Showing posts with label risk management planning. Show all posts
Showing posts with label risk management planning. Show all posts

Tuesday, December 13, 2011

Chapter 18: Risk Management


Aim: To understand the following Risk Management Processes
• Plan Risk Management
• Identify Risks
• Perform Qualitative Risk Analysis
• Perform Quantitative Risk Analysis
• Plan Risk Responses

If you have read the PMBOK or my earlier series “PMP Certification - Study Guide” you would by now know that

“A Risk is an Uncertain Event that can affect your Project”

Remember that this risk can be either Negative (An Actual Risk) or Positive (An Opportunity).

PMI’s risk management philosophy is based on a proactive approach to preventing negative risks and enhancing positive risks. Key points that you must remember about risk are:
• Risk can be either positive or negative. Positive risks are opportunities; negative risks are threats.
• A risk breakdown structure (RBS) is used to organize risk in a hierarchical structure.
• Monte Carlo analysis is a technique using simulations and probability in determining quantitative risk analysis.
• Risk categories are important in classifying risk.
• Probability and impact are both needed to assess risks.
• Quantitative analysis is generally reserved for high-probability, high-impact risk.
• Risk management planning and risk response planning are not the same activities.
• Risk identification is an iterative process that is performed throughout the project, not just during planning.
• Decision tree analysis is a technique using probabilities and costs for structured decision making.
• Five of the six risk management processes are conducted during the planning process group.
• The risk register is an important tool for capturing and tracking risks.

Exam Watch:
Risk register is a term introduced by PMI for the document detailing information on risks. The risk register includes all identified risks, the impacts of identified risks, proposed responses, responsible parties, and the current status.
Risk Management Planning and Risk Response Planning

The first step in Risk Management is to plan how we are going to conduct the whole Risk Management exercise in our project.
The risk management plan includes the risk methodology, roles/responsibilities, budget, execution timing, and definitions for risk categories, probabilities, and impacts. It is a summation of how the project team will carry out the remainder of the risk management activities for the project.

Exam Watch:
The risk management plan is not the same as the risk response plan. The Risk Response Plan will contain the possible actions you must take when a risk actually happens whereas the Risk Management Plan is the overall approach to managing Risks in the Project.

The risk management plan is the single output of the plan risk management process. The table below shows the inputs, tools and techniques, and outputs for the plan risk management process.

Plan Risk Management
Inputs Tools & Techniques Outputs

Project scope statement
Cost management plan
Schedule management plan
Communications management plan
Enterprise environmental factors
Organizational process assets

Planning meetings and analysis
Risk management plan
To know more about the Plan Risk Management Process Click Here

Risk Breakdown Structure (RBS)

A risk breakdown structure (RBS) is a tool that can be used to organize risks in a hierarchical fashion. The structure is defined using the risk categories. Even if an RBS is not used, risk categories are still defined in risk management planning. Risk categories can include
• Technical - Risk associated with using new technology.
• External - Risk associated with forces or entities outside the project organization. External risks can include external suppliers, customers, weather, and market conditions.
• Organizational - Risk associated with either the organization running the project or the organization where the project will be implemented.
• Project Management - Risk associated with project management processes.
Note that this is just a high level classification of Risks and you need to tweak this whole process to suit your needs in the Project that is being executed.

Risk Probability and Impact

Probability can be defined as the likelihood that a risk will occur. It can be expressed mathematically or as a relative scale (low, medium, high).

Impact is the effect a risk has if it actually occurs. It can also be defined on a relative scale or mathematically.

The team documents in the project management plan detail how probabilities and impacts are measured. For example, a red/yellow/green scale might be used, where high-probability, high-impact risks are red; low-probability, low-impact risks are green; and so on. Again, I repeat, how the risks are categorized and prioritized will vary based on the Project at hand and there is no Universal Rule as to how you must handle risks.

Exam Watch:
Both probability and impact are mandatory for evaluating risks. Think of it this way, how will you prioritize a risk if you do not know what the chances are of the risk happening and what the impact it would have if it occurs.

