0% found this document useful (0 votes)
3 views40 pages

Strategic Project Risk Management

Uploaded by

davidsdavid900
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views40 pages

Strategic Project Risk Management

Uploaded by

davidsdavid900
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Strategic Project Risk Management

Evolution of Project Risk Management


Lead projects to success with strategic risk management
If you are not thinking about project risks, you have virtually a zero
chance of finishing your projects on time and on budget. If you
implement the practices of risk management, your project success rate
is guaranteed to soar, leading to program and portfolio success, and
ultimately, organizational success.

/*

Project Portfolio and Programs


A portfolio in project management is a high-level collection of
programs, projects, sub-portfolios, and operations managed together to
achieve strategic business goals.

Core Purpose

 Strategic Alignment: Ensures every project supports the company's


long-term vision.
 Resource Optimization: Allocates money, people, and time to the
highest-priority initiatives.
 Risk Management: Balances high-risk, high-reward projects with
stable, low-risk ones.
 Value Maximization: Focuses on doing the right work, rather than
just doing work right.

The Project Management Hierarchy

 Portfolio (The Blueprint): Asks "Should we do this project?" to


meet business goals.
 Program (The Cluster): It groups related projects together to get
benefits you couldn't get by managing them alone.
 Project (The Task): Asks "How do we build this?" focusing on
specific deadlines and deliverables.
Key Roles

 Portfolio Manager: Governs the selection, prioritization, and


funding of all initiatives.
 Project Manager: Executes a specific project within the
constraints of scope, time, and budget.

Real-World Example: Tech Company

 The Portfolio: All corporate investments for 2026.


 Program A (Cloud Migration): Multiple projects moving data
infrastructure.
 Program B (Mobile App Refresh): Multiple projects updating the
iOS and Android apps.
 Stand-alone Project: A quick security audit required by law.

*\

How project risk management has evolved


Do you know where your organization is on the maturity spectrum of
project risk management? It's like knowing the depth of water before
diving in. It helps you gauge your readiness to handle project
uncertainties, and act accordingly. Let’s introduce the spectrum
marked by four levels of project risk management, or PRM. We may
identify these maturity levels based on the evolution of project risk
management we may have observed over several years.

First, let's start with the era of PRM 0.0. The early days. Going back
to the late 70s and 80s, project risk management was almost never
heard of unless you worked for NASA or some large government funded
difference project. Then came the 90s, a time for PRM 1.0. The
tactical approach. During this period, technology grew more complex,
and projects expanded to a global scale. This increased the risk of
project delays, and the cost of overruns, leading to potential project
failures. So we took a tactical approach, and focused on what we call
event risks. These are risks caused to by specific events. For
example, if a project involves outdoor construction on the Texas Gulf
Coast, hurricanes are an event risk potentially causing a time delay,
and cost overrun.

The most common tool of PRM 1.0 is a risk register. It's simply a
spreadsheet documenting a list of risk events, their magnitude and
ranking, and an action plan to treat them. Enter the 2000s and enter
PRM 2.0. Here we are getting more quantitative. It's like predicting a
storm's path, and then preparing accordingly. We're talking about
quantifying the likelihood, and impact of risks that we have
identified. For example, in the case of a hurricane, we may estimate
the probability of it happening to be 70%, and the impact to be a two
weeks project delay with an additional cost of $20,000. Furthermore,
we may use sophisticated tools like Monte Carlo simulation where we
take a probabilistic approach by talking about ranges and
probabilities of our estimates rather than just a single values.

As we near completion of the first quarter of the millennium, we have


entered the era of PRM 3.0. The strategic era. This era is
characterized by VUCA. Volatility, uncertainty, complexity, and
ambiguity. In the VUCA world, it's not just about managing risks at
the individual project level. It's about a holistic strategic approach
of managing them as part of programs and portfolios. In this era, we
consider other types of risks as well. Not only the event risks, but
also variability risk, ambiguity risk, and emergent risk. Also, as we
become more strategic in addition to threats, we consider positive
risks or opportunities, events with a positive impact on our projects.

The strategic era is also marked by application of adaptive and hybrid


methods to reduce risks on our projects, right methods for right
projects. Finally, the use of artificial intelligence tools in the
project risk management is inevitably here. So we care about the
maturity spectrum in the project risk management because we want to be
able to think about where the organization is on the evolutionary
scale, so we can advance to the next level, and that next level will
help us achieve greater project success.

 What’s meant by the project risk management maturity spectrum?


 What’s PRM 0.0?

How project, program, and portfolio risks differ


In the realm of strategic risk management, think of project, program,
and portfolio management as a game of chess. While a project risk may
seem like losing a pawn, unchecked, it can escalate to losing a queen
and that is equivalent to failure of a program or even a checkmate
which represents a disruption of your business strategy through a
collapse of a portfolio. If a software project hits a snag, say coding
errors, the ripple effect can be significant. This setback can thwart
the broader goal of digital transformation, denting the organization's
market competitiveness, a single project risk escalating to affect the
entire portfolio. Before managing such a cascade of risks, we must
first understand what kinds of risks do we face at each entity?

You may broadly classify risks as strategic and tactical. Strategic


risks affect long-term goals and strategy of the organization. They're
related to selecting and prioritizing the right projects and
allocating the right resources across the portfolio. A unique feature
of strategic risks is that while they may pose thrust to your project,
they may create great opportunities at the same time. A simple example
is entering into new markets. Strategic risks are typically driven by
external changes, therefore they demand a higher level of perspective
and are managed at the portfolio and the program levels under the
direction of senior managers and executives.

Tactical risks, on the other hand, are related to day-to-day project


operations. These are specific to the project's deliverables,
schedule, budget, quality, and the performance, and are managed at the
project level. Let's look at some examples. Portfolio risks involve
the balance and the mix of the portfolio with the right projects to
optimize return and spread risk. For example, a portfolio of energy
projects including renewable and non-renewable sources may face risks
from changes in global oil prices or shifts in government policy on
green energy incentives. Other examples include shifts in market
trends affecting the business case for the entire portfolio or a major
economic downturn impacting funding and the prioritization of all
initiatives.

Program risks are concerned with the interdependencies between


projects and may impact multiple projects within a program
simultaneously. Risks at this level could impact the strategic
objectives that the program aims to achieve. For instance, a program
aimed at implementing new banking software across multiple branches
may encounter risks if a regulatory change requires additional
compliance features after the program has started. Other examples
include a strategic supplier facing financial difficulties or a key
technological change impacting all projects within the program.

Project risks typically affect the project's so-called triple


constraint comprising of course, scope, schedule, and cost. For
example, a construction project might face a risk of delay due to
unexpected archeological findings at the building site which can lead
to halted work and the need for archeological assessments. Other
examples are vendors failing to deliver a critical component on time,
a key team member falling ill, or a technological tool not performing
as expected. Remember the essence of chess lies in protecting the king
which represents your overall business strategy. This protection is
achieved through the strategic placement and the movement of every
piece on the board, each representing a project in your portfolio.

 What’s the main difference b/n strategic and tactical risks?


