PRM Platform

Simple, effective, and intuitive risk management on a dedicated platform

Risk Matrix Configuration

Applying PMI – PMBOK and ISO 31000 Risk Management Principles and Guidelines

PRM is a qualitative risk management platform, designed by professional project risk managers for project teams to efficiently identify, analyse, and control risks on their projects using a fully configurable risk management system.

Cloud-Hosted and Local Server Options

The PRM platform is cloud-hosted by default, meaning all data is regularly backed up and fully secured on our cloud servers, using AES-256 encryption and TLS 1.2+, ensuring that no data can be intercepted or modified, either at rest or during transit. With our cloud-hosted platform, subscribers never have to worry about downloading and installing software upgrades, bug fixes, or new version releases. These are done regularly and automatically, ensuring the platform is always stable, secure, and up to date.

The application can also be installed on local in-house servers, providing additional autonomy, on request. 

Web-Based

As a web-based platform, you can use PRM with any browser and operating system on any internet-connected desktop, laptop, or mobile device. Data is updated continuously and seamlessly, allowing all team members to work on the platform simultaneously from any location with internet connectivity.

User Roles

Subscribers to PRM can assign multiple team members to work simultaneously on the platform. Team members may be assigned user roles in one of four categories:

  1. Organisation Owner – The PRM subscriber who creates and manages the organisations in which project risks are created and managed. This team member has full access to all configurable parameters within the PRM platform and can create multiple organisations with independent projects and team members for each organisation.
  2. Project Owner – The team member with access rights to all project data within the organisation they have been assigned to. This team member can add, edit, or delete existing projects, risks, or team members from their organisation.
  3. Risk Owner – The team member with access rights only to risks that have been assigned to them. This team member can add and edit mitigation plans to these risks only.
  4. Guest – The team member with view-only access rights. This team member cannot add, edit, or delete any data, but they can view all projects and risks within the organisation they have been assigned to.
PRM in Practice

PRM in Practice

Configure your risk management system, define your projects, identify, analyse, and control your risks.

Clarity and consistency are key to effective risk management. Project Risk Manager applies the principals of proven risk management methods, ensuring all risks are clearly identified and ranked on a fully configurable risk severity matrix. As mitigation plans are developed and their response actions implemented, the system tracks progress from initial risk identification through to final mitigation and acceptance.

Project Risk Manager’s dynamic dashboard gives you a live snapshot of your Key Risk Indicators. The dashboard can be customised to suit project requirements and multiple dashboards can be created for tracking and reporting different KRIs.

Risk Identification

Risk comprises three primary components:

  • Risk Source (threat or opportunity)
  • Risk Event
  • Risk Impacts


To effectively manage a risk, it is essential to identify all three of these components. Without this, the risk is cannot be fully controlled. When identifying and recording a risk in the project risk register, it is important to describe the risk in the following terms: “The risk SOURCE (Threat or Opportunity) that could trigger a risk EVENT, resulting in risk IMPACTS”.

Mitigation Plan Development

When a risk is clearly identified and recorded by capturing all three components (Source, Event, Impact) of the risk, the process of mitigation plan development becomes clear and straightforward.

Mitigation plan development for threat-based risks considers how to minimise the probability of a risk event from occurring and how to minimise its impacts. Mitigation plan development for opportunity-based risks considers how to maximise the probability of a risk event from occurring and how to maximise its impacts. Mitigation plans usually comprise several response actions for any one risk.

Response actions for threat-based risks are individual actions designed to reduce either the probability of risk event occurrence, or the severity of the risk impacts. Response Actions for opportunity-based risks are individual actions designed to enhance either the probability of risk event occurrence, or the benefits of the risk impacts. It is therefore often necessary to develop several response actions for each risk component depending on the nature of the risk source, event, and impacts.

Mitigation plan development also entails assigning resources, budget, and schedule for the implementation of each response action.

Response Action Implementation

Response actions are implemented in accordance with the risk mitigation plan. Threat-based risk response actions are implemented to reduce the probability of risk event occurrence and minimise the impacts of the risk event. Opportunity-based risk response actions are implemented to enhance the probability of risk event occurrence and maximise the impacts of the risk event.

Response actions should always apply the S.M.A.R.T. principal. That being:

  1. Each response action needs to be specific to the nature of the risk being addressed.
  2. The effectiveness of each implemented response action needs to be clearly measurable.
  3. Implementation of each response action needs to be achievable within the resources, budget, schedule, and capabilities of the risk management team.
  4. Each response action needs to have a realistic chance of succeeding in its objectives.
  5. Implementation of each response action needs to be time-bound to the expected risk occurrence date.

Key Risk Indicator (KRI) Monitoring & Reporting

Effective risk governance depends on knowing not just which individual risks exist, but how risk is distributed and concentrated across your project. PRM’s Reports module enables you to configure and monitor Key Risk Indicators directly from your live risk register data, giving project managers and stakeholders a continuous, quantified view of risk health.

Configurable risk charts
The Reports module allows you to build custom charts from your risk data using a flexible drag-and-drop interface. Choose from multiple chart types — including stacked bar, grouped bar, pie, line, radar, and others — and select the data fields that matter most to your KRI framework. Charts update dynamically as risk data changes, ensuring your indicators always reflect the current state of the register.

Risk severity by department, team, or category
A typical KRI configuration — such as the Risk Severity by Department chart — segments risks by an organisational dimension (department, project phase, risk owner, or any custom field) and stacks them by any other available field. Stacking by current severity level makes it immediately apparent where high-severity risks are clustering, and which areas of the project require urgent management attention.

Pivot table drill-down
Beneath each chart, an interactive pivot table provides the underlying risk counts broken down by any selected field and category. This allows risk owners and reviewers to move seamlessly from the headline KRI view to the granular data behind it, supporting more informed decision-making in risk review meetings.

Threshold visibility
By tracking risk counts at each severity level over time, teams can identify adverse trends — such as a growing concentration of Major or Severe risks within a particular department — before they breach acceptable thresholds. This transforms the risk register from a static log into an active early-warning system.

Export and reporting
KRI charts and pivot tables can be exported directly to Excel or printed, making it straightforward to include current risk indicators in project board reports, steering committee packs, or client-facing documentation without manual reformatting.

Managing project risks with confidence and assurance