0% found this document useful (0 votes)
4 views60 pages

Topic09-Risk Management 2026

This document outlines the principles and processes of managing project risk, emphasizing the importance of effective risk management for project success. It covers risk identification, analysis, response strategies, and monitoring, along with key concepts such as risk appetite, tolerance, and capacity. The document also highlights various techniques for risk identification and categorization, ensuring comprehensive risk management throughout the project lifecycle.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views60 pages

Topic09-Risk Management 2026

This document outlines the principles and processes of managing project risk, emphasizing the importance of effective risk management for project success. It covers risk identification, analysis, response strategies, and monitoring, along with key concepts such as risk appetite, tolerance, and capacity. The document also highlights various techniques for risk identification and categorization, ensuring comprehensive risk management throughout the project lifecycle.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Topic 9: Managing Project Risk

Lecture
Learning Objectives
At the end of this topic, you should be able to:
• Define risk and explain why effective risk management is critical to project
success
• Identify common sources of risk in ICT projects
• Outline the risk identification process and describe its key outputs, including the
RBS, Risk Register, Top Ten Risks, etc.
• Describe the main components of risk management planning
• Differentiate between qualitative and quantitative risk analysis techniques
• Apply risk factor calculations and develop probability–impact matrices
• Explain how tools such as decision trees, simulation, and sensitivity analysis can
be used in risk analysis
• Provide examples of risk response strategies with practical examples
• Describe the processes involved in risk monitoring and control
What is a Risk?
Individual Risk is defined as:
• ‘an uncertain event or condition that, if it occurs, has a
positive or negative effect on one or more project
What is objectives’
Risk Project (Overall) Risk is defined as:
Management? • ‘the effect of uncertainty on the project as a whole…
more than the sum of the individual risks within a
project… & represents the exposure of stakeholders to
the implications of variations in project outcomes’
A Risk Event occurs when that risk happens

Source: PMBoK 6th Edn


What is Risk Management?

Risk management is …
• An iterative process for identifying,
How does this analysing, handling (responding to) and
fit with other monitoring/controlling risks.
aspects of • Each facet of Risk Management must be
your project planned and applied consistently
throughout a project

Sources: Chapman & Ward (2003); Kerzner & Kerzner (2017); Cleden (2017); Kleim & Ludin (2019)
Risk Management – Principles,
Framework, and Process
✓ Managing Risks is guided Risk
Management
by principles, framework, Principles
and processes, according
to ISO31000:2018

Risk Risk
Management Management
Framework Process

Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Management Principles

What does good risk • RM is customised to organisational


management look like? context
• RM should create value • RM considers human and cultural
factors (considers human behaviour
• RM is integrated in organisational and org culture)
activities and decision making
• RM is transparent and inclusive
• RM is structured and comprehensive (involves stakeholders)
(uses a systematic approach)
• RM is dynamic (responsive to change,
• RM is based on the best valuable uncertainty and emerging risks)
information (historical data,
experience, and forward-looking) • RM involves continuous improvement
(through experience and learning)
ISO 31000:2018 – 8 Principles of Risk Management
Risk Management Framework
How do you ensure risk management is consistently applied,
supported, and reviewed?
• Leadership and commitment
• Top management must lead and support
• Define risk ownership and accountability
• Design a framework for risk management
• Define risk policies, accountability, and competence, allocate resources for RM, internal and external
communication, and reporting
• Integrate RM in all processes – governance, strategy, planning
• Implement risk management (apply risk principles and processes consistently)
• Evaluate – assess whether risk management is effective
• Continuously improve – enhance risk practices based on feedback and performance
Risk Management Process
How is risk actually managed?
1. Plan Risk Management. Communicate, consult, and document how risk
management activities will be managed in the project
2. Identify Risks. Detecting possible risks – what could happen? How and why
could it happen?
3. Analyse Risks. Determining the likelihood and effect of risks through
Qualitative and Quantitative methods
4. Risk Responses
• Plan Risk Response. Developing options & actions to reduce/manage the risks appropriately
• Implement Risk Responses. Take appropriate steps to manage/treat risks
5. Monitor Risks. Track risks and controls, detect changes and emerging risks
Risk Management Process