 How can a small project risk impact the overall business
strategy?
A comprehensive strategy to manage project risks
Four types of project risks
Imagine you are managing a project from the United States with
critical equipment shipping to the Philippines. Everything seemed
planned perfectly. Yet, four weeks past and the equipment hasn't
arrived at the Manila site. The project is delayed because the
equipment got stuck at the customs in Manila. This incidence
highlights the unpredictability of event risks. According to the
Project Management Institute, risk is an uncertain event or condition
that if it occurs, has a positive or negative impact on a project's
objectives. This includes both threats and opportunities where threats
have negative and opportunities have positive impact.

The methodologies and tools we discuss here apply to managing both.


There are four types of risks we must consider on our projects, event,
variability, ambiguity, and emergent. First, let's start with event
risk. Event risk arises from specific uncertain events that may not
happen, but have the potential to impact the project significantly.
Some other common examples include natural disasters like the
hurricanes, rejection of necessary government permits or the
bankruptcy of a crucial supplier. An example of an opportunity could
be unexpectedly securing an additional funding grant, which might help
speed the project completion.

Second, variability risk. This risk is associated with the systemic


uncertainty in our projects schedule and cost estimates. It's not
related to any specific event. It's typically caused by unclear
definition of work scope, general fluctuations in resource
productivity, poor estimation methods, lack of estimation expertise,
and so on. For example, during a local community center renovation,
the estimated time for drywall installation was five days. But the
actual time could vary due to factors like unclear work scope or
fluctuations in resource productivity. This type of risk is virtually
guaranteed on every project.

Third, ambiguity risk. Ambiguity risk arises from the uncertainty


about how project objectives or scope will unfold, especially in
projects involving innovation. If you are developing a new drug, for
instance, you won't know how effective it'll be until it is tested
through clinical trials. Projects involving emerging technologies like
artificial intelligence or blockchain also face high ambiguity risk.

Finally, emergent risk. It comes from unforeseen events, often


referred to as unknown unknowns. They become apparent only after they
have occurred. Classic examples, the COVID-19 pandemic, the dot-com
crash, the 9/11 attacks, the 2008 global financial crisis and the 2011
Japanese tsunami. Event and the variability risks are typically
tactical and managed at the project level. In contrast, ambiguity and
emergent risks, which are more strategic, should ideally be managed at
the program or portfolio levels.

However, in organizations with the low risk management maturity, it's


common to see all types of risks managed at the project level, which
is not best practice. Understanding these four types. Check out the
handout in the exercises file for more details on these four risk
types.

 How does the project management institute define risk in a


project context?
 What’s event risk in project management?

Risk debt: The good, the bad, and the ugly


Debt, can't live with it, can't live without it. Anyone that has a
mortgage or credit card bill doesn't like paying it every month, but
without a mortgage or credit card, we can't afford the lifestyle we
are leading. In some sense, project risk is like debt. We may call it
the risk debt. You need to accept certain risks to make the project
viable. And if you take on too much of it, you may lose your shot at
the end. Just like financial debt, if you pay for the risks early on
to fix them, it costs you less. But instead, if you put it off, it'll
cost you more. The longer you put it off, the more it'll cost. Tricky
balancing act.

When is the right time to pay the risk debt? In the pre-project
initiation phase or the planning phase, the execution phase, or during
the post-project phase after the project is completed? That brings us
to the good, the bad, and the ugly story of risk debt. Starting with
the good. Steve Jobs, the co-founder and former chief executive of
Apple spent $50 million upfront to buy up the entire air cargo space
for the shipments of Macs in 1994 from China to the US. Why? Because
he wanted to avoid the common risks of delays related to sea shipping,
which was the standard industry practice at that time. During the peak
Christmas season of the product launch, while every computer
manufacturer faced the usual delays with sea shipping, Apple delighted
its customers with the fast deliveries, thanks to air shipping.

Now, the bad story of risk debt. Boeing, the aerospace company
outsourced virtually the entire development of their 787, the
Dreamliner, including the engineering and manufacturing functions,
despite their engineers' warnings of risks of cost overruns, schedule
delays, quality issues, and so forth. Unfortunately, many of the
predicted risks did materialize during the development of the plane.
It cost the company hundreds of millions of dollars to fix, let alone
the billions of dollars of loss of shareholder value and the lost
revenues.

What about the ugly story? In 2014, General Motors was hit with a
class action lawsuit resulting from the death of about 120 people.
They were killed in accidents related to a faulty ignition switch of
the vehicles they were driving. Ultimately, GM settled by paying $1.2
billion to the victims and the families, and then $900 million to the
United States government. Apparently, GM knew about their risks for 10
years, but didn't do anything about it. If they had fixed the problem
way back, it would have cost them a meager $5 per switch. So, here is
our 10X risk multiplier rule. The cost of treating your risk increases
by at least one order magnitude as you go from the initiation phase
into planning, execution, and production phases. The earlier you take
care of your risk, the less it's going to cost you, just like your
financial debt.

 What is meant by risk debt in project context?


 Why is project risk compared to financial debt?

A holistic strategic approach to managing risks


Does your organization have a systematic approach to managing risks or
do you use more of an ad hoc approach? If you are a small
organization, you are probably using the latter, but if you are a
large organization, presumably more mature in risk management, you are
likely to apply standard methodologies at the project level, but
what's lacking most often is a holistic, strategic approach to
integrate project, program, and portfolio risks. Whether you're a
small or large organization makes no difference. Here is a five-step
process that paves your path to not only project success, but also
program, portfolio, and ultimately organizational success.

Please, refer to the handout in the exercise files for a summary of


these five steps. Step one, develop a high level roadmap. It's a guide
that outlines how project, program, and portfolio risks should be
managed at each entity level in your organization. It provides the
risk management methodology, standards, processes, tools, and
techniques to be used by the project, program, and portfolio managers
in the organization. Note that this roadmap should be developed at the
organizational level by your enterprise or business unit PMO, that is
project management office. If it's not developed yet, work with
stakeholders to create it. If it already exists, work with management
to locate it and it is the responsibility of the project, program, and
portfolio managers to understand this roadmap and apply it following
the next four steps.

That brings us to step two, identify risks. In this step, each


project, program, or portfolio team, with the help of their managers,
will first identify relevant risk types, that is variability, event,
ambiguity, and emergent. And for event risk, you will identify and
document the risk events on a so-called risk register, a simple
spreadsheet, so each entity will have its own risk register. Next is
step three, prioritize the identified risks based on their magnitude.
For every event on the risk register, estimate its magnitude, which is
a function of its probability of occurrence and the impact, if it
occurs. They may be estimated either qualitatively or quantitatively.
Based on their magnitude, you will rank the identified risks.

Then step four, develop and implement risk treatment options. These
are action steps for each risk type which you will implement either
proactively or reactively. Again, these action steps need to be
identified separately for projects, programs, and portfolios. Keep in
mind, while the risk register is meant for event risk, you need to
document the details about the other risk types separately. And the
last step is five, evaluate and improve risk management practices.
Check how effective your risk management processes have been, what
worked, and what didn't work. Document the lessons learned and
continuously improve your approach, starting from step one through
step five. So there you have it, a simple, holistic, strategic
approach to managing risks in your organization.

