0% found this document useful (0 votes)
32 views103 pages

Project Risk Management Guide

The document outlines the principles and processes of Project Risk Management, emphasizing the importance of identifying, analyzing, and responding to risks throughout a project's lifecycle. It highlights the distinction between negative and positive risks, the need for a structured risk management plan, and the benefits of proactive risk management. Additionally, it discusses factors influencing risk appetite and the components of a comprehensive risk management approach.

Uploaded by

singibacha
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
32 views103 pages

Project Risk Management Guide

The document outlines the principles and processes of Project Risk Management, emphasizing the importance of identifying, analyzing, and responding to risks throughout a project's lifecycle. It highlights the distinction between negative and positive risks, the need for a structured risk management plan, and the benefits of proactive risk management. Additionally, it discusses factors influencing risk appetite and the components of a comprehensive risk management approach.

Uploaded by

singibacha
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

PROJECT RISK

MANAGEMENT
CHAPTERS
Chapter 1 - Project Risk Management
Chapter 2 - Identifying Project Risks
Chapter 3 - Performing Qualitative Risk Analysis
Chapter 4 - Performing Quantitative Risk Analysis
Chapter 5 - Developing Risk Response Strategies
Chapter 6 - Implementing Responses and Monitoring Risks
Chapter 1
1.1. Risk Management
Risk Management

• Risk is the focal topic in the • A project is defined as a sequence


management of many of tasks that must be completed
activities and technologies to attain a certain outcome.

• Project refers to ” to any


• A risk is the potential of a
temporary endeavor with a
situation or event to impact
definite beginning and end”
on the achievement of specific
objectives.
• Project management is the
application of processes,
• Risk implies future uncertainty methods, skills, knowledge and
about deviation from expected experience to achieve
earnings or expected outcome specific project objectives.
5

What is Project Risk?

• Project risk is an uncertain event or


• An event that, if it occurs,
condition that, if it occurs, has an effect on
at least one project objective. causes either a positive or
negative impact on a
• Objectives can include scope, schedule,
cost, and quality. project.
• A risk may have one or more causes and, if
it occurs, it may have one or more impacts. • Keys attributes of Risk

• A cause may be a requirement,


• Uncertainty
assumption, constraint, or condition that • Positive and Negative
creates the possibility of negative or
positive outcome. • Cause and Consequence
6

Risk Management
RM

• Risk management is concerned with • Risk management is the


identifying risks and drawing up plans process of identifying,
to minimise their effect on a project. assessing and controlling
threats to an organization's
• A risk is a probability that some adverse
capital and earnings.
(or positive) circumstance will occur:

• Project risks affect schedule or resources;


• Product risks affect the quality or
performance of the software being
developed;
• Business risks affect the organization
developing or procuring the software


7

Project Risk Management

• Project risk management is the art


• Project Risk Management is the and science of identifying,
processes of conducting risk analyzing, and responding to risk
management planning, throughout the life of a project and
identification, analysis, response in the best interests of meeting
planning and monitoring and control project objectives
on a project.
• Risk management is often
overlooked in projects, but it can
• The Objectives are to increase the
help improve project success by
probability and impact of positive
helping select good projects,
events and decrease the probability
determining project scope, and
and impact of negative events in the
developing realistic estimates
project
8

The Importance of Project Risk Management

• The purpose of project risk • Moreover, the objective of project


management is to minimize the risks risk management is to understand
of not achieving the objectives of the project and program level risks,
project and the stakeholders with an minimize the likelihood of negative
interest in it, and to identify and take events and maximize the likelihood
advantage of opportunities. of positive events on projects and
program outcomes.
• In particular, risk management assists
project managers in: • PRM is a continuous process that
 setting priorities, begins during the planning phase and
 allocating resources and
 implementing actions and processes that
ends once the project is successfully
reduce the risk of the project not achieving its
commissioned and turned over to
objectives. operations.
1. identifying, analyzing and assessing risks
Keys to managing
early and systematically, and developing
project RISK effectively: plans for handling them;

2. allocating responsibility to the party best


placed to manage risks, which may
There are three involve implementing new practices,
keys to procedures or systems or negotiating
managing project suitable contractual arrangements; and
and procurement
risk effectively:
3. ensuring that the costs incurred in
reducing risks are commensurate with the
importance of the project and the risks
involved.
• Business risks include all those risks that might

scope of risk impact on the viability of the enterprise,


management including market, industry, technology,
economic and financial factors, government
and political influences.

• Project risk includes all those risks that might


The scope of risk
impact on the cost, schedule or quality of the
management for
projects includes :.
project.

