The objective of this study is to explore the identification, understanding and application of risk management in information technology (IT) projects in, Peshawar, Pakistan. IT sector holds prominent place economically throughout the globe. However, high failure rate is associated with IT projects, and factors pertaining to risk management is one of the main causes of this failure. Risk management processes and procedures are considered a newly emerging field in Pakistan, so there is need to explore and tackle the status of risk management in IT sector. The adopted methodology of research is quantitative in nature, in the form of survey as research strategy. Primary data is collected by means of questionnaire as a data collection tool. The target population is 40 IT companies of Peshawar registered with Khyber Pakhtunkhwa IT Board and the entire population of IT firms are taken as a sample size. The research results highlight the importance of knowledge base in risk management as well as its role in risk mitigation; however, the availability of databases and tools and techniques for managing knowledge of risk management are found not up to the significant mark. There is a need to develop databases and tools for managing information about risk. A similar study with longitudinal design should be conducted on a considerably bigger sample size through various sectors including IT, Health, mining, and others which allow a more detailed analysis to tackle the whole scenario of the risk management status.