12.
0 PROJECT RISK MANAGEMENT
Learning Outcomes
On completion of this session, Learners will be able to:
1. Define risk and risk management
2. Conduct a risk management process to help project managers and other
stakeholders identify potential risks, assess their likelihood and impact and
develop strategies to mitigate or manage those risks
Introduction
Risk is inevitable. There are risks on every project or business. But the impact of risks
to a project can be reduced through preparation and planning. The “Risk Management
Plan” will be the communication tool used by the project teams in planning for risk.
Through the execution of this plan, the negative impact of the risk to the project is
reduced or eliminated. A key to success in dealing with risk is to start early and lay the
foundation for risk management; that is, be proactive, not reactive; during the project
lifecycle.
12.1 Definitions of Risk
A risk is an event or condition that, if it occurs, could have a positive or negative
effect on a project’s objectives.
A risk is defined as the probability that the actual result is different from the
plan.
A risk is a potential problem – it might happen and it might not.
12.1.1 Two characteristics of risk
1. Uncertainty – the risk may or may not happen, that is, there are no 100% risks
(those, instead are called constraints).
2. Loss – the risk becomes a reality and unwanted consequences or losses occur.
12.2 Risk Management
Risk management is the process of conducting risk management planning,
identification, analysis, response planning, monitoring and control on a project. A well-
designed risk management process helps project managers identify potential risks,
assess their likelihood and impact, and develop strategies to mitigate or manage those
risks. In this topic, we will discuss an effective risk management process that can help
project managers achieve project success.
12.2.1 Step 1: Risk Identification
Identifying a list of potential risks is the first step in successful risk management.
Project managers should collaborate with their team and stakeholders to identify all
potential hazards to the project. Ask “What could go wrong?” There should be a
brainstorming session involving all stakeholders and think about the project's scope,
resources, budget, timetable, and stakeholders. To identify common hazards, project
managers can also look at past data from previous projects. All potential hazards
should be documented in a risk register, which is a living document that should be
maintained throughout the project lifecycle.
12.2.2 Step 2: Risk Assessment
The second step allows you to prioritize risk from the above list. How probable is that
the risk will happen? If risk occurs, how badly will it damage the project (impact) in
terms of cost, schedule, scope resources, etc? The process aims to identify the threats
and provide solutions on how to mitigate them by preventing their occurrence. The
methods of analyzing risks are qualitative risk analysis and quantitative risk
analysis.
[Link] Qualitative Risk Analysis
The qualitative analysis seeks to analyze individual project risk characteristics against a
pre-defined scale prearranged scale that uses H,M,L (High, Medium and Low). This
entails the risk's probability of occurrence and the impact it would cause on the project
if it occurred. This helps prioritize risks and decide which ones need to be managed
more urgently. Project managers use a risk matrix or other risk assessment tools such
as high, medium, or low likelihood/impact, qualitative and quantitative analysis and
Monte Carlo simulations. The tools help them prioritize risks and decide which ones
need to be managed urgently based on their likelihood and impact.
Example:
S/N RISK PROBABILITY IMPACT
1 A MEDIUM LOW
2 B MEDIUM MEDIUM
3 C LOW LOW
4 D HIGH HIGH
From the table above, it is clear that project team will focus more on risk D
[Link] Quantitative Risk Analysis
Quantitative risk analysis is the process of calculating risk based on data gathered. The
goal of quantitative risk analysis is to further specify how much the impact of the risk
will cost the business. This is achieved by using what’s already known to predict or
estimate an outcome. For data to be suitable for quantitative risk analysis, it has to
have been studied for a long period of time or to have been observed in multiple
situations. For example, in the past five projects, equipment type A has broken down
after 7 hours of use. With this information, it can be assumed that if a project requires
workers to use equipment type A for 8 hours, then it has a 100% chance of breaking
down. Since quantitative tools rely on numbers to express the level of risk, they
typically have more transparency and the validity of the analysis can be more easily
determined. Quantitative risk assessment relies on models. Models can range from
simple to complex. Some of the models include Failure Mode and Effects Analysis
(FMEA), Business Impact Analysis (BIA) and Expected Monetary Value (EMV).
