Risk Management
2
Design and Coffee Risk management 1
Format:
1. Establish the project's priority matrix (constrain, enhance, accept).
2. Identify a minimum of 10 project risks and when each will occur in the project life cycle, and then determine their impact and probability of occurrence.
3. Create a matrix similar to the one below:
Make sure that it is consistent with your priority matrix, or use the risk management process in the Practitioner section that is on page 3 of this Doc
4. Justify the use of your risk-scoring matrix or use the risk management process in the Practitioner that is on page 3 of this doc
5. Assess your risks according to your matrix.
6. Rank the risks according to their total risk score.
7. Prepare the Risk Response Matrix for each risk—Risk, Response, Contingency, Trigger, Responsible Person—Using the Risk Management Analysis Template that is on page 2 of this Doc.
Deliverables:
· Use the Risk Management Analysis Template spreadsheet (risk management analysis template.xls) found as an attachment named Risk Matrix (there is a separate tab for each portion of the risk management plan) or use the risk management process in the Practitioner on page 3 of this Doc.
· If working in a team, include a statement of participation, describing how each person contributed to this project deliverable. Please have each person sign the statement.
|
Practitioner Corner |
|
Project Management practitioners generally take a slightly different view of risk on a project than we have seen above. To begin, risks are not necessarily bad. A project has both good and bad risks which are referred to as positive and negative risks. Some use the terms opportunities and negative risks to differentiate the two. For positive risks the project manager may chose to attempt to make them happen or do nothing at all. Conversely, for negative risks a project manager may chose to prevent them from happening or do nothing at all. What action a project manager may take depends on a number of things. In the practitioner world, risk management is a stepwise process. In step one, we do this; in step two, we do that. So it is often best to describe the process in a stepwise fashion as shown below: 1. Plan Risk Management. In plan risk management, we review the following areas of risk management. · Methodology. In this section, we determine how we will perform the following sets of the risk management process. The risk management process allows the project manager some latitude in how to perform various steps of the process. Here we review this and decide how to proceed. · Roles and Responsibilities. In this section we denote who is responsible for what steps within the risk management process. · Budget. How much are you willing to spend to do this process? · Schedule. When and how much time are you planning on devoting to risk management? · Risk categories. How do you plan on subdividing risks for ease of understanding? · Definitions of Risk and impact. Here you create the rating system that you will use later to rate your risks. This ensures that all team members understand and are rating risks in the same manner. · Stakeholder Tolerance. How much risk are the stakeholders willing to accept on this project?
2. Identify risk. In this step we begin to identify both positive and negative risks associated with our project. There are a number of methods recommended to do this. These include brainstorming, Delphi, nominal group, interviewing, SWOT, fishbone diagramming, checklist analysis, and assumption analysis. The output of this step is called a risk register, which, simply put, is a list of identified risks
3. Qualitative Risk Analysis. In this process, we rank our risks. We examine the impact and the probability of each risk. Impacts and probabilities are listed on a scale of either one to three, one to five, high to low, or very high to very low. Below is an example of a very high to very low scale. Each risk is rated based on its impact and probability to give it a color code. Red risks usually require a proactive response, Yellow risks usually require a contingency plan, and green risks are placed on a watch list because they are too low in impact or probability to require an action plan.
4. Quantitative Risk Analysis. In this step we further analyze our red risks from qualitative risk analysis. In this way we further refine which of the red risks are the most important to do something about. There are a number of methods available to perform this step, such as simulations, expected monetary value, and decision trees.
5. Plan Risk Responses. Now that we have analyzed our project’s risks, it is time to plan proactive and reactive response plans for those risks needing them. In the practitioner world, there are a number of possible responses for a positive risk and a number of possible responses for a negative risk. Let’s start with the positive risks. · Exploit. Exploitation ensures that the positive risk will occur. Work is added to the WBS to ensure that the risk occurs. · Enhance. Enhance means just that: enhance the probability of the risk occurring or enhance its impact should it occur. · Share. Partner with another party to help ensure that the risk occurs. · Active Acceptance. In active acceptance, no proactive action is taken to increase the likelihood that the risk will occur. However, a contingency plan is created so that, should the risk occur, the project team will be ready to take advantage of it. · Passive Acceptance. In passive acceptance, nothing proactive or reactive is done concerning this risk. This method is usually reserved for green risks on the risk register. Now let's look at negative risk responses. · Avoid. To avoid a negative means to prevent the risk from happening in the first place. This is usually done by removing the work from the WBS in which the risk would have occurred. · Mitigate. To mitigate means to lessen the impact or lessen the chance the risk will occur. · Transfer. To transfer a risk means to transfer the responsibility for that risk to a third party. This is normally accomplished by buying insurance or hiring contractors to do the work. · Active Acceptance. In active acceptance, no proactive action is taken to increase the likelihood that the risk will occur. However, a contingency plan is created so that, should the risk occur, the project team will be ready to take advantage of it. · Passive Acceptance. In passive acceptance, nothing proactive or reactive is done concerning this risk. This method is usually reserved for green risks on the risk register.
