RISK MANAGEMENT PROFESSIONAL (RMP)
BASED ON APRIL 2022 EXAM CONTENT
PREPARED BY: ENG. ALI ODEH “MBA, CPM, PMP, ACP, SP, RMP& ITIL“
Ch 01:
Introduction
CH 01 CONTENTS
Purpose of this Standard
Approach of this Standard
Principles of Risk Management
Structure of this Standard
1.1:
Purpose of this Standard
INTRODUCTION
• Risk is an uncertain event or condition that, if it occurs,
has a positive of negative effect on one more objectives.
Risk
Negative Positive
Threats Opportunities
INTRODUCTION
• The practice of risk management includes :
• Planning the approach.
• Identifying and analyzing risks.
• Response planning.
• And implementation.
• And ongoing monitoring of risks.
• Risk management is essential aspect of all
organizational activities.
• This standard describes the application of risk
management within an enterprise risk management
( ERM) context that includes the portfolio, program
and project domains.
PMI’S 2015 PULSE OF THE PROFESSION® REPORT
• The organizations that apply a formal risk
management approach :
• 73% of projects meet their objectives.
• 61% finish on time.
• 64% are completed within the approved budget.
INTRODUCTION
• Risk management allows an organization to :
• Anticipate and manage change.
• Improve decision making.
• Proactively implement typically lower-cost preventive
actions instead of higher-cost reaction to issues.
• Increase the chances to realizes opportunities for the
benefit of the business.
• Generate broad awareness of uncertainty of outcomes.
• Act upon the transformations taking place in its
business environment.
• Support organizational agility and resilience .
Risk management also establish iterative connections
among portfolios , programs, and projects and links these
connections with ERM and organizational strategy.
PURPOSE OF THIS STANDARD
Describe the fundamentals of risk management.
Support the objectives and demonstrate the link to ERM.
Apply risk management principles, as appropriate, to
portfolio, program and project domains as described in the
PMI foundational standards.
It expands on the knowledge contained on risk management in
the relevant sections of the PMI foundational standards.
1.2:
Approach of this Standard
APPROACH OF THIS STANDARD :
• This standard presents the what and why of risk
management. The following concepts are
elaborated in this standard :
• Purpose and benefits of risk management.
• Principles and concepts of risk management in
portfolios, programs and projects.
• Risk management is life cycle in portfolios, programs
and projects.
• Integration of risk management within portfolios,
programs and projects .
APPROACH OF THIS STANDARD :
The scope of this standard is to provide guidance
and not to impose uniformity of processes across
portfolios, programs and projects .
When planning and implementing risk management
, it is essential that each team consider the
characteristics of the organization, portfolio,
program, or project.
The approach presented in this standard is based on
risk management principles that can be used as
guidance when designing specific management or
business processes adapted to the organizational
environment and nature of the work.
1.3:
Principles of Risk
Management
PRINCIPLES OF RISK MANAGEMENT
1- Strive to achieve excellence in the practice of risk management
.
2-Align risk management with organizational strategy and
governance practices .
3-Focus on the most impactful risks.
4-Balance realization of value against overall risks.
5-Foster a culture that emphases risk management
6-Navigate complexity using risk management to enable
successful outcomes
7-Continuously improve risk management competencies
PRINCIPLE -1 : EXCELLENCE IN RISK MANAGEMENT :
1- Strive to achieve excellence in the practice of risk management:
• Risk management allows organizations and teams to increase the
predictability of outcomes, both qualitatively and quantitatively .
• This principle is about reaching the appropriate level of organizational
process maturity ( the ability of an organization to apply a certain set of
processes in a consistent manner) and the optimal level of performance.
• Excellence in risk management is not achieved by the strict application
of related processes. Rather , excellence can be achieved by :
1- Balancing the benefits to be obtained with associated cost.
2- Tailoring the risk management processes to the characteristics of the
organization and its portfolios, programs and projects.
PRINCIPLE -2 : ALIGN RISK MANAGEMENT WITH
ORGANIZATIONAL STRATEGY :
2-Align risk management with organizational strategy and
governance practices .
• The practice of risk management in organizations is developed and
evolved in coexistence with other organizational processes, such as
strategy and governance.
