Attention Writing King: Select a Risk Identification Method and Use it to Determine Risks Facing a Project

profilejjoes3
11.2_identify_risks.pdf

319©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition

1 1 - P R O J E C T R I S K M A N A G E M E N T

11

11.2 Identify Risks

Identify Risks is the process of determining which risks may affect the project and documenting their

characteristics. The key benefit of this process is the documentation of existing risks and the knowledge and ability

it provides to the project team to anticipate events. The inputs, tools and techniques, and outputs of this process

are depicted in Figure 11-5. Figure 11-6 depicts the data flow diagram of the process.

Inputs Tools & Techniques Outputs

.1 Risk management plan .2 Cost management plan .3 Schedule management plan .4 Quality management plan .5 Human resource management plan .6 Scope baseline .7 Activity cost estimates .8 Activity duration estimates .9 Stakeholder register .10 Project documents .11 Procurement documents .12 Enterprise environmental factors .13 Organizational process assets

.1 Documentation reviews

.2 Information gathering techniques .3 Checklist analysis .4 Assumptions analysis .5 Diagramming techniques .6 SWOT analysis .7 Expert judgment

.1 Risk register

Figure 11-5. Identify Risks: Inputs, Tools & Techniques, and Outputs

320 ©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition

1 1 - P R O J E C T R I S K M A N A G E M E N T

R

R s

Q

P s

Project Risk Management

7.2 Estimate

Costs

8.1 Plan Quality Management

12.1 Plan

Procurement Management

Project Documents

5.4 Create WBS

7.1 Project Cost Management

8.1 Plan Quality Management

6.5 Estimate

Activity Durations

6.1 Plan Schedule Management

12.1 Plan Procurement

Management

13.1 Identify

Stakeholders

9.1 Plan Human Resource

Management

Enterprise/ Organization

11.2 Identify Risks

11.3 Perform

Qualitative Risk Analysis

11.5 Plan Risk

Responses

11.4 Perform

Quantitative Risk Analysis

11.6 Control Risks

11.1 Plan Risk

Management

7.2 Estimate Costs

Figure 11-6. Identify Risks Data Flow Diagram

321©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition

1 1 - P R O J E C T R I S K M A N A G E M E N T

11

Participants in risk identification activities may include the following: project manager, project team members,

risk management team (if assigned), customers, subject matter experts from outside the project team, end

users, other project managers, stakeholders, and risk management experts. While these personnel are often key

participants for risk identification, all project personnel should be encouraged to identify potential risks.

Identify risks is an iterative process, because new risks may evolve or become known as the project progresses

through its life cycle. The frequency of iteration and participation in each cycle will vary by situation. The format of

the risk statements should be consistent to ensure that each risk is understood clearly and unambiguously in order

to support effective analysis and response development. The risk statement should support the ability to compare

the relative effect of one risk against others on the project. The process should involve the project team so they can

develop and maintain a sense of ownership and responsibility for the risks and associated risk response actions.

Stakeholders outside the project team may provide additional objective information.

11.2.1 Identify Risks: Inputs

11.2.1.1 Risk Management Plan

Described in Section 11.1.3.1. Key elements of the risk management plan that contribute to the Identify Risks

process are the assignments of roles and responsibilities, provision for risk management activities in the budget

and schedule, and categories of risk, which are sometimes expressed as a risk breakdown structure (Figure 11-4).

11.2.1.2 Cost Management Plan

Described in Section 7.1.3.1. The cost management plan provides processes and controls that can be used to

help identify risks across the project.

11.2.1.3 Schedule Management Plan

Described in Section 6.1.3.1. The schedule management plan provides insight to project time/schedule

objectives and expectations which may be impacted by risks (known and unknown).

11.2.1.4 Quality Management Plan

Described in Section 8.1.3.1. The quality management plan provides a baseline of quality measures and metrics

for use in identifying risks.

322 ©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition

1 1 - P R O J E C T R I S K M A N A G E M E N T

11.2.1.5 Human Resource Management Plan

Described in Section 9.1.3.1. The human resource management plan provides guidance on how project human

resources should be defined, staffed, managed, and eventually released. It can also contain roles and responsibilities,

project organization charts, and the staffing management plan, which form a key input to identify risk process.