 What’s the purpose of a high-level risk management roadmap?


 Who should develop the organizational risk management roadmap?

Risk management roadmap


Piloting an airplane through thick clouds poses a significant
challenge. You cannot see what lies ahead, and the route remains
hidden. Risk management roadmap is much like a pilot's navigation
system, designed to steer our projects, programs, and portfolios
safely through any uncertainty. This roadmap, as detailed in our
exercise files handout, consists of several critical sections.

Section 1, Definitions and Glossary. Start by defining essential terms


to ensure everyone across the organization is on the same page. This
includes distinguishing between project, program, and the portfolio
risks and explaining various risk types such as variability, event,
ambiguity, and emergent. It's also vital to categorize risks as
operational, strategic, financial, environmental, and so on, and to
create a comprehensive glossary for clarity and uniform understanding.

Section 2, Risk Management Policies and Procedures. Outline your


overarching risk management strategy here, detailing methods for risk
identification, analysis, mitigation, and monitoring. Clearly
delineate rules and responsibilities at all organizational levels.
Guidelines should specify how to handle different types of risks and
allocate financial reserves adequately across all the projects,
programs, and portfolios. Also, standardize reporting formats to
ensure consistency and document all activities for accountability and
auditing.

Section 3, Risk Identification Framework. Develop a structured


framework for identifying risks using techniques like brainstorming,
the nominal group technique, SWOT analysis, expert interviews,
generative AI, and reviews of previous projects. List typical risks
for predefined categories, operational, financial, strategic,
compliance, and so on to simplify the identification process. Use if-
then statements to articulate risks, enhancing clarity and
actionability. For example, if delivery of a critical component is
delayed, then project completion may be postponed, increasing costs.

Section 4, Risk Analysis Scale. Introduce a standardized risk analysis


scale to measure the likelihood and impact of risks, ensuring
assessments are consistent across the organization. This scale might
range from very low to very high, allowing for clear, quantifiable
risk evaluations that aid in prioritization and decision making. An
example of a risk analysis scale is in the exercises file.

Section 5, Risk Response Strategies. Standardize strategies for


responding to identified risks by establishing tailored mitigation
plans and contingency measures. These should be adaptable yet grounded
in organizational principles. Provide examples demonstrating how these
strategies manage both threats and opportunities.

Section 6, Monitoring and Review. Establish mechanisms for continuous


monitoring and regular reviews to keep the risk management process
dynamic and adaptive. Regularly update the risk management plan to
address new challenges and changes within the organization,
maintaining its relevance and efficacy. In conclusion, just as a pilot
expertly lands the plane by following a well-prepared flight plan, our
risk management roadmap equips you to successfully navigate and
complete your projects, programs, and portfolios.

 What’s the main purpose of the risk management roadmap?


 Why is a definitions and glossary section important in risk
management?

Managing different types of risks


Variability risk
How long does it take to drive to the airport? This is a question your
out of town guests ask you. This is kind of like the question project
managers ask their team members all the time. How long does it take to
compete this task? How much does it cost? Your likely answer is, hmm,
it depends. In fact, that's our answer to the airport drive question.
You see, the actual time for our guest to reach the airport depends on
many conditions like the day of the week, time of the day, traffic
light patterns, et cetera.

The uncertainty with these conditions will cause variation between the
actual time it takes, and any estimate you make. This variation can be
positive or negative. For example, if our estimate is 45 minutes, the
actual time may end up being longer or shorter. Again, depending upon
the conditions at the time of the drive. By the way, the right time
may become super high because of specific events such as a snowstorm
or a major accident. These are event risks. But here we are talking
about the variability risk created by the variation between the actual
and estimated values, resulting from the uncertainty of normal day-to-
day conditions. This type of risks with each project activity will
collectively cause a difference, positive or negative, between the
actual values and the plan estimates of your overall project cost and
durations.

Variability risk is virtually guaranteed on a every project. It's


typically caused by unclear scope, lack of expertise in estimation,
unavailability of expected resources, changes in resource productivity
levels, fluctuations in the cost of materials, so on and so forth. So
what can you do to manage variability risk? First, define your scope
of work as clearly as possible. Don't rush into the estimation
process. It takes longer than you think to reach the mountain top if
you don't clearly understand the landscape of the mountain.

Second, estimate the level of uncertainty associated with each project


activity. For this, you may consult with subject matter experts who've
been there and done that. Ask them, what are the most likely values,
as well as optimistic and pessimistic values. Third, identify the
sources of uncertainty and reduce it where it is high. For example, on
an office move project, if there is a huge uncertainty about the
availability of internal staff for moving, you might hire an external
contractor instead. Fourth, improve the quality of the estimation
process. You may achieve this by talent acquisition, skill training,
expert to peer reviews and so on.

Finally, set schedule and cost to targets as ranges, not as single


values. For instance, instead of setting the cost for a project as $1
million, you may say it'll be 1 million, plus or minus 10%. For
projects with the low uncertainty, example, capital projects like
construction of large facilities, you may use a narrow range.

But for new product development projects with the high uncertainty,
the range can be broader. Knowing the variability risk, you can manage
your project schedules and cost more effectively.

 What’s variability risk in project management?


 How’s variability risk different from event risk?

Event risk
Imagine losing a key resource in the middle of a project, or a
supplier not delivering on time, or a permit application declined by
the government. To be sure, these events are uncertain, meaning they
may happen or may not happen, but when they do, some of them
invariably do, they will collectively pose a risk called event risk,
causing scheduled delays and cost overruns. So how do you manage
project risks that are caused by specific events?

Let's focus on six proactive risk response or treatment strategies.


For ease of illustration, let us take a simple example from a personal
travel life experience. Being a road warrior with millions of air
miles under one’s belt, you may learn several strategies. So here is
how you may apply proactive risk treatment strategies for various
travel risks. Strategy one, avoid the threat altogether by following a
different course of action. While you have tight schedules on your
calendar, avoid making commitments for an out-of-town in-person
engagement, but rather possibly meet on Zoom. Strategy two, reduce the
probability of occurrence or the impact of the risk. Prefer nonstop
flights to minimize the probability of canceled flights or the loss of
checked bags. You may further reduce the potential impact by carrying
on with you an extra set of clothes.

Strategy three, transfer the risk to a third party. For an


international travel, you may always buy insurance to transfer some or
all the financial risk related to various threats. Strategy four,
build schedule or budget contingencies. For instance, you may prefer
to take an earlier flight in the day, so even if it is canceled, there
would be other flights the same day.

Strategy five, escalate the threat to a higher authority. There are


times when you may have to take the last flight from one meeting
destination to another for an early morning meeting the next day. In
those cases, you may escalate the threat by letting your meeting
sponsor know in advance the possibility of late arrival or being a no-
show so they can decide on alternative courses of action.

