Topic 9: Managing Project Risk
Lecture
Learning Objectives
At the end of this topic, you should be able to:
• Define risk and explain why effective risk management is critical to project
success
• Identify common sources of risk in ICT projects
• Outline the risk identification process and describe its key outputs, including the
RBS, Risk Register, Top Ten Risks, etc.
• Describe the main components of risk management planning
• Differentiate between qualitative and quantitative risk analysis techniques
• Apply risk factor calculations and develop probability–impact matrices
• Explain how tools such as decision trees, simulation, and sensitivity analysis can
be used in risk analysis
• Provide examples of risk response strategies with practical examples
• Describe the processes involved in risk monitoring and control
What is a Risk?
Individual Risk is defined as:
• ‘an uncertain event or condition that, if it occurs, has a
positive or negative effect on one or more project
What is objectives’
Risk Project (Overall) Risk is defined as:
Management? • ‘the effect of uncertainty on the project as a whole…
more than the sum of the individual risks within a
project… & represents the exposure of stakeholders to
the implications of variations in project outcomes’
A Risk Event occurs when that risk happens
Source: PMBoK 6th Edn
What is Risk Management?
Risk management is …
• An iterative process for identifying,
How does this analysing, handling (responding to) and
fit with other monitoring/controlling risks.
aspects of • Each facet of Risk Management must be
your project planned and applied consistently
throughout a project
Sources: Chapman & Ward (2003); Kerzner & Kerzner (2017); Cleden (2017); Kleim & Ludin (2019)
Risk Management – Principles,
Framework, and Process
✓ Managing Risks is guided Risk
Management
by principles, framework, Principles
and processes, according
to ISO31000:2018
Risk Risk
Management Management
Framework Process
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Management Principles
What does good risk • RM is customised to organisational
management look like? context
• RM should create value • RM considers human and cultural
factors (considers human behaviour
• RM is integrated in organisational and org culture)
activities and decision making
• RM is transparent and inclusive
• RM is structured and comprehensive (involves stakeholders)
(uses a systematic approach)
• RM is dynamic (responsive to change,
• RM is based on the best valuable uncertainty and emerging risks)
information (historical data,
experience, and forward-looking) • RM involves continuous improvement
(through experience and learning)
ISO 31000:2018 – 8 Principles of Risk Management
Risk Management Framework
How do you ensure risk management is consistently applied,
supported, and reviewed?
• Leadership and commitment
• Top management must lead and support
• Define risk ownership and accountability
• Design a framework for risk management
• Define risk policies, accountability, and competence, allocate resources for RM, internal and external
communication, and reporting
• Integrate RM in all processes – governance, strategy, planning
• Implement risk management (apply risk principles and processes consistently)
• Evaluate – assess whether risk management is effective
• Continuously improve – enhance risk practices based on feedback and performance
Risk Management Process
How is risk actually managed?
1. Plan Risk Management. Communicate, consult, and document how risk
management activities will be managed in the project
2. Identify Risks. Detecting possible risks – what could happen? How and why
could it happen?
3. Analyse Risks. Determining the likelihood and effect of risks through
Qualitative and Quantitative methods
4. Risk Responses
• Plan Risk Response. Developing options & actions to reduce/manage the risks appropriately
• Implement Risk Responses. Take appropriate steps to manage/treat risks
5. Monitor Risks. Track risks and controls, detect changes and emerging risks
Risk Management Process
Plan Risk Risk Perform Risk Implement Risk Risk Monitoring
Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register
Plan Risk Management
• Create your Risk Management Plan (RMP) Risk Management Plan
for the project
Table of Contents
• May vary, but often includes the following:
Definitions………………………………
• Risk Identification
• Risk Categories/Types (Risk Breakdown Structure) Project Background……………..............
• Risk register Risk Identification………………..............
• Risk Management Organisation (Roles & Responsibilities)
• Risk Analysis Risk Analysis……………………..............
• Risk matrix (Likelihood and Impact) Risk Responses…………………………
• Risk Management Methodology (Tools, approaches, etc)
Risk Monitoring and Control………….
