Showing posts with label secondary risk. Show all posts
Showing posts with label secondary risk. Show all posts

Friday, March 22, 2013

Updates to the Risk Register – After Risk Response Planning


In the previous chapter we took a high level look at the possible updates that could be created by the Risk Response Planning process to the various project documents. In this chapter we are going to take a detailed look at all the updates that happen to the Risk Register.

The following are the updates that happen in the Risk Register:

1. Agreed Upon Risk Strategies

These are the strategies that will be utilized to handle the risks that are outlined in the Risk Register. Strategies for both negative and positive risks are available here. Remember the strategies – Avoid, Mitigate, Exploit etc.?

Remember that the strategy we choose will depend on the stakeholder and project risk tolerance and threshold.

2. Risk Owners and Responsibilities

Every Risk must have an owner and this information is captured in the Risk Register. Note that here; we are not assigning owners for the activities that are taken up to handle the risks. Instead, we are talking about the person who is in-charge of the risk as a whole.

Trivia:
A large project could have hundreds of risks and assigning the same individual to track all of them may result in gaps that may hurt the project. So, it is a good idea to assign a manageable number of risks to each individual.

3. Risk Symptoms and Warning Signs

These symptoms and warning signs are also known as “Triggers”. It would be a good idea to document them so that we know when we need to respond to any risk. It also will help the team in responding to a risk if it materializes. Risk owners must stay on top of the triggers for their respective risks…

Trivia:
Without knowing the risk trigger, how will you or anyone respond to a risk???


4. Budget and Schedule Requirements

To handle a risk, some actions may be required from people in our team. So, that would involve spending time and money. The cost and time required to implement the risk responses must be outlined in the risk register.

5. Contingency Plans and Triggers

As explained in the chapter on Contingency Reserves, we accept a certain number of risks. Along with this, we also need to take into account all of the Residual Risks as well as those in the Watchlist. So, listing out those risks, their contingency plans as well as triggers that will cause us to use the contingency plan must be clearly specified in the risk register.

6. Time and Cost Contingency

By this stage in Risk Analysis & Planning, we must have a clear idea of how much reserves we need – in terms of time and cost to handle those risks that were accepted or residual risks or those from the Watchlist. During the Monitor & Control risks phase, we will keep a close lookout for risks during our project activities to ensure that we have enough reserves to handle the risks appropriately

7. Fall-back Plans

You might remember that a fall-back plan is the “Plan B” we are planning on executing if our original (Plan A) fails. So, noting this too in the risk register will be useful in future in the unfortunate event of our original plan failing.

8. Residual Risks

When we plan the responses for our risks, we will get a clear idea of any risks that may remain even after we implement our responses. These must be noted down clearly in the risk register so that we can utilize the contingency reserves to handle them appropriately in case they materialize in future.

9. Secondary Risks

Secondary Risks are those risks that are created as a direct consequence of us implementing our planned risk responses. If such a risk is caused by our response, we must make sure that they are also captured accurately in the Risk Register.

Remember that the Risk Register is the most up to date information of all risks that were/are/will be handled by the project. Any risk related activity either uses this document or results in updates to this document. So, keeping it accurate is vital for successful risk management in our project.


Prev: Introduction - Outputs of the Plan Risk Responses Process

Next: Updates to the Project Management Plan

Wednesday, March 20, 2013

Important Terms - Plan Risk Responses


The Plan Risk Responses process was fairly complicated and is extremely vital in successful risk management in our Project. So, before we move on to the next topic and start looking at the outputs of the process, let us quickly cover the important terms we learnt in this section. 

The purpose of this chapter is to prevent or rather avoid any confusion or misunderstanding to anyone who is reading this series because some of these terms may be quite confusing. 

Risk Triggers: 

• Are warning signs or symptoms
• Provide a warning that  a risk is about to occur
• Provides a heads-up to the risk management team to handle the risk
• Tells the team when to execute the risk response or contingency plan

Residual Risk

• Those risks that are expected to remain after the planned responses have been executed
• May include risks that have been accepted

Trivia: 
Even when a risk is accepted or placed in a watchlist, we must never forget them. They can be considered residual risks and must be handled as and when required.


