Showing posts with label planning risk response. Show all posts
Showing posts with label planning risk response. Show all posts

Friday, June 8, 2012

Risk Response Planning


The Risk Response Planning domain of the Risk Management Framework is the third largest domain in terms of the no. of questions it contributes to the RMP Certification Exam. As seen in the introductory chapter on the Risk Management Framework, the exam objectives of this domain are:

a. Develop a Risk Response Strategy
b. Develop a Contingency Approach & Plan
c. Present the Recommendations to Key Stakeholders

Let us say you are the project manager for a project and the warning signs have appeared that a risk is about to happen, what will you do? This is exactly what this domain is all about.

The exam objectives are only 3 in number and may be deceptive that this domain is easy. But as with the other domains, these 3 objectives cover a lot of ground. As you may have guessed by now (If you are a PMP or atleast have read the PMBOK guide) that much of this chapter is centered around the “Plan Risk Response” chapter of the PBMBOK Guide. In the series on PMP Exam Preparation, we had covered this topic in great detail. You can click here to access the chapter on Planning Risk Responses

In order to develop a good Risk Response Plan, you first need to understand the types of strategies you can use for Negative & Positive Risks. Do you know what these Negative & Positive Risks are and how to differentiate between the two? This is one of those basic pre-requisites you need to know before you can actually manage risks for any project. You also need to understand the concepts of Secondary and Residual risks.

Trivia:
A Negative Risk is one that affects a project in a negative way (Like causing delays, bugs, monetary losses etc).
A Positive Risk is one that affects a project in a positive way (Improving schedule, monetary benefits etc).


In order to efficiently execute this domain, a project manager needs to know about:
a. Contingency Plans
b. Contingency Reserves
c. Fallback Plans
d. Workarounds
e. Various Risk Response Techniques
f. Interpreting Risk Related Data

As with other domains, we will be taking a detailed look at all the exam objectives of this domain in future…

Prev: Risk Analysis

Next: Risk Governance

Tuesday, December 13, 2011

Chapter 18: Risk Management


Aim: To understand the following Risk Management Processes
• Plan Risk Management
• Identify Risks
• Perform Qualitative Risk Analysis
• Perform Quantitative Risk Analysis
• Plan Risk Responses

If you have read the PMBOK or my earlier series “PMP Certification - Study Guide” you would by now know that

“A Risk is an Uncertain Event that can affect your Project”

Remember that this risk can be either Negative (An Actual Risk) or Positive (An Opportunity).

PMI’s risk management philosophy is based on a proactive approach to preventing negative risks and enhancing positive risks. Key points that you must remember about risk are:
• Risk can be either positive or negative. Positive risks are opportunities; negative risks are threats.
• A risk breakdown structure (RBS) is used to organize risk in a hierarchical structure.
• Monte Carlo analysis is a technique using simulations and probability in determining quantitative risk analysis.
• Risk categories are important in classifying risk.
• Probability and impact are both needed to assess risks.
• Quantitative analysis is generally reserved for high-probability, high-impact risk.
• Risk management planning and risk response planning are not the same activities.
• Risk identification is an iterative process that is performed throughout the project, not just during planning.
• Decision tree analysis is a technique using probabilities and costs for structured decision making.
• Five of the six risk management processes are conducted during the planning process group.
• The risk register is an important tool for capturing and tracking risks.

Exam Watch:
Risk register is a term introduced by PMI for the document detailing information on risks. The risk register includes all identified risks, the impacts of identified risks, proposed responses, responsible parties, and the current status.
Risk Management Planning and Risk Response Planning

The first step in Risk Management is to plan how we are going to conduct the whole Risk Management exercise in our project.
The risk management plan includes the risk methodology, roles/responsibilities, budget, execution timing, and definitions for risk categories, probabilities, and impacts. It is a summation of how the project team will carry out the remainder of the risk management activities for the project.

Exam Watch:
The risk management plan is not the same as the risk response plan. The Risk Response Plan will contain the possible actions you must take when a risk actually happens whereas the Risk Management Plan is the overall approach to managing Risks in the Project.

The risk management plan is the single output of the plan risk management process. The table below shows the inputs, tools and techniques, and outputs for the plan risk management process.

