0% found this document useful (0 votes)
3 views76 pages

Topic Three - Risk Management Process

The document outlines the risk management process, emphasizing its integration into organizational decision-making and operations. It details steps such as communication and consultation, defining the scope and context, risk assessment, and analysis, including qualitative and quantitative methods. The document also provides tools for risk identification and evaluation, along with examples of risk rating scales and methodologies for calculating expected monetary value.

Uploaded by

yohanaagrey10
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views76 pages

Topic Three - Risk Management Process

The document outlines the risk management process, emphasizing its integration into organizational decision-making and operations. It details steps such as communication and consultation, defining the scope and context, risk assessment, and analysis, including qualitative and quantitative methods. The document also provides tools for risk identification and evaluation, along with examples of risk rating scales and methodologies for calculating expected monetary value.

Uploaded by

yohanaagrey10
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Topic Three: Risk Management Process

Overview
Risk management process: the steps to carry out risk management.

The risk management process should be an integral part of management


decision-making and integrated into the organization's structure,
operations, and processes.

The risk management process can be applied at various levels and must
be tailored to achieve objectives and adapt to the internal and external
context.

The risk management process should take into account the diverse and
evolving nature of human behavior and culture.
ISO 31000:2018 Risk Management Processes
Communication and Consultation
Communication and Consultation
This is the first step in risk management but should be carried out during
the whole risk management process.
Communication seeks to promote awareness and understanding of risk.
Consultation aims at obtaining feedback and information to support
decision-making.
Communication and consultation aims at;
Assisting relevant stakeholders in understanding risk
Learning from stakeholders
Influencing the targeted audience
Achieving an attitudinal or behavioural shift about risk
Obtaining a better understanding of the context, the risk criteria, or the
effect of risk treatments.
Communication and Consultation..
 Depending on the type of the organisation, the main types of stakeholders
may include:
Risk owners (directors, heads of departments and units)
Risk champions
Key staff from across the organisation
 External stakeholders (especially from entities linked to the activities of
the organisation).

It should be decided in advance how to Reliably, accurately, and


transparently communicate risk assessment results to external stakeholders.
Define the Scope, Context, and Criteria of Risk
Assessment
Scope, Context and Criteria
 The purpose of establishing the scope, context, and criteria is to customize the
risk management process, enabling effective risk assessment and appropriate risk
treatment.

 The scope of risk management activities can be at strategic level, operational


level, program level, project level, or other activities.
It should be clear, relevant to objectives, and aligned with organisation objectives.

 The context of the risk management process involves understanding both the
external and internal environment of the organisation.
The context should also consider the specific environment of the activity to which the
risk management process will be applied.
Scope, Context, and Criteria..
 Sources of information for defining the scope and context of risk assessment
include;
 Interviews/discussions with members of the organisation management,
Review of documents, including the organisation strategic plan, budget, directives,
internal and external auditor’s report, and the respective institutional legal framework.
 This process will result into;
Brief background of the organisation e.g. mission, vision, core values, core functions,
and legal framework.
List of strategic objectives and their specific key performance indicators
A list of key stakeholders to be involved in risk management
Definition of risk categories or main sources of risks
Scope, Context, and Criteria..
 Risk criteria are rules to enable consistent decision-making on risks, especially in
determining the scale to measuring the impact and likelihood of a risk.

 Assessment scales for impact and likelihood enable the rankings, prioritization,
and comparison of risk across the organisation and benchmark them to the risk
tolerance levels.