• Tolerances and Limits (General Principles)
• Risk Responses
• Budget (Funds for risk management)
Plan Risk Management
• Define and document risk limits – risk capacity, risk appetite, and risk tolerances
• Risk appetite is explicitly considered
• Risk tolerances are established for:
• Cost
• Schedule What do
• Scope
• Quality these mean?
• Risk capacity is acknowledged (often implicitly) when deciding:
• Level of risk management effort
• Escalation thresholds
• Authority limits
• These will influence your risk management plan, risk categories, and your
definition of risk levels (high/medium/low risk) and response strategies
Risk Capacity
✓ Risk Universe. All of the possible Risk Universe
High
risks that could affect a project or
entity
Risk Profile
✓ Risk Profile. An analysed indicator
of the level of risk for a project/task Risks beyond
RISK
capacity
Risks within
✓ Risk Capacity. The expected ability capacity
Risk Capacity
of the organisation (team) to manage
the associated risks
Low
The capacity is influenced by the organisation’s Limit to capacity
(team’s) Appetite and Tolerance for risk
Low REWARD High
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Appetite
✓ Risk Appetite. The amount and Risk Universe
High
types of risks that an organisation is Hungry/
Seeking
willing to take to meet strategic
objectives – Can be classified as…
• Averse. Avoids risk & uncertainty
• Minimal. Will take some minimal
risks if the reward is very high
RISK
Open
• Cautious. Will take some risks if
there are clear rewards & controls
• Open. Willing to take risks if
Cautious
there is a chance of strong reward
• Hungry/Seeking. Actively
chasing risk for high reward Minimal
Low
Averse
Low REWARD High
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Tolerance
Risk Universe
High
✓ Risk Tolerance. The specific Hungry/
maximum risk that an organisation Seeking
is willing to take regarding each
Limit
Risk
relevant risk
✓ This is defined by:
Target
RISK
Open
Risk
• Risk Profile (risk level, known-
unknowns & unknown unknowns)
• Risk Appetite (how far are they willing
to go to achieve the objective)
Risk Profile
Cautious
• Risk Target (the optimal level of risk that
organisation wants to take)
• Risk Limit (identified thresholds beyond
Minimal
which risks should not deviate)
Low
Averse
Low REWARD High
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Defining Risk Limits
Defining Risk Limits. These can be numeric or ordinal
Element Very Low Limit Low Limit Moderate Limit High Limit Very High Limit
% Difference in Outcome <= %2.5 2.5% - 5% 5% - 7.5% 7.5% - 10% > 10%
NUMERIC
Cost (what is acceptable) Very small increase Small increase Significant increase Significant increase Large increase
(<5% of profit) (< 10% of profit) (< 20% of profit) (< 40% of profit) (< 60% of profit)
Scope (what is acceptable) Barely noticeable Minor noticeable Some significant Numerous Very significant
changes changes scope changes significant scope changes in scope
ORDINAL
changes required
Time (Schedule) (what is No change to key Minor changes but Minor change to Significant change Very significant
acceptable) milestones not for end date end date to end date change to end date
Quality (what is acceptable) Quality variance Only affects very Differences would Differences would Does not meet key
barely noticeable intensive use be noticeable be very noticeable requirements
✓ These have to be agreed by the key stakeholders (formally)
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018) &
[Link]
Quik Question
What is the difference between an organisation’s Risk
Appetite and its Risk Tolerance?
Risk Management Process
Plan Risk Risk Perform Risk Implement Risk Risk Monitoring
Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register
Risk Identification
• An ongoing process of identifying potential risks that could affect the project and
documenting them in a Risk Register
• Use different risk identification techniques
• Recognise different types of risks
• Threats (negative risks)
• Opportunities (positive risks)
• Recognise the different sources of risk
• Recognise different categories of risk – use a risk breakdown structure (RBS)
• An RBS is a hierarchically organised framework that categorises potential project risks by source, helping
teams identify and manage risks more effectively.
