Views, Filters & Print
Risks Are Uncertain Events, Not Issues or Thresholds
PRORISK / RISKTYPE (Professional); not issues; not project thresholds; XML for EPPM

What a planner means
Oracle: risks are uncertain events or conditions that, if they occur, have a positive or negative effect on project objectives. A threat is usually negative; an opportunity is usually positive.
The EPPM risk register (Risks page) is where you name the risk, mark threat vs opportunity, set status and owner, and (if a risk scoring matrix is assigned to the project) set probability, schedule, cost, and user-defined impacts. Those values calculate risk score; probability and cost calculate exposure. If Probability / Cost / Schedule are disabled, no matrix is assigned — you can still track the risk, but qualitative scoring is off.
You can assign a risk to activities. You can add response plans. Oracle response types:
| Kind | Types |
|---|---|
| Threat | Accept, Avoid, Reduce, Transfer |
| Opportunity | Enhance, Exploit, Facilitate, Reject |
Accept: take no action; post-response impacts are set to the same values as pre-response. Avoid: change the project so the risk is avoided; usually reduces post-response probability to zero.
Risk thresholds (probability, tolerance, schedule impact, cost impact, user-defined; 2–9 levels) feed a risk scoring matrix. They are not project thresholds (PROJTHRS) and they do not generate issues.
Quantitative analysis of the P6 register is done in Oracle Primavera Cloud. Oracle: document in P6, analyze in Cloud, see results back on Activities. Do not claim P6 Professional/EPPM itself runs that quantitative engine.
XER: PRORISK / RISKTYPE (Professional)
Current project XER map names the risks table PRORISK, not PROJRISK. Oracle: available in P6 Professional only. Same note on RISKTYPE.
PRORISK (Risks)
| Column | Oracle label |
|---|---|
risk_id | Unique ID |
risk_code | Risk ID |
risk_name | Risk Name |
risk_desc | Risk Description |
risk_cause / risk_effect | Risk Cause / Risk Effect |
risk_to_type | Risk Type |
risk_type_id | Risk Category ID |
rsrc_id | Risk Owner |
status_code | Risk Status |
response_type / response_text | Response Type / Response Description |
pre_rsp_prblty / post_rsp_prblty | Pre- / Post-Response Probability |
pre_rsp_schd_prblty / post_rsp_schd_prblty | Pre- / Post-Response Schedule |
pre_rsp_cost_prblty / post_rsp_cost_prblty | Pre- / Post-Response Cost |
identified_by_id / add_date | Identified By / Identified On |
notes | Notes |
proj_id | Project ID |
RISKTYPE (Risk Types)
| Column | Oracle label |
|---|---|
risk_type_id | Unique ID |
risk_type | Risk Category |
parent_risk_type_id | Parent Risk Category ID |
seq_num | Sort Order |
Oracle on XER import to EPPM: Professional risks live in the ProjRisk table, are included in XER and imported into EPPM, but are not visible in P6 (the web). If you need to import and export risk information, Oracle recommends XML.
The activity-assignment table for risks is not named in the current project XER map. Do not invent TASKRISK. Stored tokens for status_code, response_type, and risk_to_type are not listed. Do not invent them.
An older export map used PROJRISK / RISKCTRL with different columns (impact units, WBS, probability %). Treat that as a different / older shape. Do not merge column lists.
Microsoft Project
Desktop Project has no risk register and no scoring matrix. Custom Text/Number fields are not this object. Do not map PRORISK to Task Notes or to a flag.
Don't
- Treat a risk as an issue (
PROJISSU) or a project threshold (PROJTHRS). Risk thresholds score risks; project thresholds write issues. - Treat PRORISK as the EPPM scoring-matrix register, or assume an XER carries matrix scores the web UI can show. Oracle: XER ProjRisk is not visible in P6; use XML for risk exchange.
- Treat a risk as schedule logic. Assigning a risk to an activity does not move dates.
- Invent XER tokens or an activity-risk assignment table name you have not seen.
- Map P6 risks to MSP custom fields and call them the same object.