 An organisation may choose to use either a three-point scale or a five-point scale


band.
Scope, Context, and Criteria..
Illustrative 5-point Scale for Assessing the Impact of a Risk
Ratin Descriptor/ Definition
g Colour
5 Extreme (Very • Significant financial loss (e.g. budget reduction by 20%)
High) • Event that involves significant management time
4 Major or High • High financial loss (e.g. budget reduction by 10%
• Event that involves relatively higher management time

3 Moderate • Moderate financial loss (e.g. budget reduction by 5%)

2 Minor (Low) • Minor financial loss (e.g. budget reduction below 5%)
• An event that involves little management time

1 Very Low • No impact


• Insignificant Financial Loss
Scope, Context, and Criteria..
Illustrative 5-point Scale for Assessing the Probability of Risk
Rating Descriptor/ Colour Frequency
5 Very high/ Almost • The adverse event will definitely occur, probably multiple
certain times in a year, (more than 90%)
4 High/ Likely • There is a strong likelihood that the event will occur at least
once in the next 6-12 months given the history of the event
(66% up to 90%)
3 Moderate/ • 50/50 chance of the event occurring within the next year. (36%
Possible up to 65%)
2 Low/ Unlikely • Event not likely to occur in next 12 months, but there is a slight
possibility of occurrence (10% up to 35%)

1 Rare/ Very Low • Highly unlikely to occur in the next 5 years (below 10%)
Scope, Context, and Criteria..
Set Risk Tolerance /Threshold Levels
 In setting risk tolerance/threshold levels, organisation can use either one of both of the
following:
 Risk rate obtained by multiplying impact and likelihood of the risk, or
Risk appetite for a given risk category
Risk status/rate (I*L) Meaning and Responses

15-25 • This is a very serious concern, the highest priority.


• Take immediate action and review regularly.
10-14 • Serious concern; higher priority.
• Take immediate action and review at least three times a year.

5-9 • Moderate concern; steady improvement needed.


• Possibly review biannually
1-4 • Low concern; occasional monitoring.
• Tolerate/ Accept. Continue with existing measures and review annually.
Risk Assessment
Risk Assessment
 Risk assessment involves three stages namely:
Risk identification,
Risk analysis, and
Risk evaluation.

 Risk assessment should be aligned with the organisation planning process


(budgeting, annual action plan, etc.)

 This is to provide an opportunity for risk mitigations to be accommodated in


the Annual Action Plan and Budget
Risk Identification
 The purpose of risk identification is to find, recognize, and describe risks
that might help or prevent an organization from achieving its objectives.

 It is an iterative process, involving the project team, management team,


stakeholders, and subject matter experts.

 Risk identification involves acknowledging that there are always


unknowable or unidentifiable risks, regardless of the identification
technique used.
Risk Identification - Tools and Techniques
 The organisation can use a range of techniques for identifying uncertainties that
may affect one or more objectives

 Numerous tools and techniques to identify risks exist which fall into the following
three categories;
Historical Review e.g. Use of a standard risk checklist.
Current Assessments e.g. Analysis of assumptions and constraints.
Creativity techniques e.g. Structured brainstorming.

 The use of these techniques in combination with one another yields better results
than their isolated usage.
Risk Identification - Tools and Techniques..
 The use of these techniques in combination with one another yields
better results than their isolated usage.
Past Focused Techniques Present Focused Techniques Future Focused Techniques