• Focuses on where risks come from
• Ensures comprehensive risk identification so nothing is overlooked
Risk Identification – Key Sources of
Risk
Schedule flaws, Failing Significant Cost Inability to meet requirements,
Poorly controlled Differences unrealistic expectations
changes in scope to meet schedule due
to complications (Financial Losses)
Scope Schedule Cost Quality Value
Not knowing
what is at stake ProjectIntegration
Project Development Lifecycle
Management
(the risks)
Risk Communicati Project
Risk
Manageme Complexity Stakeholders
on Team
nt
Disagreements /conflict, user
People, technology, Key people leaving, team culture, involvement
Communication lack of executive support, project
uncertainties, ambiguity gaps management, and contractors
Risk Identification – Risk Categories
Consider the different categories/dimensions of risk
Internal/Direct External/Environmental
Structure/Process/Method PEST (Political, Economic,
Technical/System Social, Technology)
Stakeholder & Comms Market Forces/Competitors
Financial/Costs Clients (Demands/Usage/etc.)
Guide: Risk Management
Risk Management Guidelines Vocabulary
APPLY DIRECT CONTROLS OFTEN LITTLE CONTROL
Risk Assessment Techniques
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Identification – Positive and Negative
Risks
✓ Risks can be positive or negative
Positive risks open up opportunities
They are handled by:
✓ Accepting the risk & helping to make it happen
✓ Exploiting the opportunity
✓ Sharing the risk – so the impact is increased
✓ Enhancing the risk to increase its positive impact
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Positive and Negative Risks
✓ Risks can be positive or negative
Negative risks are problems/threats
They are managed with these strategies:
✓ Avoid – Eliminate the threat to protect the project
✓ Transfer – Shift the risk to another party
✓ Control – Manage variables that lead to the risk
✓ Mitigate – take steps to reduce the impact
✓ Accept – Understand the risk & only take action if it happens
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Identification – Realised, Residual and
Secondary Risks
✓ Realised Risk. Risk that has occurred and
become an actual problem, incident, or issue RISK
RISK
RISK
RISK
CONTROLS
✓ Residual Risks. Risks that remain after all of
the management strategies have been
implemented
Residual Risk RISK
✓ Secondary Risks. Risks created by
implementing the risk response/ management
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Quiz Question
What is the difference between Positive Risks and
Negative Risks?
Risk Identification Techniques
• Risk identification tools and techniques include:
• Brainstorming
• Talking to stakeholders (interviews, discussions & Management by Walking
Around (MBWA))
• Expert judgment (Consultation or Workshopping)
• SWOT analysis (generally best done as a workshop)
• Delphi Technique (uses experts who provide anonymous inputs to help avoid
Groupthink)
• Lessons learned from previous projects
• Risk breakdown structure (for categorisation of sources of risks)
• Once risks are identified, enter the content in a Risk Register
Sources: Schwalbe (2018); Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
The Delphi Approach
Choose a Facilitator
1. Choose a facilitator (must have an open mind)
2. Identify & engage the experts who will be used (they Identify & Engage the
Experts
must understand the issues from different
perspectives)
Define the Problem
3. Define the problem and develop questions (and develop Questions)
4. Send Questions (send questions & get responses)
Send Questions
5. Analyse Responses (develop more focused (Analyse and develop clarifiers)
questions as needed and do Step 4 again as
appropriate (typically 2 or 3 times)) Analyse Responses
(Develop more focussed
6. Once the issues are clarified, identify actions attention)
Identify Contingencies &
Fallbacks
Sources: Schwalbe (2018); [Link]
Risk Breakdown Structure (RBS)
• Another fundamental approach to identifying project risks
• RBS is a tool for categorising project risks
• Develop your RBS in a stakeholder workshop - use these
steps:
• Identify the categories & dimensions of risk associated with this
project (makes it easier to identify risks)
• For each category/dimension of risk
• Identify what has gone wrong in the past
• Identify what could go wrong in the future for this project
Risk Breakdown Structure
It can be depicted graphically like this…
Processes & Technology & Stakeholders &
Finance & Cost Market & Client
Methods Systems Comms
Team Data Team
Debt Funding PEST
Structure Dynamics
Mobile
Team Team Comms Cashflow Competitors
Methods Meetings from Beta
Networks Entry Threats
Communicati Team
Reserves
on Workshops
Buyer Power
SaaS
Etc… Performance
Coordination
Management Substitution
Provider
Cloud Beta Tester Suppliers
Etc…
Engagement
Etc…..
