Project Risk Management
o PMBOK® Guide 6th Edition 2017 (Project Management Institute)
o Project Management The Managerial Process 7th Edition 2017 (Erik W. Larson, Clifford F. Gray)
o Et cetera
👦 Hello!
Cahyono Bintang Nurcahyo
Institut Teknologi Sepuluh Nopember
cbintangn@[Link]
2
Project
o PMBOK® Guide 6th Edition 2017 (Project Management Institute)
o Project Management The Managerial Process 7th Edition 2017 (Erik W. Larson, Clifford F. Gray)
o Et cetera
3
4
All of mankind’s greatest accomplishments
— from building the great pyramids, to
discovering a cure for polio, to putting a
man on the moon — began as a project.
“
PROJECT
◉ Millions watch Olympic Opening Ceremony
◉ Citywide WiFi System Set to Go Live
◉ Hospitals Respond to New Healthcare Reforms
◉ Apple’s New iPhone Hits the Market
◉ City Receives Stimulus Funds to Expand Light Rail
System
5
PROJECT
◉ Project is temporary endeavor undertaken to
create a unique product or service.
(PMBOK Guide 2017)
6
PROJECT
◉ The major characteristics of a project are as
follows:
○ An established objective.
○ A defined life span with a beginning and an end.
○ Usually, the involvement of several departments and
professionals.
○ Typically, doing something that has never been done
before.
○ Specific time, cost, and performance requirements.
7
PROJECT
8
A limiting factor that affects the execution of a project, program, portfolio, or process.
PMBOK Guide 2008
9
Risk
o Project Management The Managerial Process 7th Edition 2017 (Erik W. Larson, Clifford F. Gray)
o Et cetera
10
11
You’ve got to go out on a limb sometimes
because that’s where the fruit is.
Will Rogers
“
RISK
◉ In the context of projects, risk is an uncertain event
or condition that, if it occurs, has a positive or
negative effect on project objectives.
◉ A risk has a cause and, if it occurs, a consequence.
◉ For example, a cause may be a flu virus.
The event is that team members get stricken with the flu.
If this uncertain event occurs, it will impact the cost, schedule, and quality
of the project.
12
RISK
◉ Some potential ◉ Risks can be ◉ Risks can be
risk events can anticipated beyond
be identified consequences imagination —
before the — like schedule like the 2008
financial meltdown.
project starts — slippages or cost
such as equipment overruns.
malfunction or
change in technical
requirements.
13
SOURCE OF PROJECT RISK
◉ Uniqueness
◉ Different stakeholders
◉ People
◉ Assumption
◉ Constraints and objectives
◉ Change
◉ Environment
14
15
RISK CONTINUUM
Total Risk Uncertainty No Risk
Unknown Known
Known
Unknown Unknown
No Information Partial Information Complete Information
o Feasibility Study o Close-out Report
o Enter New Market o Identifies Unknown o Project Succesfully
Issues Completed
16
Tingkat Ketidakpastian
Tingkat Ketidakpastian Karakteristik Contoh
Hukum alam (Lama bumi
Tidak ada (pasti) Hasil bisa diprediksi dengan pasti
mengitari matahari)
Hasil bisa diidentifikasi dan
Ketidakpastian Obyektif Permainan dadu, kartu
probabilitas diketahui
Hasil bisa diidentifikasi, tapi Kebakaran, kecelakaan mobil,
Ketidakpastian Subyektif
probabilitas tidak diketahui investasi
Hasil tidak bisa diidentifikasi dan
Sangat Tidak Pasti Eksplorasi angkasa
probabilitas tidak diketahui
Sumber : Hanafi (2006) 17
Project Management
o PMBOK® Guide 6th Edition 2017 (Project Management Institute)
18
Interrelationship of
PMBOK® Guide
Key Components in Projects
Project Management
◉ The project life cycle is managed by executing a series of
project management activities known as project
management processes.
◉ Project management is accomplished through the
appropriate application and integration of logically grouped
project management processes.
◉ The PMBOK® Guide groups processes into five categories
called Process Groups.
Project Management Process Group
5. Closing
4.