• Operations and processing risks include all


those risks that might impact on the design,
procurement, construction, commissioning,
operations and maintenance activities,
including major hazards and catastrophic
events.
• Many organizations undertake projects
involving significant capital outlays, or
When is project risk management used? groups of related projects that together
make up large programs.
Three aspects
of large projects
• Three aspects of large projects or programs
or programs
make risk make risk management desirable.
management 1. Their size implies there may be large
desirable potential losses unless they are
managed carefully,
2. They often involve unbalanced cash
flows, requiring large initial
investments before meaningful
returns are obtained.
3. Large public sector projects may
12

1.2. Types of Risk and Risk Handling techniques

1. Negative Risk 2. Positive risks:

• are risks that result in good things


• A dictionary definition of risk is “the possibility happening; sometimes called opportunities
of loss or injury”
• A general definition of project risk is an
uncertainty that can have a negative or
• Negative risk involves understanding potential
positive effect on meeting project objectives
problems that might occur in the project and
how they might impede project success • The goal of project risk management is to
• Negative risk management is like a form of minimize potential negative risks while
insurance; it is an investment. maximizing potential positive risks

• Definition of opportunity: a positive risk,


• Definition of threat: a negative risk, an
an uncertain event that could have a
uncertain event that could have a negative favourable impact on a project’s objectives
impact on a project’s objectives or benefits or benefits
Risks can be broken out into two Other types of risk
primary types categorization
Pure Risk (hazard)– risk with
potential loss only. ex. Fire, theft,
personal injury

Business Risk (speculative risk) –


risk with potential loss or gain
• ex. A highly skilled employee
becomes available to work on your
project, reducing your schedule
time, the tax rate changes, a new
server costs less (or more) than you
budgeted for !
RISK MANAGEMENT
STRATGIES

4 RISK
MANAGEMENT
STRATGIES TO
ENSURE
PROJECT
SUCESSS
Risk Management Process Opportunities

Threats
Monitoring &
Project Risk Controlling Processes

Planning
Management Processes

Enter Exit
phase/ Initiating Closing phase/
Start Processes Processes End
project project

Executing
Processes

Process
Knowledg
e Area Initiating Planning Executing Monitoring & Control Closing

Plan Risk Management


Identify Risk
Risk Perform Qualitative Risk Analysis Monitor and Control Risks
Perform Quantitative Risk Analysis
Plan Risk Response
Overall Project
Management
Processes with Risk
Management
Risk Management Processes

• Risk Planning – this is how you plan on • Quantitative Analysis – a numerical


conducting risk management. You wouldn’t analysis of the probability and impact of
start managing your project without a plan, the risk on your project
so why would you approach risk
management that way?
• Plan Risk Response– a course of

• Identify Risks – this is the phase where


action you will take to deal with your
risks should they go from risk to issue
you attempt to identify most of your risks

• Qualitative analysis – this is a subjective • Monitor & Control Risks – monitoring


analysis of your risks that produces a risk your lists (there are two lists which I will
ranking, usually in the order of high, discuss later) of risks to enact a risk
medium, low, or on an ordinal scale. response plan, to move a risk from one
Rankings are by agreement of your project list to the other, or to remove a risk
team, sponsors and key stakeholders because it is no longer a risk.
Terms & concepts 1.3. Level of risks in projects

• Uncertainty: a lack of knowledge There are three levels of risk


about an event that reduces
confidence
management that apply to
• Risk averse: someone who does not projects
want to take risks.
• Risk Prone – Someone who is
willing to take big risk
1. Project risk : This is
• Risk tolerances: area of risk that perhaps the most obvious.
are acceptable / unacceptable. These risks do not recognize
• Risk thresholds: the point at which interdependencies and risks
a risk become unacceptable outside the scope of the
• Risk Areas: Project Constraints
(scope, time, cost, etc)
project.
2. Project selection risk: 3. Project portfolio risk:

At this level the question relates to • This is where you start to


how risk plays a part in making
decisions about which projects should
look outside the projects as
be started. individual initiatives and start
to gather rich data about the
The challenge here is whether the organization's approach to
business just says yes or no to a risk management as a whole.
project without looking at the overall
position and the wider business
requirements.
1.4. Planning
Risk “Prevention is better than Cure”
Management
A risk management plan also called a “risk
mitigation plan” is a well-defined document
that tells how to deal with specific risks and
what management actions must be taken
against those risks in order to mitigate or
PPRM remove threats to the project tasks and
outcomes.

The risk management plan gives teams a


sense of measures they need to take in
order to identify, analyze, and respond to
all the risks running around within the
project wheel.
1.4. Planning
Risk • A Risk Management Plan (RMP) is prepared
Management by a project manager to address risks, and
their potential impact on a program and
consists of ways to reduce these risks.

• A RMP is a written record of the whole


process, including how risks are found,
evaluated, and dealt with.

• It also includes monitoring risk control, a


PPRM cost-benefit analysis, and a look at the
financial effects.

• The RMP tells the government and


contractor team how they plan on reducing
risks to a certain level by a certain time.
How to Create a Risk Management Plan?

