You are on page 1of 48

Project Risk Management

“uncertainty that matters”


(Dr. David Hillson, 2003, 2009)
Project Risk Management
 Conducting risk management planning, identification, analysis, response planning, response
implementation, and monitoring risk on a project.
 Individual project risk: is an uncertain event or condition that, if it occurs, has a positive or
negative impact on one or more parts of the project
 Overall project risk: The risk exposure of the project as a whole. It’s made up of the sum of
individual project risks plus other sources of uncertainty.
 Risk is negative or positive. Negative risk are threats and positive risks are opportunities.
 Increase the probability and/or impact of positive risks and to decrease the probability and/or
impact of negative risks
 Risk appetite
 Amount of risk you are willing to take for a reward

 Risk tolerance
 Amount of volume of risk you are willing to take
Risk
 Known-Knowns, Known-unknowns, unknown-unknowns
 Event Risk
 Future possible events – Most identified risk

 Non-Event Risks
 Variability Risk
Some aspect of a planned task or situation is uncertain. E.g.: Productivity targets, error during testing,
weather patterns.
 Ambiguity Risk
 Uncertainties arising from lack of knowledge or understanding. E.g.: Use of new technology, future
regulations.
 Project Resilience
 Ability to handle risk that was not known. Ability to handle unknowable-unknowns.

 Integrated risk management


 Manage risk at the appropriate level.
Risk Management Processes
Process Name Process Group Key Outputs

Plan Risk Management Planning Risk Management Plan

Identify Risks Planning Risk Register

Perform Qualitative Risk Analysis Planning Project Document Updates

Perform Quantitative Risk Analysis Planning Project Document Updates

Project Document Updates, Project Management Plan


Plan Risks Response Planning
Update
Implement Risk Responses Executing Change Requests

Monitor Risks Monitoring And Controlling Work Performance Information, Change Requests
Plan Risk Management
 Defining how to conduct risk management activities for a project
 Planning how to identity, assess, response, implement responses
and monitor risk
 Risk Management is a proactive approach and should be done
early in the project
Plan Risk Management - ITTO

INPUTS
TOOLS AND TECHNIQUES OUTPUTS
Project Charter
Project Management Plan 1.Expert Judgments Risk Management Plan
All Components 2.Data Analysis
Project Documents 1.Stakeholder Analysis
Stakeholder Register 3.Meetings
Enterprise Environmental Factors
Organizational Process Assets
Plan Risk Management - Inputs
 Project Charter
 Project Management Plan
 All Components
 Project Documents
 Stakeholder Register
 Enterprise Environmental Factors
 Organizational Process Assets
Plan Risk Management - Tools
 Expert Judgment
 Data Analysis
Stakeholder analysis
 Meetings
Plan Risk Management - Outputs
 Risk Management Plan, (Roadmap to the other 6 risk processes)
 Used to determine
 How risks will be categorized/identified
 How quantitative/ qualitative analysis will be completed

 How risk response planning will happen

 How will the risk response be implemented

 How risks will be monitored

 How ongoing risk management activities will happen throughout the project life cycle

 Roles and responsibilities for the project team

 Stakeholders risk appetite, helps to determine what is acceptable risk vs. non
acceptable
 Risk Breakdown structure(RBS) is used to categories risks.
Sample Risk Breakdown Structure

