Showing posts with label quantitative risk analysis. Show all posts
Showing posts with label quantitative risk analysis. Show all posts

Wednesday, February 20, 2013

Introduction – Updates to Risk Register – After Quantitative Analysis


We have covered the Quantitative Risk Analysis topic in great detail in the previous section. As with any other activity in Risk Management, the output of this activity too would result in updates to the “Risk Register”.

To recap, the Risk Register is going to contain the most up-to-date information regarding all of the risks that have been identified for our Project. As we progress through each stage in Risk Management, we update the Risk Register so that it remains as the one comprehensive document that contains all the details we need in order to perform our Risk Management Activities.

So far, we have done the following – In Order:
1. Identified Risks
2. Updated the Risk Register with the preliminary risk information identified in step 1
3. Performed Qualitative Risk Analysis
4. Updated the Risk Register with the output of the analysis performed in step 3
5. Performed Quantitative Risk Analysis
6. WE ARE HERE NOW!!!

Common Sense would tell us that the next logic step here would be “Do Updates to the Risk Register with output of the Analysis performed in step 5” and this is exactly what we are going to do now.

Remember that, we did not perform quantitative analysis on all the risks we identified. Instead, we selected a sub-set of high priority (probability/impact) risks and have analyzed them further. So, as a result of this step, the updates to the risk register would affect only those risks that we selected…

Quantitative Risk Analysis typically results in the following updates to the Risk Register:



In the following chapters, we will be covering those updates one by one…

Prev: Section Summary - Quantitative Risk Analysis

Next: Probabilistic Analysis of the Project

Saturday, February 16, 2013

Sensitivity Analysis


In the previous chapters, we have learnt about the tools and techniques of Quantitative Risk Analysis that come under the Data Gathering and Representation Techniques sub-group. In this chapter, we are going to take a look at Sensitivity Analysis that falls under the Quantitative Risk Analysis & Modeling Techniques sub-group.

Purpose of Sensitivity Analysis:

The purpose of sensitivity analysis is to determine which risks have the highest potential impact on project objectives. Our goal is to single out those important risks so that we can respond in a more effective manner. During our analysis, we will find out things like: 

a. How imp certain elements are to the project? 
b. Which variables require special attention?
Etc... 

The Use of Sensitivity Analysis

Any analysis we take up should have some direct or indirect use, otherwise, what is the point of taking it up? Similarly, Sensitivity analysis can help us gather information to back up our recommendations. Sensitivity Analysis shows us a range of outcomes for a risk event. It also helps us identify those risks that can have the greatest effect on the project plan and the overall project objectives. 

Once we know which risk would impact us more, we can use the Sensitivity Analysis as the information backing up our recommendation to give additional consideration for that risk. 

How Sensitivity Analysis is performed:

We measure the effects of a project element on the project objective, when all the other elements are held at their baseline values. By modifying one element and keeping the others static, we are trying to determine the level of uncertainty each element could pose to our project objectives. 

Information required to perform Sensitivity Analysis: 

We will be using all the quantitative information gathered for the risks up until now, along with other information from the Project Management Plan. Remember that these risks are expected to have a significant impact on the project objectives like cost, time, quality etc. So, the corresponding plans from the Project Management Plan too may be consulted when the analysis is performed. 

Another point to note here is that, Sensitivity analysis can be done on a risk even if it does not fall under the Important or High Impact category. But, in real life, we may not have the time or the resources to take up such analysis on lower impact/priority risks. 

What happens after Sensitivity Analysis? 

We establish a range of variation for each of the risk event and also determine a level of acceptance. Our focus is on changing a single element only. This is also called “What-If Scenarios” wherein we understand what happens if a particular element that could impact the project objective is altered while all others remain stable. We typically play around with the variables and see what happens. Let me repeat, during normal sensitivity analysis, only one element/variable is changed at any given time. 

If you are thinking, why should I change only one variable, why can’t I change more than I at the same time, then fear not? Whatever you thought is perfectly valid and possible. If you do that, it’s perfectly fine but, it just won’t be called Sensitivity Analysis. It is called “Design of Experiments” 

Design of experiments is a statistical method to find the factors that may influence specific variables that may affect the specific outcomes of our project. We determine the combined effect of uncertainty as well as interaction between the various factors. 

