Project and Enterprise Risk Management Course
Project and Enterprise Risk Management Course
Credit Hours 2
5/19/2023 4
4. Course Content
1. Background to Risk Management
1.1 Basic Concept of Risk and Risk Management
Definition of risk and risk management
Purpose of RM
Principles of RM
5/19/2023 5
Course content…
2. Risk Management and Decision Making
2.1 Application of risk on Project Life cycle
2.2 Risk Management in the Decision Making Process
2.3 Risk Management Roles and Responsibilities
5/19/2023 6
Course content…
4. Risk Management Methods
4.1 Identifying Risk
4.2 Analyzing Risk and its Impact (on
time/cost/quality)
4.3 Assessment of Risk (Impact, Probability and
Urgency)
4.4 Risk Management Action
4.5 Reviewing the pattern of risk over time
4.6 Re-evaluating Risk
5/19/2023 7
5. References
Hillson David 2009, Managing Risk in Projects, David
Hilson, Gower publishing, limited Farnham: England
Kendrick, Tom 2015, Identifying and Managing Project
Risk: Essentials for Failure- Proofing Your Project
Cooper, Dole F 2005, Project Risk Management Guidelines:
Managing Risk in Large Project and Complex
Procurements
Heldman, Kim 2005, Project Manager, Spotlight on Risk
Management
5/19/2023 8
6. Mode of delivery
The course will use Lerner-centered teaching
learning
The methods include:
Lecturing
Case study and
Group discussion
7. Assessment method
Individual assignment on risk assessment and risk
management for a given project 30%
Article Review or Analyzing Different Articles 20%
Final Exam =50%
5/19/2023 9
1. Background to Risk Management
1.1 Definition of Risk and Risk Management
5/19/2023 10
Background …
Risk
is an uncertain event or condition that, if it occurs,
has a positive or negative effect on a project
objective.
Management
Process of administration of an organization,
whether it is a business, a non-profit organization, or
a government body.
Risk management
a systematic and explicit approach for identifying,
quantifying, and controlling project risk.
5/19/2023 11
Definition of Risk …
Definition of risk Organization
It is combination of likelihood of the threat being able to Risk Management
expose an element(s) of the system and its impact ISO/IEC 27001
A combination of probability of an event and its Institute of Risk
consequences. The consequences can be negative and Management
positive
A probability or threat of damage, injury, loss, or any Business Dictionary
other negative occurrence that is caused by external or
internal vulnerabilities, and may be avoided through
preemptive action."
Combination of the probability or frequency of Association of
occurrence of a defined threat or opportunity and the Project
magnitude of the consequences of the occurrence. Management
The likelihood of variation in the occurrence of an event, Risk Analysis and
which may have either positive or negative consequences. Management of
Projects
5/19/2023 12
Definition of Risk …
Risk is an uncertain event or set of circumstances
that, should it occur, will have an effect on
achievement of project’s objectives.
Some scholars suggest that uncertainty belongs to the
subjective realm of belief, while risk has an objective
component based in fact or truth.
Not all uncertainties are risk
Risk = (probability of unfavorable outcome) times
(consequence of unfavorable outcome)
= P*C
Risk = f(event, uncertainty, damage)
Risk = f(hazard, safeguard)
5/19/2023 13
Definition of Risk…
Risk is inevitable in a business organization when
undertaking projects or businesses.
However, the project manager needs to ensure that
risks are kept to a minimal.
Risks can be mainly divided between two types,
Negative impact risk and
positive impact risk.
Project managers not all the time would be facing negative
impact risks as there are positive impact risks too.
5/19/2023 17
RM…
Benefits/ purpose of Risk Management
Identify factors that are likely to impact the project/business
objectives (scope, quality, cost and time)
Quantify the likely impact of each factor on the project/business
Give a baseline(reference) for project non-controllable
Mitigate impacts by exercising influence over project controllable
Maximizing the results of positive events and minimizing the
consequences of adverse events.
More and better information is available during planning and
decision making
Verify project/business objectives and Improve communications
Higher probability of project success
Proactive approach and Project might be canceled
May be a legal requirement depending upon industry or sector
5/19/2023 18
RM…
Principles of RM
Following principles of risk management can help your
organization manage risk in the best possible way.
This is important to ensure that your organization is
protected from the various threats that it may face.
It’s also create opportunities for your business.
Applicable for all types of organizations, the ISO 31000
standard provides useful guidelines for managing risk.
One way it does this is with the ISO 31000 risk
management principles.
Let as look the ISO 31000 risk management principles
and its benefits
5/19/2023 19
RM…
Principles of RM
1. Integrated - Ensure that all of your organisation’s activities make risk
management a focus. Integrate it throughout your organisation.
2. Structured and comprehensive – To achieve consistent results,
your approach to risk management needs to be well-organized and
thorough. It can’t be arbitrary or sloppy; this only leads to failures down the
line.
3. Customized – Every organisation is different. Make sure that your risk
management framework and process is tailored to your organisation, the
context in which operates, and its objectives.
4. Inclusive – Where appropriate, involve stakeholders in the risk
management process. Stakeholders are defined as either a person or
organisation that can impact or be impacted by your decisions or activities.
By considering their knowledge, views and perceptions, you can gain
valuable insight to improve awareness and inform risk management.
5/19/2023 20
RM…
5. Dynamic
The risk landscape is constantly changing, as is your organisation.
You must be able to do this quickly and appropriately.
6. Best available information
A robust RM process relies on past & present data, and anticipations for
the future, limitations and uncertainties surrounding that information.
all information must be timely & accessible for stakeholders who need it
5/19/2023 22
RM…
Tips for Success of Risk Management
Involve all levels of staff & management in the process
Check controls are relevant & effective
Ensure risk owner takes responsibility for management of
risks under their control
Focus on risk cause, not its symptoms
Create a risk management plan
Reasons for Risk Management Failure
Limitations of scope
Lack of top management support
Did not engage all stakeholders
Failure to share information
RM not embedded within planning & management system
5/19/2023 23
1.2 Project Risk Management
Emergent risks
are risks that can only be recognized after they have been
occurred after project started on.
This type of risk can be tackled through developing
project resilience.
5/19/2023 27
PRM…
The development of project resilience requires:
1. Right level of budget and schedule contingency for
emergent risks, in addition to a specific known risks;
2. Flexible project processes that can cope with emergent
risk while maintaining overall direction toward project
goals, including strong change management;
3. Empowered project team that has clear objectives and
that is trusted to get job done within agreed upon limits;
4. Frequent review of early warning signs to identify
emergent risks as early as possible; and
5. Clear input from stakeholders to clarify areas where the
project scope or strategy can be adjusted in response to
emergent risks.
5/19/2023 28
PRM…
Project risk management
Is intentional and systematic process of planning,
identifying, analyzing, responding, monitoring & controlling
project risks.
It involves people, processes, tools, and techniques that
will contribute, to the greatest extent possible, to
maximizing the probability of successful results.
It is a process for identifying, communicating, and
managing project risks through all phases of project
delivery.
It is the art and science of identifying, analyzing, and
responding to risk throughout the life of a project and in the
best interests of meeting project objectives.
5/19/2023 29
PRM…
Identify your
project risks
early
Communicate
Track risks and about risks
associated tasks
Consider
Register project
opportunities
risks
and threats
Importance of PRM
Develop the
Prioritize the
contingency
risks
plan
Develop the
preventative Assess the risks
measure
Develop risk
responses
5/19/2023 30
PRM…
1. Identify your project risks early
Review the lists of possible risk sources as well as the project
team’s experiences and knowledge.
Brainstorm all potential risks.
Brainstorm all missed opportunities if project is not completed.
Make clear who is responsible for what risk.
5/19/2023 34
PRM…
9. Register project risks
Maintaining a risk log enables you to view progress and
make sure that you won’t forget a risk.
It’s also a communication tool to inform both your team
members, as well as stakeholders, what is going on.
you create a track record that no one can deny, even if a
risk happens that derails the project.
10. Track risks and associated tasks
Tracking tasks is a day-to-day job for each project manager.
Integrating risk tasks into that daily routine is the easiest
solution.
It keeps your project focused on the current situation of risks
and helps you stay on top of their relative importance.
5/19/2023 35
Project risk considerations
Basically there are four PRM considerations are:
1. Financial risk
2. Physical safety risk
3. Technical risk
4. Contractual risk
5/19/2023 36
Project risk considerations…
1. Financial Risk
As a project manager you have estimate the job properly,
unless you will suffered costs over run.
furthermore, a lot of changes to the project, leads to both
spending more money on those changes and lengthening
the timeline of the project, which gets expensive.
You have to carefully plan and monitor the status of you're
project to lower financial risks.
In order to lower you're financial risk,
1. You should plan out the project ahead of time
2. speak in depth with the client to make sure you know everything they
need from the project before getting started
3. Has airtight/strong contracts.
4. Make sure each client signs a contract before work begins.
5/19/2023 37
Project risk considerations…
2. Physical Safety Risk
Is common risk in construction or manufacturing industries.