Regulation

External

Vendors

Risk

People

Organizational

Funding
Identify Risks
 Identifying individual project risks as well as sources of overall
project risk, and documenting them in the risk register and risk
report
 All personnel should be encouraged to identify risks.
 Should be done throughout the project. Risk changes daily.
 Identify both positive and negative risk
Identify Risks
INPUTS
1.Project Management Plan
Requirements Management Plan
Schedule Management Plan
Cost Management Plan
TOOLS AND TECHNIQUES
Quality Management Plan
Resource Management Plan Expert Judgment
Risk Management Plan Data Gathering
Scope Baseline a.Brainstorming
OUTPUTS
Schedule Baseline b.Checklists
c.Interviews Risk Register
Cost Baseline
Data Analysis Risk Report
Project Documents
Assumption Log a.Root Cause Analysis Project Documents Updates
Cost Estimates b.Assumption and Constraint Analysis a.Assumption Log
Duration Estimates c.SWOT Analysis b.Issue Log
Issue Log d.Document Analysis c.Lessons Learned Register
Lessons Learned Register Interpersonal and Team Skills
Requirements Documentation a.Facilitation
Resource Requirements Prompt Lists
Stakeholder Register Meetings
Agreements
Procurement Documentation
Enterprise Environmental Factors
Organizational Process Assets
Identify Risks - Inputs
 Project Management Plan
 Requirements Management Plan
 Schedule Management Plan
 Cost Management Plan
 Quality Management Plan
 Resource Management Plan
 Risk Management Plan
 Scope Baseline
 Schedule Baseline
 Cost Baseline
 Project Documents
 Assumption Log
 Cost Estimates
 Duration Estimates
 Issue Log
 Lessons Learned Register
 Requirements Documentation
 Resource Requirements
 Stakeholder Register
Identify Risks - Inputs
 Agreements
 Procurement Documentation
 Enterprise Environmental Factors
 Organizational Process Assets
Identify Risks - Tools
 Expert Judgement
 Data Gathering
 Brainstorming
 Checklists
 Interviews
 Interpersonal and Team Skills
 Facilitation
 Prompt Lists
 A predetermined list of risk categories. RBS can be used to used to
identity both individual and overall risk
 Meetings
Identify Risks - Tools
 Data Analysis
 Documentation Analysis
 Structure review of all project documentation
 Assumptions and constraints analysis
 Root Cause Analysis
 SWOT Analysis

Strengths Weaknesses
-Little free time
- Expert team
-High cost
-Management support
SWOT

Opportunities Threats
-New Market - Regulations
-New IT Systems -Staff Shortage
Identify Risks
 Risk Register - (Individual Project Risks)
 List of all Identified Risks
 List of Potential Responses
 Provides a list of all identified risks on the project, what reactions
to this risk are, what the root causes are, and what categories the
risks fall into.
Risk ID Risk Response Cause Project Area

S1 Bad weather Add 3 more days to Environment Time


schedule
C1 Cost overrun Add 10% more to budget Supplier might increase Cost
cost

 Risk Report
Sources of overall project risk and summary information on
identified individual risk.
 Project Document Updates
Perform Qualitative Risk Analysis
 Prioritizing individual project risks by assessing their probability of
occurrence and impact as well as other characteristics.
 Done in order to determine which risks are the highest priority on
the project.
 Creates a ranking
 Preformed throughout the project
Perform Qualitative Risk Analysis - ITTO

TOOLS AND TECHNIQUES


Expert Judgment
Data Gathering
Interview
INPUTS Data Analysis
OUTPUTS
Project Management Plan Risk Data Quality Assessment
Risk Management Plan Risk Probability and Impact 1.Project Documents Updates
Project Documents Assessment a.Assumption Log
Assumption Log Assessment of Other Risk b.Issue Log
Risk Register Parameters c.Risk Register
Stakeholder Register Interpersonal and Team Skills d.Risk Report
Enterprise Environmental Factors Facilitation
Organizational Process Assets Risk Categorization
Data Representation
Probability and Impact Matrix
Hierarchical Charts
Meetings
Perform Qualitative Risk Analysis - Inputs
 Project Management Plan
 Risk Management Plan
 Project Documents
 Stakeholder Register
 Assumption Log
 Risk Register
 Enterprise Environmental Factors
 Organizational Process Assets
Perform Qualitative Risk Analysis - Tools
 Expert Judgement
 Data Gathering
 Interviews
 Interpersonal and Team Skills
 Facilitation
 Meetings
Perform Qualitative Risk Analysis - Tools
 Data Analysis
 Risk Probability and Impact Assessment
 The likelihood that each specific risk will occur, level of probability
 Investigate the potential effect on the project, Cost, Schedule, Quality, Performance,
Positive or Negative
 Risk Data Quality Assessment
 The degree of which the risk is understood and the accuracy, quality, reliability and the
integrity of the data
 Assessment of other risk parameters
 Other parameters such as urgency, proximity, manageability, and detectability.
 Risk Categorization
 Sources of Risk
 Grouped by root cause
Perform Qualitative Risk Analysis - Tools
 Data Representation
Risk Probability Impact Score Ranking
 Probability and Impact Matrix
Bad 4 5 20 High
 Outlines the probability and impact on the project Contractor
 Sorted by High Risk, Medium Risk, Low Risk Bad 3 3 9 Medium
Weather
 Hierarchical Char
Earthquake 1 5 5 Low
 Bubble Chart
Probability = 1-5 Impact = 1-5

