complexity and the associated risk increases as the size of the project increases. In this paper we have proposed a technique to evaluate the risk based on the source code as well as on the changes in the requirements of the user. Because it is not possible to test exhaustively each and every path in the code so some of the faults are left which can become the future risks. The risk assessment is based on the code is calculated by considering the conditions, variable and predicates in the code. Because there are always some changes in the project, major or minor. These changes increase the chances of the risk. So this proposed model considers the impact of changes on the risk. Keywordsrisk, Risk exposure, Risk management, Risk Assessment. in the software. Further steps can be taken based on the severity of the risk. Risk identification includes the process of identifying the risk associated. Risk assessment is used for rating the various risks and the probability and impact of the risk. Risk mitigation is used to prepare a plan for handling and minimizing the adverse effect of the risk. It can be done by using controlling, avoiding or transferring the risk. Risk mitigation consist of the various activities including planning risk control measures, implementing risk control measures, monitoring the risk, controlling the risk, learning on risk. II. BACKGROUND AND RELATED WORKmodels have been developed for various types of projects for the risk management based on their different needs and conditions. Software risk management is not a onetime activity and it is a continuous process that has to be followed throughout the life of a project. Approach for the risk management can be based on the traditional approach or it can be based on the proactive such that each project is studied individually to find out the related risk and their management. In traditional approach focus is on the risks which are common in all the projects. These are easy to identify and control. SEI has defined six paradigms of risk management. These are identification, analyzing, planning, tracking, controlling, and communicating the risk. Details of these is best describes in (3). SEI's software risk management is supported by three groups Software risk evaluation, Continuous risk management and team risk management. The objective of risk management strategies is to prevent, mitigate, correct and ensure system failure. The goal of this model was to identify and resolve risk in early stage and to develop risk strategies to handle all these risk. There is another model called Model of risk assessment of Software Project based on grey theory defines grey comprehensive evaluation model of the risk management. It combines AHP and entropy method to confirm the weight of risk index and calculates the grey approach degree by using improved grey correlation degree as decision making unit. Then software risk can be ranked according to grey approach degree (4). Another model for risk assessment and evaluation is for the projects based on the fuzzy analytical hierarchal process. For this related risk factors are identified and then expert qualitative judgments about these factors are acquired. These judgments are translated into fuzzy numbers and used as a input to FAHP. After this risk factors are ranked and prioritized by FAHP in order to make project managers aware of important risk and to enable them to adopt measures to deal with these highly devastating risks. It suggested the risk identification. FAHP establishes the hierarchical structure and creates the fuzzy judgment matrix using pair-wise comparisons (5). Various approaches are used for the risk management. They can be based on the process model, checklist, analytical framework or risk response strategies. In checklist method a list of the risks is