0% found this document useful (0 votes)
14 views62 pages

Chapter 2 - Project Risks Management Process

Chapter Two discusses the project risk management process, emphasizing the proactive nature of risk management and its importance throughout the project life cycle. It outlines the steps involved in risk management, including identification, assessment, response planning, and monitoring. The chapter also classifies risks based on various factors and highlights the need for effective communication and integration of risk management with other project functions.

Uploaded by

wongelu bula
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views62 pages

Chapter 2 - Project Risks Management Process

Chapter Two discusses the project risk management process, emphasizing the proactive nature of risk management and its importance throughout the project life cycle. It outlines the steps involved in risk management, including identification, assessment, response planning, and monitoring. The chapter also classifies risks based on various factors and highlights the need for effective communication and integration of risk management with other project functions.

Uploaded by

wongelu bula
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter Two

Project Risk Management Process

3/5/2024 Prepared by Garedew D. 1


2.1 Understanding Nature of project risk management

• Project management deals with uncertainty,


• The sources of project risks are unlimited
• Project Risk Management is Pro-active
• Risk Management - An Integrative Function
• Variation of Risk Factors through the Project Life Cycle
• Classifications and Types of risks and related consequences
• Factor of a project risks

3/5/2024 Prepared by Garedew D. 2


Uncertainty, Causes/and sources of a project risks
• Every project manager understands risks are inherent in
projects. No amount of planning can overcome risk, or
the inability to control chance events.
• In the context of projects, risk is an uncertain event or
condition that, if it occurs, has a positive or negative
effect on project objectives.
• A risk has a cause and, if it occurs, a consequence. For
example, a cause may be a flu virus or change in scope
requirements. The event is that team members get
stricken with the flu or the product has to be
redesigned. If either of these uncertain events occurs, it
will impact the cost, schedule, and quality of the project.
• PRM has to do with uncertainty, probability or
unpredictability, and contingent planning.
3/5/2024 Prepared by Garedew D. 3
• The sources of project risks are unlimited. There are sources
external to the organization, such as inflation, market
acceptance, exchange rates, and government regulations.
• In practice, these risk events are often referred to as “threats”
to differentiate them from those that are not within the project
manager’s or team’s responsibility area. Thus, external risks
are extremely important and must be addressed.
• Risk management identifies as many risk events as possible
(what can go wrong), minimizes their impact (what can be
done about the event before the project begins), manages
responses to those events that do materialize (contingency
plans), and provides contingency funds to cover risk events
that actually materialize

3/5/2024 Prepared by Garedew D. 4


• Typical risk sources
The term ―risk source‖ can be used to describe the more general-level events,
phenomena, or factors that cause risk.
• Generally, the most substantial risk sources in a project are:
 customer, user, financer;
 supplier, subcontractor;
 new technical, functional, or methodical solutions;
 decision-making speed and content of decisions (in a company related to the
project), and the degree of management support and amount of resources
provided to the project;
 communication, transfer of information, availability of information
 changes to plans;
 human factors, such as excessive optimism in preparing estimates, lack of
information and knowledge, or change resistance due to other factors; and
 coordination problems due to the dependencies among activities or the complex
dependencies among parts of the project.
3/5/2024 Prepared by Garedew D. 5
3/5/2024 Prepared by Garedew D. 6
Project Risk Management is Pro-active

Risk management is a proactive approach rather than reactive. It is a


preventive process designed to ensure that surprises are reduced and that
negative consequences associated with undesirable events are minimized.
It also prepares the project manager to take action when a time, cost, and/or
technical advantage is possible.
 Successful management of project risk gives the project manager better
control over the future and can significantly improve chances of reaching
project objectives on time, within budget, and meeting required technical
(functional) performance.
• Severity of the potential loss appears to attract the most
attention because individuals appear to be willing to accept small (even
frequent) losses, but are averse to a risk which has high stakes. Even so, a
major thrust must be to minimize unwarranted optimism, prejudice,
ignorance or self-interest.
3/5/2024 Prepared by Garedew D. 7
• Consider this improbable, but quite possible, situation.
You are at risk of being shot at. You have four options.
• Reactive:
1. You can move to avoid the bullet;
2. You can deflect the bullet; or
3. You can repair the damage done by the bullet.
• Pro-active:
4. You can take steps to avoid being confronted by the
person with the gun
• Crisis management (reactive mode) consists of
selecting the appropriate response. However, if
anticipation and planning make it possible to avoid the
situation in the first place (pro-active mode) then this
approach would obviously be better.

