For Kim Wod- Bus519 Project Risk Management - week 4 Assignments

profilealozot1
figure_a-1-_risk_management_plan_template.docx

Templates and Examples

<TEMPLATE> RISK MANAGEMENT PLAN FOR THE <PROJECT NAME> PROJECT

Prepared by: <Project Manager> Approved by: <Project Sponsor> Reference: <> Version: <> Date: <>

INTRODUCTION

This document is the Risk Management Plan for the <project name> project, defining the risk management process to be employed throughout the life of this project. The project manager is responsible for reviewing and maintaining this Risk Management Plan throughout the project to ensure that the risk process remains appropriate to deal with the level of risk faced by the project.

PROJECT DESCRIPTION AND OBJECTIVES

<Brief description of the project, including its background and purpose>

The scope and objectives for the <project name> Project are summarized as follows:

• <list all objectives, including time, cost, scope, quality, performance, functionality, reputa- tion, business benefits, safety, etc.>

<Comment on relative prioritization of project objectives>

AIMS, SCOPE, AND OBJECTIVES OF RISK PROCESS

The <project name> project risk management process aims to manage all foreseeable risks (both opportunities and threats) in a manner that is proactive, effective, and appropriate, in order to maximize the likelihood of the project achieving its objectives, while maintaining risk exposure at an acceptable level.

“Acceptable risk” is defined for the <project name> project as <clear definition of how much risk is acceptable to key stakeholders such as the project sponsor, perhaps in terms of how many “high” threats can be present in the project, or maximum acceptable Threat P-I Score and minimum acceptable Opportunity P-I Score, or extent of allowable delay or additional cost>.

The risk process will aim to engage all project stakeholders appropriately, creating ownership and buy-in to the project itself and also to risk management actions.

FIGURE A-1: risk management Plan template (continues)

10 Practical Project Risk Management: The ATOM Methodology

Risk-based information will be communicated to project stakeholders in a timely manner at an appropriate level of detail, to enable project strategy to be modified in the light of current risk exposure.

The risk management process will enable project stakeholders to focus attention on those areas of the project most at risk by identifying the major risks (both opportunities and threats) poten- tially able to exert the greatest positive or negative influence on achievement of project objectives.

The risk management process covers all activities undertaken during the lifetime of the project.

<Clarify whether the risk process is intended to cover internal project risks only, or whether it extends to supplier risks, corporate risks, program risks, business risks, etc. Also clarify what types of risk are included; for example, technical risks, commercial risks, management risks, external risks, etc. Consider using a risk breakdown structure (RBS) for this (see Appendix B). Where some sources or types of risk are excluded, state how these will be dealt with if they are identified.>

APPLICATION OF THE ATOM PROCESS

<Either refer to the standard ATOM process document, or summarize briefly the approach to be used, perhaps using text as below. Comment on whether or not the risk process is expected to include quantitative modeling. Detail the frequency with which the risk process will be updated.>

This project is considered to be <small, medium, or large> in accordance with the agreed-upon project sizing tool. For this project a <reduced, standard, enhanced> ATOM process will be applied.

The following ATOM process will be used for the <project name> project:

• Initiation: clarifying and recording objectives for the project being assessed, and defining the details of the risk process to be implemented, documenting the results in a Risk Manage- ment Plan

• Identification: exposing and documenting risks that might affect project objectives either positively or negatively

• Assessment: either qualitatively describing risks individually so they can be understood and prioritized, and/or quantitatively modeling the effect of risks on project outcome, to deter- mine which areas of the project are most at risk

Response Planning: determining appropriate strategies and actions to deal with identified risks, with a nominated owner to address each risk

• Reporting: communicating the dynamic status of risk on the project to all stakeholders • Implementation: implementing agreed-upon response strategies and actions and checking

their effectiveness

• Review: updating the risk assessment at regular intervals through a series of Major and Minor Reviews

• Post-Project Review: where lessons are learned for both the improvement of risk manage- ment and project management in general.

The Initiation phase will be completed before the project commences, then the remaining steps in the risk process will be cyclic, repeated regularly throughout the life of the project. The First Risk Assessment will be completed within <> of project start, and reviews will be performed <weekly/ monthly/trimonthly/etc.> thereafter. <Describe use and planned periodicity of Major and Minor Reviews here>.

FIGURE A-1: risk management Plan template (continued)

RISK TOOLS AND TECHNIQUES

<List the tools and techniques to be used for the risk process, perhaps using the words below.>

The following tools and techniques will be used to support the risk management process on the <project name> project:

• Initiation

• Risk Management Plan (this document), issued at project start and reviewed regularly by the project manager during the project

• Identification • Risks (both threats and opportunities) will be identified using the following techniques:

• Brainstorming with all members of the project team plus representatives of key suppliers • Analysis of all project assumptions and constraints, both implicit and explicit • Review of a standard risk checklist • Ad hoc identification of risks by project team members at any time during the project

• Initial Risk Register to record identified risks for further assessment, following the stan- dard format

• Assessment

• Probability and impact assessment for each identified risk, using the project-specific scales defined in Appendix A

• Double P-I Matrix to prioritize risks for action, using the standard risk scoring calculations based on probability (P) and impact (I)

• Top risk list for priority management attention

• Risk categorization using the standard risk breakdown structure (see Appendix B) to iden- tify patterns of exposure

• Risk Register update to include assessment data • Response Planning

• Response strategy selection as appropriate for each identified risk, including owner allocation

• Identification of specific actions and action owners

• Risk Register update to include response data • Reporting

• Risk report to project sponsor and steering group/project board

• Provision of ad hoc reports to stakeholders and project team as required • Implementation

• Implementation of response strategies via their agreed-upon actions

• Monitoring of the effectiveness of agreed-upon actions and updating of project plans • Review (see section below on risk reporting)

• Risk workshops as part of a Major Review to identify new risks, review progress on exist- ing risks and agreed-upon responses, and assess process effectiveness

FIGURE A-1: risk management Plan template (continues)

Risk review meeting as part of a Minor Review to identify new risks, review progress on existing risks and agreed-upon responses

• Post-Project Review

• A lessons-learned meeting to capture all lessons learned relating to risk management on the project.

