
- Risk score = P × I
| Risk ID | P | I | Score | Rating |
|---|---|---|---|---|
| R1 | 3 | 4 | 12 | Medium |
| R2 | 3 | 3 | 9 | Medium |
| R3 | 2 | 4 | 8 | Medium |
| R4 | 4 | 4 | 16 | High |
| R5 | 3 | 5 | 15 | High |
| R6 | 2 | 4 | 8 | Medium |
| R7 | 3 | 3 | 9 | Medium |
| R8 | 2 | 4 | 8 | Medium |
From this matrix, top risks are:
- R4 (High)
- R5 (High)
Potentially also R1 if your exam rubric treats 12 as high in some bands, but based on the stated banding, R1 is Medium.
Risk Response Planning: Matching Strategies to Risk Types
Risk response strategies should be chosen based on risk nature.
For threats (negative risks):
- Avoid: remove threat source (e.g., change procurement route).
- Mitigate: reduce probability and/or impact (e.g., buffer time, quality assurance).
- Transfer: shift impact to another party (e.g., warranties, contract clauses, insurance).
- Accept: no active treatment beyond contingency; monitor.
For opportunities (positive risks):
- Exploit, Enhance, Share, Accept (depending on whether you want to pursue the benefit)
Example Responses for the Top Risks
R4: Supplier B lead times exceed plan (P=4, I=4, Score=16 High)
Likely response:
- Mitigate: order earlier, negotiate delivery schedules, include penalty/expedite clauses.
- Transfer: include contractual clauses for late delivery with financial penalties.
- Contingency: identify an alternative supplier shortlist or plan to perform installation in sections pending delivery.
Response actions you could write in an exam:
- “Negotiate delivery milestone dates with Supplier B; require progress reporting and confirm availability by Week 4.”
- “Allocate contingency lead time of 2 weeks in the schedule.”
- “Request partial shipment where feasible.”
Triggers for monitoring:
- “Supplier B delivery confirmation missed by Week 4.”
- “Supplier B manufacturing status indicates more than 1 week delay.”
- “Purchase order amendment rejected.”
R5: Compliance certificates delay lab handover (P=3, I=5, Score=15 High)
Likely response:
- Mitigate: start compliance process early; assign dedicated compliance coordinator.
- Avoid (limited in practice): ensure documentation completeness upfront.
- Accept only if contingency handover processes exist (e.g., temporary permits).
Response actions:
- “Engage compliance officer from Week 1; maintain a documentation checklist for electrical and ventilation compliance.”
- “Submit compliance applications immediately after commissioning readiness achieved.”
- “Hold pre-inspection walkthroughs with inspectors.”
Triggers:
- “Compliance submission not completed by Week 10.”
- “Inspector feedback indicates missing evidence or non-conformance.”
Semi-Quantitative Enhancement: Expected Time Impact (Optional but Strong)
Some exams award extra marks if you convert risk impact into schedule impact.
Example:
- If supplier delays likely add 1–3 weeks, you can model:
- 1 week at P=3 scenario,
- 2 weeks at P=4 scenario,
- 3 weeks at P=4 or higher.
However, since PRM3BB3 often emphasises manageable scoring, stick to what your lecturers use. The safest approach is to use the risk matrix and then justify selected contingency buffers with clear logic.
Risk Response Implementation, Monitoring & Control, and Exam-Style Case Applications
Turning Risk Plans into Actions (Who Does What)
A common weakness in student answers: they propose responses but not implementation details. In PRM3BB3-type answers, you should specify:
- Action (what exactly you will do)
- Owner (who will ensure the action occurs)
- Timing (when to do it)
- Resources (what capability is needed)
- Evidence (what document/record proves you acted)
Using the scenario:
R4 response actions:
- Owner: Procurement Manager (or Contracts Lead)
- Timing: negotiation before purchase orders finalised (e.g., before Week 4)
- Evidence: signed amendments/contract clauses; updated delivery schedule
R5 response actions:
- Owner: Compliance Coordinator (or QA/QC + Compliance lead)
- Timing: compliance engagement starts Week 1; submission by Week 10
- Evidence: submission receipts; compliance checklist completion record
Risk Monitoring and Control: What to Write in Exams
Monitoring isn’t just “watch risks.” Examiners want mechanisms, such as:
- Regular risk review meetings (weekly during execution, monthly earlier)
- Status updates in the risk register
- Risk audits (especially for high risks like R4 and R5)
- Variance analysis:
- schedule variance (SV),
- cost variance (CV),
- quality nonconformance logs
- Tracking triggers:
- procurement delivery milestones missed,
- inspection feedback changes,
- QA defect trends rising.
Risk Register Updates: How Risks Change
Risks evolve. A good exam answer should mention that:
- probability and impact can change as project information improves,
- risk can move from Medium to High or become Closed,
- new risks emerge when assumptions fail.
Example of evolution:
- Supplier B confirms new estimated lead time at Week 6.