3/5/2024 Prepared by Garedew D. 8


• Risk Management - An Integrative Function
• A failure to give proper recognition to risk management on a
project can lead to unnecessary and often substantial losses, or
even complete project failure.
• The status of risk on a project varies significantly during the
course of its life cycle, and, as with most of the other project
functions, the most effective time for achieving the greatest
impact on project results is early on in the project
development phase.
• Consequently, risk management should be established as a
continuing integrative function throughout the project's life
cycle.
• Figure 11.1 illustrated schematically how risk management
integrates with each of the other project management
functions.
3/5/2024 Prepared by Garedew D. 9
3/5/2024 Prepared by Garedew D. 10
• Risks are often chained together revealing one risk as the
cause of another, revealing relationships and interactions
among risks, and facilitating understanding of a complex
matter.
• Visual charts are often used as tools to portray
relationships among risks, illustrating the cause-and
effect chains and risk interactions

3/5/2024 Prepared by Garedew D. 11


Variation of Risk Factors Through the Project Life Cycle
• the life cycle of a project is very dynamic, i.e., characterized by rapid
change.
• the project risk factors are also subject to considerable change
during the project life cycle.
• A typical project is made up of four generic phases, consisting of
concept, development, implementation, and termination and that
these in turn are broken down into stages specific to the industry or
area of project application.

3/5/2024 Prepared by Garedew D. 12


3/5/2024 Prepared by Garedew D. 13
• The significance is that opportunity and risk generally remain
relatively high during project planning but, because of the relatively
low level of investment to this point, the amount at stake remains
low.
• In contrast, during project accomplishment opportunity and
risk progressively fall to lower levels as remaining unknowns are
translated into knowns. At the same time, the amount at stake
steadily rises as the necessary resources are progressively invested
to complete the project.
• The period of highest vulnerability to risk occurs during the last two
phases. At this time, adverse conditions may also be discovered as a
result of acceptance testing and start-up of the project.
• The purpose of risk management must be to influence the project
planning such that both uncertainty-risk and amount- at-stake are
reduced to acceptable levels throughout the project life cycle

3/5/2024 Prepared by Garedew D. 14


• The nature of project risk and its management varies based
on the types of the types of risks
• Classification of project risks based on
Nature of uncertainty
Impacts of risks
 time frame
Nature of response to risks
 source-external internal

3/5/2024 Prepared by Garedew D. 15


knowns, known-unknowns, and unknown-unknowns
• Risks may be classified in a number of different ways. Forv example, one
way is to describe uncertainties (and hence opportunities and risks) in
terms of knowns, known-unknowns, and unknown-unknowns.
• A known -is an item or situation containing no uncertainty. An example of a
known in our personal lives is death-it will happen and there is no
uncertainty about it.
• Known-Unknowns are those things which we know exist but do not know
how they will affect us. A known-unknown is an identifiable uncertainty. An
example of a known-unknown is our electricity bill-we know that we shall get
one next month but do not how much it will be. Another example is cancer.
We know that cancer exists, but do not know if we shall fall victim to it.
• An unknown-unknown is simply an item or situation whose existence we
cannot imagine. For example, before the first case was reported, AIDS was
an unknown-unknown. Now, however, since we know that AIDS exists, it is a
known-unknown like cancer.
Obviously, there can be no example of an unknown-unknown since, by
definition, its existence cannot
3/5/2024
be imagined
Prepared by Garedew D. 16
3/5/2024 Prepared by Garedew D. 17
• Another approach is to classify risks according to their impact*
on the project. For example:
• Scope risks - risks associated with changes of scope, or the
subsequent need for "fixes" to achieve the required technical
deliverables
• Quality risks - failure to complete tasks to the required level of
technical or quality performance
• Schedule risks -failure to complete tasks within the estimated
time limits, or risks associated with dependency network logic
Cost risks - failure to complete tasks within the estimated
budget allowances
• Unfortunately, many identifiable risks will have an impact on
two or more of these areas, particularly both schedule and cost, so
that this leads to significant overlapping and potential double
counting when it comes to making offsetting provisions.
3/5/2024 Prepared by Garedew D. 18
• Discrete vs time scale risks
• Yet another way of classify risks is to separate them according to their
nature. For example, discrete one-time risk events such as fire and theft
may be distinguished from those that are time-scaled, such as with
flooding or earthquakes, because in the latter case the probability and
magnitude of occurrence varies with the period of time selected.
• Such risks are typically insurable, and corporate management usually
draws a distinction between insurable risk and business risk, where
business risk is risk arising from the business venture itself.
• Internal vs external risks
• Again, for any particular project, some risks may be considered to be
sufficiently remote or catastrophic as to be outside of the realm of
project responsibility.
• Example: Obvious examples include a change in political direction or
the financial collapse of the sponsoring organization
3/5/2024 Prepared by Garedew D. 19