With the large equipment used in these projects, it’s easy for
someone to get hurt if their isn’t a proper safety plan in place
Lowering physical safety risks
1. Make sure anyone who’s going to handle large, heavy machinery has the proper
training and certification to do so.
2. Everyone on the projects need to know what the dangers are, so they can be wary
of them.
3. You also need to assign team members clear roles and responsibilities regarding
the safety of the worksite.
4. Thoroughly document all safety protocols and ensure they are readily available
for your employees or contractors to access.
5. Go over it with new hires and make sure that all current employees are familiar
with the policies and procedures.
6. Deal with any potential hazards quickly before they become a bigger problem.
5/19/2023 38
Project risk considerations…
3. Technical risk
It usually comes from poor project planning or a project manager
lacks technical knowledge and resource for the project handling
You can also run into problems when clients haven’t properly
defined what they want from a project, or you don’t has a good way
to test whether or not you’ve met their requirements.
Lowering Technical risks
1. Work closely with the client to determine exactly what the
deliverables are and when they are expected.
2. Be upfront if you don’t have the time, skills, or resources to
complete the project as requested.
3. Some jobs may allow you to hire outside contractors.
4. If so, make sure you select candidates carefully and ensure they
can offer what you're current team is missing for a project.
5/19/2023 39
Project risk considerations…
4. Contractual risk
It can come from
not sticking to the contract as it’s written
mishandle confidential client information
project team doesn’t understand contractual agreements
Lowering contractual risk
1. Cyber insurance covers financial losses due to cyber attacks
5/19/2023 42
PRM…
PRM Process
5/19/2023 43
PRM…
5/19/2023 44
1.3 Business Risk Management (BRM)
5/19/2023 45
BRM…
Business
It is an organization or enterprising entity engaged in
commercial, industrial, or professional activities.
an organized economic activity, wherein the exchange of
goods and services takes place, for adequate consideration.
It is nothing but a method of making money, from
commercial transactions.
It includes all those activities whose sole aim is to make
available the desired goods and services to the society, in
an effective manner.
It can be for-profit entities or non-profit organizations.
5/19/2023 46
BRM…
Business Types
1. Sole proprietorships:
owned and operated by a single person with full tax and legal liabilities
2. Partnerships:
relationship between two or more people who together conduct business.
Each partner contributes resources and money to the business and shares profits
and losses of the business which are recorded on each partner's tax return.
3. Corporations:
a group of people (shareholders) acts as a single entity with a limited
personal liability.
A corporation comes with unfavorable taxation rules for the owners of the
business (their share will be liable).
4. Limited liability companies (LLCs):
combines the pass-through taxation benefits of a partnership with the limited
liability benefits of a corporation.
5/19/2023 47
BRM…
Business Sizes
1. Small Businesses
Small owner-operated companies commonly managed by one
person or a small group of people with less than 100 employees
It include family restaurants, home-based companies, clothing,
books, and publishing companies, and small manufacturers.
2. Mid-Sized Enterprises
It is defined as one with 100 to 499 employees or $10 million to
less than $50 million in annual gross sales
3. Large Businesses
Have >500 employees and garner >$50 million in gross receipts
and organized by departments
They may issue corporate stock to finance operations
They separate their tax burden from their owners
5/19/2023 48
BRM…
Characteristics of Business
5/19/2023 49
BRM…
Business risk
It is a future possibility that may prevent you from
achieving a business goal.
Business risks are broad and include things that
you can control such as your strategy and
5/19/2023 50
BRM…
Common types of business risk
1. Competitive risk:
The risk that your competition will gain advantages over you
that prevent you from reaching your goals.
Competitors have a cheaper cost base or a better product.
2. Economic risk:
The economy increase your costs or reduce your sales.
3. Operational risk:
The potential of failures related to the day-to-day operations
of an organization because of insufficient or failed processes.
4. Legal risk:
The chance that new regulations will disrupt your business or
that you will incur expenses and losses due to a legal dispute
5/19/2023 51
BRM…
5. Compliance risk:
The chance that you will break laws or regulations.
Business may fully intend to follow the law but ends up violating
regulations due to oversights or errors.
6. Strategy risk:
The risks associated with a particular strategy.
7. Reputational risk:
The chance of losses due to a declining reputation as a result of
practices or incidents that are perceived as dishonest,
disrespectful or incompetent.
The risk of a serious loss of confidence in an organization
8. Program risk:
Risks associated with a particular business program or
portfolio of projects.
5/19/2023 52
BRM…
9. Innovation risk:
Risk that applies to innovative areas of your business such as
product research.
Such areas may require adapting your risk management practices
to fast paced and relatively high risk activities.
10. Country risk:
Exposure to the conditions in the countries in which you operate
such as political events and the economy.
11. Quality risk:
The potential that you will fail to meet your quality goals for your
products, services and business practices.
12. Credit risk:
The risk that those who owe you money to fail to pay.
This is mostly related to accounts receivable risk.
5/19/2023 53
BRM…
13. Exchange Rate risk
volatility in foreign exchange rates will impact the value of
business transactions and assets.
14. Interest Rate risk:
changes to interest rates will disrupt your business model and
profitability by increase cost of capital.
15. Taxation risk:
The potential for new tax laws or interpretations to result in
higher than expected taxation.
new tax laws may completely disrupt business model.
16. Process risk:
The business risks associated with a particular process.
Processes tend to be a focus of RM as reducing risks in core
processes can often yield cost reductions and improved revenue.
5/19/2023 54
BRM…
17. Resource risk:
The chance that you will fail to meet business goals due to a lack
of resources such as financing or the labor of skilled workers.
18. Political risk:
Potential political events and outcomes to impede a business.
19. Seasonal risk:
A business with revenue that's concentrated in a single season
such as plant disease, rainfall .
20. Health and safety risk:
potential harm to people as a result of your business activities.
general health and safety of employees independent of work
related hazards.
Employers may offer medical services or support for a healthy
lifestyle to reduce the risks that employees will become sick.
How do you look Workers in flower farms of Ethiopia ????55
5/19/2023
BRM…
Business Risk Management
It encompasses the identification, analysis, and response
to risk factors that form part of the life of a business.
5/19/2023 57
BRM…
Ways to minimize business risks
Hire a business risk consultant.
help to identify areas of risk, calculate their likelihood and develop plans.
Hire an accountant.
help your company avoid compliance and financial risks.
Develop a risk management strategy.
plan for ways to mitigate current and future risks to your business.
Buy an insurance plan.
It can help protect your business from risks.
Perform research before committing to a loan.
take a loan that is financially viable for your business' performance.
Document all relevant financial information.
help you keep your records organized and lower the risk of fraud or theft.
Stay informed of all laws and regulations in business area.
Knowing corporate finance laws and rules help you avoid compliance risks.
Analyze the risks and rewards of your choices.
quantify potential risks & rewards to help you mitigate risks & maximize rewards.
5/19/2023 58
BRM…
Importance of BRM
1. Lower expenses: Preparing ahead of time for risks can save your company
money. For example, using security software on your computer typically
costs less than eradicating malware from your network.
2. Make better use of your time: Unexpected issues, such as adjusting
project timelines or budgets after a project is underway, can sometimes
cause various procedures to take longer than expected. Organizations that
use risk management processes may operate more efficiently.
3. Keep your company safe: Minimizing the risk of security issues, such as
lowering the possibility of data breaches occurring, can protect your
sensitive client or business information.
4. Adhere to local or federal regulations: Reducing compliance risks can
help ensure that your business continues to operate legally.
5. Help team members feel included: A comprehensive risk management
process makes an effort to involve all team members. This can help staff
members feel like their contributions matter and assist supervisors in
developing more thorough risk mitigation plans.
5/19/2023 59
1.4 Components and Types of Risk
Components of Risk
1. Uncertain events or situation or exposure
Amount of time, number of events, people and equipment involved
The mission you perform is the basis for measuring exposure.
This data is critical to the risk assessment process.
2. likelihood of occurrence of the situation
The probability of the future event occurring must be > 0% but < 100%.
Future events that have a zero or 100 % probabilities are not risks
3. Effect or Severity (positive or negative)
What is the likely result of each event -injury, damage, or death?
The database is the key here.
Tell distribution of hazard events by severity for occupational illness,
personal injury,, property or equipment damage could ultimately occur.
The impact or consequence of future event must be unexpected or
unplanned for.
5/19/2023 60
Components of Risk…
5/19/2023 61
Types of Project Risk
Generally project risk classified as
Internal and
external
A. Internal risks:
1. Cost Risks: Risks of project costs being exceeded due to
inaccurate estimates of costs or creeping scope changes.
2. Schedule Changes: Risks that activities take longer than
expected, which in turn usually leads to cost increases,
later benefits and a possible loss of competitiveness.
3. Performance or Quality risks: Risks that the project fails
to deliver the planned results with the promised
performance and quality. All these risks arise from project
execution.
5/19/2023 62
Types of Project Risk…
B. External risks :
1. Governance risks: These are related to business management,
project support, leadership and corporate reputation.