Plan Risk Risk Perform Risk Implement Risk Risk Monitoring


Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register
Plan Risk Management
• Create your Risk Management Plan (RMP) Risk Management Plan
for the project
Table of Contents
• May vary, but often includes the following:
Definitions………………………………
• Risk Identification
• Risk Categories/Types (Risk Breakdown Structure) Project Background……………..............
• Risk register Risk Identification………………..............
• Risk Management Organisation (Roles & Responsibilities)
• Risk Analysis Risk Analysis……………………..............
• Risk matrix (Likelihood and Impact) Risk Responses…………………………
• Risk Management Methodology (Tools, approaches, etc)
Risk Monitoring and Control………….
• Tolerances and Limits (General Principles)
• Risk Responses
• Budget (Funds for risk management)
Plan Risk Management
• Define and document risk limits – risk capacity, risk appetite, and risk tolerances
• Risk appetite is explicitly considered
• Risk tolerances are established for:
• Cost
• Schedule What do
• Scope
• Quality these mean?
• Risk capacity is acknowledged (often implicitly) when deciding:
• Level of risk management effort
• Escalation thresholds
• Authority limits
• These will influence your risk management plan, risk categories, and your
definition of risk levels (high/medium/low risk) and response strategies
Risk Capacity
✓ Risk Universe. All of the possible Risk Universe

High
risks that could affect a project or
entity

Risk Profile
✓ Risk Profile. An analysed indicator
of the level of risk for a project/task Risks beyond

RISK
capacity
Risks within
✓ Risk Capacity. The expected ability capacity

Risk Capacity
of the organisation (team) to manage
the associated risks

Low
The capacity is influenced by the organisation’s Limit to capacity
(team’s) Appetite and Tolerance for risk
Low REWARD High

Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Appetite
✓ Risk Appetite. The amount and Risk Universe

High
types of risks that an organisation is Hungry/
Seeking
willing to take to meet strategic
objectives – Can be classified as…
• Averse. Avoids risk & uncertainty
• Minimal. Will take some minimal
risks if the reward is very high

RISK
Open

• Cautious. Will take some risks if


there are clear rewards & controls
• Open. Willing to take risks if
Cautious
there is a chance of strong reward
• Hungry/Seeking. Actively
chasing risk for high reward Minimal

Low
Averse

Low REWARD High

Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Tolerance
Risk Universe

High
✓ Risk Tolerance. The specific Hungry/
maximum risk that an organisation Seeking

is willing to take regarding each

Limit
Risk
relevant risk
✓ This is defined by:

Target
RISK
Open

Risk
• Risk Profile (risk level, known-
unknowns & unknown unknowns)
• Risk Appetite (how far are they willing
to go to achieve the objective)

Risk Profile
Cautious
• Risk Target (the optimal level of risk that
organisation wants to take)
• Risk Limit (identified thresholds beyond
Minimal
which risks should not deviate)

Low
Averse

Low REWARD High


Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Defining Risk Limits
Defining Risk Limits. These can be numeric or ordinal
Element Very Low Limit Low Limit Moderate Limit High Limit Very High Limit
% Difference in Outcome <= %2.5 2.5% - 5% 5% - 7.5% 7.5% - 10% > 10%
NUMERIC

Cost (what is acceptable) Very small increase Small increase Significant increase Significant increase Large increase
(<5% of profit) (< 10% of profit) (< 20% of profit) (< 40% of profit) (< 60% of profit)
Scope (what is acceptable) Barely noticeable Minor noticeable Some significant Numerous Very significant
changes changes scope changes significant scope changes in scope
ORDINAL

changes required
Time (Schedule) (what is No change to key Minor changes but Minor change to Significant change Very significant
acceptable) milestones not for end date end date to end date change to end date

Quality (what is acceptable) Quality variance Only affects very Differences would Differences would Does not meet key
barely noticeable intensive use be noticeable be very noticeable requirements

✓ These have to be agreed by the key stakeholders (formally)


Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018) &
[Link]
Quik Question

What is the difference between an organisation’s Risk


Appetite and its Risk Tolerance?
Risk Management Process
Plan Risk Risk Perform Risk Implement Risk Risk Monitoring
Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register
Risk Identification
• An ongoing process of identifying potential risks that could affect the project and
documenting them in a Risk Register
• Use different risk identification techniques
• Recognise different types of risks
• Threats (negative risks)
• Opportunities (positive risks)
• Recognise the different sources of risk
• Recognise different categories of risk – use a risk breakdown structure (RBS)
• An RBS is a hierarchically organised framework that categorises potential project risks by source, helping
teams identify and manage risks more effectively.
• Focuses on where risks come from
• Ensures comprehensive risk identification so nothing is overlooked
Risk Identification – Key Sources of
Risk
Schedule flaws, Failing Significant Cost Inability to meet requirements,
Poorly controlled Differences unrealistic expectations
changes in scope to meet schedule due
to complications (Financial Losses)