3/5/2024 Prepared by Garedew D. 20
• Risk Factors
• All project risks are characterized by the following three risk
factors?
1. Risk event - precisely what might happen to the detriment
of the project;
2. Risk probability - how likely the event is to occur; and
3. Amount at stake - the severity of the consequences.
With this data, the risk event status (criterion value or
ranking) of a given risk event can be determined by the
following relationship:
Risk Event Status = Risk Probability x Amount at Stake

3/5/2024 Prepared by Garedew D. 21


• Some risk events are characterized by low probability and high
severity, while high probability and low severity.

• Clearly, the most serious risks are those involving both high
probability and high severity.

• Many risk events cannot be treated as simply discrete and


independent as the total amount at stake may increase
substantially as a result of a series of interacting events and
requires careful examination and special analytical techniques.

3/5/2024 Prepared by Garedew D. 22


2.2 Approach to Project Risk Management

3/5/2024 Prepared by Garedew D. 23


2.2.1 Project Risk Management Process
• Risk management consists of four activities, the purposes of which
are to strengthen and utilize the positive effects of risks and weaken
and prevent the unfavorable effects of risks.
• Many approaches can be used to address risk and the threats it
produces.
• In its most simplistic form, project risk management consists essentially
of four process phases or phases. These are:
Step 1: Project risk Identification
Step 2: Project Risk Assessment/analysis
Step 3: Project Risk response planning and
Step 4: Project Risk monitoring and control

3/5/2024 Prepared by Garedew D. 24
Table 1: The major components of the Project risk management process

3/5/2024 Prepared by Garedew D. 25


1) Risk identification: Figure out what could go wrong and write it
down/listing all the potential risks affecting the project success.
2) Risk analysis: Identify the likelihood and consequences of each
risk, and prioritize the risks.
3) Risk response planning: Get ready for what might happen, item
by item.
4) Risk monitoring and control: Throughout the project, check up on
the risks and update the risk control plan at each daily or weekly
status meeting.

3/5/2024 Prepared by Garedew D. 26


Identification (determining what threats exist). Identify all significant
uncertainties (sources of risk), including specific threats (also called
potential problems or risk events) that could occur throughout the life
of the project.

3/5/2024 Prepared by Garedew D. 27


• The first step in the risk management process is figuring
out what you’re up against. What kinds of things
threaten your ability to deliver what you’ve promised?
 it means trying to generate a list of all the possible
risks that could affect the project.
• Identifying risks refers to searching for, defining, and
documenting them.
• Once risks are identified, their nature and magnitude can
be communicated with systematic methods over the
various stages of a single project, and from one project
to another.