 Document Review  Assumptions/ constraints  Team based-


 Checklist Analysis brainstorming
 Analyzing historical  SWOT Analysis  Interviews
records,  Root cause Analysis  Delphi Technique
 Analysis of assumptions and  Structured questionnaires
constraints
 A prompt list (PESTLE,
PESTLIED, STEEPLE, TECOP,
SPECTRUM)
Working exercise – Risk identification
 XYZ company plans the construction of one multiple floor Eco-friendly modern
academic block with the following activities;
i. Procure consultant to design and supervise the construction and furnishing works for
one multiple floor Eco-friendly modern academic block building comprising of: (i) 2
lecture theatres each with 400 students capacity; 3 studio rooms each with 200
students capacity, 1 computer lab with 200 students capacity, 1 seminar room with
100 people capacity, 1 classroom with 80 student capacity and staff offices with 76
staff capacity
ii. Procure Contractor to carry out construction of one multiple floor Eco-friendly
academic block building comprising of: (i) 2 lecture theatres each with 400 students
capacity; 3 studio rooms each with 200 students capacity, 1 computer lab with 200
students capacity, 1 seminar room with 100 people capacity, 1 classroom with 80
student capacity and staff offices with 76 staff capacity
 Required: As a risk specialist, help XYZ company to identify the potential risks likely to
face the above activities.
Working exercise – Risk identification
 Read the following case study and answer the question below;
 HAPA KAZI TU company plans a one-year bridge construction project, relying on a 30+
year-old geotechnical report. Before the project implementation started, HAPA KAZI
TU company decided to hire a risk specialist consultant to advise them on the
proposed project. A risk consultant warned that due to poor scope planning, a lack of
communication plan, a lack of team member selection criteria, poor activity duration
estimate techniques, and a lack of procurement plan, there is a possibility the
proposed project will face scope creep, time overrun, delayed procurement process,
cost overrun, labour disputes, and resistance from project stakeholder. The consultant
concluded these issues could lead to stakeholder dissatisfaction with the project
deliverables.
 Required: Identify potential risks from the above case study
Risk Analysis
Risk Analysis

Risk analysis: Systematic process applied to understand the effect of


the risk on objectives.

 Inherent risk: The level of risk exists before considering the


effectiveness of current controls.

 Residual risk: The level of risk remains after considering the


effectiveness of current controls.
Risk Analysis
 Risk analysis provides inputs to decisions on whether risks need to be
treated or not and the most appropriate and cost-effective risk treatment
strategies.
 The following key consideration must be taken when analysing risks:
Categorizing the identified risks
Determining the causes and consequences of the risks
Rating the impact and likelihood of the inherent risk
Documenting existing mitigation/controls and their effectiveness
Rating the impact and likelihood of the residual risk.
Proposing treatment actions
Proposing resources for implementation of treatment actions
Risk Analysis

 Risk analysis can be done in the form of;


Qualitative analysis
Quantitative analysis

 The analysis step produces a risk register


Qualitative Risk Analysis
 Qualitative risk analysis: assesses the risk events concerning the
impact/consequence on the project objectives and the probability/likelihood of
occurrence.

 Qualitative risk analysis is subjective in nature, based on judgment, intuition, and


experience, and lacks hard numbers to justify return on investment.

 Generally, the purpose of the qualitative analysis step is to:


Ranks the seriousness of the risks
Identify low-priority risks
Assign appropriate Risk Owners to all risks
Tools for Qualitative Analysis
 Qualitative risk analysis is performed by using the following tools
Top Ten Risk Item Tracking
Probability and Impact Matrix
Probability and Impact Matrix
A Probability and Impact Matrix: lists the relative probability of a risk
occurring on one side of a matrix on a chart and the relative impact of the
risk occurring on the other.

Risk probability and impact are applied to specific risk events and may be
described in qualitative terms, such as very high, high, moderate, low, and
very low.

Risk probability and impact also, can be expressed in numbers from 0 to 1


or 1 to 5 depending on the organisation’s needs.
Probability and Impact Matrix..
Probability and impact matrix presents the results of risk analysis by using
color in priority zones.

These zones are often colored following a traffic-light convention, with


Red zone: used for high-priority risks to be treated urgently if the
project objectives are to be met.
Yellow zone: used for medium-priority risks to be monitored
Green zone: used for low-priority risks to be accepted

For the best opportunities (where high probability means easy to capture,
and high impact means very good).
Probability and Impact Matrix..
 Recently, a double ‘mirror’ matrix format has been used to plot threats
and opportunities together, creating a central zone of focus.

The score from the qualitative risk analysis should be compared with the
risk threshold level constructed in the defining scope, context, and criteria
step to determine the risk’s severity.

Example of risk threshold level


1-4: Acceptable/tolerable level
5-9: Medium/ moderate level
10-14: High level
15- 25: Extreme/ Unacceptable level
Probability and Impact Matrix..

