Project Management
Jordan 25 June – 2016
Professor Hussein M Al-Yaseen BSc, MSc, PhD
Professor of IT/IS Project Management
Email: hyaseen@[Link]
Mobile: 0777 440 737
Module 3
Project Risk Management
Module 3: Contents
3.1 Introduction
3.2 Background to risk
3.3 The human cognitive process
3.4 Risk handling and control
3.4 Types of risk
3.5 Risk conditions and decision making
3.6 The concept of risk management
3.7 Risk, contracts and procurement
3
Module 3: Learning objectives
1. What risk is and why it is important;
2. The difference between certainty, risk and
uncertainty;
3. How decisions can be made under each condition;
4. The concept of risk management;
5. The basic components of a risk management
system;
6. The basics of contract theory and how contracts are
used to transfer risk.
4
3.1 Introduction
• All projects are subject to risk of one kind or another
• The project manager has to be able to transfer or
reduce unacceptable risks
5
3.2.2 The Likelihood and Impact of Risk
• It depends on both the likelihood (probability) of and
event occurring and on the consequences (impact)
of that event on the project/organization.
• Risk is a measure of the probability and impact of
not achieving a specific project goal.
6
3.2.2 The Likelihood and Impact of Risk
• Most risk management systems consider the
magnitude (size) of a risk as a product of two
independent variables (likelihood + impact)
• Risk magnitude = risk likelihood X risk impact
• Or as a function of the two variables
• Risk magnitude = f (Event, Likelihood, Impact)
7
3.2.2 The Likelihood and Impact of Risk
• In this consideration, something – or the lack of
something – causes a risky situation.
• The source of danger is a hazard and the mitigation
or defence against the hazard is a safeguard. So,
• Risk magnitude = Risk hazard X Risk Safeguard
• Or
• Risk magnitude = f (Event, Hazard, Safeguard)
8
3.2.3 Exposure and Sensitivity
• Risk magnitude (size) expressed in terms of
likelihood and exposure is one consideration.
• Organizations need to consider the extent to which
they are exposed to risks and how sensitive they
are to risks.
• This is because two organizations may affected
differently by the occurrence of risks of similar
magnitude.
9
3.2.3 Exposure and Sensitivity
• Read details and examples (Pp. 3/6) and time out
Pp. 3/7.
• Risk sensitivity is effectively this same functionality
but extended to include the resilience (defensive) of
the organization. Where resilience is a measure of
the ability of the organization to stand the risk
impact and continue, so
• Risk sensitivity = f (Event, Likelihood, Impact,
Resilience)
10
3.2.4 Risk and Opportunity
• Risk generates opportunity, in most companies, if
most of the risk is eliminated then most of the
opportunity may disappear.
• The level of risk involved in the work will create a
value of the work, so a few companies can do that
work and this is a good opportunity.
11
3.2.5 Risk and Projects
• Most projects have time, cost and quality limits, the
project manager has to be able to identify and
manage project risks of late completion, cost
overspend and quality standards.
• Project manager has to be able to manage different
risk types, including strategic risk, operational risk,
unforeseen risk.
12
3.3 The human cognitive process
• Different people see risk in different ways.
• People are categorized to (risk seeker, risk neutral,
or risk averse)
• Individuals opinion/perception of a risk based on
their (attitudes towards risk, past experience,
sensitivity towards risk, … etc.)
13
3.3 The human cognitive process
• Different people see risk in different ways.
• Individuals opinion/perception of a risk based on
their (attitudes towards risk, exposure, past
experience, sensitivity towards risk, … etc.)
• People are categorized to (risk seeker, risk neutral,
or risk averse)
14
3.3 The human cognitive process
• Decision making under the conditions of risk
includes four cognitive stages:
– Pattern recognition and attention
– Consideration within the limits of bounded rationality
– Experience, prediction and outcome forecasting
– Solution formulation
15
3.3 The human cognitive process
• Decision making under the conditions of risk
includes four cognitive stages:
– Stage 1: Pattern recognition and attention
• In pattern recognition we use all available information saved in
our memory to identify risk based on past experience. In
attention analysis, we consider only the information that is
relevant to the decision to be made.