• The nature of portfolios, programs, and projects is such that circumstances
may change frequently.
• Adjustments became necessary as the organization evolves, for example,
when changes to decision-making processes, timing, scope, and speed are
made.
PRINCIPLE -3 : FOCUS ON THE MOST IMPACTFUL RISKS :
3-Focus on the most impactful risks:
• Successful organizations are able to effectively and efficiently identify the
risks that directly influence goals and objectives.
• The challenges for most organizations is making the best use of resources
by focusing on the right risks.
• This depends on the characteristics of the organizations, its environment,
internal maturity, culture and strategy.
• Determining the most impactful risks can be difficult. Organizations
develop and improve by refining the processes for risk prioritization.
PRINCIPLE -4 : RISK VS EXPECTED BUSINESS VALUE :
4-Balance realization of value against overall risks:
• Risk management seeks to find the proper balance between the exposure to
risk and the expected business value creation or realization.
• Initiatives presenting a low level of risk may not create a sufficient level of
value and performance.
• On the other hand, initiatives presenting a high, expected performance
may expose the organization to an acceptable level of threat.
PRINCIPLE -5 : A CULTURE OF RISK MANAGEMENT:
5-Foster a culture that emphases risk management:
• A culture of risk management encourages:
• The identification of threats rather than ignoring them.
• The identification of opportunities by cultivating a positive mindset
within the organization.
PRINCIPLE - 6 : NAVIGATE COMPLEXITY:
6-Navigate complexity using risk management to enable successful
outcomes:
• Managing risks is an essential part of reducing and handling the
complexity within organizational initiatives.
• The ability to identify and mange risks is directly dependent on the level of
complexity of the initiatives.
• The more organizations navigate complexity using risk management, the
more they will be able to optimize the use of resources, increase the return
on investments, and improve overall performance and business results.
PRINCIPLE - 7 : CONTINUOUSLY IMPROVE COMPETENCIES:
7-Continuously improve risk management competencies :
• The nature of risks to which an organization is exposed and the available
technology to manage those risks are changing.
• Technology allows organizations to mange risks more effectively and to
better focus on the risks’ impacts.
• Through continuous improvement of risk management competencies,
organizations and individuals can develop sustainable competitive
advantages that contributes to overall organizational performance.
1.4:
Structure of this
Standard
STRUCTURE OF THIS STANDARD
This standard can be used to review portfolio, program, and project
management processes from a risk management perspective. It is
organized as follows :
Ch 02:
Context and Key Concepts
of Risk Management
CH 02 CONTENTS
Key Concepts and Definitions
Risk Management in Organizations
Domains of Risk Management
Key Success Factors
2.1:
Key Concepts and Definitions
KEY CONCEPTS AND DEFINITIONS
•An individual risk is an uncertain event or condition that, if it
1- Individual Risk : occurs, has a positive or negative effect on one or more objectives.
•Overall risk is the effect of uncertainty that affects organizational
2- Overall risk : objectives at different levels or aspects.
•Opportunities are risks that would have a positive effect on one or
3- Opportunities : more objectives.
•Threats are risks that would have a negative effect on one or more
4- Threats : objectives.
•A chosen mental disposition towards uncertainty, adopted or
5- Risk Attitudes : implicitly by individuals or groups.
•The degree of uncertainty an organization or individual is willing
6- Risk Appetite : to accept in anticipation of reward.
•Risk threshold in the measure of acceptable variation around an
7- Risk Threshold : objective that reflects the risk appetite of the organization and its
stakeholders.
1 & 2 : INDIVIDUAL & OVERALL RISK :
1 & 2 : INDIVIDUAL & OVERALL RISK :
1. Individual Risk:
•Definition: These are risks associated with specific tasks, activities,
resources, or components within a project. They are usually more localized
and can affect specific outcomes or deliverables.
•Examples:
• A key team member might be unavailable during a critical phase of the
project.
• A supplier might fail to deliver materials on time.
• A technical issue might arise with a particular piece of software.
•Assessment:
• Risks are assessed based on their likelihood and impact on the
specific task or component.
• Mitigation strategies are developed to address these risks individually.