 Example of a Double Probability-Impact Matrix


Probability and Impact Matrix..
 Example of a Probability-Impact Matrix (Risk Heat Map)
Risk score for a specific risk
5
4
Probability

3
2
1 A
1 2 3 4 5
Impact/consequence

 Scale:
Low Risk Medium Risk High Risk
Risk Evaluation

 Risk evaluation involves comparing the residual risk’s overall rate (i.e.,
impact x likelihood) against organisations established risk tolerance
criteria

 The purpose of comparing the residual risk rate to the risk tolerance
criteria is to determine if additional action is necessary to reduce the
significance of the risk.

 The results of the risk assessment process must be well documented in


the Risk Assessment Sheet (See Template in the next slide).
Quantitative Risk Analysis
 Quantitative risk analysis: This is the approach used for modeling the overall
effect of risk on the project objectives such as cost and schedule objectives.

 Quantitative risk analysis is used in bigger projects, such as those that are
inherently risky because they are of high cost or long duration, or are innovative
or strategically important and pose a higher level of risk challenge.

 These projects demand a deeper understanding of risk and therefore more


rigorous analysis.
 To conduct a quantitative risk analysis, you will need high-quality data and
prioritized lists of project risks (usually from performing a qualitative risk
analysis)
Quantitative Risk Analysis: Tools & Techniques
 Quantitative Risk Analysis tools and techniques include but are not limited to:
Decision Tree Analysis: a diagram that shows the implications of choosing
one or other alternatives

Expected Monetary Value (EMV): a method used to establish the contingency


reserves for a project budget and schedule

Sensitivity Analysis: a technique to determine the impact of change in one of


the variables (investment cost, revenue, variable costs) on the project’s net
present value.

Monte Carlo simulation: a technique used to determine the impact of risk and
uncertainty in financial project management and other forecasting models.
1. Expected Monetary Value (EMV)
 Expected Monetary Value: a statistical technique in risk management used to
quantify risks and calculate the contingency budget.

 It calculates the average outcome of all future events that may or may not
happen.

 Expected Monetary Value (EMV) = Probability * Impact

 If you have multiple risks, you will add the EMVs of all risks. This will be the
expected monetary value of the identified risks in the project.
1. Expected Monetary Value (EMV)..
 EMV Example: Let’s say you have four risks with probabilities and impacts as
follows:

Risks Probability Impact (Tzs)


1 10% -400000
2 10% -100000
3 30% 200000
4 50% -150,000
 Required: calculate the Expected Monetary Value for the above-identified risks
1. Expected Monetary Value (EMV)..
 Solution: EMV = Probability x Impact

Risks Probability Impact (Tzs) EMV (P*I)


1 10% -400000 -40000
2 10% -100000 -10000
3 30% 200000 60000
4 50% -150,000 -75,000
Total -65,000

 From the above table, The expected monetary value (EMV) of the risk events is
-65,000 Tzs (Which means that you will incur 65,000 Tsh to manage all identified
risks in the above case).
1. Expected Monetary Value (EMV)..
 Example 2: You have identified a risk with a 30% chance of occurring. If this risk
occurs, it may cost you 500,000 Tsh. Calculate the expected monetary value (EMV)
for this risk event.

 Solution: Given in the question:


The probability of risk = 30%
Impact of risk = – 500,000 Tsh
We know that: Expected monetary value (EMV) = Probability * Impact
EMV = 0.3 * – 500,000 = -150,000 Tsh