16
3.3 The human cognitive process
• Decision making under the conditions of risk
includes four cognitive stages:
– Stage 2: Consideration within the limits of bounded
rationality
• Bounded rationality is based on the assumption that people
are logical and will make rational decisions. This rationality is
limited by knowledge, experience and limits of the decision
maker.
• The decision maker looks at possible outcomes and decide
what acceptable and what is unacceptable outcomes in order
to make a rational decision.
17
3.3 The human cognitive process
• Decision making under the conditions of risk
includes four cognitive stages:
– Stage 3: Experience, prediction and outcome
forecasting
• Experience allows the decision maker to use knowledge and
understanding from past decisions and past outcomes to
assist in the selection of the best outcome.
• Prediction momentum suggests or expects an outcome that is
similar to previous outcomes where the same conditions and
variables are applied.
18
3.3 The human cognitive process
• Decision making under the conditions of risk
includes four cognitive stages:
– Stage 3: Experience, prediction and outcome forecasting
• Outcome forecasting: in making risky decisions people try to
forecast what the outcome will be based on past experience.
Outcome forecasting has limitations, such as:
– Time: reliable forecasting is a function of short/long period of time.
– Information: reliable forecasting is based on a reliable information.
– Cost: accurate forecasting sometimes costly.
– Flexibility: reliable forecasting need the decision maker to put aside
any ideas about what he/she thinks is likely to happen (become bias).
19
3.3 The human cognitive process
• Decision making under the conditions of risk
includes four cognitive stages:
– Stage 4: Solution formulation
• After the decision maker generate and forecast an outcome
based on pattern recognition, bounded rationality and
prediction, he/she needs to formulate a solution to the
risk/problem.
20
3.3 The human cognitive process
• Decision making under the conditions of risk includes
four cognitive stages:
– Stage 4: Solution formulation
• Formulating or analysis of a risk/problem form a five-stage
process, these are:
– Problem framing: remove all unnecessary data about the problem
– Solution formulation: decision maker considers problem nature, the
outcomes required, level of risk, and initial solution is generated.
– Solution evaluation: analysis of advantages and disadvantages of the
solution
– Solution refinement: improvement on the proposed solution
– Solution implementation
21
3.4 Risk handling and control
• Risk management is done by deciding what level of
risk is acceptable and what level is not. Risk that is
not acceptable is transferred or reduced in some
way.
• Once the residual risk is at an acceptable level, it is
managed to ensure that it does not affect the
performance of the project.
22
3.4 Risk handling and control
• Risk management includes two basic elements, risk
handling and risk control.
– Risk handling relates to the approach and philosophy of
the organization to risk
– Risk control relates to the procedures and mechanisms
to maintain risk to an acceptable levels.
23
3.4.1 Approaches to handling risk
• The fortress: or “what happens if” “WHIF”
– Fortress companies take extreme precautions to protect
themselves against risk impact
– They assume things will go wrong and risks will impact
– Fortress companies employ specific “WHIFs team to
analyse all possible WHIF results
– Fortress organisations are those where risk impacts can
have catastrophic effect, such as health, safety, nuclear
power
24
3.4.1 Approaches to handling risk
• The ostrich:
– Ostrich companies may have risk management systems
in place that are unreliable and incorrect and defective
– This risk management system does not identify all the
risks that face the organisation
– These organisations know that their risk management
systems are defective but do not fix it or upgrade it
25
3.4.1 Approaches to handling risk
• The optimist:
– Optimist companies are similar to the ostrich, but worse,
they may have more reliable approaches to risk
handling, and they may be aware of risk probability and
impact but decides to ignore it in the hope that
everything will be all right.