1 & 2 : INDIVIDUAL & OVERALL RISK :
2. Overall Risk:
•Definition: This refers to the cumulative effect of all individual risks on the
project as a whole. It considers how these risks interact and what the
overall impact on the project's objectives might be.
•Examples:
• Multiple delays in individual tasks might lead to a significant delay
in the project timeline.
• Budget overruns in several areas could lead to a major financial
issue for the project.
•Assessment:
• Overall risk is assessed by aggregating individual risks and
considering their combined impact on the project's success.
• This might involve scenario analysis, simulations, or other
techniques to understand the full risk exposure of the project.
3 & 4 – OPPORTUNITIES & THREATS :
1. Opportunities:
•Definition: Opportunities are external factors or situations that could have a
positive impact on the project or organization if leveraged effectively. They
represent potential benefits, advantages, or gains.
•Examples:
• A new technology becoming available that could enhance project efficiency.
• A favorable market condition that could lead to increased demand for the
project's outcome.
• A competitor's failure that opens up a new market segment.
2. Threats:
•Definition: Threats are external factors or situations that could negatively impact
the project or organization. They represent potential risks, challenges, or obstacles.
•Examples:
• Regulatory changes that could increase project costs or cause delays.
• A new competitor entering the market with a superior product.
• Economic downturns that reduce funding or demand for the project's
deliverables.
3 & 4 – OPPORTUNITIES & THREATS :
1. Opportunities - Management:
• Identification: Identify potential opportunities through brainstorming, market
analysis, and stakeholder input.
• Evaluation: Assess the likelihood and potential impact of each opportunity.
• Exploitation: Develop strategies to exploit or enhance these opportunities. This
could involve reallocating resources, adjusting timelines, or pursuing
partnerships.
• Monitoring: Continuously monitor the environment for new opportunities and
adjust the project plan to take advantage of them.
2. Threats - Management:
• Identification: Identify potential threats through risk assessment, market
analysis, and stakeholder input.
• Evaluation: Assess the likelihood and potential impact of each threat.
• Mitigation: Develop strategies to mitigate, avoid, or transfer these threats. This
could involve contingency planning, insurance, or risk-sharing agreements.
• Monitoring: Continuously monitor for new threats and adjust the project plan to
reduce their potential impact
5- RISK ATTITUDES :
A chosen mental disposition towards
uncertainty, adopted or implicitly by individuals
or groups.
1- Risk-Averse 3- Risk-Seeking (or Risk-
2- Risk-Neutral
Tolerant)
5- RISK ATTITUDES :
1- Risk-Averse:
•Definition: Individuals or organizations with a risk-
averse attitude prefer to avoid risk. They are more
focused on minimizing potential losses rather than
maximizing potential gains.
•Characteristics:
•Preference for safe, predictable outcomes.
•Tendency to choose options with lower risk, even
if it means lower potential rewards.
•High emphasis on risk mitigation and
contingency planning.
•Impact on Project Management:
•Conservative decision-making, possibly leading
to missed opportunities.
•Preference for well-established processes and
methods.
•Extensive use of safety buffers and reserves in
budgeting and scheduling.
5- RISK ATTITUDES :
2- Risk-Neutral:
•Definition: A risk-neutral attitude means that
decisions are made based solely on expected
outcomes, without a preference for or against risk. The
focus is on balancing potential gains and losses.
•Characteristics:
•Decisions are driven by expected value, not by
the level of risk.
•Willingness to accept a fair level of risk if the
potential reward justifies it.
•Analytical approach to risk assessment, focusing
on probabilities and outcomes.
•Impact on Project Management:
•Balanced decision-making, weighing risks and
rewards equally.
•Potential for more flexible project approaches,
adapting to changes as needed.
•Moderate use of risk management tools and
techniques.
5- RISK ATTITUDES :
3- Risk-Seeking (or Risk-Tolerant):
•Definition: Individuals or organizations with a risk-
seeking attitude are willing to take on more risk in
pursuit of higher rewards. They may prioritize
potential gains over the possibility of loss.
•Characteristics:
•Preference for options with higher potential
rewards, even if they involve higher risk.
•Tendency to innovate and take bold actions.