The expected monetary value (EMV) of the risk event is -150,000 Tsh (Means that
you will incur 150,000 Tsh to manage the risk if it occurs)
1. Expected Monetary Value (EMV)..
 Review Questions
1. You have identified an opportunity with a 50% chance of happening.
However, it may help you gain 1,500,000 Tsh if this risk occurs. Calculate the
expected monetary value (EMV) for this risk event.
2. You have identified two risks with a 40% and a 60% chance of occurring. They
will cost you 800,000 Tsh and 700,000 Tsh respectively if both risks happen.
What is the expected monetary value of these risk events?
3. During risk management planning, your team has identified four risks with
probabilities of 5%,10%, 50%, and 35%. If the first two risks occur, they will cost
you 3,000,000 Tsh and 5,000,000 Tsh respectively; however, the third and
fourth risks will give you 1,000,000 Tsh and 3,000,000 Tsh respectively if they
occur. Determine the expected monetary value of these risk events.
2. Decision Tree Analysis (DTA)
 A decision tree: a diagramming analysis technique used to help select the best
course of action in situations in which future outcomes are uncertain.
 Decision tree analysis (DTA) uses EMV analysis internally.

 A decision tree, as the name suggests, is about making decisions when you’re
facing multiple options.

 The decision tree diagram incorporates the cost of each choice and the
probabilities and impacts of each possible scenario.

 It is usually drawn chronologically from left to right and branches out, like a tree
lying on its side.
2. Decision Tree Analysis (DTA)..
 The decision tree diagram consists of three types of nodes:

Node type Indicated in diagram by Represents

Decision Squares Variables/actions that decision maker


controls

Chance Event Circles Variables/events that decision maker


cannot control

Terminal/End Reverse triangle Endpoints where outcome values are


attached
2. Decision Tree Analysis (DTA)..
 Example of a decision tree diagram
2. Decision Tree Analysis (DTA)..
Steps to Use Decision Tree Analysis
1. Construct a decision in a decision tree ( move from left to right).
2. Assign a probability of occurrence for the risk pertaining to that
decision.
3. Assign monetary value of the impact of the risk when it occurs.
4. Compute the Expected Monetary Value for each decision path
5. Then add the setup costs (initial costs) to each Expected Monetary
Value

The best decision is the option that gives the highest positive value or
lowest negative value, depending on the scenario.
2. Decision Tree Analysis (DTA)..
 Example: Assume you have two sub-contractors to supply materials for your
project as follows;
Mangi investment has submitted a bid with the initial cost of Tsh 4,800,000.
During risk analysis it was discovered that, there is a 50% possibility that Mangi
investment will deliver materials late by 60 days and our contract with the
main client specifies that we must pay a delay penalty of Tsh10,000 per day.

Sanga investment also submitted a bid with the initial cost of Tsh 5,000,000.
During risk analysis it was discovered that, there is a 10% possibility that Sanga
investment will deliver materials late by 20 days and our contract with the
main client specifies that we must pay a delay penalty of Tsh10,000 per day.

 Based on the Decision tree analysis which contractor will be the best option for
your project?
2. Decision Tree Analysis (DTA)..
 Solution: For the Mangi investment alternative
 Delay 60 days times
Cost for delay 10,000 per day
Total cost for delay (impact) 60 x 10,000 = 600,000
Probability for delay 50%
EMV for Mangi investment = Impacts x Probability
EMV for lower bidder = 50% x 600,000 = 300,000
Expected Cost for Mangi investment will be = Initial cost + EMV for lower
bidder
Expected Cost = 4,800,000+300,000 = 5,100,000
 Expected Cost of this option =5,100,000 Tsh
2. Decision Tree Analysis (DTA)..
 Solution: For the Sanga investment alternative
 Delay 20 days times
Cost for delay 10,000 per day
Total cost for delay (Impact) 20 x 10,000 = 200,000
Probability for delay 10%
EMV for Sanga investment = Impacts x Probability
EMV for reliable high bidder = 10% x 200,000 = 20,000
Expected Cost for Sanga investment will be = Initial cost + EMV for lower
bidder
Expected Cost = 5,000,000+20,000 = 5,020,000 Tsh
 Expected Cost of this option = 5,020,000
2. Decision Tree Analysis (DTA)..
In the Contractor Decision case there is only one decision node, the
original one.