ORGANIZATION, ROLES, AND RESPONSIBILITIES FOR RISK MANAGEMENT

<Define the roles and responsibilities for various staff in relation to the risk process, perhaps using the words below.>

The responsibilities of key project stakeholders for risk management on the <project name> proj- ect are defined in individual terms of reference for each job role and summarized as follows:

Project sponsor

• Actively support and encourage the implementation of a formal risk management process on the project

• Set and monitor risk thresholds and ensure these are translated into acceptable levels of risk for the project

• Attend risk workshops; identify risks and ownership of risks

• Review risk outputs from the project with the project manager to ensure process consistency and effectiveness

• Review risks escalated by the project manager that are outside the scope or control of the project or require input or action from outside the project

• Make decisions about project strategy in light of current risk status to maintain acceptable risk exposure

• Ensure that adequate resources are available to the project to respond appropriately to iden- tified risks

• Release “management reserve” funds to the project where justified to deal with exceptional risks

• Report risk status regularly to senior management.

Project manager

• Manage the overall risk management process; ensure that foreseeable risks (both threats and opportunities) are identified and managed effectively and proactively to maintain an acceptable level of risk exposure for the project

• Determine the acceptable levels of risk for the project by consultation with the project sponsor

• Approve the Risk Management Plan prepared by the risk champion • Promote the risk management process for the project • Participate in risk workshops and review meetings, and identify and own risks • Approve risk response plans and their associated risk actions prior to implementation • Apply project contingency funds to deal with identified risks that occur during the project • Oversee risk management by subcontractors and suppliers

FIGURE A-1: risk management Plan template (continued)

Risk review meeting as part of a Minor Review to identify new risks, review progress on existing risks and agreed-upon responses

• Post-Project Review

• A lessons-learned meeting to capture all lessons learned relating to risk management on the project.

ORGANIZATION, ROLES, AND RESPONSIBILITIES FOR RISK MANAGEMENT

<Define the roles and responsibilities for various staff in relation to the risk process, perhaps using the words below.>

The responsibilities of key project stakeholders for risk management on the <project name> proj- ect are defined in individual terms of reference for each job role and summarized as follows:

Project sponsor

• Actively support and encourage the implementation of a formal risk management process on the project

• Set and monitor risk thresholds and ensure these are translated into acceptable levels of risk for the project

• Attend risk workshops; identify risks and ownership of risks

• Review risk outputs from the project with the project manager to ensure process consistency and effectiveness

• Review risks escalated by the project manager that are outside the scope or control of the project or require input or action from outside the project

• Make decisions about project strategy in light of current risk status to maintain acceptable risk exposure

• Ensure that adequate resources are available to the project to respond appropriately to iden- tified risks

• Release “management reserve” funds to the project where justified to deal with exceptional risks

• Report risk status regularly to senior management.

Project manager

• Manage the overall risk management process; ensure that foreseeable risks (both threats and opportunities) are identified and managed effectively and proactively to maintain an acceptable level of risk exposure for the project

• Determine the acceptable levels of risk for the project by consultation with the project sponsor

• Approve the Risk Management Plan prepared by the risk champion • Promote the risk management process for the project • Participate in risk workshops and review meetings, and identify and own risks • Approve risk response plans and their associated risk actions prior to implementation • Apply project contingency funds to deal with identified risks that occur during the project • Oversee risk management by subcontractors and suppliers

FIGURE A-1: risk management Plan template (continued)

<Detail the frequency and content of risk reports, perhaps using words similar to those below.>

A risk report will be issued <state frequency> by the project manager to the project sponsor after each Major or Minor Review. See Appendix C for the contents of a full risk report following a Major Review, and Appendix D for the contents of a summary risk report following a Minor Review.

Project team members and other stakeholders will be provided with an extract from the cur- rent Risk Register after each review, listing those risks and actions for which the individual is responsible.

On completion of the project, a risk section will be provided for the <project name> project lessons-learned report, detailing generic risks (both opportunities and threats) that might affect other similar projects, together with responses that have been found effective in this project. Input will also be provided for the project knowledge database to capture risk-related lessons learned from this project.

APPENDIX A: Definitions of Probability and Impacts

<Define scales for probability and impact to be used for this project in a similar format to those below. The probability scale below may be used unchanged, but the impact scales must be replaced with values specific to the particular project and that reflect agreed-upon risk thresholds for this project.>

(Note: When using these impact scales to assess opportunities, they are to be treated as repre- senting a positive savings in time or cost, or increased functionality. For threats, each impact scale is interpreted negatively; i.e., time delays, increased cost, or reduced functionality.)

FIGURE A-1: risk management Plan template (continued)