Plan Risk Management
Inputs Tools & Techniques Outputs

Project scope statement
Cost management plan
Schedule management plan
Communications management plan
Enterprise environmental factors
Organizational process assets

Planning meetings and analysis
Risk management plan
To know more about the Plan Risk Management Process Click Here

Risk Breakdown Structure (RBS)

A risk breakdown structure (RBS) is a tool that can be used to organize risks in a hierarchical fashion. The structure is defined using the risk categories. Even if an RBS is not used, risk categories are still defined in risk management planning. Risk categories can include
• Technical - Risk associated with using new technology.
• External - Risk associated with forces or entities outside the project organization. External risks can include external suppliers, customers, weather, and market conditions.
• Organizational - Risk associated with either the organization running the project or the organization where the project will be implemented.
• Project Management - Risk associated with project management processes.
Note that this is just a high level classification of Risks and you need to tweak this whole process to suit your needs in the Project that is being executed.

Risk Probability and Impact

Probability can be defined as the likelihood that a risk will occur. It can be expressed mathematically or as a relative scale (low, medium, high).

Impact is the effect a risk has if it actually occurs. It can also be defined on a relative scale or mathematically.

The team documents in the project management plan detail how probabilities and impacts are measured. For example, a red/yellow/green scale might be used, where high-probability, high-impact risks are red; low-probability, low-impact risks are green; and so on. Again, I repeat, how the risks are categorized and prioritized will vary based on the Project at hand and there is no Universal Rule as to how you must handle risks.

Exam Watch:
Both probability and impact are mandatory for evaluating risks. Think of it this way, how will you prioritize a risk if you do not know what the chances are of the risk happening and what the impact it would have if it occurs.

Risk Identification, Analysis, Response Planning, and Monitoring/Controlling

In the risk management process, completing the risk management plan is the first step. After the plan is in place, according to PMI the next steps in the risk management process are
• Risk Identification
• Risk Analysis (qualitative and quantitative)
• Risk Response planning
• Monitoring/controlling Risks (This is not in scope as part of this chapter on Planning. We will cover it in the chapter on Monitoring & Controlling)

Identify Risks

The identify risks process determines the risks that might affect the project and characterizes those risks.
Obviously, you need to identify all the possible risks that might affect your project if you are to have any success handling them. Isnt it? Keep in mind that identifying risks is not just the project manager’s responsibility; team members, subject matter experts, customers, stakeholders, and others are involved in this process.

The table below shows the inputs, tools and techniques, and outputs for the identify risks process.

Identify Risks
Inputs Tools & Techniques Outputs

Risk management plan
Activity cost estimates
Activity duration estimates
Scope baseline
Stakeholder register
Cost management plan
Schedule management plan
Quality management plan
Project documents
Enterprise environmental factors
Organizational process assets

Documentation reviews
Information gathering techniques
Checklist analysis
Assumptions analysis
Diagramming techniques
SWOT analysis (Strength, Weakness, Opportunity, Threat)
Expert judgment
Risk register
The Risk Register

The risk register is the output of the identify risks process. The risk register contains the following information:
• Risk description
• Date identified
• Category
• Potential responses
• Current status

Exam Watch:
Identify risks is not a one-time event that occurs just during the planning process. It should be conducted throughout the project, including when major milestones are reached and when an actual risk event occurs.
To know more about the Identify Risks Process Click Here

Qualitative and Quantitative Risk Analysis

Qualitative risk analysis provides further definition to the identified risks in order to determine appropriate responses to them. The key terms are probability and impact. Probability is important because it measures how likely a risk is to occur. A high-probability risk deserves more attention than a low-probability risk. Similarly, impact is a measure of how the risk will affect the project should it occur. A risk with low impact has a different response than one with a high impact.

Exam Watch:
Qualitative risk analysis is most concerned with ranking or prioritizing risks. It is used to determine which risks pose more of a potential effect on the project.

Qualitative risk analysis quickly prioritizes risks in order to conduct response planning and quantitative risk analysis, if required. Using the probability of the impact and a probability impact matrix, the project manager develops a prioritized list of risks. The output to this step is captured in the risk register.

The table below shows the inputs, tools and techniques, and outputs for the perform qualitative risk analysis process.

