Week #2:
Risk Science:
Definitions,
Frameworks,
and Processes
1
Purpose of today’s Lecture :
• To provide an introduction to the concept of risk, the importance of the risk management
process, and the main steps and techniques involved in identifying, analysing, and responding to
project risks.
Why is research on risk 2
increasing?
3
What is Risk?
• According to International Organization for Standardization (ISO) 31000, risk is the “effect of
uncertainty on objectives”.
• Uncertainty refers to an absence of complete certainty; that is, the outcomes of any event are not known, and
therefore cannot be predicted or measured.
• Project Objectives are what we plan to achieve by the end of the project.
Fig. A. The project management triangle
4
Are all risks bad?
The Effect of Uncertainty
Downside risks Upside risks
(threats) (Opportunities)
The Effect of the COVID-19 Pandemic on the IT Sector
Downside risks Upside risks (Opportunities)
• Increased Cybersecurity Threats: With the rise in • Increased Demand for IT Solutions: There's a
remote work, there's a significant increase in the surface heightened demand for IT solutions that support
area for potential cyber attacks. remote work, e-commerce, online education, and
• Regulatory Compliance Risks: Rapidly changing telehealth services.
regulations (especially related to data protection) can • Enhanced IT Infrastructure: The increased reliance
introduce risks in compliance and necessitate sudden on IT solutions can lead to significant investments in
shifts in project scopes or practices. upgrading IT infrastructure
What is the Risk Management Process? 5
Project Risk Management is a systematic process of planning, identifying, analysing, and responding to
project risks.
Why is Risk Management Important?
1 It fills strategic gaps by shaping and updating risk culture at all levels within the organisation
2 It discourages the acceptance of financially unsound projects
3 It preserves the credibility and reputation of the organisation
4 it improves communication within and between project teams
5 it provides a structured framework for systematically guiding the process of managing unwanted events
What are the steps involved in risk management? 6
• The following are examples of risk management frameworks:
Plan risk management
Identify risks
Perform qualitative risk
analysis
Perform quantitative risk
analysis
Plan risk response
Control risks
Figure B. PMI Risk Management Framework Figure C. ISO 31000 Risk Management Framework Figure D. IRM Risk Management Framework
(Source: PMBOK, 2021) (Source: IS0 31000, 2018) (Source: IRM, 2002)
1 Risk Management Planning 7
Risk management planning outlines the responsibilities of the risk management team and schedules all activities and
procedures necessary to observe, evaluate, and document the risks associated with the project
Outputs:
1 Risk strategy. Describes the general approach to managing risk on this project.
Methodology. Defines the specific approaches, tools, and data sources that will be used to perform risk
2
management on the project.
Roles and responsibilities. Defines the lead, support, and risk management team members for each type of activity
3 described in the risk management plan, and clarifies their responsibilities
4 Funding. Identifies the funds needed to perform activities related to Project Risk Management. Establishes protocols
for the application of contingency and management reserves
Timing. Defines when and how often the Project Risk Management processes will be performed throughout the
5
project life cycle, and establishes risk management activities for inclusion into the project schedule.
Stakeholder risk appetite. The risk appetites of key stakeholders on the project are recorded in the risk management
6
plan, as they inform the details of the Plan Risk Management process. I
2 Risk Identification and Classification 8
Risk identification involves two phases:
1 The Initial Risk Identification Phase: this phase is normally performed by firms that have not previously identified their risk
factors in a structured manner, or by new firms or projects.
2 The Continuous Risk Identification Phase: this phase aims at identifying new risk factors that have never been identified
before.
Risk identification techniques
Expert interviews Brainstorming Delphi technique Cause and effect diagrams
Risk Classification
Risks can be classified depending on their source of origin, their nature, and type in to (for example):
Financial risks Technical risks Design risks Management risks Environmental risks Safety risks
9
Individual discussion (10-15 minutes):
Each student to densify the key risks facing the successful implementation of IT projects. Classify them
under categories such as financial-related risks, technical-related risks, and operational-related risks.