Step 1. Identify the risk Step 2. Analyze the risk

• Foreseeing possible pitfalls of Once you and your team


a project does not have to identify potential issues, it’s
feel like a dead-end for an time to explore a little deeper.
organization. On the • How often do these risks
contrary, identifying risks is a happen?
positive experience that your • And if they do, what will the
whole team can learn from consequence be?
and take part in.
Step 3. Prioritize the risk
Prioritize the risk

• After the in-depth analysis of • This step provides you a


your risks its time to holistic view of the project at
prioritize. hand and points out where
the team’s focus should be.
• Rank each risk by
considering both the • Most importantly, it will
probability of its happening assist them in identifying
and its possible effect on the workable solutions for each
project. prioritized risk.
Step 4. Treat the risks Step 5. Monitor the risk

• Once the risks come to light, execute • While as the project proceeds, the
your treatment plan. risk management plan simultaneously
takes care of all the risks that you
• Begin with the highest priority risk, might encounter on the way.
assess your team with either mitigating
the risk or at least solving it so that it’s
• Since all the proceeds of the risk
no longer a threat to the project.
management plan are documented,
keeping tabs on those moving targets
• Effectively mitigating and treating the
becomes important! It’s crucial to
risk also means utilizing your team’s
review this document at regular
resources optimally without hampering
intervals of time.
the project in the meantime.
PRM : input, tools and technique and output
Plan Risk Management Data Flow Diagram. Figure 11-3
1. Boosts Results: By defining a risk management plan
Benefits of Writing a for your organization, your chances of a successful
Risk Management Plan project are more likely as it minimizes and eliminates
negative risks such that projects can be completed on
time.

2. Help you be Proactive, and Not Reactive: Having a


Benefits of clear management plan lets you be proactive and take
Writing a Risk steps to reduce potential issues before they arise,
Management instead of constantly fire fighting.
Plan
3. Help you Evaluate the Entire Project: With the help
of a devised risk management plan, you can assess the
impact of your tasks by mitigating exposure to risks and
exploiting opportunities that capitalize on your
organizations’ strengths. In other words, it helps you
evaluate your current project’s success and to helps you
build best practices for the future.
Risk Management Plan (RMP) Objectives

(RMP) Objectives (RMP) Objectives


• The goal of well-written RMP Reduce Schedule Impacts
is to provide a repeatable Reduce development cost
process that reduces risk on
Increase system
a project or program and
meets organizational Risk performance
Management Objectives. Ensure proper
• The following are a few communication
objectives of a risk Determine risk priorities
management plan that an
organization can aim for.
1.5. Stakeholder risk appetite

risk appetite risk appetite


• The risk appetite, in project • Moreover, it also refers to the
management, is the level of amount of risk that organizations
uncertainty and stakeholders want to accept in
an organization or stakeholder is order to attain its objectives.
willing to take on with the
anticipation of reward at the end. • There are some organizations that
are willing to take a lot of risks
• The risk appetite of especially if the rewards are high
an organization indicates how thus a high-risk appetite, but some
much it is willing to take risks to want to play it safe and just go
grow itself. conservatively thus a low-risk
appetite.
Factors Affecting Risk Appetite 1.6. Risk Utility

The following factors affect • The goal of PRM is to minimize


potential negative risks while
the risk appetite of an maximizing potential positive risks.
organization: • Risk utility or risk tolerance is the
amount of satisfaction or pleasure
• Organizational culture received from a potential payoff
• Risk attitude of stakeholders • Utility rises at a decreasing rate for
people who are risk-averse
• Competition
• Those who are risk-seeking have a higher
• The organization’s financial tolerance for risk and their satisfaction
condition increases when more payoff is at stake
• The capability of the • The risk-neutral approach achieves a
organization balance between risk and payoff
32

Risk Utility
Function and
Risk Preference
Risk • A comprehensive project risk
management management approach should
approach
have the following components,
which should be scalable to the
specific project’s size and type:
1. Strategy and planning;
2. Risk identification;
3. Analysis (quantitative and qualitative);
4. Response planning; and
5. Monitoring and control.
1. Strategy and planning 2. Risk identification

• Strategy and planning activities • Risk identification is the


set the foundation for a risk identification of all possible
management program and risks that could either
ultimately determine whether negatively or positively affect
the initiative is successful. the project.

• During the strategy and


• It is important in the risk
planning phase an organization
will define how risks are identification process to
addressed and managed. solicit input from all project
stakeholders including those
outside of the core project
3. Analysis
4. Response planning

• The analysis phase determines the likelihood • Response planning is the phase where the
and impact of each identified risk and project team develops response actions and
prioritizes risks for management attention. alternative options to reduce project risks.

• Successful risk analysis requires objective • Project teams use response planning to decide
thinking and input from those most familiar ahead of time how they will address possible risk
with the area affected by the possible risk occurrences and how they will avoid, transfer,
mitigate or accept project risks.

• Qualitative Risk Analysis – Prioritizing risks for


• Response planning must take into consideration
subsequent further analysis or action by
available resources and potential repercussions
assessing and combining their probability of
of the response plans.
occurrence and impact
• The goal of response planning is to align risks
• Quantitative Risk Analysis - Analyzing with an appropriate response based on the
probabilistically the effect of identified risks on severity of the risk along with cost, tie and
overall project objectives. feasibility considerations
1.6. Risk management plan
5. Monitoring and control
elements
• The final step of risk management is 1. Summary : The final version of your risk
management plan typically includes a
monitoring and control.
summary of the project and its scope of
work.
• This process should be set up to track
potential risks, oversee the 2. Definitions : You may include a definitions
section to ensure stakeholders'
implementation of risk plans, and understanding of your risk scoring and
evaluate the effectiveness of risk analysis methods. For example, your
management procedures. probability and impact matrix may define
risks using phrases.