Finally, strategy six, accept the risk by taking no action. There are
times you want to take the last flight of the day, not your favorite
choice, by accepting the threat of flight cancellation because you
have no other alternatives or the impact of the threat may be minimal.

Of course, every one of the response actions you identify will have
its own pros and cons. The idea is to identify possible actions for
each risk that you have identified, perform a cost benefit analysis,
select the best option, and implement it. If you follow this process
regularly, the overall risk to your projects should decrease
substantially. This leads to fewer crises and unpleasant surprises,
and most importantly, more successful projects.

 What’s event risk in the context of projects?


 What’re the six proactive risk response strategies?

Ambiguity risk
The typical response to new ideas is usually a firm no, primarily due
to the inherent uncertainty with investing in something novel, which
introduces ambiguity risk. This type of risk arises from incomplete,
unclear, or unknown information that hampers our ability to fully
define a project's scope at the outset. This uncertainty complicates
the planning and prediction of project outcomes. Ambiguity risk
manifests in several forms. New unproven technology that has not yet
been tested in the market. Evolving technical requirements as the
project progresses. Technically complex projects with the full extent
of the challenges not understood until you are deep into the
development process. These factors contribute to technical
uncertainty, imperfect knowledge, and the general lack of
understanding about how the project will unfold.

To effectively manage this type of risk and unlock potential high


returns on investment, it is crucial to, number one, distinguish
between scope ambiguity and scope creep. It's common to confuse
between the two. Scope creep refers to unauthorized extensions of the
project scope, leading to cost overruns, schedule delays, and the
potential project failures. Scope ambiguity, or may also be called
strategic ambiguity, arises naturally from project's inherent
characteristics and can create strategic opportunities if managed
correctly.

Two, develop a strategic ambiguity roadmap. Similar to navigating


through a decision tree, this involves outlining initial decision
alternatives to explore different aspects of the project. It helps you
identify possible outcomes of each alternative and estimate their
likelihood and impacts. This strategic exploration should be cyclic
with ongoing assessments at each project phase.

Three, avoid all or nothing bets. Employ a robust project governance


process with phase gates. Make incremental investments at the end of
each phase, assessing whether it is worthwhile to proceed to the next
phase. Four, implement iterative and incremental development
approaches. Where suitable, use an iterative prototyping for new
product development or complex projects. This method involves multiple
cycles of prototyping, testing, and redefining. On the other hand,
incremental development is particularly useful in projects with
evolving requirements or high complexity. It helps you plan the
project in manageable chunks rather than all at once. For example,
deploying a major ERP system globally could be segmented by function
or region, reducing risk, and allowing for adjustment as the project
progresses.

Five, utilize advanced analytical tools. From the beginning, integrate


the tools that enhance decision-making under uncertainty. Decision
trees, scenario analysis, sensitivity analysis, simulations, and real
options analysis are some effective tools for evaluating various
possible project outcomes and determining the best path forward.
Finally, number six, capitalize on data-driven insights. Modern
project management tools that harness extensive data can detect
trends, forecast risks, and convert this information into actionable
insights which help in making informed unbiased decisions. By adopting
these strategies, you equip yourself to manage projects more
effectively.

You can embrace risks not just as challenges, but as avenues for
innovation and strategic advantage. This mindset shift from looking at
risks as mere obstacles to treating them as opportunities is essential
for achieving success in today's fast-evolving business landscape.

 What’s ambiguity risk in the context of projects?


 How’s scope ambiguity different from scope creep?

Emergent risk
The term unknown unknown has recently become ubiquitous thanks to the
COVID-19 pandemic. Also known as emergent risk, it refers to uncertain
events with severe negative impact. These are highly unpredictable
events which become known only after they have occurred. As mentioned
earlier, some historic examples include the Japanese tsunami of 2011,
global financial crisis of 2008, and the collapse of the Soviet Union
in the early 1980s. These kind of events are also called black swans,
because historically black swans were presumed non-existent until they
were first encountered in southern Australia.
So how do you deal with such highly unpredictable events? The key
simply lies in building a resilient organization, an organization that
can swiftly recover from the crisis created by the threat and get back
to business as usual as quickly as possible. Five key strategies can
help build resiliency. First, adapt agile leadership to pivot swiftly
to a new strategy and advance business agility. After the 2008
financial crisis, Toyota rapidly shifted its strategy, moving away
from large vehicles to focus on hybrids and smaller cars. It
demonstrated agile leadership in the face of economic shifts.

Second, create a silo-free organization to promote effective


communication and cross-functional teamwork. Under Alphabet, Inc,
Google reorganize its structure to enable greater collaboration
between ventures and foster innovation across its companies by
eliminating silos. Third, build agile teams that are empowered with a
singular focus on implementing the new strategy, with no other
responsibilities.

The Autonomous Squads at Spotify focus solely on continuous


improvement of individual features to enable swift implementation of
innovative ideas. Fourth, install redundancies into your systems and
processes that enable results even if some parts have failed. Amazon
Web Services employs redundant systems to ensure uptime, which allowed
seamless handling of increased loads during the 2020 pandemic without
service interruptions. And finally, maintain a rainy day reserve or
contingency fund that can help you with the urgent resources needed
for the speedy recovery. Netflix raised $500 million in debt financing
for content creation in 2011 to create a reserve that later helped to
finance its rapid expansion into original content during uncertain
market conditions.

Airbnb's chief executive Brian Chesky exemplified resiliency when the


COVID pandemic put the company at the brink of collapse in spring
2020. He applied many of the strategies we discussed about, not only
to survive the crisis but thrive. He led the company by a gangbuster
IPO in less than eight months since the emergence of COVID erupted.
Recounting this journey through the crisis, Chesky commented in an
interview, "I didn't know I would make 10 years’ worth of decisions in
10 weeks." Well, that's got to be part of your strategy to manage
unknown unknowns.

 What’re unknown unknowns or emergent risks?


 What’s a black swan event?

Managing event risk


Creating a risk register
One tool that may be an indispensable part of scores of projects,
programs, and portfolios, is the risk register. It's a document that
evolves with your planning process leading you to ultimate success. A
risk register is a detailed log where you record potential risks,
their characteristics, and how you plan to treat them. You should
build two separate risk registers, one for the threats, and one for
the opportunities. The risk management process is virtually the same
for both.

The risk register stands at the core of your project planning. It


helps us track identified risks, understand their potential impact on
the project, and plan our responses. Essentially, it adds as your
project's risk memory, ensuring that all team members are aware of and
can prepare for potential challenges ahead. Building a risk register
starts with risk identification. List everything that could
potentially derail your project, be it small, like a manner of
technical glitch to a significant threat like system failure. Every
risk is meticulously cataloged. Take for instance, a technology
project facing the risk of critical software component failure due to
untested third party updates, potentially causing system downtime.

Each risk is then described in a detail, including its causes,


likelihood of occurrence, and the possible effects on the project,
preparing the groundwork for in-depth analysis. Based on the analysis,
prioritize the. Next, outline treatment measures for each risk, like
mitigation or avoidance, drawing upon the collective expertise of your
project stakeholders and the team. This collaborative endeavor not
only enriches the risk register with the spectrum of insights, but
also cultivates a proactive culture of risk management. This risk
register also serves as a critical asset across various levels of
management and operations amongst many other users.