3/5/2024 Prepared by Garedew D. 28


• This phase consists of identifying all the possible risks which may
significantly impact the success of the project. Conceptually, these
may range from
high-impact/high-probability, through high-impact/low-probability,
low-impact/high-probability to low-impact/low-probability.
• Attentions:
the high and medium risks, including accumulations under any one
item of risk, should receive the most attention and
 combinations of risk which together pose a greater threat than each
individually should not be overlooked

3/5/2024 Prepared by Garedew D. 29


In order to identify all the potential risks to a particular project, it
may be necessary to undertake a risk identification program.

This might involve soliciting the considered opinions of


knowledgeable persons associated with the project or similar
projects or conducting a "brainstorming" type of workshop
amongst the project team.

3/5/2024 Prepared by Garedew D. 30


• Risk identification is proactive worry. We start with knowing that
something could go wrong, that something unexpected could
happen. We ask, ―What could that be?‖ Then we write down the
answer.
• Project identification stars during the planning phase.
• Typically the project manager pulls together, a risk management
team consisting of core team members and other relevant
stakeholders during the planning phase,
 The team uses brainstorming and other problem identifying
techniques to identify potential problems.
Participants are encouraged to keep an open mind and generate
as many probable risks as possible

3/5/2024 Prepared by Garedew D. 31


Approaches to Project Risk Identification

• Risk Break Down Structure (RBS)


• Work Breakdown structure (WBS)
• Project Profile

3/5/2024 Prepared by Garedew D. 32


Risk Breakdown structure

 Organizations use risk breakdown structures (RBSs) in conjunction


with work breakdown structures (WBSs) to help management teams
identify and eventually analyze risks.

The focus at the beginning should be on risks that can affect the
whole project as opposed to a specific section of the project or
network.

 Figure 7.3 provides a generic example of an RBS.

3/5/2024 Prepared by Garedew D. 33


3/5/2024 Prepared by Garedew D. 34
• Work Break Down Structure (WBS)
• After the macro risks have been identified, specific areas
can be checked.
• An effective tool for identifying specific risks is the work
breakdown structure. Use of the RBS reduces the chance
a risk event will be missed.
• On large projects multiple risk teams are organized
around specific deliverables and support the project
manager in successful managing a project including risk
management.
3/5/2024 Prepared by Garedew D. 35
3/5/2024 Prepared by Garedew D. 36
2. Project Risk Profile
• A risk profile is another
useful tool. A risk profile is a
list of questions that
address traditional areas of
uncertainty on a project.
• These questions have been
developed and refined from
previous, similar projects.
• Figure 7.4 provides a partial
example of a risk profile

3/5/2024 Prepared by Garedew D. 37


• The project team review the WBS, the activity list, and the list of items planned to
undertake:
1) Ask, ―What could keep us from getting what we need and doing a good job?‖
2) Ask, ―What are we getting from outside the team? Who are we depending on
outside the team? What would happen if they don’t deliver?‖
3) Ask, ―What have we never done before? What areas are difficult for us?‖
4) Ask, ―What has gone wrong on other projects that could happen again here?‖
5) Finally, ask, ―What could go unexpectedly right? What could make the project
easier, get it done sooner or at lower cost, give us a better result?‖ List those
positive risks, too.
The result of this meeting is a list of risks, formally called a risk register.

3/5/2024 Prepared by Garedew D. 38


• Risk profiles recognize the unique strengths and weaknesses of the
firm. Finally, risk profiles address both technical and management
risks.
• For example, the profile shown in Figure 7.4 asks questions about
design (Does the design depend upon unrealistic assumptions?)
and work environment (Do people cooperate across functional
boundaries?)
• Risk profiles are generated and maintained usually by personnel
from the project office. They are updated and refined during the
post-project audit. These profiles, when kept up to date, can be a
powerful resource in the risk management process.

3/5/2024 Prepared by Garedew D. 39


Step Two – Project Risks Assessment/Analysis

3/5/2024 Prepared by Garedew D. 40


project Risk Assessment
 Having identified the range of possible risks, the next step is to
assess them. The purpose is to determine their ranking or status
in terms of type, impact and probability.
This may range from a simple attempt at subjective evaluation
to a more serious attempt at measurement.
Due to their nature, or simply through lack of relevant data,
however, it may be found that many of the risks defy direct
measurement, and a more in-depth impact analysis becomes
necessary.