• Monitoring and control should occur


3. Approach and methodology: The
throughout the project lifecycle and approach and methodology section of your
help improve and guide the overall risk management plan defines your team's
risk management process approach to identify, manage and mitigate
risks.
• 4. Team roles and responsibilities : This
• Risk management plans
section defines the roles, tasks and
often comprise several key deliverables assigned to team members. In a
risk management plan, these factors may align
components that you can with specific risk scenarios identified by your
customize based on the team.
• 5. Budgeting and scheduling: When
needs of your project or managing risk, you need to make budget and
organization. scheduling considerations to ensure your
project remains on task.
• 6. Probability and impact matrix: Also
known as a risk assessment matrix, this tool
• These components include: helps you assess risks based on their
probability and impact.
• 7. Risk breakdown structure: A risk
breakdown structure is a chart that details the
categories of risk your project may encounter.
1.7. Risk impact and probability scales

Risk impact and probability scales Risk impact and probability scales

• Effective risk management requires • Probability – A risk is an event that "may"

assessment of inherently uncertain occur. The probability of it occurring can


range anywhere from just above 0 percent
events and circumstances, typically
to just below 100 percent. (Note: It can't be
addressing two dimensions: exactly 100 percent, because then it would
be a certainty, not a risk. And it can't be
• how likely the uncertainty is to occur exactly 0 percent, or it wouldn't be a risk.)
(probability), and what the effect would be if
it happened (impact). • Impact – A risk, by its very nature, always
has a negative impact. However, the size of
• The probability and impact scores the impact varies in terms of cost and
are used to arrive at overall values for impact on health, human life, or some other
critical factor.
ranking the risk events.
The corners of the chart have these
characteristics:

• Low impact/low probability – Risks in the bottom left corner


are low level, and you can often ignore them.

• Low impact/high probability – Risks in the top left corner are


of moderate importance – if these things happen, you can cope
with them and move on. However, you should try to reduce the
likelihood that they'll occur.

• High impact/low probability – Risks in the bottom right


corner are of high importance if they do occur, but they're very
unlikely to happen. For these, however, you should do what you
can to reduce the impact they'll have if they do occur, and you
should have contingency plans in place just in case they do.

• High impact/high probability – Risks towards the top right


corner are of critical importance. These are your top priorities,
and are risks that you must pay close attention to.
The corners of
the chart have
these
characteristics:
The corners of the
chart have these
characteristics:
Chapter 2 - Identifying
Project Risks
2.1. Identification participants
• Where time and resources permit, all members of the
project team should attend the identification
session, including functional unit members assigned
to the project on a part-time basis.
• People who might be included in a brainstorming
group are:
the project manager and the project team;
project sponsors;
discipline engineers;
experts with specific knowledge in particular areas of
concern
commercial specialists;
health, safety and environmental specialists;
users of the project outcomes;
key stakeholders
gathering
techniques for
identifying 1. Documentation reviews:
project risk What is and what is not included in the
preliminary project scope statement, the
project charter and later documents can
help identify risks.
Lessons learned, articles and other
documents can also help uncover risks.
Documentation reviews involve reviewing
project plans, assumptions, and historical
information from a total project perspective
as well as at the individual deliverables or
activities level.
This review helps the project team identify
risks associated with the project objectives.
2. Brainstorming
• Brainstorming is a group creativity
technique designed to generate a
large number of ideas for the
solution of a problem.
• it may still provide benefits, such as
boosting morale, enhancing work
enjoyment, and improving team
work. Thus, numerous attempts
have been made to improve
brainstorming or use more effective
variations of the basic technique.
• There are four basic rules in brainstorming. These
are :
i. Focus on quantity: This rule is a means of
enhancing divergent production, aiming to
facilitate problem solving through the maxim,
quantity breeds quality. The assumption is that
the greater the number of ideas generated, the
greater the chance of producing a radical and
effective solution.
ii. Withhold criticism: In brainstorming, criticism
of ideas generated should be put 'on hold'.
Instead, participants should focus on extending or
adding to ideas, reserving criticism for a later
'critical stage' of the process. By suspending
judgment, participants will feel free to generate
unusual ideas.
iii. Combine and improve ideas: Good ideas may
be combined to form a single better good idea,
3. Delphi technique
• The Delphi method is a systematic,
interactive forecasting method which
relies on a panel of independent experts.
The carefully selected experts answer
questionnaires in two or more rounds.
• This method utilizes a formal Delphi
group and is designed to pool the
expertise of many professionals in such
a way as to gain access to their
knowledge and to their technical skills
while removing the influences of
seniority, hierarchies, and personalities
on the derived forecast.
4. Interviewing
• Interviews are question-and-answer sessions held with
others, including other project managers, subject matter
experts, stakeholders, customers, the management team,
project team members, and users.
• These people provide possible risks based on their past
experiences with similar projects.
5. Root cause analysis
• Root cause analysis (RCA) is a class of problem solving
methods aimed at identifying the root causes of problems
or events.
• The practice of RCA is predicated on the belief that
problems are best solved by attempting to correct or
eliminate root causes, as opposed to merely addressing
the immediately obvious symptoms.
• By directing corrective measures at root causes, it is
hoped that the likelihood of problem recurrence will be
minimized.
6. Checklists
• Checklists are quick to use, and they
provide useful guides for areas in which
the organization has a depth of
experience, particularly for projects that
are standard or routine in nature.
• The checklists are part of the
organization's quality assurance
procedures and documentation.
• Checklists used during the Risk
Identification process are usually
developed based on historical
information and previous project team
experience.
7. Diagramming techniques
• Diagramming techniques, such
as system flow charts, cause-
and-effect diagrams, and
influence diagrams are used to
uncover risks that aren't readily
apparent in verbal descriptions.
• SWOT Analysis is a strategic
2.3. SWOT
analysis planning method used to
evaluate the Strengths,
Weaknesses, Opportunities,
and Threats involved in a
project.
• It involves specifying the
objective of the project and
identifying the internal and
external factors that are
favorable and unfavorable to
achieving that objective.
• Strengths: attributes of the team
or company those are helpful to
achieving the objective.
• Weaknesses: attributes of the
team or company those are harmful
to achieving the objective.
• Opportunities: external conditions
those are helpful to achieving the
objective.
• Threats: external conditions which
could do damage to the business's
performance.
Pro Con