Once all your analysis is complete, you need to represent your findings in some form so that the other people in your team as well as your management can understand it. Isn’t it? This final representation is called a “Tornado Diagram” 


Tornado Diagrams

Tornado Diagrams are a very common way of displaying results of sensitivity analysis. They compare the importance of variables that have a higher degree of uncertainty to the more stable variables. As you might remember from the previous paragraphs, during sensitivity analysis, one variables impact on the project objectives is understood while all other variables are set at the baseline. 

A sample tornado diagram:



As you can see, the greater the effect of a variable, the higher up it will feature on the diagram. This means that we should focus on the elements that are higher up in the image. 

When you say that a particular risk would have a higher impact on the project and back it up with the sensitivity analysis and tornado diagram, it would be easier for the people higher up the org hierarchy to understand your recommendation. 

Typically we use tornado diagrams to represent impact on cost, time or quality objectives. 

Prev: Discrete Distributions

Next: Expected Monetary Value Analysis

Sunday, February 10, 2013

Inputs Used In Quantitative Risk Analysis

In the previous chapter, we took a high level introductory look at Quantitative Risk Analysis. Next, we are going to look at the inputs that we will be using in this process.

The inputs that we will utilize for performing Quantitative Analysis are:

1. Risk Register
2. Risk Management Plan
3. Cost Management Plan
4. Schedule Management Plan &
5. Organizational Process Assets

Trivia:
If you are someone who is still using the 3rd edition of the PMBOK guide you will find some major differences between the guide and what you are seeing above. First off, the 3rd edition just lists the Project Management Plan as an input while the 4th edition (Which I am following & strongly urge you do too) splits them up and lists down the individual plans. In fact, the 3rd edition lists down the Risk Register & the Risk Management Plan as separate inputs while they too are part of the Project Management Plan.
Let us now take a detailed look at each of these items…

Risk Register

In one of our previous sections, we took a detailed look at the Risk Register. To refresh our memory, the Risk Register contains all the information about the risks we have identified so far. Almost all the information in the risk register will be useful for our analysis but, from a quantitative analysis perspective, we will focus especially on:
a. Risks set aside for Additional Analysis &
b. Risk Categories used

Trivia:
I have said this numerous times but let me repeat – Remembering how each item will be used for a certain activity/process will help you remember them because, if you know what it is used for and when it will be used, you can relate to it better. So, don’t just try to memorize the inputs, try to understand them.

Risk Management Plan

The Risk Management Plan, as we all know is the heart of all Risk Management activities in our project. During quantitative risk analysis, we will use the following elements of our Risk Management Plan:

a. Risk Management Methodology
b. Roles & Responsibilities
c. Budgets available
d. Timing Information
e. Risk Categories
f. Risk Breakdown Structure
g. Stakeholder Risk Tolerance
h. Reporting Formats

As you might remember from our earlier section that was dedicated to the Risk Management Plan, the plan actually contains a lot more information that what is listed above. If you can’t remember all of them, you can go back to that section to review them once again.

Trivia:
From a layman perspective, the Risk Management Plan is the background and the Risk Register is the front & center of our quantitative analysis.

Cost Management Plan

The Cost Management Plan provides the necessary information we need to establish the criteria for controlling the project costs. Before we can numerically analyze the risks, we need to analyze and identify the best approach possible. We can use the cost management plan to select the best structure and techniques that will suit our project, from the ones available. Without the Cost Baseline information (which is present inside the cost management plan) taking this decision could be very difficult.

We can also use the cost management plan to analyze the numeric impact of the risks that we have identified on our project’s costs.

Schedule Management Plan

The Schedule Management Plan provides the necessary information we need to develop and control the Project’s Schedule. It will help us develop controls on how we will approach or rather handle our Project’s schedule. Things like the overall schedule, network diagrams etc. will be required to understand the impact that the risks we have identified will have on our Project.