Perform Qualitative Risk Analysis
Inputs Tools & Techniques Outputs

Risk register
Risk management plan
Project scope statement
Organizational process assets

Risk probability and impact assessment
Probability and impact matrix
Risk data quality assessment
Risk categorization
Risk urgency assessment
Expert judgment
Risk register updates
To know more about Qualitative Risk Analysis Click Here

Quantitative risk analysis assigns numerical values to risks and looks at those risks that are high on the list of prioritized risks (The output of qualitative risk analysis). The goal of this process is to quantify possible outcomes for the project, determine probabilities of outcomes, further identify high impacting risks, and develop realistic scope, schedule, and cost targets based on risks.

The table below shows the inputs, tools and techniques, and outputs for the perform quantitative risk analysis process.

Perform Quantitative Risk Analysis
Inputs Tools & Techniques Outputs

Risk register
Risk management plan
Cost management plan
Schedule management plan
Organizational process assets

Data gathering and representation techniques
Quantitative risk analysis and modelling techniques
Expert judgment
Risk register updates
Exam Watch:
Quantitative risk analysis is more concerned with assigning each risk a numerical value. This value can then be used to figure out the relative impact that particular risk would have on the project.

To know more about Quantitative Risk Analysis Click Here

Planning Responses to Positive and Negative Risks

After all risks are identified, options to deal with the risks must be identified. Each risk is assigned to one or more owners to carry out the planned response. The responses are documented in the risk register after it has been updated in the plan risk responses process.

The table below shows the inputs, tools and techniques, and outputs for the plan risk responses process.

Plan Risk Responses
Inputs Tools & Techniques Outputs

Risk register
Risk management plan

Strategies for negative risks or threats
Strategies for positive risks or opportunities
Contingent response strategies plan
Expert judgment
Risk register updates
Risk-related contract decisions
Project management updates
Project document updates
There are four possible responses to negative risks:
• Avoid (Best) – Eliminating the Actual Threat by taking some action
• Transfer – Shifting the Risk to another party
• Mitigate – Take steps to ensure that the chances of the Risk happening are reduced
• Accept – Let the Risk happen. Use Contingency Reserves to handle it
For positive risks the responses include
• Exploit (Best) – Take steps to ensure that the Opportunity happens
• Share – Enlist the help of a Third party to capitalize on the opportunity
• Enhance – Taking steps to increase the probability of the Opportunity happening
• Accept – Take no steps to take advantage of the situation

To know more about the Plan Risk Responses process Click Here

Exam Watch:
Risks should be re-evaluated when the following events occur:
• A risk trigger is identified
• A change request is approved
• Key project milestones are reached
• Project phases end
• Deviations are detected in variance and trend analysis
• Corrective or preventive actions are implemented

Prev: Chapter 17

Next: Chapter 19

Friday, July 1, 2011

Chapter 55: Planning Risk Response

In the previous chapters, we learnt how to identify the risks that might affect our project and how to analyze them. The next step is to plan a risk response. Simply put, how will you handle a risk once you identify it? That's what we are going to learn in this chapter.
So, lets get started!!!

Planning Risk Response

Depending on the project, the nature of risks, and the experience of the team, risk response planning can start after risk identification, qualitative risk analysis, or quantitative risk analysis. But if qualitative risk analysis and quantitative risk analysis are performed on the risk, then the response planning must come after completing these two analysis tasks. If you remember, risks can include threats (negative risks) and opportunities (positive risks).

Accordingly, the central task in risk response planning is to develop actions and options to meet the following two goals:
• Minimize threats to meeting project objectives
• Maximize opportunities

Risk Response is planned using the plan risk response process. It is explained in the picture below:


Input to Risk Response Planning

The two input items for risk response planning are the risk register and the risk management plan.

Risk register - The risk register contains the results from risk identification, qualitative risk analysis, and quantitative risk analysis. The following elements of the risk register are especially useful for risk response planning:
• List of identified risks
• Root causes of risks
• Prioritized list of risks
• List of risks that need immediate attention
• Trends in analysis results

Risk management plan - The elements of the risk management plan that can be useful for risk response planning include:
• Organizations’ and stakeholders’ thresholds for low, moderate, and high risks to sort out those risks for which response is needed.
• Roles and responsibilities that specify the positions and functions for each position involved in risk management. These roles are assigned to members of the risk management team, which might include members from inside or outside the project team.
• Timing and a schedule that specifies how often the risk management processes will be performed and which risk management activities will be included in the project schedule.
Because there is a wide spectrum of risks that can occur, there are a multitude of tools and techniques available to plan responses for these risks.

