First, we will deal with the various approaches to risk management in the literature on risk management in IT projects. These approaches vary among researchers, while their preference for a certain approach mostly remains implicit. Two approaches are distinguished here: an evaluation approach and a management approach. Subsequently, the concept of project success in the context of IT projects is surveyed. The traditional vendor-oriented definition of project success (Turner and Cochrane, 1993), based on time, budget and requirements criteria, is frequently used in publications that study risk management in relation to IT project success. However, due to incorrect assumptions
or claims that are only valid in certain situations, this definition of project success does not fit the context of IT projects very well. Therefore, a more elaborate view on project success, as presented in the more recent literature, will be used in the remainder of this paper.