For programs, it unifies related projects, guiding risk management


toward shared goals. It involves correlating project specific risks
and pinpointing nuances from project interdependencies. It fosters a
comprehensive view for better decisions, especially related to
activities that are going to cross many projects within the program
like procurement, resource allocation, and so on. In portfolio
management, that register helps you catalog, analyze, and prioritize
risks impacting your organization's strategic business objectives. It
allows for the identification of systemic risks and opportunities to
facilitate more effective portfolio balancing and risk
diversification. By continuously updating the risk register at least
every two weeks, it creates a dynamic risk management process that
supports strategic agility and resilience. The risk registry can be a
dynamic compass.

With this tool by your side, you are always prepared to face the
unknown, the uncertain, and the unpredictable.

 What’s a risk register in project management?


 Why should threats and opportunities have separate registers?

Risk identification
Imagine sailing smoothly on a clear day only to be caught off guard by
an unexpected storm. That's project management without risk
identification, unpredictable, and challenging. It's your lookout on
the project management ship. It's about foreseeing storms or risks and
navigating your project to success. Without it, you are sailing blind,
vulnerable to delays, cost overruns, and missed objectives. Before
diving into risk identification, as a project manager, there are three
things you may do with your team.

First, inform them about the risk management roadmap we are going to
use on the project. It's basically your approach to managing risks on
your project, general policies and procedures of risk management, the
tools and techniques we are going to use, and so on. Second, share
what the project goals and scope of work are. Third, review the
project scope, time, and cost baselines. Baselines, by the way, are
your plans that serve as benchmarks to compare your actual project
progress with. Understanding your journey's destination and the route
you have planned is a vital before assessing potential impacts on it.

There are several tools and technique that you can use to identify
risks. The choice often depends on the project's nature, size, and
complexity. Brainstorming with your team unlocks collective insights.
Nominal group technique involves collecting lists of risks from
individual team members. Checklists ensure you don't miss common
risks. Delphi technique, relying on anonymous feedback from experts,
helps in identifying less obvious risks. SWOT analysis reveals
strengths, weaknesses, opportunities, and threats. Risk categories
such as technical, regulatory, environmental, internal, external, et
cetera, can help you identify as well as organize risks into
manageable groups.

Finally, we have generative AI tools like ChatGPT that can quickly


produce a list of risks. Once you identify risks using whatever tool
of your choice, you need to write them down using proper risk
statements. Each statement must be specific and direct. Here is the
formula. Three things to remember, if, then, leading to. For example,
if the project scope is not clearly defined, then scope creep could
occur, leading to delays and cost overruns. This statement outlines
the cost, potential event, and its impact.
Clear and concise. Risk identification is a team sport. It involves
everyone from project managers to team members and stakeholders.
Diverse perspectives ensure a thorough exploration of potential risks.
Once identified, document your risks in a risk register. After
identification comes analysis, prioritization, and responses, and your
risk register evolves accordingly. These steps transform your insights
into actionable strategies, fortifying your project against threats.
Just as a skilled sailor anticipates and then navigates through
storms, effective risk identification steers projects to success. It
transforms uncertainty into clarity, challenges into opportunities.

 Why is risk identification important in project management?


 What should be done before starting risk identification on a
project?

Qualitative analysis
When you're navigating through the unpredictable seas, it requires not
just a knowledge of the waters, but also the ability to foresee which
waves pose the greatest threat and which can be sailed over safely.
Once you have identified the potential risks, the next crucial step is
analyzing the magnitude of each risk. It involves estimating its
probability of occurrence and impact using qualitative measures on a
scale consisting, typically, of one to five, where one represents very
low and five very high probability of impact. Before you solve the
analysis, as a team, it's a good practice to develop guidelines in
terms of what these qualitative measures represent. For example, one
means some 10% probability of occurrence and $1,000 cost overrun, or
one week of schedule slippage. It's about gauging the storms of
potential force without precise measurements.

Imagine a scenario where a critical supplier might face delivery


issues, a high impact, but perhaps medium probability event, or
consider the frequent, minor delays in communication, high
probability, but low impact. Whereas the project manager acts as the
leader, the project team takes the responsibility in estimating the
probabilities and impacts with help from subject matter experts as
needed. The subjective nature of qualitative analysis can introduce a
bias, potentially overlooking critical nuances, but it speeds up the
risk management process with its simple, straightforward approach.
Plus, not every project can afford the time and the resources needed
for a more objective quantitative analysis.

Our voyage of discovery leads us back to the risk register, now to be


updated with qualitative analysis findings. To the lens of qualitative
risk analysis, you can gain clarity on the risks that loom over your
project. It's about estimating the size of the waves and the strength
of the wind, along with other threats, preparing us for what lies
ahead. The next step is the challenge of quantitative analysis, where
we'll measure the depths and the currents in precise terms.

 What’s qualitative risk analysis in project management?


 How are probability and impact measured in qualitative risk
analysis?

Quantitative analysis
Quantitative risk analysis turns the shadows of risk into a chartered
landscape. It turns rough guesses into hard numbers. For each risk we
have identified by giving a number for its chance to occur, and its
potential damage, we can see which risks are pebbles and which are
boulders. For the big league projects, think oil rigs and skyscrapers,
this precision isn't just a helpful, it is critical. We rely on tools
like expected value analysis, decision trees, and the Monte Carlo
simulation to guide us.

Starting with expected value analysis. On a software project, say you


identified a threat involving a bug. You estimated that there is a 40%
chance it could happen with a likely cost of $10,000. Multiply 40% by
$10,000, and you get an expected value of $4,000. This number helps us
grasp how heavy a risk weighs on our budget.
Similarly, you can calculate the expected values of every one of the
threats that you identified. As some of these values represents the
cost of the risks, which you may add to the initial cost estimate of
the project. This means you will likely have enough in the budget to
respond to those risks that may materialize. The handout in the
exercise files shows different methods on calculating the cost of the
risks, which is added as a contingency reserve to the project cost
estimate.

Next, decision trees clarify our decision choices under uncertainty.


Particularly useful for ambiguity risks faced at a program or
portfolio level. They help us see the potential outcomes and impacts
of each choice, for example, a project Go/No-Go. Finally, Monte Carlo
simulations, on the other hand, play the odds over a multitude of
scenarios, showing us a range of possible project futures. They are
adept at tackling variability, event, and ambiguity risks all at once.
With these tools, we quantify project uncertainties and their effect
on cost and schedules. We converted this data into contingencies,
added to our budgets to cover costs when risks materialize.