Monitoring
2. Planning
&
Controlling
3. Executing
1. Initiating
Project Management Process Group
Initiating Process Group à to define a new project or a new phase of an
existing project by obtaining authorization to start the project or phase.
Planning Process Group à to establish the scope of the project, refine the
objectives, and define the course of action required to attain the objectives
that the project was undertaken to achieve.
Executing Process Group à to complete the work defined in the project
management plan to satisfy the project requirements.
Monitoring and Controlling Process Group à to track, review, and regulate
the progress and performance of the project; identify any areas in which
changes to the plan are required; and initiate the corresponding changes.
Closing Process Group à to formally complete or close the project, phase, or
contract.
10 Knowledge Areas
Project Integration Management
Project Scope Management
Project Schedule Management
Project Cost Management
Project Quality Management
Project Resource Management
Project Communications Management
Project Risk Management
Project Procurement Management
Project Stakeholder Management
Construction Extension
Project Health Safety
Security Enviroment
(HSSE) Management
Project Financial
Management
Project Risk Management
o PMBOK® Guide 6th Edition 2017 (Project Management Institute)
o Project Management The Managerial Process 7th Edition 2017 (Erik W.
Larson, Clifford F. Gray)
o Et cetera
25
Project Risk Management
◉ Risks will continue to emerge during the lifetime of the
project, so Project Risk Management processes should be
conducted iteratively.
◉ In order to manage risk effectively on a particular project,
the project team needs to know what level of risk exposure
is acceptable in pursuit of the project objectives.
◉ This is defined by measurable risk thresholds that reflect
the risk appetite of the organization and project
stakeholders.
26
Project Risk Management
◉ The objectives of Project Risk Management are :
○ to increase the probability and/or impact of
positive risks and
○ to decrease the probability and/or impact of
negative risks
○ in order to optimize the chances of project
success.
27
Project Risk Management
◉ 1. Plan Risk Management
◉ 2. Identify Risks
◉ 3. Perform Qualitative Risk Analysis
◉ 4. Perform Quantitative Risk Analysis
◉ 5. Plan Risk Responses
◉ 6. Implement Risk Responses
◉ 7. Monitor Risks
30
Planning
Process
Group
1 PLAN RISK MANAGEMENT
◉ The process of defining how to conduct risk
management activities for a project.
◉ It ensures that the degree, type, and visibility of risk
management are proportionate to both risks and the
importance of the project to the organization and
other stakeholders.
◉ Performed once or at predefined points in the
project.
31
32
Output : Risk Management Plan
◉ The Risk Management Plan is a component of the
project management plan that describes how risk
management activities will be structured and
performed.
33
Output : Risk Management Plan
◉ Risk strategy. Describes the general approach to managing
risk on this project.
◉ Methodology. Defines the specific approaches, tools, and
data sources that will be used to perform risk management
on the project.
◉ Roles and responsibilities. Defines the lead, support, and
risk management team members for each type of activity
described in the risk management plan, and clarifies their
responsibilities.
34
Output : Risk Management Plan
◉ Funding. Identifies the funds needed to perform activities related
to Project Risk Management. Establishes protocols for the
application of contingency and management reserves.
◉ Timing. Defines when and how often the Project Risk
Management processes will be performed throughout the project
life cycle, and establishes risk management activities for inclusion
into the project schedule.
◉ Risk categories. Provide a means for grouping individual project
risks. A common way to structure risk categories is with a risk
breakdown structure (RBS), which is a hierarchical representation
of potential sources of risk.
35
36
37
Output : Risk Management Plan
◉ Stakeholder risk appetite. The risk appetites of key
stakeholders on the project are recorded in the risk
management plan, as they inform the details of the Plan
Risk Management process.
◉ Definitions of risk probability and impacts. Definitions of
risk probability and impact levels are specific to the project
context and reflect the risk appetite and thresholds of the
organization and key stakeholders.
38
39
40
Output : Risk Management Plan
◉ Probability and impact matrix. Opportunities and threats
are represented in a common probability and impact
matrix using positive definitions of impact for opportunities
and negative impact definitions for threats.
◉ Reporting formats. Reporting formats define how the
outcomes of the Project Risk Management process will be
documented, analyzed, and communicated.