Risk Identification, Analysis, Response Planning, and Monitoring/Controlling

In the risk management process, completing the risk management plan is the first step. After the plan is in place, according to PMI the next steps in the risk management process are
• Risk Identification
• Risk Analysis (qualitative and quantitative)
• Risk Response planning
• Monitoring/controlling Risks (This is not in scope as part of this chapter on Planning. We will cover it in the chapter on Monitoring & Controlling)

Identify Risks

The identify risks process determines the risks that might affect the project and characterizes those risks.
Obviously, you need to identify all the possible risks that might affect your project if you are to have any success handling them. Isnt it? Keep in mind that identifying risks is not just the project manager’s responsibility; team members, subject matter experts, customers, stakeholders, and others are involved in this process.

The table below shows the inputs, tools and techniques, and outputs for the identify risks process.

Identify Risks
Inputs Tools & Techniques Outputs

Risk management plan
Activity cost estimates
Activity duration estimates
Scope baseline
Stakeholder register
Cost management plan
Schedule management plan
Quality management plan
Project documents
Enterprise environmental factors
Organizational process assets

Documentation reviews
Information gathering techniques
Checklist analysis
Assumptions analysis
Diagramming techniques
SWOT analysis (Strength, Weakness, Opportunity, Threat)
Expert judgment
Risk register
The Risk Register

The risk register is the output of the identify risks process. The risk register contains the following information:
• Risk description
• Date identified
• Category
• Potential responses
• Current status

Exam Watch:
Identify risks is not a one-time event that occurs just during the planning process. It should be conducted throughout the project, including when major milestones are reached and when an actual risk event occurs.
To know more about the Identify Risks Process Click Here

Qualitative and Quantitative Risk Analysis

Qualitative risk analysis provides further definition to the identified risks in order to determine appropriate responses to them. The key terms are probability and impact. Probability is important because it measures how likely a risk is to occur. A high-probability risk deserves more attention than a low-probability risk. Similarly, impact is a measure of how the risk will affect the project should it occur. A risk with low impact has a different response than one with a high impact.

Exam Watch:
Qualitative risk analysis is most concerned with ranking or prioritizing risks. It is used to determine which risks pose more of a potential effect on the project.

Qualitative risk analysis quickly prioritizes risks in order to conduct response planning and quantitative risk analysis, if required. Using the probability of the impact and a probability impact matrix, the project manager develops a prioritized list of risks. The output to this step is captured in the risk register.

The table below shows the inputs, tools and techniques, and outputs for the perform qualitative risk analysis process.

Perform Qualitative Risk Analysis
Inputs Tools & Techniques Outputs

Risk register
Risk management plan
Project scope statement
Organizational process assets

Risk probability and impact assessment
Probability and impact matrix
Risk data quality assessment
Risk categorization
Risk urgency assessment
Expert judgment
Risk register updates
To know more about Qualitative Risk Analysis Click Here

Quantitative risk analysis assigns numerical values to risks and looks at those risks that are high on the list of prioritized risks (The output of qualitative risk analysis). The goal of this process is to quantify possible outcomes for the project, determine probabilities of outcomes, further identify high impacting risks, and develop realistic scope, schedule, and cost targets based on risks.

The table below shows the inputs, tools and techniques, and outputs for the perform quantitative risk analysis process.

Perform Quantitative Risk Analysis
Inputs Tools & Techniques Outputs

Risk register
Risk management plan
Cost management plan
Schedule management plan
Organizational process assets

Data gathering and representation techniques
Quantitative risk analysis and modelling techniques
Expert judgment
Risk register updates
Exam Watch:
Quantitative risk analysis is more concerned with assigning each risk a numerical value. This value can then be used to figure out the relative impact that particular risk would have on the project.

