PROJECT RISK
MANAGEMENT
WHAT IS PROJECT RISK MANAGEMENT
Project risk management includes the processes of conducting risk
management planning, identification, analysis, response planning, and
controlling risk on a project. The objectives of project risk management
are to increase the likelihood and impact of positive events, and
decrease the likelihood and impact of negative events in the project
WHY IS PROJECT RISK MANAGEMENT
IMPORTANT?
Risk management is a very important part of project management because it can
exponentially increase the chances of a project's successful outcome. Developing
and sticking to a project management plan is extremely beneficial as it:
• Assists you in avoiding major disasters.
• Increases your revenue by lowering your costs
• Ensures successful project completion
• Gives you a competitive advantage
• Increases a sense of accountability and responsibility
• Assists you in discovering new possibilities
Risk management is inseparable from the cost, schedule and quality of the project.
Consequently, it has to be a key component of the project management process.
PROJECT RISK MANAGEMENT PROCESSES
1) Plan Risk Management
2) Identify Risks
3) Perform Qualitative Risk Analysis
4) Perform Quantitative Risk Analysis
5) Plan Risk Responses
6) Control Risks
[Link] RISK MANAGEMENT
• Plan Risk Management is the process of defining how to conduct risk
management activities for a project. The key benefit of this process is
it ensures that the degree, type, and visibility of risk management are
commensurate with both the risks and the importance of the project
to the organization.
• The inputs, tools and techniques, and outputs of this process are
depicted
No INPUT
1 Project Management Plan In planning risk management, all approved subsidiary management plans and baselines
should be taken into consideration in order to make the risk management plan consistent
with them. The risk management plan is also a component of the project management
plan. The project management plan provides baseline or current state of risk-affected
areas including scope, schedule, and cost.
2 Project Charter The project charter can provide various inputs such as high-level risks, high-level project
descriptions, and high-level requirements.
3 Stakeholder Register The stakeholder register, which contains all details related to the project’s stakeholders,
provides an overview of their roles.
4 Enterprise Environmental Factors The enterprise environmental factors that can influence the Plan Risk Management
process include, but are not limited to, risk attitudes, thresholds, and tolerances that
describe the degree of risk that an organization will withstand.
5 Organizational Process Assets The organizational process assets that can influence the Plan Risk Management process
include, but are not limited to:
▪ Risk categories,
▪ Common definitions of concepts and terms,
▪ Risk statement formats,
▪ Standard templates,
▪ Roles and responsibilities,
▪ Authority levels for decision making, and Lessons learned.
No TOOLS AND TECHNIQUES
1 Analytical Techniques Analytical techniques are used to understand and define the overall risk management
context of the project. Risk management context is a combination of stakeholder risk
attitudes and the strategic risk exposure of a given project based on the overall project
context. For example, a stakeholder risk profile analysis may be performed to grade and
qualify the project stakeholder risk appetite and tolerance.
2 Expert Judgment To ensure a comprehensive establishment of the risk management plan, judgment, and
expertise should be considered from groups or individuals with specialized training or
knowledge on the subject area, such as:
Senior management,
Project stakeholders,
Project managers who have worked on projects in the same area (directly or through
lessons learned),
Subject matter experts (SMEs) in business or project area,
Industry groups and consultants, and
Professional and technical associations.
3 Meetings Project teams hold planning meetings to develop the risk management plan. Attendees
at these meetings may include the project manager, selected project team members and
stakeholders, anyone in the organization with responsibility to manage the risk planning
and execution activities, and others, as needed.
OUTPUTS
PLAN RISK MANAGEMENT
The risk management plan is a component of the project management plan and describes
how risk management activities will be structured and performed. The risk management
plan includes the following:
• Methodology. Defines the approaches, tools, and data sources that will be used to
perform risk management on the project.
• Roles and responsibilities. Defines the lead, support, and risk management team
members for each type of activity in the risk management plan, and clarifies their
responsibilities.
• Budgeting. Estimates funds needed, based on assigned resources, for inclusion in the
cost baseline and establishes protocols for application of contingency and management
reserves.
• Timing. Defines when and how often the risk management processes will be performed
throughout the project life cycle, establishes protocols for application of schedule
contingency reserves, and establishes risk management activities for inclusion in the
project schedule.
Plan Risk Management: Inputs, Tools & Techniques, and Outputs
[Link] RISKS
Identifying risks basically involves recognizing potential treats or under
uncertainties that may impact project objectives.
