A number that sounds more solid than it is
In a steering committee meeting for a β¬2.4 million municipal IT renewal, a slide appears with a single line: "a dedicated risk manager gives 3.9 times more chance of project success." No one in the room asks a follow-up question. The number is sharp enough to note down, and the conversation moves straight on to next quarter's planning.
That's a shame, because the number says something different from what is usually made of it.
What the research actually measures
The 3.9x figure comes from research by Rabechini and Carvalho (2013) across 415 projects in Brazil. Projects with a dedicated risk manager had a 3.9 times higher chance of what the researchers call "perceived success." That word "perceived" is not a footnote: the score comes from a questionnaire answered by the people who ran the project themselves. No independent audit, no after-the-fact review by a third party β the judgment of the project leadership about their own project.
That's not worthless. Self-assessed success correlates with things that genuinely matter: whether the client is satisfied, whether the team feels in control, whether escalations were caught in time. But it is a different kind of evidence than an independent measurement of budget, timeline and delivered functionality. A project manager who has just survived a difficult quarter and still calls the project "successful" is measuring something different than an external auditor comparing the final account to the business case. Anyone who cites the figure without naming that difference leaves out half the story.
The counter-voice that belongs with it
Anyone who cites only the Brazilian figure also misses a firmer counter-voice from the same body of research. De Bakker, Boonstra and Wortmann concluded in 2010, after reviewing the existing literature, that there is barely any evidence that risk management contributes to IT project success. Two research teams, two outcomes β and both belong in the same conversation. Risk management is not a tool with a fixed return; the effect differs by study, by definition of "success" and by method of measurement.
Where it does come together
A third study offers a clue as to why the outcomes diverge. Zwikael and Ahn (2011) found that risk management moderates the relationship between a project's risk level and its success β a correlational relationship, not proven cause and effect. Translated into practice: in a project with little uncertainty, structured risk management makes less of a difference than in a project full of unknowns. The Rabechini and Carvalho figure therefore probably says the most about projects that are already risky β not about every project in general, and certainly not about the routine project that happens to also have a risk register.
How to use the number correctly
For a steering committee document, this comes down to three lines of text. Name the source and the sample: Rabechini and Carvalho, 415 projects, Brazil. State that it concerns self-reported success, not an independent measurement. And place the critical counter-voice of De Bakker et al. next to it, so the figure becomes a claim with conditions instead of a law.
That costs one extra sentence on the slide. It saves a drawn-out argument the moment someone in the room does ask a follow-up question β which happens more often than you'd think, usually right after the decision seemed to have already been made.