To know more about Quantitative Risk Analysis Click Here

Planning Responses to Positive and Negative Risks

After all risks are identified, options to deal with the risks must be identified. Each risk is assigned to one or more owners to carry out the planned response. The responses are documented in the risk register after it has been updated in the plan risk responses process.

The table below shows the inputs, tools and techniques, and outputs for the plan risk responses process.

Plan Risk Responses
Inputs Tools & Techniques Outputs

Risk register
Risk management plan

Strategies for negative risks or threats
Strategies for positive risks or opportunities
Contingent response strategies plan
Expert judgment
Risk register updates
Risk-related contract decisions
Project management updates
Project document updates
There are four possible responses to negative risks:
• Avoid (Best) – Eliminating the Actual Threat by taking some action
• Transfer – Shifting the Risk to another party
• Mitigate – Take steps to ensure that the chances of the Risk happening are reduced
• Accept – Let the Risk happen. Use Contingency Reserves to handle it
For positive risks the responses include
• Exploit (Best) – Take steps to ensure that the Opportunity happens
• Share – Enlist the help of a Third party to capitalize on the opportunity
• Enhance – Taking steps to increase the probability of the Opportunity happening
• Accept – Take no steps to take advantage of the situation

To know more about the Plan Risk Responses process Click Here

Exam Watch:
Risks should be re-evaluated when the following events occur:
• A risk trigger is identified
• A change request is approved
• Key project milestones are reached
• Project phases end
• Deviations are detected in variance and trend analysis
• Corrective or preventive actions are implemented

Prev: Chapter 17

Next: Chapter 19

Friday, July 22, 2011

Points to Remember: Project Risk Management

A risk is any uncertain event or condition that might affect your project.

Not all risks are negative. Some events (like finding an easier way to do an activity) or conditions (like lower prices for certain materials) can help your project! When this happens, we call it an opportunity… but it’s still handled just like a risk.

Risk Breakdown Structure (RBS) is a great tool for managing your risk categories. It looks like a WBS, except instead of tasks it shows how the risks break down into categories.

It’s important to come up with probability and impact guidelines to help you figure out how big a risk’s impact is. The impact tells you how much damage the risk will cause to your project. A lot of projects classify impact on a scale from minimal to severe, or from very low to very high. The plan should also give you a scale to help figure out the probability of the risk. Some risks are very likely; others aren’t.

All four of the Risk Management processes are in the Planning process group—you need to plan for your project’s risks before you start executing the project.

The goal of all of the risk planning processes is to produce the risk register. That’s your main weapon against risk. It’s a list of all of the risks and some initial ideas about how you’d respond to them.

The risk register is built into the Risk Management Plan. Updates to the risk register are the only output of the Identify Risks process.

Perform Qualitative Risk Analysis helps you prioritize each risk and figure out its probability and impact. The only output of Perform Qualitative Risk Analysis is the updated risk register.

Sometimes you’ll find that some risks have obviously low probability and impact, so you won’t put them in the main section of your register. Instead, you can add them to a separate section called the watchlist, which is just a list of risks. It’ll include risks you don’t want to forget about, but which you don’t need to track as closely. You’ll check your watchlist from time to time to keep an eye on things.

The first step in risk management is Identify Risks, where you work with the whole team to figure out what risks could affect your project.

Qualitative and quantitative analysis are all about ranking risks based on their probability and impact.

Qualitative analysis is where you take the categories in your risk plan and assign them to each of the risks that you’ve identified.

Quantitative analysis focuses on gathering numbers to help evaluate risks and make the best decisions about how to handle them.

Decision Tree Analysis is one kind of Expected Monetary Value analysis. It focuses on adding up all of the costs of a decisions being made on a project so that you can see the overall value of risk responses.

To calculate EMV, be sure to treat all negative risks as negative numbers and all opportunities as positive ones. Then add up all of the numbers on your decision tree.

Don’t forget watchlists. They let you monitor lower-priority risks so that you can see if triggers for those risks occur and you need to treat them as higher priorities.

