0% found this document useful (0 votes)
2 views37 pages

Introduction To Risk Management

The document provides an overview of risk management, defining risk as the possibility of negative outcomes affecting projects. It outlines the risk management process, including planning, identification, analysis, response, and monitoring, emphasizing the importance of proactive risk management for project success. The document also discusses various risk types, analysis techniques, and strategies for managing risks effectively.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views37 pages

Introduction To Risk Management

The document provides an overview of risk management, defining risk as the possibility of negative outcomes affecting projects. It outlines the risk management process, including planning, identification, analysis, response, and monitoring, emphasizing the importance of proactive risk management for project success. The document also discusses various risk types, analysis techniques, and strategies for managing risks effectively.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd

RISK MANAGEMENT: AN

OVERVIEW
Introductory
Dr. Waheed Asghar
MA English Lecture
MBA
PhD
DEFINITION / CONCEPT
OF RISK
• In simple terms, risk is the possibility of
something bad happening
•Risk is the probability of an outcome having a
negative effect on people, systems or assets.
Risk is typically depicted as being a function of
the combined effects of hazards, the assets or
people exposed to hazard and the vulnerability
of those exposed elements.
• In project management, risk refers to an
uncertain event or condition that, if it occurs,
can have a positive or negative impact on the
project's objectives.
2
RISK
Project risk – any possible event that
can negatively affect the viability of a
project

Risk management - the art and


science of identifying, analyzing,
and responding to risk factors
throughout the life of a project and
in the best interest of its objectives

01-03
WHAT IS PROJECT RISK?
An event that, if it occurs, causes
either a positive or negative impact
on a project
Keys attributes of Risk
 Uncertainty
 Positive and Negative
 Cause and Consequence
 Known & Unknown
 Risk overall guide project success

4
RISK VERSUS AMOUNT AT
STAKE:
CHALLENGE IN RISK
MANAGEMENT

07-06
RISK MANAGEMENT
PROCESS
PMBOK ® Definition
“The systematic process of identifying,
analyzing, and responding to project risk”
Steps
Risk Management Planning
Risk Identification
Qualitative/Quantitative Risk Analysis
Risk Response Planning
Risk Monitoring & Control

7
VALUE FROM MANAGING
RISKS
Opportunity to move from “fire-fighting” to
proactive decision making on the task.
Better chance of the success of the task.
Improved schedules and cost performance.
Stakeholders and team members better
understand the nature of the task and the
project.
Helps define the strengths and weaknesses
of the initiative/task/project.

8
WHY NOT RISK MANAGEMENT?

With so much benefit to managing risk,


why is it often overlooked? :
1. The organization is too busy with real
problems to worry about potential ones,
2. There is a perception that there is not too
much that can go wrong, or
3. They have a fatalistic belief that not much
can be done about risks, or
4. “Shoot the messenger mentality”; fear that
disclosure of the task risks will be seen as an
indication of its weakness.

9
WON’T IDENTIFIED INITIATIVE/RISKS
MAKE THE PROJECT LOOK BAD?

All initiatives/projects have risks, denial


does not make them go away, it just
makes you unprepared for them if they
occur.
Risk in itself is not bad, it is how well the
project plans for and reacts to risks that
counts.
Formal risk management is a cornerstone
of good project management. Stakeholder
visibility into project risks makes it easier
to get additional resources and
organizational support when risks do occur.
10
RISK MANAGEMENT
PLANNING
Plan for the Planning
 Risk planning should be appropriate for the
task
 Question you should ask:
1. How big is the task?
2. What is the visibility of the task?
3. How important is the task?
4. How risky is the task?
5. Is it a new technology or something your
organization is familiar with?
6. Do you have past similar tasks to reference?

11
THE RISK MANAGEMENT
PLAN
What should it include?
 How you will identify, quantify or qualify risk
 Methods and tools
 Budget…yes budget
 Who is doing what
 How often
 Risk categories, levels, and thresholds for
action.
 Reporting requirements
 Monitoring, tracking and documenting
strategies

12
THE RISK MANAGEMENT
PROCESS
Risk identification
 Identify the taks/project/product and business risks;

Risk analysis
 Assess the likelihood and consequences of these
risks;

Risk response planning


 Draw up plans to avoid or minimize the effects of
the risk;

Risk monitoring
 Monitor the risks throughout the task/project;

13
THE RISK MANAGEMENT
PROCESS

Risk Risk
Risk analysis Risk planning
identification monitoring

Risk avoidance
List of potential Prioritised risk Risk
and contingency
risks list assessment
plans

14
IDENTIFYING RISK

Continuous, Iterative Process


What is it and what does it look like
The sooner the better
The more the merrier
A fact is not a risk (it’s an issue).
Be specific
Don’t try to do everything at once

16
IDENTIFICATION
TECHNIQUES
Brainstorming
Checklists
Interviewing
SWOT Analysis (strengths, weaknesses opportunities,
threats)

Delphi Technique (anonymous consensus building)