Tools and Techniques for Risk Response Planning

Risk, as you have already seen & learnt, can come in two categories: negative risks, which pose threats to meeting the project objectives, and positive risks, which offer opportunities. The goal here is to minimize the threats and maximize the opportunities.

In project management, there are three kinds of possible responses to risks:
1. Take an action or
2. Take no action or
3. Take a conditional action.

When you want to take an action, different response strategies for negative and positive risks need to be planned. Accordingly, there are three kinds of strategies available to handle three kinds of scenarios:
• Strategies to respond to negative risks (threats) when action is required
• Strategies to respond to positive risks (opportunities) when action is required
• Strategies that can be used to respond to both negative and positive risks when no action or a conditional action is taken

Response Strategies for Threats

There are only three ways to take an action against a potential problem & this is basically common sense:
1. Get out of harm’s way or
2. Pass it to someone else or
3. Confront it to minimize the damage.

In project management, these three strategies are called avoid, transfer, and mitigate; the ATM approach.

Avoid - You avoid risk by changing your project management plan in such a way that the risk is eliminated. Depending upon the situation, this can be accomplished in various ways, including:
• Obtaining information and clarifying requirements for risks based on misunderstanding or miscommunication. This answers two questions: Do we really have this risk, and, if yes, how can we avoid it?
• Acquiring expertise for risks that exist due to a lack of expertise.
• Isolating the project objectives from the risk whenever possible.
• Relaxing the objective that is under threat, such as extending the project schedule.

Transfer - Risk transfer means you shift the responsibility for responding to the risk (the ownership of the risk), the negative impact of the risk, or both to another party. Note that transferring the risk transfers the responsibility for risk management and does not necessarily eliminate the risk. Risk transfer almost always involves making payment of a risk premium to the party to which the risk has been transferred. Some examples include buying an insurance policy and contracting out the tasks involving risk.

Mitigate - Mitigation in general means taking action to reduce or prevent the impact of a disaster that is expected to occur. Risk mitigation means reducing the probability of risk occurrence, reducing the impact of the risk if it does occur, or both. A good mitigation strategy is to take action early on to first reduce the probability of the risk happening, and then to plan for reducing its impact if it does occur, rather than letting it occur and then trying to reduce the impact or repair the damage. Following are some examples of mitigation:
• Adopting less complex processes
• Conducting more tests on the product or service of the project
• Choosing a more stable supplier for the project supplies
• Designing redundancy into a system so that if one part fails, the redundant part takes over and the system keeps working

Each of these three strategies has a counter-strategy to deal with the opportunities.

Response Strategies for Opportunities

Just like in the case of threats, you have three strategies to deal with opportunities. Not surprisingly, each response strategy to deal with an opportunity is a counterpart of a response strategy to deal with a threat; a one-to-one correspondence:
• Share corresponds to transfer
• Exploit corresponds to avoid
• Enhance corresponds to mitigate

You use the SEE (Share, Exploit, Enhance) approach to deal with opportunities presented by the positive risks.

Note: As per the PMBOK Accept is also a strategy to handle Opportunities which means you just do nothing about the opportunity. If I were a PM and know that an opportunity is going to present itself, you should do something to take advantage of it. That is why we will concentrate on only Share, Exploit and Enhance.

Share - Sharing a positive risk that presents an opportunity means transferring ownership of the risk to another party that is better equipped to capitalize on the opportunity. Some examples of sharing are:
• Forming risk-sharing partnerships
• Starting a joint venture with the purpose of capitalizing on an opportunity
• Forming teams or special-purpose companies to exploit opportunities presented by positive risks

Exploit - Exploiting an opportunity means ensuring that the opportunity is realized; that is, the positive risk that presents the opportunity does occur. This is accomplished by eliminating or minimizing the uncertainty associated with the risk occurrence. An example of exploiting is assigning more talented resources to the project to reduce the completion time and therefore to be the first to market. Another example could be to provide better quality than planned to beat a competitor. Whereas exploiting refers to ensuring that the positive risk occurs.
Enhance - This strategy means increasing the size of the opportunity by increasing the probability, impact, or both. You can increase the probability by maximizing the key drivers of the positive risks or by strengthening the causes of the risks. Similarly, you can increase the impact by increasing the project’s susceptibility to the positive risk.