3/5/2024 Prepared by Garedew D. 41


3/5/2024 Prepared by Garedew D. 42
Assessment Methodology

3/5/2024 Prepared by Garedew D. 43


• Simple Assessment Development
• A simple risk assessment may be conducted by stepping
through the sequence shown in the next figure.

• As a prelude to a better understanding of the relative


significance of the findings, however, a Risk Baseline
should be established based on the organization's
external "status quo."

3/5/2024 Prepared by Garedew D. 44


• Step 1: Select the risk events, or series of related events, to be
examined. Prioritize these for attention according to the initial
selection discussed earlier

3/5/2024 Prepared by Garedew D. 45


• Step 2: Assess the probability associated with the risk event(s1.
• This is perhaps one of the more subjective steps, although there are
a number of procedures which can help.
• An estimate of the degree of uncertainty may be arrived at by:
Influence diagrams
Risk contribution analysis
Probability distribution
Probability trees
Risk modelling
Sensitivity profile

3/5/2024 Prepared by Garedew D. 46


Step 3: Assess the consequences and severity of the risk event(s) by
determining:
the amount at stake, and the criticality.
• Note that amount at stake and criticality may vary with time, i.e.,
according to the stage in the project life cycle, as discussed earlier
• In most cases, the amount at stake and criticality can be arrived at
by a simple examination of the available data and some subjective
judgment.
• In complex situations, however, it may be necessary to develop
some form of mathematical model and conduct a series of
computer runs.

3/5/2024 Prepared by Garedew D. 47


• Step 4. Having identified the consequences and
their significance, this step involves planning to
mitigate the likelihood of the risk event(s) in
question, and/or developing suitable responses
and contingency plans.
• It may even be necessary to gain more insight
and gather additional information to complete
this step.
• Either way, it should be the most creative step of
all because it provides the occasion for
converting risks into opportunities.

3/5/2024 Prepared by Garedew D. 48


• Step 5
• The final step in the process is to accumulate the results
of the assessment in a set of "Conclusions and
Recommendations" such that appropriate management
decisions can be made with full knowledge of the
apparent risks involved. Either the residual risks must be
accepted, or the project abandoned.

• By following these steps the management of risk and


uncertainty can be directly incorporated into the early
project planning process as well as dealt with
expeditiously during the course of project execution

3/5/2024 Prepared by Garedew D. 49


Step 3: Planning Project Risk Response

 Response (dealing with the threats). Determine the best


approaches for addressing each high-threat potential problem,
which may include evaluating and choosing among a number of
alternatives, and create specific action plans.

3/5/2024 Prepared by Garedew D. 50


• Risk Response Planning
• Once a risk is on our list, we have to decide what we’re going to do
about it— our risk management options. By putting it on the list,
we’ve accepted the risk under management, that is, we’ve
committed to keeping track of it and doing something about it.
• Planning project risk response requires may range from simple
decisions to accept the risks as they are, especially on a small
project, to a comprehensive plan for deployment of resources to
control a risk event, should it occur, where the event may be far
reaching (e.g., labor strife) or urgent (e.g., fire, accident)

3/5/2024 Prepared by Garedew D. 51


1. Avoid/prevent: The best thing that you can do with a risk is to avoid it.
If you can prevent it from happening, it definitely won't hurt your
project. The easiest way to avoid this risk is to walk away from the cliff
but that may not be an option on this project.
2. Mitigate: If you can't avoid the risk, you can mitigate it. This means
taking some sort of action that will cause it to do as little damage to your
project as possible.
3. Transfer: One effective way to deal with a risk is to pay someone else
to accept it for you. The most common way to do this is to buy insurance.
4. Accept: When you can't avoid, mitigate, or transfer a risk, then you
have to accept it. But even when you accept a risk, at least you've looked
at the alternatives and you know what will happen of it occurs. If you
can't avoid the risk, and there’s nothing you can do to reduce its impact,
then accepting it is your only choice.