Diagramming Techniques
 Cause & effect
 Flow Charts
 Influence Diagrams

17
CAUSE AND EFFECT

18
FLOW CHART

Another Example:
[Link]
-analysis/project-risk-management-process
.html 19
20
RISKS AND RISK TYPES
Risk type Possible risks
Technology The database used in the system cannot process as many transactions
per second as expected.
Software components that should be reused contain defects that limit
their functionality.
People It is impossible to recruit staff with the skills required.
Key staff are ill and unavailable at critical times.
Required training for staff is not available.
Organizational The organization is restructured so that different management are
responsible for the project.
Organizational financial problems force reductions in the project budget.
Tools The code generated by CASE tools is inefficient.
CASE tools cannot be integrated.
Requirements Changes to requirements that require major design rework are proposed.
Customers fail to understand the impact of requirements changes.
Estimation The time required to develop the software is underestimated.
The rate of defect repair is underestimated.
The size of the software is underestimated.
22
RISK ANALYSIS

Assess probability, seriousness, and


urgency of each risk.
Probability may be very low, low,
moderate, high or very high.
Risk effects might be catastrophic,
serious, tolerable or insignificant.
Urgency might be immediate, short
term, or long term.

23
ANALYZING RISK -
QUALITATIVE
Subjective
Educated Guess
High, Medium, Low
Red, Yellow, Green
1-10
Prioritized/Ranked list of ALL identified risks
First step in risk analysis!

24
RISK ANALYSIS -
QUANTITATIVE
Numerical/Statistical Analysis
Determines probability of occurrence and
consequences of risks
Should be focused to highest risks as
determined by Qualitative Risk Analysis and Risk
Threshold

25
RISK ANALYSIS (I)
Risk Probability Effects
Organizational financial problems force reductions in Low Catastrophic
the project budget.
It is impossible to recruit staff with the skills required High Catastrophic
for the project.
Key staff are ill at critical times in the project. Moderate Serious
Software components that should be reused contain Moderate Serious
defects which limit their functionality.
Changes to requirements that require major design Moderate Serious
rework are proposed.
The organization is restructured so that different High Serious
management are responsible for the project.

26
RISK ANALYSIS (II)
Risk Probability Effects
The database used in the system cannot process as Moderate Serious
many transactions per second as expected.
The time required to develop the software is High Serious
underestimated.
CASE tools cannot be integrated. High Tolerable
Customers fail to understand the impact of Moderate Tolerable
requirements changes.
Required training for staff is not available. Moderate Tolerable
The rate of defect repair is underestimated. Moderate Tolerable
The size of the software is underestimated. High Tolerable
The code generated by CASE tools is inefficient. Moderate Insignificant

27
PROBABILITY & IMPACT
ANALYSIS
Risk Probability Expected Value

1 25% $11,250

2 50% $1,000

3 30% $30,000

28
RISK RESPONSE
PLANNING
“What are we going to do about it?”
Techniques/Strategies:
 Avoidance – Eliminate it
 Transference – Pawn it off
 Mitigation – Reduce probability or impact of it
 Acceptance – Do nothing
Strategy should be commensurate with risk
 Hint: Don’t spend more money preventing
the risk than the impact of the risk would be
if it occurs 

29
RISK MANAGEMENT
STRATEGIES (I)
Risk Strategy
Organizational Prepare a briefing document for senior management
financial problems showing how the project is making a very important
contribution to the goals of the business.
Recruitment Alert customer of potential difficulties and the
problems possibility of delays, investigate outsourcing work.
Staff illness Reorganize team so that there is more overlap of work
and people therefore understand each other’s jobs.

30
RISK MANAGEMENT
STRATEGIES (II)
Risk Strategy
Requirements Derive traceability information to assess requirements
changes change impact, and maximise information hiding in the
design.
Organizational Prepare a briefing document for senior management
restructuring showing how the project is making a very important
contribution to the goals of the business.
Database Investigate the possibility of buying a higher-
performance performance database.
Underestimated Investigate outsourcing components, investigate use of
development time a program generator

31
RISK MONITORING
Assess each identified risk regularly to decide whether
or not it is becoming less or more probable.
Also assess whether the effects of the risk have
changed.
Each key risk should be discussed at management
progress meetings.

32
RISK MONITORING &
CONTROL
Continuous, Iterative Process
Done right the risk impact will be
minimized:
 Someone IS responsible
 Watch for risk triggers
 Communicate…Communicate…Communicate
 Take corrective action - Execute
 Re-evaluate and look for new risk constantly

Tools:
 Risk Reviews
 Risk Audits

33
RISK INDICATORS
Risk type Potential indicators
Technology Late delivery of hardware or support software, many
reported technology problems
People Poor staff morale, poor relationships amongst team
member, job availability
Organizational Organizational gossip, lack of action by senior
management
Tools Reluctance by team members to use tools, complaints
about CASE tools, demands for higher-powered
workstations
Requirements Many requirements change requests, customer
complaints
Estimation Failure to meet agreed schedule, failure to fix reported
defects
34
TOOLS & TRICKS

Risk Identification Spreadsheet


Risk log Spreadsheet
Templates (
[Link]
og/risk-management-templates-for-excel
)
Make your own

35
RISK IDENTIFICATION
SPREADSHEET

36
RISK LOG SPREADSHEET

37
QUESTIONS???

Thank You

38

You might also like