•Less emphasis on risk mitigation, more focus on
exploiting opportunities.
•Impact on Project Management:
•Aggressive decision-making, possibly leading to
higher rewards or greater losses.
•Openness to experimentation and adopting
new, untested methods.
•Potential for underestimating risks or neglecting
contingency planning.
6- RISK APPETITE :
Risk Appetite refers to the level of risk that an organization or individual is
willing to accept in pursuit of its objectives. It is a crucial concept in risk
management, as it guides decision-making and shapes how risks are
identified, assessed, and managed.
7- RISK THRESHOLD :
Risk threshold in the measure of acceptable variation around an objective that
reflects the risk appetite of the organization and its stakeholders.
•Cost: A specific budget overrun percentage
(e.g., 10% above the planned budget).
•Time: A delay beyond a certain number of
days or weeks (e.g., project milestones delayed
by more than 15% of the timeline).
•Quality: A defect rate that exceeds a certain
percentage (e.g., 5% of units failing quality
tests).
•Performance: A performance metric falling
below a defined level (e.g., system availability
dropping below 95%).
7- RISK APPETITE VS THRESHOLD :
8- TRIGGER CONDITION
An event or situation that indicates that a risk is
about to occur.
2.2:
Risk Management in
Organizations
RISK MANAGEMENT IN ORGANIZATIONS
• The organization’s governance body is ultimately responsible for setting, confirming, and enforcing risk
appetite and risk management principles as part of its governance oversight.
• The definition of risk includes both ( a ) district events that are uncertain but can be clearly described
and ( b ) more general conditions that are less specific but may also give rise to uncertainty.
• Both of these uncertain solutions are considered to be risks when they could have an adverse or
positive effect on the achievement of objectives.
• It is essential to address both situations within an enterprise, portfolio, program, and project risk
management processes.
• A risk may have one or more causes and, if it occurs, may have one or more effects.
• Threats that occur are termed issues, and opportunities that occur are benefits to the enterprise.
• A portfolio, program, and project managers are responsible to resolve these issues and manage them
effectively .
• Issues may entail actions that are outside the scope of portfolio, program, and project risk management
processes; therefore, these issues are escalated to a higher management level according to the
organization’s governance policy.
2.3:
Domains of
Risk Management
DOMAINS OF RISK MANAGEMENT
DOMAINS OF RISK MANAGEMENT
Enterprise Risk Portfolio Risk
1 2
Management Management
Program Risk Project Risk
3 4
Management Management
DOMAINS OF RISK MANAGEMENT – 1- ENTERPRISE :
The primary purpose of risk management is the creation and protection of value.
ERM is an approach for identifying major risks that confront an organization and
forecasting the significance of those risks to business processes.
The way in which risks are managed reflects the organization’s culture, capability, and
strategy to create and sustain value.
ERM addresses risks at the organizational level including the aggregation of all risks
associated with the enterprise’s portfolio of programs and projects.
ERM provides a systematic, organized, and structured method
for:
• Identifying and assessing all risks an organization faces.
• Developing suitable responses.
• Communicating status with stakeholders.
• Assigning responsibility to monitor and manage risks in
alignment with the strategic objectives of the organization.
There is no one-size-fits-all approach to performing ERM. The ERM function,
structure, and activities vary with each organization. ERM is responsible for
ensuring that all organizational risks are addressed and properly managed and
monitored.
DOMAINS OF RISK MANAGEMENT – 1- ENTERPRISE :
Risk management in the enterprise management context of integrated portfolio,
program, and project management consists of:
• Elaborating the risk governance framework.
• Identifying operational and contextual risks at each level of the integrated governance
framework, including both negative risks (threats) and positive risks (opportunities).
• Analyzing the identified risks from both the qualitative and quantitative perspectives and
identifying the governance layer best suited to manage them according to the escalation
rules in place within the portfolio, program, and project management framework.
• Defining an appropriate risk management strategy based on increasing the probability
and/or impact of positive risks (opportunities) and decreasing the probability and/or
impact of negative risks (threats).
• Identifying the risk owner and assigning the risk.
• Implementing the corresponding strategies and activities related to anticipative and/or
responsive actions.
