On the surface, agile and risk management process models seem to constitute two contrasting approaches. Risk management follows a heavyweight approach whereas agile process models oppose it. In this paper, we identify commonalities in these two process models. Our results show that they have much in common, and that a merge between them is possible.