| Level | Risk is about… | Primary focus | Horizon | Owner |
|---|---|---|---|---|
| Portfolio | Strategic objectives & the balance/mix of components; aggregate exposure vs risk capacity | Doing the right mix | Long / strategic | Portfolio governance |
| Program | Risks between components & their interdependencies; threats to benefits & integration | Coordinated benefits | Medium | Program manager |
| Project | Risks to scope, schedule, cost, quality of a specific deliverable | Reliable delivery | Short / tactical | Project manager |
Escalation & cascade: a project risk beyond the PM's authority escalates up to program or portfolio; strategic decisions and constraints cascade down. Consolidated reporting rolls individual risks into an overall picture at each level.
EMV = Σ (probability × impact); impacts are signed (− threat, + opportunity).
Feed EMVs into a decision tree to choose the option with the best expected value (e.g. build vs buy).
| Prob ↓ / Impact → | Low | Medium | High |
|---|---|---|---|
| High | Medium | High | High |
| Medium | Low | Medium | High |
| Low | Low | Low | Medium |
Score = probability × impact → a priority that drives response order & depth.