Attention Writing King: Select a Risk Identification Method and Use it to Determine Risks Facing a Project
319©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition
1 1 - P R O J E C T R I S K M A N A G E M E N T
11
11.2 Identify Risks
Identify Risks is the process of determining which risks may affect the project and documenting their
characteristics. The key benefit of this process is the documentation of existing risks and the knowledge and ability
it provides to the project team to anticipate events. The inputs, tools and techniques, and outputs of this process
are depicted in Figure 11-5. Figure 11-6 depicts the data flow diagram of the process.
Inputs Tools & Techniques Outputs
.1 Risk management plan .2 Cost management plan .3 Schedule management plan .4 Quality management plan .5 Human resource management plan .6 Scope baseline .7 Activity cost estimates .8 Activity duration estimates .9 Stakeholder register .10 Project documents .11 Procurement documents .12 Enterprise environmental factors .13 Organizational process assets
.1 Documentation reviews
.2 Information gathering techniques .3 Checklist analysis .4 Assumptions analysis .5 Diagramming techniques .6 SWOT analysis .7 Expert judgment
.1 Risk register
Figure 11-5. Identify Risks: Inputs, Tools & Techniques, and Outputs
320 ©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition
1 1 - P R O J E C T R I S K M A N A G E M E N T
R
R s
Q
P s
Project Risk Management
7.2 Estimate
Costs
8.1 Plan Quality Management
12.1 Plan
Procurement Management
Project Documents
5.4 Create WBS
7.1 Project Cost Management
8.1 Plan Quality Management
6.5 Estimate
Activity Durations
6.1 Plan Schedule Management
12.1 Plan Procurement
Management
13.1 Identify
Stakeholders
9.1 Plan Human Resource
Management
Enterprise/ Organization
11.2 Identify Risks
11.3 Perform
Qualitative Risk Analysis
11.5 Plan Risk
Responses
11.4 Perform
Quantitative Risk Analysis
11.6 Control Risks
11.1 Plan Risk
Management
7.2 Estimate Costs
Figure 11-6. Identify Risks Data Flow Diagram
321©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition
1 1 - P R O J E C T R I S K M A N A G E M E N T
11
Participants in risk identification activities may include the following: project manager, project team members,
risk management team (if assigned), customers, subject matter experts from outside the project team, end
users, other project managers, stakeholders, and risk management experts. While these personnel are often key
participants for risk identification, all project personnel should be encouraged to identify potential risks.
Identify risks is an iterative process, because new risks may evolve or become known as the project progresses
through its life cycle. The frequency of iteration and participation in each cycle will vary by situation. The format of
the risk statements should be consistent to ensure that each risk is understood clearly and unambiguously in order
to support effective analysis and response development. The risk statement should support the ability to compare
the relative effect of one risk against others on the project. The process should involve the project team so they can
develop and maintain a sense of ownership and responsibility for the risks and associated risk response actions.
Stakeholders outside the project team may provide additional objective information.
11.2.1 Identify Risks: Inputs
11.2.1.1 Risk Management Plan
Described in Section 11.1.3.1. Key elements of the risk management plan that contribute to the Identify Risks
process are the assignments of roles and responsibilities, provision for risk management activities in the budget
and schedule, and categories of risk, which are sometimes expressed as a risk breakdown structure (Figure 11-4).
11.2.1.2 Cost Management Plan
Described in Section 7.1.3.1. The cost management plan provides processes and controls that can be used to
help identify risks across the project.
11.2.1.3 Schedule Management Plan
Described in Section 6.1.3.1. The schedule management plan provides insight to project time/schedule
objectives and expectations which may be impacted by risks (known and unknown).
11.2.1.4 Quality Management Plan
Described in Section 8.1.3.1. The quality management plan provides a baseline of quality measures and metrics
for use in identifying risks.
322 ©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition
1 1 - P R O J E C T R I S K M A N A G E M E N T
11.2.1.5 Human Resource Management Plan
Described in Section 9.1.3.1. The human resource management plan provides guidance on how project human
resources should be defined, staffed, managed, and eventually released. It can also contain roles and responsibilities,
project organization charts, and the staffing management plan, which form a key input to identify risk process.