◉ Tracking. Tracking documents how risk activities will be
recorded and how risk management processes will be
audited.
41
42
Planning
Process
Group
2 IDENTIFY RISK
◉ The process of identifying individual project risks as well as
sources of overall project risk, and documenting their
characteristics.
◉ The documentation of existing individual project risks and
the sources of overall project risk. It also brings together
information so the project team can respond appropriately
to identified risks.
◉ Performed throughout the project.
43
44
Tools & Techniques
◉ Expert Judgement
◉ Data Gathering
○ Brainstorming
○ Checklists
○ Interviews
◉ Data Analysis
○ Root Cause Analysis
○ Assumption and Constraint Analysis
○ SWOT Analysis
45
T&T : Root Cause Analysis
46
T&T : Root Cause Analysis
47
5 Whys
48
Fishbone Diagram
49
Fault Tree Analysis
50
T&T : SWOT Analysis
SWOT Strength Weakness Internal
Opportunity +
Threath -
External
51
Outputs : Risk Register
◉ Risk register may include but is not limited to:
○ List of identified risks.
○ Potential risk owners.
○ List of potential risk responses.
Potential Risk Potential Risk
Risk Variable
Owner Response
1. Risk A Dept X Mitigate
2. Risk B Division Y Accept
3. Risk C Vendor Z Transfer
52
Planning
Process
Group
PERFORM QUALITATIVE
3
RISK ANALYSIS
◉ The process of prioritizing individual project risks
for further analysis or action by assessing their
probability of occurrence and impact as well as
other characteristics.
◉ It focuses efforts on high-priority risks.
◉ Performed throughout the project.
53
54
Tools & Techniques
◉ Expert Judgement
◉ Data Gathering
○ Interviews
◉ Data Analysis
○ Risk Data Quality Assesment
○ Risk Probability Impact Assesment
55
T&T : Risk Probability Impact Assesment
◉ Risk probability assessment considers the likelihood
that a specific risk will occur.
◉ Risk impact assessment considers the potential effect
on one or more project objectives such as schedule,
cost, quality, or performance.
○ Impacts will be negative for threats and positive for
opportunities.
◉ Probability and impact are assessed for each
identified individual project risk.
56
57
Tools & Techniques (2)
◉ Data Representation
○ Probability Impact Matrix
○ Hierarchical Chart
(example : Bubble Chart)
58
59
Proximity.
○ The period of time
before the risk might
have an impact on one
or more project
objectives.
○ A short period indicates
high proximity.
Detectability.
○ The ease with which the
results of the risk
occurring, or being about
to occur, can be detected
and recognized.
○ Where the risk
occurrence can be
detected easily,
detectability is high.
60
Outputs : Updated Risk Register
Potential Risk Potential Risk
Risk Variable Probability Impact Classification
Owner Response
1. Risk A 3 4 Moderate Dept X Mitigate
2. Risk B 2 1 Minor Division Y Accept
3. Risk C 5 4 Major Vendor Z Transfer
61
Planning
Process
Group
PERFORM QUANTITATIVE
4
RISK ANALYSIS
◉ Is the process of numerically analyzing the combined
effect of identified individual project risks and other
sources of uncertainty on overall project objectives.
◉ It quantifies overall project risk exposure, and it can
also provide additional quantitative risk information
to support risk response planning.
◉ Is not required for every project, but where it is used,
it is performed throughout the project.
62
Planning
Process
Group
PERFORM QUANTITATIVE
4
RISK ANALYSIS
◉ Undertaking a robust analysis depends on the
availability of high-quality data about individual
project risks and other sources of uncertainty, as well
as a sound underlying project baseline for scope,
schedule, and cost.
◉ It also consumes additional time and cost.
63
64
T&T : Data Analysis
◉ Simulation
○ Quantitative risk analysis uses a model that simulates
the combined effects of individual project risks and
other sources of uncertainty to evaluate their potential
impact on achieving project objectives.
○ Simulations are typically performed using a Monte
Carlo analysis.
65
66
T&T : Data Analysis
◉ Sensitivity Analysis
○ Sensitivity analysis helps to determine which individual
project risks or other sources of uncertainty have the
most potential impact on project outcomes.