6. Control Risks. In this final process, the project manager monitors the project to ensure that the risk plans and responses are working to assist in the project’s success. We do this through project status meetings, risk audits, risk reassessments, and the creation of workarounds. A workaround is a plan created for a newly discovered risk. |
7.1 RISK MANAGEMENT: FOUR-STAGE PROCESS
Systematic risk management comprises four distinct steps:
· • Risk identification—the process of determining the specific risk factors that can reasonably be expected to affect your project.
· • Analysis of probability and consequences—the potential impact of these risk factors, determined by how likely they are to occur and the effect they would have on the project if they did occur.
· • Risk mitigation strategies—steps taken to minimize the potential impact of those risk factors deemed sufficiently threatening to the project.
· • Control and documentation—creating a knowledge base for future projects based on lessons learned.
Risk Identification
A useful method for developing a risk identification strategy begins by creating a classification scheme for likely risks. Risks commonly fall into one or more of the following classification clusters: 3
· • Financial risk—Financial risk refers to the financial exposure a firm opens itself to when developing a project. If there is a large up-front capital investment required, as in the case of Boeing or Airbus Industries’ development of a new airframe, the company is voluntarily assuming a serious financial risk in the project. Construction companies building structures “on spec” provide another example. Without a contracted buyer prior to the construction, these companies agree to accept significant financial risk in the hopes of selling office space or the building itself after it is completed.
· • Technical risk—When new projects contain unique technical elements or unproven technology, they are being developed under significant technical risk. Naturally, there are degrees of such risk; in some cases, the technical risk is minimal (modifications to an already-developed product), while in other situations the technical risk may be substantial. For example, TRW, now part of Goodrich Corporation, recently developed a modification to its electronic hoist system, used for cable hoists in rescue helicopters. Because the company had already developed the technology and was increasing the power of the lift hoist only marginally, the technical risk was considered minimal. The greater the level of technical risk, the greater the possibility of project underperformance in meeting specification requirements.
· • Commercial risk—For projects that have been developed for a definite commercial intent (profitability), a constant unknown is their degree of commercial success once they have been introduced into the marketplace. Commercial risk is an uncertainty that companies may willingly accept, given that it is virtually impossible to accurately predict customer acceptance of a new product or service venture.
· • Execution risk—What are the specific unknowns related to the execution of the project plan? For example, you may question whether geographical or physical conditions could play a role. For example, developing a power plant on the slopes of Mount Pinatubo (an active volcano) in the Philippines would involve serious execution risks! Likewise, poorly trained or insufficient project team personnel might constrain project execution. Execution risk is a broad category that seeks to assess any uniquecircumstances or uncertainties that could have a negative impact on execution of the plan.
· • Contractual or legal risk—This form of risk is often consistent with projects in which strict terms and conditions are drawn up in advance. Many forms of contracted terms (e.g., cost-plus terms, fixed cost, liquidated damages) result in a significant degree of project risk. Companies naturally seek to limit their legal exposure through legal protection, but it is sometimes impossible to pass along contractual risk to other parties. For example, most U.S. railroads will not accept penalty clauses for late deliveries of components because they have an almost monopolistic control of the market. Therefore, organizations utilizing rail transportation must accept all delivery risk themselves.
Risk Management Plan
Version 6: 06/28/11 Page 1 of 6
Project Name: DAS Network Build-out Project Description Summary: This project is to provide a build out of the DAS Network
in Chicago. It requires new building infrastructure, negotiations with the City of Chicago, and coordination with various suppliers and vendors.