- If lead time reduces to “within plan,” probability might drop from 4 to 2 or 3.
- Inspector identifies documentation gap at pre-inspection.
- Probability of compliance delay increases; impact remains 5.
Escalation Criteria (Marks Through Clarity)
A strong risk management plan includes escalation thresholds. Example:
- Any risk rated High (13–25) escalates to project steering committee within 2 working days after rating confirmation.
- Medium risks reviewed weekly but escalation only if:
- probability increases by 1 point,
- score increases above threshold,
- triggers occur.
Even if the exam doesn’t require you to specify exact days, mentioning an escalation process helps.
Contingency vs Management Reserves (Quality of Answer)
Students often confuse reserves. Use a clear explanation:
- Contingency reserve: money/time set aside to respond to known risks.
- Management reserve: extra buffer for unknown unknowns or unplanned work beyond known risks.
In exam settings, if you state:
- “R4 has contingency of 2 weeks and a budget contingency of R 60,000”
you show you understand that risk response uses reserves.
Consistency Check Example (Cost Logic)
Budget = R 2,000,000. Suppose you allocate:
- contingency for known schedule risks: 3% of budget = R 60,000
- If you reference this later, it must remain the same.
You can then mention:
- “If Supplier B delays exceed 2 weeks, trigger release of R 60,000 contingency for overtime/alternative logistics.”
A Full Mini Case Application (Exam-Ready Narrative Structure)
Assume the following additional exam detail is provided:
- The project duration is 20 weeks.
- Week 4 is the procurement negotiation checkpoint.
- Handover is dependent on compliance certificate completion.
Based on our earlier top risks:
R4 Monitoring Plan (High)
- Trigger 1: Supplier B manufacturing schedule not confirmed by Week 4 → escalate.
- Trigger 2: supplier reports more than 1 week delay by Week 6 → activate contingency plan to accelerate installation in parallel tasks and update schedule.
- Owner: Procurement Manager (supplier relationship owner)
R5 Monitoring Plan (High)
- Trigger 1: compliance submission checklist less than 90% complete by Week 8 → corrective action (documentation completion sprint).
- Trigger 2: inspector indicates major evidence gaps → escalate immediately.
Linking Risk Responses to Quality Assurance (Without Repeating Concepts)
When writing risk responses for installation projects, show that quality is a risk control mechanism.
Examples:
- For R6 (QA/QC failure), response includes:
- method statements,
- test plans,
- inspection test records,
- acceptance criteria.
You can add:
- “Hold point inspections before concealment (e.g., before electrical works are enclosed).”
This is a classic quality practice that also reduces risk by catching defects early.
Dealing with Uncertainty: Scenario Analysis in a Simple Way
Even if your module uses primarily qualitative scoring, exams sometimes ask about scenario thinking.
A simple exam-appropriate method:
- define 3 scenarios for a high risk (e.g., Supplier B lead time):
- Best case: on-time (Probability low)
- Likely case: +1 week delay
- Worst case: +3 weeks delay
- describe impacts on schedule and handover.
Then show how risk response differs across scenarios:
- best case: standard plan
- likely/worst case: contingency triggers and alternative tasks schedule.
Exam Preparation Toolkit for PRM3BB3: Templates, Common Questions, and High-Scoring Answer Strategies (UJ + South African University Style)
A “Risk Register” Template You Can Reproduce in Exams
Use this template format. You can copy the fields into your exam answer.
Risk Register Fields
- Risk ID:
- Risk statement:
- Category:
- Owner:
- Assumptions:
- Probability (1–5):
- Impact (1–5):
- Score (P×I):
- Rating band:
- Response strategy (avoid/mitigate/transfer/accept or exploit/enhance/share/accept):
- Planned action(s):
- Contingency action(s):
- Triggers/indicators:
- Review frequency:
- Status:
This template helps you structure marks efficiently. When an exam asks for a risk register, markers look for completeness and coherence more than perfect wording.
Common Exam Questions and What Markers Look For
Q1: “Define risk and explain the difference between risk and issue.”
High-scoring structure:
- Define risk.
- Define issue.
- Provide one example distinguishing them.
- Mention why it matters (planning vs resolution).
Q2: “Identify risks for the given project and build a risk matrix.”
High-scoring structure:
- Provide a list of risks (at least 8).
- Assign categories.
- Provide probability and impact scales (state your scales).
- Compute risk scores consistently.
- Prioritise top 3 risks and justify selection.
Q3: “Explain risk responses for top risks.”
High-scoring structure:
- For each top risk:
- state why it is top (score)
- select strategy and justify (e.g., “transfer via contract penalties because supplier delay is outside project control”)
- include planned actions and triggers.
Q4: “Describe risk monitoring and control mechanisms.”
High-scoring structure:
- risk reviews and reporting cadence
- triggers and indicator tracking
- risk register updates
- audits/assurance activities
- escalation process
High-Scoring Writing Techniques (That Don’t Require Extra Knowledge)
-
Use “event → effect” statements
Weak: “There is procurement risk.”