3 Risk Analysis 10
The objective of the risk analysis is to gain a clear view of risks' circumstances and implications and then to rank them
based on a set of priorities
Risk Analysis
Qualitative Quantitative
Risk Analysis Risk Analysis
Qualitative 11
Risk Analysis
The process of qualitative risk analysis consists of assessing the probability and impact of the identified risks.
Advantages of using Qualitative Risk Analysis
1. It offers low-cost coverage for a wide range of risks;
2. It offers greater flexibility in terms of reporting and processes.
3. It provides a better understanding of project risks at an early stage of the project
Disadvantages of using Qualitative Risk Analysis
1. It is solely based on experts' subjective judgments.
2. The cost analysis of risks is not considered.
12
Probability and Impact Matrix
• Using this method, risks are ranked by multiplying the probability score of each risk by its impact score, resulting in
the risk score as presented in Equation (1).
Risk= Probability * Impact …………………………………………..……. (1)
Probability
For Example:
If the likelihood of Risk x is 4 and its
impact is 2, the score (weight) of Risk x
would be 8 (Yellow Zone) (According to
Equation (1)).
Impact
Figure D. Risk Matrix (Source: Kassem et al. 2019)
13
Failure Mode Effect Analysis
In the FMEA approach, the following parameters are used to calculate the rank of risks (Prakash et al., 2015):
Likelihood (L): the probability of failure occurrence.
Severity (S): the impact of failure on the project objectives.
Detection (D): the ability to identify a potential failure before its occurrence, which means how detectable the
failure is while something is still done, also called detectability.
Risk Priority Number (RPN): a number used to express the priority of the failure, where: RPN = L * S * D
14
Table A. FMEA likelihood, severity and detection scales
Table B. The RPN ranking categories
How to use FEMA:
[Link]
15
Enhancing Multi-Criteria Risk Matrices
One of the methods is by running risk matrices under fuzzy sets theory (fuzzy environment).
The importance of Fuzzy Sets Theory (FST) comes when decision-
makers have to make decisions with uncertain, ambiguous,
vagueness data. FST is a mathematical approach introduced by
Zadeh (1965) to deal with information or data that is too complex or
ill-defined to be processed in a conventional algorithm. The key Professor Lotfi A. Zadeh
Founder of Fuzzy Logic
advantage of fuzzy sets in comparison with the classical set theory is
its capability to capture the vagueness of concepts due to uncertainty
and human subjectivity. One of the essential advantages of using
fuzzy logic when analysing risks is that the whole process leads to
creating a control system that can reduce risks efficiently and
effectively. Furthermore, fuzzy logic applications for risk assessment
can minimise the subjectivity to an acceptable level.
Direct link: [Link]
16
The Fuzzy Process:
Fuzzification is a fundamental process in fuzzy set theory that involves transforming crisp or deterministic data
into fuzzy or uncertain data. In other words, fuzzification is the process of mapping precise numerical values or
discrete states onto fuzzy values, which are represented by membership functions.
Fuzzy Inference: In this step, the system uses a set of predefined rules (typically expressed as "if-then"
statements) to combine and aggregate the fuzzy input variables.
Defuzzification is the process of converting the fuzzy output of a fuzzy inference system back into a crisp or
numerical value that can be used as a decision or an action.
Example of fuzzy modelling using MATLAB: 17
Out of control-related factors
Availability of expertise
Company level of contingencies
Impact on cost
Impact on time
Impact on quality
See the full example and its description via: [Link]
Quantitative 18
Risk Analysis
Qualitative risk analysis is the process of numerically analysing the combined effect of identified individual project risks
and other sources of uncertainty on overall project objectives.
Advantages of using Quantitative Risk Analysis
1. Providing a means of analysing the combined effect of risks together on objectives.
2. Allowing exploration of a range of options for addressing risk
3. Presenting targets realistically
Disadvantages of using Quantitative Risk Analysis
1. The need to use software tools
2. Analytical outputs need careful interpretation.
19
Monte Carlo Simulation
Monte Carlo Simulation is a stochastic technique that is used to estimate the possible outcomes of an uncertain event.
