0% found this document useful (0 votes)
16 views5 pages

Effective Project Risk Management Guide

The document outlines the process of risk management, distinguishing between reactive and proactive approaches, as well as informal and formal methods. It emphasizes the importance of a Risk Management System (RMS) for enhancing organizational capacity to handle risks and improving internal transparency. Additionally, it references international standards like ISO 31000 and PMI's PMBOK Guide, providing a structured framework for systematic project risk management through various stages including risk identification, analysis, evaluation, and response.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views5 pages

Effective Project Risk Management Guide

The document outlines the process of risk management, distinguishing between reactive and proactive approaches, as well as informal and formal methods. It emphasizes the importance of a Risk Management System (RMS) for enhancing organizational capacity to handle risks and improving internal transparency. Additionally, it references international standards like ISO 31000 and PMI's PMBOK Guide, providing a structured framework for systematic project risk management through various stages including risk identification, analysis, evaluation, and response.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Project risk Day2

Risk management
Risk management is a process of dealing with risks.
It may be implemented reactively or proactively and informally or formally.

A risk is managed reactively when something happens on a project and the relevant
stakeholder takes action to deal with the post-event consequences.

Risks are managed proactively when the stakeholder gives timely and deliberate consideration
to the possibility of particular events occurring during its involvement with the project.

Informal approaches to managing risks imply that the actions are reactive, decided upon on the
spur of the moment, and unrelated to any pre-planning.

Formal approaches, in contrast, derive from policies and procedures that have been that have
been considered well ahead and are appropriately planned for, resourced, and budgeted.

Risk Management System (RMS)


A systematic approach to risk management increases the capacity of an organization to handle
risks at all levels.

Where it is implemented uniformly, it promotes internal transparency and common


understanding of the business activities of the organization and facilitates the establishment
and growth of a commitment and culture
Having a formal RMS in place simplifies the organizational capture, transformation, and transfer
of risk knowledge towards managing risks.

It provides the means for assessing best practice, for benchmarking risk management
performance, and for establishing a platform that permits the benefits of modern information
and communication technology to be exploited.

Within a stakeholder organization, congruence between the organization's objectives and the
project objectives can be confirmed, or any conflict between them quickly identified.

Trust and confidence between the levels of management, and between management and
operatives, are improved.

Responsibilities are clarified, and ownership of responsibility is more willingly accepted.


Potential problems are exposed to a wider internal audience.
The organization's capacity to deal with new risks is enhanced.

Risk Management Standards and Guides


The international standard for risk management, ISO 31000 (ISO 2018), promotes a framework
for risk management that is substantially similar to those offered by many texts.

The origins of this standard lie in Australia and New Zealand, where the Australian
Standard/New Zealand Standard (AS/NZS) standard 3931, Risk Analysis of Technological
Systems - Application Guide (1998), provided a starting point.

This standard was aimed principally at the chemical engineering industry, and its focus was
mainly upon analytical techniques for assessing risks in the operating phase of production
facilities.

The Project Management Institute's (PMI) A Guide to the Project Management Book of
Knowledge (2013; hereafter, PMBOK Guide) offers a six-point plan for project risk management:
 Plan risk management
 Identify risks
 Perform qualitative risk analysis
 Perform quantitative risk analysis
 Plan risk response
 Control risks

The ISO 31000 (2018) guide is also a good starting point as a partial framework for systematic
risk management. It comprises five stages:
 Establish the context
 Identify risks
 Analyze risks
 Evaluate risks
 Treat risks

A Cycle of Systematic Project Risk Management


Systematic risk management is a dynamic process of activities intended to deal with project
risks.

When the process includes the deliberate capture of risk knowledge from a project, it becomes
a learning activity in addition to its management function.

If the process, together with the acquired knowledge, is then applied to subsequent projects, it
becomes a learning cycle.

Explanation
Establish the Context: Contextualizing a project firmly establishes its role and significance to the
organization (the internal context) and its place in the wider environment or society (the
external context).

Thorough contextualization will also expose the internal and external drivers which will shape
or influence the project risks that are identified.

Identify the Risk: For risks to be managed systematically, they must first be identified.
Otherwise, these risks are unknown (or at least unrecognized), and unanticipated future events,
should they occur, may have to be dealt with in purely reactive manner.
Analyze Risks: This stage marks the first of the actual assessment activities in the risk
management cycle.

Generally, a project stakeholder, besides wanting to know the risks they face, also wish to gain
an appreciation of how severe the threat risks are or how beneficial opportunity risks might be.

The analysis, among other things, involves examination of the likelihood of the risk event
occurring and the nature and magnitude of the subsequent consequences of that event for the
project (and thus the stakeholder).

Evaluate Risks: The evaluation process focuses on the level of risk in terms of the magnitude of
the potential severity or benefit.

Respond to Risks: Also known as the risk treatment stage, at this point each evaluated risk
(usually in highest rank order) is explored in terms of possible treatment or response options.

Monitor and Control Risks: The project moves from a planning phase to implementation
activities deliberately intended to bring it eventually to a stage where it can begin its
operational life.

Capture Project Risk Knowledge: An organization committed to implementing systematic risk


management on its projects will have directed valuable resources towards doing so.
Explanation
(Part 1) corresponds to Stages B (Risk Identification), C1 (Risk Analysis), and C2 (Risk Evaluation)
of the risk management cycle.

(Part 2 of the PRR template) covers Stages D (Risk Response) and E (Risk Monitoring and
Control) in the cycle.

Row allocation in the two tables has been restricted here to 10 risks, but when used as a
spreadsheet the row entry capacity is almost limitless for practice purposes.

The 'Severity' column data can be sorted to group risks of similar severity.

You might also like