Task: Complete a risk management plan and analysis/evaluation for a project. For Instance, that project can be a project of the members of the risk register/presentation group. Length and Presentation: You are to submit a report (up to 2000 words). T
PROJMGNT 5004 Risk Assessment and Management
Trimester 3 ,2021
Session 1, Day 1 (Day 1 & 2)
- Dr Krishnan Mysore Ph.D.
School of Business 1Dr Krishnan Mysore 2021 – All Slides
Ice Breaker
Let's get Introduced & Know each other...
2 This Photo by Unknown Author is licensed under CC BY-SA
School of Business
House Keeping, Time Management & Etiquettes
• Escape routes • Toilets • Start time • Short Breaks • Lunch • End time • Good Hygiene • Social Distancing • Kind & Considerate
3
Course Introduction
• Course Outline/Components
• Course Coordinator/Lecturer
• Course Calendar
• Blended Course
Assessments & Marking
5
# Assessment Task Task Type Length Weighting Learning Outcomes
1 Risk Register (20%) and presentation, 10-15 slides (10%)
Group 3,000 words
30% 1-4
2 Risk Management Plan
Individual 2,000 words
30% 1-4
3 Systemic Risk Individual 2,500 words
30% 4-6
4 Class Participation Individual N/A 10% 1-6
Total 100%
Note: Please Refer Assessment Details/Rubrics from MyUni
Resources
• MyUni: ü Course related resources
ü Session based presentations ü Case studies & Research Papers (for group discussions) ü Assignment specific readings ü Additional materials, Student Academic/ Support resources
• Suggested Textbook: But not required textbooks: ü Marchetti, A.M. (2012), Enterprise Risk Management, Best Practices,
Wiley.
ü Bowden, A., Lane, M., and Martin, J., (2001), Triple Bottom Line Risk Management, Wiley. (purchase not compulsory)
• Suggested Journals: ü International Journal of Project Management
ü International Journal of Managing Projects in Business;
ü International Journal of Project Management & Organisational
ü Project Management Journal
ü International Journal of Risk Assessment and Management. 6
Learning Objectives
Systemic Risk Complex Systems
Enterprise & Strategic Risk Project Risk (Operational Risks)
Work, Health and Safety Risk (Operational Risks)
7
Learning Objectives Schedule
Systemic Risk, Day 3 and 4 Enterprise Risk, Day 3 and 4
Complex Systems, Day 3 and 4 Project Risk, Day 1 and 2
Health and Safety Risk, Day 3 and 4
8
Now let's get the focus on Project Risks...
9
Project Risks: Why is it important?
Q. Why do we need to account for Risks as part of any project?
Q. What is a project?
10
Project Risks: Why is it important?
Class Exercise: (Individual)
Let's say each of you are planning for a domestic (personal) project of hosting a party at Home, Well...there can be two or three risks which might make you cancel or definitely make you cancel your party plan...if you list and rate them ...what are those top 1, 2 or even 3 risks?
Q. Why do we need to account for Risks as part of any project?
11
Why is it important?
Why do we need to manage project risk?
12
Why is it important? – Historical Perspective • The term risicum was used as far
back in the middle ages to describe legal issues of consequential losses during sea trade • From 1960’s, associated with oil
tanker disasters • From 1980’s, associated with
financial derivatives • From 1990’s, associated with the
power of personal computing • Now a part of any project
management contract and is used is used across industries
Oil Tanker Disaster
Financial Derivative
Sea Trade
Personal Computing
Other Industries 13
Assessment & Managing Project Risks - Why is it important?– Project Management Perspective
• As Project Managers, one need to • Meet the requirements of the CONTRACT • Meet project milestones on time, on budget and to
agreed quality • Address Stakeholder needs • Meet shareholder return, contributing to the going
concern
• By ensuring project risks under control, PMs will be able to • Manage project successfully • Save Money for the Business or concerned stakeholders • Keep Internal/External Stakeholders J • Keep their job • Progress in their career
This Photo by Unknown Author is licensed under CC BY-NC
This Photo by Unknown Author is licensed under CC BY
14
Why is it important? - Learning Perspective
Purpose of Risk Management is to learn and improve the success of project management by holding contingency
Be aware or know your risk appetite! (Risk Averse, Risk Neutral or Risk Seekers)
We learn to cope with risk on a daily basis: driving a car, playing a sport, investing money, owning property, maintaining relationship or wake up in the morning...
Risk is part of everybody’s life: As we learn or be aware, we are all risk “experts”!
15
Project Risk at the operational level
16
Learning Objectives
Aware of the fundamentals of risk
Able to work in a group to create a project risk management plan/register based on the ISO 31000:2009
Able to identify the core types of project risks
Able to use qualitative and quantitative risk assessment methods
Aware of risk simulation techniques and other risk analysis tools/ methods
Aware of a range of risk management issues and challenges
17
Project Risk - Definitions
Risk is an uncertain event or condition, that if it occurs, has a positive or negative effect on a project's objective (PmBoK Definition)
The probability of something happening multiplied by the resulting cost or benefit if it does. The probability or threat of quantifiable damage, injury, liability, loss, or any other negative occurrence that is caused by external or internal vulnerabilities, and that may be avoided through pre-emptive action.
A Potential Problem, Situation or Perhaps an Opportunity that will have a measured impact on a nominated outcome
Risk is the effect of uncertainty on objectives (ISO 31000 definition)
Risk is any Uncertainty that matters! 18
Project Risk Characteristics
Uncertain and significant
Threat to project success (or an objective) or Opportunity to project success (or an objective)
Usually adverse, however risk analysis can be used to measure and investigate future threats/opportunities
Risk is very much in the eye of the beholder: what is a risk to one may not be a risk to other, hence the power of the Corum/group can be engaged/utilised
19
Project Risk Perceptions
Can you imagine a world or project without risk?
Should we try to eliminate all risk in Projects?
All Risks are Uncertain... but do All Risks (Uncertain events) Matter!
Risk management is about effectively balancing risks and rewards
What's your Project Risk Appetite! ... Project Risk Tolerance!...
No Project Objectives/Expectations – No Project Risks!
20
Project Risk Calculations Risk = Probability x Consequence
“A chance or possibility of danger, loss, injury, or other adverse consequences”
Two components (dimensions): probability or likelihood of occurrence of event and the consequence or impact of the event
21
Project Risk Probability/Consequence – Assessment of Low Risk or High Risk
Risk of Death from an Accident
Risk of Project Cancellation
Low probability, but severe
consequences
Risk of losing money
Risk of Misunderstanding in Project Scope
High probability but moderate or
small consequences
22
Project Risk
Key role of objectives
Certainty (Awareness) of Project Risks
Project Milestones
Business Targets/Sales Forecast
Content Internal Stakeholders of Project/Program
Content External Stakeholders/Shareholder Return
Corporate Image/Corporate Social Responsibility
23
Project Risk & Objectives
Objectives in general that can be strategic, tactical and operational
If there are no objectives of an endeavour/strategy/project, there will be unlikely to be any threat, hence minimal or no risk
"If you don't care where you end-up, any road will do" J
24
Project Risk Elements of decisions
Every decision has actions. These are the possible choices
Outcomes are the consequences
Decisions made under uncertainty (or with risk) involve events that bring up outcomes
Decision trees can aid with modelling and show the outcome of various paths or choices
25
Project Risk Decision tree
26
Project Risk Decision tree
27
Project Risk Decision tree
28
Project Risk Decision tree
29
Be Aware or Know your Risk Appetite & Risk Tolerance
30
Project Risk Risk Appetite/Tolerance • What are we trying to achieve with project
risk management?
• …or should we try eliminate all project risks as far as possible?
• who typically decides the project risk appetite?
• How much should we spend on managing project risks?
• Is there some optimal level of investment in risk management…. 31
O ve
ra ll
le ve
l of
r is
k
Cost of reduction measures
Implement reduction measures
Use judgment
Uneconomic
(AS/NZS 4360)Cost- Benefit
Cost
savings
Project Risk – Balancing risk and reward
32
Project Risk Appetite & Risk Tolerance • Risk appetite: is the quantity of risk the entity or person is willing to accept or allow in
order to achieve the project objectives.
• Risk tolerance: is the extent of risk that is allowed or acceptable to address the project objectives or handle a type/category of project risk.
Risk Category Risk Averse (1-4) – (Less willing to take risks)
Risk Neutral (5-6)
Risk Taker/Seeker (7-10) (More willing to take risks)
Product Design 4 Product Development 5
Product Marketing 7
Product Sales 9 33
Project Risk Risk Appetite
• Definition - the level of risk that an organization is prepared to accept, before action is deemed necessary to reduce it
• Levels • Averse Avoidance of risk and uncertainty is a key
organization objective.
• Minimal Preference for ultra-safe options that are low risk and only have a potential for limited reward
• Cautious Preference for safe options that have a low degree of risk and may only have limited potential for reward
• Open Willing to consider all potential options and choose the one most likely to result in successful delivery, while also providing an acceptable level of reward and value for money
• Hungry Eager to be innovative and to choose options offering potentially higher business rewards, despite greater inherent risk
34
MANAGEMENT OF PROJECT RISKS
The Need for a Formal Approach
35
The Need for a Formal Approach
Need for Formal Approach It is about...