2. Strategic risks: These result in errors in the strategy definition,
e.g. in using a technology that does not bring the desired success.
3. Operational risks: This results from poor implementation and
process problems, e.g. in purchasing, production and sales, but
also in protection against theft and fraud.
4. Market risks: include competition risks, currency risks, interest
rate and commodity risks as well as liquidity and credit risks.
5. Legal risks: These arise from changes in regulatory requirements,
contract risks or patent risks.
6. Environmental risks: Risks related to earthquakes, storms,
flooding, vandalism, sabotage, civil unrest or strikes
5/19/2023 63
Types of Project Risk…
5/19/2023 64
Types of Project Risk…
5/19/2023 65
Types of Project Risk…
i. Financial risk
Reduction in funding
Failure to safeguard assets
Poor cash flow management
Lack of value for money
Fraud / theft
Poor budgeting
ii. Operational risk
Inappropriate policies, procedures, systems or activities:
Failure of an IT system
Poor quality of services delivered
Lack of succession planning
Health & Safety risks
Staff skill levels
No process to track contractual commitments
5/19/2023 66
Types of Project Risk…
iii. Reputational risk
Engagements in activities that could threaten it‘s good name
Through association with other bodies.
Staff / members acting in a criminal or unethical way
Poor stakeholder relations
iv. Governance & Compliance risk
Lack of oversight by Board
Segregation of duties not defined formally
Ensuring compliance with funders terms and conditions
Compliance with applicable legislation
v. Residual and Secondary risks
Residual risks are risks that remain after all of the response
strategies have been implemented
Secondary risks: a direct result of implementing a risk response
5/19/2023 67
Types of Project Risk…
5/19/2023 68
2. Risk Management and Decision Making
5/19/2023 70
Risk on PLC…
5/19/2023 71
Risk on PLC…
5/19/2023 72
Risk on PLC…
5/19/2023 73
Risk on PLC…
PRM occurs throughout the life cycle and the process differs
depending on the phase.
RM within a project is a process of identifying any potential
risks prior to project commencement and creating a plan to
mitigate risks and/or prevent them from occurring.
Therefore, RM requires taking an informed approach to
understanding a project’s risk appetite (desire)
Each activity associated with risk management requires
interactions with stakeholders,
considering internal and external contexts,
the effectiveness of treatments and the overarching completeness
of the identification process.
5/19/2023 74
Risk on PLC…
Phase 1: Initiation
The project initiation phase is the start of the project.
5/19/2023 75
Risk on PLC…
Initiation …
The project initiation phase requires consideration of
unknown issues that could arise.
There are more unknowns at the beginning of a project,
as many of the deliverables, requirements and outcomes
are unclear.
Risk analysis at the initiation phase requires weighing
up the potential risks compared to the potential
benefits, which will support an understanding of
whether or not the project is worthwhile.
5/19/2023 76
Risk on PLC…
Initiation …
The most common risks:
1. No clear business or organizational strategy.
The benefits for the project do not clearly link back to the
organizational objectives, future plan or strategies.
2. Lack of capabilities, skills and resources.
Organizations do not always have the right resources,
skills and capabilities required for their proposed project.
3. Lack of stakeholder support.
Ensuring that key stakeholders are aware of the project,
its value and why it is underway is vital to success.
5/19/2023 77
Risk on PLC…
Initiation …
A risk management framework should be reviewed and tailored
to outline specifics within the project risk management plan in
the initiation phase (PMI 2021).
5/19/2023 78
Risk on PLC…
Phase 2: Planning
Its key component is expanding on the risk identification
process.
This phase requires the project manager and team to
document in detail the objectives, goals and requirements
that the project seeks to achieve (PMI 2021).
These are called the Critical Success Factors (CSF), which are
the elements within a project deemed critical to the project
achieving its goals (Bennet 2017).
By describing these factors or requirements, project team
members, stakeholders and sponsors have a consistent
understanding of what they are aiming towards.
5/19/2023 79
Risk on PLC…
Planning…
Here Risks are things which can threaten, prevent or support
the completion of the CSFs within the project (Bennet 2017).
A positive risk is an event which poses an opportunity for a project,
negative risk presents a challenge or issue needs to be overcome
Keeping this in mind, risk planning involves
identifying the important risk events (positive or negative),
their prioritization and evaluation, and
the process of developing responses.
The 3 primary steps occur during this phase of RM:
1. Identification
2. Evaluation and prioritization
3. Risk response
5/19/2023 80
Risk on PLC…
Planning…
Step 1. Identification
It starts with identifying potential risks:
Ask ‘what if?’ questions.
5/19/2023 83
Risk on PLC…
Planning…
Response …
The level of detail required for RM plans will differ depending
on their likelihood or consequence.
For the most significant risks (e.g., high likelihood and
consequence), a detailed action plan is necessary.
For medium risks (e.g., medium likelihood and
consequence), a brief action plan will do.
For small risks (e.g., low likelihood and consequence), no
action plan may be required at all.
It is important that all risks within the action plan be
allocated to a person who can take the actions required to
respond to the risk.
5/19/2023 84
Risk on PLC…
Planning …
5/19/2023 85
Risk on PLC…
Phase 3: Execution
The project moves into the execution phase when
work begins to meet the project goals and objectives
(PMI 2021).
As the project progresses, more information
becomes available, and more risks can be identified
and support response planning.
This highlights the importance of updating the risk
register as new information comes to light.
5/19/2023 86
Risk on PLC…
Phase 4: Monitor and control
The process of monitoring and controlling within
project management and risk management is an
iterative process which requires ongoing performance
and status reporting (PMI 2021).
These reports outline the current state of deliverables or
outcomes in comparison to the baseline or
planned/expected deliverables or outcomes.
This is a point-in-time analysis, which is supported by a
status report (e.g., quality, progress, follow-up and risk
reporting).
5/19/2023 87
Risk on PLC…
Monitoring and controlling…
This Process of RM includes:
identifying new risks
planning responses for new risks as they arise
5/19/2023 88
Risk on PLC…
Monitoring and controlling…
Key actions required within this process include:
1. Risk Reclassification
It refers to risks which are not ready to be closed, but whose
likelihood and consequence decreases over time (due to
responses within the action plan).
However, not all actions will have been sufficient to address the
risks, and more actions may be needed.
2. Risk reporting
risk registers require updating.
This includes going through risk identification, planning and
responses and status updates.
The risk register is the primary risk tool and needs to be
accessible by all key stakeholders.
5/19/2023 89
Risk on PLC…
Monitoring and controlling…
This process is mandatory in risk management, it is part of
milestone and regular project meetings.
The frequency of risk management meetings can be altered
to meet the needs or risk level of the overall project.
As part of the monitoring and controlling process, the risk
thresholds may change.
This includes the different priorities, where risks change
from higher to lower exposure rates.
Risks may decrease in risk thresholds or priorities, and lower
ranked exposure risks can then be removed from response plans.
5/19/2023 90
Risk on PLC…
Phase 5: Closure
Here needs to be agreement across the stakeholders,
sponsors and project team/manager that the RM plans can
be finalized along with the project (PMI 2021).
All the risks that occurred need to be documented, and their
impact needs to be assessed and documented.
additional lessons can be learned from the RM process
across the project management life cycle (PMI 2021).
We conduct a risk score or rating (represents the thresholds
or classifications for risks) (Lavanya and Malarvizhi 2008).
This is based on normal conditions; however, there are
circumstances where an upgrade is needed, including when
critical factors could impact the likelihood or consequence.
5/19/2023 91
Risk on PLC…
Closure…
Close out process of risk register
how the risks, issues or problems faced within the project differed
from the plan.
Each of these metrics are documented within the lessons learned
and support future project and risk planning.
5/19/2023 93
Risk on PLC…
Closure …
Risk audits
are a process by which an independent analyst assesses the
risks and provides recommendations on how to improve
maturity or effectiveness of PRM processes (PMI 2021).
This process includes:
understanding how good project team are at identifying risk
checking how complete the list of risks identified was
5/19/2023 94
Risk on PLC…
Closure …
Risk audits…
It is comprised of a group of technical or subject matter experts
brought together via documentation reviews and interviews.
Key outcomes of a risk audit:
checklists for evaluating project risks
identifying the importance of risk analysis categories within
project or organization
documenting the key risk categories and triggers
adding any additional risks which were identified during risk
assessment process and which were missed in early planning
listing the top 10 project and organization risks which required
the most attention.
5/19/2023 95
2.2 Risk Management in Decision Making Process
Decision making process
It is the adoption and application of rational choice for the
management of a private, business, or governmental
organization in an efficient manner.
It indicates how rational individuals should behave under
risk and uncertainty
It is choosing between alternative courses of action.
5/19/2023 96
RM in DMP…
Decision making can be divided into two parts:
1. the decision that someone arrives at and
2. the process or actions taken.
Implementing a decision is as important as
making that decision.
From this perspective, RM will help the organizations to
conduct their risk-based decision-making.