All of the processes in Risk Management are Planning or Monitoring & Controlling processes. There are no Executing processes here. Since the goal is to plan for risks, there is no need to focus on actually doing the work. By then, it’s too late to plan for risks.

Your risk register should include both threats and opportunities. Opportunities have positive impact values, while threats have negative ones. Don’t forget the plus or minus sign when you’re calculating EMV.

Plan Risk Responses is figuring out what you’ll do if risks happen.

Risk monitoring should be done at every status meeting.

The better you prepare for risks, the more secure your project is against the unknown.


Points to Remember - Other Topics:

Introduction to Projects & Project Management
Relationship Between Knowledge Areas & Process Groups
Project Integration Management
Project Scope Management
Project Time Management
Project Cost Management
Project Quality Management
Human Resource Management
Project Communication Management
Project Procurement Management
Ethics & Professional Responsibility

Wednesday, June 29, 2011

Chapter 50: Planning Risk Management

In the previous chapter, we saw the big picture of risk management and the next step now is to plan for managing risks in our project.
So, lets get started!!!

Planning Risk Management

Risk management planning is the process used to decide how the risk management activities for the project at hand will be performed. The major goals for planning risk management are threefold: Ensure that the type, level, and visibility of risk management are proportionate to the actual risk involved in the project and the importance of the project to the organization; secure sufficient resources, including time for risk management activities; and set up an agreed-upon basis for evaluating risks.
To be more explicit, you use the risk management planning process to determine the following:
• How to approach the risk management activities for this project
• How to plan the risk management activities
• How to execute the risk management activities
The picture below explains the process used for Planning Risk Management:


Developing the Risk Management Plan

You perform risk management planning to develop a document called the risk management plan. As an input to this development process, you need to look at the project scope statement, which contains elements such as the following, which are relevant to risk management planning:
Assumptions and constraints - Assumptions should be evaluated for their uncertainty and thereby the possible risks. Constraints represent fixed parameters, such as available funds and deadlines that can also pose risks to the project.
Project objectives and requirements - You must address the risks that might prevent the team from meeting the project objectives and requirements.
Product description - There might be risks involved in performing the work for meeting the product description.
Initial risk identification - The project scope statement might contain some of the risks you initially identified. Now you have more information to build on that work.
The cost management plan may have information on risks related to budget, contingency, and management reserves. The schedule management plan may have information on how the schedule contingencies will be used and reported. The communication management plan should have information on who should receive reports about the different risks.

The enterprise environmental factors relevant to risk planning include the organizational attitude toward risks and the risk tolerance level of the organization. This information can be found from the policy statements of the organization and from actual experience with previous projects. The organizational process assets relevant to risk planning include organizational approaches toward risk management, definitions of concepts and terms used within the organization, standard risk templates you can use, a roles and responsibilities list, and authority levels for decision making.

You develop the risk management plan by holding planning meetings, which might include the following attendees:
• Project manager
• Selected members from the project team (Usually the team leads and other experienced members of the team)
• Selected stakeholders
• Any member from the performing organization who has responsibility for risk planning and executing

In these meetings, the input items are used to develop the risk management plan, the only output of the risk management planning process.

Risk Management Plan

The only output of the Plan Risk Management process is the risk management plan, which includes the following elements.

Methodology - This specifies the system of approaches, tools, and data sources that will be used to perform risk management on the project at hand. These tools and approaches might vary over projects, so you have to make the best selection for the given project.
Identifying and assigning resources - This identifies and assigns resources for risk management, such as human resources, cost, and time.
Roles and responsibilities - This specifies the roles and responsibilities for each role involved in risk management. These roles are assigned to members of the risk management team. The risk management team might include members from outside the project team.
Budgeting - The cost for risk management activities needs to be estimated and included in the budget and the project cost baseline.
Timing and scheduling - The plan specifies how often risk management processes will be performed and which risk management activities will be included in the project schedule, which is planned and developed by using processes discussed in the chapter on Planning for Project Schedule and Communication.