Need a systematic approach to identify, analyse and evaluate threats or risks
Manage Project Risks
Need Risk Planning parallel with project planning and other plans
Proactive Approach
Need attention to risks before and during project
Risk Monitoring across Project Phases
Need to inform and manage risk to stay in business by ensuring projects have required contingency
Business Continuity
36
Project Risk Management – ISO 31000
• An international standard providing principles and guidelines for effective risk management
• International Standards with a purpose to have a universal approach and harmonise the project risk management process across Industries.
• Its 16 pages, been developed & updated by Global Experts in Risks (2009; 2018); Led by risk experts from Aust and NZ using AS4360 as the basis
• International Standards Generic Document for Risk Management not intended for certification!
37
Project Risk – ISO 31000 - Key Definitions
• Risk Management Definition Risk management is the term applied to a logical and systematic method of establishing context, identifying, analyzing, evaluating, treating, monitoring and communicating risks associated with any activity, function, project or process in a way that will enable organizations to minimize losses and maximize opportunities
• Risk definition Risk is an 'effect of uncertainties on objectives'
38
RISK MANAGEMENT FRAMEWORK - ISO 31000
• The framework: • assists in managing risks effectively through the application of the risk
management process;
• ensures that information about risk derived from the risk management process is adequately reported; and
• ensures that these information is used as a basis for decision making and accountability at all relevant organizational levels.
39
11 Principles of RISK MANAGEMENT - ISO 31000 • Risk management creates and protects value; • Risk management is an integral part of all organizational processes; • Risk management is part of decision making; • Risk management explicitly addresses uncertainty; • Risk management is systematic, structured and timely; • Risk management is based on the best available information; • Risk management is tailored; • Risk management takes human and cultural factors into account; • Risk management is transparent and inclusive; • Risk management is dynamic, iterative and responsive to change; • Risk management facilitates continual improvement of the organization.
40
Project Risk – ISO 31000 Extraction – Principles, Framework & Process
41
ISO 31000
7-Step Risk Management Process
M onitor and review
Establish context (objectives, organisation)
Identify risks (what, how)
Analyse risks (likelihood, consequence)
Evaluate risks (criteria, priorities)
Treat risks (options, plan, implement)
Co m
m un
ic at
e an
d co
ns ul
t
42
Project Risk – ISO 31000 The seven steps/process
1. Establish context - Strategic & Operational objectives, organizational and risk
management context - The organization’s external and internal environment
2. Identify risks - Which and what uncertainties that matters to whom, why
those uncertainties can arise as a basis for further analysis
3. Analyze risks - Determine the existing controls, and analyze the risks in terms
of the likelihoods - Consider the range of consequences and how they are likely
to occur and impact - Consequences & likelihoods are combined to produce a level
of risks 43
Project Risk – ISO 31000 The seven steps/process
4. Evaluate risks - Compare the estimated risks against the pre-established criteria - This enables risks to be ranked to identify management priorities
5. Treat risks - Accept and monitor low priority risks - For other risks, develop a management plan
6. Monitor and review - Regular monitoring
7. Communicate and consult - Communicate with internal and external stakeholders at each
stage of the process 44
Project Risk Management ISO 31000 – Key Benefits • Applicable at all stages of activity, function, project,
product or asset • Applicable to address Strategic objectives • A more confident and rigorous basis for decision
making and planning • A better identification of opportunities and threats • Gaining value from uncertainty and variability • Effective allocation of resources, procurement
budgets, strategy etc • Proactive rather than reactive management
45
Project Risk Management | The process | 1. Establishing the Context
• The context
• What is the project about? • Aligned to Strategic, Enterprise and
Operational (Project) Objectives • Adherence to Delivery and contract value • Benefits to organization (job creation, future
opportunities, tenure in market etc.)
• Relationship between the organization and its environment (Technology, economical, social, financial, operational, competitive, political and social context)
• Involvement of the stakeholders (owners, personnel, project team, customers, suppliers, local community)
46
Project Risk Management | The process | Establishing the Context
• Consider the following areas for Risk at operational level • Technical • Commercial • Legal/Regulatory • Financial • Programmatic
• And at the Enterprise/strategic level • Understand the organization
and its capabilities in relation to the environment • Wider goals and objectives
47
Project Risk Management | The process | Establishing the Context • Key performance indicators (KPI) at strategic level • Financial health - revenues, profitability,
growth, shareholder return • Product or Service differentiation • Customer satisfaction • Market/Competitive position • Technology/Cost Leadership • Productivity/Continuous improvement • Innovation (Product, Process, Service) • Community engagement • Corporate Image/Social Responsibility • Health, safety and environmental goals
48
Project Risk Management | The process | Establishing the Context
• Key performance indicators at Project level
• Project Schedule Performance • Project Budget Utilization • Contract Requirements (Scope) • Product or service quality • Team Productivity • Resource Utilization
• Customer/Stakeholder Satisfaction (Largely Subjective?) 49
Project Risk Management | The process | Establishing the Context • Examples of project objectives • Completion within budget • Completion within time schedule • Effective Utilization of Resources • Gather the relevant Requirements • Bring out Quality outcomes • Effective stakeholder communications • Ensuring Customer satisfaction • Promote Technological innovation • Meet Health, safety and environmental standards • Ensure team performance • Seek Government approvals • Ensure Supplier performance
50
Establishing KPIs for business & project goals
Revenue
Profits
Schedule
Customer satisfaction
Achieve target revenue within specified %
Achieve target profit within specified %
Complete programs within specified schedule
Achieve a specified % of customer satisfaction (by survey)
Project Risk Management | The process | Establishing the Context
51
Key Difference between CSF and KPI
• CSF are pathways to Project Success • Example: Stakeholder Satisfaction; Effective Team Communication;
• KPIs are the effect of Actions within the Project • Example: Schedule Delays; Cost Overrun
• Word of Caution: At times CSFs and KPIs can be used interchangeably in contracts, organizations or by stakeholders/managers/team
52
Stakeholders - individuals inside the
organisation or project, such as
employees, management, senior
management and volunteers
• decision makers • employee groups • financial institutions • regulators and other
government organisations
• environmental groups • business associates • union groups • insurance organisations • politicians
Project Risk Management | The process | Establishing the Context
Who are your stakeholders? 53
• Separate the activities of a project into a set of activities • Work (Risk) breakdown structure • Business/Project/Product phases
• Based on contract milestones, provides a logical foundation for categorising and understanding associated risks (Risk Breakdown Structure)
Project Risk Management | The process | Establishing the Context
54
Project Risk Management | The process | Establishing the Context
• Class Exercise Establish the context for starting of a small-medium- scale - Retail store / Food Cart/Catering or Cafe project in the precincts of Adelaide CBD
55
Class Exercise – Establishing the Context - Key Considerations
•The core mission, vision and purpose •Products/Services to be sold •Estimated Cost in AUD •Resources/Approvals required •Expected Revenue in AUD •Who are your stakeholders •Competitive/Marketing Strategy for rollout •Duration of starting/rolling out the Business •Duration you are going to run the business
56
Project Risk Management |The process | Step 2 | Identify the Risk
What can be the uncertain events that can matter for your project?
Develop a comprehensive filtered list of events which might affect the project Be well-structured and systematic Use a phased approach
How and why those uncertain events can happen and what could be the outcome/consequences?
Consider causes and affect scenarios (can use decision trees as a modelling method)
Which are the Tools that can be used for Identification of Risks?
Checklists Brainstorming Flowcharts Judgements based on experience Scenario and systems analysis
57
Project Risk | The process| Identify the Risk
GROUP (CORUM) COMMUNICATION/ BRAINSTORMING & EXPERT VIEWS
This Photo by Unknown Author is licensed under CC BY-NC-ND
58
Project Risk | The process| 2. Identify the Risk
• Purpose • Identify where risk might arise • Identify what might be done about this risk, in
proactive and reactive responses terms
• Identify what might go wrong with responses, will an an element of residual risk remain?
• Deliverables • Compile all key risks and responses identified,
classified, characterized, verified and reported
• Identify and classify risks that will directly impact on central project performance objectives/KPI’s/CSF’s
• If there seem to be multiple risks for the same issue, note them at this point, consolidate later
• A Risk Register enabling a clear understanding of threats and opportunities facing the project
59
Project Risk Management | The process | 2. Identify the Risks
• Class Exercise Identify the risk categories and risks involved in your project of starting of a small-medium-scale Retail store / Food or Cafe project in the precincts of Adelaide CBD
60
Identify Risk Phases/Categories – Cheat Sheet
Planning Pre-Operations Operations Closure/Wind Up Survey (Market, Product) Plan of Activities System. Processes,
Governance Waste management
Business/Project Scope Procurement, Logistics, Production Planning
Inventory Control, Quality Control
Inventory Management
Financial Planning Investment, Budget Allocations, Forecast
Cost Control, Financial Closures
Human Resource Planning Recruitment, Selection, Training
WHS, HRM Human Resource Retrenchment/Redundancy
Licensing Branding Sales, Customer Management
Customer Updates (if any)
61
Identify Risk Phases/Categories Template
Planning Pre-Operations Operations Closure Financial Planning
Investment
62
Project Risk – The process | 2. Identify the Risk | Template
Risk register template 1 63
Project Risk – The process | 2. Identify the Risk | Template
Risk register template 2 (Available In MyUni) – To be used for Assessment 1 64
Project Risk – The process | 2, Identify the risks | Writing Style...