• Monitoring the effectiveness and efficiency of the risk management strategies deployed
within the enterprise, portfolio, program, and project management framework.
• Ensuring alignment between portfolio, program, and project management risk
governance models and the ERM strategy.
• Promoting effective risk management within the entire enterprise through a risk
management culture
DOMAINS OF RISK MANAGEMENT – 2- PORTFOLIO :
Portfolio risk management categorizes risks as:
structural, component, and overall risk.
• Structural risks are risks associated with the
composition of a group of projects and the potential
interdependencies among components.
• Component risks at the portfolio level are risks
that the component manager escalates to the
portfolio level for information or action.
• Overall, portfolio risk considers the
interdependencies between components and is,
therefore, more than just the sum of individual
component risks.
DOMAINS OF RISK MANAGEMENT – 2- PORTFOLIO :
• Planning, designing, and implementing an effective portfolio risk management
system depends on organizational culture, top management commitment,
stakeholder engagement, and open and fair communication processes.
• Portfolio risk management is important for the success of managing portfolios
where the value lost due to component failure is significant, or when the risks of
one component impact the risks in another component.
• As defined in The Standard for Portfolio Management, portfolio risk management
ensures that components achieve the best possible success based on the
organizational strategy and business model.
• The result of portfolio risk management strategy is defining and launching
new components or closing other ones. Portfolio components can be
responses to identified threats or opportunities in alignment with the
organization’s overall business strategy.
DOMAINS OF RISK MANAGEMENT – 3- PROGRAM :
• Program risk management strategy ensures effective management of any risk
that can cause misalignment between the program roadmap and its supported
objectives to organizational strategy.
• It includes defining program risk thresholds, performing the initial program risk
assessment, and developing a program risk response strategy.
• The Standard for Program Management describes
program risk management strategy as:
• Identifying program risk thresholds.
• Performing an initial program risk assessment.
• Developing a high-level program risk response
strategy.
• Determining how risks are to be communicated and
managed as part of governance
DOMAINS OF RISK MANAGEMENT – 4- PROJECT :
• Project Risk Management is a Knowledge Area of project management that
identifies and manages project risks that could impact cost, schedule, or
scope baselines.
• A Guide to the Project Management Body of Knowledge (PMBOK® Guide)
describes Project Risk Management as the processes of conducting risk
management planning, identification, analysis, response planning,
response implementation, and monitoring risk on a project.
• The objectives of Project Risk Management are to increase the probability
and/or impact of opportunities and to decrease the probability and/or
impact of threats in order to optimize the chances of project success.
DOMAINS OF RISK MANAGEMENT – 4- PROJECT :
• The PMBOK ® Guide states that when unmanaged, these risks have the
potential to cause the project to deviate from the plan and fail to achieve
the defined project objectives.
• Consequently, project success is directly related to the effectiveness of
Project Risk Management.
• Project Risk Management supports project objectives by adapting or
implementing the courses of action and project activities to take advantage of
emerging changes in the project environment.
2.4:
Key Success Factors
KEY SUCCESS FACTORS
1
6 2
5 3
4
KEY SUCCESS FACTORS
1-Recognizing the value of risk management:
Portfolio, program, and project risk management is recognized
by organizational management, stakeholders, and team
members as a valuable discipline that provides a positive return
on investment.
2-Individual commitment/responsibility:
Portfolio, program, and project participants and stakeholders
accept responsibility for undertaking risk-related activities as
required. Risk management is everyone’s responsibility.
3-Open and honest communication:
Everyone is involved in the risk management process. Any
actions or attitudes that hinder communication about risk reduce
the effectiveness of risk management regarding proactive
approaches and effective decision making.
KEY SUCCESS FACTORS
4-Organizational commitment. Organizational:
commitment is established only when risk management is
aligned with the organization’s goals, values, and ERM policies.
Risk management actions may require the approval of or
response from others at levels above the portfolio,
program, or project manager.
5-Tailoring risk effort:
Risk management activities are consistent with the value of the
endeavor to the organization and with its level of risk, scale, and
other organizational constraints.
6-Integration with organizational project management:
Risk management does not exist in a vacuum isolated from
other organizational project management processes.
