10-10-2024
Term V: Project Management
Session 7: Managing Risk
Prof. Rohit Gupta
Operations Management Area
Email: rohitg@[Link]
Where We Are Now
1
10-10-2024
Risk Management Process
Risk Defined:
An uncertain event or condition that, if it occurs, has a positive or negative effect on project
objectives such as scope, schedule, cost, or quality.
No amount of planning can overcome or control risk.
Risk Management
The Risk Management is a systematic approach used in project management to identify,
assess, and mitigate risks that could impact the project's success.
What can go wrong (risk event)?
How to minimize the risk event’s impact (consequences)?
What can be done before an event occurs (anticipation)?
What to do when an event occurs (contingency plans)?
Risk Event Graph
Chances of Risk Occurring (Risk Exposure)
The risk curve begins high in the early stages of the
project (Defining and Planning) and decreases as the
project progresses through the Executing and
Delivering phases. By the end of the project, this risk is
low.
This reflects that at the start of the project, uncertainty
is high. There are many unknowns regarding
requirements, resources, timelines, etc. As the project
moves forward, risks are identified, analyzed, and
mitigated, thus reducing the overall chance of risks
occurring as the project advances.
Cost to Fix Risk Event (Impact of Risks)
The cost to fix risk curve begins low at the start of the project but increases over time, reaching its peak in the Executing and
Delivering phases. By the end of the project, the cost to fix risks is very high.
This reflects the increasing cost and difficulty of addressing risks as the project progresses. At the beginning (Defining and
Planning stages), changes are cheaper and easier to implement because the project is still in the conceptual phase. However,
as the project moves to execution, fixing a risk (or an issue caused by a risk) becomes more complex and costly due to the
integration of various project components, resource allocation, and timeline constraints.
2
10-10-2024
Practical Implications for Project Managers
Early Risk Mitigation is Key: Since the cost to fix risks grows over time, identifying
and addressing risks in the early stages of a project is much more cost-effective than
waiting until execution or later stages.
Proactive Risk Management: Early risk identification and mitigation plans should be
emphasized, as fixing risks later on becomes significantly more resource-intensive.
Balancing Risk and Cost: Understanding this relationship helps project managers
balance the need for early investment in risk management against the potential cost of
addressing risks later in the project.
Change Management: Effective change management processes can help keep costs
down by ensuring that risks are mitigated early and that changes are well-managed
throughout the project life cycle.
The Risk Management Process
The goal of this step is to recognize all potential risks that could affect the
project. These can include risks related to scope, schedule, cost, resources,
technology, stakeholders, and external factors.
This step involves evaluating each identified risk to determine how likely it is
to happen and how severe its impact would be on project objectives. It also
assesses how controllable the risk is, based on existing resources and
mitigation strategies
In this step, a strategy is created for each significant risk, aiming to either
reduce the probability of the risk occurring or minimize its impact if it does.
Contingency plans are also developed to deal with risks that cannot be
completely avoided or mitigated.
This step involves executing the risk responses and monitoring risks
throughout the project life cycle. The risk environment is dynamic, meaning
that as the project progresses, new risks can emerge, and existing risks can
change in priority.
3
10-10-2024
Step 1: Risk Identification: Risk Breakdown Structure (RBS)
A Risk Breakdown Structure (RBS) is a hierarchical framework used in project management to systematically organize
and categorize potential risks to a project.
The RBS is similar in structure to a WBS. A WBS breaks down project deliverables and tasks while RBS breaks down
risks into different types and sources.
Example: RBS for Software Development Project
Level 1: Main Categories
1. Technical Risks
2. Project Management Risks
3. Organizational Risks
4. External Risks
Level 2: Subcategories
[Link] Risks 3. Organizational Risks
1.1. Technology Obsolescence 3.1. Resource Availability
1.2. Software Integration Issues 3.2. Team Attrition
1.3. System Requirements Changes 3.3. Internal Communication Failures
1.4. Performance Issues 3.4. Stakeholder Conflicts
2. Project Management Risks 4. External Risks
2.1. Scope Creep 4.1. Market Changes
2.2. Schedule Delays 4.2. Regulatory Changes
2.3. Cost Overruns 4.3. Supplier Issues
2.4. Poor Quality Control 4.4. Environmental Factor
4
10-10-2024
Risk Identification: Risk Profile
The Risk Profile technique is a structured approach used in project management for identifying and assessing risks. It
involves creating a detailed set of questions, criteria, or checklists that guide the project team in identifying potential risks
specific to a particular project or industry.
Risk Profile for Product Development Project
Technical Requirements: Quality:
Are the requirements stable? Are quality considerations built into the design?