State risks in the following form..."There is a risk in"
• Late delivery of widget
• Inability to complete build due to limited workshop space
• Lack of suitably qualified personnel
• Delay in contract award for project xyz
• Increased effort during design phase of widget
• Prolonged council approval period
65
Project Risk Management | The process | 3. Risk Analysis & 4. Evaluation
Aim: Estimate likelihood and consequence of risk events using risk matrix
• These risky events are analysed in the context of existing controls
• The existing controls are there to achieve effective operations, reliable reporting systems and compliance with laws and regulations
• The existing controls are to there to maintain project control, protect PM and make meaningful judgements and decisions, so make sure they are real/valid in the Risk Matrix.
66
Project Risk Management | The process | 3. Risk Analysis
Avoid using your own judgement as far as possible and assumptions by using • Past records • Published literature • Subject matter experts • Market research • Use experiments and prototypes • Expert judgements
Tools & Techniques to establish likelihood and consequence
Structured interview
Assessments using questionnaires
Computer modelling
Decision trees
Multi-disciplinary groups of experts
67
Project Risk Management | The process | Risk Analysis
• Qualitative analyses • Use of words or descriptive scales
• Pros • Quick to use & Easy to understand
and communicate • Cons • Highly Subjective & Prone to error
Types of Risk Analysis • Quantitative analyses • Use of numerical value
• Pros • Less subjective & appear to
be more credible & consistent • Cons • Less easy to communicate • More time consuming
Safety first Organization Culture Revenue/Profit first Organization Culture68
• People • Skills • Attitude • Knowledge • Culture • Power • Trust • Politics • Interests • Priority
• Systems • Information technology –
Automation, Digitization • Equipment • Facilities • Logistics
• Maintenance • Policy & Procedures • Interfaces
Project Risk Management | The process | Risk Analysis
RISK DRIVERS
69
Descriptor
Almost certain
Likely
Moderate
Unlikely
Rare
Description
The event expected to occur in most circumstances
The event will probably occur in most circumstances
The event might occur at some time
The event could occur at some time
The event may occur in exceptional circumstances
Level
A
B
C
D
E
RISK OCCURANCE/LIKELIHOOD
Project Risk Management | The process | Risk Analysis
70
Description
Insignificant
Minor
Moderate
Major
Catastrophic
Examples of detail description
No injuries, low financial loss
First aid treatment, medium financial loss
Medical treatment required, high financial loss
Extensive injuries, major financial loss
Death, high financial loss
Level
1
2
3
4
5
Project Risk Management | The process | Risk Analysis
RISK IMPACT/CONSEQUENCE
71
Likelihood
1 (almost certain)
2 (likely)
3 (moderate)
4 (unlikely)
5 (rare)
Insignificant=1
H
M
L
L
L
Consequences Minor=2
H
H
M
L
L
Moderate=3
E
H
H
M
M
Major=4
E
E
E
H
H
Catastrophic=5
E
E
E
E
H
Project Risk – The process RISK LIKELIHOOD/IMPACT MATRIX
E – Extreme H – High L - Low
72
Risk matrix
• Risk matrix can be used company wide, not just per project, usually driven by PMOs or Board
• The matrix is developed through group discussion as to what constitutes risk at various levels
• Likelihood and consequence criteria need to be defined so that an appropriate number of risks/events fall into each category.
E.g.: • few events in the extreme category • slightly more in the high category, etc
Project Risk Management | The process | Risk Analysis
73
H H E E E L(1)
M H H E E
L M H E E
L L M H E
L L M H H L(2)
Insignificant Minor Moderate Major Catastrophic
Consequences
Li ke
lih oo
d
Risk levels
Almost certain
Likely
Moderate
Unlikely
Rare
Project Risk Management | The process | Risk Analysis
QUALITATIVE RISK MATRIX
HEAT MAP/ THERMO- MAP
L(1) is highly likely but low consequence whereas L(2) is very rare but high impact 74
PROBABILITY
DESCRIPTION INDIVIDUAL ITEM TOTAL RAN INVENTORY FREQUENT Likely to occur REGULARLY. CONTINUOUSLY experienced in the inventory. PROBABLE Will occur SEVERAL TIMES in the life of the item. Will occur REGULARLY in the inventory.
OCCASIONAL Unlikely but can be REASONABLY EXPECTED to
occur in the life of the item. Will occur SEVERAL TIMES in the inventory.
REMOTE UNLIKELY but possible to occur in the life of the
item. Unlikely but can be REASONABLY EXPECTED to
occur in the inventory. IMPROBABLE So unlikely it MAY NOT BE EXPERIENCED. UNLIKELY to occur, but possible.
CONSEQUENCES
DESCRIPTION FITNESS FOR SERVICE SAFETY OF PERSONNEL ENVIRONMENT
CATASTROPHIC Failure that would prevent the platform, system
or equipment from meeting the primary operational requirements.
Failure which could result in death or permanent total disability.
Failure would result in significant long-term damage to the environment and would be
extremely difficult to rectify.
CRITICAL Failure that would significantly degrade the
platform’s, system’s or equipment’s ability to perform its primary mission.
Failure which could result in permanent partial disability, or temporary total disability in excess
of 30 days.
Failure would result in significant short term damage to the environment which would be
difficult to rectify.
MAJOR Failure would result in temporary loss of one or
more significant capabilities within the platform, system or equipment.
Failure which could result in temporary partial disability less than 30 days, hospitalisation,
emergency medical treatment, injury or illness eligible for compensations.
Failure would result in short term damage to the environment, which would be readily rectifiable.
MINOR Failure would result in temporary degradation or
loss of one or more capabilities within the platform, system or equipment.
Failure which could result in first aid or minor supportive medical treatment.
Failure would result in short term damage to the environment requiring no rectification activities.
RISK MATRIX CONSEQUENCE
PROBABILITY CATASTROPHIC CRITICAL MAJOR MINOR FREQUENT 1 3 7 13 PROBABLE 2 5 9 16 OCCASIONAL 4 6 11 18 REMOTE 8 10 14 19 IMPROBABLE 12 15 17 20
ACCEPTABILITY
HRI RISK LEVEL RISK ACCEPTABILITY 1 to 5 Extremely high Intolerable 6 to 9 High Unacceptable
10 to 17 Medium Acceptable with continuous review 18 to 20 Low Acceptable with periodic review
QUANTITATIVE RISK MATRIX – HEAT MAP/ THERMO MAP
75
Risk Matrices
V. High
Pr ob
ab ili
ty
Medium (4) High (6) Very High (8) Very High (10) Very High (12)
High Medium (3) High (5) High (7) Very High (9) Very High (11)
Medium Medium (2) Medium (4) High (6) Very High (8) Very High (10)
Low Low (1) Medium (3) High (5) Very High (7) Very High (9)
V. Low Low (1) Low (2) Medium (4) High (6) High (8)
Limited Significant Major Unacceptable Catastrophic
IMPACT
Cost Impact # Minimum Likely Maximum
Limited 1 $ 3,000 $ 5,000 $ 10,000
Significant 2 $ 10,000 $ 25,000 $ 50,000
Major 3 $ 25,000 $ 50,000 $ 100,000
Unacceptable 4 $ 50,000 $ 100,000 $ 200,000
Catastrophic 5 $ 150,000 $ 250,000 $ 350,000
Significant 2
Schedule Impact # Minimum Likely Maximum
Limited 1 1 Week 1 Month 2 Months
Significant 2 1 Month 2 Months 4 Months
Major 3 2 Months 4 Months 8 Months
Unacceptable 4 4 Months 8 Months 1.5 Years
Catastrophic 5 8 Months 1.5 Years 3 Years
Quantitative Risk Matrix
Number
Project Risk Management | The process | Risk Analysis
76
4. Risk Evaluation
• Calculate Likelihood X Consequence
• Calculate the sum of the risks (pure addition)
• Purpose • Prioritise Risks/Compare risk levels found with previously established criteria
• Outputs - Prioritised risk register for further action
Project Risk Management | The process | Risk Evaluation
77
ALARP As Low as Reasonably Practicable
Project Risk Management | The process | Risk Evaluation
Case Example from a Drilling Company
78
RISK MATRIX
CONSEQUENCE
PROBABILITY CATASTROPHIC CRITICAL MAJOR MINOR
FREQUENT 1 3 7 13
PROBABLE 2 5 9 16
OCCASIONAL 4 6 11 18
REMOTE 8 10 14 19
IMPROBABLE 12 15 17 20
ACCEPTABILITY
HRI RISK LEVEL RISK ACCEPTABILITY Cost (AUD)
1 to 5 Extremely high Intolerable 1,000,000-,000,000
6 to 9 High Unacceptable 50,000-500,000
10 to 17 Medium Acceptable with continuous review 10,000-20,000
18 to 20 Low Acceptable with periodic review 5,000-10,000
Risk Matrix for Class Exercise
Project Risk Management | The process | Risk Evaluation
79
Project Risk Management | The process | Risk Analysis & Evaluation
• Class Exercise Analyse & Evaluate the risks involved in your project of starting of a small-medium- scale Retail store / Food or Cafe project in the precincts of Adelaide CBD
80
Project Risk | The process | Risk Treatment • Treatment of Risks as per your risk register
• Identify remedies for treating risks for positive outcomes • Stay on target – risks are to be treated to ensure
contract outcomes are achieved • Addressing consequences for positive outcomes • Increasing the likelihood of opportunities • Sharing the opportunity
• Some examples for positioning treatments • Product initiation/development phase • Controls • CSFs (Critical Success Factors)–may be linked to contract
81
Project Risk – The Process | Risk Treatment • Some Examples of Actions to treat or reduce negative consequences
• Risk Register and Risk Management Plan • Contingency planning • Contractual arrangements, conditions, contract variations • Design specifications • Disaster recovery plans • Business Continuity Plans • Fraud control planning • Minimizing exposure to sources of risk
