0% found this document useful (0 votes)
21 views19 pages

Risk Analysis in Project Management

Chapter 6 focuses on risk analysis as part of systematic risk management, emphasizing the importance of understanding the magnitude of risks faced by organizations in projects. It discusses the process of risk allocation, the three-dimensional perspective of risk involving likelihood, consequence, and duration, and the challenges of uncertainty in risk assessment. The chapter also outlines qualitative and quantitative approaches to assessing risks, highlighting the significance of stakeholder interpretations and the potential impacts of risk events.

Uploaded by

akmelkaty
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
21 views19 pages

Risk Analysis in Project Management

Chapter 6 focuses on risk analysis as part of systematic risk management, emphasizing the importance of understanding the magnitude of risks faced by organizations in projects. It discusses the process of risk allocation, the three-dimensional perspective of risk involving likelihood, consequence, and duration, and the challenges of uncertainty in risk assessment. The chapter also outlines qualitative and quantitative approaches to assessing risks, highlighting the significance of stakeholder interpretations and the potential impacts of risk events.

Uploaded by

akmelkaty
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 6: Risk Analysis

6.1. Introduction
This chapter continues the exploration of systematic risk management, taking up from the
identification of risks discussed in the previous chapter. The risk statements that are the outcome
of the risk identification process form the input to the risk analysis stage of the RMS cycle. Risk
analysis is an evaluative process that serves the purpose of establishing some understanding of
the magnitude of the risks faced by an organization in undertaking a project. The analytical
process decomposes each risk into its constituent components and subjects them to some form of
assessment. While the risk analysis stage itself is often lengthy, it is not always necessary for the
risk assessments to be exhaustively exact in terms of mathematical accuracy. Indeed, accuracy
criteria would be difficult to define in terms of many of the risk factors relating to projects. The
financial performance of an investment project, such as a proposed shopping centre, for example,
can rarely be forecast accurately (and perhaps more importantly, reliably) to within two or three
percentage points in early stage modeling of internal rates of return for the project.

The nature of many projects also militates against high levels of accuracy in risk analysis
assessments, since the input data are rarely derived from large sample statistics such as those
used in the insurance industry or in large-scale manufacturing. For the most part, project data are
collected from case-based small samples and gathered in unique situations. This also
distinguishes them from data from repeatable experiments conducted under controlled laboratory
conditions. However, what such case-based project data may lack in statistical adequacy is often
made up by their capacity to generate information that is rich in content.

Appropriate risk analysis allows an organization to gain an understanding of the relative severity
of its risks on a project. In turn, this permits a strategic approach to managing them.

6.2. Risk Allocation


Before embarking on the risk analysis process, a stakeholder organization should investigate
what prior risk allocation arrangements already exist for the project. There is little point in
207
analyzing a risk further if it has already been allocated to another party through a mechanism
such as a special clause in a contract agreement. For example, a subcontractor normally used to
submit tenders on a fixed price basis would usually identify the chance of high economic
inflation as a risk factor on a long-term project. However, if the head contract included clauses
agreeing to share cost fluctuations between client and main contractor, with flow-on provisions
for subcontractors, this would mean that the consequences of the inflation risk would be borne
partly by the subcontractor and partly by the main contractor, who in turn would share the
increased cost with the client. The contract agreement has effectively allocated the risk on a
shared basis, and the subcontractor would need to reflect this in his assessment of the inflation
risk. In theory, of course, any risk should be allocated to the party best able to control it. Practice,
however, especially in the guise of contracts, has a habit of mocking theory!
6.3. A Three-Dimensional Risk Magnitude Perspective

Armed with knowledge of the prevailing risk allocation mechanisms of the project, the
stakeholder can proceed to assess the likelihood of occurrence (chance or probability),
consequence (impact), and time (duration) aspects of the risks that have been identified.
Together these provide an important three-dimensional perspective of risk, as illustrated in figure
5.1, giving more substance to the concept of risk itself.

Figure 6.1

208
Before considering each of these components of risk, the matter of uncertainty must be addressed
once again, since uncertainty states can affect any or all of them.