Now, regarding contingencies, for projects, we include a contingency


reserve atop the initial cost estimate. This reserve controlled by the
project manager should adequately cover any cost or schedule changes
due to risks identified in the risk register. At the program level,
management may add an extra contingency reserve to each project. This
provides an additional layer of protection, if the project level
reserve is insufficient to cover materialized risks, often calculated
for large projects using Monte Carlo simulations. These reserves
address event risks. Emergent risks, or "unknown unknowns," the
portfolio maintains a separate reserve. There's no systematic method
to calculate these reserves, which are typically set at five to 10% of
the total project budgets in the portfolio

Quantitative analysis is complex and resource intensive, and also


demands subject matter expertise. It may be recommended to use
qualitative analysis on small projects, and save the quantitative for
multimillion dollar projects.

 What’s quantitative risk analysis in project management?


 How do you calculate the expected value of a risk?

Risk prioritization
Imagine navigating a rapidly flowing river. It has many bends, each
with its own risks, ready to capsize your journey. After identifying
and analyzing the risks, you want to prioritize them, so you can
decide which rapids to navigate with caution, and which ones to steer
through with the confidence. Risk prioritization ensures our resources
are aligned with the most critical challenges. After we have
identified potential project risks, and analyzed them using
qualitative, quantitative methods, our next step is prioritization.
For qualitative analysis, the probability impact grid is our compass.
Here we simply plot the risks we have identified on a grid,
probability of the risk happening, versus impact if it happens. The
risks in the upper right hand corner of the grid may be considered
high priority. While those in the lower left, low priority, and the
rest, medium priority.
The grid sometimes referred to as a risk heat map is a great visual to
share with senior leaders. They can easily understand where the big
risks are, and where we're going to need more resources to manage them
proactively. When it comes to quantitative analysis, prioritization
involves a bit more precision. Here we use tools like expected value
analysis when the risk has a monetary impact. Expected value is simply
the probability of the risk happening, multiplied by its impact in
dollars if it happens. Once you have completed quantitative analysis
of all the risks you identified, you can simply rank them based on
their expected values. Remember that a project risk can escalate,
affecting the program, and the portfolio it may be part of. So make
sure you factor in this potential impact when prioritizing risks.

We have other tools too at our disposal. The risk urgency assessment
is a tool to prioritize risks based on their time sensitivity, and the
need for immediate action. You evaluate each risk based on the
criteria such as their proximity to critical project milestones, the
availability of resources to address them, and the lead time required
to implement response actions. The risk data quality assessment,
another tool, evaluates risk data's accuracy, the level of
understanding of the risk, and the reliability of the sources of
information.

By assessing the quality of risk data, you can prioritize risks based
on their need for further investigation, before making decisions on
risk responses. For relatively small ones, you may use only
qualitative analysis, followed by prioritization with the probability
impact grid. On projects involving multimillion dollar budgets, first,
you may go through qualitative analysis and identify high priority
risks using the grid. Then you perform quantitative analysis on those
high priority risks and rank them by expected values. You may also use
the other two tools, risk urgency, and risk data quality assessments
as needed.

By using the right tool for the right project, you can ensure your
resources are optimally used and your efforts are strategically
aligned across projects, programs, and portfolios.

 What’s the purpose of risk prioritization in project management?


 What’s a probability impact grid and how is it used?

Risk treatment strategies


One recurring challenge you may face is the risk of supplier delays,
potentially causing project delays. How we navigate these waters
depends on our chosen strategy, avoid, mitigate, transfer, accept, or
escalate. Let’s dive into what each strategy is and how it can be
applied to the most common risk of supplier delay.

First, avoid. Avoidance means changing your project plan so the


condition causing the risk cannot occur. For example, choose a
supplier with a proven track record of reliability over the one with a
history of delays. Second, mitigate. Mitigation aims to reduce the
probability of the risk occurring or lessen its impact if it does.
It's about making a risk more manageable. For supply delays,
minimizing probability might involve signing contracts with a penalty
clause for late delivery. To minimize impact, we could stockpile
critical materials in advance.

Third, transfer. Transferring risk involves shifting the


responsibility to another party, typically through insurance or
outsourcing. In the case of supply delay, we could use a third party
logistics provider, transferring the risk of delay to them. Mind you,
this strategy doesn't eliminate the risk, but assigns its consequences
to someone else. Fourth, accept. Acceptance can be passive where we do
nothing and accept the risk, or it can be active where we create a
contingency plan. For supplier delays, passive acceptance might simply
mean acknowledging the risk without taking preventative action. Active
acceptance, however, could involve setting aside budget and time and
contingencies to deal with the potential delays. It's about preparing
for the risk, ensuring we are not caught off guard. And lastly,
escalate.

Escalation is used when the risk is outside the project team's control
and requires higher level intervention. If supplier delays are due to
strategic partnership agreements beyond your control, you might
escalate this to management for resolution.

You can apply the strategies to any event-based risk. In your


projects, you involve your team to identify possible actions aligning
with these strategies. Together you discuss the pros and cons of each
action and decide on final action steps to take for each risk. Please
refer to the handout in exercise files to go through examples to
illustrate this process for both threats and opportunities. Since some
of the actions involve upfront effort, you'll need to add this extra
work to the original work scope accordingly. This often means you will
likely need more resources, a larger budget, or even more time than
initially estimated.

For the risk remaining, including those risks which you decided to
accept without proactive action, you may add to your budget and
schedule a contingency reserve. The reserve is meant to cover the cost
and the time needed if any of the (indistinct) materialize. You make
it a point to discuss all of this with your project sponsor, keeping
them fully informed. Don't forget to document your work in the risk
register, which you should maintain as a living document.

Remember, the strength of our voyage through risk management lies not
in avoiding all storms, but in navigating them with the foresight,
resilience, and strategic planning.

 What’re the main risk response strategies?


 How does risk avoidance work in the context of supplier delay?

Advanced Risk Management


Managing program risks
Ever felt like you were trying to solve a jigsaw puzzle without the
picture on the box? That's a bit what managing a program feels like.
In a program, a collection of interrelated projects, each project
connects to the next.

It's your job as a program manager to make all these pieces click,
revealing the overarching picture. But here is the twist. Each piece
or project carries its own set of risks, and then there are the
program risks, those related to the connections between the projects
and those in delivering the entire picture. There are six major types
of risks programs typically face, starting with strategic risks.
Strategic risks pop up when your program's objectives start drifting
away from the organizational goals. Maybe the market shifts or the
company's strategy changes. Handling these risks might involve regular
strategic reviews and adapting your strategy to keep everything
aligned. For example, a major retailer chain planning to expand into
emerging markets might face such risks if political instability or
economic downturns arise. Their mitigation strategy? Flexible entry
strategies like forming local partnerships that allow for scalable
investments and quick adaptation to changing conditions.

Second, resource risks. Resource risks deal with the classic problem
of not having enough people, equipment, or money. Imagine launching a
new series of electric vehicles, but suddenly there's a shortage of
lithium batteries. This snag could delay your entire program or drive
up your costs. A savvy response? Diversify your suppliers or invest in
alternative battery technologies to cushion your program against such
shocks.