Scope Schedule Cost Quality Value

Not knowing
what is at stake ProjectIntegration
Project Development Lifecycle
Management
(the risks)

Risk Communicati Project


Risk
Manageme Complexity Stakeholders
on Team
nt
Disagreements /conflict, user
People, technology, Key people leaving, team culture, involvement
Communication lack of executive support, project
uncertainties, ambiguity gaps management, and contractors
Risk Identification – Risk Categories
Consider the different categories/dimensions of risk
Internal/Direct External/Environmental
 Structure/Process/Method  PEST (Political, Economic,
 Technical/System Social, Technology)
 Stakeholder & Comms  Market Forces/Competitors
 Financial/Costs  Clients (Demands/Usage/etc.)
Guide: Risk Management
Risk Management Guidelines Vocabulary
APPLY DIRECT CONTROLS OFTEN LITTLE CONTROL
Risk Assessment Techniques

Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Identification – Positive and Negative
Risks

✓ Risks can be positive or negative

Positive risks open up opportunities


They are handled by:
✓ Accepting the risk & helping to make it happen
✓ Exploiting the opportunity
✓ Sharing the risk – so the impact is increased
✓ Enhancing the risk to increase its positive impact

Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Positive and Negative Risks

✓ Risks can be positive or negative


Negative risks are problems/threats
They are managed with these strategies:
✓ Avoid – Eliminate the threat to protect the project
✓ Transfer – Shift the risk to another party
✓ Control – Manage variables that lead to the risk
✓ Mitigate – take steps to reduce the impact
✓ Accept – Understand the risk & only take action if it happens

Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Risk Identification – Realised, Residual and
Secondary Risks

✓ Realised Risk. Risk that has occurred and


become an actual problem, incident, or issue RISK
RISK
RISK
RISK

CONTROLS
✓ Residual Risks. Risks that remain after all of
the management strategies have been
implemented
Residual Risk RISK

✓ Secondary Risks. Risks created by


implementing the risk response/ management
Sources: ISO 31000: 2018; ISO 73:2009; IEC 31010:2019; Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
Quiz Question

What is the difference between Positive Risks and


Negative Risks?
Risk Identification Techniques
• Risk identification tools and techniques include:
• Brainstorming
• Talking to stakeholders (interviews, discussions & Management by Walking
Around (MBWA))
• Expert judgment (Consultation or Workshopping)
• SWOT analysis (generally best done as a workshop)
• Delphi Technique (uses experts who provide anonymous inputs to help avoid
Groupthink)
• Lessons learned from previous projects
• Risk breakdown structure (for categorisation of sources of risks)
• Once risks are identified, enter the content in a Risk Register
Sources: Schwalbe (2018); Scherling (2016); Fraser, Fraser & Simkins (2010); Oliveira, et al. (2018)
The Delphi Approach
Choose a Facilitator
1. Choose a facilitator (must have an open mind)
2. Identify & engage the experts who will be used (they Identify & Engage the
Experts
must understand the issues from different
perspectives)
Define the Problem
3. Define the problem and develop questions (and develop Questions)

4. Send Questions (send questions & get responses)


Send Questions
5. Analyse Responses (develop more focused (Analyse and develop clarifiers)
questions as needed and do Step 4 again as
appropriate (typically 2 or 3 times)) Analyse Responses
(Develop more focussed
6. Once the issues are clarified, identify actions attention)

Identify Contingencies &


Fallbacks

Sources: Schwalbe (2018); [Link]


Risk Breakdown Structure (RBS)
• Another fundamental approach to identifying project risks
• RBS is a tool for categorising project risks
• Develop your RBS in a stakeholder workshop - use these
steps:
• Identify the categories & dimensions of risk associated with this
project (makes it easier to identify risks)
• For each category/dimension of risk
• Identify what has gone wrong in the past
• Identify what could go wrong in the future for this project
Risk Breakdown Structure
It can be depicted graphically like this…

