Introduction
Risk management is the backbone of successful project delivery, especially in dynamic environments like Agile. Yet, one of the most persistent—and often overlooked—challenges is the subjective nature of risk scoring. Although risk management professional established good standards, valid for the entire organisation, projects and product teams, Agile teams struggle to understand the importance of risk management, from the perception that risk is bad to using semiquantitative metrics and wrong risk terminology. How teams assess the likelihood and the consequence of risks can vary wildly, and these judgments are not always objective. This introduces bias, both conscious and unconscious, and raises significant ethical concerns, especially when project success, team reputation, or personal interests are at stake. Drawing on the PMI Code of Ethics, insights from risk and project management practitioners, and ISO 31000, this blog explores the pitfalls of subjective risk assessment and provides actionable recommendations for mitigating bias in Agile projects.
Challenges: Where Bias Creeps In
The Nature of Subjectivity in Risk Scoring
Risk scoring typically involves assigning a consequence (impact) and a likelihood, sometimes wrongly defined as probability, although there is no data available to calculate that probability for a given threat or opportunity. While frameworks and matrices (like those described in ISO 31000) provide guidance, the numbers themselves are often the product of subjective interpretation. Factors such as previous experience, organisational culture, and personal incentives all colour these decisions.
Cognitive Biases in Play
Cognitive biases are systematic errors in thinking that influence decision-making. In risk management, two biases are especially relevant:
- Optimism Bias: Underestimating the likelihood or consequence of negative events, leading to downgrading the consequences or assigning overly favourable likelihood.
- Anchoring Bias: Relying too heavily on initial values or past events, even if they do not accurately reflect the current situation.
Such biases lead to risk registers that look good on paper but fail to reflect reality.
Intentional Distortion
Not all bias is unconscious. Teams may intentionally downgrade the consequence or ‘adjust’ probabilities to make a project seem less risky, particularly under management or client pressure. The PMI Code of Ethics and Professional Conduct is explicit: “We do not engage in or condone behaviour that is designed to mislead others.” Yet, the incentive to manipulate data remains, especially in deadline-driven Agile sprints.
The Agile Paradox
Ron Jeffries, one of the founders of the Agile movement, notes that Agile teams, by valuing individuals and interactions, can sometimes fall prey to groupthink or “happy path” planning, where dissenting views about risk are downplayed. This can result in a dangerous consensus that underestimates real threats.
Organisational and Cultural Drivers
Practice shows that organisational culture strongly influences risk perception. If leadership signals that “bad news” is unwelcome, teams may unconsciously adjust their risk assessments to align with what they believe management wants to hear.
Consequences for Projects
When risks are systematically underestimated:
- Problems are discovered too late to mitigate effectively
- Budgets and timelines slip
- Stakeholder trust is eroded
- Ethical breaches can occur, damaging professional reputations
Recommendations: Building Objectivity and Integrity
Anchor in Professional Ethics
The PMI Code of Ethics reminds us to act with honesty, responsibility, respect, and fairness. Embed these values in your risk management process:
- Require transparent documentation of risk scoring rationales
- Encourage whistleblowing and dissent without fear of retribution
- Regularly remind teams of their ethical obligations
Use Structured, Repeatable Processes
ISO 31000 advocates for a systematic approach to risk management. Standardising risk scoring criteria and using agreed-upon definitions for likelihood and consequence reduces variance due to personal interpretation. This aspect is very important because, unlike story points, a metric that should be used only by the team, risk values are socialised within the entire organisation.
- Develop clear guidelines for what constitutes “high,” “medium,” and “low” risk
- Use calibrated scales and, where possible, historical data to inform estimates
Facilitate Diverse Perspectives
Agile highlights the importance of diversity in risk assessment. Risk Management should be a team responsibility, not an administrative task for the Project Manager. Risk Management must involve stakeholders from different functions, backgrounds, and levels of seniority. Diverse teams are less likely to fall into groupthink or shared blind spots.
- Hold risk workshops with cross-functional participation
- Use anonymous voting or scoring to surface minority views
Leverage External Review
Bring in external reviewers or auditors to periodically assess the integrity of your risk logs. A fresh pair of eyes can often spot biases that insiders overlook.
Train Teams on Cognitive Bias
Awareness is the first step towards mitigation. Offer training to help team members recognise and counteract their own biases (optimism, anchoring, confirmation, etc.).
Encourage Psychological Safety
Teams are more likely to surface uncomfortable truths when they feel safe to do so. Create an environment where raising concerns is valued, not punished.
Automate Where Possible, but Don’t Abdicate Judgment
Tools can help reduce subjective variability, but they must be used wisely. Automated risk engines should be calibrated and their underlying assumptions reviewed regularly.
Continuous Improvement
Risk management is not a set-and-forget process. Regularly revisit and refine your risk scoring practices based on lessons learned, audit results, and changing project realities.
The Bottom Line
Subjectivity and bias in risk scoring are inevitable, but not insurmountable. By grounding your approach in professional ethics, using structured processes, fostering diversity, and promoting psychological safety, Agile teams can mitigate the worst effects of bias. The stakes are high: not only project success, but also professional credibility and ethical standing are on the line. As ISO 31000 reminds us, risk management is about creating and protecting value—an imperative that demands both rigour and integrity.
This blog post has explored the ethical and practical challenges of bias in risk scoring. By recognising and addressing these issues, Agile teams can better protect their projects—and their professional reputations—from avoidable pitfalls.
Questions for Readers
- How does your team currently score risks, and what steps do you take to minimise subjectivity?
- Have you ever witnessed (or participated in) the intentional downgrading of risk likelihood or consequence? What was the result?
- What practices have you found most effective in surfacing and addressing cognitive bias in your Agile projects?




Community Champion