11.2.1.6 Scope Baseline
Described in Section 5.4.3.1. Project assumptions are found in the project scope statement. Uncertainty in
project assumptions should be evaluated as potential causes of project risk.
The WBS is a critical input to identifying risks as it facilitates an understanding of the potential risks at both
the micro and macro levels. Risks can be identified and subsequently tracked at summary, control account, and/or
work package levels.
11.2.1.7 Activity Cost Estimates
Described in Section 7.2.3.1. Activity cost estimate reviews are useful in identifying risks as they provide a
quantitative assessment of the likely cost to complete scheduled activities and ideally are expressed as a range,
with the width of the range indicating the degree(s) of risk. The review may result in projections indicating the
estimate is either sufficient or insufficient to complete the activity (i.e., pose a risk to the project).
11.2.1.8 Activity Duration Estimates
Described in Section 6.5.3.1. Activity duration estimate reviews are useful in identifying risks related to the time
allowances for the activities or project as a whole, again with the width of the range of such estimates indicating
the relative degree(s) of risk.
11.2.1.9 Stakeholder Register
Described in Section 13.1.3.1. Information about the stakeholders is useful for soliciting inputs to identify risks,
as this will ensure that key stakeholders, especially the stakeholder, sponsor, and customer are interviewed or
otherwise participate during the Identify Risks process.
323©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition
1 1 - P R O J E C T R I S K M A N A G E M E N T
11
11.2.1.10 Project Documents
Project documents provide the project team with information about decisions that help better identify project
risks. Project documents improve cross-team and stakeholder communications and include, but are not limited to:
Project charter,
Project schedule,
Schedule network diagrams,
Issue log,
Quality checklist, and
Other information proven to be valuable in identifying risks.
11.2.1.11 Procurement Documents
Defined in Section 12.1.3.3. If the project requires external procurement of resources, procurement
documents become a key input to the Identify Risks process. The complexity and the level of detail of the
procurement documents should be consistent with the value of, and risks associated with, planned procurement.
11.2.1.12 Enterprise Environmental Factors
Described in Section 2.1.5. Enterprise environmental factors that can influence the Identify Risks process
include, but are not limited to:
Published information, including commercial databases,
Academic studies,
Published checklists,
Benchmarking,
Industry studies, and
Risk attitudes.
324 ©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition
1 1 - P R O J E C T R I S K M A N A G E M E N T
11.2.1.13 Organizational Process Assets
Described in Section 2.1.4. Organizational process assets that can influence the Identify Risks process include,
but are not limited to:
Project files, including actual data,
Organizational and project process controls,
Risk statement formats or templates, and
Lessons learned.
11.2.2 Identify Risks: Tools and Techniques
11.2.2.1 Documentation Reviews
A structured review of the project documentation may be performed, including plans, assumptions, previous
project files, agreements, and other information. The quality of the plans, as well as consistency between those
plans and the project requirements and assumptions, may be indicators of risk in the project.
11.2.2.2 Information Gathering Techniques
Examples of information gathering techniques used in identifying risks can include:
Brainstorming. The goal of brainstorming is to obtain a comprehensive list of project risks. The project
team usually performs brainstorming, often with a multidisciplinary set of experts who are not part of the
team. Ideas about project risk are generated under the leadership of a facilitator, either in a traditional
free-form brainstorm session or structured mass interviewing techniques. Categories of risk, such as in a
risk breakdown structure, can be used as a framework. Risks are then identified and categorized by type
of risk and their definitions are refined.
Delphi technique. The Delphi technique is a way to reach a consensus of experts. Project risk experts
participate in this technique anonymously. A facilitator uses a questionnaire to solicit ideas about the
important project risks. The responses are summarized and are then recirculated to the experts for
further comment. Consensus may be reached in a few rounds of this process. The Delphi technique helps
reduce bias in the data and keeps any one person from having undue influence on the outcome.
