Showing posts with label risk register. Show all posts
Showing posts with label risk register. Show all posts

Monday, June 18, 2012

Section Summary – The Risk Register


In the previous two chapters, we took a detailed look at one of the key documents that is created/updated throughout project risk management “The Risk Register”. Let us now quickly summarize what we have learnt so far about the risk register.

• The risk register contains the list of all risks that have been identified as well as its details like description, owner, category, root cause, probability & impact etc
• The risk register is an input to 4 of the 6 risk management processes and an output of 5 of the 6 risk management processes, making it the document that is going to contain the most up-to-date information reg. all the project risks
• The risk register is created in the Identify Risks process and is updated in all the other processes
• The risk register contains the up-to-date status information of all the risks including who is responsible for it, the proposed response, the owner of the risk, the actual outcome etc
• Not all risks are analyzed in the quantitative risk analysis phase. Only those risks that are selected as “Requiring further analysis” in the qualitative analysis phase are analyzed in this phase
• A watch list has to be constantly monitored to ensure that those lower priority risks don’t become near-term threats
• Updating the actual outcomes (even if they are failures) can help us in the future. It can also help other project managers who may work on similar projects in our organization.

Prev: Contents of the Risk Register

Next: Intro to Identify Risks

Contents of the Risk Register


In the previous chapter we learnt that the risk register is going to be constantly updated as we progress through the various processes in the Risk Management knowledge area. From the RMP exam perspective we will be using a term called the “Risk Register Update Cycle” which refers to how the risk register is going to get updated right from the moment it gets created in the “Identify Risks” process to the last process in risk management “Monitor & Control Risks”

The Risk Register Update Cycle is illustrated in the picture below:



If you are preparing for the RMP Certification, it would be a good idea to print out this picture and keep it handy because this is going to give you a high level idea of the overall risk management activities in your project. More importantly, understanding this whole cycle is vital in understanding the subsequent chapters in our RMP preparation series.

Let us now take a detailed look at the various stages in this Risk Register Update Cycle.

1. Identify Risks

Identify Risks is the risk management process that actually creates the Risk Register. When we create the risk register, the following initial/basic information is available:
a. List of identified risks with their description, owner, consequences if the risks were to occur
b. Root causes of risks
c. Potential risk responses

A point to note here is that risk owners or root causes or potential responses may not be immediately available when the initial version of the risk register is created. But, at this stage we must make a dedicated attempt to furnish as much information as possible so that the subsequent processes can take things forward.

2. Perform Qualitative Risk Analysis

The Perform Qualitative Risk Analysis process takes the risk register created in the Identify Risks process and makes further updates to the same. The updates that happen to the risk register in this process include:

1. Ranking or a priority list of risks
2. Risks grouped by categories
3. Causes of risks
4. List of risks that require a near-term response
5. List of risks that require additional analysis & response
6. Watch list of low priority risks
7. Trends in qualitative risk analysis results

As you must remember from the previous section on the Risk Management Plan, we will use the Probability & Impact matrix to classify risks and to create a prioritized list of risks. The purpose of categorizing risks is to group related risks and to address them together. Usually this is done because this categorization can help us identify the root cause and addressing one root cause can help us eliminate multiple risks.

In this process, we identify those risks that are urgent (ones with high probability & impact) and try to take care of them immediately. There are also cases where we may need to perform further analysis before we decide on the further course of action on the risk. In those cases, we note them down and analyze them in the next process which is the Perform Quantitative Risk Analysis. During our analysis we may also find out certain risks that are either very low risk or impact or both. In such cases we usually move them to a watch list for the moment and continue with the other risks. We must constantly monitor those watch list items to ensure that their probability or impact hasn’t changed to ensure that we don’t get any unwanted surprises.

The trends identification part may have taken you by surprise. Identifying trends is not easy and requires a lot of experience. Do you remember that I said that Risk Management is an iterative process? We usually do multiple iterations of these processes and during such cases, if we watch closely we may be able to identify trends on those risks that may be due to a totally different or even a bigger problem.


3. Perform Quantitative Risk Analysis

After we complete qualitative analysis, we would’ve identified a subset of risks that need further analysis. We will be analyzing those risks quantitative in this process. During this phase, the following updates happen on the risk register:

1. Probabilistic Analysis of the Project
2. Probability of Achieving cost & time objectives
3. Prioritized list of quantified risks
4. Trends in quantitative risk analysis results

Conducting a probabilistic analysis of the whole project helps us avoid cost and schedule overruns. Here we will be trying to figure out the probability that we will complete the project in time or under budget. This will also give us a fair idea of how much reserves are required.