Dealing with uncertainty


Risk analysis inevitably involves making estimates of variables that may lie far ahead in the
future. Because the future cannot be known with certainty, uncertainty enters the scene. There
will be uncertainty associated with the values of nearly all of the input variables from which the
estimates are derived. Anyone of a range of values might actually occur for a variable. Returning
yet again to uncertainty in this chapter serves to emphasize its pervasive presence in projects.

Uncertainty is not necessarily confined to the values of input variables in an estimate. If the
estimating technique is based upon some form of mathematical model, there may be uncertainty
associated with the model itself. The model may not perform consistently under different
conditions, nor with different ranges of input variable values. Thus, uncertainty of variable input
values, plus model uncertainty, equals inherent variability in output values.

It should be possible to deal with model uncertainty by calibration, i.e. measuring the
performance of the model over the whole range of possible conditions and comparing this with
the real outcomes of what the model is trying to represent. The deviations from reality can then
be translated into measures of confidence in the model. For example, it might be possible to
describe a simple area/cost model for a particular type and configuration of building (i.e. a model
which calculates the estimated construction cost for a proposed building by multiplying the total
floor area by a price rate per m2) as having a 95 per cent confidence level that the calculated cost
will be accurate to within ±25 per cent of the real cost determined after the building has been
built (assuming that the costs of any post-estimate change in project scope or quality are
excluded from the post-completion cost calculation).

209
Several techniques exist for the treatment of uncertainty in the input values for risk analysis
models. The principle that applies is that any method must be appropriate to the modeling
context and logically defensible.

Quantitative approaches to treating uncertainty generally use mathematically based analyses of


statistical data and may involve simulation. At a simple level, the analysis might comprise
sensitivity testing of the critical variable values: changing the value of one variable by one
incremental step at a time and observing the effect on the outcome. The limitation of sensitivity
testing is that it is not suitable for exploring the effect of multiple changes in several variables at
the same time.

At a more sophisticated level, Monte Carlo simulation may be appropriate. It is worth noting that
several computer software packages for Monte Carlo simulation are commercially available,
either as independent software applications in their own right or as add-on modules for popular
spreadsheet and project scheduling software.

The main criteria for using quantitative approaches for treating uncertainty in risk analysis are
adequacy and sufficiency of variable input data, cost of data collection and cost of assessment. If
the data are suitable and readily available, and if the assessment process is quick and
straightforward, then quantitative approaches are preferable as they are objective. If sufficient
data cannot be obtained, or if the cost/benefit ratio of collecting data or processing it is too high
(and this may include techniques such as obtaining the consensus judgment of experts using
Delphi methods), then qualitative approaches may have to be used. Earlier in this book it was
noted that, in much of project risk analysis work, qualitative analysis is sufficient, since often the
main purpose of the analysis is simply to gain an understanding of the relative severity of the
risks that the stakeholder organization faces in its involvement in the project.

In exploring the assessment of each of the components of risk, we will consider the necessary
basis for each type of assessment and then present a qualitative model to represent it.

210
Qualitative assessment is subjective because it relies largely on human judgment. That judgment
will be influenced by experience and by personal biases. Errors in human judgment include
errors arising from biases such as:
▪ anchoring (wrongly sticking with a first estimate even though it is inappropriate)
▪ selective recall (remembering only certain facts or incidents)
▪ base rate fallacies
▪ over-pessimism
▪ over-optimism
▪ over-confidence in the assessment
▪ inappropriate search for patterns in data
▪ inappropriate framing of the situation.

The advantage of subjective assessment is that it is generally quick to apply and simple to
understand. The disadvantage is that errors in judgment are often difficult to detect and eradicate.
Because this is happening in human decision-making, the fields of decision science and
behavioural psychology have much to offer in terms of addressing the problems of human
judgment, and you are recommended to further reading in these areas. Reluctantly, they have to
remain beyond the scope of this book.