Always there is a time lag between when the decision-
making is made and when the outcome or the objective of
such a decision will be realized.
In this case, there could be some risks that may hinder us
from accomplishing the objective.
5/19/2023 97
RM in DMP…
RM is linked to three stages of decision-making process:
1. Intelligence activity stage.
Here we identify the issues and challenges faced by an organization.
Board and senior management analyze strategic issues and
challenges leading to strategic risks,
middle managers are on operational issues and challenges leading
to operational risks, and
the assurance function is to identify issues and challenges leading
to compliance risks against all prevailing rules and regulations.
It is linked to the step of risk assessment, which consists :
risk identification,
risk analysis, and
risk evaluation.
5/19/2023 98
RM in DMP…
2. Design activity stage:
we identify and analyze possible solutions to the issues and
challenges and its respective risk category.
Board and senior management
look for suitable strategies, possible series of actions and approaches.
analyze merits and demerits to select a particular strategic action.
Middle management
assure that workable design has chosen
followed to all requirements of prevailing laws and regulations.
this stage is linked to the risk assessment
risk analysis, figuring out magnitude of risk impact & likelihood.
should be well communicated to concerned stakeholders and
reviewed and monitored by the organization regularly.
5/19/2023 99
RM in DMP…
3. Choice activity stage:
Here we critically examines and evaluates the various
consequences of all alternatives,
selecting the most suitable course of action.
requires creativity, judgment, and quantitative analysis skills.
this stage is linked to the risk assessment
risk evaluation
figuring out the magnitude of the risk impact and likelihood,
which is compared to the threshold to decide whether risk
mitigation needs to be taken or not.
If risk mitigation should be taken, then what option could be
chosen upon cost-benefit analysis toward assessing particular
risk prior to.
5/19/2023 100
2.3 RM Roles and Responsibilities
Everybody working for an organization will need to be
made aware of their risk management responsibilities,
as will contractors and suppliers.
There are many professional people in large
organizations who have an understanding of risk and a
substantial contribution to make to the successful
management of the priority significant risks.
There should be clear statements of responsibilities for the
following aspects of the management of significant risk:
Setting required risk standards;
Implementing risk standards;
2. Location Manager:
Build risk-aware culture within the location
Agree risk management performance targets for the location
Evaluate reports from employees on RM matters
Ensure implementation of risk improvement recommendations
Identify and report changed circumstances/risks
5/19/2023 102
RM Roles and Responsibilities…
3. Individual employees
Understand, accept and implement RM processes
Report inefficient, unnecessary or unworkable controls
Report loss events and near-miss incidents
Cooperate with management on incident investigations
Ensure that visitors and contractors comply with procedures
4. Risk manager
Develop the risk management policy and keep it up-to-date
Facilitate a risk-aware culture within the organization
Establish internal risk policies and structures
Coordinate the risk management activities
Compile risk information and prepare reports for the board
5/19/2023 103
RM Roles and Responsibilities…
5. Specialist risk management functions
Assist the company in establishing specialist risk policies
Develop specialist contingency and recovery plans
Keep up-to-date with developments in the specialist area
Support investigations of incidents and near misses
Prepare detailed reports on specialist risks
5/19/2023 104
RM Roles and Responsibilities…
7. RM Committee
To advise the board on RM and to foster a culture that emphasizes and
demonstrates the benefits of a risk-based approach to RM
To make appropriate recommendations to the board on all significant
matters relating to the risk strategy and policies of the company
To monitor the performance of the RM systems and review reports
prepared by relevant parties
To keep under review the effectiveness of the risk management
infrastructure of the company
To review the risk exposure of the company in relation to the risk appetite
of the board and the risk capacity of the company
To consider the development of RM and make appropriate
recommendations to the board
To consider whether disclosure of information regarding RM policies and
key risk exposures is in accordance with financial reporting standards.
5/19/2023 105
RM Roles and Responsibilities…
Project teams, managers and different stakeholders require
numerous skills to manage risk including:
Communication: ability to communicate the importance of
understanding risk across all stakeholders, team members,
sponsors and managers.
Organizational understanding: understanding of current
organizational strategic direction, goals and risk appetite.
Creativeness: ability to act under pressure and respond to
risks as required.
Preparedness: ability to establish a risk management
process that is easy to follow and action throughout.
Solutions driven: ability to solve problems and develop
solutions to respond to identified project risks.
5/19/2023 106
3. Applying Risk Management
5/19/2023 107
3.1 Risk Management Life cycle
The risk management life cycle involves identifying a
hazard, assessing the risk of potential harm, and managing the
risk of harm by using appropriate control measures.
The risk management process involves identifying risks,
analyzing them, evaluating them, treating them, and
monitoring and reviewing them
The Risk Management lifecycle is not static.
It’s really important to recognize that just identifying risks and
expecting them to manage themselves is not enough.
We need to focus on all the key parts of the lifecycle
we will look at how to properly identify what risks are and how to
understand what are not risks.
5/19/2023 108
RM Life cycle…
It emphasizes the necessity for project managers to: Identify,
Assess, Control, Prevent the risks faced by the
project throughout its development.
In RM life cycle risks being reviewed periodically so that
mitigation strategies are always up-to-date.
The events that could affect the project and the actions the
team could take to lessen the risk should be monitored
continuously.
This approach could be seen as a continual improvement
process, whose goal is to ensure steady progress and
compliance with changing internal and external constraints.
5/19/2023 109
RM Life cycle…
RM Life cycle…
5/19/2023 110
RM Life cycle…
1. Identifying risks
As soon as the project starts, it is essential to:
List different risks the project could face during its
execution,
Define their characteristics considering the context in
which the project will take place.
How to identify the risk of the project?
Set up a brainstorming session with your team or even other
relevant people from or outside your organization,
Prepare a feasibility study to base your analysis on a thorough
picture of your environment,
If applicable, study the data from previous projects in a similar
industry to have an overview of the possible risks associated with
this type of project.
5/19/2023 111
RM Life cycle…
Identifying risk…
This document is called the risk register
It provides the basis for most risk management processes.
This document will be enriched with new information
throughout the next steps of the risk lifecycle.
Helps to identify changes to internal and external risk
environments at an enterprise and client level and
Supports the identification of emerging risks.
5/19/2023 112
RM Life cycle…
2. Assessing their impact
The goal of conducting a risk assessment is to:
assess the risk level,
meaning to sort risks according to quantitative and
qualitative criteria.
to categorize risks (high, moderate or low) regarding
possible impact in terms of scope, delays or costs.
To classify risks, you should consider:
The probability of the risk occurring,
5/19/2023 113
RM Life cycle…
3. Defining risk control strategies
Risk mitigation is based on control strategies and careful
response planning.
The goal is to describe the actions to be taken to:
Avoid the risk,
5/19/2023 114
RM Life cycle…
Defining risk control strategies…
To define appropriate risk response, base your conclusions
on the sorted list of risks done during the previous steps.
Consider their degree of urgency and priority: some will
need to be dealt with immediately, while others could be
solved in the medium or long term
Once risks have controls in place, it is likely there will be
actions required to ensure the likelihood and impact of the
risk is minimized.
It’s important that these actions have named owners in the
business and dates to ensure they progress.
5/19/2023 115
RM Life cycle…
4. Monitoring your actions
It is set up a process for tracking and monitoring risks
throughout the project development.
This ensures new risks are identified and always controlled.
For effective risk management:
the risk register should be updated on a regular basis, and
the risk monitoring phase should go on even after the
project has ended.
5/19/2023 116
RM Life cycle…
5. Reporting the results
As a project manager, be sure to save your analysis and
record your tracking to make the history available to
others.
This makes it possible to derive good practices for
future projects from your experience.
Accurate reporting is very important for
stakeholders and the company as a whole.
5/19/2023 117
3.2 Schedule of Risk Management Activates
It is relies heavily on upfront of project risk planning.
We first plan everything prior to execution.
Developing a project risk schedule can be broken down in:
1. Develop a risk work breakdown structure.
2. Identify risk task relationships.
3. Estimate risk work packages.
4. Calculate initial risk schedule.
5. Assign and level resources for the stated risks.
5/19/2023 118
Schedule of RM Activates…
1. Risk Work Breakdown Structure
It is break down the work related to risk into smaller pieces of
work which make it easier to accurately estimate the required
time and resources for RM.
It identifies all the tasks/deliverables in a project risk and can
be set up graphically or as an textual outline.
Traditionally, a risk WBS focused on risk tasks, more recently
there has been a shift towards risks related to deliverables
A WBS breaks all the work into separate tasks of two types:
1. Summary tasks: includes several subordinate tasks and is not
actually executed.
2. Work packages. These are the tasks that actually require execution.
5/19/2023 119
Schedule of RM Activates…
2. Identify risk task relationships
The sequence in which detailed tasks (work packages) are
performed is determined by the relationship b/n the tasks.
Any time a series of tasks is performed, there will be
sequence constraints, i.e. some tasks need to be performed
before others.