The inputs, tools and techniques, and outputs of this process are depicted
IDENTIFYING RISKS
▪ Understanding and identifying potential risks is crucial for effective risk management.
▪ By proactively identifying risks, we can anticipate challenges and take appropriate measures to mitigate them.
METHOD OF RISKS IDENTIFICATIONS
▪ Brainstorming: Engage stake holders in a collaborative discussions to identify potential risks across various
aspects of the projects.
▪ SWOT Analysis: Evaluate strengths, Weaknesses, Opportunities, and Threats to uncover internal and external
risks
IMPORTANCE OF EARLY RISKS IDENTIFICATION
▪ Early identification allows for timely mitigation actions, reducing the likelihoods and impact of potential risks.
▪ It enables better decision better decision making and resource allocation, leading to more efficient project
execution.
▪ Ultimately, proactive risks identification enhances project success and project against unforeseen setbacks.
3. PERFORM QUALITATIVE RISK ANALYSIS
• Qualitative risks analysis basically involves assessing risks based on their
probability and impact
• It helps prioritize risks and determine which ones require further attention and
mitigation.
The Inputs, tools and techniques, and outputs of this process
STEPS FOR QUALITATIVE RISKS ANALYSIS
[Link] identification: Identify potential risks that may affect project
objectives or outcomes.
[Link] Assessment : Evaluate each risks based on its likeliwood of
occurrence and potential impact.
[Link] prioritization: Ranks risks according to their significance,
focusing those with highest probabilities and impact.
[Link] Response Planning: Develop mitigation strategies for high-
priority risks to minimize potential impact
BENEFITS OF QUALITATIVE RISKS ANALYSIS
• Provides a systematic approach for understanding and managing
project risks.
• Enables informed decision-making by identifying key risks and their
potential consequences
• Facilitate communication and collaboration among project
stakeholders, fostering proactive risk management culture.
4. PERFORM QUANTITATIVE RISK ANALYSIS
Perform Quantitative Risk Analysis is the process of numerically
analyzing the effect of identified risks on overall project objectives. The
key benefit of this process is that it produces quantitative risk
information to support decision making in order to reduce project
uncertainty.
The inputs, tools and techniques, and outputs of this process
PERFORM QUANTITATIVE RISK ANALYSIS: INPUTS
1 Risk Management Plan The risk management plan provides guidelines, methods, and tools to
be used in quantitative risk analysis.
2 Cost Management Plan The cost management plan provides guidelines on establishing and
managing risk reserves.
3 Schedule Management Plan The schedule management plan provides guidelines on establishing
and managing risk reserves.
4 Risk Register The risk register is used as a reference point for performing
quantitative risk analysis.
5 Enterprise Environmental Factors Enterprise environmental factors may provide insight and context to
the risk analysis, such as:
▪ Industry studies of similar projects by risk specialists, and
▪ Risk databases that may be available from industry or proprietary
sources.
6 Organizational Process Assets The organizational process assets that can influence the Perform
Quantitative Risk Analysis process include information from prior,
similar completed projects.
Control Risks: Tools and Techniques
Risk Reassessment Control Risks often results in identification of new risks, reassessment of current
risks, and the closing of risks that are outdated. Project risk reassessments should be
regularly scheduled.
Risk Audits Risk audits examine and document the effectiveness of risk responses in dealing with
identified risks and their root causes, as well as the effectiveness of the risk
management process.
Variance and Trend Analysis For the purposes of controlling risks, trends in the project’s execution should be
reviewed using performance information. Earned value analysis and other methods
of project variance and trend analysis may be used for monitoring overall project
performance. Outcomes from these analyses may forecast potential deviation of the
project at completion from cost and schedule targets.
Technical Performance It requires the definition of objective, quantifiable measures of technical
Measurement performance, which can be used to compare actual results against targets.
Reserve Analysis Reserve analysis compares the amount of the contingency reserves remaining to the
amount of risk remaining at any time in the project in order to determine if the
remaining reserve is adequate.
Meetings Project risk management should be an agenda item at periodic status meetings. The
amount of time required for that item will vary, depending upon the risks that have
been identified, their priority, and difficulty of response.
PERFORM QUANTITATIVE RISK ANALYSIS: OUTPUTS
Project Documents Updates
Project documents are updated with information resulting from quantitative risk analysis.