Assessing the likelihood of occurrence


Probability, expected frequency, chance, and likelihood are used synonymously for this
component of risk. The mathematical probability that a risk event will occur is expressed either
as a percentage or as a decimal fraction greater than 0 (event certainly cannot occur) and less
than 1 (event certainly will occur). The expression is really a contraction of a ratio relationship,
so a 1 per cent (or 0.01) chance that a risk event will occur is really stating that there is one
chance out of every 100 possible occasions that it will happen. There is a converse to the
relationship, of course. If we believe that there is a 1 per cent probability of something
happening, we must also believe that there is a 99 per cent probability of it not happening. This
tells us that, for a finite number of possible and mutually exclusive alternatives for an event, the
sum of the probability for each must equal 100 per cent (or 1). Thus, if the weather forecast

211
indicates a 25 per cent chance of light rain showers over the next 24 hours, with a 5 per cent
chance of heavy rain, then there must be a 70 per cent chance that no rain will occur during that
period (assuming that light rain, heavy rain and no rain are the only possible and mutually
exclusive alternatives).

The latter example brings in the issue of exposure period, since technically the likelihood of
occurrence of an event must relate to some dimension of time. In some fields there is no problem
about this. In surgery, for example, it might be stated that the 5-year survival rate for males
between 50 and 55 years of age who have had prostate cancer surgery is 78 per cent (note how
specific the context is here, and how the medical profession has used the optimistic converse: the
death rate is 22 per cent). Other fields also use specific contexts and explicit periods: e.g. number
of road accident deaths annually per 100 000 of population. Because of the probability
convention used, in each example it is possible to make credible comparisons with another
relevant context, such as female breast surgery or deaths due to industrial accidents.
Projects do not really 'work' in the same way. Potentially each has multiple environments
(procurement, operation, and disposal); up to four elements (tasks, technologies, resources and
organization); and usually a great number of differentiated and interdependent sub-elements.
The many hundreds of identifiable risks for a project stakeholder are therefore likely to exhibit a
great array of different exposure periods, and most of these may not be known precisely. This,
together with the difficulties of obtaining reliable probabilistic data, is why the assessment of
risks in project risk management tends to be undertaken using qualitative approaches. For the
most part, the 'time' aspect of risk event probability is either ignored, or treated implicitly as
equivalent to the project procurement period. Later in this chapter you will see that we have
chosen to give this issue more explicit treatment, although still qualitative to a large extent.

A useful guide to making qualitative expressions of probability or likelihood is given in Table


8.1. This risk management standard offers a 5-interval scale of linguistic descriptors for the
likelihood of occurrence for a risk event, as shown in table 8.1. It is immediately apparent that
the scale is generic, as it does not relate to any specific project context. The table below is
generic and not uniquely project focused. Nor is the scale specific as to time.

212
Table 6.1 Interval descriptors for likelihood

One implication of offering a generic scale is that, before using a qualitative instrument such as
this, a stakeholder organization must establish interpretations for the scale intervals that are
meaningful in terms of its involvement in, and objectives for, a project. For most projects there is
no point in all the stakeholders coming together and agreeing uniform meanings for each
interval- there will be too much disparity between the nature of their individual involvement and
the objectives each seeks to achieve.

A further implication that arises is that, where qualitative approaches to risk assessment have
been used, any communication about risk between stakeholders will be affected. If different
stakeholders maintain different interpretations of 'rare' or 'likely', for example, they are unlikely
to share completely congruent understanding.

On the other hand, it is desirable and practical for an organization to decide on uniform meanings
for its scale interval descriptors across the organization, which can then be applied to all the
projects it undertakes. Without such uniformity, an organizational risk register would lose much
of its usefulness.

Given an agreed scale, such as that in table 8.1, a stakeholder organization has the opportunity to
'score' its qualitative assessments of probability for identified project risks. The results can then
be incorporated into a risk severity model as shown later in this chapter.

213
Assessing the consequences
A risk event that occurs on a project must have consequences, since this is fundamental to the
definition of risk. From the 'dual' view of risk, these impacts may be positive or negative;
beneficial or adverse, but it must be remembered that, for the time being, risk events in this book
are presented as leading to negative consequences.

The consequences of a risk event will impact the project, but more importantly they impact the
stakeholder bearing that risk. Impacts from the same event may also be experienced by other
stakeholders in the project and, in some instances, by others beyond it.

