You are on page 1of 1

Risk Management

Chapter Contents
1 Introduction | 2 Risk Classification | 3 Risk Identification | 4 Initial Risk Assessment | 5 Risk Mitigation and Residual Risk
Assessment | 6 Conduct Residual Risk Assessment | 7 Risk Monitoring and Governance (Phase G) | 8 Summary
This chapter describes risk management, which is a technique used to mitigate risk when implementing an architecture
project.

1. Introduction
There will always be risk with any architecture/business transformation effort. It is important to identify, classify, and
mitigate these risks before starting so that they can be tracked throughout the transformation effort.
Mitigation is an ongoing effort and often the risk triggers may be outside the scope of the transformation planners (e.g.,
merger, acquisition) so planners must monitor the transformation context constantly.
It is also important to note that the enterprise architect may identify the risks and mitigate certain ones, but it is within the
governance framework that risks have to be first accepted and then managed.
There are two levels of risk that should be considered, namely:
1. Initial Level of Risk: Risk categorization prior to determining and implementing mitigating actions.
2. Residual Level of Risk: Risk categorization after implementation of mitigating actions (if any).
The process for risk management is described in the following sections and consists of the following activities:

Risk classification

Risk identification

Initial risk assessment

Risk mitigation and residual risk assessment

You might also like