• Portfolio planning • Pricing policy and controls
• Separation or relocation of an activity and resources • Public relations to protect corporate reputational damage
82
Project Risk – The Process | Risk Treatment
• Identify & Evaluate options for risk treatment • Terminate (Avoid) e.g. IT or Construction Project due to new technology • Treat (Reduce) e.g. Airline Maintenance Procedure, Training of Equipment • Transfer e.g. Buying Insurance while construction or IT Outsourcing • Tolerate (Accept) – e.g. Stock Market Downfall, Vaccine side affects
• Prepare risk treatment plans or agree on a way forward with your Management Team
• Implement the treatment plans as necessary
83
Project Risk | The process | Risk Treatment
ALARP – As Low As Reasonably Practicable
• Your treatment(s) should ensure this is achieved • Usually achieved after 2nd or 3rd pass of
assessment, post treatment. • Generally, by application, contracts, especially
government contracts will stipulate this requirement of ALARP
84
Project Risk | The Process | Risk Treatment Class Exercise
Treat the risks involved in your project (for one of the phases/category) of starting of a small-medium-scale Retail store / Food or Cafe project in the precincts of Adelaide CBD
85
Why do we need to monitor and review project risks? • Risks are not static, new & residual risks can emerge, identified/treated risks can retire
• The effectiveness of the risk management plan/process should also be monitored and reviewed • Continuously improve your risk management techniques and system
How do we need to monitor & review project risks? • Develop and apply mechanisms to ensure ongoing review of risks using
• Reports • Discussion Forums
• If you weren’t happy with the process which was tailored to your project, do something to change it • Conduct a lessons learnt meeting on the risk management side of the project near project close out
Project Risk | The process | 6. Risk Monitoring & Review
86
Question:
Based on your experience or observations....
Have you seen the effectiveness of lessons learnt in projects... do project teams really make use of it... discuss with your own examples
Project Risk | The process | 6. Risk Monitoring & Review
This Photo by Unknown Author is licensed under CC BY-NC
87
Risk Monitoring & Control of Project (Operational) Risks @ Sydney Train stations
88
https://www.youtube.com/watch?v=Keind0OOUhI
• Why do we need to communicate and consult? • Need to manage and report risk as per required standards (e.g. ISO 31000) • To demonstrate risk awareness, transparency and a systematic approach in managing risks (Risk Culture) • Facilitate decision makers for decisions/approvals (Risk based Decision Making)
• How do we need to communicate and consult? • Provide a record or inventory of risks (Risk Register) • Provide a risk management plan/report for managing risks • Information on accountability (Risk Owners) • Facilitate periodic Audit Trail/Review Meetings
• Which are the Tools for communication? • Risk Management Plan/Report • Risk Register • Waterfall (Cost) or Burndown Chart
Note: The information from these tools will feed into monthly reports, knowledge database, quarterly financial reports and other similar documents used to report and track process of your project
Project Risk | The process | 7. Communication & Consultation
89
• Tools for communication
• Waterfall (Cost) or Burn Down Chart • Communicates effectively with
Stakeholders/Senior Management • Opportunities to take project profit • Current state of project risk $ being held • Can be used to communicate actual
progress against planned progress of managing Risks
Project Risk | The process | Communication & Consultation
90
• Tools for communication • A report should include
• Executive summary • Project Scope • Methodology of study • Contextual aspects of the project including issues/constraints • Vulnerabilities in phases of the project • Critical Success factors (CSFs) chosen • Key performance indicators (KPIs) for each success factor • Discussions about the Top ten risks across all CSF’s for the entire project • Drivers triggering each of top ten risks • Target and tolerance • Authority & Responsibilities for managing risks in phases • Existing controls • Any assumptions • Charts, Tables and figures • Conclusions
Project Risk | The process | Communication & Consultation
91
Establishing an Effective Risk Management System/Framework for your Enterprise
92
Establishing an Effective Risk Management System/Framework for your Enterprise
• Purpose • Develop and sustain systematic risk management within an organization
• Evaluate existing practices and needs • Critical assess those elements of the risk process already in place
• Look at the considerations and deliver a structured appreciation of: • The maturity and effectiveness of the current processes/systems • Degree of integration/consistency across organisation and the types of risks • Those processes and systems that should be modified and extended • Constraints including resources
93
Establishing Effective Risk Management
• Risk management planning • Develop risk management plans • Define how it should be done • Embed risk management in all of the organisation’s practices and business
processes • Especially in policy development, business and strategic planning and change
management processes
• Ensure support of senior management • Awareness of risk management among senior managers • Active and ongoing support of the organization’s directors and senior executives • Appoint a senior manager to champion, lead and sponsor initiatives • Obtain commitment of all senior managers
94
Establishing Effective Risk Management • Establish & communicate risk management plan, policy or framework • The extent and types of risk the organisation will take • The processes to be used to manage risks • Accountabilities for managing particular risks • Details of the support and expertise available • A statement on how risk management performance will be measured and reported
• Ensure adequate resources • People and skills • Documented processes and procedures • Funding and other resources for treatment of risks • Information systems and databases
95
Establishing Effective Risk Management
• Customise the risk management process
• Risk management information systems • Record details of risks, controls and priorities • Record risk treatments and resource requirements • Record details of incidents and loss events and lessons learned • Track accountability for risks, controls and treatments • Allow progress against the risk management plan to be measured • Trigger risk monitoring activity
96
Establishing Effective Risk Management
.1 Plan Risk Management .1 Inputs
.1 Project scope statement
.2 Cost management plan
.3 Schedule management plan
.4 Communications management plan
.5 Enterprise environmental factors
.6 Organisational process assets
.2 Tools and techniques .1 Planning meetings and analysis
.3 Outputs .1 Risk management plan
.2 Identify risks
.1 Inputs .1 Risk management plan .2 Activity cost estimates .3 Activity duration estimates .4 Scope baseline .5 Stakeholder registration .6 Cost management plan .7 Schedule management plan .8 Quality management plan .9 Project documents .10 Enterprise environmental factors .11 Organisational process assets
.2 Tools and techniques .1 Documentation reviews .2 Information gathering techniques .3 Checklist analysis .4 Assumptions analysis .5 Diagramming techniques .6 SWOT analysis .7 Expert judgment
.3 Outputs .1 Risk register
Ready Reckoner
97
E st
a b
li sh
in g
E ff
e c
ti ve
R is
k M
a n
a g
e m
e n
t R
e a
d y
R e
c k o
n e
r
.3 Perform Qualitative Risk Analysis
.1 Inputs .1 Risk register .2 Project management plan .3 Project scope statement .4 Organisational process assets
.2 Tools and techniques .1 Risk probability and impact
assessment .2 Probability and impact matrix .3 Risk data quality assessment .4 Risk categorisation .5 Risk urgency assessment .6 Expert judgment
.3 Outputs .1 Risk register updates
.4 Perform Quantitative Risk Analysis
.1 Inputs .1 Risk register .2 Project management plan .3 Cost management plan .4 Schedule management plan .5 Organisational process assets
.2 Tools and techniques .1 Data gathering and
representational techniques .2 Quantitative risk analysis and
modelling techniques
.3 Outputs .1 Risk register updates
98
E st
a b
li sh
in g
E ff
e c
ti ve
R is
k M
a n
a g
e m
e n
t R
e a
d y
R e
c k o
n e
r
.5 Plan Risk Responses
.1 Inputs .1 Risk register .2 Risk management plan
.2 Tools and techniques .1 Strategies for negative risks
or threats .2 Strategies for positive risks
or opportunities .3 Contingent response strategies .4 Expert judgment
.3 Outputs .1 Risk register updates .2 Risk related contract decisions .3 Project management plan updates .4 Project documentation updates
.6 Monitor and control risks
.1 Inputs .1 Risk register .2 Project management plan .3 Work performance information .4 Performance reports
2 Tools and techniques .1 Risk assessments .2 Risk audits .3 Variance and trend analysis .4 Technical
.3 Outputs .1 Risk register updates .2 Organisational process assets .3 Change requests .4 Project management plan updates .5 Project documentation updates
99
PROJMGNT 5004 Managing Project and Systemic Risks
Trimester 3 ,2021
Session 1, Day 2 (Day 1 & 2)
- Dr Krishnan Mysore Ph.D.