For the purposes of assessing the consequences of a risk event, it is often assumed that the
impacts can be expressed in terms of cost to the risk bearer. Where quantitative assessment of
probability has been used, this assumption is even more strongly held, since it allows the
assessor to calculate a financial exposure to the risk, and thus a total financial exposure to all
risks. Thus, if a risk event has a 5 per cent chance of occurring each year, and the estimated
consequence is $1000, then the risk bearer is said to be exposed to $50 of risk (0.05 X $1000 =
$50) and might wish to consider spending up to $50 a year to eliminate or avoid it.

One problem with this approach is that not all risk consequences are directly related to costs.
Among many others, the outcomes may lead to impaired reputation, vulnerability to legal
prosecution, loss of capacity, loss of staff, difficulty in recruiting staff, lowered resilience, etc.
Assessing monetary values for any of these, while it can be done (and is done by the courts, for
example), could be extremely difficult for an organization unfamiliar with such a task. It would
almost certainly involve some degree of financial gymnastics.

For a qualitative approach, a 5-point interval descriptor scale for risk impacts in the risk
management standard is shown in table 8.2 as guidance. With this scale, the table has tried to
denote more specific contextual impacts by referring to 'containment' and 'toxic release', but

214
these should not be seen as limiting the applicability of the scale. It also refers to financial loss
and we have already noted the difficulties that can arise with assessment of this.

Table 6.2 Interval descriptors for risk impacts

As with the qualitative interval descriptor scale for likelihood, a stakeholder organization must
assign interpretations to the scale intervals that are internally meaningful. For example, it may be
appropriate for the organization to assess the impacts of risk events in terms of their capacity to
delay the project. Scale interval descriptors such as 'not greater than 2 hours; between 2 and 6
hours; 6-12 hours; 12-48 hours; and greater than 48 hours' might be appropriate for organizations
used to a very short-term involvement with projects, or for event-type projects with an extremely
short duration. Actual monetary amounts could be set against the scale intervals where this is
practicable, and in fact any scalable impact of risks borne by the organization could be treated in
a similar way.

215
Care is needed in setting the interpretive levels. An organization in the early stages of RMS
maturity will tend to score too many of its risk impacts too highly simply because it has not set
the bar high enough for the upper level descriptors. A 'catastrophic' impact descriptor, for
example, should be reserved for a risk impact that might completely destroy a company
financially and cause it to cease to exist. While none of the interval scales offered is intended to
convey absolute value meanings, and while the scales should therefore not be used to attempt to
calculate precise impact values, their purpose is to permit some meaningful comparison of the
relative severity of risks. The interval descriptor interpretations that an organization assigns to
the scales should therefore have some reasonable correspondence with reality for that
stakeholder.
The impact assessment 'score' for each identified risk may also be incorporated into a simple risk
severity model.

Assessing the duration of exposure

Earlier in this chapter we noted that, strictly speaking, the duration of exposure belongs to the
component of risk that relates to the likelihood of occurrence (the chance or probability) of the
risk event. It was suggested that, because of the nature of many projects, the risks that arise from
them do not readily fit this time perspective neatly, at least not for the purposes of assessment by
a project stakeholder. This is because the risk event may be framed by one time window and the
consequences by another. The risk event might occur in one project environment, but its impact
could be felt in another.

For example, in most projects there is a chance that poor quality workmanship could occur
during the procurement phase, but the consequences might not become evident until well into the
operational phase, or even not until the disposal phase. This drawing out of exposure time,
perhaps for as much as 30 years or more, is a complicating issue for risk management. It is
usually the reason why time is ignored in much of risk analysis except for discounted cash-flow
models for investment projects and some quantitative long-term health project studies.