Design: Management:
Does the design depend on unrealistic or optimistic Do people know who has authority for what?
assumptions? Work Environment:
Testing: Do people work cooperatively across functional
Will testing equipment be available when needed? boundaries?
Development: Staffing:
Is the development process supported by a compatible set of Is staff inexperienced or understaffed?
procedures, methods, and tools? Customer:
Schedule: Does the customer understand what it will take to
Is the schedule dependent upon the completion of other complete the project?
projects? Contractors:
Budget: Are there any ambiguities in contractor task
How reliable are the cost estimates? definitions?
Step 2: Risk Assessment
Scenario Analysis is a valuable technique for assessing risks in project management in terms of the probability
of an event (likelihood of occurrence) and its impact.
Project risk need to be evaluated in terms of the likelihood the event is going to occur and the impact or
consequences of its occurrence.
Example of a Likert Scale for Likelihood of Risk Occurrence
Likelihood Rating Description Probability (%) Interpretation
Almost no chance of the risk Unlikely; risk is very
1: Very Low 0-10%
occurring rare
Small chance of
2: Low Risk is unlikely but possible 11-30%
occurrence
Risk could occur under certain Possible, but not highly
3: Moderate 31-50%
conditions probable
Likely occurrence in the
4: High Risk is likely to occur 51-70%
project
Almost guaranteed to
5: Very High Risk is almost certain to occur 71-100%
occur
10
5
10-10-2024
Impact Scale of Risk on Major Project Objectives
The impact scale of project risk measures the severity of the consequences if the risk occurs.
Impact
Project 1 2 3 4 5
Objective Very Low Low Moderate High Very High
Insignificant cost < 10% cost 10% to 20% cost 20% to 40%
Cost > 40% cost increase
increase increase increase cost increase
Insignificant time < 5% time 5% to 10% time 10% to 20%
Time > 20% time increase
increase increase increase time increase
Scope reduction
Scope decrease Minor areas of Major areas of Project end item is
Scope unacceptable to
barely noticeable scope affected scope affected effectively useless
sponsor
Only very Quality
Quality Quality reduction
demanding reduction Project end item is
Quality degradation barely requires sponsor
applications are unacceptable to effectively useless
noticeable approval
affected sponsor
11
Example: A 1-10 Impact Scale for Risk Assessment
Impact Impact on Cost, Time, Scope, or
Description General Consequences
Rating Quality
No measurable change in cost, time, or
1 Negligible impact No noticeable disruption
quality
2 Minimal impact Minor, less than 2% change Easily managed, barely noticeable
3 Very low impact Slight cost or time increase (2-5%) Very little disruption, minor adjustments
4 Low impact Small cost or time increase (5-10%) Minor issues that are easy to control or fix
5 Moderate-low impact Noticeable impact, but within tolerance Moderate rework or adjustments required
Moderate increase in cost or time (10- Some disruption, requires active
6 Moderate impact
20%) management
Major effort required to mitigate and
7 High-moderate impact Significant impact on key deliverables
manage
Serious impact (20-40% cost or time Significant delays or overruns, quality
8 High impact
increase) issues
Severe impact, major cost or time Critical project objectives at risk,
9 Very high impact
increases (> 40%) substantial rework
Project may fail or require complete
10 Catastrophic impact Project-threatening impact
overhaul
12
6
10-10-2024
Risk Assessment Form
A Risk Assessment Form in project management is a structured tool used to identify, evaluate, and document the risks
associated with a project. It helps project teams assess the likelihood of risks occurring, their potential impact on the project,
and prioritize them for appropriate management.
Construction of Risk Assessment Form
Example: Risk assessment form for Operating System Upgrade
Risk Event Likelihood Impact Detection
Risk Event Likelihood Impact When
Difficulty
Interface problems 4 4 Interface problems 4 4 4 Conversion
System freezing 2 5 System freezing 2 5 5 Start-up
User backlash 4 3 Post
User backlash 4 3 3
Hardware installation
1 5
malfunctioning Hardware
1 5 5 Installation
malfunctioning
Detection Difficulty: It is a measure of
how easy it would be to detect risk activity.
When: At what stage or process that risk
activity is going to happen.
13
Risk Severity Matrix
A Risk Severity Matrix is a project management tool used to evaluate and prioritize risks by combining two critical factors:
Likelihood of occurrence of risk and Impact (Severity).
The matrix helps project teams visually assess risks and determine which risks need immediate attention and which can be
monitored or accepted.
Risk Severity Matrix for OS Upgrade
Green (Low Risk): Risks in the low-risk zone (e.g., low
likelihood and low impact) that require little attention.