3/5/2024 Prepared by Garedew D. 52


Mitigate a risk. That means reducing its likelihood or reducing its
consequences. These are two separate actions and we can do both.
For example, we can reduce the likelihood of not getting the right
construction supplies for a building project by identifying two
suppliers.
We can reduce the consequences by having an alternate schedule for
the work if no supplies are available.
• Avoid a risk by changing our plans so that the risk cannot possibly
happen at all. For example, if our project originally involves travel, we
avoid the risks associated with travel if we arrange to work remotely,
so we don’t have to travel at all.
• Transfer the risk, for example, by getting insurance. Risk transference
is not that important for most projects. When we transfer a risk,
someone else foots the bill, but the project still gets into trouble or
fails. However, it is important in some industries.
3/5/2024 Prepared by Garedew D. 53
• Transferring the risk. Risks can be transferred in the contract to the
responsibility of the customer or subcontractor. The risk can also be
transferred to an insurance company by purchasing an insurance
policy.
• Avoiding risk. Project risk as a whole can be avoided by executing the
requested functional product using a different technical solution, for
example, or by choosing another method for executing the work.
• Although these approaches would avoid the risks present in the
original plan, a different technical solution or method of execution
brings with it different types of risks.
• Thus, new solutions may turn out to be more risky than familiar, tested
technical solutions and working methods that have been used on prior
projects.

3/5/2024 Prepared by Garedew D. 54


Step 4: Risk Monitoring and Control
• Once we have completed project risk planning, then
we are ready to keep risk under control throughout the
project. Important measures include:
Review the risk list at every daily or weekly status
meeting
Implement project risk control strategy
 Monitor and adjust the plan to accommodate new
risks
Change the management approach as necessary

3/5/2024 Prepared by Garedew D. 55


• A major element of the risk control process is
change management. Every detail
of a project plan will not materialize as expected.
Coping with and controlling
project changes present a formidable challenge for
most project managers. Changes
come from many sources such as the project
customer, owner, project manager, team members,
and occurrence of risk events. Most changes easily
fall into three
categories:
3/5/2024 Prepared by Garedew D. 56
3/5/2024 Prepared by Garedew D. 57
• As part of the project communication plan,
stakeholders define up front the
communication and decision-making process that
will be used to evaluate and ac-
cept changes. The process can be captured in a flow
diagram like the one presented
in Figure 7.9. On small projects this process may
simply entail approval of a small
group of stakeholders. On larger projects more
elaborate decision-making pro-
cesses are established, with different processes
being used for different kinds of
3/5/2024 Prepared by Garedew D. 58
change. For example, changes in performance
• Of particular importance is assessing the impact of
the change on the project.
Often solutions to immediate problems have
adverse consequences on other as-
pects of a project. For example, in overcoming a
problem with the exhaust system
for a hybrid automobile, the design engineers
contributed to the prototype exceed-
ing weight parameters. It is important that the
implications of changes are as-
sessed by people with appropriate expertise and
perspective. On construction
3/5/2024 Prepared by Garedew D. 59
projects this is often the responsibility of the
• Organizations use change request forms and logs to
track proposed changes.
An example of a simplified change request form is
depicted in Figure 7.10. Typi-
cally change request forms include a description of
the change, the impact of not
approving the change, the impact of the change on
project scope/schedule/cost,
and defined signature paths for review as well as a
tracking log number

3/5/2024 Prepared by Garedew D. 60


• The benefits derived
from change control systems are the following:
1. Inconsequential changes are discouraged by the
formal process.
2. Costs of changes are maintained in a log.
3. Integrity of the WBS and performance measures
is maintained.
4. Allocation and use of budget and management
reserve funds are tracked.
5. Responsibility for implementation is clarified.
6. Effect of changes is visible to all parties involved.
7. Implementation of change is monitored.
3/5/2024 Prepared by Garedew D. 61
8. Scope changes will be quickly reflected in
Step 5 – Documentation ( many scholars ignore this step)
• The purpose is to build a data base of reliable data for the
continuing evaluation of risk on the current project, as
well as for improving the data base for all subsequent
projects

3/5/2024 Prepared by Garedew D. 62

You might also like