Risk Management Process
GBEPM 720 – Risk Management
Lesson Outline
• Evolution of Risk Management
• Major stages of Risk Management Process
• Risk Identification
• Risk Assessment
• Risk Response
• Risk Monitoring and Review
• Beneficiaries of Risk Management
• How Risk Management can be embedded into
an organisation
Evolution of Risk Management
• RM is one of the important parts of planning and managing investment at all
levels
• Idea of chance and fortune existed in primitive culture
• Idea of gambling came when the Babylonian empire was established (1750-
539BC)
• First insurance against misfortune to cover risk loss of cargo by shipwreck
(ship owner obtain loan)
• Egyptian & Greek Civilisations enjoyed gambling
• 14th – 16th Centuries new thinking that it was God (or Gods) that determine
fate
• 1494 Luca Pacciolo of France proposed the idea of systematic probability
analysis, beginning of risk quantification
• 17th century Pascal & Fermat proposed generalisation and rules to calculate
probabilities in simple cases
• 18th saw raise of insurance companies currently known today
• Development of Probability theory continued in the 19th century
• 20th century (1871-1970) saw development of probability of ‘management
science’ and birth of formal risk management.
• By this time RM was beginning to be defined as a separate discipline in its
own right, but further developments were to follow
Risk Management in the 1970’s
• Until the advent of project risk management in the 1970’s
• Risk was little discussed & its effects on business &
projects were either ignored or concealed
• Risk and uncertainty were treated as necessary evil that
should be avoided
• Project RM developed in 1970’s
• Firstly in relation to quantitative assessment, them
methodologies and processes
• At the end of the 1970’s project management
academicians and professions saw the need for project
management function to be devoted to risk analysis and
management
• Several authors published papers on the subject.
Risk Management in the 1980’s
(Quantitative Analysis Predominates)
• In early 1980’s RM acknowledged as specific topic in project
management
• Scope of risk identification, estimation and response was generally
known
• Risk management emphasised quantitative analysis
• Project risk management focussed on time & cost
• Software using probability distributions used on large projects
• BP and Norwegian Petroleum Consultants pioneered project RM
methodology and risk analysis techniques
• The developed internal software, which allowed risk quantification
and modelling using probability distributions
• In the late 1980 Computer Aided Software for Project Risk Appraisal
(CASPAR) was further developed
• Use of methods based on risk and response diagrams began in late
1980’s
Risk Management in the 1990’s
(Emphasis on Methodology and Processes)
• Principle established in relation to contractual allocation of risk
• Partnering and ‘alliancing’ strategies laid to avoid rivalry and
promote a risk and reward sharing approach in capital projects
• 1990 period has seen variety of proposals for risk management
processes, these include
• The
• RM is an important part of project and business management
• Benefits RM generate often unseen while costs are all too visible
• To sell risk focus on benefits
• RM involves identifying risks, predicting what to do about them and
implementing these decisions
Risk Management Process
The Risk Management Process
Risk Identification
Risk Elimination
Risk Assessment
Risk Transfer
Risk Response
Risk reduction
Risk Retention
Risk Monitor & Review
•
Risk Identification
Involves determining which risk might affect the project and document
the characteristics of each.
• What can go wrong? – cause & effect (If this happens…how will)
• Should be a continuous process
• Risk identification must be approached on the basis of Murphy’s Law,
searching for every possible reason for failure or hazard. Primary
sources of risk which have potential to cause impact on project should
be determined and classified
• Use both historical and current information in risk identification
• Inputs to risk identification includes product description, historical
information, planning outputs such as WBS, cost and time estimates
• Output to risk identification includes sources of risk, potential risk
events, risk symptoms and inputs to other processes
• After identification risks should be validated
• Purpose of risk identification is to:
Identify inherent risk in a business or project
To identify project components
Identify participants in risk management and provide basis for management
Provide necessary information to conduct risk analysis
• Risk identification Process – See diagram
Risk Identification Techniques
1. Brain storming
• This is essentially a team led by an experienced
person, and conducted as follows:-
• Structured to cover: Concepts, Processes,
Systems and Components
• Method capturing ideas
• No criticism by fellow team members (No idea is bad)
• The more ideas the better
• Encouragement to build upon one another’s ideas
• Refine the list to 10-15% of the total
Risk Identification Techniques
2 Delphi
• The Delphi method was developed by the Rand
Corporation to make predictions. The method is
based on using a panel of experts to provide
opinions, but managing the process to optimise the
confidence which can be placed on the outcome.
• The assumptions are:-
– Panel members are experts
– The panel will produce predictions at least as
good as those by any one member
Risk Identification Techniques
• Panel members are kept physically separate in order to
remove social pressures and individual dominance
• Each member answers a questionnaire which is returned
to the co-ordinator
• Subsequent questionnaires are accompanied by
consensus information from the previous questionnaires
• After several iterations, the panel should reach
convergence, with possibly one or more minority views
Risk Identification Techniques
3 Interviews
• Used where group work is impractical
• Means of soliciting information from people
• E.g. Corporate level personnel may request
interviews with project personnel to get
information about potential risks that mighty
affect the commercial viability of a project.
