Project Risk Management
1. Give short answers for the following questions:
i. Which processes are involved in project risk management?
Answer: The processes involved in project risk management are:
Risk Management Planning
Risk Identification
Qualitative Risk Analysis
Quantitative Risk Analysis
Risk Response Planning
Risk Monitoring and Control.
ii. Define the term ‘risk holder’s tolerance.’
Answer: Risk holder’s tolerance is a term used to define the ability of stakeholders to
tolerate certain risks based on the project, the conditions, and the potential for loss or
reward.
iii. What is risk identification?
Answer: Risk identification is the process of detecting the risks and then documenting how
their manifestation may affect the project.
iv. Define the term ‘Qualitative Risk Analysis.’
1. Answer: The term ‘Qualitative Risk Analysis’ define the methodology of ranking risks
by priority, which then guides the risk response process.
v. What is a Decision Tree Method? How it is used for examining risks?
Answer: A decision tree is a method to determine which of two decisions would be better.
The decision tree model examines the risks and benefits of decision based on probability
of success and probabilities to happen . Less likely risks will be prioritized in a different way
then extremely likely risks .
vi. Explain the term ‘risk response.’
Answer: Risk response are the appropriate steps taken or procedures implemented upon discovery
of an unacceptably high degree of exposure to one or more risks
vii. What is ‘risk acceptance’?
Answer: Risk Acceptance is one of the strategies of dealing with risks. Acceptance means
that we accept the identified risk. We will not take any action because we can accept
its impact and probability .
viii. Give a few examples of risk transfers.
Answer:
1. Insurance policy
Purchasing insurance is a common method of transferring risk. When an individual or entity
is purchasing insurance, they are shifting financial risks to the insurance company. Insurance
companies typically charge a fee – an insurance premium – for accepting such risks.
2. Indemnification clause in contracts
Contracts can also be used to help an individual or entity transfer risk. Contracts can include
an indemnification clause – a clause that ensures potential losses will be compensated by
the opposing party. In simplest terms, an indemnification clause is a clause in which the
parties involved in the contract commit to compensating each other for any harm, liability,
or loss arising out of the contract.
2. How can the effects of risks be mitigated? Give some examples.
Answer: Risk mitigation can be defined as taking steps to reduce adverse effects. There are
four types of risk mitigation strategies .
Risk acceptance does not reduce any effects however it is still considered a strategy.
This strategy is a common option when the cost of other risk management options
such as avoidance or limitation may outweigh the cost of the risk itself. A company
that doesn’t want to spend a lot of money on avoiding risks that do not have a high
possibility of occurring will use the risk acceptance strategy.
Risk avoidance is the opposite of risk acceptance. It is the action that avoids any
exposure to the risk whatsoever. It’s important to note that risk avoidance is usually
the most expensive of all risk mitigation options.
Risk limitation is the most common risk management strategy used by businesses.
This strategy limits a company’s exposure by taking some action. It is a strategy
employing a bit of risk acceptance along with a bit of risk avoidance or an average of
both. An example of risk limitation would be a company accepting that a disk drive
may fail and avoiding a long period of failure by having backups.
Risk transference is the involvement of handing risk off to a willing third party. For
example, numerous companies outsource certain operations such as customer
service, payroll services, etc. This can be beneficial for a company if a transferred risk
is not a core competency of that company. It can also be used so a company can
focus more on their core competencies.
3. Discuss, in detail, the process of identifying project risks.
Answer: The process of identifying project risks consists in:
Interviews. Select key stakeholders. Plan the interviews. Define specific questions.
Document the results of the interview.
Brainstorming. I will not go through the rules of brainstorming here. However, I
would offer this suggestion. Plan your brainstorming questions in advance. Here are
questions to use:
A. Project objectives. What are the most significant risks related to [project
objective where the objective may be schedule, budget, quality, or scope]
B. Project tasks. What are the most significant risks related to [tasks such as
requirements, coding, testing, training, implementation]
Checklists. See if your company has a list of the most common risks. If not, you may
want to create such a list. After each project, conduct a post review where you
capture the most significant risks. This list may be used for subsequent projects.
Warning – checklists are great, but no checklist contains all the risks.
Assumption Analysis. The Project Management Body of Knowledge (PMBOK) defines
an assumption as “factors that are considered to be true, real, or certain without
proof or demonstration.” Assumptions are sources of risks. Project managers should
ask stakeholders, “What assumptions do you have concerning this project?”
Furthermore, document these assumptions and associated risks.
Cause and Effect Diagrams. Cause and Effect diagrams are powerful. Project
managers can use this simple method to help identify causes-facts that give rise to
risks. And if we address the causes, we can reduce or eliminate the risks.
Affinity Diagram. This technique is a fun, creative, and beneficial exercise.
Participants are asked to brainstorm risks. I ask participants to write each risk on a
sticky note. Then participants sort the risks into groups or categories. Lastly, each
group is given a title.