Trivia:
Think of a scenario where we have uncovered a potential positive risk that can help reduce the project schedule by 3 months and improve profits by 25%. Would you want to pass-up on an opportunity like that? I am sure your answer would be, No Way. I would want to capitalize on the opportunity. This is exactly where Quantitative Analysis comes into picture. If you have all your facts readily available about the threat or the opportunity, we can take better informed decisions.

Organizational Process Assets

Organizational Process Assets are used as input to almost every single activity that you may take up as part of Project Management or Risk Management. So, it is no wonder that you see it here as well. We will use the following items from the Organizational Process Assets during Quantitative Risk Analysis:

a. Information from previous similar projects, including actual outcomes and risk analysis performed
b. Techniques used, lessons learned etc.
c. Studies of similar projects conducted by Risk Specialists
d. Industry or Proprietary Risk Databases

Items c & d, may or may not be available for everyone but if your organization uses proper Project Management processes, items a & b should be readily available. Using these can help save time as well as improve the efficiency of our current activities.

Trivia:
Though not explicitly listed as an input to Quantitative Analysis, the Project Scope statement gives us the boundaries of what the project is supposed to accomplish. We need to keep this in perspective to ensure that we do not deviate from our boundaries while performing our Risk Management activities.

Prev: Introduction to Quantitative Risk Analysis

Next: Tools & Techniques in Quantitative Analysis

Sunday, January 20, 2013

Introduction to Quantitative Risk Analysis


We have successfully completed Qualitative Risk Analysis and updated the Risk Register. The next step would be Quantitative Risk Analysis. This section is dedicated to look in great detail about the Quantitative Risk Analysis process.

Quantitative Risk Analysis:

In the previous section on “Qualitative Risk Analysis” we prioritized risks and came up with a list of risks that are high priority and require additional analysis. Well, in Quantitative Risk Analysis, we are going to focus on those risks. The purpose of Quantitative analysis is to assign a numeric rating to the risk. This will help the risk management team to numerically analyze the risk which will aid them in the decision making process.

If you have already prepared for the PMP Exam or are PMP Certified, you must know by now that Quantitative analysis is the 4th process in the PMBOK Guides coverage of Risk Management. If you do not remember this, then I suggest you revisit the chapter titled Big Picture of Risk Management in our PMP Certification study series.

According to the PMBOK guide, we will analyze all those risks that potentially and substantially impact our project and our project objectives. Risks that have higher impact on our project with a higher probability of occurrence are those that we need to concentrate on.

While Qualitative Analysis is quick and cost effective, Quantitative analysis can be more time consuming and costly. Depending on the size of our project, the time and effort/cost we need to spend in this step (Quantitative Analysis) will vary. In some smaller projects, we may ignore this step altogether because it may not be prudent or feasible to spend that much time or resources in this activity. However, in most cases, a feasibility analysis or a cost benefit analysis is undertaken to decide whether to proceed with Quantitative analysis or not.

As you might have guessed by now, performing quantitative analysis can be very useful because it helps us make informed decisions in uncertain circumstances. So, if you have the time and resources to take up this step, it is advisable to perform Quantitative Risk Analysis.

Before we dig into the details of Quantitative Risk Analysis, let me repeat something that I have said multiple times. This step is not done only once after Qualitative Analysis. It is repetitive and may be required to be taken up after the “Develop Risk Responses” step or the “Monitor & Control Risks” step. At the end of day, we need to have as much information as possible about the risks that may impact our project and the only way to accomplish that is by thorough analysis.

Prev: Updates to Risk Register - After Qualitative Analysis

Next: Inputs Used in Quantitative Risk Analysis

Thursday, June 7, 2012

Risk Analysis

Risk Analysis is by far the most important domain of Project Risk Management. So, it is no big surprise that this domain will contribute 30% of questions in the RMP Examination. This is the largest of the domains in the Risk Management Framework in terms of contribution to the exam questions. To recap the exam objectives of Risk Analysis are:

a. Identify Risks
b. Evaluate Risks using Quantitative & Qualitative Risk Analysis
c. Prioritize Risks
d. Establish Control Limits

In order to plan effectively for the risks, we need to first analyze them properly. The Risk Analysis domain gives us all the inputs we need in order to plan the risk responses for the event that the risk occurs.