The alternatives are:


Mangi investment at -5,100,000 Tsh
Sanga investment at -5,020,000 Tsh

Basing on decision tree analysis, Sanga investment is the best option to


supply materials for the project because of its low total costs.
2. Decision Tree Analysis (DTA)..
Review Question
Assume you have two sub-contractor to supply materials for your project
as follows
 One sub-contractor is lower-cost bid $110,000. We estimate however
that there is a 50% chance that this contractor will be 90 days late and
our contract with the main client specifies that we must pay a delay
penalty of $1,000 per calendar day for every day we deliver late.
 The higher-cost sub-contractor bids $140,000. We know this contractor
and assess that it poses a low 10% chance of being late, and only 30 days
late at that. Of course, our customer will impose on us the same $1,000
delay penalty per day for late delivery.
 Based on the Decision tree analysis which contractor will be best option
for your project?
Risk register
 The output from the risk analysis process is a risk register document

 Risk register/Risk Log: a comprehensive record of risks across an organisation,


business unit, or project.

 A risk register is prepared by summarizing all risks from the Risk Assessment
Sheet into a single spreadsheet

 In the risk register only ratings for residual risk are used and risks may be arranged
by objectives or departmental-wise.

 The Risk Register should be regularly reviewed (during project team meetings) to
monitor progress.
Components of the risk register -matrix
 The components of the risk register differ from one organisation to another
depending on the purpose/context of the register.

 This example includes necessary information that needs to be captured


Objectives/ targets: likely to be affected by the risk

 Risk ID: a unique identifier for the risk (usually include objective number and
risk number)

Risk title: the risk itself

Risk description: statement of the risk


Components of the risk register-matrix..
Residual risk analysis: that includes
Likelihood: How likely is that the risk will occur? Can be 1- 5 or High / Medium /
Low

Impact: What will the impact be if the risk occurs? Can be 1- 5 or High /
Medium / Low

Severity/rating: Likelihood * Impact


Risk status: Obtained by comparing the risk rating against the organisation
risk thresholds

Owner: The person who will be responsible for managing the risk.

Risk category: under which category the identified risk falls. E.g. financial,
environmental, technical, etc.
Risk Register-matrix
No OBJECTIVE RISK TITLE RISK DESCRIPTION RISK ID CATEGORY OF RESIDUAL RISK ANALYSIS PRINCIPAL RISK
RISK OWNER
IMPACT LIKELIHOOD RISK RATING RISK STATUS

1To strengthen the learning Delayed Possibility of delaying A1-IRDP-R01 Operational 5 2 10 HIGH Project
environment and labor procurement procurement of Coordinator
market alignment of of contractor contractor due to
priority programs at prolonged procurement
beneficiary higher procedures resulting to
education institutions and delay in commencement
improve the management of the building
of the higher education construction
system.

2To strengthen the learningDelays in Possibility of delays in A7-IRDP-R01 Operational 3 3 9 MODERAT Project
environment and labortimely timely completion of PhD E Coordinator
market alignment ofcompletion of studies due to untimely
priority programs atPhD studies supervision resulting to
beneficiary higher shortage of manpower
education institutions and
improve the management
of the higher education
system.
Contents of the risk register document
Chapter 1: Introduction
Background information of the organisation (vision, mission, core functions,
strategic objectives etc.)
Legal issues pertaining to risk management
Purpose of the risk register
Scope of risk management
Intended Audience/user of the Risk Register
Structure of the risk register document

Chapter 2: Risk Assessment Methodology


Risk identification: Tools and techniques used in identifying the risks
Risk analysis: Criteria used for analyzing the probability and impact (scales and
their meaning)
Risk evaluation: criteria used for ranking the overall severity of risks (Threshold
Level and Risk Heat Map)
Contents of the risk register document
Chapter 3: Risk Register matrix
Summary of identified and analysed risks showing;
Objective/target
Activity likely to be affected by risk
 Risk title
Risk description/statement
Risk ID, Risk category
Residual risk analysis: [impact scale, probability scale, rating/severity, and status]
Risk owner
Chapter 4: Annexes
Detailed Risk Assessment Sheets per each risk
Risk Treatment
Risk Treatment
 Risk treatment: involves examining possible treatment options to determine the
most appropriate action for managing a risk.