Successful risk management requires the appropriate
execution of organizational project management and ERM
processes, including the allocation of resources necessary for
the effective application of risk management.
Ch 03:
Framework for Risk Management
in Portfolio, Program, and Project
CH 03 CONTENTS
Business Context of Risk management in
Portfolio, Program, and Project Management
Scope of accountability, responsibility, and authority
General Approach to Risk Management
Questions & Answers
3.1:
Business Context of Risk management in
Portfolio, Program, and Project Management
BUSINESS CONTEXT OF RISK MANAGEMENT IN :
PORTFOLIO, PROGRAM, AND PROJECT MANAGEMENT
• All organizations encounter internal and external factors that influence
their ability to achieve desired objectives. Achieving those objectives is
rarely ensured. All organizational activities involve risk .
• An organization manages risk through people, processes, technology, and
information.
• Portfolio, program, and project managers are responsible for risks
associated with their endeavors. These managers are responsible for
working with stakeholders at various levels of the organization and applying
a systematic, integrated approach to risk management.
BUSINESS CONTEXT OF RISK MANAGEMENT IN :
PORTFOLIO, PROGRAM, AND PROJECT MANAGEMENT
BUSINESS CONTEXT OF RISK MANAGEMENT IN :
PORTFOLIO, PROGRAM, AND PROJECT MANAGEMENT
• Risk permeates through the pyramid.
• The organizational strategy sets the direction through the vision and
mission, and strategy defines specific goals and objectives for the
organization.
• Some threats arise when strategy or business objectives are not aligned
with the organization’s mission, vision, and core values.
• Additional threats arise when business objectives do not support strategy
or when endeavors, such as portfolios, programs, and project, are not
aligned with business objectives.
• Opportunities could be enhanced when strategy and business
objectives are well aligned.
1- ORGANIZATIONAL FRAMEWORK :
• Risk management includes all domains of the organization: enterprise,
portfolio, program, and project.
• ERM is an approach to managing risk that reflects the organization’s culture,
capability, and strategy to create and sustain value. It covers the policies,
processes, and methods by which organizations manage risks (both threats
and opportunities) to advance the mission and vision of the organization.
• Portfolio risk management derives its policies, processes, methods, and
tolerance from the ERM framework and tailors it for the management of
portfolios.
1- ORGANIZATIONAL FRAMEWORK :
• Similarly, programs and projects adopt their respective risk management
practices from the portfolio framework.
• The governance board typically oversees ERM in that it steers the process
with significant and proactive management engagement.
• The portfolio, program, and project managers manage and monitor
communications with internal and external stakeholders, which is required to
instill the importance and values of risk management, expected culture and
• behavior, and risk attitude.
2- ORGANIZATIONAL CONTEXT :
• The application of ERM is influenced by industry, regulations, and
organizational context.
• By understanding the context in which the organization exists, portfolio,
program, and project managers can tailor the optimal approach to risk
management for their endeavors and simultaneously assist the organization
in assessing and responding to risks.
• Many factors can also impact the extent of risk management practices. Some
of these factors include:
• Capital availability.
• Competitive landscape.
• Risk attitude.
3- STRATEGIC AND ORGANIZATIONAL PLANNING :
• Risk management in portfolios, programs,
and projects aligns with the setting of
strategic vision, mission, goals, values, and
business objectives. It provides the inputs for
pursuing different alternatives.
• Strategic goals and business objectives are
developed to realize the organization’s vision
and mission in line with core values.
• Once these goals and objectives are set,
they become inputs for risk management.
• If there are potential conflicts between
strategic goals and the portfolio of work,
then the risk is escalated to the proper
level of management. See Figure 3.1
4- LINKING PLANNING WITH EXECUTION THROUGH
PORTFOLIO, PROGRAM, AND PROJECT MANAGEMENT
• Portfolio, program, and project management refers to domains in the
organizational project management (OPM) framework for managing capabilities
and enhancing existing value or creating new value.
• Portfolio management serves as the bridge that connects strategic planning
with business execution. By focusing on selecting the right portfolio
components (e.g., programs, projects, and operational initiatives),
portfolio management enables organizations to achieve alignment with
strategy and to invest their resources wisely and effectively.
