NATIONAL ECONOMICS UNIVERSITY
STRATEGIC RISK ANALYSIS AND MANAGEMENT
CONTENTS
1. DEFINITION
2. RISK MANAGEMENT PROCESS
3. DISCUSSION
DEFINITION
DEFINITION
• Risk
• Uncertain or chance events that planning can not overcome or
control.
• Risk Management
• A proactive attempt to recognize and manage internal events and
external threats that affect the likelihood of a project’s success.
• What can go wrong (risk event).
• How to minimize the risk event’s impact (consequences).
• What can be done before an event occurs (anticipation).
• What to do when an event occurs (contingency plans).
7–4
DEFINITION
• Strategic risk assessment is the process of identifying and
managing the specific risks that affect an organization's ability
to achieve key objectives.
• Strategic risks are the risks that are most consequential to the
organization’s ability to execute its strategy and achieve its
objectives, potentially affecting shareholder value and the viability of
the entire company
7–5
RISK ASSESSMENT CHECKLIST
1. Understand the strategies of the organization
2. Collect data and views on strategic risks from the organization
3. Prepare a preliminary strategic risk profile
4. Validate and finalize the strategic risk profile with management and
the Board
5. Develop a strategic risk management action plan
6. Communicate the strategic risk profile and action plan
7. Implement the enterprise risk management action plan
7–6
RISK MANAGEMENT BENEFITS
• A proactive rather than reactive approach.
• Reduces surprises and negative consequences.
• Prepares the project manager to take advantage
of appropriate risks.
• Provides better control over the future.
• Improves chances of reaching project performance
objectives within budget and on time.
7–7
RISK MANAGEMENT PROCESS
RISK MANAGEMENT PROCESS
7–9
STEP 1: RISK IDENTIFICATION
• Step 1: Risk Identification
• Generate a list of possible risks through
brainstorming, problem identification and
risk profiling.
• Macro risks first, then specific events
7–10
STEP 2: RISK ASSESSMENT
• Step 2: Risk Assessment
• Scenario analysis for event probability and
impact
• Risk assessment matrix
• Failure Mode and Effects Analysis (FMEA)
• Probability analysis
• Decision trees, NPV, and PERT
• Semi-quantitative scenario analysis
7–11
EXAMPLE OF IMPACT SCALE
Risk Assessment Form
Risk Severity Matrix
PROBABILITY ANALYSIS - PERT
• PERT is almost identical to the critical path method (CPM) technique
except it assumes each activity duration has a range that follows a
statistical distribution. PERT uses three time estimates for each
activity.
• a beta distribution for activity durations
PERT PROCEDURE AND CALCULATION
• Estimate each activity duration at three point:
• optimistic activity time
• pessimistic activity time
• most likely activity time
• Compute the weighted average duration for each activity (equation 7.1)
• Place on project network: the average (deterministic) value, the early,
late, slack, and project completion times as in the CPM method
• Calculate the variability in the activity time estimates
• the standard deviation for the activity (equation 7.2)
• the standard deviation for the project (equation 7.3)
• Calculate the average project duration (TE) is the sum of all the average
activity times along the critical path (sum of te)
• Calculate the probability of completing the project by a specific time (Z)
EXAMPLE
EXAMPLE
EXAMPLE
• What is the probability the project will be completed
before a scheduled time (T ) of 67?
• What is the probability of completing the project by
time period 60?
EXAMPLE
EXAMPLE
STEP 3: RISK RESPONSE
• Mitigating Risk
• Reducing the likelihood an adverse event will occur.
• Reducing impact of adverse event.
• Avoiding Risk
• Changing the project plan to eliminate the risk or condition.
• Transferring Risk
• Paying a premium to pass the risk to another party.
• Requiring Build-Own-Operate-Transfer (BOOT) provisions.
• Retaining Risk
• Making a conscious decision to accept the risk.
7–24
Contingency Planning
• Contingency Plan
• An alternative plan that will be used if a possible
foreseen risk event actually occurs.
• A plan of actions that will reduce or mitigate the
negative impact (consequences) of a risk event.
• Risks of Not Having a Contingency Plan
• Having no plan may slow managerial response.
• Decisions made under pressure can be potentially
dangerous and costly. 7–25
Contingency Planning
• Contingency Plan vs. Response Plan
• a response is part of the actual implementation plan and
action is taken before the risk can materialize
• a contingency plan is not part of the initial
implementation plan and only goes into effect after the
risk is recognized
7–26
Risk and Contingency Planning
Technical Schedule
risks risks
Cost Funding
risks risks
7–28
Risk and Contingency Planning
• Technical Risks
• Backup strategies if chosen technology fails.
• Assessing whether technical uncertainties
can be resolved.
• Schedule Risks
• Use of slack increases the risk of a late project finish.
• Imposed duration dates (absolute project finish date)
• Compression of project schedules due to a shortened
project duration date. 7–29
Risk and Contingency Planning (cont’d)
• Costs Risks
• Time/cost dependency links: costs increase when
problems take longer to solve than expected.
• Price protection risks (a rise in input costs) increase if
the duration of a project is increased.
• Funding Risks
• Changes in the supply of funds for the project can
dramatically affect the likelihood of implementation
or successful completion of a project.
7–30
Contingency Funding and Time Buffers
• Contingency Funds
• Funds to cover project risks—identified and unknown.
• Size of funds reflects overall risk of a project
• Budget reserves
• Are linked to the identified risks of specific work packages.
• Management reserves
• Are large funds to be used to cover major unforeseen risks (e.g., change in
project scope) of the total project.
• Time Buffers
• Amounts of time used to compensate for unplanned delays in the
project schedule.
• Severe risk, merge, noncritical, and scarce resource activities
7–31
STEP 4: RISK RESPONSE CONTROL
• Risk control
• Execution of the risk response strategy
• Monitoring of triggering events
• Initiating contingency plans
• Watching for new risks
• Establishing a Change Management System
• Monitoring, tracking, and reporting risk
• Fostering an open organization environment
• Repeating risk identification/assessment exercises
7–32
• Assigning and documenting responsibility for managing risk
Change Control System Process
1. Identify proposed changes.
2. List expected effects of proposed changes on schedule and budget.
3. Review, evaluate, and approve or disapprove of changes formally.
4. Negotiate and resolve conflicts of change, condition, and cost.
5. Communicate changes to parties affected.
6. Assign responsibility for implementing change.
7. Adjust master schedule and budget.
8. Track all changes that are to be implemented
7–33
Benefits of a Change Control System
1. Inconsequential changes are discouraged by the formal process.
2. Costs of changes are maintained in a log.
3. Integrity of the WBS and performance measures is maintained.
4. Allocation and use of budget and management reserve funds are
tracked.
5. Responsibility for implementation is clarified.
6. Effect of changes is visible to all parties involved.
7. Implementation of change is monitored.
8. Scope changes will be quickly reflected in baseline and
performance measures. 7–34
DISCUSSION
CASE XSU Spring Concert
PAGE 235
CASE XSU Spring Concert
PAGE 235
THANK YOU!