Processes & Technology & Stakeholders &


Finance & Cost Market & Client
Methods Systems Comms

Team Data Team


Debt Funding PEST
Structure Dynamics
Mobile
Team Team Comms Cashflow Competitors
Methods Meetings from Beta
Networks Entry Threats
Communicati Team
Reserves
on Workshops
Buyer Power
SaaS
Etc… Performance
Coordination
Management Substitution
Provider
Cloud Beta Tester Suppliers
Etc…
Engagement
Etc…..
Etc… Etc…
Risk Breakdown Structure (… or like this)
… or it can be depicted in a table like this…
LEVEL 0 LEVEL 1 LEVEL 2 LEVEL 3
Team responsibilities not well defined
Team dynamics
Poor balance of resources & expertise
Stakeholders & Comms
Changing/unclear requirements
Customer/client
Low client engagement
Project Risk Unmet expectations
Client application
Poor quality code
Technology Supplier delivery issues
Data center Poorly designed data systems
Natural disasters (fires or floods)
Risk Register
• Different organisations use different formats. Common elements
are provided in the example…
• Records all identified risks related to a
project
• Providing details of the risk (Description)
• Providing risk ownership (Risk Owner)
• Provides estimation of risk impact
• Prioritises risk Use the format
• Identifies risk response plans (avoided, mandated by
transferred, controlled, mitigated, or your
accepted) organisation
Risk Management Process
Plan Risk Risk Perform Risk Implement Risk Risk Monitoring
Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register

Perform Qualitative Risk Analysis and/or Quantitative risk analysis


(if required) … and prioritise risks to guide your risk responses
Qualitative Risk Analysis

• Assessing the likelihood and impact of identified risks


(determine their magnitude and priority for control) using relative
descriptive scales rather than numerical values

• Common techniques include:

Can be used jointly


• Probability/Impact matrices
• Expert judgment *Which risks matter most
• Risk categorisation and need attention?
• Top Ten Risk Item Tracking

Let’s look at each of these techniques in turn


Probability/Impact Matrix
• Used to assess
• the probability of occurrence of an identified risk and
• the impact of a risk event
• Often used to identify risk factors (a numeric Severity Weighting)
• A severity weighting is a numerical value assigned to represent how serious
the consequences of a risk are if that risk occurs.
• Severity weighting is commonly used in:
• Risk scoring models, such as Failure Mode and Effects Analysis (FMEA), Risk
matrices (probability × impact)
• Risk prioritisation and monitoring tools such as the top ten risk item tracking
Probability/Impact Matrix
IMPACT OF OCCURRENCE PROBABILITY OF OCCURRENCE
Low (1) Medium (3) High (5) High Major uncertainty remains
(5) No or little prior experience or data/information
Very
PROBABILITY OF OCCURRENCE

Moderate Significant infrastructure, systems & resources not in place


High High Risk High
(5) Risk (5x3=15) Medium Some uncertainties remain
(5x1=5) Risk
(5x5=25) (3) Some experience and data/information exists
Infrastructure, systems, resources in place but not complete

Medium Moderate Low Few uncertainties remain


Low Risk High Risk
(3) (3x1=3)
Risk (3x5=15) (1) Significant experience and data/information exist
(3x3=9) Infrastructure, systems & resources in place

Low Very Low


Low Risk
Moderate IMPACT OF OCCURRENCE
(1) Risk (1x3=3)
Risk High Performance, technical, quality, costs or safety impacts can
(1x1=1) (1x5=5) (5) result in major injury, redesign/program delay

Very High – Escalate & resolve quickly Medium Performance, technical, quality, costs or safety impacts can
WHAT TO DO

