AARJSH VOLUME 3 ISSUE 6 (JUNE 2016) ISSN : 2278 – 859X
The use of data of low precision, for instance, if a risk is not well understood may lead to a
qualitative risk analysis of little use to the project team. If a ranking of data precision is
deficient, better data gather is required.(1)
Outputs from Qualitative Risk Analysis
Overall Risk Ranking: Risk ranking will help to indicate the overall risk position relative to
other risks by comparing the risk scores. It can be used to assign personnel or other
I. Resources to risk types with different risk rankings, to make a benefit-cost analysis
decision about the project, or to support a recommendation for project strategy.
II. List of Prioritized Risks: Risks and conditions may be prioritized by their group category
(low, moderate, high etc) at a detailed level, perhaps at the lowest WBS level. Risks may also
be grouped by those that require an immediate response and those that can be handled at a
later date. Cost, schedule, functionality, scope and quality risks may be assessed separately
with different ratings. Significant risks should have a description of the basis for the assessed
probability and impact.
III. List of Risks for Additional Analysis and Management: Risks classified as high or
moderate would be prime candidates for further analysis, including Quantitative Risk
Analysis, and for risk management action.
Quantitative Risk Analysis
The quantitative risk analysis process aims to analyse numerically the probability of each risk
and of its impact on project objectives as well as the extent of overall project risk. This
process uses techniques such as decision tree analysis, value quantification and simulation to:
a) Determine the probability of not achieving a specific project objective.
b) Quantify the risk exposure for the project and determine the size of cost and time
contingency reserves that may be needed.
c) Identify risks requiring the most attention by quantifying their relative contribution to
project risk.
d) Identify realistic and achievable cost, time, quality or scope targets.
Quantitative risk analysis generally follows the Qualitative Risk Analysis. The qualitative and
quantitative risk analysis processes can be performed separately or sequentially.
Considerations of time and budget availability and the need for qualitative or quantitative
statements about risks and impacts will determine which method(s) to use.
Inputs to Quantitative Risk Analysis
i. Risk Management Plan;
ii. Identified Risks;
iii. List of Prioritised Risks;
iv. List of Risks for Additional Analysis and Management;
v. Historical Information: Information on prior, similar completed projects, studies of
similar projects by risk specialists, and risk databases that may be available from industry or
proprietary sources;
Asian Academic Research Journal of Social Sciences & Humanities
[Link]
261
AARJSH VOLUME 3 ISSUE 6 (JUNE 2016) ISSN : 2278 – 859X
vi. Expert Judgment: Input may come from the project team, other subject matter experts in
the organisation, and from others outside the organisation. Other sources of information
include engineering or statistical experts;
vii. Other Planning Inputs: Some helpful planning inputs are the project logic and duration
estimates used in determining programmes, the WBS listing of all cost elements with cost
estimates, and models of project technical objectives.
Tools and Techniques for Quantitative Risk Analysis
Interviewing: Interviewing techniques are used to quantify the probability and impact of
risks on project objectives. A risk interview with project parties and subject matter
I. Experts can be the first step in quantifying risks. Documenting the rationale of the risk
ranges is an important component of the risk interview because it can lead to effective
strategies for risk response.
II. Decision tree analysis: A decision analysis is usually structured as a decision tree. The
decision tree is a diagram that describes a decision under consideration and the implications
of choosing one or another of the available routes. It incorporates probabilities of risks and
the costs or rewards of each logical path of events and future decisions. Solving the decision
tree indicates which decision yields the greatest expected value to the decision-maker when
all the uncertain implications, costs, rewards and subsequent decisions are quantified. An
example of a decision tree is shown in Figure 3.
III. Simulation: A project simulation uses a model that translates the uncertainties specified
at a detailed level into their potential impact on objectives that are expressed at the level of
the total project. For a cost risk analysis, a simulation may use the project WBS as its model.