• Program and project management are then responsible for the implementation.
• Portfolio, program, and project managers work inclusively to:
(a) Identify, analyze, evaluate, prioritize, recommend, plan, and
implement risk responses.
(b) Monitor progress.
(c) Adjust risk responses as appropriate.
3.2:
Scope of accountability, responsibility, and authority
SCOPE OF ACCOUNTABILITY, RESPONSIBILITY, AND
AUTHORITY :
The accountability, responsibility, and authority of risk
management are shared by stakeholders involved in
portfolio, program, and project management.
SCOPE OF ACCOUNTABILITY, RESPONSIBILITY, AND
AUTHORITY :
Accountability :
is individual by nature and derived from a
position held in the organization. Accountability is related to
authority in that one is usually held accountable within one’s
limits of authority. However, one still may be held
accountable beyond one’s authority to act.
SCOPE OF ACCOUNTABILITY, RESPONSIBILITY, AND
AUTHORITY :
Responsibility :
Resides in an individual by the
assignment of a function or task. By accepting the
assignment, an individual takes on the associated
responsibility. The fact that others higher in the organization
may also be held responsible or accountable does not
diminish the responsibility held by the individual. The
assigning individual still is held accountable for the delegated
task, but responsibility is passed to the assigned individual.
SCOPE OF ACCOUNTABILITY, RESPONSIBILITY, AND
AUTHORITY :
Authority :
Like responsibility, may be delegated and gives
an individual the ability to make decisions within defined
bounds.
SCOPE OF ACCOUNTABILITY, RESPONSIBILITY, AND
AUTHORITY :
Accountability At :
Enterprise Level Portfolio Level
Program Level Project Level
ACCOUNTABILITY AT ENTERPRISE LEVEL :
• The objective of risk management is to apply knowledge, skills, and good
practices to manage the area of focus within the risk threshold that is
acceptable to the organization, whether at the enterprise, portfolio, program,
or project level.
• The purpose is to minimize the impact of threats to protect the organization
from loss and to embrace opportunities that translate to value.
• The management of risk across the continuum of portfolios, programs, and
projects requires collaboration throughout the enterprise, and the
recognition that failure to allocate the appropriate amount of resources
could jeopardize the organization’s strategic objectives.
• Portfolio, program, and project management are responsible for supporting
management policies, defining roles and responsibilities, setting targets,
and overseeing implementation.
• The managers of the work are responsible for keeping senior management
apprised of ongoing risk exposure and corresponding actions.
ACCOUNTABILITY AT PORTFOLIO LEVEL :
• In some cases, portfolios may exist for brief periods; however, portfolios often
exist for as long as the organization itself exists. As a result, portfolio
managers may oversee activities or authorize components that may take
several years for the organization to realize the value of the investment.
• Any change in this landscape has direct implications on the organization’s
strategic objectives. Specific external factors can include regulatory
requirements or mandates, market conditions, and organizational restructuring.
• Portfolio risk management tackles strategic, execution, and structural risks.
Whereas program risk management evaluates risk across a related set of
components, portfolio risk management is broad and considers risks that could
impact unrelated components and operational activities within the portfolio.
• As a result, portfolio managers address several challenges when managing
risk because portfolio-level risks encompass both external and internal
factors by bridging organizational strategy to implementation.
ACCOUNTABILITY AT PROGRAM LEVEL :
• At the program level, the risks that are evaluated span the related components
and, if triggered, could have a positive or negative impact on one or more other
components.
• Working with the component managers, it is the responsibility of the
program manager to identify and manage these risks. Rather than manage
these risks individually within the component, program managers ensure that
program risks are managed through coordination.
• Within the program, risks can affect the delivery of specific components.
• The program managers advise their component managers of any shared
risks and response plans that relate to individual components.
• There may be economies of scale and scope in that the shared risks may be
managed by initiating one risk response at the program level.
ACCOUNTABILITY AT PROJECT LEVEL :
• At the project level, the objective of risk management is to :
• (a) Decrease the probability and impact of negative risks.
• (b) Increase the probability and impact of positive risks specific to project
deliverables or objectives.
• Project managers are accountable for evaluating, reporting, and managing
both individual and overall project risks within the constraints of the project.