Internal Strength Weaknes


s
External
Opportuni Threat
ty
• A work breakdown structure (WBS) is
2.4. Work breakdown a visual, hierarchical and deliverable-
structure (WBS)
oriented deconstruction of a project.
• It is a helpful diagram for project managers
because it allows them to break down their
project scope and visualize all the tasks
required to complete their projects.
• A work breakdown structure (WBS) is a
project management tool that takes a step-
by-step approach to complete large
projects with several moving pieces.
• By breaking down the project into smaller
components, a WBS can integrate scope,
cost and deliverables into a single tool.
At this point the risk register would include:
2.5. Risk • List of risks.
register
• List of potential responses. Though risk
response planning occurs later, one of the
things experienced risk managers know is
that it is not always logical to separate work
on each part of risk management.
• Root causes of risks previously explained,
these are now documented.
• Updated risk categories. You will notice lots
of places where historical records and
company records are updated throughout
the project management process
Risk register at Task Cause Risk Effect
identification
process
Design Conflict Errors + Delay
Rework

Procurem Single Inappropriate Delay/ cost


supplier delivery increase
ent
Handing Permit not No access Delay
ready
out
Executing Technical Rework Delay/ cost
problems increase

Verificatio Non Corrective quality./cost/


conformance action time
n
• Risk Documentation
Each element and each risk should be
numbered, to facilitate storage and retrieval of
information. Often the risk numbers are nested
within the element number, and the nested
numbering is extended as necessary as the
analysis progresses.
Each risk should be described.
The description of the risk should include the
main assumptions and mechanisms leading to
the risk arising, the criteria likely to be affected,
the phases of the project in which it is most
likely to occur and notes on the consequences if
it does arise. Sources of information should also
be noted.
• Risk Responsibility
Management responsibility for
dealing with each specified risk
and ensuring effective treatment
plans are developed and
implemented should be assigned
and recorded. The responsible
manager is sometimes called the
risk owner.
• Project management is most frequently
2.6. Risk report associated with the topics of cost,
quality, and time. Yet, those three legs of
project management are all directly
impacted by risk.
• Risk management is crucial in all
projects; whether an opportunity or
threat, all risks should be identified and
planned to increase the possibility of a
successful outcome for a project.
• Project managers (PM) conduct risk
analysis work, maintain a risk watch list,
and generate a risk report as part of
overall risk management work.
• By definition, a risk report is a communication
tool within risk management. The report should
be clear, concise, and indicate actions taken,
preparation for other risk-related actions, and
any inputs needed by stakeholders to ensure
continuous risk management support.
• The risk report will inform key stakeholders of
the consequence of the risks, the likelihood of
occurrence, and the mitigation strategy to be
adopted in the event the risks occur.
• A well-developed and maintained risk register
can serve as the risk report, if it includes not
only negative risks but also opportunities, a
supporting risk treatment plan, a work
performance data review, project progress, and
the status of all deliverables.
• A risk report is an indicator of
the performance of the overall
risk management work. Project
managers should use the risk
report to convey risk status to
the team and to provide
information to stakeholders to
inform risk management
decisions.
Chapter 3
• Qualitative risk assessment is the most useful part of
Performing
Qualitative the risk management process and it lays the
foundation for all the subsequent stages in that
Risk Analysis
process, including the quantitative analyses that are
frequently required to define budgets and time-
scales.
• Qualitative risk analysis is an essential step when
conducting risk management that helps you manage
a project and maintain its schedule. Preparing these
can help you avoid potentially costly delays or
mistakes, which helps ensure the project succeeds.
• Qualitative risk analysis is a formal process for
evaluating the likelihood and potential impact of
project risks. It provides a framework for ranking
risks according to the level of threat they pose to
inform project risk management strategies.
• Qualitative methodologies concern
Qualitative themselves with how management
Methodologies
decisions are actually made, rather than
the traditional operational research
approach of obtaining the “right” answer.
• Methodologies that can screen out
unfeasible alternatives, study the entire
range of solutions, and explore the effect of
likely constraints, will develop contrasting
possibilities as to what is required.
• Placing decisions in the context of
alternative future environments permits the
opening up of discussions about threats and
opportunities.
• Simplicity and clarity are sought, and
uncertainty treated as a fact.
• Qualitative risk analysis is the process
of identifying, analyzing and evaluating
risks in an organization.
• Qualitative risk analysis uses subjective
expert judgment to determine the
probability of a risk occurring and its
impact on an organization.
• The outcome of this process is a list of
risks with their corresponding
probabilities and impacts.
• relatively straight-forward technique
that can be applied to many types of
projects.
Qualitative analysis of risk
serves 3 functions:

• Prioritize risks according to


probability & impact
• Identify the main areas of
risk exposure
• Improve understanding of
project risks
• Performing a qualitative risk analysis isn’t
5 Step process to
perform a qualitative particularly difficult, but it takes focus and
risk analysis attention to detail. It requires a project
manager or risk manager to follow this process
carefully.
1. Put together a team to identify risks. It’s
crucial to assemble a team of subject matter
experts that bring direct knowledge and
experience to help project managers isolate
potential trouble spots.
2. Isolate all potential risks. What may seem
like a minor risk can quickly expand to become a
significant concern. Avoid assuming that some
threats don’t need to be considered. It’s better
to document all risks, then analyze and assign a
weighting that can be re-evaluated later.
3. Rate and prioritize each risk /impact
assessment : Based on its impact and likelihood
of occurring, each risk should be rated to
determine if it’s a high priority or low concern.
4. Develop strategies to address risks based
on their priority / Risk Treatment : After
setting the priority for each risk, work with subject
matter experts to come up with potential
strategies to address them. Make sure to think
about the impact of each solution on other risks
and solutions.
5. Monitor each risk and re-evaluate: It’s not
enough to identify risks and come up with
solutions. Often, as a project is progressing, risks,
their impact, and the likelihood of occurring can
change. Revisit risks as each crops up and is
addressed.
1. Identifying Risks / Put together a
team to identify potential risks
• Risk identification is arguably the most
important part of qualitative risk analysis. If
you fail to identify risks ahead of time, it
becomes extremely challenging to manage
them.
• The trick to risk identification is keeping it
simple. Start thinking of anything which
could have an uncertain effect on your
project. Capturing the obvious risks will help
lead you deeper into more slanted ones.
• Risk identification is all about quantity. So,
reach out to as many people as you can to
get a wide range of views.
Tools for Risk Identification
• Mind maps/Brainstorming
• Questionnaires
• Interviews
• Documentation review
• Checklist analysis
• SWOT Analysis
2. Impact Analysis
• Once you’ve identified possible risks, the next
step is to consider their potential impact.
• Segregate the risks into threats and opportunities,
but remember that they are similar but not
opposite.
• Using qualitative risk analysis, estimate the
impact of each risk on a scale (1-5 or
low/medium/high/extreme).
• Next, estimate the probability of each risk
occurring, using a similar scale.
• Finally, take those scores and combine them to
create a total risk ranking.
• Simplicity is the major benefit of qualitative risk
analysis;
3. Risk Treatment
• The next stage in the qualitative risk analysis
is to apply treatments to each risk. This can
be approached in any number of ways
depending on your industry or process. A
simple example could show five options
when it comes to risk treatment, but these
are by no means definitive:
• Accept
• Mitigate
• Exploit
• Transfer
• Avoid
4. Review & Monitor
• Risk management is never over, not even
after the project has finished. As the
project progresses, it’s important to keep
risk logs up to date. At each stage of the
project, risk probability will fluctuate. Some
risks will disappear, while others might
increase in likelihood. Reviewing your risks
regularly will help keep you on top of these
changes.
• After the project, a full retrospective will
provide valuable data and experience for
future projects, making the next one more
secure and helping to further your risk
maturity.
• Expert judgment, data gathering, and data analysis
Qualitative tools
are just some of the qualitative risk analysis tools
and techniques
teams can use. Each has its benefits and drawbacks.
• Expert judgment provides insight based on similar
experiences and is somewhat subjective, while data
gathering provides information from stakeholder
interviews.

• Data analysis involves risk probability (likelihood) and


impact.