At the end of this process, we would have further prioritized the risks. The trends part here is similar to the trends we covered under the Qualitative analysis process.

4. Plan Risk Responses

After we have analyzed and prioritized all the risks, the next step is to figure out “What to do in case the risk occurs” and that is what we will be doing in this process. This is the process that makes the most number of updates to the risk register. Also, most of these updates are interrelated.

The updates that happen to the risk register in this process are:

1. Agreed upon response strategies
2. Risk Owner & Assigned Responsibilities
3. Specific actions to implement the chosen response strategy
4. Symptoms & warning signs of risk occurrence
5. Budget and schedule activities required to implement the chosen responses
6. Contingency reserves of time & cost designed to provide for stakeholder risk tolerances
7. Contingency plans and triggers that call for their execution
8. Fallback plans
9. Residual risks expected to remain
10. Secondary risks
11. Contingency reserves that are calculated based on quantitative analysis

By this point all risks must have an assigned owner who is in-charge of those risks. If some of the items in the list above seem new to you, don’t get overwhelmed. This is just the introductory phase of our preparation for the RMP Certification. There is still a long way to go and we will be covering all of these in great detail…

Usually our response strategies are based on our organizational policies as well as risk tolerances. Also, the organizational and stakeholder risk tolerance has a direct bearing on the contingency reserves. Usually if the stakeholder risk tolerance is how, the reserves will be low and vice versa. It is our responsibility to gauge the risk tolerance level and arrive at the appropriate contingency reserves.

Fallback plans are those “Plan B” kind of plans that we will implement in case the original response is not fully effective. Residual risks are those risks that remain even after our original responses are implemented. Secondary risks on the other hand are those risks that are caused because of the risk response plan we implemented. These risks must not be ignored and have to be dealt with accordingly.

5. Monitor & Control Risks

This is the last process in our risk management knowledge area. In this process the following updates happen to the risk register:

1. Outcomes of risk assessment, risk audits and periodic risk reviews
2. Closing risks that are no longer applicable
3. Actual outcomes of Project risks & risk responses
An important point to note here is that, risk reassessments and audits may unearth new risks as well. We need to ensure that those risks are handled appropriately as well. Also, documenting the actual outcomes can help us as well as other projects in future that may encounter similar scenarios as those that just failed for us. So, it is extremely vital that we document all those items accurately and truthfully.

Prev: Overview of Risk Register

Next: Section Summary - Risk Register

Overview of the Risk Register


The risk Register is one of the most important (if not the important) components of project risk management. It is also a key component of the Project Management Plan. The risk Register stores all the identified risks along with a lot of other information regarding those risks.

The details that you can expect to find in a Risk Register, about those risks are:
1. Risk Description
2. Risk Owner
3. Risk Category
4. Root Cause
5. Impact on the Project Objectives (If the risk event occurs)
6. Probability of the Risk Occurring
7. Proposed Responses
8. Current Status of the Risk

As you can see, it is the one stop shop for all your information needs with respect to the risks that might affect your project. Because of all the details it contains, it is an input and/or an output of almost all risk management processes.

Remember the chapter on Risk Management & the PMBOK guide? Of the 6 Risk Management processes outlined in that chapter, the Risk Register is an input to 4 of those processes and an output of 5 of those processes.

The Risk Register is an input to the following risk management processes:
1. Perform Qualitative Risk Analysis
2. Perform Quantitative Risk Analysis
3. Plan Risk Responses
4. Monitor & Control Risks
In short – It is an input to every single process that comes after risks are identified.

The Risk Register is an output of the following risk management processes:
1. Identify Risks
2. Perform Qualitative Risk Analysis
3. Perform Quantitative Risk Analysis
4. Plan Risk Responses
5. Monitor & Control Risks

In short – It is an output of every single process that comes after risk management is planned.

Trivia:
If you see that the Risk Register is an input to a process, it essentially means that it will be updated and be an output of the same process as well.

Because the risk register is part of almost all activities/processes in project risk management, if you properly understand the risk register, you will be able to easily understand the rest of the topics on risk management. So, it is very important that you understand the purpose of the risk register and how it used instead of just memorizing what you read here.

Prev: Section Summary - The RM Plan

Next: Contents of the Risk Register

Monday, June 11, 2012

Important Risk Related Definitions


In the previous chapter we learnt about the Project Environmental Factors that may affect our project. Before we go any further, let us stop for a moment and take a look at some of the important definitions that we will be using henceforth throughout this series on the Risk Management Professional certification exam prep.

We may have some of these definitions already in the previous chapters. But, they are still here for the sake of completeness so that we cover all these important terms in one place.