School of Business 100 Dr Krishnan Mysore 2021 – All Slides
Day 1 session...
101
Day 1 Recap Learning Objectives
Aware of the fundamentals of risk – Day 1
Able to identify the core types of project risks – Partly on Day 1
Able to use qualitative and quantitative risk assessment methods - Day 1
Aware of risk simulation techniques and other risk analysis tools/ methods
Aware of a range of risk management issues and challenges
Able to work in a group to create a risk management plan/register based on the ISO 31000:2009 – Day 1
102
Some Important Slides...
103
Project Risk – The process | 2, Identify the risks | Writing Style...
State risks in the following form
• Late delivery of widget
• Inability to complete build due to limited workshop space
• Lack of suitably qualified personnel
• Delay in contract award for project xyz
• Increased effort during design phase of widget
• Prolonged council approval period
104
• Tools for communication
• Waterfall (Cost) or Burn Down Chart • Communicates effectively with Stakeholders/Senior Management
• Opportunities to take project profit/add contingency • Current state of project risk $ being held • Understand the trend of New, old or retired risks • Can be used to communicate actual progress
against planned progress of managing Risks
Project Risk | The process | Communication & Consultation
105
ALARP As Low as Reasonably Practicable
Project Risk Management | The process | Risk Evaluation
Case Example from a Drilling Company
106
RISK MATRIX
CONSEQUENCE
PROBABILITY CATASTROPHIC CRITICAL MAJOR MINOR
FREQUENT 1 3 7 13
PROBABLE 2 5 9 16
OCCASIONAL 4 6 11 18
REMOTE 8 10 14 19
IMPROBABLE 12 15 17 20
ACCEPTABILITY
HRI RISK LEVEL RISK ACCEPTABILITY Cost (AUD)
1 to 5 Extremely high Intolerable 1,000,000-,000,000
6 to 9 High Unacceptable 50,000-500,000
10 to 17 Medium Acceptable with continuous review 10,000-20,000
18 to 20 Low Acceptable with periodic review 5,000-10,000
Risk Matrix for Class Exercise
Project Risk Management | The process | Risk Evaluation
107
Categories (Types) of Risk
108
Categories of Risk Project (Operational) Level
• Scope Risk • Schedule Risk • Cost Risk • Quality Risk • Resource Risk • Procurement Risk • Stakeholder Risk
• Commercial Risk • Financial Risk • Strategic Risk • Technical Risk • Governance Risk • Market Risk • External Hazard Risk • Performance Risk • Reputational Risk (in some cases)
109
Categories of Risk Generic Project Risks
• Scope Ø Poorly defined requirements Ø New product feature added
• Schedule Ø Quantity needed is not available Ø Particular items are on long lead delivery Ø Underestimation of necessary time for activity Ø Intertwining of third party schedules
• Resource Ø Resignation of key staff Ø Travel budget cut/ban
110
Historical/Generic Risk Categories • Strategic • Operation • Compliance • Financial & Reporting; • Added it can be Environmental, Social and Cybersecurity risks
KEY Secondary data Sources for RISK • Gartner Risk Management Leadership Council • The World Economic Forum Global Risks Report • The Global Reporting Initiative Framework • The Carbon Disclosure Project and • The Task Force on Climate-related Financial Disclosures
111
Categories of Risk New Ventures
Risk an essential part of a gated or funnelled process, commonly used in business development and new product development (NPD)
Gate 0 – Discovery/concepts Gate 1 – Scoping Gate 2 – Build Business case Gate 3 – Development Gate 4 – Testing, Validation and Verification; Gate 5 – Launch
112
Categories of Risk New Ventures - NPD
Stage 0 - Discovery: Activities designed to discover opportunities and to generate new product ideas. Stage 1 - Scoping: A quick and inexpensive assessment of the technical merits of the project and its market
prospects. Stage 2 - Build Business Case: This is the critical homework stage - the one that makes or breaks the project.
Technical, marketing and business feasibility are accessed resulting in a business case which has certain main components: product road map and project definition; project justification; and project plan.
Stage 3 - Development: Plans are translated into concrete deliverables. The actual design and development of the new product occurs, the manufacturing or operations plan is mapped out, the marketing launch and operating plans are developed, and the test plans for the next stage are defined.
Stage 4 - Testing and Validation: The purpose of this stage is to provide testing and validation of the entire project: the product itself, the production/manufacturing process, customer acceptance, and the economics of the project.
Stage 5 - Launch: Full commercialization of the product - the beginning of full production and commercial launch.
113
Categories of Risk New Ventures
The benefit of the Phase-Gates process for product development is to provide:
• More discipline in the development decision-making process
• Improved quality of execution
• Clearer risk understanding and management of Investments/Projects
• Decision making based more on facts
• More structure for idea generation
• Better scope for end user involvement in the earlier process phases
• More transparency for reviewers
114
Categories of Risk New Ventures
Some Theoretical Perspectives... Cooper (2001:25) • The process is not linear • Inside each stage there is ‘looping, iterations and back-and-forth play; • Some activities are sequential, others in parallel, and others overlapping. • The gated process is not a control mechanism so that executives micromanage projects • Rather, the gated process is a playbook designed to enable project teams and team
leaders assess risks, get resources for their projects to ensure success’
115
Categories of Risk New Ventures
The assessment at each phase gate is to decide:
• What are the risks?
• What is the cost of managing the risk?
• Do the reputational benefits/revenues appear to outweigh the risks – this might be expressed as an
acceptable ROI?
• Does it fit into our risk appetite?
• Do we supply funds to progress to the next phase-gate?
• Part of this investigation is to decide if there is a competitive advantage in the product
116
Categories of Risk New Ventures
117
Categories of Risk New Ventures – Example 1
Airbus Discloses Cost Overruns On Big A380 Jet
“PARIS -- Airbus parent European Aeronautic Defence & Space Co. said the plane maker's flagship A380 superjumbo jetliner faces cost overruns of €1.45 billion ($1.93 billion) because of unbudgeted work to cut its weight and improve efficiency.”
Source: Wall Street Journal, Dec. 16, 2004
118
Categories of Risk - New Ventures Smith and Reinertsen (1995:209) comment on product risks: Technical Risks
• Organisations usually place more emphasis on technical risk (easier to manage) than market risk
• Technical risk can arise from the technology failing to perform as expected:
• From its cost being higher than projected, or from unanticipated side effects (obsolescence, supply chain
issues, system engineering requirements, verification and validation) that arise from a technical approach.
• Outcome of having un-resolve technical risks is usually schedule delay or cost over run risk
• If a technology does not perform as expected, extra time to fine tune to probably solve the difficulty
• If cost is the issue, the design cost can probably be reduced through refinement’. ( Design Thinking, Value Engineering)
• The most effective time to deal with technical risks is during the design phase.
• Several reviews are required by management, and produce numerous plans which needs approval • Preliminary design review; Critical design review; Final design review
119
Categories of Risk - New Ventures Market Risks
• Market risk often receives less attention than technical risk – its no less important! • Usually occurs after launch of a product:
• Weak product specifications/requirements, such as what the customer wants in terms of the products/applications
• Products with a long development cycle can experience greater market risk as the market changes – Time to Mkt
• Need to remain flexible on key issues – when you cannot determine the correct path remain flexible (or Agile)
• Doing a large number of upgrades simultaneously increases the risk.
• One way of dealing with risks is to incrementally innovate with small regular upgrades
120
ISO 31000
Risk Management Process
M onitor and review
Establish context (objectives, project, organisation)
Identify risks (what, how)
Analyse risks (likelihood, consequence)
Evaluate risks (criteria, priorities)
Treat risks (options, plan, implement)
Co m
m un
ic at
e an
d co
ns ul
t
121
Categories of Risk: Commercial/Liability Risk • Contractor can be generally liable for a range of issues - not possible to limit liability against
legal proceedings but can limit liability to a figure, such as a proportion of the margin
• Political influence: can range from the project being cancelled due to a change in policy, & inadequate compensation, or compensation is very slow to be received, and bad publicity
• Malicious acts and arson: some projects may be more susceptible than others to damage, due to acts initiated by third parties
• Third party litigation: some projects may be more susceptible than others
• Unfortunate media attention: takes the time of project staff to deal with, and may require a costly public relations campaign to counter
122
Categories of Risk Commercial/Liability Risk
• A standard form for contract is not being used • Economic conditions such as basis of price and contract price adjustment not clear • Too many or too complex additional clauses have been inserted • Customer requirements not clear and unambiguous • Unclear basis for resolution of payment disputes • Principal is not guaranteeing correctness of information • Conditions associated with payment milestones not clearly defined • Allowance for penalties for late completion • Clauses Guaranteeing performance, Materials and equipment guarantees • Contractual liability (breach, third party actions) • latent conditions, Warranties • Public liability, IP Rights • Liquidated damages, Performance damages • International business contracts/legal obligations • Requirements on packaging/transportation not clearly specified • Subcontractor violation of laws • Consequential loss (only exists in the UK) • Contract Termination conditions not read properly (procedure, compensation) 123
Categories of Risk Commercial/Liability Risk Example 1 How Culture ended the Daimler-Benz Chrysler Merger
“Analysts agree that the cultural gap in corporate cultures was one of the main reasons for the Daimler- Chrysler failure. Daimler was a German company which could be described as “conservative, efficient and safe”, while Chrysler was known as “daring, diverse and creating” (Appelbaum, Roberts and Shapiro, 2009:44).”