216
While the time factor may complicate quantitative risk analysis, it can be addressed quite simply
in qualitative analysis. For convenience, a 5-point interval descriptor scale can be devised to suit
the characteristics of the project types most familiar to the stakeholder organization in its field of
operations. As before, each stakeholder must assign meaningful values to the scale interval
descriptors. The indicators described in table 8.3 are therefore only suggested interpretations and
should be tailored to suit individual circumstances. For some stakeholders dealing with particular
projects, long-term risk exposure durations might last no more than a few weeks. For other
stakeholders involved in different projects they could endure for many years. A stakeholder
might experience risk exposures spanning only the procurement environment; but another might
be vulnerable throughout the operational and disposal environments as well. The time value
assigned to each risk should include the period of exposure to the risk event and the period
during which the consequences might flow.

Table 6.3 Interval descriptors for risk duration (exposure time)

Armed with these qualitative approaches to assessing the likelihood of occurrence, impact and
duration of exposure for project risks, it is now possible to consider combining them into a
subjective risk severity assessment model.

217
Combining probability, impact and duration
Given the three-dimensional concept of risk presented by Figure 6.1, and the rating scales
discussed above (Tables 6.1, 6.2 and 6.3) for the probability, impact and exposure duration
components of risk, combining them into a simple risk severity model is quite straightforward.

Many approaches to qualitative risk analysis suggest two-dimensional models, using 3- or 5-


point interval scales for probability and impact only. Scoring each risk is simply matter of
multiplying the chosen probability rating for the risk by the chosen impact rating. With
maximum risk severity scores of 9, 15 or 25 (depending upon the scales used), the results may be
too coarse to allow more subtle distinctions between different risks. There will be too many with
identical scores. It would be possible to expand the rating scales to perhaps 9 or 11-point
intervals, but this would pose a difficult linguistic problem in assigning realistic descriptor labels
to each interval, to reflect sufficiently finer shades of meaning. In any case, the main drawback
with two-dimensional scoring models is that they ignore the important dimension of time. A
three-dimensional risk severity model, based upon 5-point subjective rating scales for
probability, impact and duration, is shown in figure 6.2.

Figure 6.2

218
Using the model to assess a risk is simply a matter of assigning a value between 1 and 5 to each
of the three scales. This will produce a potential risk severity score ranging from 1 (1 X 1 X 1) to
125 (5 X 5 X 5). Theoretically, finer-grained scores could be obtained by assigning decimal
values to any scale (e.g. 0.75 probability X 1.5 impact X 3.25 duration = 3.65625), but in
practice this is unnecessary and integer values are sufficient. Injecting decimal precision into the
scale values is more often than not counter-productive in terms of the extra effort required and
begins to defeat the objective of the assessment being done at this stage. The purpose of the
model is simply to establish some measure of comparative severity for the risks that a
stakeholder organization faces in a project. It is not intended to produce absolute results. The
severity scores produced by the 5 X 5 X 5 model allow the organization to confidently rank the
identified risks and hence to prioritize the treatment options and decisions for them. The most
severe risks will have to be revisited for further, more detailed analysis anyway, so there is little
point in prolonging the time needed for initial assessment by setting unnecessarily high precision
targets for the subjective scales of the model.

219
6.4. Other Assessment Techniques
Other risk analysis and assessment techniques are available which can be used either objectively
or subjectively, according to circumstances. Prominent among these are 'expected utility' and
'expected monetary value'.

Expected utility
The expected utility (EU) assessment technique originates in decision science, and is simply the
product of probability and impact. This expression of risk was noted earlier when the assessment
of risk consequences was considered. EU assessment may be applicable when the direct and
indirect financial impacts of risk events are difficult (or even impossible) to estimate. 'Utility' in
this case is some measure of the loss of worth, or loss of usefulness, to the risk taker if the risk
event should happen. An example, using a decision tree approach, will help to demonstrate the
technique.

Example 8.1 uses a travel itinerary project as a scenario. From the market survey and time
performance data that the tour company has obtained, it is able to draw up a decision tree as
shown in figure 8.3. The decision nodes are shown as A (flying), B (bus) and C (train).
Since the probabilities of arrival on time at the destination town are known from the statistical
performance data the company has obtained, the chance of delay for each travel mode can be
determined (100 per cent - x per cent chance of timely arrival). The values in brackets at the end
of each paired branch, assigned to arrivals on time and to delays, were derived from the
responses to the carefully worded market survey questions as these could be translated into the
perceived worth of each outcome to the potential customers.