Example:
S/N RISK PROBABILITY IMPACT (K) TOTAL
1 A 3 3 9
2 B 6 3 18
3 C 2 20 40
4 D 5 2 10
The table above shows that you can rate probability and impact, you assign a value to
each risk. The probability scale can be based on a range of 1 through 10, with 1
representing unlikely and 10 being very likely. Negative impact can be represented by
the same scale or in budgetary impact. According to this analysis, risk C will demand
most of this project team’s attention because of its relative value of 40K. It should be
noted that the same method can be used to focus on schedule impact or even resource
utilization.
[Link] Difference between qualitative and quantitative risk analysis
Quantitative risk analysis uses figures to determine the impact of the occurrence of a
risk in a project. In contrast, qualitative risk analysis uses relative and subjective terms
to determine the probability of occurrence and impact of a risk. Qualitative analysis is
based on a person’s perception or judgment while quantitative risk analysis is based
on verified and specific data. In qualitative risk analysis, this value is the risk rating or
scoring. A risk may be rated “Low” or given a score of 1 to indicate that the risk does
not require immediate attention. In quantitative analysis, the value associated with the
risk is often in percentages and indicates the probability of the risk occurring or of it
causing a specific negative effect on project objectives.
Here’s a clear comparison table showing the key differences between Quantitative
and Qualitative Risk Analysis:
Feature / Criteria Qualitative Risk Analysis Quantitative Risk Analysis
Purpose Prioritize risks based on Numerically estimate the impact
probability and impact of risks on project goals
Approach Subjective, based on expert Objective, using numerical data
judgment and categorization and statistical techniques
Data Required Limited data, mainly descriptive Detailed numerical data and
models
Risk ranking or priority (e.g., Quantified impact in terms of
Output
high, medium, low) cost, time or performance
Tools/Techniques Risk probability-impact matrix, Monte Carlo simulation,
Used risk categorization sensitivity analysis, decision
trees
Time & Cost Quicker and less expensive Time-consuming and costly
Accuracy Lower precision, good for early High precision, supports
analysis detailed decision-making
Used When In early stages of risk When more data is available and
assessment detailed analysis is needed
Decision Support Helps identify major risks to Supports risk-based decision
focus on making with numerical backing
12.2.3 Step 3: Planning for Risk Response
Once the risks have been identified and assessed, risk response plans must be
developed. Risk response techniques are actions that can be taken to lessen the
severity of a risk if it occurs. There are four main risk response strategies: avoidance,
transference, mitigation (minimizing) and acceptance. Taking steps to eliminate a risk
is what it means to avoid it. A risk is transferred when it is transferred to another party,
such as an insurance company. Mitigating a risk entails taking actions to lessen the
impact of the risk if it occurs. Accepting a risk entails admitting the risk and
developing a plan to manage it if it arises. These strategies help organizations
proactively manage potential issues and opportunities.
Here's a more detailed breakdown:
1. Avoidance:
Definition: Eliminating the risk by not engaging in the activity that creates the risk.
Example 1: If a project involves a specific technology that poses a high risk of failure,
the project team might choose to use a different, more reliable technology instead.
Example 2: choosing a reliable supplier than one who is known to be unreliable
2. Transfer:
Definition: Shifting the risk to a third party, often through insurance or contracts.
Example: A construction company might purchase insurance to cover potential
damages during construction, transferring the financial risk to the insurance
company.
3. Mitigation:
Definition: Reducing or minimizing the probability or impact of the risk.
Example 1: Implementing stricter quality control measures to reduce the likelihood of
defects in a product.
Example 2: reinforcing security at a warehouse by including burglar bars.
4. Acceptance:
Definition: Recognizing that the risk is unavoidable and developing a plan to manage
its potential consequences.
Example 1: A company might accept a small risk of a software virus occurring, but
have a plan in place to quickly fix it if it does.
Example 2: accepting that a critical Team Player will retire but have a plan in place for
a good replacement
[Link] Additional Strategies
Though the above four are the most acceptable, there are other additional strategies
that can be considered:
Exploiting: Focusing on positive risks to maximize potential benefits.
