Canonical Distinction
A product is a persistent value system managed through learning. It may be a customer-facing product, an internal platform, a business capability, a service, a data product, or an operational process. What makes it product-like is not the presence of a user interface or a commercial SKU. It is the continuing need to improve an outcome under uncertainty.
A project is a temporary change effort managed through coordinated completion. It is rational when the objective and solution are sufficiently known, and the principal uncertainty concerns sequencing, dependency management, migration, compliance, correctness, cost, schedule, or transition into operation.
The central rule is therefore conservative: choose the operating model by dominant risk. Product teams exist to reduce discovery and adaptation risk. Project teams exist to reduce coordination and completion risk. Many serious initiatives contain both; mature governance decomposes the initiative rather than forcing the whole effort into one category.
Risk Management Translation
In ISO 31000 language, the starting point is the objective and the uncertainty that affects it. In COSO ERM language, the question links risk to strategy and performance. In PMI language, risk management protects portfolio, program, and project objectives from uncertain events or conditions. These frameworks make the product/project distinction more precise: the operating model should be selected as a risk treatment, not as an organisational identity.
Product-mode question
Are we solving the right problem in a way that improves the intended outcome?
Primary treatment: discovery, experimentation, instrumentation, iteration, and durable ownership.
Project-mode question
Can the known change be completed correctly, safely, predictably, and across dependencies?
Primary treatment: planning, controls, dependency management, validation, readiness, and closure.
The failure pattern is not that organisations use projects. The failure pattern is that unresolved product uncertainty is converted into fixed scope before the organisation has credible evidence. In that situation, project governance may improve delivery discipline while leaving the larger investment risk untreated.
Residual Risk
The useful classification is residual rather than inherent. An initiative may begin with high value, usability, feasibility, and viability uncertainty. If those uncertainties have been tested with behavioural evidence, prototypes, technical spikes, constraint review, and credible business validation, the residual product risk may be low enough for project or program governance to dominate.
Conversely, a fixed deadline or approved business case does not make product uncertainty disappear. If adoption, value, workflow fit, or outcome movement remain untested, the organisation is carrying product risk inside a project wrapper. That may sometimes be an intentional risk acceptance; it should not be mistaken for assurance.
Risk Frameworks Invoked
The module does not replace established risk frameworks. It uses their language to classify work more carefully: objectives, uncertainty, likelihood, impact, control effectiveness, residual risk, risk appetite, treatment, monitoring, and acceptance.
Use It
Begin with the expected failure modes, not the preferred label. Ask how the initiative could fail even if people work competently. If the answer is adoption, value, usability, feasibility, viability, or outcome movement, product-mode logic is still needed. If the answer is deadline, migration, dependency, correctness, compliance, or readiness, project or program controls may be the more appropriate treatment.
Selected References
Narayan, S. (2018). Products over projects. Martin Fowler. martinfowler.com/articles/products-over-projects.html
ISO. (2018). ISO 31000:2018 Risk management — Guidelines. iso.org/standard/65694.html
COSO. (2017). Enterprise Risk Management — Integrating with Strategy and Performance. coso.org/enterprise-risk-management
Project Management Institute. (2024). Risk Management in Portfolios, Programs, and Projects: A Practice Guide. pmi.org/standards/risk-management
IEC. (2019). IEC 31010:2019 Risk management — Risk assessment techniques. iso.org/standard/72140.html
NIST. (2024). Risk Management Framework. csrc.nist.gov/projects/risk-management/about-rmf
ISO. (2019). ISO 14971:2019 Medical devices — Application of risk management to medical devices. iso.org/standard/72704.html
European Medicines Agency. (2023). ICH Q9(R1) Quality risk management. ema.europa.eu