• By using a random number generator, a value is calculated for each probability distribution in order to calculate the values of
cost/schedule
• The result of a Monte Carlo simulation is a range – or distribution – of possible outcome values. This data on
possible results enables you to calculate the probabilities of different outcomes in your forecasts, as well as perform
a wide range of additional analyses.
Examples of probability distributions :
4 Risk Response/treatment 20
Risk response/treatment is the process of developing options, selecting strategies, and agreeing on actions to address
overall project risk exposure, as well as to treat individual project risks.
Risk response/treatment strategies
This strategy involves reducing the likelihood or impact of a risk through proactive measures
Mitigate
such as implementing controls or taking insurance.
This strategy involves sharing the risk with another party through mechanisms such as
Share
outsourcing, partnering,
Avoid This strategy involves eliminating the risk by avoiding the activities or situations that cause it.
This strategy involves accepting the potential consequences of a risk and not taking any
Accept
action to mitigate it.
21
Examples:
Mitigate Share Avoid Accept
Examples include: For example:
replanning the setting up a
project, changing collaborative Active Passive
business structure in For example, a
the scope and The most common
which the buyer and manufacturing
boundaries of the business may avoid
strategy is to establish
the seller share the an overall contingency
project, modifying using certain
overall project risk, reserve for the project,
project priority, hazardous materials No proactive
launching a joint including amounts of
changing resource or chemicals due to time, money, or
actions.
venture or special-
allocations, purpose company, or safety concerns. resources to be used
if the project exceeds
adjusting delivery subcontracting key its thresholds.
times, etc. elements of the
project.
Optimisation in Risk Management 22
• Optimisation, in the context of mathematics, engineering, and computer science, refers to the process of
finding the best solution or outcome from a set of possible choices, often while considering certain
constraints or objectives.
• In the context of risk management, risk optimisation is mainly concerned with the selection of risk
response strategies. While it can also be used to choose suitable tools for identification or analysis, the
primary focus here is on risk treatment and response.
• For illustration purposes, please refer to the following paper on risk response strategies optimisation: "A
Proposed Fuzzy-based Optimisation Model for Evaluating Construction Projects' Risk Response
Strategies." The paper is attached to Week 2.
4 Risk Monitoring and control 23
Monitor Risks is the process of monitoring the implementation of agreed-upon risk response plans, tracking identified risks,
identifying and analysing new risks, and evaluating risk process effectiveness throughout the project. The key benefit of this
process is that it enables project decisions to be based on current information about overall project risk exposure and individual
project risks
How to Monitor the Performance of the Risk Management Process?
This Includes, but is Not Limited to, the Following:
• Performance monitoring: Monitoring the performance of the organisation, including financial results, operational metrics,
and key performance indicators, can help identify any potential risks that may affect the organization's objectives.
• Internal audits: Conducting internal audits can help identify potential risks, evaluate the effectiveness of risk management
processes and procedures, and identify areas for improvement.
• External assessments: Engaging external auditors or risk management consultants can provide an independent
assessment of the organisation's risk management processes and identify areas for improvement.
• Meetings: meetings that can be used during this process include but are not limited to risk reviews. Risk reviews are
scheduled regularly and should examine and document the effectiveness of risk responses in dealing with overall project
risk and with identified individual project risks.
Case Studies 24
Cost overrun = Risks, which lead to the question: What are the key reasons for cost overruns?__ Class discussion
25
Group work:
Use the PI risk matrix to determine the level of significance for the risks listed in Table X:
Table X . IT risks during COVID-19 pandemic
26
References:
1. International Standards Organisation (ISO), (2018) “ISO/IEC New Work Item Proposal: General
Guidelines for Principles and Implementation of Risk Management”. London, UK.
2. Project Management Institute (PMI), (2021)“Project management body of knowledge (pmbok® guide)”.
USA.
3. Institute of Risk Management (IRM), (2002) “A Risk Management Standard”. London, UK.
4. Kassem, M.A., Khoiry, M.A. and Hamzah, N. 2019. Using probability impact matrix (PIM) in analyzing risk
factors affecting the success of oil and gas construction projects in Yemen. International Journal of
Energy Sector Management, Vol. 14 No. 3, pp. 527-546