Probability and Impact Matrix

Risk bubble chart


Perform Qualitative Risk Analysis - Outputs
 Project Documents Updates
 Risk Register
 Risk Report
 Issue Log
 Assumption log
Perform Quantitative Risk Analysis
 Numerically analyzing the effect of individual project risks on the
overall project objectives.
 Assigns a value to the risk that have been ranked by qualitative risk
analysis.
 Usually requires specific risk software and knowledge in the
development and interpretation of risk models.
Perform Quantitative Risk Analysis - ITTO
INPUTS
Project Management Plan
Risk Management Plan
Scope Baseline TOOLS AND TECHNIQUES
Schedule Baseline
Expert Judgment
Cost Baseline
Data Gathering OUTPUTS
Project Documents
Interviews Project Documents Updates
Assumption Log
Interpersonal and Team Skills Risk Report
Basis of Estimates
Facilitation
Cost Estimates
Representations of Uncertainty
Cost Forecasts
Data Analysis
Duration Estimates
Simulations
Milestone List
Sensitivity Analysis
Resource Requirements
Decision Tree Analysis
Risk Register
Influence Diagram
Risk Report
Schedule Forecasts
Enterprise Environmental Factors
Organizational Process Assets
Perform Quantitative Risk Analysis - Inputs
 Project Management Plan
 Risk Management Plan
 Scope Baseline
 Schedule Baseline
 Cost Baseline
 Project Documents
 Assumption Log
 Basis of Estimates
 Cost Estimates
 Cost Forecasts
 Duration Estimates
 Milestone List
 Resource Requirements
 Risk Register
 Risk Report
 Schedule Forecasts
 Enterprise Environmental Factors
 Organizational Process Assets
Perform Quantitative Risk Analysis – Tools
 Expert Judgement
 Data Gathering
 Interviewing
 Interpersonal and Team Skills
 Facilitation
 Representation of Uncertainty
 Probability distribution, looking at the probability of risks actually taking
place
 Triangular or beta distributions
Perform Quantitative Risk Analysis – Tools
 Data Analysis
 Sensitivity Analysis
 Tornado Chart
Perform Quantitative Risk Analysis – Tools
 Data Analysis
 Influence diagrams
 Graphical aids to decision making under uncertainty
 Sensitivity Analysis
 Decision Tree Analysis
 Make or buy analysis

Initial Risk Cost Probability EMV Total


Cost
New 1,000,000 400,000 25% 100,000 1,100,000
Constructed
House
Remodel older 800,000 500,000 10% 50,000 850,000
house
To calculate the EMV you would take the probability multiply the risk
costs. To get the total, add the EMV to the initial cost.
Perform Quantitative Risk Analysis – Output
 Project Documents Updates
 Risk register
Plan Risk Responses
 Developing options, selecting strategies, and agreeing on ways to
address risk on the project
 Will allocate resources needed to response to risk if they happen
 Will address all risk
Plan Risk Responses - ITTO

OUTPUTS
Change Requests
INPUTS Project Management Plan Updates
TOOLS AND TECHNIQUES
Schedule Management Plan
Project Management Plan Expert Judgment
Cost Management Plan
Resource Management Plan Data Gathering
Quality Management Plan
Risk Management Plan Interviews
Resource Management Plan
Cost Baseline Interpersonal and Team Skills
Procurement Management Plan
Project Documents Facilitation
Scope Baseline
Lessons Learned Register Strategies for Threats
Schedule Baseline
Project Schedule Strategies for Opportunities
Cost Baseline
Project Team Assignments Contingent Response Strategies
Project Documents Updates
Resource Calendars Strategies for Overall Project Risk
Assumption Log
Risk Register Data Analysis
Cost Forecasts
Risk Report Alternatives Analysis
Lessons Learned Register
Stakeholder Register Cost-Benefit Analysis
Project Schedule
Enterprise Environmental Factors Decision Making
Project Team Assignments
Organizational Process Assets Multicriteria Decision Analysis
Risk Register
Risk Report
Plan Risk Responses - Inputs
 Project Management Plan
 Risk Management Plan
 Resource Management Plan
 Project Documents
 Lessons Learned Register
 Risk Report
 Project Schedule