Etc… Etc…
Risk Breakdown Structure (… or like this)
… or it can be depicted in a table like this…
LEVEL 0 LEVEL 1 LEVEL 2 LEVEL 3
Team responsibilities not well defined
Team dynamics
Poor balance of resources & expertise
Stakeholders & Comms
Changing/unclear requirements
Customer/client
Low client engagement
Project Risk Unmet expectations
Client application
Poor quality code
Technology Supplier delivery issues
Data center Poorly designed data systems
Natural disasters (fires or floods)
Risk Register
• Different organisations use different formats. Common elements
are provided in the example…
• Records all identified risks related to a
project
• Providing details of the risk (Description)
• Providing risk ownership (Risk Owner)
• Provides estimation of risk impact
• Prioritises risk Use the format
• Identifies risk response plans (avoided, mandated by
transferred, controlled, mitigated, or your
accepted) organisation
Risk Management Process
Plan Risk Risk Perform Risk Implement Risk Risk Monitoring
Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register
Perform Qualitative Risk Analysis and/or Quantitative risk analysis
(if required) … and prioritise risks to guide your risk responses
Qualitative Risk Analysis
• Assessing the likelihood and impact of identified risks
(determine their magnitude and priority for control) using relative
descriptive scales rather than numerical values
• Common techniques include:
Can be used jointly
• Probability/Impact matrices
• Expert judgment *Which risks matter most
• Risk categorisation and need attention?
• Top Ten Risk Item Tracking
Let’s look at each of these techniques in turn
Probability/Impact Matrix
• Used to assess
• the probability of occurrence of an identified risk and
• the impact of a risk event
• Often used to identify risk factors (a numeric Severity Weighting)
• A severity weighting is a numerical value assigned to represent how serious
the consequences of a risk are if that risk occurs.
• Severity weighting is commonly used in:
• Risk scoring models, such as Failure Mode and Effects Analysis (FMEA), Risk
matrices (probability × impact)
• Risk prioritisation and monitoring tools such as the top ten risk item tracking
Probability/Impact Matrix
IMPACT OF OCCURRENCE PROBABILITY OF OCCURRENCE
Low (1) Medium (3) High (5) High Major uncertainty remains
(5) No or little prior experience or data/information
Very
PROBABILITY OF OCCURRENCE
Moderate Significant infrastructure, systems & resources not in place
High High Risk High
(5) Risk (5x3=15) Medium Some uncertainties remain
(5x1=5) Risk
(5x5=25) (3) Some experience and data/information exists
Infrastructure, systems, resources in place but not complete
Medium Moderate Low Few uncertainties remain
Low Risk High Risk
(3) (3x1=3)
Risk (3x5=15) (1) Significant experience and data/information exist
(3x3=9) Infrastructure, systems & resources in place
Low Very Low
Low Risk
Moderate IMPACT OF OCCURRENCE
(1) Risk (1x3=3)
Risk High Performance, technical, quality, costs or safety impacts can
(1x1=1) (1x5=5) (5) result in major injury, redesign/program delay
Very High – Escalate & resolve quickly Medium Performance, technical, quality, costs or safety impacts can
WHAT TO DO
(3) result in injury, or significant redesign/program delay
High – Proactive steps ASAP
Moderate – Manage with caution Low Performance, technical, quality, costs and safety impacts are
Low – Proceed but monitor (1) likely to be minimal & requirements should still be met
Very Low – Monitor but little risk
Probability/Impact Matrix
Typically, more detailed guidance is provided (such as the table in the RMP)
Score Definition/Actions to be taken
Very High Anything classified as Very High indicates that this risk is extremely or very likely to occur. Additionally, the occurrence could have a
(25) profound impact on the project’s safety, technical, cost, and/or schedule, which may cause the project to be terminated or can cause
significant cost/schedule changes (e.g. increases of more than 5 percent) for the project. The management of this level of risk should be
escalated, and that aspect of the project must be implemented with extreme care until the risks can be mitigated/controlled effectively.