26
3.4.1 Approaches to handling risk
• The animal:
– Animal organizations assume that everything can be
sorted out by brute or physical force
– They wait until a risk impacts and then attempt to fight
its way out of the problem
– Generally, they are very competitive, small
organisations, with limited resources, such as personal
computers and mobile telephones companies
27
3.4.1 Approaches to handling risk
• The seer:
– Seer organizations believe they can see into the future
– They employ very expensive business and management
consultants
– They use complex mathematical modelling techniques
that use operational data to make predictions about
what is likely to happen in the future
28
3.4.1 Approaches to handling risk
• The natural:
– Natural organizations think they can observe the
environment and interpret risk by intuition (sixth sense)
or by some kind of instinct (feel)
– It would be very risky to run a company using only
instinctive means of identifying and managing risk, but
sometimes it succeeded
29
3.4.2 Project risk control
• Risk control is the collective term for a number of
different activities that allow risk to be identified
• Go to page 3/20 for more details
30
3.5 Types of risk
• There are a large number of different risk types,
here are some of the basic risk types that are likely
to be encountered in project management.
– Strategic risk and project risk
– Operational risk
– Market risk and static risk
– Foreseeable and unforeseeable risk
– Internal and external risk
31
3.5.1 Strategic Risk and Project Risk
• Strategic risk is more difficult to manage than project
risk, it tends to be applicable over the long term, it
tends to be more complex and difficult to model and
assess than project risk. Ex. (Variations in competitor
behavior; Changes in the economy)
• Project risk is limited to those aspects of risk that are
considered entirely in relation to the project under
consideration. Ex. (client risks, supplier risks,
contractor risks…etc.) 32
3.5.2 Operational Risk
• Operational risk is the risk associated with the
everyday operations of an organization. Some
examples include:
– Mechanical risks, production risks, employees risks,
electricity risks, client risks, competitor risks… etc.
33
3.5.3 Market and Static Risk
• Market risk (or business risk or dynamic risk):
example: share flotation, competitor activities,
release of new product.
• Static risk (specific or insurable risk): example: fire
insurance.
• Static risk can be reduced and controlled to some
extent. However, market risk will always remain and
will affect the project performance and organization.
34
3.5.4 Foreseeable/Unforeseeable Risk
• Risks are often categorized in terms of whether
they are foreseeable or not. Some examples of
Unforeseeable risks are the emergence of (a new
disease, a new technology, a new global issue like
climate…etc.)
35
3.5.5 Internal and External Risk
• Internal risks originate within the organization while
external risks originate outside it.
– Internal risk: operational, financial, IT, management risk.
– External risk: competitor risk, political risk.
36
3.5.6 The Concept of Risk Interdependency
• If risk is considered in terms of the level at which it
applies, the most basic classification listing is:
– strategic risk; project risk; operational risk;
unforeseeable risk.
• Also risk can be considered as applying across the
different functional divisions within the organization.
Typical functional divisions include the following:
– process; people; IT support; finance; sales and
marketing (interface).
37
3.5.6 The Concept of Risk Interdependency
• Risks of each level can operate in each functional
division.
– An example of a strategic process risk is the risk
associated with committing to a single long-term
production philosophy such as a new mass production
line. If this line is incorrectly designed or is incapable of
being modified to meet changes in customer demand,
the strategic risk may be significant.
38
3.5.6 The Concept of Risk Interdependency
• The relationship between risk levels and functional
sections can be considered in terms of a simple
grid.
• Risk levels are shown on the vertical axis and
functional sections are shown on the horizontal axis
See figure 3.6
• The size of the node point may be taken as the
product of the likelihood of a particular risk and the
impact of that risk. See figure 3.7
39
3.6 Risk Conditions and Decision Making
• There are generally three main conditions under
which decisions can be made. These are:
– Conditions of certainty;
– Conditions of risk;
– Conditions of uncertainty.
40
3.6 Risk Conditions and Decision Making
• Decision making under conditions of certainty:
apply where the outcome is known. It is foreseeable
from the information that is available to the decision
maker and its occurrence can be forecasted with
certainty.