• Performing a thorough qualitative risk analysis to


isolate and prioritize risks, develop strategies to
address, monitor, and re-evaluate them, provides
your team the confidence.
There are four • Risk register.
inputs to Qualitative
risk analysis: This of course, is the source of all of
the known risks that are to be
analyzed.
• Risk management plan.
it will clarify the overall approach that
needs to be taken to risk management
on this particular project as well as
stating how much risk is acceptable
and who should be involved in
carrying out the qualitative risk
analysis of the project risks.
• Project scope statement.
This key document describes both the project and
product deliverables along with the objectives of the
project and to the requirements, along with the
constraints and assumptions. When it was first
created within the define scope process, it also
included all the identified risks known at that time,
and these will be used along with the other
information within this document for qualitative risk
analysis.
• Organizational process assets.
These will include aspects such as tools to help
carry out qualitative risk analysis, policies,
procedures and guidelines for risk management,
and historical information including lessons learned
from previous similar projects.
• Risk register updates.
This is the only output from this
process. Prior to qualitative risk
analysis, the risk register
contains a list of all of the risks,
but now extra information can be
added to the risk register
including the priority of urgency
of each risk, their categorization
and any trends of have been
observed while carrying out this
process.
• Different types of project demand
Types of qualitative
risk Analysis different types of qualitative risk
analysis. Availability of resources and
personal experience also factor into the
decision of how to approach assessing a
project’s risk. The five most common
types of analysis are:
1. Probability/Consequence Matrix
2. Bow-Tie Analysis
3. Delphi Technique
4. SWIFT Analysis (Structured What-
IF Technique)
5. Pareto Principle
• To many, this is the standard method of
1.
Probability/Consequenc establishing risk severity. Risk matrices will
e Matrix
often vary in size, but they all essentially do the
same thing. They provide a practical way to
rank the overall severity of a risk by multiplying
the likelihood of risk occurrence against the
impact of the risk, should it still occur.

• A probability and impact matrix is a tool used in


qualitative risk analysis to evaluate the
likelihood and impact of identified risks. It uses
a numerical scale to rate the likelihood and
impact of each risk, which can then be used to
prioritize risks and develop strategies to
mitigate or manage them.
• By ranking risk probability
against risk consequence, you
can see the main driver of risk
severity, whether that’s a
probability or a consequence.
This information helps identify
suitable treatments to manage
the risk, based on its prominent
drivers.
• The qualitative risk matrix in
belowfigure shows high-priority
risks in red and the lowest in
green.
following
key was
used for
1. Very low impact – not significant to
scoring.
project
Probability
Impact
2. Low impact – can be managed
without mitigation
[Link] impact – may require
1. Very low probability – not worth considering
2. Low probability – unlikely to occur
[Link] probability – realistic chance
mitigation
of occurrence
4. High probability – likely to occur 4. High impact – significant impact on
5. Very high probability – almost certain
to occur cost / schedule
5. Very high impact – can be a
“project killer”
• A bow-tie analysis is one of the most

2. Bow-tie Analysis
practical techniques for identifying risk
mitigations. Bow-tie analysis starts by
looking at a risk event and then projects it in
two directions. On the left, you list all the
potential causes of an event. On the right,
you list all the potential consequences of the
event.

• A 'bowtie' is a diagram that visualizes the


risk you are dealing with in just one, easy to
understand picture.
• A simple diagram is required to
communicate the range of causes and
consequences and the associated controls
Advantages
 The Bow-Tie Diagram is simple to read and
understand - it gives a clear understanding of the
threat controls and consequences that apply to a
system
 The technique is not overly complex and the
approach can be understood by non- specialists
 On the left hand side of the diagram the full range of
initiating events and intervening safeguards and the
way they combine and escalate are clearly shown
 On the right hand side of the diagram the many
possible consequences and outcomes are defined
and the barriers are shown in an equivalent manner
 The linkage of the barriers to the safety
management system can be made explicit
• Disadvantages
• Does not provide quantitative assessment or
evaluation of the acceptability of risks
unless linked to fault tree analysis or event
tree analysis
• In depth knowledge required/essential – high
level of knowledge regarding a system and
the components of the system that relate to
safety
• No standards exist therefore there is a range
of different and subtle representations of
bow-tie diagrams
• The technique does not provide a framework
to evaluate whether the selected safeguards
are sufficient
3. Delphi • The process of consulting field
Technique experts to predict how risky a
certain action would be.
Between a panel of experts and
several rounds of feedback and
response modification, a
conclusion is reached by the
panel.
• Steps to be followed :
1) Identify experts and
ensure their participation
2) Choose a facilitator
3) Define the problem
4) Send request and have the
experts evaluate
independently
5) Gather expert
opinions .Review and restate
the responses
Strengths :
• It involves input from technical experts and seeks to reach
the "correct" response through consensus.
• It can be done virtually. Absence of face-to-face meetings
eliminates biased viewpoints and preventing any undue
influence of one expert over another.
• Anonymity allows the experts to express their opinions
freely, encourages openness and avoids admitting errors
by revising earlier forecasts.
Weaknesses:
• Limited to technical risks.
• The process may be time consuming and is dependent on
the actual expertise of the experts. You may need to wait
long periods of time for experts to respond.
• It also greatly reduces immediate access to the
knowledge of others.
Critical success factors (CSFs)
for effective application :
• Effective facilitation is required.
• Careful selection of experts is
needed.
• Clear definition of scope
• It's a risk analysis method that focuses on

4. SWIFT Analysis identifying potential risks associated with


changes made to a project plan. As its name
suggests, team members have to come up
with any “what if” questions they can to find
out all the potential risks that could arise.