(3) result in injury, or significant redesign/program delay


High – Proactive steps ASAP
Moderate – Manage with caution Low Performance, technical, quality, costs and safety impacts are
Low – Proceed but monitor (1) likely to be minimal & requirements should still be met
Very Low – Monitor but little risk
Probability/Impact Matrix
Typically, more detailed guidance is provided (such as the table in the RMP)
Score Definition/Actions to be taken
Very High Anything classified as Very High indicates that this risk is extremely or very likely to occur. Additionally, the occurrence could have a
(25) profound impact on the project’s safety, technical, cost, and/or schedule, which may cause the project to be terminated or can cause
significant cost/schedule changes (e.g. increases of more than 5 percent) for the project. The management of this level of risk should be
escalated, and that aspect of the project must be implemented with extreme care until the risks can be mitigated/controlled effectively.
High Risk High Risks may cause significant safety, technical, cost, and/or schedule increases (e.g. increases of 2 to 5 percent) for the project. These
(15) risks are to be managed proactively, and a priority must be applied to mitigate/control the risks as soon as practicable. In the meantime,
the elements of the project associated with this risk must be managed with due care.
Moderate This refers to risks that are Moderate, because they may have a relatively small but significant impact on the project’s safety, technical,
Risk cost, and/or schedule (e.g. less than 2 percent). Appropriate mitigation/control strategies should be implemented when practicable.
(5 or 9) Obviously, risks with a score of nine (9), should be addressed with higher priority than those with a score of (5). While awaiting
mitigation/controls to be implemented, the team should still manage this aspect of the project with care.
Low Risk A Low Risk refers to an event that is relatively unlikely to occur, or the impact would be low if it did occur. In other words, this refers to
(3) situations in which the combination of likelihood and impact means that this risk would not be expected to have a significant impact on
the project’s safety, technical, cost and/or schedule. Typically, consolidated risk management is not applied to these types of risks.
However, the team associated with this aspect should keep it in mind while implementing the project and monitor the issue with an
appropriately level of caution.
Very Low Risk A Very Low Risk refers to matters where it would be unlikely for the risk to occur and even if it did, the impact is expected to be minimal.
(1) In these circumstances, consolidated risk management would not be applied. However, as with all aspects of Risk Management, those
involved with the project should continue to monitor evolving levels of risk and take proactive action when considered appropriate.
Quantitative Risk Analysis

• Numerically evaluating the combined effect of identified risks


on project objectives, such as cost or schedule.
• This entails using different techniques to help quantify risks -
How much risk do we have, in numbers (quantified exposure)?
• Some of these techniques include:
• Decision tree analysis & Expected Monetary Value (EMV)
• Simulation (e.g., Monte-Carlo)
• Sensitivity Analysis (e.g., What-If analysis) Let’s look at EMV
Expected Monetary Value (EVM) Analysis
• EMV is a technique for evaluating decisions under uncertainty
by combining possible outcomes, probabilities, and impacts.
• calculates the average expected outcome of uncertain events by weighting
each possible outcome by its probability
• EMV applies the decision tree approach to determine the most
appropriate course of action (e.g. for risk/reward analysis)
• Decision Tree Analysis is a visual and analytical technique used to evaluate
different decision options and their possible consequences under
uncertainty
• EMV answers: “On average, what is the financial impact of this
decision?”
EMV – example of a Decision Tree
This is a variation that allows costed
Numerical estimate
options to be assessed – discussed of risk exposure
further in Topic 9 Workshop Possible outcomes

Options Delivered Monetary


Chance Node
successfully Outcome
Decision
Custom-Build
Risk Event System
Node
(Decision Trigger) Moderate rework Monetary
Contingency Chance Node
required Outcome
Implement New
Decision
System Smooth Monetary
Chance Node
implementation Outcome
Decision
Buy Commercial
System
Node Configuration Monetary
Fallback Chance
issuesNode Outcome
Risk Simulation
• Uses mathematical modeling and
random sampling to evaluate risk
parameters and variables to • Simulation answers
determine impact on project questions like
outcomes • What is the probability of
finishing the project on time?
• Simulation determines things like:
• What is the likely cost range,
• The scope of the risk not just a single estimate?
• Risk probability (likelihood) • How much contingency
• Risk impact (cost, time, etc.) reserve is needed?
• Which variables will likely be most • Which risks contribute most
important (what do we need to watch?) to uncertainty?
• The risk limits that should be set
• Contingency (known unknowns)
Risk Simulation
• A common approach applies Monte Carlo Simulation,
which uses a range of variables to:
• Determine the most likely effect of variable changes across a range of
circumstances (multiple run analysis)
• Define/apply three outcome estimates (most pessimistic, most likely, most
optimistic)
• Apply the probability of the most likely being between in the
optimistic/pessimistic range (to create a numeric weighting model)
• Develop Quantitative risk parameters (Probability, Impact, Risk level, etc.)