High Risk High Risks may cause significant safety, technical, cost, and/or schedule increases (e.g. increases of 2 to 5 percent) for the project. These
(15) risks are to be managed proactively, and a priority must be applied to mitigate/control the risks as soon as practicable. In the meantime,
the elements of the project associated with this risk must be managed with due care.
Moderate This refers to risks that are Moderate, because they may have a relatively small but significant impact on the project’s safety, technical,
Risk cost, and/or schedule (e.g. less than 2 percent). Appropriate mitigation/control strategies should be implemented when practicable.
(5 or 9) Obviously, risks with a score of nine (9), should be addressed with higher priority than those with a score of (5). While awaiting
mitigation/controls to be implemented, the team should still manage this aspect of the project with care.
Low Risk A Low Risk refers to an event that is relatively unlikely to occur, or the impact would be low if it did occur. In other words, this refers to
(3) situations in which the combination of likelihood and impact means that this risk would not be expected to have a significant impact on
the project’s safety, technical, cost and/or schedule. Typically, consolidated risk management is not applied to these types of risks.
However, the team associated with this aspect should keep it in mind while implementing the project and monitor the issue with an
appropriately level of caution.
Very Low Risk A Very Low Risk refers to matters where it would be unlikely for the risk to occur and even if it did, the impact is expected to be minimal.
(1) In these circumstances, consolidated risk management would not be applied. However, as with all aspects of Risk Management, those
involved with the project should continue to monitor evolving levels of risk and take proactive action when considered appropriate.
Quantitative Risk Analysis
• Numerically evaluating the combined effect of identified risks
on project objectives, such as cost or schedule.
• This entails using different techniques to help quantify risks -
How much risk do we have, in numbers (quantified exposure)?
• Some of these techniques include:
• Decision tree analysis & Expected Monetary Value (EMV)
• Simulation (e.g., Monte-Carlo)
• Sensitivity Analysis (e.g., What-If analysis) Let’s look at EMV
Expected Monetary Value (EVM) Analysis
• EMV is a technique for evaluating decisions under uncertainty
by combining possible outcomes, probabilities, and impacts.
• calculates the average expected outcome of uncertain events by weighting
each possible outcome by its probability
• EMV applies the decision tree approach to determine the most
appropriate course of action (e.g. for risk/reward analysis)
• Decision Tree Analysis is a visual and analytical technique used to evaluate
different decision options and their possible consequences under
uncertainty
• EMV answers: “On average, what is the financial impact of this
decision?”
EMV – example of a Decision Tree
This is a variation that allows costed
Numerical estimate
options to be assessed – discussed of risk exposure
further in Topic 9 Workshop Possible outcomes
Options Delivered Monetary
Chance Node
successfully Outcome
Decision
Custom-Build
Risk Event System
Node
(Decision Trigger) Moderate rework Monetary
Contingency Chance Node
required Outcome
Implement New
Decision
System Smooth Monetary
Chance Node
implementation Outcome
Decision
Buy Commercial
System
Node Configuration Monetary
Fallback Chance
issuesNode Outcome
Risk Simulation
• Uses mathematical modeling and
random sampling to evaluate risk
parameters and variables to • Simulation answers
determine impact on project questions like
outcomes • What is the probability of
finishing the project on time?
• Simulation determines things like:
• What is the likely cost range,
• The scope of the risk not just a single estimate?
• Risk probability (likelihood) • How much contingency
• Risk impact (cost, time, etc.) reserve is needed?
• Which variables will likely be most • Which risks contribute most
important (what do we need to watch?) to uncertainty?
• The risk limits that should be set
• Contingency (known unknowns)
Risk Simulation
• A common approach applies Monte Carlo Simulation,
which uses a range of variables to:
• Determine the most likely effect of variable changes across a range of
circumstances (multiple run analysis)
• Define/apply three outcome estimates (most pessimistic, most likely, most
optimistic)
• Apply the probability of the most likely being between in the
optimistic/pessimistic range (to create a numeric weighting model)
• Develop Quantitative risk parameters (Probability, Impact, Risk level, etc.)