Enhancing: Taking actions to increase the probability of positive outcomes.
Sharing: Involving other parties in managing the risk.
Terminating: Stopping the activity that gives risk higher than the acceptable
level.
12.2.4 Step 4: Risk Prevention or Mitigation Implementation
The fourth step in the process is to put risk-mitigation strategies in place. This could
include updating compliance procedures, strengthening information security defenses,
or refining internal workflows. The activities outlined in the risk response plan mitigate
the impact of the risk if it occurs. For example, some risks can be prevented; others
can only be mitigated. Drought or the retirement of an important stakeholder cannot
be prevented. Unreliable Suppliers can be avoided by replacing them with Reliable
ones. Another way is to make attempts to mitigate or lessen the probability and/or
impact should the risk occur (in case we use the Unreliable supplier). In this case, we
can create concrete steps to pro-actively expedite the delivery of the material, thereby
mitigating the impact of the risk.
12.2.5 Step 5: Consider Contingency
Preventive measures are those steps taken before the risk becomes reality.
Contingencies represent the specific actions that will be taken if the risk occurs. Here,
you answer the question “If the risk becomes reality, what will we do”?
Risk contingency is a strategy used in risk management to prepare for and mitigate
potential risks. It involves identifying potential risks and developing a plan to address
those risks if they occur. The purpose of a risk contingency plan is to minimize the
negative impact of a risk event and to ensure that the project can continue to move
forward. The risk register is an effective tool for organizing and prioritizing threats to
the project.
[Link] Types of Contingency Plans
1. Proactive Contingency Plan
Proactive contingency plans involve taking steps to prevent the risk from occurring.
This can include increasing the budget, extending the timeline, or changing the scope
of the project.
2. Reactive Contingency Plan
Reactive contingency plans involve responding to a risk event after it has occurred.
This can include allocating additional resources, changing the project plan, or
executing a backup plan.
Examples include having backup suppliers in case the primary supplier cannot deliver
products or services, having a backup plan in case a vital team member becomes
unavailable, or having a disaster recovery plan in case of natural disasters or other
catastrophic events are all risk contingency plans.
12.2.6 Step 6: Risk Monitoring and Control
Risk management isn’t a one-time process. Risk monitoring and control is a continuous
process involving identifying, analyzing, and responding to potential threats or
opportunities that can impact project objectives, ensuring effective risk management
throughout the project lifecycle. This ensures proactive management rather than
reactive firefighting, allowing for necessary adjustments to response plans as needed.
[Link] Why is Risk Monitoring and Control Important?
1. Proactive Approach: It allows for early identification and mitigation of potential
problems, leading to better project outcomes.
2. Continuous Improvement: It's an ongoing process that adapts to changing
project conditions and emerging risks.
3. Data-Driven Decisions: Monitoring and control provide valuable data for
informed decision-making and course correction.
4. Enhanced Project Success: By effectively managing risks, projects are more likely
to be completed on time, within budget, and to the required quality standards.
In conclusion, effective risk management is critical to the success of any project. By
following these six steps for risk management, project managers can identify potential
risks, assess their likelihood and impact, develop risk response strategies, implement
risk mitigation strategies, monitor and control risks, and communicate risks and risk
management strategies to all stakeholders. By doing so, they can ensure that their
projects stay on track and meet their objectives.
Key Points to Remember
Project risk management should begin early in the process and continue
through the life cycle.
A key to success in dealing with risk is to start early and lay the foundation for
risk management; be proactive, not reactive; manage risks formally with a
process; and be flexible.
The Six-Step process to establishing a project risk plan includes making a list of
potential risks; determining the probability of risk occurrence; determining its
negative impact; preventing or mitigating the risk; considering contingencies;
and establishing trigger points for activating contingencies.
Establishing contingency and management reserves enables you to leverage
your project risk plan to its fullest potential.
A standard risk matrix is a useful tool when managing many risks across
projects.
The risk register can be an effective tool for organizing and prioritizing threats
to the project.