For a program risk analysis, the Critical Path Method (CPM) may be used. .(7)
Outputs from Quantitative Risk Analysis
I. Prioritized List of Quantified Risks: This list of risks includes those posing the greatest
threat or presenting the greatest opportunity to the project together with a measure of their
impacts.
II. Probabilistic Analysis of the Project: Forecasts of potential project programme and cost
results listing the possible completion dates or project duration and costs with their associated
confidence levels. A similar approach is available for the evaluation of contract strategy.
III. Probability of Achieving the Project Cost and Time Objectives: The probability of
achieving the project objectives under the current plan and with the current knowledge of the
risks facing the project can be estimated.
RISK RESPONSE PLANNING
Risk Response Planning is the process of developing options and determining actions to
enhance opportunities and to reduce threats to the projects objectives. It includes the
identification and assignment of individuals or parties to take responsibility for each agreed
risk response. This process ensures that identified risks are properly addressed. The
effectiveness of response planning will directly determine whether risk increases or decreases
for the project.
Asian Academic Research Journal of Social Sciences & Humanities
[Link]
262
AARJSH VOLUME 3 ISSUE 6 (JUNE 2016) ISSN : 2278 – 859X
Risk Response Planning must be appropriate to the severity of the risk, cost-effective in
meeting the challenge, timely to be successful, realistic within the project context and agreed
upon by all parties involved. Selecting the best risk response from several options is required.
Decision Tree Analysis
Decision Definition Decision Node Chance Node Net Path Value
(Probability and
(Decision Name) (Cost of the Decision) (Probability and Payoff)
Payoff - Cost)
Strong 65% 0
200 80
Retail Complex FALSE Product Demand
-120 41.5
Weak 35% 0
90 -30
Single or dual use? Decision
49
Strong 65% 0.65
120 70
Retail/Office Complex TRUE Product Demand
-50 49
Weak 35% 0.35
60 10
Figure 1: Decision Tree Analysis (Illustrative view
Inputs to Risk Response Planning
I. List of Prioritised Risks from Qualitative Risk Analysis;
II. Overall Risk Ranking;
III. Prioritised List of Quantified Risks from Quantitative Risk Analysis;
IV. Probabilistic Analysis of Individual Cost, Time, Scope & Quality Ratings;
V. Probability of Overrunning the Project Cost and Time Objectives;
VI. List of Potential Responses: In the risk identification process, actions may be identified
that respond to individual risks or categories of risks;
VII. Risk Thresholds: The level of risk that is acceptable to the Employer will influence risk
response planning;
VIII. Risk Owners: A list of project parties able to act as owners of appropriate risk
responses. Risk owners should be involved in developing the risk responses;
IX. Common Risk Responses: Several risks may be driven by a common cause. This
situation may reveal opportunities to mitigate two or more risks with one generic response
[1].
Asian Academic Research Journal of Social Sciences & Humanities
[Link]
263
AARJSH VOLUME 3 ISSUE 6 (JUNE 2016) ISSN : 2278 – 859X
Tools and Techniques for Risk Response Planning
Several risk response strategies are normally available. The strategy that is most likely to be
effective should be selected for each risk. Then, specific actions should be developed to
implement that strategy. Primary and backup strategies may be selected.
I. Avoidance: Risk avoidance is changing the project plan to eliminate the risk or condition
or to protect the project objectives from its impact. The project team can never eliminate all
risks, but some specific risks may be avoided.
Some risk causes that arise early in the project can be dealt with by clarifying requirements,
obtaining information, improving communication, or acquiring expertise. Reducing scope to
avoid high-risk activities, adding resources or time, adopting a familiar approach instead of
an innovative one, or avoiding an unfamiliar subcontractor are some examples of avoidance.
II. Transfer: Risk transfer is seeking to transfer the impact of a risk to a third party together
with ownership of the response. Transferring the risk does not eliminate it, but simply gives
another able-bodied party responsibility for its management.
III. Mitigation: Mitigation seeks to reduce the probability and/or impact of a risk to below
an acceptable threshold. Taking early action to prevent a risk from occurring is more
effective than trying to repair the consequences after it has occurred. Mitigation costs should
be appropriate given the likely impact and probability of the risk.