11.2.1.6 Scope Baseline

Described in Section 5.4.3.1. Project assumptions are found in the project scope statement. Uncertainty in

project assumptions should be evaluated as potential causes of project risk.

The WBS is a critical input to identifying risks as it facilitates an understanding of the potential risks at both

the micro and macro levels. Risks can be identified and subsequently tracked at summary, control account, and/or

work package levels.

11.2.1.7 Activity Cost Estimates

Described in Section 7.2.3.1. Activity cost estimate reviews are useful in identifying risks as they provide a

quantitative assessment of the likely cost to complete scheduled activities and ideally are expressed as a range,

with the width of the range indicating the degree(s) of risk. The review may result in projections indicating the

estimate is either sufficient or insufficient to complete the activity (i.e., pose a risk to the project).

11.2.1.8 Activity Duration Estimates

Described in Section 6.5.3.1. Activity duration estimate reviews are useful in identifying risks related to the time

allowances for the activities or project as a whole, again with the width of the range of such estimates indicating

the relative degree(s) of risk.

11.2.1.9 Stakeholder Register

Described in Section 13.1.3.1. Information about the stakeholders is useful for soliciting inputs to identify risks,

as this will ensure that key stakeholders, especially the stakeholder, sponsor, and customer are interviewed or

otherwise participate during the Identify Risks process.

323©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition

1 1 - P R O J E C T R I S K M A N A G E M E N T

11

11.2.1.10 Project Documents

Project documents provide the project team with information about decisions that help better identify project

risks. Project documents improve cross-team and stakeholder communications and include, but are not limited to:

Project charter,

Project schedule,

Schedule network diagrams,

Issue log,

Quality checklist, and

Other information proven to be valuable in identifying risks.

11.2.1.11 Procurement Documents

Defined in Section 12.1.3.3. If the project requires external procurement of resources, procurement

documents become a key input to the Identify Risks process. The complexity and the level of detail of the

procurement documents should be consistent with the value of, and risks associated with, planned procurement.

11.2.1.12 Enterprise Environmental Factors

Described in Section 2.1.5. Enterprise environmental factors that can influence the Identify Risks process

include, but are not limited to:

Published information, including commercial databases,

Academic studies,

Published checklists,

Benchmarking,

Industry studies, and

Risk attitudes.

324 ©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition

1 1 - P R O J E C T R I S K M A N A G E M E N T

11.2.1.13 Organizational Process Assets

Described in Section 2.1.4. Organizational process assets that can influence the Identify Risks process include,

but are not limited to:

Project files, including actual data,

Organizational and project process controls,

Risk statement formats or templates, and

Lessons learned.

11.2.2 Identify Risks: Tools and Techniques

11.2.2.1 Documentation Reviews

A structured review of the project documentation may be performed, including plans, assumptions, previous

project files, agreements, and other information. The quality of the plans, as well as consistency between those

plans and the project requirements and assumptions, may be indicators of risk in the project.

11.2.2.2 Information Gathering Techniques

Examples of information gathering techniques used in identifying risks can include:

Brainstorming. The goal of brainstorming is to obtain a comprehensive list of project risks. The project

team usually performs brainstorming, often with a multidisciplinary set of experts who are not part of the

team. Ideas about project risk are generated under the leadership of a facilitator, either in a traditional

free-form brainstorm session or structured mass interviewing techniques. Categories of risk, such as in a

risk breakdown structure, can be used as a framework. Risks are then identified and categorized by type

of risk and their definitions are refined.

Delphi technique. The Delphi technique is a way to reach a consensus of experts. Project risk experts

participate in this technique anonymously. A facilitator uses a questionnaire to solicit ideas about the

important project risks. The responses are summarized and are then recirculated to the experts for

further comment. Consensus may be reached in a few rounds of this process. The Delphi technique helps

reduce bias in the data and keeps any one person from having undue influence on the outcome.

