Concept and mechanism
A risk involves uncertainty with possible effects on objectives, including threats or opportunities. Recording is insufficient: define oversight, response, and evidence of effect. The overall risk owner and the person executing an action can differ. An issue needs capture and assessment; not every raised matter requires a baseline change. For example, difficulty reading a runbook may be resolved through clarification, whereas an additional permanent environment can change cost, scope, and operations. Assessment precedes decision by applicable authority. A recorded request is not authorization.
Guided application
Progress compares current state and forecasts against agreed limits. A 100 person-day stage with 10% upper tolerance has a 110-day limit. If forecast is 114, do not wait for final consumption or change the baseline to hide deviation: present impact and options to the appropriate level. Within delegated authority, management continues with monitoring and reporting; exception management does not mean absence of regular information. Reports should show product state, criteria, risks, and decisions because 90% completed tasks can hide one outstanding critical test.
For another environment, assess installation, licensing, support, and decommissioning alongside security and schedule. Record the decision before updating the authorized reference.
Common pitfalls
Risk records without response; completed action treated as eliminated risk; issues treated as automatic changes; forecasts confused with authorized budgets.
Related topics: Processes from preparation to closure · Project, principles, and context
Control should expose deviations and decisions while options remain.
Reference: PRINCE2 7 Issues: not every issue equals a change · PRINCE2 Project Management Version 7