 The purpose of risk treatment is to select and implement options for addressing risk.

 An organisation should select, design, and implement the most appropriate risk
treatment options that support the achievement of intended outcomes and manage
risks to an acceptable level.

 Treatment actions are required where the current controls are not managing the risk
within defined tolerance levels.

 Treatment options could involve improving existing controls and implementing


additional controls.
Risk Treatment..
 When choosing a response strategy for an individual risk, the factors used to
prioritize risks should be considered so that the level of response matches the
importance of the risk.

 For example, (avoid/exploit) strategies should be applied to the highest priority


risks and only the lowest priority risks should be accepted.

 Risk prioritization factors for response selection includes;


Manageability and Propinquity of the risk
Availability of resources to address the risk (resourcing)
Likely cost of addressing the risk compared to its possible impact (cost-
effectiveness)
Degree to which the probability and/or impact might be modified (risk-
effectiveness)
Whether the response will introduce additional risks (secondary risks).
Risk treatment Strategies
 Selection of the best response from several options is often required. The strategy
(or mix of strategies) most likely to be effective should be selected for each risk
event.
 Several risk treatment strategies are available which fall into two categories;
1. Strategies for negative risks (Threats)
 Terminate/ Avoidance
 Transference
 Treat /Reduction
 Tolerate /Accept
2. Strategies for positive risks (Opportunities)
 Share
 Enhance
Risk treatment Strategies for threats (Negative risks)
1. Terminate
 Risk termination involves changing the project plan to eliminate the risk or condition

 Termination aims to eliminate the risk to the project, making the threat impossible
or irrelevant.

 The termination strategy may lead to project cancellation if the overall level of risk
remains unacceptable.

 It’s the most effective way of dealing with risk.


Risk treatment Strategies for threats (Negative risks)
2. Transference
 Risk transference requires shifting the negative impact of a threat, along with the
ownership of the response, to a third party.

 Transferring the risk does not eliminate the risk, but the new owner should be able
to take action to avoid or reduce it.

 Risk transference nearly always involves payment of a risk premium to the party
taking on the risk.

 Examples of risk transference;


Using a fixed-price contract
Purchasing insurance
Risk treatment Strategies for threats (Negative risks)
3. Treat
 This involves reducing the probability or impact of a potential threat to an acceptable
threshold.
 Taking proactive measures to mitigate the likelihood or impact of a potential risk is
often more effective than trying to repair the damage after the risk has occurred.
 Examples of risk reduction;
 Adding resources or time.
 Avoiding an unfamiliar subcontractor.
 Clarifying requirements.
 Improving communication
 Choosing a stable supplier
Risk treatment Strategies for threats (Negative risks)
4. Tolerate
 This strategy acknowledges the existence of a threat but no proactive action is
taken.
 It may be appropriate for low-priority threats, and it may also be adopted
where it is not possible or cost-effective to address a threat in any other way.
 Acceptance can be either active or passive.
Passive acceptance: requires no action except to document the risk and
review periodically to ensure that it does not change significantly
(especially those with low severity/rating).
Active acceptance: the project team may establish a contingency reserve,
including amounts of time, money, or resources to handle the threat if it
occurs.
Risk treatment Strategies for Opportunities (Positive risks)
1. Share
Sharing a positive risk involves allocating ownership to a third party who
can best capture the opportunity for the project.

Example of a share risk strategy is;


Forming partnerships
Joint ventures
Rewards etc.
Risk treatment Strategies for Opportunities (Positive risks)..
2. Enhance
 A risk response strategy aimed at increasing the probability of a positive risk
occurrence.

 This is done by identifying and maximizing key drivers of these positive risk events.

 Assume you are constructing a building, and suddenly the client tells you that he will
give you a monetary reward if you complete the project two months earlier than
scheduled.