○ It correlates variations in project outcomes with
variations in elements of the quantitative risk analysis
model.
○ One typical display of sensitivity analysis is the tornado
diagram.
67
68
T&T : Data Analysis
◉ Decision Tree Analysis
○ Used to support selection of the best of several
alternative courses of action.
○ Alternative paths through the project are shown in the
decision tree using branches representing different
decisions or events, each of which can have associated
costs and related individual project risks (including
both threats and opportunities).
69
T&T : Data Analysis
◉ Decision Tree Analysis (2)
○ The end-points of branches in the decision tree
represent the outcome from following that particular
path, which can be negative or positive.
○ The decision tree is evaluated by calculating the
expected monetary value of each branch, allowing the
optimal path to be selected
70
71
Outputs : Updated Risk Report
◉ Assessment of overall project risk exposure.
○ Chances of project success
○ Degree of inherent variability remaining within the project
◉ Detailed probabilistic analysis of the project.
◉ Prioritized list of individual project risks.
◉ Trends in quantitative risk analysis results.
◉ Recommended risk responses.
72
Planning
Process
Group
5 PLAN RISK RESPONSE
◉ The process of developing options, selecting
strategies, and agreeing on actions to address overall
project risk exposure.
◉ It identifies appropriate ways to address project risks.
◉ Also allocates resources and inserts activities into
project documents and the project management plan
as needed.
◉ Performed throughout the project.
73
Strategies
◉ Threaths ◉ Opportunities
○ Escalate ○ Escalate
○ Avoid ○ Exploit
○ Transfer ○ Share
○ Mitigate ○ Enhance
○ Accept ○ Accept
74
- Escalate Threats
◉ Escalation is appropriate when the project team or the
project sponsor agrees that a threat is outside the scope of
the project or that the proposed response would exceed
the project manager’s authority.
◉ Escalated risks are managed at the program level, portfolio
level, or other relevant part of the organization, and not on
the project level.
75
- Avoid Threats
◉ Eliminate the threat or protect the project from its impact.
◉ It may be appropriate for high-priority threats with a high
probability of occurrence and a large negative impact.
◉ Examples of avoidance actions may include removing the
cause of a threat, extending the schedule, changing the
project strategy, or reducing scope.
◉ Some risks can be avoided by clarifying requirements,
obtaining information, improving communication, or
acquiring expertise.
76
- Transfer Threats
◉ Transfer involves shifting ownership of a threat to a third
party to manage the risk and to bear the impact if the
threat occurs.
◉ Risk transfer often involves payment of a risk premium to
the party taking on the threat.
◉ Transfer can be achieved by a range of actions, which
include but are not limited to the use of insurance,
performance bonds, warranties, guarantees, etc.
◉ Agreements may be used to transfer ownership and
liability for specified risks to another party. 77
- Mitigate Threats
◉ To reduce the probability of occurrence and/or impact of a
threat. Early mitigation action is often more effective than
trying to repair the damage after the threat has occurred.
◉ Adopting less complex processes, conducting more tests, or
choosing a more stable seller are examples of mitigation
actions.
◉ Where it is not possible to reduce probability, a mitigation
response might reduce the impact by targeting factors that
drive the severity.
78
- Accept Threats
◉ Acknowledges the existence of a threat, but no proactive
action is taken.
◉ This strategy may be appropriate for low-priority threats,
and it may also be adopted where it is not possible or cost-
effective to address a threat in any other way.
◉ Acceptance can be either active or passive.
79
- Accept Threats (2)
◉ Acceptance can be either active or passive.
○ The most common active acceptance strategy is to
establish a contingency reserve, including amounts of
time, money, or resources to handle the threat if it
occurs.
○ Passive acceptance involves no proactive action apart
from periodic review of the threat to ensure that it
does not change significantly.
80
+ Escalate Opportunities
◉ Escalation is appropriate when the project team or the
project sponsor agrees that an opportunity is outside the
scope of the project or that the proposed response would
exceed the project manager’s authority.
◉ Escalated opportunities are managed at the program level,
portfolio level, or other relevant part of the organization,
and not on the project level.
81
+ Exploit Opportunities
◉ May be selected for high-priority opportunities where the
organization wants to ensure that the opportunity is
realized.