Logically thinking, it makes a lot of sense to spend our time and effort on risks that have the highest probability of occurring or on risks that have the highest potential impact on our project. Doesn’t it?

How will we identify which risk has a higher probability or a higher impact when compared to others? This is exactly what the Quantitative & Qualitative Analysis aspects of Risk Analysis will help us with. Before we begin our analysis, we need to identify all possible risks that may occur. By analyzing these risks and by understanding our stakeholder risk tolerance levels, we can shortlist and arrive at the important (or high priority) risks that we need to concentrate on…

You might be wondering what this “Establish Control Limits” objective is doing in the Risk Analysis domain. Are you? Setting these control limits is also part of the Risk Analysis Domain. We set these control limits by analyzing the risk tolerance levels of our stakeholders. The Project Management Team will use these limits to monitor the risks and to implement the planned responses. So, it makes perfect sense to include this objective as part of this domain…

In order to conduct an efficient Risk Analysis we need:
1. Good Information Gathering Techniques
2. Ability to Understand and Utilize Historic Information
3. Tools and Techniques to perform Qualitative Analysis
4. Tools and Techniques to perform Quantitative Analysis
5. Good Decision Making Capabilities
6. Ability to Perform Stakeholder Sensitivity Analysis

If all these things are not too clear and are making you nervous, don’t worry… This is just the initial introduction chapter. We will be covering the Risk Analysis Domain in great detail until you understand it clearly.

Prev: Risk Communication

Next: Risk Response Planning

Tuesday, December 13, 2011

Chapter 18: Risk Management


Aim: To understand the following Risk Management Processes
• Plan Risk Management
• Identify Risks
• Perform Qualitative Risk Analysis
• Perform Quantitative Risk Analysis
• Plan Risk Responses

If you have read the PMBOK or my earlier series “PMP Certification - Study Guide” you would by now know that

“A Risk is an Uncertain Event that can affect your Project”

Remember that this risk can be either Negative (An Actual Risk) or Positive (An Opportunity).

PMI’s risk management philosophy is based on a proactive approach to preventing negative risks and enhancing positive risks. Key points that you must remember about risk are:
• Risk can be either positive or negative. Positive risks are opportunities; negative risks are threats.
• A risk breakdown structure (RBS) is used to organize risk in a hierarchical structure.
• Monte Carlo analysis is a technique using simulations and probability in determining quantitative risk analysis.
• Risk categories are important in classifying risk.
• Probability and impact are both needed to assess risks.
• Quantitative analysis is generally reserved for high-probability, high-impact risk.
• Risk management planning and risk response planning are not the same activities.
• Risk identification is an iterative process that is performed throughout the project, not just during planning.
• Decision tree analysis is a technique using probabilities and costs for structured decision making.
• Five of the six risk management processes are conducted during the planning process group.
• The risk register is an important tool for capturing and tracking risks.

Exam Watch:
Risk register is a term introduced by PMI for the document detailing information on risks. The risk register includes all identified risks, the impacts of identified risks, proposed responses, responsible parties, and the current status.
Risk Management Planning and Risk Response Planning

The first step in Risk Management is to plan how we are going to conduct the whole Risk Management exercise in our project.
The risk management plan includes the risk methodology, roles/responsibilities, budget, execution timing, and definitions for risk categories, probabilities, and impacts. It is a summation of how the project team will carry out the remainder of the risk management activities for the project.

Exam Watch:
The risk management plan is not the same as the risk response plan. The Risk Response Plan will contain the possible actions you must take when a risk actually happens whereas the Risk Management Plan is the overall approach to managing Risks in the Project.

The risk management plan is the single output of the plan risk management process. The table below shows the inputs, tools and techniques, and outputs for the plan risk management process.