Source: Kwintessential website, viewed Jul. 7, 2015
• How could the consequences of the risk have been avoided? Ø Pre-Merger Integration plan
ü Appreciation of different cultures, driven by country of origin effects ü Appreciation of different corporate cultures
v What is the main purpose for mergers? ü ROI & Synergy ü Better handle of Techno-Market risk in changing market 124
Categories of Risk New Ventures – Example 2
Major milestone for GSK/NIH candidate Ebola vaccine as first doses shipped to Liberia for use in phase III clinical trial
“GSK has announced that the first batch of its candidate Ebola vaccine is being shipped to west Africa and is
expected to arrive in Liberia...The shipment...initial 300 vials of ...vaccine, is the first to arrive in one of the main
Ebola affected countries and will...start the first large-scale efficacy trial of experimental Ebola vaccines.”
“Staff at GSK and J&J say they are working around the clock to accelerate production and that efforts are being
driven by humanitarian need rather than ...profitable. Other vaccines are now being pushed forward...
Profectus BioSciences recently got two government contracts worth $17m to speed up work on its vaccine.”
Source: GSK website, Jan. 23, 2015 125
Categories of Risk | New Ventures
Cooper (2001:25) cites the largest risks in product development as:
• Inadequate market analysis
• Product problems or defects
• Lack of effective marketing effort
• Higher costs than anticipated
• Competitive strength or reaction
• Poor timing of product introduction
• Technical or production problems
126
Risk In Product Business: Sample Risk Appetite
Extremely High tolerance for pursuing product related business opportunities and partner collaborations. High tolerance towards high performing product teams that engage in the research and development, marketing, services and sales of products that enhances our market position, branding of the product, stakeholder satisfaction and organisational reputation. High tolerance for responding to and accommodating the Industry, Partner or customer driven product requirements. Low tolerance for unhealthy or unethical practices with organisations that can damage our market position, branding of the product, stakeholder satisfaction and organisational reputation and community as a whole. Low tolerance for not achieving the product quality. Zero tolerance for not adhering to code of business ethics and product safety.
127
Categories of Risks - Risks in Research projects
• Research Engagements with foreign entities (Collaboration/Knowledge Transfer or sharing Risk) • Research Ethics: involving human or non-human entities • Research Ethics: Confidentiality and sensitiveness of research data • Technical risks (Research sample, lab, equipment, data
collection/analysis instruments) • Suite of Project Management Risks of Research projects • IP and commercialisation related risks
128
Categories of Risk: Financial Risk
• Security of payment
• Payment terms
• Foreign exchange
• Tax
• Foreign markets
• Material adverse effect
• Credit Risk
129
Categories of Risk Environmental Risk
• Biological processes • Chemical processes • Refinery processes • Mining Processes • Foreign made materials • Poor definition of initial project environmental impacts • Environmental investigation delays and costs • Environmental permits delays and costs • Environmental mitigation delays and costs • Environmental compliance delays and costs • Known hazardous waste • Unknown/non-defined hazardous waste • Obtaining environmental approvals leading to construction delays and cost
130
Categories of Risk Environmental Risk – Example 1
BP Oil Spill – Gulf of Mexico (Largest Environmental Disaster in 2010)
“They lied to the people of the Gulf. And they lied to their shareholders, and they lied to all Americans," said Representative Ed Markey, the top Democrat on the House Natural Resources Committee who led investigations at the time of the spill.”
“The government also indicted the two highest-ranking BP supervisors aboard the Deepwater Horizon during the disaster, charging them with 23 criminal counts including manslaughter.”
Industries impacted with adverse affects from Oil spill: Marine, Wildlife habitats and fishing and tourism industries
Payments by BP – up to USD $46 Billion
Allocation in corporate risk register – USD $3.5 Billion (in preparation for trial)
Source: Reuters, Nov. 16, 2012 131
Categories of Construction Site/Project Risk • Weather conditions • Access hearings or findings and order • Appraisal or review • Establishing Just Compensation • Acquiring a right of way • Taking possession/Hand over • Completing relocation • Certification • Construction easements • Permanent easements
• Certification of completed work
• Site security
• Difficulties in indemnification from any payment for losses and damages incurred by a third party such as adjacent property owners
• Permits, licenses, laws, and regulations
• Enforcement of legal provisions
• Erosion control
• Inadequate site investigation
132
Categories of Risk Construction Site/Project Risk – Example 1
• Completion of Aged Care Facility or School
• Risks to scheduled hand over date (after handover/defects phase)
Ø Risks to residents from unfinished works, hazards
Ø Risks to ROI of facility, based on lower recovery
• Beach Front Home/Luxury Home Constructions
• Risks from Sea Swells, Soil erosion etc
• Risks to residents, property owners
• Risks to Property Investors
• Risks to Insurance companies 133
Categories of Risk IT Transformation Projects Example 1
Key Risks encountered during IT Transformation Projects
• LACK OF COMMON VISION AND COOPERATION BETWEEN CUSTOMER AND VENDOR
• PROJECT SCOPING AND BUDGET MISMATCH
• DESIGN AND REQUIREMENTS MISMATCH
• LACK OF EFFECTIVE PROJECT MANAGEMENT CONTROLS
• TECHNICAL FEASIBILITY AND OPERATIONAL CHALLENGES
Source: LOGICALIS website, Jul. 29, 2016 134
Multi-Stakeholder Perspectives/Discussion on one of (current) Infosys Large Project Troubles:
1) What went wrong (risks) with the Large Govt IT Transformation project delivered from Infosys?
2) How can Infosys treat the project risks and ALARP?
135
Food for Thought... https://www.youtube.com/watch?v=nEBSvnYDZDA
Categories of Risk IT Project Risk – Example 3 83.9% of IT projects partially or completely fail - Standish Report
According to Standish only 16.2% of projects
were deemed successful by being completed on
time and budget, with all the promised
functionality. A majority of projects, or 52.7%,
were over cost, over time, and/or lacking
promised functionality. That leaves 31.1% to be
classified as failed, which means they were
abandoned or cancelled.
Source: Opendoor Technology website, Feb. 20, 2019
All of the top factors found in failed projects include:
1. Incomplete Requirements 2. Lack of user involvement 3. Lack of resources 4. Unrealistic expectations
5. Lack of executive support 6. Changing Requirements & Specifications 7. Lack of planning
8. Didn’t need it any longer 9. Lack of IT management 10. Technical illiteracy
136
Categories of Risk IT Project Risk – Example 2
Why poorly defined user requirements can lead to contract termination
Source: Creating a Sustainable Social Ecology Using Technology-driven Solutions Elias G. Carayannis, 2013
137
Categories of Risk IT Project Risk – Example 2
Lack of IT Collaboration can lead to Project Delays & Cost Overruns
Carol Matlack describes this hard-to-believe situation in BusinessWeek: It sounds too simple to be true. Airbus’ A380 megajet is now a full two years behind schedule—and the reason, CEO Christian Streiff admitted on Oct. 3, is that design software used at different Airbus factories wasn’t compatible. [Ed. note: on Oct. 10, Airbus announced that Louis Gallois is replacing Streiff as CEO.]
Early this year, when pre-assembled bundles containing hundreds of miles of cabin wiring were delivered from a German factory to the assembly line in France, workers discovered that the bundles, called harnesses, didn’t fit properly into the plane. Assembly slowed to a near-standstill, as workers tried to pull the bundles apart and re-thread them through the fuselage. Now Airbus will have to go back to the drawing board and redesign the wiring system.
It’s shaping up to be one of the costliest blunders in the history of commercial aerospace.
Source: www.zdnet.com 138
Project Risk – Cost Overrun/ Over Budget Spend/Delays
28-09-2018 Data Source: Business Insider March 2021
This Photo by Unknown Author is licensed under CC BY-NC-ND
https://www.youtube.com/watch?v=7PM4sYl3dsI
139
Risk Simulation
140
Why Simulate?