To visualize these constraints, tasks and sequential
constraints can be visualized as a graph.
When doing so, two basic rules are important:
Task relationships (arrows) should only be shown between
work packages (and not summary tasks).
Task relationships should only reflect sequence constraints
between work packages, not resource constraints.
5/19/2023 120
Schedule of RM Activates…
The sequential constraints between tasks can further be
separated into different categories:
Finish-to-start relationship. The subsequent activity can only
start when then preceding activity finished.
Start-to-start relationship. The subsequent activity can
already/only start when the preceding activity started.
Finish-to-finish relationship. The subsequent activity can
start independently of its predecessor, but cannot finish
before the predecessor finishes.
5/19/2023 121
Schedule of RM Activates…
4. Calculate Initial Schedule (estimating duration of risk task)
i. The first step is to perform a forward pass.
This will allow you to determine the earliest starting point (ES) and finish time
(EF=ES + its duration).
The ES of a task equals the latest EF of all its direct predecessors.
The forward pass starts with the first task, whose ES = starting time of the project.
5/19/2023 123
3.3 Assessing Appropriate Level of RM
Some form of measurement of risk is necessary.
5/19/2023 125
Level of RM…
Impact (consequence)
It refers to the extent a risk event might affect the enterprise.
Impact assessment criteria may include financial, reputational,
regulatory, health, safety, security, environmental, employee,
customer, and operational impacts.
Enterprises typically define impact using a combination of these
types of impact considerations
When assigning an impact rating to a risk, assign the rating for
the highest consequence anticipated.
The following table show the 5 levels of impact and
corresponding definitions
5/19/2023 126
Level of RM…
5/19/2023 127
Level of RM…
Likelihood
represents the possibility that a given event will occur.
It can be expressed using qualitative terms (frequent, likely,
possible, unlikely, rare), as a percent probability, or as a
frequency.
When using numerical values, whether a percentage or
frequency, the relevant time period should be specified such
as annual frequency or the more relative probability over the
life of the project or asset.
Sometimes enterprises describe likelihood in more personal
and qualitative terms such as “event expected to occur several
times over the course of a career” or “event not expected to
occur over the course of a career
5/19/2023 128
Level of RM…
Level of likelihood
5/19/2023 129
3.4 Defining RM procedures
RM within a project is a process of identifying any potential
risks prior to project commencement and creating a plan to
mitigate risks and/or prevent them from occurring.
RM requires taking an informed approach to understanding a
project’s risk appetite.
The most common procedure to managing risks is using the
International Organization for Standardization (ISO) 31000
approach (ISO 2018).
The ISO 31000 considers that all organizations face numerous
internal and external factors and influences which add
uncertainty to achieving objectives (ISO 2018).
ISO 31000classified risk analysis in seven procedures
5/19/2023 130
RM procedures…
5/19/2023 131
RM procedures…
1. Communication and consultation.
This step assists the project team and stakeholders to
understand the risk (ISO 2018).
It seeks to promote awareness and understanding of risks,
using consultation to obtain feedback to inform decision-
making.
Collaboration b/n stakeholders assist in obtaining factual,
timely, relevant, accurate and understandable information.
Both internal and external stakeholders need to be part of
the steps within the risk management process.
2. Establish context
Context within the RM process needs to be established by
developing an understanding of the internal and external
environment in which organization operates (ISO 2018).
5/19/2023 132
RM procedures…
3. Risk assessment.
3. It is the process of identifying, analyzing and evaluating
risk.
4. It needs to be systematic, iterative and collaborative, using
the stakeholders’ knowledge.
5. It should be based on the most recent information and
supported by further research as required.
4. Risk identification.
This is the process of finding, recognizing and describing
potential risks which can support or threaten a project
achieving its objectives (ISO 2018).
The project team should use a wide range of techniques to
identify risks which affect one or more objectives.
5/19/2023 133
RM procedures…
5. Risk analysis.
This is a comprehensive analysis of risk, based on its
characteristics (ISO 2018).
This involves sources, consequences, likelihood, triggers,
contingencies, controls and control effectiveness.
A key consideration is the risk exposure, which is the risk
likelihood and consequence levels.
6. Risk evaluation.
It is used to support decision-making.
It involves comparing the results of the risk analysis process
to the pre-defined risk criteria (ISO 2018).
It can lead to a decision to transfer, avoid, treat/mitigate,
approve, or reject.
5/19/2023 134
RM procedures…
7. Risk treatment.
This requires selecting and implementing options to address
different risks.
It includes determining risk treatment options,
implementing the treatment, reviewing effectiveness,
determining if the remaining levels of risk are acceptable
and, where necessary, taking further action (ISO 2018).
8. Monitor and review.
The assurance process which determines the improvement
of quality and effectiveness in the design, implementation
and outcomes (ISO 2018).
Iterative reviews of RM processes help to determine if the
treatments that are used in response to risk are effective or
not.
5/19/2023 135
4. Risk Management Methods
5/19/2023 137
RM methods…
An unmanaged risk can make it difficult for a project to meet its
goals and may even make it impossible for the project to be
successful.
RM is essential during the start, planning, and execution phases
of a project; when risks are well managed, the probability of a
successful project considerably increases.
Project managers can determine the strengths, weaknesses,
opportunities, and hazards that are associated with the project
by using effective risk management methods.
As a project manager, you might be better prepared to deal with
uncertainties if plans are made for these and the project team is
guided to mitigate them as well.
5/19/2023 138
RM methods…
will help to identify level of risks, their associated probabilities,
potential impacts, and recommended countermeasures.
1. Low risk typically have a minimal or no effect on the
budget, the schedule, or the performance.
2. A moderate amount of risk might result in a small but
noticeable increase in costs, a disturbance of the schedule,
or a decline in performance.
3. high probability of occurring are very likely to result in a
substantial increase in the budget, a disruption of the
schedule, or performance issues.
Effective project managers also communicate their strategy to
the project sponsors, stakeholders, and team members to
guarantee that projects are carried out without a hitch.
5/19/2023 139
4.1 Identifying Risk
It is the process of identifying any and all potential risks
that might affect a project and documenting their
characteristics.
It determines what might happen that could affect the
objectives of the project, & how those things might happen.
This process must be comprehensive, as risks that have not
been identified cannot be assessed, and their emergence at
a later time may threaten the success of the project and
cause unpleasant surprises.
It should be structured using key elements to examine risks
systematically, in each area of the project to be addressed.
5/19/2023 140
Identifying Risk…
identify Risks is the process of
identifying individual project risks and their sources and
documenting their characteristics.
5/19/2023 141
Identifying Risk…
5/19/2023 142
Identifying Risk…
Who participate in identifying project risks
Participants in activities to identify project risks are:
project manager,
project team members,
customers, end users,
experts from outside the project team,
other project managers,
stakeholders, and
risk management experts.
5/19/2023 143
Identifying Risk…
What are the questions we need to answer here?
Why is sales down?
Why is market share down?
What is the reason behind employee turnover?
Why is our new product recently introduced not doing
well?
What are the reasons behind all the budget variances?
Are we charging the right price for products and services?
Are our cost centers and revenue centers functioning
according to their set objectives?
Should we make investment in a new technology? Why?
Why not?
5/19/2023 144
Identifying Risk…
Primary sources of Risk
Risk Source Description
5/19/2023 146
Identifying Risk…
Risk category list
Project Risk Organisation Technical Commerc Environmen
Management al Risks Risks ial Risks tal Risks
5/19/2023 147
Identifying Risk…
Tools and techniques for Risk identification:
Brainstorming
The Delphi Technique
Interviewing
SWOT analysis
Risk breakdown structure
5/19/2023 149
Identifying Risk…
Tools…
2) Delphi Technique
it is used to derive a consensus among a panel of experts
who make predictions about future developments/ pheromone
Provides independent and anonymous input regarding future
events
Uses repeated rounds of questioning and written responses
and avoids the biasing effects possible in oral methods.
3) Interviewing
is a fact-finding technique for collecting information in face-
to-face, phone, e-mail,
Interviewing people with similar project experience is an
important tool for identifying potential risks
5/19/2023 150
Identifying Risk…
Tools …
4) SWOT analysis
analysis (strengths, weaknesses, opportunities, and
threats) can also be used during risk identification
Helps identify the broad negative and positive risks
that apply to a project
A. Scope risk
Product/services scope: includes the features and
functions of the products, services, and results.
Project scope: is the work required to create the
deliverables.
Scope risks: are uncertain events or conditions that are
related to the project scope.
5/19/2023 152
Identifying Risk…
Scope Risk Examples: Scope tends to be a vague concept. eg…
Individuals may add features to the product that were not approved.
The project team may not identify all the deliverables, requiring
changes later.
Scope changes may not be processed through the change control
process.
Requirements may not be properly analyzed and understood.
Requirements may not be properly prioritized.
Traceability structure may not be developed resulting requirements
not being managed through the design, development, and testing
processes.
The project team may fail to identify all the activities required to
create the deliverables.