Risk mitigation may take the form of implementing a new course of action that will reduce
the problem, e.g. adopting less complex processes, conducting more engineering tests, or
choosing a more stable supplier. It may involve changing conditions so that the probability of
the risk occurring is reduced, e.g. adding resources or time to the programme. It may require
prototype development to reduce the risk of scaling up from a bench scale model.
Where it is not possible to reduce probability, a mitigation response might address the risk
impact by targeting linkages that determine the impact severity. For example, designing
redundancy into a subsystem may reduce the impact that results from a failure of the original
component.
IV. Acceptance: This option indicates that the project team/owner has decided not to change
the project plan to deal with a risk that may occur or is unable to identify any other suitable
response strategy. Active acceptance may include developing a contingency plan to execute
should the risk occur. Passive acceptance requires no action, leaving the project team to deal
with the risks if and when they occur.
A contingency plan is always useful for risks that may arise during the project. Developing a
contingency plan in advance can greatly reduce the impact of an event should the risk occur.
Risk triggers, such as start dates and other intermediate milestones, will be monitored by the
Master Programme and construction sub-programmes.
A „fallback plan‟ may be developed if the risk has a high impact or if the selected strategy
may not be fully effective, hence the confidence-level of a solution strategy is vital to manage
residual and secondary risks. This might include allocation of a risk contingency amount,
development of alternative options or changing project scope.
The most usual risk acceptance response is to establish a contingency allowance (Expected
Monetary Value), or reserve, including amounts of time or resources to account for impacts.
Asian Academic Research Journal of Social Sciences & Humanities
[Link]
264
AARJSH VOLUME 3 ISSUE 6 (JUNE 2016) ISSN : 2278 – 859X
For the risks that have been accepted any allowances should be determined by the risk
consequences, computed at an acceptable level of risk exposure. (1)
Outputs from Risk Response Planning
I. Risk Response Plan: The risk response plan should be written to the level of detail at
which the actions will be taken. It should include some or all of the following: -
a) Identified risks, their description, the area of the project affected (e.g. programme); their
causes and how they may affect project objectives;
b) Risk owners and assigned responsibilities;
c) Results from the qualitative and quantitative risk analysis processes;
d) Agreed responses including avoidance, transference, mitigation or acceptance for each
risk in the management plan;
e) The level of residual risk expected to be remaining after the strategy is implemented;
f) Specific responses to implement the chosen strategy;
g) Budget and times for responses;
h) Contingency plans and fallback plans.
II. Residual Risks: Residual risks are those that remain after the first line of defence
(mitigation), i.e. risk avoidance, transfer or mitigation responses have been taken. They also
include minor risks that have been accepted and addressed, e.g. by adding contingency
amounts to the cost or time allowable.
III. Secondary Risks: Risks that arise as a direct result of implementing a second level of
defence (contingency plan) are termed secondary risks. These should be identified and
responses planned for.
IV. Contractual Agreements: Contractual agreements may specify each parties
responsibility for specific risks should they occur, in order to avoid or mitigate threats.
V. Contingency Reserve Amounts Needed: The probabilistic analysis of the project and the
risk thresholds help the project team determine the amount of buffer or contingency needed to
reduce the risk of overruns of project objectives to a level acceptable to the project owner.
VI. Inputs to Other Processes: Most responses to risk involve allocation of additional time,
cost or resources and require changes to the project plan. Project owners will require
assurance that spending is justified for the level of risk reduction.
VII. Inputs to Revised Project Plan Incorporating Risk Responses: A new plan will require
further risk management, which is an iterative process.
RISK MONITORING AND CONTROL
Risk monitoring and control:
a) Is the process of keeping track of the identified risks, monitoring residual risks and
identifying new risks, ensuring the execution of risk plans and evaluating their effectiveness
in reducing risk;
b) Records risks that are associated with implementing contingency plans;
Asian Academic Research Journal of Social Sciences & Humanities
[Link]
265