Third, schedule risks. Schedule risks are all about delays that affect
one or more projects within the program, potentially derailing the
entire program's timeline. Let's say that you're upgrading patient
record systems across multiple hospitals. If the software installation
in the first hospital lags, it could set back the entire program's
timeline. How to manage, build in buffer times and have rapid response
teams ready to address and rectify delays quickly, preventing a domino
effect. Fourth, performance risks.
Performances get real when outputs don't meet expectations. For
instance, you are at a telecom company, overhauling customer
interactions and network management. If an untested software patch is
released prematurely, it could knock out service for thousands of
customers, a major blunder for the program. Preventing such disasters
might mean, implementing multi-stage testing for every update, or
consider a phase rollout. Test small, ensure stability, then expand.

Fifth, technology risks. Technology risks arise from failures or


inadequacies in your tech to meet the program's needs, or from new
tech disrupting established processes. Consider financial services
from integrating a blockchain to boost the transaction security.

The unknown facets of blockchain, coupled with a shaky regulatory


environment, introduce high stakes. Manage this by staging your tests,
evaluating the results at each phase, and adjusting your strategy
accordingly. This method, which you may call strategic ambiguity,
turns potential challenges into opportunities for innovation and a
competitive edge.

Lastly, compliance and regulatory risks. Changes in loss or


regulations represent the compliance and regulatory risks. Staying on
top of this is crucial. For example, pharmaceutical companies must
continuously adapt to FDA regulations during drug development.
Regularly liasoning with the regulatory consultants ensures, these
programs are just as swiftly to regulatory shifts without notable
delays. As we piece together this complex puzzle of program
management, effective risk management ensures, each piece fits
perfectly to complete the picture.

 What’s the main difference b/n project risk and program risk?
 What’re the six major types of risks in program management?

Managing portfolio risks


Project portfolio management, or PPM, is an essential discipline in
strategic management. The key objective of PPM is to ensure selection
of right projects and programs for investment to achieve
organizational strategy and goals. But it's not just about lining up
your ducks.

It's also about making sure they can weather any storm. Let's explore
how top industries, Fortune 500 companies, tackle portfolio risks with
some real world strategies. Let's start with strategic risks. These
are your big picture challenges. Take Tesla, the electric car company,
for instance. They use scenario planning to prepare for different
future states. Whether it is a sudden change in technology or a shift
in consumer preferences, they're ready to tackle it on because they
have already thought about a plan.

Another approach is staying flexible, to pivot. The pharmaceutical


industry shows us how it is done. In developing new drugs, they use
incremental funding approaches, avoiding all or nothing buts. They
adjust their strategies based on ongoing results, which allows them to
pivot efficiently in response to new data or regulatory feedback. A
common strategic risk is decision making biases. Pfizer, a global
pharmaceutical and biotech corporation, tackles this by incorporating
cross-functional review teams and third party audits. This approach
helps ensure decisions are based on diverse perspectives and solid
evidence, steering clear biases like overconfidence and group think.

Onto financial risks. Energy giants like BP hedge against the market
volatility with the financial instruments like derivatives and
options. This helps stabilize their funding, ensuring that the
fluctuating oil prices don't derail their projects. Walmart, a retail
giant, shows the power of strict budget controls to weather financial
risks. They keep their projects aligned with the financial targets
through detailed department specific financial planning and regular
reviews. This rigorous approach ensures they stay within budget and
just spending proactively construction firms, especially those like
back tail set aside management reserves. These financial and
resourceful buffers are crucial, especially for covering unexpected
costs or delays.

You do unknown unknowns or emergent risk. And let's not forget about
the power of diversification. Toyota, the Japanese car company, for
example, balances their project portfolio by investing in a range of
initiatives from hybrid vehicles to cutting edge hydrogen fuel
technology. This spreads risk and optimizes returns, ensuring
stability across varying global market conditions.

Next, regulatory changes can come fast and furious, creating their own
risks. Tech companies like IBM stay ahead by continuously monitoring
these changes and regularly training their teams. This ensures
projects in the portfolio to be compliant with the latest standards,
avoiding potential legal hurdles.

As for market risks, consumer goods companies like Proctor and Gamble
continuously conduct extensive market research to accurately
anticipate consumer needs and adjust their product lines accordingly.
Tech companies like Apple diversify their offerings across hardware,
software, and services to mitigate the risks associated with the
dependency on a single market segment.

Finally, to tackle technological risks, establishing a technology


watch team is a good practice. Intel has dedicated teams that
constantly monitor emerging technological trends, ensuring they stay
ahead of potential disruptions.

Plus, investing heavily in R&D is key in the highly innovative tech


sector. Samsung allocates a significant portion of its budget to R&D,
enabling them to maintain technological superiority in a highly
competitive market.
Remember, the goal of portfolio management is not just to manage
projects, but to achieve strategic success that propels your
organization forward. With the right approach to risk management, you
can ensure that your projects aren't just completed, they're completed
successfully to help you achieve organizational goals.

 What’s project portfolio management (PPM)?


 How does PPM differ from traditional project management?

Quantitative methods
Let's explore how to quantify four key types of risks; variability,
event, ambiguity, and emergent, with the tools that prepare us for any
challenges our projects might face. Quantitative risk management, not
only sharpens our ability to make smarter decisions, but also enhances
the accuracy of our schedule and cost estimates. This will, of course,
significantly boost the likelihood of completing projects within the
planned time and budget. You may check out the exercise files for
details of the calculations presented.

Let's start with variability risk. Consider a scenario where you are
estimating the time required to code a software module. Say you
estimate it'll most likely take four weeks. However, this estimate
often fails to consider daily uncertainties, such as fluctuations in
resource availability. To address this variability, you could estimate
best case scenario, two weeks, and worst case scenario, seven weeks,
scenarios alongside the most likely scenario of four weeks. A simple
average of these three numbers results in 4.3 weeks. Alternatively, if
you want to be less conservative, a weighted average, where the most
likely scenario is given more emphasis, often called a PERT estimate,
might conclude with an estimate of about 4.2 weeks. Applying this
method across all relevant tasks provides a more robust buffer against
the inherent variability of a project tasks, enhancing overall project
timeline accuracy.

Events risk. For event risks, expected value calculations, which we


introduced earlier, are paramount. Imagine a software project
initially budgeted $500,000. If there is a 30% chance of encountering
a bug that could lead to an additional $15,000 in cost, the expected
value of this risk would be $4,500. You multiply those two numbers,
summing the expected values of all the identified risks, let us say
that came out to be $50,000. You add that number to the initial budget
of $500,000. Now the adjusted project budget becomes $550,000. This
new figure includes a contingency reserve of $50,000, specifically set
aside to cover potential risks if they materialize. This ensures that
the project has adequate funds to address unforeseen costs.

Next, ambiguity risk. Tackling ambiguity risk involves decision making


under uncertainty. Here we use decision tree analysis with expected
value calculation as shown in the handout. For example, consider
investing a hundred thousand dollars in an innovative technology with
a 60% chance of returning an additional $200,000. However, mind you,
there's also a 40% chance it might fail, resulting in a total loss.
The expected value for the outcome is 60% times $200,000, which equals
$120,000. After subtracting the initial investment of a hundred
thousand, the net gain is $20,000. So investing appears financially
advantageous compared to not investing, which is no financial gain.