• The Structured What-If Technique (SWIFT)


combines the use of checklists with a
brainstorming ‘What if?’ approach.

• The Structured What-If Checklist is a thorough,


systematic, multi-disciplinary team orientated
analytical technique.
• The Structured What-If Technique is a
"brainstorming" method where "What-
If" questions are generated using a
variety of sources such as checklists,
past incidents, standards and
guidelines etc.
• SWIFT is generally applicable for
almost every type of risk assessment
application, especially those
dominated by relatively simple failure
scenarios. It can be used alone, but
most often used to supplement other,
more structured techniques.
Recomme
What If? Answer Likelihood Severity
ndations
What will
• What–If Analysis is a structured
What brainstorming method of
we do
about them
determining what What
things can
could go wrong
would and judging
How likely?
Consequen
Again –
the likelihood and consequences of those situations occurring.
go wrong? happen if it ces
prevent
did?
and
monitor
• The technique is efficient because it generally avoids
lengthy discussions of areas where hazards are well
Advantages
understood or where prior analysis has shown no
hazards are known to exist.
• It is very flexible, and applicable to any type of
installation, operation or process, at any stage of the
lifecycle.
• It is quick, because it avoids repetitive consideration of
deviations.
• It uses the experience of operating personnel as part of
the team.
• If the subject matter experts are not available for the
SWIFT session their questions can be gathered in
advance and included in the checklist.
• The checklists used are robust as the questions asked
intuitively cover historical incidents that have happened
in the past
• Adequate preparation of a checklist in advance is critical
to achieve completeness.
Disadvantages
• Its benefit depends on the experience of the leader and
the knowledge of the team.
• SWIFT relies exclusively on the knowledge of the
participants to identify potential problems. If the team
fails to ask important questions, the analysis is likely to
overlook potentially important weaknesses.
• Reviewing a what-if analysis to detect oversights is
difficult because there is no formal structure against
which to audit.
• Most what-if reviews produce only qualitative results;
they give no quantitative estimates of risk-related
characteristics. This simplistic approach offers great
value for minimal investment, but it can answer more
complicated risk-related questions only if some degree of
quantification is added (for example using Risk Matrices).
5. Pareto Principle
• The Pareto Principle states that 80 percent of a
project's benefit comes from 20 percent of the
work. Or, conversely, that 80 percent of
problems can be traced back to 20 percent of
causes. Pareto Analysis identifies the problem
areas or tasks that will have the biggest payoff.

• Better known as the "80/20 Rule", the Pareto


Principle helps in identifying risks that will be
most effective.

• Risk managers use Pareto analysis as a tool for


rapidly identifying the most critical 20% of
risks that will effectively mitigate 80% of the
impact.
• The key steps to conduct a
Pareto Analysis are:Identify the
problems
1. Identify root causes
2. Score the problems
3. Group problems
4. Tally the scores
5. Action
Advantages Of Pareto Analysis
1. Easy and Effective
2. Problem Analysis
3. Decision-Making Traits

Disadvantages Of Pareto
Analysis
1. Based on Past Data
2. Only Identifies Problems
3. Qualitative in Nature
4. Inaccuracy in Scoring-
Limitations of
Qualitative Project risk management is a multi-step
Risk Analysis process. This is because qualitative risk
analysis has its limitations. These include:
1. Subjective Evaluation
• A qualitative risk analysis produces no
metrics, it depends on the perception of a
person carrying out the study.
• In order to minimize subjectivity, a qualitative
risk analysis should involve several people.
• The accuracy and detail of the analysis
depends on previous team experience. If the
risk team hasn’t experienced a project type,
they might miss some risks or assess them
inadequately.
2. Limited Scope
• The qualitative risk analysis assesses each
risk on a project but doesn't provide an
assessment of the overall project risk
exposure. The analysis also won't
calculate how much risk management
activities and risk treatment will cost.
3. Lack of Differentiation
• Once several risks fall into the same
category, for example, high likelihood and
medium impact, there is no further way to
differentiate between the severity of risks
and no way to determine which risk should
be dealt with first.
What are the
benefits of Qualitative risk analysis can be used at any stage
qualitative risk of the project lifecycle. Some of its top benefits
analysis? include:
1. Provides a structured approach to risk
management: Qualitative risk assessment
breaks down the risk management process into
a series of well-defined steps. This helps ensure
all potential risks are identified and addressed
in a systematic manner.

2. Develops an effective risk management


plan: Qualitative risk analysis identifies all
potential project risks as well as their
corresponding mitigation measures. This helps
your project stay on track and within budget.
3. Facilitates effective decision-
making: Qualitative risk assessment
offers a clear understanding of potential
risks and their impact on your project. This
allows you to make informed decisions
about how to best mitigate or avoid the
risks
4. Improves the overall project
communication: Qualitative risk analysis
provides a common framework and
language for discussing risks. This ensures
all project stakeholders are on the same
page in terms of understanding potential
risks and their impact on the project.

You might also like