Secondary Risks

• Those risks that emerge as a direct result of implementing a planned risk response
• It is not the same as a new risk that may be uncovered during the project’s life 

Fallback Plan

• Is planned in advance 
• Is used/implemented when the original planned risk response proves ineffective
• Is typically the “Plan B” in common lingo
• Is created typically for very high priority/impact risks to minimize impact in case the original plan fails
• Is created also for cases where we are not too confident about the response that has been formulated or about the impact of a risk 

Prev: Reserve Management

Next: Introduction - Outputs of the Plan Risk Responses Process

Friday, July 22, 2011

Points to Remember: Project Risk Management

A risk is any uncertain event or condition that might affect your project.

Not all risks are negative. Some events (like finding an easier way to do an activity) or conditions (like lower prices for certain materials) can help your project! When this happens, we call it an opportunity… but it’s still handled just like a risk.

Risk Breakdown Structure (RBS) is a great tool for managing your risk categories. It looks like a WBS, except instead of tasks it shows how the risks break down into categories.

It’s important to come up with probability and impact guidelines to help you figure out how big a risk’s impact is. The impact tells you how much damage the risk will cause to your project. A lot of projects classify impact on a scale from minimal to severe, or from very low to very high. The plan should also give you a scale to help figure out the probability of the risk. Some risks are very likely; others aren’t.

All four of the Risk Management processes are in the Planning process group—you need to plan for your project’s risks before you start executing the project.

The goal of all of the risk planning processes is to produce the risk register. That’s your main weapon against risk. It’s a list of all of the risks and some initial ideas about how you’d respond to them.

The risk register is built into the Risk Management Plan. Updates to the risk register are the only output of the Identify Risks process.

Perform Qualitative Risk Analysis helps you prioritize each risk and figure out its probability and impact. The only output of Perform Qualitative Risk Analysis is the updated risk register.

Sometimes you’ll find that some risks have obviously low probability and impact, so you won’t put them in the main section of your register. Instead, you can add them to a separate section called the watchlist, which is just a list of risks. It’ll include risks you don’t want to forget about, but which you don’t need to track as closely. You’ll check your watchlist from time to time to keep an eye on things.

The first step in risk management is Identify Risks, where you work with the whole team to figure out what risks could affect your project.

Qualitative and quantitative analysis are all about ranking risks based on their probability and impact.

Qualitative analysis is where you take the categories in your risk plan and assign them to each of the risks that you’ve identified.

Quantitative analysis focuses on gathering numbers to help evaluate risks and make the best decisions about how to handle them.

Decision Tree Analysis is one kind of Expected Monetary Value analysis. It focuses on adding up all of the costs of a decisions being made on a project so that you can see the overall value of risk responses.

To calculate EMV, be sure to treat all negative risks as negative numbers and all opportunities as positive ones. Then add up all of the numbers on your decision tree.

Don’t forget watchlists. They let you monitor lower-priority risks so that you can see if triggers for those risks occur and you need to treat them as higher priorities.

All of the processes in Risk Management are Planning or Monitoring & Controlling processes. There are no Executing processes here. Since the goal is to plan for risks, there is no need to focus on actually doing the work. By then, it’s too late to plan for risks.

Your risk register should include both threats and opportunities. Opportunities have positive impact values, while threats have negative ones. Don’t forget the plus or minus sign when you’re calculating EMV.

Plan Risk Responses is figuring out what you’ll do if risks happen.

Risk monitoring should be done at every status meeting.

The better you prepare for risks, the more secure your project is against the unknown.


Points to Remember - Other Topics:

Introduction to Projects & Project Management
Relationship Between Knowledge Areas & Process Groups
Project Integration Management
Project Scope Management
Project Time Management
Project Cost Management
Project Quality Management
Human Resource Management
Project Communication Management
Project Procurement Management
Ethics & Professional Responsibility
© 2013 by www.getpmpcertified.blogspot.com. All rights reserved. No part of this blog or its contents may be reproduced or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, or otherwise, without prior written permission of the Author.

Followers

Popular Posts