41
3.6 Risk conditions and decision making
1. Conditions of certainty: example
42
3.6 Risk Conditions and Decision Making
2. Decision making under conditions of risk: apply
where there is a reasonable probability that an
event will occur and where some kind of
assessment can be made.
– Most risk management and decision making take place
under conditions of risk.
43
3.6 Risk Conditions and Decision Making
2. Conditions of risk: example:
44
3.6 Risk Conditions and Decision Making
3. Decision making under conditions of uncertainty:
apply where it is not possible to identify any known
events. Decision making under conditions of
uncertainty is therefore concerned with wholly
‘unknown’ events.
45
3.6 Risk Conditions and Decision Making
• Under conditions of uncertainty, decision makers often
adopt one of a series of risk attitude philosophies. In
such cases the decision on which strategy to adopt
depends on the risk attitude criterion that is adopted.
There are four primary attitude criteria:
– Hurwicz criterion;
– Wald criterion;
– Savage criterion;
– Laplace criterion.
46
3.6 Risk Conditions and Decision Making
1. Hurwicz (maximax) risk seeking: maximizing profits
at the risk of maximum loss
47
3.6 Risk Conditions and Decision Making
2. Wald criterion: decision maker is pessimistic and
seeks to minimize losses, example:
48
3.6 Risk Conditions and Decision Making
3. Savage criterion: decision maker is a bad loser-
seeks to minimize maximum regret that applies to
each strategy, example:
49
3.6 Risk Conditions and Decision Making
3. Savage criterion: example:
For N1 the largest value = 200m then For N3 the largest value = 80m then
S1 regret = 200 – 100 = 100m S1 regret = 80 – 60 = 20m
S2 regret = 200 – 150 = 50m S2 regret = 80 – 80 = 0m
S3 regret = 200 – 200 = 0m S3 regret = 80 – -100 = 180m
For N2 the largest value = 160m then
S1 regret = 160 – 80 = 80m
S2 regret = 160 – 100 = 60m
S3 regret = 160 – 160 = 0m
50
3.6 Risk Conditions and Decision Making
3. Savage criterion: example:
In total:
S1 = 100 + 80 + 20 = 200m
S2 = 50 + 60 + 0 = 110m
S3 = 0 + 0 + 180 = 180m
51
3.6 Risk Conditions and Decision Making
4. Laplace criterion: maximum profits:
52
3.6 Risk Conditions and Decision Making
3. Decision making under conditions of uncertainty:
apply where it is not possible to identify any known
events. Decision making under conditions of
uncertainty is therefore concerned with wholly
‘unknown’ events.
53
3.7 The concept of risk management
• Risk can be a good thing. Without risk there is no
reward. Risk is therefore to be encouraged within
an organisation, but it is also dangerous and so has
to be managed through risk management system.
• Organization has to be able to identify, analyse,
classify and treat risks so that the danger or hazard
presented by the risk is within the limits.
54
3.7 The concept of risk management
• Most risk management systems contain six distinct
areas:
1. Risk strategy
2. Risk identification.
3. Risk analysis and classification.
4. Risk attitude
5. Risk response
6. Risk management system monitoring, control, and
reporting.
55
3.7 The concept of risk management
1 Risk strategy:
– organization need to establish a risk management
strategy to deal with risk.
– All organizations have some kind of strategy for dealing
with risk, even if it is not formalized as a code of
practice.
– Different types of risk might be more important in some
organizations than in others based on their risk
management strategy.
56
3.7 The concept of risk management
2 Risk identification:
– After establishing risk management strategy to be
adopted, the next step is to establish a reliable risk
identification system
– Risk identification is to find out all the risks that are
likely to impact on a given project and to explore the
linkages and interdependencies between them.
– The most obvious and widely used method for risk
identification is brainstorming.
57
3.7 The concept of risk management
2 Risk identification:
– There are a number of risk identification tools or
techniques [expected question in the exam]:
1. Brainstorming technique
– Delfi technique (see page 3/45)
– Nominal Group technique
2. SWOT Analysis technique (figure 3.8 page 3/48]
3. Cause and Effect Analysis technique: lists causes and
affects of expected problem/event (figure 3.9)
58
3.7 The concept of risk management
• Once the various risks have been identified, they
then have to be analyzed in order to be classified in
some way.