They may escalate certain risks to, or receive guidance from, sources such as
the program manager, portfolio manager, project management office,
governance board, and other leadership entities, depending on the
complexity of the initiative and organizational inputs.
• All project team members have the responsibility for managing risk, for
example,
▪ The identification of risk during initiation.
▪ Clarification of the trigger events.
▪ Awareness of potential new risks that could affect the endeavor.
3.3:
General Approach to Risk Management
GENERAL APPROACH TO RISK MANAGEMENT:
Factors for evaluating risks :
In order for risk management to take
place, portfolio, program, and project
managers need to identify the risk
probability and impact.
• Probability. The chance of a risk
occurring can range from slightly
above 0% to just below 100%.
• Impact. Risks, should they occur,
can have either a positive or
negative consequence for the
organization.
There are additional factors to consider when evaluating risks. Some are
included in Appendix X6 on Techniques for the Risk Management Framework.
RISK MANAGEMENT LIFE CYCLE :
• The risk management life cycle described in this section
illustrates a structured approach for undertaking a
comprehensive view of risk throughout the
enterprise, portfolio, program, and project
domains.
• Even though the way of managing risks differs
between these domains and from one organization
to another, an overall life cycle approach outlines a
sequence of logical phases that can be iterated.
• The risk management life cycle is shown in Figure 4-1.
It has a dedicated, procedural, and iterative workflow
of activities and processes, supported and performed
across the enterprise and within the portfolio, program,
and project
• domains.
• Because of the evolutionary nature of risk, the risk
management life cycle ensures a repeatable workflow
of processes that supports strategic decision making.
• All these activities are performed in an integrated
way within and across the portfolio, program, and
project domains.
3.4:
Questions & Answers
QUESTION ( 1 ) :
Members of a project team are not taking their risk management
responsibilities seriously. They don’t consider risk management as
primary to the project’s success and do not believe that the benefits are
significant. What should the risk manager do ?
A ) Motivate and influence the project team with risk engagement activities
like workshops.
B ) Ensure that the risk language used by all stakeholders is consistent
with the risk management plan.
C ) schedule a meeting to review and develop realistic risk thresholds with
the project team.
D ) Ensure that risk management responsibilities are clearly identified in
the risk management plan.
Answer is : ( A )
QUESTION ( 2 ) :
A risk manager faces resistance as they try to implement the project’s risk
strategy. Some members of the project team believe it is waste of time
and money. What should the risk manager do ?
A ) Reduce the number of risk management activities.
B ) Raise the concerns of the project sponsor.
C ) Meet with team members to address their concerns.
D ) Continue to implement the risk strategy.
Answer is : ( C )
QUESTION ( 3 ) :
A project manager wants to introduce new technology to improve a
project’s performance. However, there are some costs associated that are
beyond the current budget, and the proposed technology has not been
applied to any previous company projects. What should the project
manager do in this situation ?
A ) Outsource the implementation of the new technology as possible.
B ) Escalate the initiative to project decision-makers and sponsors.
C ) Take the advantage of this opportunity of improving the project
performance.
D ) Accept the fact that there is a risk associated with this new technology
Answer is : ( B )
QUESTION ( 4 ) :
What are the examples of risk thresholds ? ( Choose three )
A ) A Construction company walks away from a joint venture project
proposal due to a 30% chance of loss.
B ) A Business unit agreed that top project risks with more than US $ 100
million impacts would be escalated.
C ) A Project has defined the project level risk rating matrix based on the
like hood of occurrence and possible consequences and possible
consequences of schedule and cost.
D ) An organization seeks to establish a consistent method for evaluating
and responding to risk across the enterprise.
E ) A risk with a less than one-month schedule delay will be
communicated through the ares of concerns section in the project status
report instead of the risk register.
Answer is : ( A & B & E )
QUESTION ( 5 ) :
The risk manager is facilitating risk planning activities with the team. The
team is documenting all the checkpoints along the way that might indicate
delays on critical deliverables. What is this example of ?
A ) Risk categories.
B ) Risk responses.
C ) Risk registers.
D ) Risk triggers.
Answer is : ( D )
THANK YOU