◉ Seeks to capture the benefit associated with a particular
opportunity by ensuring that it definitely happens,
increasing the probability of occurrence to 100%.
◉ Examples of exploiting responses may include assigning an
organization’s most talented resources to the project to
reduce the time to completion, or using new technologies
or technology upgrades to reduce cost and duration.
82
+ Share Opportunities
◉ Involves transferring ownership of an opportunity to a third
party so that it shares some of the benefit if the
opportunity occurs.
◉ It is important to select the new owner of a shared
opportunity carefully so they are best able to capture the
opportunity for the benefit of the project.
◉ Examples of sharing actions include forming risk-sharing
partnerships, teams, special-purpose companies, or joint
ventures.
83
+ Enhance Opportunities
◉ Used to increase the probability and/or impact of an
opportunity. Early enhancement action is often more
effective than trying to improve the benefit after the
opportunity has occurred.
◉ Examples of enhancing opportunities include adding more
resources to an activity to finish early.
84
+ Accept Opportunities
◉ Accepting an opportunity acknowledges its existence but
no proactive action is taken.
◉ This strategy may be appropriate for low-priority
opportunities, and it may also be adopted where it is not
possible or cost-effective to address an opportunity in any
other way.
◉ Acceptance can be either active or passive.
85
86
Executing
Process
Group
6 IMPLEMENT RISK RESPONSE
◉ The process of implementing agreed-upon risk response
plans.
◉ It ensures that agreed-upon risk responses are executed as
planned in order to address overall project risk exposure,
minimize individual project threats, and maximize
individual project opportunities.
◉ Performed throughout the project.
87
88
Outputs
◉ Change Request
◉ Project documents updates :
○ Issue log
○ Lessons learned register
○ Project team assignments
○ Risk register
○ Risk report
89
Outputs : Change Request
◉ A change request is a formal proposal to modify
any document, deliverable, or baseline.
◉ When issues are found while project work is
being performed, change requests can be
submitted.
◉ Change requests can be initiated from inside or
outside the project and they can be optional or
legally/contractually mandated
90
Outputs : Change Request (2)
◉ Change requests may include:
○ Corrective action.
○ Preventive action.
○ Defect repair. An intentional activity to modify a
nonconforming product or product component.
○ Updates. Changes to formally controlled project
documents, plans, etc., to reflect modified or
additional ideas or content.
91
Outputs : Issue Log
◉ The issue log is a project document where all the issues are
recorded and tracked. Data on issues may include:
○ Issue type,
○ Who raised the issue and when,
○ Description,
○ Priority,
○ Who is assigned to the issue,
○ Target resolution date,
○ Status, and
○ Final solution.
92
Monitoring
& Controlling
Process Group
7 MONITOR RISKS
◉ The process of monitoring the implementation of agreed-
upon risk response plans, tracking identified risks,
identifying and analyzing new risks, and evaluating risk
process effectiveness throughout the project.
◉ It enables project decisions to be based on current
information about overall project risk exposure and
individual project risks.
◉ Performed throughout the project.
93
94
T&T : Data Analysis
◉ Technical performance analysis.
○ Compares technical accomplishments during project
execution to the schedule of technical achievement.
○ It requires the definition of objective, quantifiable measures
of technical performance, which can be used to compare
actual results against targets.
○ Such technical performance measures may include weight,
transaction times, number of delivered defects, storage
capacity, etc.
○ Deviation can indicate the potential impact of threats or
opportunities.
95
T&T : Data Analysis
◉ Reserve analysis.
○ Throughout execution of the project, some individual
project risks may occur with positive or negative impacts
on budget or schedule contingency reserves.
○ Reserve analysis compares the amount of the contingency
reserves remaining to the amount of risk remaining at any
time in the project in order to determine if the remaining
reserve is adequate.
○ This may be communicated using various graphical
representations, including a burndown chart.
96
Outputs : Work Performance Information
◉ Includes information on how project risk
management is performing by comparing the
individual risks that have occurred with the
expectation of how they would occur.
◉ This information indicates the effectiveness of
the response planning and response
implementation processes.
97
Thanks!
Any questions ?
You can find me at
◉ cbintangn@[Link]
98