Plan Risk Management
Inputs Tools & Techniques Outputs

Project scope statement
Cost management plan
Schedule management plan
Communications management plan
Enterprise environmental factors
Organizational process assets

Planning meetings and analysis
Risk management plan
To know more about the Plan Risk Management Process Click Here

Risk Breakdown Structure (RBS)

A risk breakdown structure (RBS) is a tool that can be used to organize risks in a hierarchical fashion. The structure is defined using the risk categories. Even if an RBS is not used, risk categories are still defined in risk management planning. Risk categories can include
• Technical - Risk associated with using new technology.
• External - Risk associated with forces or entities outside the project organization. External risks can include external suppliers, customers, weather, and market conditions.
• Organizational - Risk associated with either the organization running the project or the organization where the project will be implemented.
• Project Management - Risk associated with project management processes.
Note that this is just a high level classification of Risks and you need to tweak this whole process to suit your needs in the Project that is being executed.

Risk Probability and Impact

Probability can be defined as the likelihood that a risk will occur. It can be expressed mathematically or as a relative scale (low, medium, high).

Impact is the effect a risk has if it actually occurs. It can also be defined on a relative scale or mathematically.

The team documents in the project management plan detail how probabilities and impacts are measured. For example, a red/yellow/green scale might be used, where high-probability, high-impact risks are red; low-probability, low-impact risks are green; and so on. Again, I repeat, how the risks are categorized and prioritized will vary based on the Project at hand and there is no Universal Rule as to how you must handle risks.

Exam Watch:
Both probability and impact are mandatory for evaluating risks. Think of it this way, how will you prioritize a risk if you do not know what the chances are of the risk happening and what the impact it would have if it occurs.

Risk Identification, Analysis, Response Planning, and Monitoring/Controlling

In the risk management process, completing the risk management plan is the first step. After the plan is in place, according to PMI the next steps in the risk management process are
• Risk Identification
• Risk Analysis (qualitative and quantitative)
• Risk Response planning
• Monitoring/controlling Risks (This is not in scope as part of this chapter on Planning. We will cover it in the chapter on Monitoring & Controlling)

Identify Risks

The identify risks process determines the risks that might affect the project and characterizes those risks.
Obviously, you need to identify all the possible risks that might affect your project if you are to have any success handling them. Isnt it? Keep in mind that identifying risks is not just the project manager’s responsibility; team members, subject matter experts, customers, stakeholders, and others are involved in this process.

The table below shows the inputs, tools and techniques, and outputs for the identify risks process.

Identify Risks
Inputs Tools & Techniques Outputs

Risk management plan
Activity cost estimates
Activity duration estimates
Scope baseline
Stakeholder register
Cost management plan
Schedule management plan
Quality management plan
Project documents
Enterprise environmental factors
Organizational process assets

Documentation reviews
Information gathering techniques
Checklist analysis
Assumptions analysis
Diagramming techniques
SWOT analysis (Strength, Weakness, Opportunity, Threat)
Expert judgment
Risk register
The Risk Register

The risk register is the output of the identify risks process. The risk register contains the following information:
• Risk description
• Date identified
• Category
• Potential responses
• Current status

Exam Watch:
Identify risks is not a one-time event that occurs just during the planning process. It should be conducted throughout the project, including when major milestones are reached and when an actual risk event occurs.
To know more about the Identify Risks Process Click Here

Qualitative and Quantitative Risk Analysis

Qualitative risk analysis provides further definition to the identified risks in order to determine appropriate responses to them. The key terms are probability and impact. Probability is important because it measures how likely a risk is to occur. A high-probability risk deserves more attention than a low-probability risk. Similarly, impact is a measure of how the risk will affect the project should it occur. A risk with low impact has a different response than one with a high impact.

Exam Watch:
Qualitative risk analysis is most concerned with ranking or prioritizing risks. It is used to determine which risks pose more of a potential effect on the project.

Qualitative risk analysis quickly prioritizes risks in order to conduct response planning and quantitative risk analysis, if required. Using the probability of the impact and a probability impact matrix, the project manager develops a prioritized list of risks. The output to this step is captured in the risk register.

The table below shows the inputs, tools and techniques, and outputs for the perform qualitative risk analysis process.