Project complexity (interfaces, algorithmic assessments, technical or
architecture analysis) and Volume of anticipated changes.
5/19/2023 153
Identifying Risk…
B. Schedule risk
It is the likelihood of failing to meet schedule plans and the
effect of that failure.
It exists in every schedule and is impossible to predict, with
complete confidence, the length of time necessary to
complete an activity, meet a milestone, or deliver a system.
Schedule risks are the most numerous in the project
experience risk information database.
It can categorized: delays, dependencies, and estimates.
We can avoid schedule risk in project management by:
1. Reduce the number of Critical Paths
2. Reduce Activity Dependencies
3. Schedule Risky Activities Earlier
4. Plan Regular Schedule Reviews
5/19/2023 154
Identifying Risk…
C. Resource risk
It is chance of failing to meet a goal due to a lack of resources.
Resources can include financing, time, skilled workers and
anything else you need to achieve a particular goal.
Project resource risks are usually most severe for activities
that are most likely to impact project schedule activities
Categories of resource risk :
Staff leaving the project permanently as well as temporarily
Staff joining the project late
Queuing issues involving people not dedicated to the project
Resource shortfalls
Training isn't available and inadequate
Resources are inexperienced
Lack of commitment from functional managers
5/19/2023 155
Identifying Risk…
Outputs of identifying Risk
[Link]
has a positive or negative effect on a project objective.
[Link]
5/19/2023 156
Identifying Risk…
Risk Register
It is a document you use to record:
All of your organization's identified risks
how they could affect the projects and when they could occur
The likelihood and consequences of a risk occurring,
The actions you are undertaking to reduce those risks and
Who is responsible for managing them.
5/19/2023 158
4.2 Analyzing Risk & its Impact
Analyzing Risk
It is the process that figures out how likely that a risk will arise
in a project.
It is systematic use of available information to determine how often
specified events may occur & the magnitude of their consequences.
5/19/2023 161
Analyzing Risk …
Qualitative Risk Analysis…
It requires the probability and consequences of the risks
be evaluated using established qualitative-analysis
methods and tools
Trends in the results when qualitative analysis is
repeated can indicate the need for more or less risk-
management action.
It should be revisited during the project’s life cycle to stay
current with changes in the project risks.
This process can lead to further analysis in quantitative
risk analysis or directly to risk response planning
5/19/2023 162
Analyzing Risk…
Qualitative Risk Analysis…
Techniques of qualitative risk analysis
1. For small projects, project managers can use what we call
the KISS (Keep It Super Simple) Method.
This one-dimensional technique involves rating risks as:
5/19/2023 164
Analyzing Risk …
Qualitative Risk Analysis…Techniques…
4. Project assumptions testing.
Identified assumptions must be tested against two criteria:
assumption stability and the consequences on the project if the
assumption is false.
Alternative assumptions that may be true should be identified and
their consequences on the project objectives tested in the
qualitative risk analysis process.
5. Data precision ranking.
It is a technique to evaluate the degree to which the data about
risks is useful for risk management by examining:
Extent of understanding of the risk
Data available about the risk
Quality of the data
Reliability and integrity of the data
5/19/2023 165
Analyzing Risk…
Qualitative Risk Analysis…Techniques…
6. Top ten risk item tracking
It helps to identify risks and maintain an awareness of
risks throughout the life of a project.
Establish a periodic review of the top ten project risk
items.
List the current ranking, previous ranking, number of
times the risk appears on the list over a period of time,
and a summary of progress made in resolving the risk
item.
5/19/2023 166
Analyzing Risk …
Qualitative Risk Analysis…
Inputs
1. Risk management plan.
2. Identified risks with their potential impacts on the project.
3. Project status at different level of project stages.
4. Project type whether is recurrent type or new or highly
complex projects
5. Data precision: extent of data available and reliability
6. Scales of probability and impact: are used in assessing
the two key dimensions of risk
7. Assumptions: identified during the risk identification
process are evaluated as potential risks
5/19/2023 167
Analyzing Risk …
Qualitative Risk Analysis…
Outputs
1. Overall risk ranking for the project. It can used
to assign personnel or other resources to projects with d/t risk
rankings,
to make a benefit-cost analysis decision about the project, or
to provide recommendation for project initiation, continuation,
or cancellation.
5/19/2023 169
Analyzing Risk … Qualitative Example
Id Risk Description Event Probabilit Impact
Date y
1 Performance issues due to redesign of batch (splitting into 4 concurrent Sep-10 High Medium
jobs) are not handled before the cycle testing begins
2 Server performance issues are not handled before the cycle testing Sep-10 Low Medium
begins in September
3 Unanticipated table changes occur after the coding has been completed Aug-10 Low Low
in August
4 The testing environment chosen could interfere with other high priority Sep-10 Low Medium
projects
5 Priority to implement non-rating mod may go up due to NJ coming up Aug-10 Medium High
right after IOWA.
6 Impact Analysis brings up something that we are not thinking of now Jun-10 Medium Medium
(on both mainframe and PARIS sides), that may push the project dates
7 Coding may take longer than expected Jul-10 High Medium
8 Finding too many differences between SBR and Mainframe rating of a Aug-10 Medium Medium
policy may push the dates for cycle testing and the project.
9 Daily business functions could be interrupted for Production Problems - Anytime Medium Medium
taking the resources away from this project
10 Other new product (MA Auto, NJ Auto, Company8, Chrome Expansion) Anytime High High
-Taking resources away from this project
11 System upgrades (Rating Engine 4.0, end of VB6…) may be pushed Jun-10 Low Medium
on us right in the middle of this project
5/19/2023 170
Project Management…
B. Quantitative Risk Analysis
It is a risk analysis which assign numerical values for the
probability and impact of each risk to measure it in a more
precise manner
This process aims to
analyze numerically the probability of each risk and its
consequence on project objectives and
the extent of overall project risk.
5/19/2023 171
Project Management…
Quantitative risk analysis
Tools and techniques
1. Decision Tree Analysis – a diagram that shows the
implications of choosing one or other alternatives.
2. Expected Monetary Value (EMV) – establish the
contingency reserves for a project budget and schedule.
3. Simulation models ( Monte Carlo Analysis): technique
that uses optimistic, most likely, and pessimistic estimates
to determine the total project cost and project completion
dates.
4. Sensitivity Analysis – a technique used to determine
which risks have the greatest impact on a project.
5. Fault Tree Analysis– the analysis of a structured diagram
which identifies elements that can cause system failure
5/19/2023 172
Analyzing Risk …
Quantitative Risk Analysis…
Inputs
1. Risk management plan.
2. Identified risks.
3. List of prioritized risks
4. List of risks for additional analysis and
management.
5. Historical information.
6. Expert judgment.
7. Extra planning outputs
8. Qualitative risk analysis results (outputs)
5/19/2023 173
Analyzing Risk …
Quantitative Risk Analysis…
Outputs
1. Prioritized list of quantified risks.
threat or opportunity to the project together with their impact.
2. Probabilistic analysis of the project
listing the possible completion dates or project duration and costs
with their associated confidence levels.
3. Probability of achieving the cost and time objectives.
The probability of achieving the project objectives under the current
plan and with the current knowledge of the risks facing the project
can be estimated using quantitative risk.
4. Trends in quantitative risk analysis results.
Repeated analysis help to develop a trend of results.
5/19/2023 174
Analyzing Risk … Example
Id Risk Description Event Probabili Impact Magnit
Date ty (days) ude
1 Performance issues due to redesign of batch (splitting into Sep-10 H 70% M 15 10.5
4 concurrent jobs) are not handled before the cycle testing
2 Server performance issues are not handled before the cycle Sep-10 L 10% M 10 1
testing begins in September
3 Unanticipated table changes occur after the coding has been Aug-10 L 10% L 5 0.5
completed in August
4 The testing environment chosen could interfere with other high Sep-10 L 10% M 10 1
priority projects
5 Priority to implement non-rating mod may go up due to NJ Aug-10 M 25% H 40 10
coming up right after IOWA.
6 Impact Analysis brings up something that we are not thinking of Jun-10 M 25% M 15 3.75
now (on both mainframe and PARIS sides), that may push the
7 Coding may take longer than expected Jul-10 H 50% M 20 10
8 Finding too many differences between SBR and Mainframe rating of a Aug-10 M 30% M 15 4.5
policy may push the dates for cycle testing and the project.
9 Daily business functions could be interrupted for Production Anytime M 30% M 10 3
Problems - taking the resources away from this project
10 Other new product (MA Auto, NJ Auto, Company8, Chrome Anytim H 70% H 45 31.5
Expansion) - Taking resources away from this project e
11 System upgrades (Rating Engine 4.0, end of VB6…) may be Jun-10 L 20% M 20 4
pushed on us right in the middle of this project
11 Total Risk Magnitude for the Project 79.75
5/19/2023 175
Analyzing Risk …
Quantitative Risk Analysis…
1. Decision Tree Analysis
It is a tool for analyzing situations where sequential decision
making in face of risk is involved.