• Use of a range to indicate the risk of an event is more representative of situation than a fixed number
• Usually for high risk and high important projects
• Often used for corporate risk registers at the enterprise level
• Aims to remove subjectivity
141
Monte Carlo Simulation • named after Monte Carlo Casino in Monaco Spain, found by Stanislaw Ulam and John Von
Nuemann in Mid 1940s, evolved from Atomic/Nuclear energy space
• popular technique for predicting phenomena involving uncertainty, uses the principle of randomness, statistical random sampling
• uses a probability distribution, three-point estimate & runs several hundreds or thousands of trails to yield a predictive range of values/outcomes
• its software enabled – XL add-ins available @risk ; Crystal Ball;
• as its applications in Project management in terms of Project Investment, Project Scheduling and Project Risk evaluation
142
Benefits of Monte Carlo Simulation • Better estimation of budget and schedule
• Objective data-based decision making
• Quantification of Project Risks to analyze the likelihood and impacts
• Can be used effectively to predict schedule delays, cost overruns
• and whether project milestones can be met or not.
143
Key Limitations of Monte Carlo Simulation
• Can help in the overall project risk analysis, not for individual risk analysis
• 3 estimates have to be provided for every activity/task
• Garbage in is Garbage out, meaning analysis is only good as the estimates provided
144
How does Monte Carlo Analysis generally work • Monte Carlo simulation performs risk analysis by building models of possible
results by substituting a range of values—a probability distribution—for any factor that has inherent uncertainty.
• It then calculates results over and over, each time using a different set of random values from the probability functions.
• Depending upon the number of uncertainties and the ranges specified for them, a Monte Carlo simulation could involve thousands or tens of thousands of recalculations before it produces distributions of possible outcome values.
145
An Illustrative Example 1
• e.g. worst-case, best-case, and most likely durations for each task for completing the project (say 2 Months for task A, 4 Months for Task B and 5 Months for Task C) to determine the completion date for the overall project.
• The Monte Carlo will simulate, analyse the potential combinations and provide a range of outcomes • For instance, 10% chance of completing the project in 10 months, 30% chance
of completing in 11 months. 90% chance in completion of the project in 13 Months...
146
An Illustrative Example 2
• Total time needed to complete a Construction Project during uncertainty • 3 tasks to complete, 3 different estimates for each task
Task Minimum Most Likely Maximum
1 4 5 7
2 3 4 6
3 4 5 6
Total 11 14 19
147
Illustrative example 2 contd Time No of times out of 500 % (Rounded)
12 1 0%
13 31 6%
14 171 34%
15 392 79%
16 484 96%
17 499 100%
18 500 100%
Nearly 80% chance of completing the project in 15 months, helps PM to be more risk aware to plan for insurance, license, resourcing etc.
148
Monte Carlo Simulation
Illustrative Example 3
• Purchase budget • Equipment 1 (PC) = $1600 • Equipment 2 (Printer) = $1000 • Total = $2,600
• Number of Stores to check Price - 20
149
Distribution of Cost – Computer/Printer
Computer price in 20 stores Printer price in 20 stores
150
Monte Carlo Simulation Trial Trial 1
$1,600
$800
$2,400
151
152
20% chance >$3200
Minimum of Total = Minimum of PC + Minimum of Printer = $1,200 + $500 = $1,700
Maximum of Total = Maximum of PC + Maximum of Printer = $2,100 + $1,600 = $3,700
Inferences: 80% chance from 30 trails; 50% chance within purchase budget from 2000 trials more the trails run, better the distribution looks like, accurate the risk estimate...
153
Conclusions from Monte Carlo Analysis • Removes uncertainty that can come from assuming values or single estimates
• Rubbish in/ Rubbish out; The outcomes are as good as estimate values
• Having more information and simulation runs, thereby creating a more realistic range that will provide you with a better result
• By providing a range of values – max, min and most likely, Monte Carlo technique will yield the likelihood or probable outcomes
• Key Reference in MyUni: In Bowden et al. the consequence is modeled using Monte Carlo simulation
154
Sensitivity Analysis
• Used to Establish the key (individual) project risks or prioritized set of uncertainties that has probable impact on the outcomes of the project.
• Uses the co-relations and comparisons of variations between outcomes and factors from a risk model.
155
Risk Identification & Analysis – Case Study
(to be reviewed by students)
Optional – In Class Exercise
Individually Read and Discuss among groups on the following:
156
Student Group Activity:
Access the Case study from Session 1 Course Content in MyUNi Key Case Points to study, observe & discuss in-class
• What is the case context/problem? • Why there is a need for risk assessment? • What is the risk appetite/tolerance criteria? • How was the risk assessment conducted? • Which are the key risks for individual/societal groups? • How was the sensitivity analysis/evaluation done? • What are those salient conclusions from the perspective
of individual & as well as Societal risks? 157
The Project Risk Management System
158
A Project Risk Management System
What does it need?
1. Risk Management Policy or Risk Framework 2. Risk Management Plan 3. Risk Register
159
Risk Management Framework
i. Provides guidance for risk management in the business
ii. Provides guidance for development and management of risk management plan and risk register
iii. Provides guidance for reporting
160
Key Difference between Risk management Plan and Risk Register
• A Risk Management Plan outlines the Risk Management Approach/Process that is essential for Managing Risks
• A Risk Register includes all the risks, the details of their analysis and how you are addressing those risks
161
Risk Management Plan The risk management plan should have response to the following: • How are we going to identify risks to the project? • What techniques are we going to use to analyse those risks? • Which stakeholders should be kept appraised of project risks? • What is the risk appetite and tolerance of Stakeholders? • How will we decide what to do in the event a risk becomes a reality? • What is the review mechanism / communication plan for a risk event?
A Project Risk Management System
162
Risk Management Plan
The risk management plan (inclusive of risk register) will provide the necessary controls to be adopted and contains the following: • Who has responsibility for implementation of the plan • Resources to be utilized • Work breakdown structure for the activities • Budget allocation (Contingency) • Schedule for implementation • Details of the mechanism and frequency for review
A Project Risk Management System
163
Sample Risk Register
164
A Project Risk Management System
Process for Developing a Risk Register • When you are given a new project upon contract award • When you take over a partially completed contract • Development Process • Understand your contract and develop WBS/RBS (if required) • Engaging with stakeholders +Team + Program Manager to list risks. • Review by phase or WBS element/Category within phases • Consolidate list with the identified risks only at this stage • Meet with concerned group of experts/SMEs to assess risk rating against risk
matrix (Consequence, Likelihood) and decide on appropriate treatments for each of those prioritised risks • Conduct the above step again if required. • Monitor, Review regularly 165
A Project Risk Management System Communication Rules when recording in risk register
• State risks in the following form, such as "failure to achieve" or "there is a risk that"… • Late delivery of interface product
• Delay in contract award for project xyz
• Lack of suitably qualified personnel
• State the causes "Because of"
• Vendor Pricing Negotiation
• Bid Clarifications
• State the consequences "with the consequences that" • Time to Market Product X
• Dip in Quarterly Business Revenue
166
A Corporate Risk Management System Key Differences between Corporate Risk Register and Project Risk Register
- Contingency vs Planning - Scope / Breadth - Examples of Corporate Risk Register
- time-to-Market - incompatible product fit, - difficult-to-sell - loss of political support - succession planning
167
Assignment 1 & 2 Walkthrough & Pre-prep Activity
168
Assignment 1 & 2
# Assessment Task Due Date Task Type Length Weighting
1 Risk Register (20%) https://myuni.adelaide.edu.au/cour ses/67142/assignments/223155
Oct 18 th
, 2021 Group 3,000 words 30%
Presentation, 10-15 slides (10%) https://myuni.adelaide.edu.au/cour ses/67142/assignments/223153
Oct 22 nd
, 2021
2 Risk Management Plan https://myuni.adelaide.edu.au/cour ses/67142/assignments/223154
Oct 18 th
, 2021 Individual 2,000 words 30%
Total 60%
169
Plan for Assignment 1 – Risk Register • Form the group or corum (4-5 students) of your choice or take the help of the course
coordinator if needed – Pre-Prep Activity
• Select a project of your choice (this can be made-up project or project from anyone from the group)
• Plan and Decide on when, where and how to engage, who will do what...
• Engage at mutually convenient times for group discussions – for instance...a) context b) project Identification of Risks, c) Risk Analysis & evaluation and d) Treatment of Risks (Pass 1), Treatment of Risks (Part 2), Final consolidation etc
170
Tips for Assignment 1 – Risk Register
• Follow the ISO 31000 process as taught in class, use the approach of AS/NZS/ISO 31000:2009 • Develop a risk register with 50+ risks using the template in MyUni • Don't restrict to 50 risks Only, more allowed! • Use appropriate KPIs or CSFs in the register. • Don't stop with single pass treatments for the risks, use the power of corum (group) to
do multiple passes to achieve ALARP. • Use appropriate sentence formation to state risks, causes and consequences in the
register for e.g. Risks - "failure to achieve X" or "there is a risk that X..."… Cause - "Because of Y" Consequence - "with the consequences that Z" • Don't forget to use and depict the phase wise – risk (cost) burndown chart.
171
Assignment 1- Risk Register Template in My Uni...
172
Tips for Assignment 1 – Group Presentation • Develop and Present it inventively using PowerPoint • Diagrams are great and sometimes better than slides full of words! • Time limit 12-15 minutes - very important • It is expected that students will use a PowerPoint file format. • Use a University/school template • Have a cover slide • Provide clear headings • Only include key points • Keep all items concise • Provide any diagrams, tables, charts, etc. • Try to make the slides interesting!
