What Is Risk Identification? Definition and Tools
Robust risk management techniques help organizations succeed by helping them keep risks to
their objectives under control. Risk identification is a crucial part of that control process because
the better you identify potential risks, the better you can respond to them. If your position
involves risk management, you might want to learn the different ways to identify and moderate
an organization's risks.
What is risk identification?
Risk identification is the process of documenting any risks that could keep an organization or
program from reaching its objective. It's the first step in the risk management process, which is
designed to help companies understand and plan for potential risks. Examples of risks include
theft, business downturns, accidents, lawsuits or data breaches.
When you identify risks, look for events that may prevent a project from achieving its goal. The
risk's origin can be the project itself or external sources. There are several situations for which
you might need to identify risks, including:
• To support an investment decision
• To assess cost uncertainty or operational costs
• To analyze multiple alternatives
• To test a program before its acquisition
Why is risk identification important?
Risk identification allows businesses to prepare for potential harmful events and minimize their
impact before they occur. It involves not just determining the possible risks, but also
documenting and sharing them with stakeholders. This documentation serves as evidence of the
company's risk management strategy.
Ways to identify risks for a project
Here are some risk identification tools and techniques to identify risks:
Documentation review
Reviewing project-related documents like project files, plans and other information is a common
way to identify risks. It involves studying the project documentation for accuracy, completeness
and consistency. Inaccurate, incomplete or missing information and inconsistencies could
indicate risks. For example, you could discover a scheduling error that might affect when your
new inventory arrives at your warehouse.
The list of documents that can be involved in that review include:
• Project schedule
• Project charter
• Procurement plan
• Project scope statement
• Cost estimates
• Work Breakdown Structure (WBS)
Brainstorming
Brainstorming comprises gathering a group of people to talk about the project. You provide the
topic of the discussion, and everybody can share their perspective. Discussing the potential
challenge s with other company employees, executives or managers can help you identify risks.
Interviewing
You can interview stakeholders, project participants or experts to identify risks. In contrast with
the brainstorming, you direct questions about the project and usually conduct interviews one-on-
one. There are two types of interviews:
• Structured interview: You ask a specific list of questions you prepared in advance.
• Unstructured interview: You discuss the topic without a pre-defined list of questions.
SWOT analysis
A SWOT analysis analyzes a project's strengths, weaknesses, opportunities and threats. By
understanding where the project might be vulnerable, you can discover potential risks and plan
accordingly. For example, if you realize that your company's main supplier is located in an area
where hurricanes are common, you can try to avoid placing large orders during hurricane season
or contact a backup supplier in a different area.
Root cause analysis
Root cause analysis is a systematic method you can use to determine a problem's primary cause
and develop a way to address it. Here are the main steps to perform root cause analysis:
1. Specify the problem.
2. Collect data.
3. Determine the causal factors, meaning those that led to the issue.
4. Define which factors are root causes and which are simply symptoms.
5. Identify actions to correct the problem.
6. Find solutions that can stop the problem from happening again.
7. Execute the solution.
Root cause analysis is a tool that can promote an organization's continuous improvement if used
frequently.
Employee feedback
The employees' perspective of an organization can help identify risks because it's often different
from that of upper-level management. For example, there might be a risk of injury because of
insufficient training on a machine. The employees using the machine may notice the need for
additional training before their supervisors.
Assumption analysis
You can identify several assumptions of the project or program. Then, you determine if they are
valid, meaning if you can prove them to be true. You may have guessed a few times while
making decisions for your project. Perhaps you assumed that your supplier has the inventory you
need in stock or that your warehouse has enough space to store your new shipment. These
guesses are called assumptions. Inaccurate or inconsistent assumptions can present risks for the
project.
You can record and track the assumptions throughout the project's lifecycle in a document
known as the assumption log. Every project's team member is responsible for gathering
information to validate one or several assumptions.
Risk register
A risk register is a document that you can regularly update throughout the project's life cycle. It
includes:
• Risks
• Root causes of risks
• Potential responses
• Updated risk categories
Monte Carlo analysis
This is a mathematical modeling technique that helps determine a potential risk's probability and
impact. The objective of the Monte Carlo analysis is to observe what would happen if the project
didn't go as planned time and schedule-wise using a computer to run countless simulations.
Using numbers that fit predetermined criteria, the computer simulates various situations with a
different cost and schedule to determine the chances of completing a project for a particular cost
and on a specific date.
Decision tree
A decision tree is a diagram that you can use to clarify and solve a problem. It considers several
future possible events and analyzes them at one point in time, helping you to explore the
different alternatives one decision can lead to. Each branch on the decision tree represents a
possible decision or event while the leaves depict possible outcomes. The decision tree allows
you to visualize the relationship between various events and consider possible advantages and
disadvantages before making a decision.
What is the risk identification life cycle?
The risk identification life cycle is a description of the activities to do and tools to use during the
first step of risk management. Risk is the uncertainty linked to a project's accomplishment.
Project manager guides usually propose a structured method for risk management. Risk
identification can also benefit from a structure that helps project managers decide what tool to
use and when. The risk identification cycle defines phases of the process. The risk identification
life cycle helps project managers make decisions.
Here are the phases of the risk identification life cycle:
1. Risk statement
The risk identification process requires determining the list of risks progressively and describing
them. When you write the information down, it's called a risk statement. A risk statement
describes what may happen, why it's happening, during what timeframe it may occur and its
potential impact on the objective. It's also best if you specify the nature of the risks.
2. Basic identification
The basic identification phase consists of answering two questions:
• Why or why not? You can respond to this question with a SWOT analysis.
• Where did you see that before? To answer this question, you can compare current
projects with past ones and try to learn from previous experience.
3. Detailed identification
This phase aims to dig deeper into the risks you identified in the first phases. Four tools can help
you do that work:
• Brainstorming
• Interviewing
• Document reviews
• Assumptions analysis
4. External cross-check
Now that you gathered a list of risks based on your project team's ideas and knowledge, it's time
to expand your list. External cross-check is a phase that can help you find out if there is relevant
information available outside the project. Here are two tools that can help you perform external
cross-checking: checklists and categories.
• Checklists are a list of standard industry risks, their causes and usual consequences. They
usually present possible solutions, too.
• Categories are lists of risks organized by groups that can contain sub-categories. An
example of a method to create categories is the “Risk Breakdown Structure” or RBS.
With this approach, you place each risk in a category. Examples of categories include
technical, operations, marketplace and planning. Then you break each category down
further.
5. Internal cross-check
The first step of internal cross-check is mapping to a work breakdown structure, or WBS, a
project document that lists the steps required for the project's completion. When you're
identifying risks, first determine which WBS element relates to the risk from your list. For
example, if your advertising team is creating a new label, a potential delay might affect when
you can ship your products.
6. Statement finalization
To finalize your risk statement, the next step is to determine if there are missing elements.
Reread the document and double-check statements for accuracy. It may be helpful to have a few
additional team members read the statement as well.