Risk – A Risk is an uncertain event or condition that, if it occurs, has a positive or negative effect on the projects objectives

Issue – An Issue is something that is occurring now in the present. You know about it and it is being dealt with. An Issue is a threat that has already materialized. They are kept track of using an Issue Log.

Risk Event – A Risk Event is the description of a scenario that may occur if the risk were to materialize

Risk Triggers – Risk Triggers are signs or indications that a risk event is about to occur or has already occurred. These are also known as Risk Symptoms or Warning Signs.

Risk Management Plan – The Risk Management Plan is the document that describes how the risk management processes will be carried out in our project. It describes how risk management will be planned; risks will be identified, analyzed & prioritized, responded, monitored and controlled.

Risk Register – The Risk Register is a document that contains all the identified risks, the results of risk analysis, the proposed risk responses and the current status of each of the identified risks

Risk Breakdown Structure – The Risk Breakdown Structure (Or RBS) is a hierarchical breakdown of risks organized by risk categories or impact

Probability – The term Probability refers to the chances that a risk may occur

Impact – The term Impact refers to the effect that a particular risk event will have on our project if it occurs

Prev: Project Environment

Next: Types of Risks

Friday, July 22, 2011

Points to Remember: Project Risk Management

A risk is any uncertain event or condition that might affect your project.

Not all risks are negative. Some events (like finding an easier way to do an activity) or conditions (like lower prices for certain materials) can help your project! When this happens, we call it an opportunity… but it’s still handled just like a risk.

Risk Breakdown Structure (RBS) is a great tool for managing your risk categories. It looks like a WBS, except instead of tasks it shows how the risks break down into categories.

It’s important to come up with probability and impact guidelines to help you figure out how big a risk’s impact is. The impact tells you how much damage the risk will cause to your project. A lot of projects classify impact on a scale from minimal to severe, or from very low to very high. The plan should also give you a scale to help figure out the probability of the risk. Some risks are very likely; others aren’t.

All four of the Risk Management processes are in the Planning process group—you need to plan for your project’s risks before you start executing the project.

The goal of all of the risk planning processes is to produce the risk register. That’s your main weapon against risk. It’s a list of all of the risks and some initial ideas about how you’d respond to them.

The risk register is built into the Risk Management Plan. Updates to the risk register are the only output of the Identify Risks process.

Perform Qualitative Risk Analysis helps you prioritize each risk and figure out its probability and impact. The only output of Perform Qualitative Risk Analysis is the updated risk register.

Sometimes you’ll find that some risks have obviously low probability and impact, so you won’t put them in the main section of your register. Instead, you can add them to a separate section called the watchlist, which is just a list of risks. It’ll include risks you don’t want to forget about, but which you don’t need to track as closely. You’ll check your watchlist from time to time to keep an eye on things.

The first step in risk management is Identify Risks, where you work with the whole team to figure out what risks could affect your project.

Qualitative and quantitative analysis are all about ranking risks based on their probability and impact.

Qualitative analysis is where you take the categories in your risk plan and assign them to each of the risks that you’ve identified.

Quantitative analysis focuses on gathering numbers to help evaluate risks and make the best decisions about how to handle them.

Decision Tree Analysis is one kind of Expected Monetary Value analysis. It focuses on adding up all of the costs of a decisions being made on a project so that you can see the overall value of risk responses.

To calculate EMV, be sure to treat all negative risks as negative numbers and all opportunities as positive ones. Then add up all of the numbers on your decision tree.

Don’t forget watchlists. They let you monitor lower-priority risks so that you can see if triggers for those risks occur and you need to treat them as higher priorities.

All of the processes in Risk Management are Planning or Monitoring & Controlling processes. There are no Executing processes here. Since the goal is to plan for risks, there is no need to focus on actually doing the work. By then, it’s too late to plan for risks.

Your risk register should include both threats and opportunities. Opportunities have positive impact values, while threats have negative ones. Don’t forget the plus or minus sign when you’re calculating EMV.

Plan Risk Responses is figuring out what you’ll do if risks happen.

Risk monitoring should be done at every status meeting.

The better you prepare for risks, the more secure your project is against the unknown.


Points to Remember - Other Topics:

Introduction to Projects & Project Management
Relationship Between Knowledge Areas & Process Groups
Project Integration Management
Project Scope Management
Project Time Management
Project Cost Management
Project Quality Management
Human Resource Management
Project Communication Management
Project Procurement Management
Ethics & Professional Responsibility
© 2013 by www.getpmpcertified.blogspot.com. All rights reserved. No part of this blog or its contents may be reproduced or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, or otherwise, without prior written permission of the Author.

Followers

Popular Posts