Trivia:
The responses for threats & opportunities are different only if you intend on taking an action to handle it. If you intend to take no action or a conditional action, then the response planning strategies for both negative and positive risks are the same.

Response Strategies for Both Threats and Opportunities

There are two response strategies that you need to plan for the risks for which you need to take either a conditional action or no action.

Acceptance - Acceptance of a risk means letting it be. Generally, it is not possible to take action against all risks. Depending upon their probabilities and impacts, some risks will simply be accepted. There are two kinds of acceptance:
• Passive acceptance that requires no action
• Active acceptance that requires a conditional action, called a contingent response

Contingency - Generally speaking, contingency means a future event or condition that is possible but cannot be predicted with certainty. So, your action will be contingent upon the condition; that is, it will be executed only if the condition happens. In risk management, a contingent response is a response that is executed only if certain predefined conditions (or events) happen. These events trigger the contingency response. Some examples of such triggers are missing a milestone or escalating the priority of a feature by the customer. The events that can trigger contingency response must be clearly defined and tracked.

Trivia: While designing a response to a risk, also design a backup plan to fall back on in case the response does not work. Also, think through and plan for responding to the risks that the response to the original (primary) risk may cause. These risks are called secondary risks.

Output of Risk Response Planning

The output of risk response planning includes:

Risk register updates - The appropriate risk responses planned and agreed upon by the risk management team are included in the risk register. The responses to high and moderate risks are entered in detail, while the low-priority risks can be put on a watch list for monitoring. After the risk register is updated, it includes the following main elements:
• A list of identified risks, descriptions of the risks, root causes of the risks, WBS elements affected by the risks and impacts of the risks on the project objectives.
• Roles and responsibilities in managing the risks; that is, risk owners and the responsibilities assigned to them.
• Results from qualitative and quantitative risk analysis, including a prioritized list of risks, a probabilistic analysis of the project objectives, and a list of risks with time urgency.
• Planned and agreed upon risk response strategies and specific actions to implement each strategy.
• Symptoms and warning signs of risk occurrences, contingency plans, and triggers for contingency risks.
• Budget and schedule requirements to implement the planned responses, including the contingency reserve, which is the amount of funds, time, or both needed in addition to the estimates in order to meet the organization’s and stakeholders? risk tolerances and thresholds.
• Fallback plans in case the planned responses prove to be inadequate
• A list of risks to remain, which include the following:
o Passive, accepted risks
o Residual risks that will remain after planned responses have been performed
• A list of secondary risks that will arise as a result of implementing the responses. You must plan for these risks like any other risk.

Updates to the project management plan - Risk response planning is a very involved and serious process. It may affect many components of the project management plan. You should go back and modify those components accordingly. For example, a risk response plan may require a change in the schedule, and therefore you will need to update the schedule management plan. Similarly, changes in budget and tolerance level as a result of planning a response would trigger updates to the cost management plan and quality management plan. Other plans that may be affected by risk response planning include the procurement management plan and the human resource management plan. These changes may also include or trigger changes in the cost baseline, the schedule baseline, and the WBS.

Trivia:
A residual risk is the remains of a risk on which a response has been performed, whereas a secondary risk is a risk that is expected to arise as a result of implementing a risk response; therefore, a response for a secondary risk must be planned.

Risk-related contract decisions - The decisions for risk-related contractual agreements might result, for example, from the decisions of transferring risks. Mitigating the risks may also have an option to contract it out, and hence a contract will be necessary. A positive risk can also be contracted out to maximize the opportunity it offers and share the resulting benefit with the vendor to which it is contracted out.

Updates to project documents - In addition to the risk register and project management plan, risk response planning may also cause updates to other project documents. For example, new information that becomes available during risk planning may change an assumption. This will require an update of the project scope statement (if it contains that assumption) or the assumption document, such as the assumption log, if you are keeping assumptions separate from the scope statement. You may also need to change some technical documents due to changes in the technical approach as a result of risk response plans.

Prev: Quantitative Analysis

Next: Big Picture of Quality & Risk Management
© 2013 by www.getpmpcertified.blogspot.com. All rights reserved. No part of this blog or its contents may be reproduced or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, or otherwise, without prior written permission of the Author.

Followers

Popular Posts