Often this is linked to Sensitivity Analysis
Sensitivity Analysis
• Examines how changes in individual risk variables affect a project
objective (such as cost, schedule, or performance).
• Allows specific variables to be manipulated directly to determine the
likely outcomes
• It is beneficial for ‘what if’ analysis
• Such models are built explicitly for likely high-impact risks (both + & -)
• Can be used to
• Predict the likely completion date of a project
• Predict the likely final cost of the project
• Determine which risks have the highest impact on the project
Determines key risk drivers
How Does Monte Carlo Analysis Work?
STEP 1 Define the problem and which aspects of the project to analyse? Cost, schedule,
performance, resources, etc
STEP 2 Determine input variables and their distribution. Such variables include task durations,
cost estimates, resource availability, probability, and impact scores for each risk
STEP 3 Create a Monte Carlo simulation model using Excel Add-ins e.g. @RISK, statistical
software packages, or dedicated Monte Carlo simulation software e.g., RiskyProject
STEP 4 Run the simulation and analyse results
STEP 5 Validate the accuracy of your results by comparing them with actual project data or
historical data from similar projects
Understanding the Monte Carlo Analysis in Project Management - Project Management Academy Resources
Risk Analysis Software
• Use a Monte Carlo Excel Add-in (pick one) – for example
• @RISK
• ModelRisk
• CrystalBall
• These vary in technical complexity, capabilities, reporting and presentation, trial
versions, pricing
• Statistical packages such as R and Python (statistical libraries)
Source: [Link]
Risk Prioritisation – Top Ten Risk Item
Tracking (TTRR)
• Uses Severity Scores/Risk Exposure to identify the Top 10 risks (or
sometimes more)
• A Prioritised List of Risks
1. Identify risks
2. Estimate the probability and impact of each risk (realistically)
3. Calculate Risk Exposure (multiply probability by impact – see previous slide
36)
4. Sort risks from highest to lowest exposure, and select the Top Ten
5. Allocate risk owners
• Monitor and update the listing as appropriate (e.g. monthly or when
new risks are identified)
• Remember: you need to assess/monitor/control all identifiable risks
Risk Management Process
Plan Risk Risk Perform Risk Implement Risk Risk Monitoring
Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register
Plan Risk Response
Plan risk response strategies
Delegated to:
✓ A Risk Owner (RO) (who is responsible for taking appropriate actions)
✓ An appropriate number of Risk Co-Owners (RCO) (who assist the RO)
RO and RCO are responsible for:
➢ Identifying options for managing the risk
➢ Presenting the options to the PM (or their delegate) for approval
➢ Preparing contingency/fallback plans for appropriate options
➢ Implementing any activities that are required
Risk Response Strategies
For negative risks For positive risks:
▪ Avoid – Eliminate threats to protect the ▪ Accepting the risk & helping to make it
project happen
▪ Transfer – Shift the risk to another party ▪ Exploiting the opportunity
▪ Control – Manage variables that lead to ▪ Sharing the risk – so the impact is increased
the risk
▪ Enhancing the risk to increase its positive
▪ Mitigate – take steps to reduce the impact impact
▪ Accept – Understand the risk & only take
action if it happens
Risk Response – Contingency Plans
• A plan with predefines actions to be taken if an identified risk event occurs
CONTINGENCY PLAN (PLAN A)
Contingency Identification Number 1001
Description of Potential Problem Failure of a critical functionality (Key feature not working as it should)
Trigger point User reports consistent errors when attempting to use the functionality
Probability Currently low (due to minimal customisation and use of experienced development team)
Main impact of potential problem Negative impact could be very high
Response Actions Technical Diagnosis: The technical team will perform a thorough diagnosis, reviewing logs, code, and
configurations.
Vendor Communication: Immediately contact the vendor for support and escalate the issue as needed.