For example, risk register updates could include:
▪ Probabilistic analysis of the project. Estimates are made of potential project schedule and
cost outcomes listing the possible completion dates and costs with their associated
confidence levels.
▪ Probability of achieving cost and time objectives. With the risks facing the project, the
probability of achieving project objectives under the current plan can be estimated using
quantitative risk analysis results.
▪ Prioritized list of quantified risks. This list includes those risks that pose the greatest
threat or present the greatest opportunity to the project.
▪ Trends in quantitative risk analysis results. As the analysis is repeated, a trend may
become apparent that leads to conclusions affecting risk responses.
5. PLAN RISK RESPONSES
• Plan Risk Responses is the process of developing options and actions to enhance
opportunities and to reduce threats to project objectives. The key benefit of this
process is that it addresses the risks by their priority, inserting resources and
activities into the budget, schedule and project management plan as needed.
• The inputs, tools and techniques, and outputs of this process
PLAN RISK RESPONSES: INPUTS
[Link] management plan [Link] Register
Important components of risk management plan includes: • Refers to identified risks
• Roles and Responsibilities • Root causes of risks
• List of potential responses
• Risk analysis definitions
• Risk owners
• Timing for reviews
• Symptoms and warning signs
• Risk threshold for low, moderate, and high risks
• Relative rating or priority list of project risks
Risk thresholds help identify those risks for which specific • Risks requiring responses in the near terms
responses are needed
• Risks for additional analytics and response
• Trends in qualitative analysis results
• A watch list, which is a list of low-priority risks within the
risk register
[Link] for negative risks or [Link] for positive risks or
threats opportunities
• Three strategies dealing with risks or threats are
• Three of the four responses are suggested to deal
AVOID, TRANSFER and MITIGATE. The fourth
with risks with potentially positive impacts on
strategy is ACCEPT. This can be used for negative
project objectives. The fourth strategy, accept, can
risks and threats or positive risks or opportunities.
be used for negative risks or threats as well as
• Each of these strategies have varied and unique positive risks or opportunities. These strategies,
influence on the risk condition. These strategies described below, are to exploit, share, enhance,
should be chosen to match the risks probability and accept
and impact on the project’s overall objectives.
• Avoidance and mitigation strategies are usually
good strategies for critical risks with high impact,
while transference and acceptance are usually
good strategies for threats that are less critical and
with low overall impact
PLAN RISK RESPONSES: TOOLS AND TECHNIQUES
1 Strategies for Three strategies dealing with risks or threats are AVOID, TRANSFER and MITIGATE. The fourth strategy is
negative risks or ACCEPT. This can be used for negative risks and threats or positive risks or opportunities.
threats Each of these strategies have varied and unique influence on the risk condition. These strategies should be
chosen to match the risks probability and impact on the project’s overall objectives.
Avoidance and mitigation strategies are usually good strategies for critical risks with high impact, while
transference and acceptance are usually good strategies for threats that are less critical and with low overall
impact.
2 strategies for Three of the four responses are suggested to deal with risks with potentially positive impacts on project
positive risks or objectives. The fourth strategy, accept, can be used for negative risks or threats as well as positive risks or
opportunities opportunities. These strategies, described below, are to exploit, share, enhance, and accept.
3 Contingent Some responses are designed for use only if certain events occur. For some risks, it is appropriate for the
response strategies project team to make a response plan that will only be executed under certain predefined conditions, if it is
believed that there will be sufficient warning to implement the plan. Events that trigger the contingency
response, such as missing intermediate milestones or gaining higher priority with a supplier, should be
defined and tracked. Risk responses identified using this technique are often called contingency plans or
fallback plans and include identified triggering events that set the plans in effect.
4 Expert judgement Expert judgment is input from knowledgeable parties pertaining to the actions to be taken on a specific and
defined risk. Expertise may be provided by any group or person with specialized education, knowledge, skill,
experience, or training in establishing risk responses.