• In analysis, the risk is broken down into
components so that the characteristics of the risk
can be identified.
• Once the characteristics of the risk are fully
understood, the risks can be classified.
59
3.7 The concept of risk management
3 Risk Analysis tools:
– Risk Analysis Tables: a table showing different risk
outcomes against the likelihood and consequences of
each occurring. The likelihood and consequences can
be expressed as an average based on the total range of
outcomes that could occur. An example is shown in
Table 3.11
60
3.7 The concept of risk management
3 Risk Analysis tools:
– Risk Factor Checklists: Risk factor checklists or risk
assessment uses a simple probability and impact score
to measure the magnitude of a range of risks. An
example is shown in Figure 3.12.
61
3.7 The concept of risk management
3 Risk Analysis tools:
– Risk Drivers Map: Risk factor checklists or risk
assessment uses a simple probability and impact score
to measure the magnitude of a range of risks. An
example is shown in Figure 3.12.
62
3.7 The concept of risk management
3 Risk Analysis tools:
– Risk Map: the most common basis for risk assessment
and classification. It represents risks in terms of the
likelihood of occurrence against the impact of a risk if it
does occur. The most common form is a quadrant risk
map, as shown in Figure 3.15.
63
3.7 The concept of risk management
3 Risk Analysis tools:
– Risk Grid: risk grid can be alternative to a risk map. It is
a risk map that shows likelihood and impact in tabular
form with some kind of response of action. See table
3.12
64
3.7 The concept of risk management
3 Risk Classification System:
– Multi-Level Classification Systems: risks are classified
according to characteristics at three different levels:
• Risk magnitude (low, moderate or high)
• Risk type (static or market)
• Risk application: level of impact on (project, company, sector,
environment). Figure 3.1
65
3.7 The concept of risk management
4 Risk Attitude:
– Risk attitude is a measure of the extent to which the risk
taker is prepared to accept risk.
– This varies from person to person and from organisation
to organisation.
– Attitude of a risk taker could be (seeker, neutral or
averse) figure 3.22
66
3.7 The concept of risk management
5 Risk response: responses to any risk include:
– eliminate it;
– reduce it as much as possible;
– transfer it to somebody else;
– negotiate it out;
– live with it and keep an eye on it;
– ignore it.
67
3.7 The concept of risk management
6 Risk management system monitoring, controlling
and reporting:
– Risks can change quickly and new risks can make a
significant impact on the project.
– The performance and reliability of the risk management
system should be reviewed at regular intervals.
– Risk reports should be produced to a timetable. The
frequency of reporting will depend on the significance of
the risk.
68
3.7 The concept of risk management
• Once the overall risk strategy has been developed
and assessed, it is sometimes adapted and
formulated into an overall risk policy.
• This is simply a statement of the policy of the
organisation in terms of risk and risk management.
69
3.8 Risk, contracts and procurement
A contract is a classic
way of managing risk!
70
3.8 Risk, contracts and procurement
• Contract is a tool for risk transfer and mitigation.
• Projects include an element of disagreement and
conflict.
• Where the risk is high, the tender price will be
higher to reflect this risk absorption.
• A contract is to some extent a protection against
disagreement and conflict.
71
3.8 Risk, contracts and procurement
• Reasons for the conflict could be:
– Incorrect estimating and pricing;
– Ambiguous specification;
• The purpose of the contract is to define the rights,
dues, obligations and liabilities of each party.
Contracts are particularly appropriate in defining
and allocating risk.
72
3.8 Risk, contracts and procurement
• Procurement is the process by which goods and
services are acquired.
• It is the process of the two (or more) different
contractual parties.
• Procurement is important because good
procurement leads to good suppliers and less risks.
For more details on contracting, see pages 3/74-
73
End of Module 3: Project
Risk Management
74