Finally, emergent risk. Unlike other risks, emergent risks are


unpredictable and cannot be foreseen with traditional tools. The best
strategy here is to allocate a management reserve and additional
percentage of the total budget determined by the organization's risk
appetite. This reserve acts as a financial safety net, allowing for
sponsor (indistinct) to sudden and unforeseen challenges. It's not
directly included in the project budget, but managed at a higher
level, maybe at the portfolio level to ensure availability when
needed.

In summary, effective quantification and the management of these risks


transform potential threats into navigable challenges. And by
employing these strategic tools, we turn uncertainties into managed
risks, leading our projects towards successful completion.

 What’s variability risk in project and how is it quantified?


 How does a PERT estimate differ from a simple average of three-
point average?

AI in project risk management


AI's applications extend across a project, program, and portfolio
management with the tools designed to address the specific needs and
challenges. One of the most transformative tools is generative AI,
which is especially effective across various management levels due to
its ability to simulate and predict outcomes based on extensive data
analysis. It can be used in every one of the applications we saw.

Let's start with project management applications. Number one,


generative AI. Large language models like ChatGPT can identify,
analyze, and prioritize risks early on and recommend mitigation
actions. For instance, take the manufacturing industry where it can
foresee potential supply chain bottlenecks and equipment failures
before they cause project delays, suggesting proactive fixes to
mitigate these risks. Number two, predictive analytics. For large
scale infrastructure projects, AI can forecast the long-term impacts
on environmental, social, and governance or ESG factors. This
capability enables leaders to make informed sustainable decisions that
align with the global ESG standards, such as predicting the community
impact of a new highway project.

Number three, machine learning. AI excels in operational oversight,


where it can preemptively identify problems. For instance, in
construction projects, AI tools analyze data from sensors and drones
to detect safety hazards, providing early warnings to prevent
accidents. Number four, probabilistic analysis. Monte Carlo
simulations and other probabilistic tools offer range based estimates
for schedules and budgets, helping project leaders understand the
likelihood of various outcomes. For example, in a multimillion dollar
renewable energy project, AI could provide a detailed risk assessment
showing the different completion scenarios based on current data.
Next, program management applications. AI proves invaluable in
coordinating complex programs such as a city's infrastructure project.
It can predict how delays in one area, like permit approvals, might
ripple through related projects.

This foresight allows managers to swiftly recalibrate plans to keep


the entire program aligned with its goals. In the pharmaceutical
sector, AI's real options analysis can determine the viability of
continuing, pausing or adjusting drug trials based on ongoing data
assessments, helping program managers make crucial decisions
efficiently.

Finally, portfolio management applications, AI aids portfolio managers


in strategic decision making, particularly in project selection and
resource allocation. For project selection, AI evaluates projects vis-
a-vis the organization's strategic goals, identifying those that best
align with the overall objectives.

It assesses projects based on benefits, costs, and risks, using data


to rank them and suggest the optimal mix for the portfolio. For
resource allocation, AI optimizes resource distribution, ensuring the
right personnel and investments are directed towards the projects with
the highest potential for success. In essence, AI acts like a master
strategist in chess, foreseeing several moves ahead and positioning
resources effectively to secure a competitive advantage.

As we navigate the complexities of project management, think of AI as


an advisor that illuminates the path forward. With AI's insights, you
can confidently steer your projects towards success, making informed
decisions that navigate through uncertainties towards a clear,
successful outcome.

 How can generative AI help in project risk management?


 What role does AI play in predictive analytics for ESG factors?

Evolving risk management tools


Imagine a future where risks aren't just obstacles, but catalyst for
growth and innovation. This isn't science fiction. It's a reality we
are building with the latest in risk management techniques. Let's
transform VUCA, volatility, uncertainty, complexity, and ambiguity,
into strategic VUCA, SVUCA, turning challenges into strategic
opportunities.

Integrated risk management. Organizations are increasingly adopting a


holistic approach that integrate risk management across projects,
programs, and entire portfolios. Such integration enhances strategic
decision-making.

Leveraging AI. Generative AI tools like ChatGPT are revolutionizing


risk identification, assessment, and mitigation. These AI algorithms
analyze massive datasets to predict potential issues before they
arise, equipping project managers with the tools to proactively
address risks with unmatched speed and accuracy.

Risk management software. Modern risk management relies heavily on


software integrated with the real-time data analytics. Oracle
Primavera risk analysis, for instance, provides advanced remodeling
and simulation capabilities to anticipate project challenges. You can
create customizable dashboards using tools like Power BI and Tableau
and offer a live overview of risk status and mitigation efforts.

Probabilistic analysis. Using Monte Carlo methods and stochastic


optimization, detailed probabilistic analysis of project schedules,
costs, and financial benefits become possible. Tools like Lumivero's
@RISK and Safran's Risk Manager enhanced by AI and the faster
computing allow for continuous forecast, facilitating informed
decisions on project viability based on real-time data.

Hybrid management approaches. The era of rigid project management is


over. Today's organizations blend traditional and Agile practices in a
hybrid approach tailored to each project's needs, minimizing the risk
of failure.

Data-driven decision-making. In our data-rich environment, analytics


drive smaller bias-minimizer decisions. Modern tools harvest the
extensive data to identify trends, forecast risks, and enhance
outcomes, turning data into actionable insights.

Building resilience. Organizations now emphasize resilience,


developing strategies to withstand unexpected disruptions. Proactive
crisis planning enables projects to handle such changes and continue
progressing.

Behavioral science. Applying behavioral science reduces decision


biases, enhancing risk decision-making. Techniques like framing and
anchoring lead to better risk assessments and more effective
strategies.

Blockchain for secure risk management. Blockchain technology offers a


secure and transparent framework for managing complex project risks,
enabling reliable tracking and storage of risk data across multi-
faceted projects with numerous stakeholders.

Opportunity management. It's crucial to balance risk management with


opportunity management. By identifying, analyzing, and leveraging
opportunities, organizations can capture potential benefits and drive
project success. Welcome to Project Risk Management 3.0. By embracing
these advanced methods, you gain a strategic advantage, transforming
potential vulnerabilities into strengths and redefining project
success in our dynamic world. Together, let's turn VUCA into strategic
VUCA.

 What’s meant by transforming VUCA into strategic VUCA in project


risk management?
 How does generative AI like ChatGPT support project risk
management?

Key reminders for successful risk management


By implementing the practices discussed, your project success in
meeting budget and scheduled targets will soar to new heights. If you
are keen to go deeper, it may be recommended to explore some
authoritative resources. Dr. David Hilson, a renowned risk management
expert, has authored several books on this subject. One notable work
that he co-authored with Peter Simon is "Practical Risk Management:
ATOM Methodology". Another essential read is Carl Pritchard's "Risk
Management: Concepts and Guidance".

Additionally, the Project Management Institutes publication, "The


Standard for Risk Management in Portfolios, Programs, and Projects is
a good reference.

 What’s the ATOM methodology?

You might also like