Perform Qualitative Risk Analysis
Inputs Tools & Techniques Outputs

Risk register
Risk management plan
Project scope statement
Organizational process assets

Risk probability and impact assessment
Probability and impact matrix
Risk data quality assessment
Risk categorization
Risk urgency assessment
Expert judgment
Risk register updates
To know more about Qualitative Risk Analysis Click Here

Quantitative risk analysis assigns numerical values to risks and looks at those risks that are high on the list of prioritized risks (The output of qualitative risk analysis). The goal of this process is to quantify possible outcomes for the project, determine probabilities of outcomes, further identify high impacting risks, and develop realistic scope, schedule, and cost targets based on risks.

The table below shows the inputs, tools and techniques, and outputs for the perform quantitative risk analysis process.

Perform Quantitative Risk Analysis
Inputs Tools & Techniques Outputs

Risk register
Risk management plan
Cost management plan
Schedule management plan
Organizational process assets

Data gathering and representation techniques
Quantitative risk analysis and modelling techniques
Expert judgment
Risk register updates
Exam Watch:
Quantitative risk analysis is more concerned with assigning each risk a numerical value. This value can then be used to figure out the relative impact that particular risk would have on the project.

To know more about Quantitative Risk Analysis Click Here

Planning Responses to Positive and Negative Risks

After all risks are identified, options to deal with the risks must be identified. Each risk is assigned to one or more owners to carry out the planned response. The responses are documented in the risk register after it has been updated in the plan risk responses process.

The table below shows the inputs, tools and techniques, and outputs for the plan risk responses process.

Plan Risk Responses
Inputs Tools & Techniques Outputs

Risk register
Risk management plan

Strategies for negative risks or threats
Strategies for positive risks or opportunities
Contingent response strategies plan
Expert judgment
Risk register updates
Risk-related contract decisions
Project management updates
Project document updates
There are four possible responses to negative risks:
• Avoid (Best) – Eliminating the Actual Threat by taking some action
• Transfer – Shifting the Risk to another party
• Mitigate – Take steps to ensure that the chances of the Risk happening are reduced
• Accept – Let the Risk happen. Use Contingency Reserves to handle it
For positive risks the responses include
• Exploit (Best) – Take steps to ensure that the Opportunity happens
• Share – Enlist the help of a Third party to capitalize on the opportunity
• Enhance – Taking steps to increase the probability of the Opportunity happening
• Accept – Take no steps to take advantage of the situation

To know more about the Plan Risk Responses process Click Here

Exam Watch:
Risks should be re-evaluated when the following events occur:
• A risk trigger is identified
• A change request is approved
• Key project milestones are reached
• Project phases end
• Deviations are detected in variance and trend analysis
• Corrective or preventive actions are implemented

Prev: Chapter 17

Next: Chapter 19

Thursday, June 30, 2011

Chapter 54: Performing Quantitative Analysis

Though we have done the Qualitative Analysis in the previous chapter, we are not complete. We still need to do Quantitative Analysis.

Quantitative risk analysis is generally performed on risks that have been prioritized by using the qualitative risk analysis. However, depending upon the experience of the team and their familiarity with the risk, it is possible to skip the qualitative risk analysis and, after the risk identification, move directly to the quantitative risk analysis. The quantitative risk analysis has three major goals:
• Assess the probabilities of achieving specific project objectives
• Quantify the effect of the risks on the overall project objectives
• Prioritize risks by their contributions to the overall project risk

The image below explains the process more clearly.


Input to Quantitative Analysis

All the items that are input for the qualitative risk analysis are also input for the quantitative risk analysis. In addition, the quantitative risk analysis generally requires more information than its qualitative counterpart. The list of inputs for this process are:
Risk register - The key input items from the risk register are the following:
o List of identified risks
o Priority list of risks if the qualitative risk analysis was performed
o Risks with categories assigned to them
o Management plans - To perform quantitative risk analysis, you must look at the risk management plan, cost management plan, and schedule management plan. To generate the output of the quantitative risk analysis, you need the following elements of the risk management plan:
 Budgeting
 Definitions of probabilities and impacts
 Probability and impact matrix
 Risk categories
 Risk timing and scheduling
To analyze the effect of risks on the project objectives, you need to know the project schedule and the project cost. These can be found in the cost management plan and schedule management plan. Also, the approaches taken by these plans can affect quantitative risk analysis.
Organizational process assets - The following organizational process assets might be useful in the quantitative analysis:
o Information on previously performed similar projects
o Studies performed by risk specialists on similar projects
o Proprietary risk databases or risk databases available from the industry