The key steps in decision tree analysis are:
1. Identifying the problem and alternatives
2. Delineating/drawing the decision tree
3. Specifying probabilities and monetary outcomes
4. Evaluating various decision alternatives
Each decision tree has 3 parts: root node, leaf nodes & branches.
Root & leaf nodes hold questions or criteria you have to answer.
Squares depict decisions while circles noted uncertain outcomes.
5/19/2023 177
Analyzing Risk …
Decision Trees and Expected Monetary Value
Decision tree
is a diagramming analysis technique used to help select
the best course of action in situations in which future
outcomes are uncertain
Expected monetary value (EMV)
is the product of a risk event probability and the risk event’s
monetary value
This value is positive for opportunities (positive risks) and
negative for threats (negative risks)
Expected monetary value analysis:
The method considers the probability of each possible outcome
and determines the average value of all outcome
You can draw a decision tree to help find the EMV
5/19/2023 178
Analyzing Risk …
Example
Assume that ABC Company has three alternatives in order
to satisfy the growth need of software its project activities
either build a new software with associated cost of $500,000;
buy a new software with associated cost of $750,000 or stay
with the existing (legacy) software as a result the associated
cost is mainly maintenance and the amount is $100,000. But
the company has a risk of not satisfying the need of software
and if it happen costs the company $2,000,000 and the
probability of its occurrence is 40, 5 and 100 percent for the
above stated alternatives respectively. Based on the given
determine the best alternative for the company using both
decision tree and expected monetary value methods.
5/19/2023 179
Analyzing Risk …
For the stated problem we can draw a decision tree
5/19/2023 180
Analyzing Risk …
Expected Monetary Value (EMV) will be
Build the new software: $ 2,000,000 * 0.4 = $ 800,000
Buy the new software: $ 2,000,000 * 0.05 = $ 100,000
Staying with existing software: $ 2,000,000 * 1 = $ 2,000,000
Now, add the setup costs to each EMV:
Build the new software: $ 500,000 + $ 800,000 = $ 1,300,000
Buy the new software: $ 750,000 + $ 100,000 = $ 850,000
Staying with legacy software: $ 100,000 + $ 2,000,000 = $ 2,100,000
5/19/2023 183
Analyzing Risk …
To use a Monte Carlo simulation, you must have three estimates
(most likely, pessimistic, and optimistic) plus an estimate of the
likelihood of estimate being b/n most likely and optimistic values.
A large aerospace company used Monte Carlo simulation to
help quantify risks on several advanced-design engineering
projects, such as the National Aerospace Plan (NASP)
5/19/2023 184
Analyzing Risk …
4. Sensitivity analysis
it measures how changes in a specific model variable
impacts the output of the model.
Spreadsheet software, such as Excel, is a common tool for
performing sensitivity analysis
It can be applied in a number of different disciplines,
including business analysis, investing, environmental
studies, engineering, physics and chemistry
Used to determine which risks have the most potential
impact on the project.
It examines the extent to which variation of a project
element affects a project objective when all other
uncertain elements are held at their baseline values.
We can apply switching values in Sensitivity analysis
5/19/2023 185
Analyzing Risk …
Switching value (SV):
is the change in the value for the variable concerned required to
reduce the NPV of the project to zero.
NPV 1
SV ( ) P%
NPV2 NPV1
Where:
NPV1 is the base value for the project NPV and
5/19/2023 187
Analyzing Risk …
Situation II: Assume that there is a 10% increase in
the Raw Material Costs (hides and skins).
It reduces the NPV at a discount rate of 10% from
1,312,800 to – 1,459,800.
To reduce the NPV to zero would therefore require
an increase of: 1312800
* 10% 4.8%
SV= 1459800 1312800
The project is very sensitive to an increase in the cost
of hides and skins, but it is not as a critical factor as
fluctuation in sales revenue (2.7% increase sufficient
to reduce NPV to zero at a discount rate of 10%).
5/19/2023 188
Analyzing Risk …
Class work
Situation III: Assume that the production level
achieved by the project is 10% below the level expected.
A 10% reduction in the level of production reduces the NPV to –
6,700 (i.e., to just below zero). Based on the given determine
a. Switching value which makes the NPV zero
b. Which one is more risky for this project (situation I, II or
III )
5/19/2023 189
Analyzing Risk …
Potential shortfalls using quantitative risk analysis
techniques:
1. Data quality: It is essential to avoid the GIGO situation
(garbage in garbage out), and attention must be paid to
ensuring good quality inputs to the model.
2. Interpretation: Outputs from risk models require
interpretation, and Quantitative Risk Analysis will not tell
the project manager what decision to make.
3. Action: The project team must be prepared to use the
results of risk modeling, and to take decisions based on the
analysis.
You should beware of “analysis paralysis” since quantitative risk
analysis is merely a means to an end, and must lead to action.
5/19/2023 190
Analyzing Risk …
5/19/2023 191
4.3 Assessment of Risk (Impact, Probability & Urgency)
Risk assessment
It is the combined effort of:
identifying and analyzing potential events that may negatively
impact individuals, assets, and/or the environment; and
making judgments "on the tolerability of the risk on the basis of a
risk analysis" while considering influencing factor.
5/19/2023 192
Risk assessment…
Steps to Risk Assessment:
1. Make a commitment as an organization to RM
2. Identify all possible material threats and risks.
3. Assess the level of each risk.
4. Decide to accept, treat or transfer each risk.
5. Determine treatment options for all unacceptable risks.
6. Formalize your RM action plan.
7. Implement your treatment options.
8. Communicate information to everyone affected.
9. Review your RM action plan on a periodical basis
10. Identify any new risks and update your plan.
5/19/2023 193
Risk assessment…
Risk Assessment Impact/Probability:
Probability
The probability of it occurring can range anywhere from
just above 0 percent to just below 100 percent.
It can't be exactly 100 percent, because then it would be a
certainty, not a risk.
It can't be exactly 0 percent, or it wouldn't be a risk
Impact
A risk, by its very nature, always has a negative impact.
However, the size of the impact varies in terms of cost and
impact on health, human life, or some other critical factor.
We can have three possibilities as explained bellow
5/19/2023 194
Risk assessment…
1. High Priority: A high risk-high impact scenario, for instance,
would undeniably be a zero-day attack, whereby hackers spot
a way of exploiting a previously unidentified weakness.
2. Medium Priority: An example of a medium-risk occurrence
can be a former worker stealing information after being
terminated from work. While most employees just go from one
occupation to the next, others may be discontented.
3. Low Priority: Low-risk cases include somebody breaking into
your company offices and stealing various devices. The
possibility of this event happening is low. Also, the possibility of
data loss is low, especially if the devices do not have any stored
information on them
5/19/2023 195
Risk assessment…
Definition of Probability and Impacts
5/19/2023 196
Risk assessment…
5/19/2023 197
Risk assessment…
The Risk Impact/Probability Chart
5/19/2023 198
Risk assessment…
The corners of the chart have these characteristics:
1. Low impact/low probability – Risks in the bottom left corner
are low level, and you can often ignore them.
2. Low impact/high probability – Risks in the top left corner are
of moderate importance – if these things happen, you can cope
with them and move on. However, you should try to reduce the
likelihood that they'll occur.
3. High impact/low probability – Risks in the bottom right
corner are of high importance if they do occur, but they're very
unlikely to happen. For these, however, you should do what you
can to reduce the impact they'll have if they do occur, and you
should have contingency plans in place just in case they do.
4. High impact/high probability – Risks towards the top right
corner are of critical importance. These are your top priorities,
and are risks that you must pay close attention to.
5/19/2023 199
Risk assessment…
Key Points
To successfully implement a project, you must identify and
focus your attention on middle and high-priority risks –
otherwise you risk spreading your efforts too thinly, and
you'll waste resources on unnecessary risk management.
With the Risk Impact/Probability Chart, you map out each
risk and its position determines its priority.
High-probability/high-impact risks are the most critical, &
you should put a great deal of effort into managing these.
The low-probability/high-impact risks and high-
probability/low-impact risks are next in priority, though
you may want to adopt different strategies for each.
Low-probability/low-impact risks can often be ignored
5/19/2023 200
Risk assessment…
The risk urgency assessment
It is a project management process that reviews and
determines the timing of actions that need to happen
sooner than the other risk items.
Its purpose of risk assessment is that it identifies the
near term risks.
It allows project managers to identify which risks
should be considered urgent or requires their
immediate attention.
There are different factors that can help project
managers identify near-term risks to effectively carry
out risk urgency assessment.
5/19/2023 201
Risk assessment…
Many factors that characterize urgent risks
1. Time available:
The project management team needs a certain amount of time to
implement responses and the responses are useful only if they are
implemented within a certain time frame.
2. Warning signs of risks:
The warning signs of risks are also called risk triggers.
It help RM team identify if a certain risk requires urgent responses.
Some risks allow small response window for the risk management
team while some require a large window.
3. Risk rating score:
Is numeric rating based on the impact and probability of risk.