173
Tips for Assignment 1 – Group Presentation • Make sure you present it as a group • Involve every-one in group to present a bit of the presentation • Present professionally • Practice...Dry Run... • Cover presenting both Risk Management Plan & Risk Register • Focus on the chosen project/context • For Adelaide based students or in-class groups involving 1 or 2 online students • You need to present in the class, followed with Q&A session
• For any Groups with only Non-Adelaide based students • You may choose to provide a Voice-Over (your audio) to your presentations and do not
need to physically present online • You will post the Audio (Voice-over) based PowerPoint files on the Discussion Forum for
students to view and make any comments or ask any questions. 174
Day 3 & Day 4 - Presentation Days!
• Please take note of the following… • Come prepared with your presentation on a memory stick • Presentation Groups/Timings will be pre-planned/scheduled • A set of group presentations will happen on Day 3 and a set of group
presentations will happen in Day 4 • There will be no particular order for group based presenters • Each group of presenters will have 12-15 minutes to present and a
couple of minutes to answer questions -Ensure your talk is concise and to the point. • There is no need to dress formal • I will assess your presentations in class
175
Assignment 2 - Risk Management Plan/Report Individual assignment
The Risk management plan covers: • Introduction to the project • Introduction to Risk Management method/approach • Application of Risk Management Process to the project (ISO 31000)
a. Establish context b. Risk identification c. Risk analysis d. Risk evaluation e. Risk treatment f. Communication and consulting. Monitoring and review
Note: • a) to e) – Leverage Information for the report from the Risk register (Assignment 1) • In addition, describe and articulate the plan for Risk Appetite, Risk Tolerance, Risk Owners, Risk Review
• Discuss and Review the top 10 risks • Conclusion/Summary of findings • In addition, make comments in conjunction with findings from variance modelling spreadsheet
176
Tips for Assignment 2 - Risk Management Plan/Report • Leverage the information required for the report from the risk register and group
interactions/ISO 31000 process know-how from Assignment 1.
• Prepare the document in a clear, professional and concise format
• Treat it as if you are addressing a client audience • Think of what information is important to the client • Use the correct language/professional tone
• Don't make any calculations and graphs too complex!
• References are minimal, Its not a literature review, its a plan/report.
• It is recommended that you follow the method/framework used in the lectures 177
Pre-Prep (In-class) Activity for Group Assignment 1 • Group Formation (4-5 Students) • Make your own choice • Take Lecturer help if needed J
• Give an appropriate 'name' for your groups and register with the course coordinator/lecturer - the name of the group, a group lead/contact, the group members engaged and when the group is interested to present on day 3 or day 4
• Have a short group meeting with your group on the choice of Project and how to go about the risk assessment for the project/assignment 1 over the coming weeks (Target date of Assignment 1 submission Risk Register - Oct 18th and Presentation Oct 20th or Oct 22nd).
This Photo by Unknown Author is licensed under CC BY 178
Use of the Variance Modelling ‘Spreadsheet’ in MyUni
179
Purpose of Variance Modelling Spreadsheet
• A Tool for getting numerical information that can be fed into Risk Management Plan/Report
• A Tool that can be used for Verification
• A Tool that can help you draw more insights into your Assignment 1 & 2
180
Snapshot of Variance Modelling Spreadsheet
181
Manipulating the Spreadsheet • Use given risks or enter your own risks from WBS
• Manipulate column F (subjective probability from 0-1)
• Where column F has value less than 1,
• Manipulate column H, variation in cost in $M
• Manipulate column J, variation in schedule in weeks
• You may change column D to obtain responsibility profile
• Drivers to be cost and schedule, X may be used; to be designated by you
• Both cells (I7 and K7) for variance should be close to ‘0’
• Is this realistic or idealistic? Can it be managed?
• If you Allocate risks to human resources? It can show impact on recruitment issues... 182
Schedule Risks Note: The top 10 risks amount to 60% of the total
21%
21% 13%9%
9%
7% 6%
5% 3% 3% 3% 0%
Schedule risks
34 Lack of understanding of main search engines 45 Customers systems not adequately understood 1 Failure to have adequate political support in the company 3 Requirements not canvassed among all stakeholders 33 Lack of experience of range of customers software 7 Inability to get team face to face through overseas travel 20 Evaluation criteria not properly defined
21 Evaluation criteria not properly defined
2 Evaluation criteria not properly defined
183
Accountability for Schedule Risks
16%
7%
15%
45%
3%
9% 4% 1% WSD
Team
SPD
PM
MPD HPD
Company CEO
184
Drivers of Schedule Risks
SPD
9%
28%
63%
X
S
P
185
Controls on Schedule Risks M
L
10%
90%
186
Interpretation/Treatment of Top Schedule Risks
• Most schedule risks are under LOW control, with the majority of drivers being people based
• The PM is responsible for a large proportion of schedule risks • The lack of understanding of the customer's processes is a theme across two risks
• Lack of correct specification of B2B, evaluation criteria and addressing requirements among stakeholders are also issues
• The people are also the largest drivers
187
Treatment of Schedule Risks
Treatment • Define a process for understanding customers, evaluation criteria, addressing
requirements among stakeholders and B2B processes
• Train the staff
• This is to be managed by XX
• The cost is $YY
• It should be completed by month ZZ
188
Use of the ‘Spreadsheet’
Additional Slides (to be reviewed by students)
Optional – In Class Exercise
Discuss among groups on the drivers, risks and related consequences impacting Stakeholder Satisfaction and
Performance and Suggest Appropriate treatments
189
Stakeholder Satisfaction Risks (a) 12
(b) 12
(c) 10 (d) 8
(e) 7.5
(f) 6
(g) 6
(h) 5 (i) 4.5 (j) 4
(a) Key functionality misunderstood
(b) Lack of experience of range of customers software
(c) Requirements not canvassed among all stakeholders
(d) Lack of availability of key designers
(e) Lack of understanding of main search engines
(f) Lack of experience of range of customers' software
(g) Evaluation criteria not properly defined
(h) Customers systems not adequately understood
(i) Lack of availability of key designers
(j) Revision due to lack of panache
Note: The top 10 stakeholder satisfaction risks cover 56% of the total
190
Stakeholder Satisfaction Drivers
40%
60%
Systems
People
191
Stakeholder Satisfaction Controls
Low
Medium
65%
35%
192
Stakeholder Satisfaction Treatment • A picture similar to Schedule emerges with the people and
systems responsible
• Looking at Driver 2 helps us understand the People issues better - Skills are seen as the main issue, with some Recruitment problems
Diagram: Stakeholder Satisfaction Driver 2
31%
69% Recruitment Skills
193
Stakeholder Satisfaction Treatment
• Define skills required more carefully for HR people and get technical people to sit in on interviews of new staff
• Define training process
• Allocate responsibility for actions
• Allocate budget and schedule
194
Performance Risk Treatment
• Have treatment processes for Schedule and Stakeholder Satisfaction reduced risks for Performance adequately?
• If not, conduct a similar risk treatment process for Performance
195
Overall Series 2 Analysis
• Assume the treatment actions have been put in place
• Then re-analyse the risks and see how the Variances for the Critical Success Factors are reduced
• Remember Variance = Sum of Risks Tolerance
• Are the new Variances acceptable?
• This is powerful as no funds have been spent yet on the real project, only on analysis
196
Some Rules in using the Risk Model • Ensure critical success factors or KPIs are mutually exclusive, as far as possible
• State risks in verb form, such as "failure to achieve Completion on time" "failure to achieve Optimized trading position"
• Controls are stated as a guide to assist your judgment of likelihoods • Likelihoods are best based on past results; however, if you are estimating these, ask yourself
the question "If I did this ten times a year, how many times would the risk event?"
• Try to work down columns e.g. the most likely consequence, and then the likelihood of this occurring- less consistent if you balance likelihoods and consequences in the same row
197
Some Rules in using the Risk Model (cont’d) • In assessing controls, the following is a guide
• High: good people, good systems and audited processes • Medium: good people and good systems • Low: good people or good systems • Negligible: poor people and poor systems
• Controls are identified to provide uniform judgments on consequences and likelihood
• When the likelihoods and consequences have been assessed, and the products calculated, add the Risk Levels by arithmetic summing
• Compare the summed risks with the tolerance you previously required
• Treat the risks
• Re-assess the sum of the risks, assuming the treatment has occurred, and see if the result is below tolerance
198
Plan/Key Dates for the next few weeks & after... ØSelf Reflection on Day 1 & Day 2 Presentation/Activities
ØEngage with your group and complete/submit Assignment 1 – Risk Register
ØEngage with your group to prepare/present Assignment 1– Group presentation
ØWrite-up/Submit Individual Assignment 2 – Risk Management Plan on Oct 18th
ØDeliver Group Presentation + Attend Session 2, Day 3 & 4 – Oct 20th & Oct 22nd
ØWrite up/Submit Assignment 3 – Systemic Risks by Nov 15th, 2021 199
200
Let's meet again on Oct 20th and 22nd for Day 3 & 4... "Risks are their, lets be aware..."