 Stakeholder Register

 Enterprise Environmental Factors


 Organizational Process Assets
Plan Risk Responses - Tools
 Expert Judgement
 Data Gathering
 Interviews
 Interpersonal and Team Skills
 Facilitation
 Strategies for Negative Risk or threats
 Escalate-Outside the Project Team Level
 Avoid-eliminate the risk entirely
 Transfer-transfer ownership to a 3rd party
 Mitigate- reduce the probability of the risk event
 Accept- Deal with the Risk at hand
Plan Risk Responses - Tools
 Strategies for Opportunities (Positive Risk)
 Escalate-Outside the Project Team Level
 Exploit-Remove any and all uncertainty
 Share-Some or all ownership to a 3rd party
 Enhance-Increase the probability of the event happening
 Accept -Take advantage of the opportunity, but not seek it
 Strategies for Overall Project Risk
 Avoid
 Exploit
 Transfer/Share
 Mitigate/Enhance
 Accept
Plan Risk Responses - Tools
 Contingent Response Strategies
 May undertake certain risk events, if certain conditions apply
 Data Analysis
 Cost-benefit analysis
 Decision Making
 Multicriteria decision analysis
Plan Risk Responses - Outputs
 Change Requests
 Project Management Plan Updates
 Schedule Management Plan
 Cost Management Plan
 Quality Management Plan
 Resource Management Plan
 Procurement Management Plan
 Scope Baseline
 Schedule Baseline
 Cost Baseline
 Project Documents Updates
 Assumption Log
 Cost Forecasts
 Lessons Learned Register
 Project Schedule
 Project Team Assignments
 Risk Register
 Risk Report
Implement Risk Responses
 Executes risk response plans when risk has taken place
 Minimizes the project threats and maximizes the project
opportunities
Implement Risk Responses - ITTO

Inputs OUTPUTS
TOOLS AND TECHNIQUES
1.Project Management Plan 1.Change Requests
Expert Judgment
1.Risk management plan 2.Project Documents Updates
Interpersonal and Team Skills
2.Project Documents Issue Log
Influencing
1.Lesson learned register Lessons Learned Register
Project Management Information
2.Risk register System Project Team Assignments
3.Risk report Risk Register
3.Organizational process assets Risk Report
Implement Risk Responses - Inputs
 Project Management Plan
 Risk Management Plan
 Project Documents
 Lessons Learned Register
 Risk Report
 Risk Register

 Organizational Process Assets


Implement Risk Responses - Tools
 Expert Judgement
 Interpersonal and Team Skills
 Influencing
 Project Management Information System (PMIS)
Implement Risk Responses - Output
 Change Requests
 Project Documents Updates
 Issue Log
 Lessons Learned Register
 Project Team Assignments
 Risk Register
 Risk Report
Monitor Risks
 Monitoring the implementation risk response plans
 Tracking identified risks to see if they change
 Identifying and analyzing new risks
 Evaluating risk process effectiveness throughout the project.
 24/7/365
Monitor Risks - ITTO

OUTPUTS
INPUTS
1.Work Performance Information
1.Project Management Plan TOOLS AND TECHNIQUES
2.Change Requests
a.Risk Management Plan 1.Data Analysis 3.Project Management Plan Updates
2.Project Documents a.Technical Performance Analysis a.Any Component
a.Issue Log b.Reserve Analysis 4.Project Documents Updates
b.Lessons Learned Register 2.Audits a.Assumption Log
c.Risk Register 3.Meetings b.Issue Log
d.Risk Report
c.Lessons Learned Register
3.Work Performance Data
d.Risk Register
4.Work Performance Reports
e.Risk Report
5.Organizational Process Assets Updates
Monitor Risks - Inputs
 Project Management Plan
 Risk Management Plan
 Project Documents
 Lessons Learned Register
 Risk Report
 Project Schedule
 Stakeholder Register
 Work Performance Data
 Performance Reports
Monitor Risks - Tools
 Data Analysis
 Reserve Analysis
 Compares the amount of contingency to the reminding amount of risk left on the
project
 Technical Performance analysis
 Audits
 Risk audits are done to determine the effectiveness of the risk
management processes.
 Meetings
Monitor Risks - Output
 Work Performance Information
 Change Requests
 Project Management Plan Updates
 Any component
 Project Documents Updates
 Assumption Log
 Lessons Learned Register
 Risk Register
 Issue Log
 Risk Report
 Organizational Process Assets Updates

You might also like