325©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition
1 1 - P R O J E C T R I S K M A N A G E M E N T
11
Interviewing. Interviewing experienced project participants, stakeholders, and subject matter experts
helps to identify risks.
Root cause analysis. Root-cause analysis is a specific technique used to identify a problem, discover
the underlying causes that lead to it, and develop preventive action.
11.2.2.3 Checklist Analysis
Risk identification checklists are developed based on historical information and knowledge that has been
accumulated from previous similar projects and from other sources of information. The lowest level of the RBS
can also be used as a risk checklist. While a checklist may be quick and simple, it is impossible to build an
exhaustive one, and care should be taken to ensure the checklist is not used to avoid the effort of proper risk
identification. The team should also explore items that do not appear on the checklist. Additionally, the checklist
should be pruned from time to time to remove or archive related items. The checklist should be reviewed during
project closure to incorporate new lessons learned and improve it for use on future projects.
11.2.2.4 Assumptions Analysis
Every project and its plan is conceived and developed based on a set of hypotheses, scenarios, or assumptions.
Assumptions analysis explores the validity of assumptions as they apply to the project. It identifies risks to the
project from inaccuracy, instability, inconsistency, or incompleteness of assumptions.
11.2.2.5 Diagramming Techniques
Risk diagramming techniques may include:
Cause and effect diagrams. These are also known as Ishikawa or fishbone diagrams and are useful for
identifying causes of risks.
System or process flow charts. These show how various elements of a system interrelate and the
mechanism of causation.
Influence diagrams. These are graphical representations of situations showing causal influences, time
ordering of events, and other relationships among variables and outcomes, as shown in Figure 11-7.
326 ©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition
1 1 - P R O J E C T R I S K M A N A G E M E N T
Project Activity
Project Estimates
Deliverables
Risk Condition
Figure 11-7. Influence Diagram
11.2.2.6 SWOT Analysis
This technique examines the project from each of the strengths, weaknesses, opportunities, and threats (SWOT)
perspectives to increase the breadth of identified risks by including internally generated risks. The technique starts
with identification of strengths and weaknesses of the organization, focusing on either the project, organization,
or the business area in general. SWOT analysis then identifies any opportunities for the project that arise from
organizational strengths, and any threats arising from organizational weaknesses. The analysis also examines
the degree to which organizational strengths offset threats, as well as identifying opportunities that may serve to
overcome weaknesses.
327©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition
1 1 - P R O J E C T R I S K M A N A G E M E N T
11
11.2.2.7 Expert Judgment
Risks may be identified directly by experts with relevant experience with similar projects or business areas.
Such experts should be identified by the project manager and invited to consider all aspects of the project and
suggest possible risks based on their previous experience and areas of expertise. The experts’ bias should be taken
into account in this process.
11.2.3 Identify Risks: Outputs
11.2.3.1 Risk Register
The primary output from Identify Risks is the initial entry into the risk register. The risk register is a document
in which the results of risk analysis and risk response planning are recorded. It contains the outcomes of the other
risk management processes as they are conducted, resulting in an increase in the level and type of information
contained in the risk register over time. The preparation of the risk register begins in the Identify Risks process
with the following information, and then becomes available to other project management and risk management
processes:
List of identified risks. The identified risks are described in as much detail as is reasonable. A
structure for describing risks using risk statements may be applied, for example, EVENT may occur
causing IMPACT, or If CAUSE exists, EVENT may occur leading to EFFECT. In addition to the list of
identified risks, the root causes of those risks may become more evident. These are the fundamental
conditions or events that may give rise to one or more identified risks. They should be recorded and
used to support future risk identification for this and other projects.
List of potential responses. Potential responses to a risk may sometimes be identified during the Identify
Risks process. These responses, if identified in this process, should be used as inputs to the Plan Risk
Responses process.
- PMBOK 5th Edition 347.pdf
- PMBOK 5th Edition 348
- PMBOK 5th Edition 349
- PMBOK 5th Edition 350
- PMBOK 5th Edition 351
- PMBOK 5th Edition 352
- PMBOK 5th Edition 353
- PMBOK 5th Edition 354
- PMBOK 5th Edition 355