Here’s a question worth sitting with: when was the last time a project you worked on failed because nobody understood the technology?
Rare, right? Most of the failures we’ve all lived through weren’t technical. They were the risk nobody flagged because the team culture didn’t reward speaking up. The threat everyone privately knew about, but nobody officially owned. The “opportunity” that got missed because the org was so busy defending against downside that it forgot risk cuts both ways.

That’s exactly the gap MoR® 4 — Management of Risk, now also marketed as PRINCE2® Risk Management — was built to close. And if you’re weighing whether it’s worth adding to your team’s certification roadmap this year, here’s what’s actually changed, and who stands to gain the most from it.
So, What’s Actually New in Version 4?
MoR has been around since 2002, originally shaped by the Turnbull Report on UK corporate governance. Versions 2 and 3 modernized it for a globalizing risk landscape. Version 4, released by PeopleCert in late 2022, is a more substantial shift — and it’s aimed squarely at how organizations actually operate today: digital-first, product-led, and moving faster than most governance frameworks were designed to handle.
A new perspective built around people and culture. Earlier editions treated risk largely as a process problem — identify it, assess it, control it. Version 4 adds a fifth perspective that puts people and organizational culture at the centre of whether risk management actually works. This isn’t a soft add-on. It’s an acknowledgment that risk registers don’t fail on their own — teams fail to surface risk when the culture punishes bad news or rewards silence.
A much deeper framework. Version 3 ran on four principles and four processes. Version 4 expands that to eight principles and eight processes — a meaningfully richer toolkit for tailoring risk management to strategic, programme, project, product, and operational contexts, rather than treating every risk the same way.
One exam, not two. MoR 4 folds Foundation-level content into a single Practitioner qualification, rather than requiring separate Foundation and Practitioner exams. In practice, that means less time and cost to achieve full certification — a meaningful shift for busy professionals who previously had to clear two separate hurdles.
You’ll also notice the framework increasingly showing up under the name PRINCE2® Risk Management. Same body of knowledge, same PeopleCert certification — just a rebrand worth knowing about so it doesn’t look like a completely different course when you see it listed that way.
Who Should Actually Get Certified?
Not everyone needs this. But if you sit in any of these seats, it’s probably overdue:
Programme and project managers who are tired of discovering risks in the retrospective rather than in the planning phase.
Business change and transformation leads, where the risks are often less about technical delivery and more about whether the organization — and its people — can actually absorb the change being asked of them.
GRC and governance professionals, who now have a framework that’s explicitly aligned with ISO 31000:2018 and speaks the same language as the rest of their compliance toolkit.
Product managers and product-led teams, a group the framework’s authors clearly had in mind this time around. If your organization is shipping fast and iterating constantly, MoR 4’s product perspective was built for exactly that environment.
Senior IT and business leadership, particularly anyone accountable for risk culture rather than just risk process. The fifth perspective makes this framework as much a leadership tool as a technical one.
Portfolio and operational risk professionals who need one consistent approach that scales from a single project up to enterprise-wide portfolio decisions.
If your role involves making a call under uncertainty — and whose doesn’t, these days — there’s a strong case for having this on your resume.
Why This Matters Right Now
We’re well past the point where risk management can be a once-a-year audit exercise. Organizations are moving faster, teams are more distributed, and the line between “project risk” and “business risk” has mostly disappeared. MoR 4 doesn’t just catch up to that reality — with its people-and-culture perspective, it’s arguably ahead of where most organizations currently are.
That’s the real value of certifying now, rather than waiting: you’re not just learning a framework, you’re getting ahead of a shift the rest of your industry is still catching up to.
Ready to get certified in MoR® 4?
SkillMetrix runs practitioner-level training designed to get you exam-ready and confident applying the framework in real organizational contexts — not just passing a test.