The risk response development phase is a major phase in the project risk ma
nagement process. We present a model that integrates project work contents,
risk events, and risk reduction actions and their effects into a comprehen
sive framework. The model allows the representation of the overlapping effe
cts of multiple risk reduction actions and of the impacts of secondary risk
events, and supports the evaluation of the total risk exposure of the proj
ect under various combinations of risk reduction actions. The model can be
treated with optimisation techniques in order to generate the most cost-eff
ective combination of risk reduction actions. In this work we describe the
model, outline a solution procedure and illustrate its application with an
example taken from the software industry.