Risk Management

profileasdsiee
week05-06_lecturenotes.docx

Introduction to risk management for IS/IT projects

This Week examines the process of risk identification and the role project managers play in assessing potential risks during each stage of the IS/IT project life cycle. You will consider risks in IS/IT projects and analyse the process of risk assessment and prioritisation for IS/IT projects. As well, you will examine tools and techniques used to mitigate risks throughout a project’s life cycle and examine the methods used to track the risks and their impact on the development and delivery of an IS/IT project.

Risk identification: What is risk?

Risks to project development can be described as threats of damage or loss caused by weaknesses in the project plan. The impact of these weaknesses may be reduced or eliminated through planning and preventative actions. When analysing a project’s life cycle, project managers assess each stage for the probability of risks, in both planned and unplanned activities, that may have an impact on the cost of development or the delivery of the project. This process is called risk identification.

Every event in an IS/IT project plan carries an inherent risk or can develop a risk during the project lifecycle. Since risk cannot be entirely eliminated, it is important to constantly manage risks to keep them at a minimum.

Project managers identify risks in IS/IT projects using various tools and techniques, depending on the type of project undertaken and the project team preference.

According to Nicholas and Steyn (2012), organisations most often employ the following risk identification methodologies: project analysis, checklists, work breakdown structure (WBS) analysis, process flow charts, project networks, cause-effect diagramming, brainstorming and the Delphi technique.

For example, imagine a project where an IS/IT secure application is to be developed for a client. The core requirement is that the application run on a secure system and should be able to handle a range of risk, from very low to high levels. In a brainstorming session, the project team identifies a few issues related to the secure application and the IS/IT system on which the secure application is to be run, as well as issues related to the project team and the project plan. One of the best ways to represent these causal issues is an Ishikawa or fishbone diagram (Ilie & Ciocoiu, 2010). This diagram is a simple diagrammatic representation of multiple possible causes of a single effect. A typical Ishikawa diagram has three components: the primary branch representing the effect, a major branch representing a major cause and the minor branches representing the more detailed causal factors.

Risk assessment

Risks associated with an IS/IT project can impact the entire organisation creating the project. Therefore, it is essential for project managers to have a complete understanding of the goals and objectives of an organisation when analysing project risks. Risk assessment is when project managers and organisations identify which assets or events in a project’s life cycle are at the greatest risk and require further protection, planning and controls to minimise their impact. IS/IT projects have inherent challenges in the assessment of risk, which can be classified by likelihood, consequences, impact and priority of risks. Table 1 classifies risk likelihood and impact.

Risk management is often associated with effective resource management. The availability (or non-availability, as is often the case) of adequate resources to satisfactorily support project requirements has the potential to directly impact the project outcome.

Risk management process

The process of risk management requires a project manager to identify risks, assess their possible impact and prioritise them according to the probability that they will occur during the development and life cycle of a project. For organisations, there is a large amount of uncertainty associated with this process.

Table 2 summarises the risk management processes for IS/IT projects (Bank, 2013). Figure 5 illustrates the steps of the risk management process.

Table 2 Risk management processes

One way for project managers to manage uncertainty in an IS/IT project is to use established or mature tools and technologies. When organisations take a proactive and responsive approach to risk management, they are more effective in overcoming the negative effects of uncertainty. A proactive approach gives project managers additional time to deploy contingency plans to mitigate risks. One tool that aids early deployment of contingency plans is called the risk register (Iqbal, 2013). The risk register is a record of identified risks, their severity and corrective actions to be taken. It can take the form of a database, a spreadsheet, a table or even a simple text document. It is a live document, frequently updated and visible to all stakeholders to communicate the plan to reduce the probability and the potential impact of specific risks. The entries of a typical risk register are dates, risk description, risk type (classification), likelihood of occurrence, severity of the effects and the countermeasures taken.

In IS/IT projects, efficient project managers frequently plan and allocate resources on an ‘as and when required’ basis. Reassigning resources to address unplanned or unforeseen events is key to a project’s successful completion.

Unexpected risks exist throughout all stages of a project and can jeopardise deliverables and deadlines to varying degrees. Often it can be difficult to identify the underlying causes for each problem, but causes and effects of risk should be studied carefully and fully understood to fix the problem and prevent reoccurrences. In many instances, organisations may develop and deploy several different iterations of a recovery plan before correctly identifying the source of a problem.