Risk Identification Techniques
4 Check Lists
• Generate checklist or used standard
checklist.
• Each risk in the list is checked for
application to a particular project
Risk Identification Techniques
5. Historical Data
• Information from previous projects close
out reports.
6. Questionnaires
7. Scenario Analysis – (What if?)
8. Workshops
9. Judgement based on knowledge &
experience
Risk Quantification and Analysis
• Involves evaluating risks to assess possible outcomes
• Concerned with determining which risks warrant a
response
• Different tools and techniques are available
• Two methods used in risk quantification and analysis.
These are (1) qualitative risk analysis and quantitative
risk analysis
• Major output of risk quantification and analysis is a list of
opportunities that should be pursued and threats that
require attention
• Diagram; Risk Quantification and Analysis.
Risk Response
Defining steps to responses to
opportunities and threats
• Who can best control events?
• Who can best control the risk?
• Who should carry the risk?
• Who can best sustain the consequences
of the risk should it occur?
Risk Response
• Response to threats generally fall in into
one of the following categories
• Risk Avoidance/Elimination
• Risk Reduction
• Risk Transfer
• Risk Retention
THE COPPERBELT UNIVERSITY
School of Business
Risk Elimination/Avoidance
• Involves removal of a particular threat.
• May mean eliminating risk at the source of
the risk within a project or by avoiding
projects or business entities which have
exposure to risk
• E.g. contractor avoiding projects involving
use of asbestos.
Risk Reduction
• Significant of risk is related to both possibility
and impact on project outcome if risk does occur
• Risk reduction may either involve lowering its
possibility or lessening its impact (or both
• E.g. severity of injuries from falling objects on a
building site or underground may be reduced
through compulsory wearing of hard hats
• While adopting safer working practices can
lessen the likehood of objects falling
Risk Transfer
• Process of transferring risk to another project
participant.
• Transferring risk does not eliminate or
reduce, merely leaves it for others to bear it.
Factors Influencing Transfer
• Control of risk source
• Management of consequences
• Containment of the effects (cost)
• Premium acceptability (risk contingency)
Risk Transfer
• Client to contractor or designer (e.g.
time/liquidated damage clause)
• Contractor to sub-contractor
• Client, contractor, sub-contractor or
designer to insurer
• Contractor or sub-contractor to surety
THE COPPERBELT UNIVERSITY
School of Business
Risk Retention
• Risks may be retained intentionally or
unintentionally
• Retaining risk not identified, or costly to
transfer.
• Retain risk most able to manage or Cost
effective by an organisation that transfer (risk
premium)
• Diagram; The Risk Response Process
THE COPPERBELT UNIVERSITY
School of Business
Monitoring
• Plan to reduce risk to acceptable residual levels
• Review progress against plan and identify new areas of
risk at regular intervals
• Monitor assumptions used in the substantiation
calculations to ensure their continuing validity
• The risk review should be incorporated into the design
review procedure within the engineering process
THE COPPERBELT UNIVERSITY
School of Business
Database
o Risk log or risk register
o Is a build-up of historic experience
o Can be accessed to review alternatives
o Consists of experience and performance of existing designs
o Should also contain codes of practice and limitations
o Should identify differences in applications
THE COPPERBELT UNIVERSITY
School of Business
• Risk Register
• Document or data base records each risk
• Register lists all risks and their methods of
management
• Risk registers used in the same way as
checklists
• Enables data collected during RM ID to be
captured and saved for review
• It has a format.
THE COPPERBELT UNIVERSITY
School of Business
Risk Monitoring Methodology
o Identify all features which can lead to deviations from
predicted behaviour and targets because of uncertainty
o Quantify risks
o Modify the programme to eliminate risks, or build in tasks
to reduce risks to an acceptable level
o Generate a risk reduction profile from the plan, showing
risk level as a function of time
THE COPPERBELT UNIVERSITY
School of Business
Risk Monitoring Methodology
• At regular intervals
o Monitor risk reduction for conformity to plan
o Review the plan for any new risk sources
• Review, for continuing validity, the assumptions used in the
performance predictions
• Register must be reassessed and if necessary amended
• to reflect the latest position. Clearly as the project
proceeds, the risks reduce in number,
• so that the contingency sums allocated to cover the risk
of the completed activities can be
• allocated to other sections of the budget.
THE COPPERBELT UNIVERSITY
School of Business-Department of Production Management
Risk Sources
Exercise:
The Copperbelt University is in the
process of installing a wireless internet/IT
System to improve speed of the existing
system. The system is intended for both in
house and consultancy service. Identify all
possible risks in this project.
References
• Smith N.J. (2002) (ed). Engineering
project management”. 2nd ed. Blackwell
publication. pp86-100
• Smith N.J. (ed). (2003) “Appraisal, Risk
and Uncertainty”. Thomas Telford,
London.
• Al-Thani and Merna Tony (2008),
Corporate Risk Management, 2nd edn.
John Wiley and Sons, London Chapter 2
END
QUESTIONS???