Project Manager: DeVry Faculty Date: May 22nd, 2005 Revision Number: 1
a. Risk Identification I have made a list of all areas that might cause project delays or failure with their respective outcomes (see numerical list below). The five risks I have chosen as key risks are bolded below and appear in the Risk Assessment Table in question “b”
1) Delay or denial of final franchise agreement with the city – this could cause the project to stop or require negotiation with another entity (e.g., ComEd).
2) City site permitting process to cumbersome and requires longer than 72 hours per submission for standard configurations – this could expand the commercial launch date significantly.
3) Carrier/Customer Delay in License Agreement – This could delay or prevent the capital funding required to begin construction and significantly impact the entire timeline.
4) Lack of Infrastructure Availability – This is the lack of connectivity and transport points within the city owned infrastructure which will require the identification of a new path or the installation of new infrastructure. This will increase cost and project completion time.
5) Delays in construction due to city operational events – City operations, construction, road repair and maintenance, water main breaks, parades, sports events, conventions. These can all cause changes in the construction and installation schedule.
6) Labor Unions – Chicago is a union labor intensive environment. We will be utilizing both skilled and unskilled labor to perform the construction and installation tasks. There may be an issue on tasks that are scheduled to be performed by specialized labor that utilizes non-union employees.
7) OEM Equipment availability – the DAS equipment that we utilize is specialized fiber-optic repeater equipment that is manufactured and shipped from Sweden. Any delays due to customs or manufacturer inventory shortfalls will delay the project timeline.
8) Power plant installation issues – commercial power to all network elements is provided by ComEd. This entity is notorious for introducing delays in fulfilling orders for commercial power connections in the outside plant network.
9) Coverage Shortfalls – Once the equipment is installed and commissioned for operations coverage testing is completed. If the coverage does not meet the design specification ClearLinx will be required to correct and rectify at it’s cost and there are potential time delay risks.
10) Fiber Optic Network installation quality failures – the fiber cable network must be optimized and tested following installation to meet a specific signal level. If the level is not met ClearLinx will be required to re-splice new fiber points to ensure they achieve the proper quality level.
Risk Management Plan
Version 6: 06/28/11 Page 1 of 6
Project Name: DAS Network Build-out
Project Description Summary: This project is to provide a build out of the DAS Network
in Chicago. It requires new building infrastructure,
negotiations with the City of Chicago, and coordination
with various suppliers and vendors.
Project Manager: DeVry Faculty
Date: May 22
nd
, 2005 Revision Number: 1
a. Risk Identification
I have made a list of all areas that might cause project delays or failure with their
respective outcomes (see numerical list below). The five risks I have chosen as key risks
are bolded below and appear in the Risk Assessment Table in question “b”
1) Delay or denial of final franchise agreement with the city – this could
cause the project to stop or require negotiation with another entity (e.g.,
ComEd).
2) City site permitting process to cumbersome and requires longer than 72 hours
per submission for standard configurations – this could expand the commercial
launch date significantly.
3) Carrier/Customer Delay in License Agreement – This could delay or prevent
the capital funding required to begin construction and significantly impact the
entire timeline.
4) Lack of Infrastructure Availability – This is the lack of connectivity and
transport points within the city owned infrastructure which will require the
identification of a new path or the installation of new infrastructure. This will
increase cost and project completion time.
5) Delays in construction due to city operational events – City operations,
construction, road repair and maintenance, water main breaks, parades, sports
events, conventions. These can all cause changes in the construction and
installation schedule.
6) Labor Unions – Chicago is a union labor intensive environment. We will be
utilizing both skilled and unskilled labor to perform the construction and
installation tasks. There may be an issue on tasks that are scheduled to be
performed by specialized labor that utilizes non-union employees.
7) OEM Equipment availability – the DAS equipment that we utilize is specialized
fiber-optic repeater equipment that is manufactured and shipped from Sweden.
Any delays due to customs or manufacturer inventory shortfalls will delay the
project timeline.
8) Power plant installation issues – commercial power to all network elements is
provided by ComEd. This entity is notorious for introducing delays in fulfilling
orders for commercial power connections in the outside plant network.
9) Coverage Shortfalls – Once the equipment is installed and commissioned for
operations coverage testing is completed. If the coverage does not meet the
design s
p
ecification ClearLinx will be required to correct and rectify at it’s cost
and there are potential time delay risks.
10) Fiber Optic Network installation quality failures – the fiber cable network must be
optimized and tested following installation to meet a specific signal level. If the
level is not met ClearLinx will be required to re-splice new fiber points to ensure
they achieve the proper quality level.