Yellow (Medium Risk): Risks that have moderate likelihood
and/or impact and need to be monitored.
Red (High Risk): Risks with a high likelihood and/or impact
that require immediate attention and management.
14
7
10-10-2024
Failure Mode and Effect Analysis (FMEA)
FMEA is a more detailed and systematic approach to identifying, assessing, and mitigating risks.
It originated in the manufacturing and engineering sectors but is widely used in project management for
risk assessment.
FMEA assesses risks based on three key dimensions:
[Link] Severity: The seriousness of the effects of a failure (similar to "Impact" in the Risk Severity
Matrix).
[Link]: The likelihood that the failure will happen (similar to "Likelihood" in the matrix).
[Link] difficulty: The likelihood that the failure will be detected before it causes harm (we get the
ratings of each activity from Risk Assessment Form)
𝑅𝑖𝑠𝑘 𝑃𝑟𝑖𝑜𝑟𝑖𝑡𝑦 𝑁𝑢𝑚𝑏𝑒𝑟 𝑅𝑃𝑁 = 𝐼𝑚𝑝𝑎𝑐𝑡 × 𝑂𝑐𝑐𝑢𝑟𝑟𝑒𝑛𝑐𝑒(𝑃𝑟𝑜𝑏𝑎𝑏𝑖𝑙𝑖𝑡𝑦) × 𝐷𝑒𝑡𝑒𝑐𝑡𝑖𝑜𝑛
15
Step3: Risk Response Development
Risk Response Development is the process of creating strategies and action plans to manage identified risks in a
project. The goal is to develop proactive approaches to minimize the negative impact of risks or capitalize on
opportunities.
Mitigating Risk:
Reducing the likelihood that the event will occur.
Reducing the impact that the adverse event would have on the project.
Avoiding Risk:
Changing the project plan to eliminate the risk or condition.
Transferring Risk:
Passing risk to another party.
Examples: Fixed-price contracts, insurance.
Escalating Risk:
Notifying the appropriate people within the organization of the threat.
Retaining Risk:
Making a conscious decision to accept the risk of an event occurring.
16
8
10-10-2024
Contingency Planning
Contingency Plan
Is an alternative plan that will be used if a possible foreseen risk event becomes a reality.
Is a plan of action that will reduce or mitigate the negative impact of the risk event.
Is not a part of the initial implementation plan and only goes into effect after the risk event is
recognized.
Consequences of the absence of a contingency plan
Cause a manager to delay or postpone the decision to implement a remedy.
Lead to panic and acceptance of the first remedy suggested.
Make the decision making under pressure which can be dangerous and costly.
17
Risk Response Matrix
A Risk Response Matrix is a tool used in project management to systematically document and plan how to
respond to identified risks.
Construction of Risk Response Matrix
Risk Event: The specific risk that might impact the project. This could include issues like delays,
equipment failure, team member turnover, or regulatory changes.
Response: The planned response strategy to manage or mitigate the risk. This is the primary course of
action the team will take to handle the risk if it occurs.
Contingency Plan: A backup plan that will be activated if the primary response fails or the risk
materializes. It is a secondary action to control the impact of the risk.
Trigger: The specific condition or event that will initiate the response or contingency plan. This helps the
team know when to take action.
Who Is Responsible: The person or role assigned to monitor and manage the risk, ensuring that the
response and contingency plan are implemented when necessary.
18
9
10-10-2024
Example: Risk Response Matrix
Contingency Who Is
Risk Event Response Trigger
Plan Responsible
Interface Mitigate: Test Work around Not solved
Nils
problems prototype until help comes within 24 hours
System Mitigate: Test Still frozen
Reinstall O S Emmylou
freezing prototype after one hour
Mitigate:
Increase staff Call from top
User backlash Prototype Eddie
support Management
demonstration
Mitigate: Select
Equipment reliable vendor Order
Equipment fails Jim
malfunctions Transfer: replacement
Warranty
19
Step 4: Risk Response Control
Risk Response Control is the process of implementing risk management strategies, monitoring risks,
and making necessary adjustments to the risk management plan throughout a project.
Risk Register:
Details all identified risks, including descriptions, category, probability of occurring, impact,
responses, contingency plans, owners, and current status.
Risk Control involves:
Executing the risk response strategy.
Monitoring triggering events.
Initiating contingency plans.
Watching for new risks.
Establishing a Change Management System:
Monitoring, tracking, and reporting risk.
Fostering an open organization environment.
Repeating risk identification/assessment exercises.
Assigning and documenting responsibility for managing risk.
20
10