Risk categories - This element specifies how the risks will be categorized. The risk categories typically correspond to the sources of risks. Depending upon the size and complexity of the project, you might need to develop a risk breakdown structure (RBS), which is a hierarchical structure that breaks the identified risk categories into subcategories. In developing this structure, you will end up identifying various areas and causes of potential risks. The performing organization might already have prepared a categorization of typical risks. However, you need to examine this categorization for each project and tailor it according to the needs of the project at hand. The risk categorization helps you identify risks to the extent that you will be identifying various areas and causes of potential risks for your project.

Risk probability and impact - Defining different levels of risk probabilities and impacts is necessary to ensure the quality and credibility of the qualitative risk analysis that we will discuss in just a bit. The basic issues are defining the scale of likelihood that the risk will happen and defining the scale of the strength of its impact if the risk occurs. These definitions, even if they already exist in the organization, must be examined and tailored to the needs of the specific project.

You can define the risk probability scale from very unlikely to almost certainly, called the relative scale. As an alternative, you can define a numerical scale in which the probability is represented by numbers, in which a value close to 0.0 means very unlikely and a value close to 1.0 means almost certainly. The impact scale represents the size of the risk impact on the given project objective should the risk occur. Just like the probability scale, you can define the impact scale relatively or numerically. The relative scale can range from very low impact to very high impact, with points in the middle such as low, moderate, and high. As an alternative, you can define the impact numerically; it might be linear, such as the first point at 0.1, the second point at 0.2, and the tenth point at 1.0, or it might be nonlinear, such as the first point at 0.001, the second point at 0.01, and the third point at 0.1.

Look at the picture below for a simple example: It shows an example of linear and nonlinear impact scales, in which the impact scale for Objective 1 is nonlinear and the impact scale for Objective 2 is linear. You can think of the X axis as a variable on which the risk impact depends.


Risks are prioritized according to the size of their impact on the project objectives, which can be recorded in what is called an impact matrix or lookup table. Even if your organization already has a typical impact matrix, you should examine it and tailor it to the needs of the specific project at hand. I will discuss the probability and impact matrix in more detail later in this chapter.

To understand the risk impact better, lets look at a sample that defines the impact of risks on the various project objectives.

Project Objectives Very Low (0.05) Low (0.10) Moderate (0.35) High (0.65) Very High (0.90)
Time Insignificant time increase 1-10% time increase 10-30% time increase 30-60% time increase 60-100% time increase
Cost Less than 1% cost increase 1-20% cost increase 20-50% cost increase 50-80% cost increase 80-100% cost increase
Scope Scope decrease unnoticeable Scope of only a few minor areas affected Sponsor approval necessary for scope reduction Scope reduction unacceptable to the sponsor Project and item are effectively useless
Quality Unnoticeable quality reduction Only a few applications will be affected Quality requires sponsor approval Quality reduction unacceptable Project and item are effectively useless
A point to note is that, this example shows only the negative impact.

Risk reporting and tracking - This element describes the format of risk reports, such as the risk register, a document that contains the results of risk analysis and risk response planning. Furthermore, it describes how different aspects of risk activities will be recorded so that the risks can be monitored for the current project. Also, should the performing organization decide to audit the risk management process, one should be able to track these activities. Another reason for recording these activities could be to save the information for the benefit of future projects in the form of lessons learned.

During the process of planning risk management for a specific project, you revisit the tolerance levels of the stakeholders for certain risks, and these levels may be revised. Risk management planning is the process that generates the risk management plan document, which contains the information that will be used in risk identification, risk analysis, and risk response planning.
You cannot manage a risk if it’s not identified. Dont worry, thats going to be the next chapter.


Prev: Big Picture of Risk Management

Next: Identifying Risks
© 2013 by www.getpmpcertified.blogspot.com. All rights reserved. No part of this blog or its contents may be reproduced or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, or otherwise, without prior written permission of the Author.

Followers

Popular Posts