It means that risks with higher scores are risks may occur soon.
5/19/2023 202
4.4 Risk Management Actions/Responses
After the risk has been identified and assessed, the project
team develops a risk management action plan.
It is the process of developing options and determining
actions to enhance opportunities and reduce threats to
the project’s objectives.
It provides vital information for what actions need to be
taken if a risk occurs or is occurring
The plan requires numerous components, including:
risk description associated with risk analysis and assessment
planned action to respond to the risk arising
owner of risk response actions
commitment date required to finalize actions.
5/19/2023 203
RM Actions…
The effectiveness of RM action plan determine
whether risk increases or decreases for the project.
Risk management action planning is appropriate to:
the severity of the risk,
cost effective in meeting the challenge,
timely to be successful,
realistic within the project context,
agreed upon by all parties involved, and
owned by a responsible person.
5/19/2023 204
RM Actions…
RM Action plan inputs
1. Risk management plan
2. List of prioritized risks.
3. Risk ranking of the project.
4. Prioritized list of quantified risks.
5. Probabilistic analysis of the project.
6. Probability of achieving the cost and time objectives.
7. List of potential responses.
8. Risk thresholds and trends.
9. Risk owners.
[Link] risk causes.
5/19/2023 205
RM Actions…
RM Action plan tools and techniques
1. Expert judgments
2. Data gathering (interview)
3. Interpersonal and team skills
4. Strategies for treats
5. Strategies for opportunities
6. Contingency response strategies
7. Strategies for overall project risk
8. Data analysis (alternative and cost-benefit analysis)
9. Decision makings
5/19/2023 206
RM Actions…
RM Action plan outputs
1. Change request
2. Project management plan updates
3. Project documents update
4. Minimized/avoided negative risks
5. Maximized / Optimized positive risks
5/19/2023 207
RM Actions…
RM Actions Strategies for negative risks:
1. Accepting
2. Avoiding
3. Mitigating
4. Transferring/ Insurance
5. Ownership
RM Actions Strategies for positive risks
1. Exploit the situation
2. Enhance the probability
3. Share the ownership
4. Accept the opportunity
5/19/2023 208
RM Actions…
1. Risk Acceptance
It can involve collaboration between team members to
identify the possible risks of a project and whether the
consequences of the identified risks are acceptable
The team members may also identify and assume the
possible vulnerabilities that risks present.
This strategy is commonly used for identifying and
understanding the risks that can affect a project’s output
the purpose of this strategy helps bring these risks to the
business’ attention so everyone working on the project has a
shared understanding of the risks and consequences
involved.
5/19/2023 209
RM Actions…
Risk Acceptance Examples
Risks impacting cost
A project team might implement the accept strategy to identify
risks to the project budget and make plans to lower the risk of
going over budget, so that all team members are aware of the risk
and possible consequences.
Risks impacting schedule
The accept strategy could help identify possible risks that could
impact scheduling, such as keeping the project on track to meet
deadlines.
Risks impacting performance
It involve performance issues like team productivity or product
performance and can be identified and accepted as part of project
planning so all members are aware of potential performance risks.
5/19/2023 210
RM Actions…
2. Risk avoidance
This strategy presents the accepted and assumed
risks and consequences of a project and presents
opportunities for avoiding those accepted risks.
It to plan for risk and then take steps to avoid it.
5/19/2023 211
RM Actions…
Risk avoidance examples:
Risk to performance
insufficient resources to perform the work,
inadequate design or poor team dynamics
Risk to schedule
Miss planed important deadlines, due dates and final
delivery dates.
schedule conflicts
Risk to cost
consequences of going over budget
For the above stated risks, the project team acts to avoid
the threat or protect the project from its impact.
5/19/2023 212
RM Actions…
3. Risk Mitigation
It is a strategy whereby the project team acts to reduce the
probability of occurrence or impact of a risk.
There are certain risks that cannot be eliminated, as a result
we need at least reduce its impact through mitigation.
It consider strategies like
taking early action to reduce the probability,
5/19/2023 213
RM Actions…
Risk mitigation Examples
5/19/2023 214
RM Actions…
4. Risk Transference
The transference strategy works by transferring the strain of the
risk and consequences of another party but it should be in a way
acceptable to all parties involved.
Is shifting the risk to a third party for the management of the risk.
It does not eliminate the risk, and could involve insurance,
warranties, and bonds.
A classic example of risk transfer is the purchase of an insurance.
The risk is transferred from the project to the insurance company.
Purchasing an insurance is usually in areas beyond the control of
the project team.
Weather, political unrest, and strikes are examples of events that
can have a significant impact on the project and that are beyond
the control of the project team.
Simply put, it is simply a matter of paying someone else to
accept the risk.
5/19/2023 215
RM Actions…
Risk Transference Examples
Transference for performance
Product defects caused by materials purchased from an
outside vendor. (transfer responsibility to outside vendor)
Transference for scheduling
a project takes longer time to complete (transfer
responsibility to project team members)
Transference for cost
project that goes over budget (holding accountants and
financial advisors accountable for issues in budgeting).
5/19/2023 216
RM Actions…
5. Risk ownership
It is means of controlling risk by assigning ownership
5/19/2023 217
4.5 Risk Reviewing
Your risk assessment should be reviewed on a regular
basis to ensure that the risk of staff harm from
workplace violence has not changed and that no
additional control measures are required.
It should also be reviewed if any changes in your business
occur that may increase the risk of violence, such as lone
working or changes in the nature of the work you do.
There is no legal time limit for reviewing your risk assessment
It is up to you to decide when a review is necessary, but the
risk assessment is a living document that should be recorded
and updated as your company’s experiences change.
5/19/2023 218
Risk Reviewing…
Usually risk reviews are included in the regular agenda
of project management meetings and used at most
project phases and milestones.
Risk reviews facilitate better change management and
continuous improvement.
Risk reviewing strategy should acknowledge successful
risk taking as well as providing support for officers in
the event of failures if risks were well managed
In most projects and businesses risk reviewing are
performed through monitoring and controlling
5/19/2023 219
Risk Reviewing…
Risk monitoring and control (M&C)
It is putting the risk plans into action and examining the
results of those plans
It records risk metrics that are associated with implementing
contingency plans.
It is an ongoing process for the life of the project.
5/19/2023 220
Risk Reviewing…
Risk M&C…
It is the process of
Tracking and monitoring identified risks
Responding to risks as they occur
Monitoring residual and secondary risks
Identifying new risks
Evaluating risk response plans that are put into action
Monitoring for risk triggers
Ensuring that risk policies and procedures are followed
Ensuring that risk response plans and contingency plans
are appropriate & effective
5/19/2023 221
Risk Reviewing…
The purpose of Risk M&C
It is to determine if:
Risk responses have been implemented as planned.
Risk response actions are as effective as expected or if new
responses should be developed.
Project assumptions are still valid.
5/19/2023 222
Risk Reviewing…
Inputs to risk M&C
[Link] management plan
It is the process of defining how to conduct RM activities for a project.
It ensures degree, type& visibility of RM proportionate to the project.
[Link] Register:
Contains outputs of the other processes: identified risks & owners,
risk responses, triggers and warning signs
[Link] Change Requests:
Approved changes include modifications such as to scope, schedule,
method of work, or contract terms.
This may often require new risk analysis to consider impact on existing
plan & identifying new risks and corresponding responses
[Link] Performance Information:
Project status and performance reports are necessary for risk
monitoring and control of risks.
5/19/2023 223
Risk Reviewing…
Tools and techniques for risk M&C
1. Reassessment
Project risk reviews at all team meetings.
Major reviews at major milestones
2. Risk audits:
Examine and document the effectiveness of the risk response
3. Variance and Trend Analysis:
Used for monitoring overall project cost & Schedule performance against a baseline plan.
Significant deviations indicate updated risk identification & analysis should performed.
4. Reserve Analysis:
compares available reserves with amount of risk remaining at the time and
determines whether reserves are sufficient
5. Status meetings:
discussions with risk’s owner, share experience & helping managing the risks.
5/19/2023 224
Risk Reviewing…
Output from Risk M&C
1. Risk Register Updates:
updated probability, impact, rank, response, etc...
2. Corrective action:
It consists of performing contingency plan or workaround (previously
unplanned responses to emerging risks).
3. Recommended Preventive Actions:
Used to direct project towards compliance with the PMP
4. Project change requests:
is issuance of a change request that is managed by overall change control.
5. Organizational Process Assets Updates:
Information gained by RMP are collected and kept for future projects
6. Project Management Plan Updates:
Updates to the RMP as a result of approval of requested changes.
5/19/2023 225
4.6 Re-evaluating Risk
Risk re-evaluation in project management involves re-
assessing current Hazards.
Risk Managers will keep checking if the impact and/or the
probabilities of risks are the same now as compared to when
were planned before.
The level of impact of a risk or its probability could change
when project execution begins.
It is the work done to update the original risk assessment
due to changes in the project or overall risk management
efforts.
5/19/2023 226
The end !
Thank you
5/19/2023 227