Often this is linked to Sensitivity Analysis


Sensitivity Analysis
• Examines how changes in individual risk variables affect a project
objective (such as cost, schedule, or performance).
• Allows specific variables to be manipulated directly to determine the
likely outcomes
• It is beneficial for ‘what if’ analysis
• Such models are built explicitly for likely high-impact risks (both + & -)
• Can be used to
• Predict the likely completion date of a project
• Predict the likely final cost of the project
• Determine which risks have the highest impact on the project

Determines key risk drivers


How Does Monte Carlo Analysis Work?
STEP 1 Define the problem and which aspects of the project to analyse? Cost, schedule,
performance, resources, etc

STEP 2 Determine input variables and their distribution. Such variables include task durations,
cost estimates, resource availability, probability, and impact scores for each risk

STEP 3 Create a Monte Carlo simulation model using Excel Add-ins e.g. @RISK, statistical
software packages, or dedicated Monte Carlo simulation software e.g., RiskyProject

STEP 4 Run the simulation and analyse results

STEP 5 Validate the accuracy of your results by comparing them with actual project data or
historical data from similar projects

Understanding the Monte Carlo Analysis in Project Management - Project Management Academy Resources
Risk Analysis Software
• Use a Monte Carlo Excel Add-in (pick one) – for example
• @RISK
• ModelRisk
• CrystalBall
• These vary in technical complexity, capabilities, reporting and presentation, trial
versions, pricing
• Statistical packages such as R and Python (statistical libraries)

Source: [Link]
Risk Prioritisation – Top Ten Risk Item
Tracking (TTRR)
• Uses Severity Scores/Risk Exposure to identify the Top 10 risks (or
sometimes more)
• A Prioritised List of Risks
1. Identify risks
2. Estimate the probability and impact of each risk (realistically)
3. Calculate Risk Exposure (multiply probability by impact – see previous slide
36)
4. Sort risks from highest to lowest exposure, and select the Top Ten
5. Allocate risk owners
• Monitor and update the listing as appropriate (e.g. monthly or when
new risks are identified)
• Remember: you need to assess/monitor/control all identifiable risks
Risk Management Process
Plan Risk Risk Perform Risk Implement Risk Risk Monitoring
Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register
Plan Risk Response

Plan risk response strategies


Delegated to:
✓ A Risk Owner (RO) (who is responsible for taking appropriate actions)
✓ An appropriate number of Risk Co-Owners (RCO) (who assist the RO)

RO and RCO are responsible for:


➢ Identifying options for managing the risk
➢ Presenting the options to the PM (or their delegate) for approval
➢ Preparing contingency/fallback plans for appropriate options
➢ Implementing any activities that are required
Risk Response Strategies

For negative risks For positive risks:


▪ Avoid – Eliminate threats to protect the ▪ Accepting the risk & helping to make it
project happen
▪ Transfer – Shift the risk to another party ▪ Exploiting the opportunity
▪ Control – Manage variables that lead to ▪ Sharing the risk – so the impact is increased
the risk
▪ Enhancing the risk to increase its positive
▪ Mitigate – take steps to reduce the impact impact
▪ Accept – Understand the risk & only take
action if it happens
Risk Response – Contingency Plans
• A plan with predefines actions to be taken if an identified risk event occurs
CONTINGENCY PLAN (PLAN A)

Contingency Identification Number 1001

Description of Potential Problem Failure of a critical functionality (Key feature not working as it should)

Trigger point User reports consistent errors when attempting to use the functionality

Probability Currently low (due to minimal customisation and use of experienced development team)

Main impact of potential problem Negative impact could be very high

Response Actions Technical Diagnosis: The technical team will perform a thorough diagnosis, reviewing logs, code, and
configurations.
Vendor Communication: Immediately contact the vendor for support and escalate the issue as needed.
Consequences of implementing (1) Schedule Delay
this contingency (2) Eliminate potential failure in the future after go-live
Communication Plan Update the project team and users

Recovery Procedures Verify that the functionality is fully restored. Test data integrity and system stability. Document root
cause and steps taken to resolve the issue. Move to Fallback Plan 2001 if 1001 fails
Risk Response – Fallback Plans
• Plan for an alternative course of action if the primary plan or approach
fails. These are action plans if the Contingency Plan fails/or cannot be achieved
(Normally linked to the Contingency Plan)
FALLBACK PLAN (PLAN B)
Contingency Identification Number 2001
Description of Potential Problem Failure to restore functionality
Probability and impact Currently low
Main impact of potential problem Business process interruption (halt essential workflow and loss of access to
information)
Solution for the problem Utilise the SaaS platform’s originally intended functionality if the functionality was
customised
Rollback to the stable version
Consequences of this approach Scope and schedule impacts / Cost impacts / Contract impacts
Preparation Identify costed options for alternative feature
Activation Activate if 1001 fails
Workaround