220
Example 6.1: Travel Project

Figure 5.3

221
The EU calculation for each travel option is shown in the small boxes on the right-hand side of
the diagram. The resulting EU value is the sum of the product of probability and utility for the
paired 'on time'/ 'delay' arrival condition states for each travel option. It represents the average
worth to the traveler for that option had the journey been made, and both condition states
experienced, on many occasions. Theoretically, the travel option yielding the highest utility
(flying: EU = 76) should be selected for the itinerary, as it represents the alternative with the
least risk of causing dissatisfaction to the tour company's customers.

Some of the difficulties associated with this technique are obvious. Obtaining objective time
performance data for the aircraft, buses and trains would probably be the most straightforward
task, but even that would not be simple. The data would be expensive and time consuming to
gather, and almost certainly some degree of data manipulation would be required. The market
survey instrument would be expensive to design and administer, and the response data would
have to be carefully processed and interpreted. Significance testing would be necessary and the
results of the model should be compared with those from other decision making approaches to
confirm the validity of the EU technique. More realistically, perhaps, would one reasonably
expect a tour company to make its project decisions in this way?

222
Expected monetary value
Expected monetary value (EMV) is simply a financial version of EU, and used in situations
where reasonably precise estimates of various possible financial outcomes can be made, as well
as the probabilities associated with their occurrence. Example 6.2 demonstrates this.

The organization now has the data it needs to calculate an EMV for a projected loss in the first
year of trading if it purchases the franchise. Table 6.4 shows the detailed calculation. Note that
the available data reflect the situation for a $100 000 franchise purchase, while the micro-
business is considering an investment of $50 000. In the absence of any other information, it is
reasonable to make pro-rata adjustments to the data as shown, but the organization should be
aware that greater uncertainty will be associated with the adjusted data.

Example 6.2

223
Table 6.4 EMV calculation for first-year loss in gardening franchise

The EMV loss of $5775 in the first year of trading is what the organization should realistically
plan for if it decides to purchase the franchise. If a more conservative business plan is preferred,
it could assume a $7500 loss.

As with the EU technique, there must be suitable data available and the user must have
confidence in their accuracy and reliability for the EMV to be considered as a practical objective
risk assessment tool. Otherwise, it is no better than any other subjective assessment technique.
6.5. Risk Ranking
Once identified risks have been analysed and scored in some way, they can be ranked in terms of
relative severity. This is a useful way of focusing the stakeholder organization's attention on the
most serious risks it faces on a project.

While a straight ranking of risks according to their severity scores is useful, an organization
could adopt a more strategic approach by aligning these scores to a set of predetermined risk
severity categories. A five-category list is shown in table 6.5.

Table 6.5 Interval descriptors for risk severity

224
Each stakeholder organization should decide upon how to align its 125-point severity scale to the
five-category list, but it is important to caution that an equidistant interval alignment is not
advisable (i.e. assigning 'minimal' category to risks with scores between 1 and 25; 'low' risks
between 26 and 50, etc.). The use of strategic risk severity categories is discussed in chapter 8.

Once risks have been ranked and prioritised, it is likely that the most severe risks will have to be
revisited for further analysis before major decisions about their treatment can be taken.
Eventually however, a response must be considered for each identified risk.

6.6. Chapter Summary


While, by intention, this chapter has not dealt with highly mathematical and financial modeling
approaches to risk analysis (and each of these warrants a separate book in its own right), many
techniques of risk analysis have been presented, ranging from semi-quantitative to subjective and
linguistic assessment tools. The treatment of each of these has been brief rather than extensive.
In real life the risk analysis stage of formal risk management can be quite time consuming.
Each of the components of risk - the likelihood of occurrence of the risk event, the consequential
impact, and the duration of exposure - must be considered carefully for every identified risk that
the stakeholder organization faces on a project. In this assessment of risk severity, an
organization must select and use techniques appropriate to its risk evaluation objectives.

Once risks have been sufficiently analyzed, it is possible to make informed decisions for dealing
with them.

225

You might also like