Consequences of implementing (1) Schedule Delay
this contingency (2) Eliminate potential failure in the future after go-live
Communication Plan Update the project team and users
Recovery Procedures Verify that the functionality is fully restored. Test data integrity and system stability. Document root
cause and steps taken to resolve the issue. Move to Fallback Plan 2001 if 1001 fails
Risk Response – Fallback Plans
• Plan for an alternative course of action if the primary plan or approach
fails. These are action plans if the Contingency Plan fails/or cannot be achieved
(Normally linked to the Contingency Plan)
FALLBACK PLAN (PLAN B)
Contingency Identification Number 2001
Description of Potential Problem Failure to restore functionality
Probability and impact Currently low
Main impact of potential problem Business process interruption (halt essential workflow and loss of access to
information)
Solution for the problem Utilise the SaaS platform’s originally intended functionality if the functionality was
customised
Rollback to the stable version
Consequences of this approach Scope and schedule impacts / Cost impacts / Contract impacts
Preparation Identify costed options for alternative feature
Activation Activate if 1001 fails
Workaround
✓ Workaround is unplanned
responses to unforeseen risk
events that must be done without
pre-planning to ensure the project
can continue
✓ a temporary or alternative solution
used after a risk has occurred (or
is about to occur) to keep work
moving
✓ It is reactive, not preventive.
Reserves / Allowances
Reserves are provisions in the project schedule or budget
set aside to address identified or unidentified risks.
• Money (or time) set aside to manage/cover
risks/changes
RESERVES
• Two categories are typical: (CONTINGENCY /
MANAGEMENT)
• Contingency (typically included in the Baseline) –
Known Unknowns (known risks)
• Management (normally not included in the Baseline) –
Unknown Unknowns (unknown risks)
Typically set as a percentage value in the initial cost modelling – It influences profit
Quik Question
What is the difference between the Fallback plan, (2)
Contingency plan, and (3) Workarounds?
Risk Management Process
Plan Risk Risk Perform Risk Implement Risk Risk Monitoring
Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register
Risk Monitoring, Control and Review
This is an iterative and ongoing process to:
• Track risks & status
• identify changes in risk profiles/situation
• evaluate the effectiveness of risk responses
• implement/modify appropriate management strategies
You are answering the question: “Are our risks changing, and
are our responses working?”
Risk Monitoring, Control and Review
Example: In an IT project, a known risk is supplier delay
• Monitoring involves regularly checking delivery milestones, supplier
performance reports, and early warning signs of slippage
• Control actions include activating contingency plans, reallocating resources,
and engaging an alternative supplier
• Review involves noting which risks occurred, what controls worked or failed,
and whether risk exposure is increasing or reducing
Risk Monitoring, Control and Review
• What is the difference between risk monitoring, risk control,
and risk review?
• Monitoring is observational, which means you do not change the
plan but watch what is happening.
• Control is action-oriented; hence observe limits and change what
the project or organisation does.
• Review is reflective and evaluative; hence it focuses on learning
and improvement (adjust accordingly)
What We Covered
• What risk means and why risk management is important
• Risk management principles, framework, and process
• Risks Identification
• Sources and categories of risk
• Risk identification techniques
• Risks Analysis (qualitative & quantitative methods)
• Risk response planning (response strategies, contingency & fallback
plans)
• Risk monitoring, control, and review
Revision Questions
• Explain the difference between individual risk and overall project risk.
• Why is effective risk management critical to project success? What does it mean that risk management is an
iterative process?
• What is the difference between positive risks (opportunities) and negative risks (threats)? Provide two
examples of positive risks and two examples of negative risks in an ICT project.
• What are residual risks and secondary risks? How do they arise?
• What is risk appetite, risk tolerance, and risk capacity? How do these three influence project decision-
making?
• Given a high-impact, high-probability risk, what actions should a project manager take?
• What techniques can project managers use to analyse risks qualitatively – when there is no ned to quantify
risk?
• A software development project is halfway through implementation when a key developer resigns
unexpectedly. The project schedule is tight, and replacing the developer will increase costs. Question: What
type of risk has occurred (residual, secondary, or realised risk)? What immediate risk response or
workaround should the project manager apply to keep the project on track?
Useful Resources
Essential:
• Schwalbe, K. (2018). Information technology project management. Cengage.
[Chapter 11]
Thank you
ANY QUESTION