The correct answer is C. The risk owner should have communicated with the project manager so that a designated stakeholder could have been assigned to accept accountability for implementing risk responses.
The core problem in this scenario is not simply that the hardware failed. The real failure is that no one was available and accountable to respond when the risk event occurred . In sound risk management practice, each significant risk should have a clearly assigned risk owner responsible for monitoring the risk and ensuring that the agreed response is implemented. If that individual becomes unavailable, responsibility should not be left unattended. A backup or delegated stakeholder should be assigned so that accountability continues without interruption.
This makes option C the best answer because it addresses the actual governance gap: lack of continuity in risk ownership and response accountability. Proper planning for risk response execution includes ensuring coverage when the assigned owner is absent.
Why the other options are incorrect:
A. The project manager should have requested and mandated that no vacations be taken during critical implementation activities or until all implementation had been completed for the project. This is unrealistic and not a proper risk management control. Projects should be structured so that important responsibilities continue even when people are unavailable. Preventing vacations is not an appropriate or sustainable risk response strategy.
B. The risk manager should have anticipated this situation and planned for schedule buffers in the project schedule to accommodate the likelihood of failed hardware. Schedule buffers may help absorb delays, but they do not solve the real issue described in the question, which is the absence of anyone responsible for responding to the incident. The key deficiency is accountability, not just schedule flexibility.
D. The risk manager should have taken the responsibility of responding to this risk instead of relying on and waiting for the risk owner to return from vacation. The risk manager facilitates and oversees the risk management process, but does not automatically become the response owner for every risk. The correct approach is assignment of the appropriate risk owner or delegate, not centralizing all response responsibility in the risk manager.
Best-practice reasoning:
Risk ownership must be explicit, continuous, and supported by delegation when needed. For critical risks, organizations should ensure backup accountability and escalation paths so that risk responses can be executed immediately when triggers occur.
Reference-aligned basis:
This answer is consistent with standard risk management guidance that emphasizes:
assigning a risk owner to each significant risk,
ensuring responsibility for implementing agreed responses,
maintaining continuity of risk response accountability during project execution.
[References:, PMI, A Guide to the Project Management Body of Knowledge (PMBOK® Guide), Project Risk Management, PMI, Practice Standard for Project Risk Management, ISO 31000, risk treatment and assignment of responsibilities, ]
Submit