 So to meet the opportunity (monetary reward promised) you may;


Adding more resources to finish early.
Motivating the team members
Working overtime
Risk Treatment..
 The output from the risk treatment process is a risk management
plan/matrix.
Risk Risk Category Risk title Risk description Proposed Key control timeline Responsib Status of
ID treatment indicator le person implementat
ion
(Completed,
ongoing, not
done)

AR01 Financial risk Delayed The possibility of Diversificatio Presence of a Continuous Country Ongoing
processing of delayed payment n to mobilize diversification director
payment due to high funds from strategy plan
dependence on private
donors as the sector,
main stream of research
funding resulting agency,
in inefficiency individuals,
operation and
government.
QUIZ

 In your group of 10 people, use any existing project to analyze the


potential risks and develop a risk management matrix.

 Deadline: 9/1/2025 at 09:10 Am


Record and Report Risks
Record and Report Risk
Risk reporting: the process of communicating the results of the risk
management process to the people who need to know

The purpose of the risk reporting step is to:


Document and communicate key results and conclusions from the
risk process

Inform project stakeholders of the current risk status of the risk

Ensure that each project stakeholder has the information required


to fulfill his or her role in managing risk on the project.
Contents for a risk report
Introduction
Organisational background
Risk Management Background, Frameworks, and standards used
Purpose of the Report
Scope of the Report

Review of Risk Management Annual Plan


Planned Activities/treatment for the Period
Contents for a risk report..
 Top Risks and Their Status
 Risk Heat Map
 Risk Register
 Status of Implementation of Mitigation Plan (for the previous quarter):
 Planned mitigation
 Implemented
 On-going Implementation
 Not Implemented
 Challenges and Way Forward
 Conclusion

 Appendices: Supporting information is presented in appendices. Appendices may


include a risk assessment sheet, complete risk register, Risk Management Report
Sheet etc.
RISK MANAGEMENT REPORT SHEET
Risk ID Risk Title Risk Rating Proposed Treatment/Control Time frame Officer/ Person Key Control Status of Remarks/C
(Residual risk Options to be taken[Risk Responsible [For Indicator implemen omments
rating) treatment Implementation Plan Implementation (KCI)[from Risk tation
] Start End of Treatment treatment
Options] Implementation
Plan]
Risk Monitoring and Review
Risk Monitoring and Review
Risk Monitoring: defined as an ongoing process focused on providing
real-time analysis of the implementation of the risk management
process against planned activities and mitigations.

The aim is to provide a continuous flow of information, thereby


enabling positive decision-making about the risk management process.

The main focus of risk monitoring should be on Key Risk Indicators


(KRI) and Key Control Indicators (KCI).
KRI: Tracks the progress of the root causes of the risk
KCI: Tracks the progress of the proposed controls/treatment actions
Risk Monitoring and Review..
Risk monitoring involves the preparation of a Risk Management
Performance Monitoring Plan

The Risk Management Performance Monitoring Plan is a tool for


organizing, planning, and implementing monitoring activities.

The Risk Management Performance Monitoring Plan outlines the


necessary steps for monitoring activities related to priority risks.

Risk management performance monitoring plan includes the


following;
Risk Monitoring and Review..
 Risk Review: a periodic assessment of the overall effectiveness of the risk
management framework.
 The Focus is on the outcome, impact, and/ or maturity of the overall or part of the
risk management framework in the organisation.
 Risk review involves;
Decide the Interval for the Review
Decide and Appoint the Reviewer
Provide Written ToR to the Reviewer
Develop Review Questions
Select Indicators for Evaluation.
Design and Implement Methods to Collect Data on Indicators
Risk Management Performance Monitoring Plan
Risk ID Risk Title Proposed Performance Time frame for Data Source of Data Data
Treatment/Control Indicator (Key Control Implementation Collection Information collection Collection
Options Indicator) Methods/Tool Frequency Responsibili
s ty

Start End

You might also like