PLAN RISK RESPONSES: OUTPUTS
[Link] management plan updates 2. Project document updates
Elements of the project management plan that In the Plan Risk Responses process, several project documents
may be updated as a result of carrying out this are updated as needed. For example, when appropriate risk
process include, but are not limited to: responses are chosen and agreed upon, they are included in
the risk register. The risk register should be written to a level
▪ Schedule management plan.
of detail that corresponds with the priority ranking and the
▪ Cost management plan. planned response. Often, the high and moderate risks are
▪ Quality management plan. addressed in detail. Risks judged to be of low priority are
included in a watch list for periodic monitoring. Updates to
▪ Procurement management plan. the risk register can include:
▪ Human resource management plan. ▪ Risk owners and assigned responsibilities
▪ Scope baseline ▪ Agreed-upon response strategies
▪ Specific actions to implement the chosen response
▪ Schedule baseline. strategy
▪ Cost baseline ▪ Trigger conditions, symptoms, and warning signs of a risk
occurrence
▪ Budget and schedule activities required to implement the
chosen responses
[Link] RISKS
Control Risks is the process of implementing risk response plans, tracking identified
risks, monitoring residual risks, identifying new risks, and evaluating risk process
effectiveness throughout the project. The key benefit of this process is that it
improves efficiency of the risk approach throughout the project life cycle to
continuously optimize risk responses.
The inputs, tools and techniques, and outputs of this process are depicted
CONTROL RISKS: INPUTS
1 Project Management Plan The project management plan, which includes the risk management plan,
provides guidance for risk monitoring and controlling
2 Risk Register The risk register has key inputs that include identified risks and risk owners,
agreed-upon risk responses, control actions for assessing the effectiveness of
response plans, risk responses, specific implementation actions, symptoms
and warning signs of risk, residual and secondary risks, a watch list of low-
priority risks, and the time and cost contingency reserves. The watch list is
within the risk register and provides a list of low-priority risks.
3 Work Performance Data Work performance data related to various performance results possibly
impacted by risks includes, but is not limited to:
Deliverable status, Schedule progress, and Costs incurred.
4 Work Performance Reports Work performance reports take information from performance
measurements and analyze it to provide project work performance
information including variance analysis, earned value data, and forecasting
data. These data points could be impactful in controlling performance
related risks.
CONTROL RISKS: TOOLS AND TECHNIQUES
1 Risk Reassessment Control Risks often results in identification of new risks, reassessment of current
risks, and the closing of risks that are outdated. Project risk reassessments should be
regularly scheduled.
2 Risk Audits Risk audits examine and document the effectiveness of risk responses in dealing with
identified risks and their root causes, as well as the effectiveness of the risk
management process.
3 Variance and Trend Analysis For the purposes of controlling risks, trends in the project’s execution should be
reviewed using performance information. Earned value analysis and other methods
of project variance and trend analysis may be used for monitoring overall project
performance. Outcomes from these analyses may forecast potential deviation of the
project at completion from cost and schedule targets.
4 Technical Performance It requires the definition of objective, quantifiable measures of technical
Measurement performance, which can be used to compare actual results against targets.
5 Reserve Analysis Reserve analysis compares the amount of the contingency reserves remaining to the
amount of risk remaining at any time in the project in order to determine if the
remaining reserve is adequate.
6 Meetings Project risk management should be an agenda item at periodic status meetings. The
amount of time required for that item will vary, depending upon the risks that have
been identified, their priority, and difficulty of response.
CONTROL RISKS: OUTPUTS
1 Work Performance Information Work performance information, as a Control Risks output,
provides a mechanism to communicate and support project
decision making.
2 Change Requests Implementing contingency plans or workarounds
sometimes results in a change request.
3 Project Management Plan Updates If the approved change requests have an effect on the risk
management processes, the corresponding component
documents of the project management plan are revised
and reissued to reflect the approved changes.
4 Project Documents Updates Project documents that may be updated as a result of the
Control Risk process include, but are not limited to the risk
register.
5 Organizational Process Assets Updates The risk management processes produce information that
may be used for future projects, and should be captured in
the organizational process assets.
6 Organizational Process Assets Updates The risk management processes produce information that
may be used for future projects, and should be captured in
the organizational process assets.
During project management plan, risks are already identified in order for the project
manager to create a planned risk response. The plan risk response usually includes the
risk register which is a list of the identified risks that may surface during the life cycle of
the project. It is also important for the control risks process to continuously monitor risks
that may be brought about by changes in the project lifestyle.
With control risk, Project managers are able to select alternative strategies, execute
contingency plans or take the necessary corrective actions. Moreover, they can also
modify the entire project management plan in order to avoid huge risks altogether.
The three main ways in which risks can be controlled and eliminating the hazard of risks
in the highest level of control in the hierarchy, followed by reducing the risks through;
▪ Substitution
▪ Isolation
▪ Engineering control.
THANK YOU