325©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition

1 1 - P R O J E C T R I S K M A N A G E M E N T

11

Interviewing. Interviewing experienced project participants, stakeholders, and subject matter experts

helps to identify risks.

Root cause analysis. Root-cause analysis is a specific technique used to identify a problem, discover

the underlying causes that lead to it, and develop preventive action.

11.2.2.3 Checklist Analysis

Risk identification checklists are developed based on historical information and knowledge that has been

accumulated from previous similar projects and from other sources of information. The lowest level of the RBS

can also be used as a risk checklist. While a checklist may be quick and simple, it is impossible to build an

exhaustive one, and care should be taken to ensure the checklist is not used to avoid the effort of proper risk

identification. The team should also explore items that do not appear on the checklist. Additionally, the checklist

should be pruned from time to time to remove or archive related items. The checklist should be reviewed during

project closure to incorporate new lessons learned and improve it for use on future projects.

11.2.2.4 Assumptions Analysis

Every project and its plan is conceived and developed based on a set of hypotheses, scenarios, or assumptions.

Assumptions analysis explores the validity of assumptions as they apply to the project. It identifies risks to the

project from inaccuracy, instability, inconsistency, or incompleteness of assumptions.

11.2.2.5 Diagramming Techniques

Risk diagramming techniques may include:

Cause and effect diagrams. These are also known as Ishikawa or fishbone diagrams and are useful for

identifying causes of risks.

System or process flow charts. These show how various elements of a system interrelate and the

mechanism of causation.

Influence diagrams. These are graphical representations of situations showing causal influences, time

ordering of events, and other relationships among variables and outcomes, as shown in Figure 11-7.

326 ©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition

1 1 - P R O J E C T R I S K M A N A G E M E N T

Project Activity

Project Estimates

Deliverables

Risk Condition

Figure 11-7. Influence Diagram

11.2.2.6 SWOT Analysis

This technique examines the project from each of the strengths, weaknesses, opportunities, and threats (SWOT)

perspectives to increase the breadth of identified risks by including internally generated risks. The technique starts

with identification of strengths and weaknesses of the organization, focusing on either the project, organization,

or the business area in general. SWOT analysis then identifies any opportunities for the project that arise from

organizational strengths, and any threats arising from organizational weaknesses. The analysis also examines

the degree to which organizational strengths offset threats, as well as identifying opportunities that may serve to

overcome weaknesses.

327©2013 Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Fifth Edition

1 1 - P R O J E C T R I S K M A N A G E M E N T

11

11.2.2.7 Expert Judgment

Risks may be identified directly by experts with relevant experience with similar projects or business areas.

Such experts should be identified by the project manager and invited to consider all aspects of the project and

suggest possible risks based on their previous experience and areas of expertise. The experts’ bias should be taken

into account in this process.

11.2.3 Identify Risks: Outputs

11.2.3.1 Risk Register

The primary output from Identify Risks is the initial entry into the risk register. The risk register is a document

in which the results of risk analysis and risk response planning are recorded. It contains the outcomes of the other

risk management processes as they are conducted, resulting in an increase in the level and type of information

contained in the risk register over time. The preparation of the risk register begins in the Identify Risks process

with the following information, and then becomes available to other project management and risk management

processes:

List of identified risks. The identified risks are described in as much detail as is reasonable. A

structure for describing risks using risk statements may be applied, for example, EVENT may occur

causing IMPACT, or If CAUSE exists, EVENT may occur leading to EFFECT. In addition to the list of

identified risks, the root causes of those risks may become more evident. These are the fundamental

conditions or events that may give rise to one or more identified risks. They should be recorded and

used to support future risk identification for this and other projects.

List of potential responses. Potential responses to a risk may sometimes be identified during the Identify

Risks process. These responses, if identified in this process, should be used as inputs to the Plan Risk

Responses process.

  • PMBOK 5th Edition 347.pdf
  • PMBOK 5th Edition 348
  • PMBOK 5th Edition 349
  • PMBOK 5th Edition 350
  • PMBOK 5th Edition 351
  • PMBOK 5th Edition 352
  • PMBOK 5th Edition 353
  • PMBOK 5th Edition 354
  • PMBOK 5th Edition 355