1 / 8100%
Running head: RISK MANAGEMENT
1
Jonathan Embry
BUSI 415-B01
Professor Clara Spenny
RISK MANAGEMENT
2
Risk Management
Risk management is the processes that allow a project manager to identify, analyze, and
respond to any risk that might arise throughout a project. In traditional projects this knowledge
area is very important to understand how the team must work to mitigate a potential or eminent
risk. Risk can be unpredictable and many times they are. The AMA Handbook of Project
management says that the term risk can be misleading because it implies a control of events
(Dinsmore, 2011). Risk management should be a preparation for events that could happen rather
than a method or process that just reacts to events as they occur. The knowledge area should be
started through detailed understanding of the project scope, timeline, and budget. This will allow
the project manager to decide on how to conduct/respond to risk management related activities.
Then the project manager must identify the risks, perform qualitative and quantitative risk
analysis, plan risk responses, and control the risks.
Plan Risk Management
Risk Management does not start by identifying risks of the project. Instead, a plan that
tells the team and the project manager how to deal with risk management activities is created.
This includes detailed understanding of the project charter, the stakeholder register, and the
overall project management plan. Through this knowledge and help from board members,
project stakeholders, industry experts, and outside consultants a plan can created correctly on
how to deal with the potential or eminent threats of the project. This is truly a team effort. The
main output of this process is the Risk Management Plan. This plan tells the project team and
the stakeholders how the risk management operations will be formulated, structured, and dealt
with. It lists out the responsibility of every team member and what their job is to mitigate risk
while explaining how the risk management operations will be funded. In addition, the Risk
RISK MANAGEMENT
3
Management Plan analyzes different risk categories and defines the probability of each one. By
doing this the team can see what the impact of each risk would be. This analysis can be
compared against the stakeholder’s tolerances and adjusted as necessary through tracking and
reporting methods. Overall this is a crucial first step in Risk Management.
Identify Risk
Once the team has created a Risk Management Plan they can begin to determine what the
risks of the project are and how each one will affect the project. This process requires
understanding of all project documents to accurately determine what the risks are and the affect
of each one. To gather all the information necessary to identify risks many methods are
recommended. The most effective ways are the Delphi technique, root cause analysis, and
brainstorming. The Delphi method is a great way to gather information through conclusions of
industry or project experts anonymously, reducing bias and focusing on pure and accurate
results. Root cause analysis is a basic method that allows the team to identify a problem, why it
happens, and what the team can do to fix it. This technique is good for identifying obvious risks
and formulating a preventative action. Lastly, brainstorming is the most common of these
methods because it is the easiest to conduct. Through the use of a meeting people are able to
help compile a list of potential risks. From that it is important to sift through and find the most
impactful risks and work to mitigate or solve them. Another great tool for identifying risk is the
use of a SWOT analysis. A SWOT analysis will quickly deliver a document that lists the internal
strengths and weaknesses of the company, while presenting the top external opportunities and
threats to the project. The internal and external data can be crosschecked to see if any
weaknesses will turn to threats as well as how to leverage any strengths with the opportunities or
against the threats. The main output of this process is the risk register. This document contains a
RISK MANAGEMENT
4
comprehensive list of all identified risks. It explains the impact of the risk while also showing
the cause and effect of each one. It also presents the potential risk as well. This provides
information to properly prepare and respond to any major potential risks.
Perform Qualitative Analysis
This process uses the Risk Management Plan, risk register, and the scope baseline to
present any current or potential risks. There are a few tools that allows the project manager to
analyze the risks qualitatively. The first is a risk probability and impact assessment. This is a
basic measurement comparing all risks and rating them and their level of impact. A probability
and impact matrix can be used for this. Using the y axis as a means to measure probability form
0-100% and the x axis for impact a simple matrix can be performed to compare all of the risks
probabilities to their impacts while comparing each risk to another. It is important that the data
used for each risk is valuable, so the team must conduct a risk data quality assessment. Next,
they should categorize each risk to properly determine what segment of the project the risk will
impact the most. Finding the root cause and knowing what the risk will impact will help mitigate
and solve the problem. All of this work will allow the project manager to update the risk register
and make necessary updates to all of the project documents.
Perform Quantitative Analysis
Like the qualitative analysis this type of analysis considers all the project documentation
especially the Risk Management Plan and the Risk Register. Tools to complete quantitative
analysis include data gathering from past experiences and historical events. Using these will
help with estimations and give examples of certain risks’ impacts and probability. Another way
is to conduct sensitivity analysis through a tornado diagram which allows the team to measure
RISK MANAGEMENT
5
each risk against each other using monetary values. By reviewing the cost and probability of
each risk a Cost Risk Simulation can be completed. This is helpful when choosing to work
around a risk, through the risk, or choosing to mitigate the risk. When doing these analyses, it is
important to always seek an expert’s opinion because they might have knowledge that will
benefit the project by knowing how to avoid a risk through past experience or through study.