✓ Workaround is unplanned
responses to unforeseen risk
events that must be done without
pre-planning to ensure the project
can continue
✓ a temporary or alternative solution
used after a risk has occurred (or
is about to occur) to keep work
moving
✓ It is reactive, not preventive.
Reserves / Allowances
Reserves are provisions in the project schedule or budget
set aside to address identified or unidentified risks.
• Money (or time) set aside to manage/cover
risks/changes
RESERVES
• Two categories are typical: (CONTINGENCY /
MANAGEMENT)
• Contingency (typically included in the Baseline) –
Known Unknowns (known risks)
• Management (normally not included in the Baseline) –
Unknown Unknowns (unknown risks)

Typically set as a percentage value in the initial cost modelling – It influences profit
Quik Question

What is the difference between the Fallback plan, (2)


Contingency plan, and (3) Workarounds?
Risk Management Process

Plan Risk Risk Perform Risk Implement Risk Risk Monitoring


Management Identification Analysis Responses and Control
Determine Identify different Use different Develop strategies Track identified risks
approaches to risk sources of risk techniques to to address risks Identify emerging
identification and Identify different analyse probability Implement risk risks
analysis categories of risk and impact responses Evaluate the
Define risk limits: Create a risk Qualitative risk Risk response effectiveness of
Risk capacity, risk breakdown structure analysis actions responses
appetite, and risk Quantitative risk
tolerance Use different risk Risk status report,
identification analysis updated risk
Plan risk responses techniques Prioritise Risks register, Lessons
Develop a risk learned
Create a risk
management plan register
Risk Monitoring, Control and Review

This is an iterative and ongoing process to:


• Track risks & status
• identify changes in risk profiles/situation
• evaluate the effectiveness of risk responses
• implement/modify appropriate management strategies

You are answering the question: “Are our risks changing, and
are our responses working?”
Risk Monitoring, Control and Review

Example: In an IT project, a known risk is supplier delay


• Monitoring involves regularly checking delivery milestones, supplier
performance reports, and early warning signs of slippage
• Control actions include activating contingency plans, reallocating resources,
and engaging an alternative supplier
• Review involves noting which risks occurred, what controls worked or failed,
and whether risk exposure is increasing or reducing
Risk Monitoring, Control and Review

• What is the difference between risk monitoring, risk control,


and risk review?
• Monitoring is observational, which means you do not change the
plan but watch what is happening.
• Control is action-oriented; hence observe limits and change what
the project or organisation does.
• Review is reflective and evaluative; hence it focuses on learning
and improvement (adjust accordingly)
What We Covered
• What risk means and why risk management is important
• Risk management principles, framework, and process
• Risks Identification
• Sources and categories of risk
• Risk identification techniques
• Risks Analysis (qualitative & quantitative methods)
• Risk response planning (response strategies, contingency & fallback
plans)
• Risk monitoring, control, and review
Revision Questions
• Explain the difference between individual risk and overall project risk.
• Why is effective risk management critical to project success? What does it mean that risk management is an
iterative process?
• What is the difference between positive risks (opportunities) and negative risks (threats)? Provide two
examples of positive risks and two examples of negative risks in an ICT project.
• What are residual risks and secondary risks? How do they arise?
• What is risk appetite, risk tolerance, and risk capacity? How do these three influence project decision-
making?
• Given a high-impact, high-probability risk, what actions should a project manager take?
• What techniques can project managers use to analyse risks qualitatively – when there is no ned to quantify
risk?
• A software development project is halfway through implementation when a key developer resigns
unexpectedly. The project schedule is tight, and replacing the developer will increase costs. Question: What
type of risk has occurred (residual, secondary, or realised risk)? What immediate risk response or
workaround should the project manager apply to keep the project on track?
Useful Resources

Essential:
• Schwalbe, K. (2018). Information technology project management. Cengage.
[Chapter 11]
Thank you
ANY QUESTION

You might also like