Tools and Techniques for Quantitative Analysis

The quantitative risk analysis can be looked upon as a two-step process; gathering and representing the data, and analyzing and modeling the data. Accordingly, all the techniques fall into two categories: data gathering and representation techniques, such as interviewing, probability distributions, and expert judgment; and analysis and modeling techniques, such as sensitivity analysis, EMV analysis, decision tree analysis, and modeling and simulation. We shall be covering them one by one in the list below:

Interviewing - This technique is used to collect the data for assessing the probabilities of achieving specific project objectives. You are looking for results such as: We have a 70% probability of finishing the project within the schedule desired by the customer. Or: We have a 60% probability of finishing the project within the budget of Rs. 100,000. The goal is to determine the scale of probabilities for a given objective; for example, there is a 20% probability that the project will cost Rs. 50,000, a 60% probability that it will cost Rs. 100,000, and a 20% probability that it will cost Rs. 150,000.

The data is collected by interviewing relevant stakeholders and subject matter experts. Most commonly, you will be exploring the optimistic (best case), pessimistic (worst case), and most likely scenarios for a given objective.

Probability distributions - After you have collected the data on meeting the project objectives, you can present it in a probability distribution for each objective under study. Note that a distribution represents uncertainty, and uncertainty represents risk. For example, if you know for sure the project will cost Rs. 25 lakhs, there will be no distribution because it is only one data point. Distribution comes into the picture when you have several possible values with a probability assigned to each value. There are distributions of different shapes in which the data can be presented.


Look at the picture above. This example is for the cost objective. The X axis represents the cost, and the Y axis represents the corresponding probability that the project will be completed within that cost.

The beta distribution and the triangular distribution are the most frequently used distributions. The other commonly used distributions that could be suitable under given circumstances are normal distribution and uniform distribution. The uniform distribution is used when all the values of an objective have the same chance of being true.

Sensitivity analysis - This is a technique used to determine which risk has the greatest impact on the project. You study the impact of one uncertain element on a project objective by keeping all other uncertain elements fixed at their baseline values. You can repeat this analysis for several objectives, one at a time. You can also repeat this study for several uncertain elements (creating risks), one element at a time. This way, you can see the impact of each element (or risk) on the overall project separate from other elements (or risks).

Expected monetary value analysis - The expected monetary value (EMV) analysis is used to calculate the expected value of an outcome when different possible scenarios exist for different values of the outcome with some probabilities assigned to them. The goal here is to calculate the expected final result of a probabilistic situation. EMV is calculated by multiplying the value of each possible outcome by the probability of its occurrence and adding the results. For example, if there is 60% probability that an opportunity will earn you Rs. 1,000 and a 40% probability that it will only earn you Rs. 500, the EMV is calculated as follows:

EMV = 0.60×1000 + 0.40×500 = 600 + 200= 800

So the EMV in this case is Rs. 800. When you are using opportunities and threats in the same calculation, you should express EMV for an opportunity as a positive value and EMV for a threat as a negative value. For example, if there is a 60% chance that you will benefit from a risk by Rs. 1,000 and a 40% probability that you will lose Rs. 500 as a result of this risk, the EMV is calculated as follows:

EMV = 0.60×1000 - 0.40×500 = 600 – 200 = 400

Therefore, the EMV in this case is Rs. 400.

The concept of EMV can be presented in a decision-making technique, such as a decision tree analysis.

Decision tree analysis - This technique uses the decision tree diagram to choose from different available options; each option is represented by a branch of the tree. This technique is used when there are multiple possible outcomes with different threats or opportunities with certain probabilities assigned to them. EMV analysis is done along each branch, which helps to make a decision about which option to choose.