The major output of this process is the project document updates and quantifiable results about
each risk. It presents trends that can be used to recognize the formation of a risk while
presenting a detailed cost risk analysis.
Plan Risk Responses
This process puts together all the previous processes to formulate a plan that will help to
“enhance opportunities and reduce threats” (PMBOK, 2013, p. 342). To plan risk responses, one
must consider the Risk Management Plan and the Risk Register. These two inputs will help
understand the risks, the causes, and the impacts so a plan can be made in response to them to
mitigate or avoid them. Each risk must be evaluated and separated into negative risks or threats
and positive risks or opportunities. In a negative situation the Project team must determine
whether the risk should then be avoided through a change in the project management plan,
transferred by shifting the impact to a third party, or accepted by not taking action until the risk
actually occurs. In a positive situation, the project team must either exploit the risk by ensuring
the opportunity is acted upon, enhance the risk by increasing the probability of the positive risk
opportunities, share the risk through partnerships or joint ventures, or accept the risk by taking
advantage of the opportunity when it presents itself during the project. The major output of this
process is project document updates and a full plan to respond to all risks of the project.
Control Risks
RISK MANAGEMENT
6
Control Risk is the final process of this knowledge area. It is the compilation of all the
prior processes to evaluate and monitor all risk management activities. To do this process the
project manager can implement a risk reassessment which can allow new risk to arise, so the
team can adjust the Risk Register, and Risk Management Plan. They can also perform risk audits
that will measure how effective each risk response is. Another tools include trend analysis and
variance analysis which will help conduct EVM calculations to understand how well the project
is performed and how well the response is working compared to the plan. Lastly, this process
produces many of the final updates to the project documents while also producing change
requests and providing work performance information. These documents are important for
corrective or preventive action to take place.
Risk Management in Agile
An agile project is much different from a traditional project. The agile risk management
plan takes less time to complete by doing so the team can focus on the project work. This might
seem that the risks are not properly identified, but all it means is that the risks aren’t as
documented. They are listed through the use of sprint meetings, and each risk is mitigated due to
the iterative processes of the project. This is because iterations naturally mitigate some of the
risks. Basically, the agile project manager spends less time documenting the risks and spends
more time looking at ways to avoid the risk from the beginning of the project. The agile project
“takes on a more active and reactive role which is important to factor into daily activities”
(Runcie, 2018). This involves the use of a specific risk manager whose job day to day is to find,
analyze, and debunk risks as they arise in the project.
Biblical Integration
RISK MANAGEMENT
7
The story of Gideon paints a decent picture of risk management in the Bible. In Judges
6-8 we see that Gideon is faced with a task—to tear down all of the alters of Baal. However, he
is faced with many risks. Should he do this in the middle of the night or in the day when
everyone could oppose him. He chose to do the act in the middle of the night and in doing so he
mitigated the risk of being opposed during the day. He did not get rid of all of the risk. He knew
that in the morning he would be reprimanded for the things he had done in the night time.
Gideon completed the task and knew that the reward of serving the Lord significantly outweighs
the risks of the punishment of man. I think this applies to our day to day life as well. If we were
to live in a way that is to solely serve the Lord we would be much quicker to take on risks such
as judgement, persecution, and rejection. Lastly, it is important to stay reminded that a life
eternal far outweighs the temporary life of this earth. Knowing this will allow us to live in a way
that is less fearful of the risks of judgment, persecution, and rejection because of our faith in
Jesus.
Conclusion
Risk management is the process of planning for risk, identifying specific risks, analyzing
the risk, responding to and controlling the risks of a project. It is important to understand the
difference between an agile project and a traditional project, so that you may be able to better
prepare the team for risk management activities. In a traditional project the activities are very
linear, but in an agile project the risk management activities are very dynamic which requires less
planning. A complete understanding of the project and project documents is required to conduct
thorough and complete risk management activities no matter what kind of project is being
conducted.
RISK MANAGEMENT
8
References
A Guide to the Project Management Body of Knowledge: (PMBOK® guide) (5th ed.). (2013).
Newtown Square, PA, USA: Project Management Institute.
Dinsmore, P. (2011). The AMA Handbook of Project Management. New York (New York):
American Management Association.
Runcie, T. (2018). Home. Retrieved from https://pmi-portland.org/resources/newsletter-article-
archive/675-risk-management-agile-v-waterfall
Students also viewed