Strong: “If Supplier A delays deliveries, electrical installation will be delayed, causing schedule slip and potentially delayed commissioning.” -
Be consistent with scoring
If you define P and I scales, keep them identical. -
Match response type to risk control
Don’t suggest “avoid” when you cannot realistically remove the threat. Instead use mitigate/transfer. -
Add triggers
Examiners reward specificity. Triggers convert plans into something monitorable. -
Use ownership
Tie risks to roles. Without an owner, response is theoretical.
Typical Risks to Mention in SA University Project Contexts
To align with real SA project patterns (campus infrastructure, compliance-heavy works, procurement constraints), your identification should often consider:
- compliance and certification lead times (electrical safety, building compliance)
- contractor/supplier availability
- payment and cashflow disputes (procurement and contractor performance risk)
- load-shedding disruptions (testing and commissioning delays)
- currency fluctuations (imported equipment)
- health and safety compliance (permit delays, inspections)
- scope creep due to stakeholder changes (academic department expectations)
- data and documentation quality risks (missing evidence for compliance)
Even if the exam scenario differs, these categories are commonly relevant.
Quick “Do Not Lose Marks” Checklist
Avoid these common pitfalls:
- Treating issues as risks (using future language for already happened events).
- Mixing scoring bands without stating them.
- Changing a risk’s score later without explanation.
- Proposing responses without actions, owners, or triggers.
- Writing “accept the risk” without describing contingency or monitoring.
Worked Micro-Example: Choosing a Response Strategy Correctly
Suppose an exam includes this additional risk:
R9: Power supply instability may damage sensitive laboratory equipment during testing.
Category: Safety/Technical/External
Assume P=3 (moderate likelihood), I=5 (severe impact), score=15 (High)
Best response:
- Mitigate: schedule testing during stable windows, use voltage regulators/backup power where feasible.
- Transfer: if equipment is insured and supplier contracts specify liability for damage.
- Avoid: postpone testing until stable supply confirmed (if feasible).
A high-scoring answer explains why:
- “Transfer alone may not be enough because even if insured, equipment damage still causes schedule delay; thus mitigate is primary.”
Worked Micro-Example: Updating Risk Based on New Information
Assume at Week 6:
- Supplier B reports revised lead time within schedule, reducing probability.
Originally:
- R4 had P=4, I=4 → score 16 (High)
Updated:
- probability drops to P=2 (new evidence), impact remains I=4.
- New score = 2×4 = 8 (Medium)
Your updated risk register should state:
- reason for probability change (supplier confirmation, updated manufacturing plan),
- new response level (still monitor, but no longer need aggressive escalation).
This demonstrates dynamic risk management—a concept often tested conceptually.
Mapping PRM3BB3 Content to Broader Project Risk & Quality Management University Notes (South Africa Focus)
UJ’s PRM3BB3 fits within the wider Project Risk & Quality Management University Notes (South Africa Focus) collection by emphasising that risk management is not separate from quality and delivery performance. In South Africa, where projects frequently face operational disruptions (utilities variability, procurement lead times, regulatory approval cycles), risk management becomes a delivery discipline rather than a compliance exercise.
Across South African curricula, you repeatedly see the same exam patterns:
- Risk identification + register
- Probability/impact scoring
- Risk response planning
- Monitoring and control
- Quality linkages (verification, inspections, nonconformance prevention)
If you practise these four patterns with consistent scoring and clear response actions, you will be well prepared for PRM3BB3 exam formats.
Final Exam Strategy: How to Structure a Full Answer Under Time Pressure
In a typical risk management exam question, aim for a structure that is easy to mark:
- Restate the scenario briefly (1–2 lines).
- Define the scales (probability 1–5, impact 1–5).
- Identify risks (at least 8) with categories.
- Score and compute totals (P×I) and state rating bands.
- Select top 3–4 risks and justify selection.
- For each top risk:
- strategy choice,
- actions,
- owner,
- triggers/monitoring,
- contingency.
- Conclude with monitoring and review approach (risk register updates + review cadence).
This structure ensures that you earn marks even if one sub-part becomes challenging.
Summary of Key Takeaways (PRM3BB3 Exam Essentials)
- Risk is uncertain future events/conditions; issues have already happened.
- Use a consistent probability–impact scoring method and show your calculations.
- Build a risk register with owners, responses, triggers, and contingency plans.
- Choose response strategies logically:
- mitigate for controllable threats,
- transfer when contractual/legal mechanisms can shift impact,
- avoid only when removal is feasible,
- accept only with monitoring and contingency.
- Monitoring and control require cadence, indicators, audits, escalation, and risk register updates.
- Link risk responses to quality assurance activities to prevent rework and compliance failures.
This guide is designed to match what students in South Africa commonly practise for UJ project/risk modules—especially the register-building and risk matrix reasoning that exam questions reward most consistently in PRM3BB3 style assessments.