Look at the image below. It is a simple decision tree.



The decision tree diagram above depicts two options: updating an existing product or building a new product from scratch. The initial cost for the update option is Rs. 500,000, whereas the initial cost for the build-from-scratch option is Rs. 700,000. However, the probability for failure is 25% for the update option, compared to 10% for the build-from-scratch option, and the impact from failure for case 1 is Rs. 1.25 lakhs whereas for the other it is only Rs. 70,000. In such a situation, the build from scratch may be chosen because, even though it costs more, the chances of failure as well as losses in case of a failure are lower than the update option.

Modeling and simulation - A model is a set of rules to describe how something works; it takes input and makes predictions as output. The rules might include formulas and functions based on facts, assumptions, or both. A simulation is any analytical method used to imitate a real-life system. Simulations in risk analysis are created using the Monte Carlo technique, which is named after the city of Monte Carlo; known for its casinos that present games of chance based on random behavior. Monte Carlo simulation models take random input iteratively to generate output for certain quantities as predictions. This technique is used in several disciplines, such as physics and biology, in addition to project management. In risk analysis, the input is taken randomly from a probability distribution, and the output for impact on the project objectives is predicted. The name “Monte Carlo” refers to the random behavior of the input.
Expert judgment - In quantitative risk analysis, expert judgment can be used to validate the collected risk data and the analysis used for the project at hand.

Output of the Quantitative Risk Analysis: Updated Risk Register

As with the Qualitative Analysis, the output of this process too is the updates to the Risk Register. The updates include:
Probabilistic analysis of the project - This includes the estimates of the project schedule and cost with a confidence level attached to each estimate. Confidence level is expressed in percentage form, such as 95%, and it represents how certain you are about the estimate. You can compare these estimates to the stakeholders’ risk tolerances to see whether the project is within the acceptable limits.
Probability of achieving the project objectives - Factoring in project risks, you can estimate the probability of meeting project objectives, such as cost and schedule, set forth by the current project plan. For example, the likelihood of completing the project within the current budget plan of Rs. 2 lakhs is 70%.
Prioritized list of risks - Risks are prioritized according to the threats they pose or the opportunities they offer. Risks with greater threats (or opportunities) are higher on the list. The goal is to prioritize the response plan efforts to eliminate (or minimize) the impact of the threats and capitalize on the opportunities. The priorities are determined based on the total effect of each risk to the overall project objectives.
Trends in the results - By repeating the analysis several times and examining the results, you might recognize a trend for specific risks. That trend might suggest further analysis or a specific risk response. In finding the trend, you can also take a look at the historical information on project cost, quality, schedule, and performance.

Prev: Performing Qualitative Analysis

Next: Planning Risk Response

Chapter 52: Analyzing Risks

In the previous chapter, we learnt how to identify risks. Identifying risks is a big task and if we screw up this step, the results can be disastrous. However, if we follow all the guidelines as explained in the PMBOK, we can be certain that our risk identification process was done efficiently. The next step for us is to analyze these risks. We are going to learn exactly that in this chapter.

So, lets get started!!!

Analyzing Risks

Once the risks have been identified, you need to answer two main questions for each identified risk:
1. What are the odds that the risk will occur,
2. If it does occur, what will its impact be on the project objectives?

You get the answers by performing risk analysis.

There are two main forms of Risk Analysis:
1. Qualitative Risk Analysis &
2. Quantitative Risk Analysis

Qualitative Risk Analysis

This is used to prioritize risks by estimating the probability of the occurrence of a risk and its impact on the project.

Quantitative Risk Analysis

This is used to perform numerical analysis to estimate the effect of each identified risk on the overall project objectives and deliverables.

Usually, you prioritize risks by performing qualitative analysis on them before you perform quantitative analysis. We will learn both one by one in the subsequent chapters.

Prev: Identifying Risks

Next: Performing Qualitative Analysis
© 2013 by www.getpmpcertified.blogspot.com. All rights reserved. No part of this blog or its contents may be reproduced or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, or otherwise, without prior written permission of the Author.

Followers

Popular Posts