PROF. ANN
Assignment 2: Risk Management Plan
BUS 519 – Project Risk Management
by
Michell Waters
Submitted to: Dr. Paul Jaikaran
Winter 2017
Introduction
The paper entails a Risk Management Plan for the DIGITECH Company dealing in the installation of computer software and hardware. The plan will provide a guideline on the processes of risk management through the daily operation of the institution for a period of six months before adjustable changes are made (Dobson, & Dobson, 2012). This document can only be strengthened through a collaborative support and commitment from the senior management, the Board of Directors and competent personal relevant on risk management. The manager will be most appropriate to ensure that under his supervisory mandate, the risk management plan developed is followed to curb unnecessary losses or challenges within the stipulated period.
1. Prepare the Scope and Objectives of the Risk Management Process section of the Risk Management Plan based on the facts presented in the case study.
Answer: The scope and objectives of the risk management plan aim at providing our company with a guidance on the sound management practices (Hillson, & Simon, 2012). These management processes cover all relevant stages of the risk management procedure i.e. establishment of a context for the risk management, communicating risk management, identifying the risks, analyzing risks, evaluating risks, treating and monitoring and reviewing the noted risks (Dobson, & Dobson, 2012). The risks of concern in the company involves technology, operational, technical, and insurance business related risks.
Enabling people to advance with confidence is the Vision that energize our employees to remain commitment and focused on the institution’s set objectives (Dobson, & Dobson, 2012). The mission is to always be a leading technological Company in the region by providing the best goods and services to our customers.
The project of software and hardware installation will help our company to enjoy technological advancement with a boosted business demand environment. Our branches are regionally located in five different countries with varying multi-national disciplines characterized with varied capabilities and responsibilities.
The risk management plan drafted will define the business scope and objectives of risk management procedures to help provide consistent and reliability of the processes (Hillson, & Simon, 2012). The project size of the company will be calculated by use of the project sizing matrix. Project sizing matrix has the ability to ease analytical and criterion needs (Dobson, & Dobson, 2012). While calculating the size of the company using the project sizing matrix, review and reporting standards are as well defined and implemented.
The weight of the impact, risk threshold, and resource justification allocated for risks monitoring are addressed through a probabilistic assessment of the impacts (Dobson, & Dobson, 2012). This analysis helps the company to identify the threats and vulnerabilities as well as determine where to implement measures for risk mitigation based on the project’s potential as a whole.
The main objective/goal of the risk management plan is to develop a mechanism/ method for risk monitoring, evaluation, and management within the stipulated six months of the project life cycle at the set available resources. The process should be successful and effective (Dobson, & Dobson, 2012).
The project management plan for DIGITECH Company is meant to manage the future predicted risks in a proactive, appropriate and efficient way enhances the possibility of the realization of the set objectives of the project. To effectively control the projected future risks, all project stakeholders are expected to create ownership and active coordination toward the success of the project and risk management (Elmhedwi et al., 2015).
The known scope and objectives of the DIGITECH Company are to identify the risks predicted to affect the business in the future and mitigate, control, and exploit the discovered risks (Assessment, 2016). The management has to develop a communication system for easy and facilitated problem-solving as well as streamlining communication among relevant parties to offer viable solutions and interventions with ability to minimize risk impact on the project (Dobson, & Dobson, 2012). For the project to realize a successful transition, the groups must execute their ability in IT migration in efficient manner.
Communication is an important factor in the project management plan, therefore, the team must build a communication forum for information, tools and techniques sharing to enhance resolve issues and prevent negative impact on the outcome. A communication forum acts a site of communication used by stakeholders to communicate, align resources, and share important lessons. Thus, reduces redundancy, costs, and time of communication. Consequently, enhances product quality and functionality of the system as well as establish standard practices learnt.
Through the communication forum, each functional area will deliver daily report as well as receive back through the center point. As the communication happens, the risks noted are recorded in the risk register where they are assessed and assigned to value criteria.
2. Determine the project size, based on the facts presented in the case study, and provide justification based on Figure 3-4, Example Project Sizing Tool (Chapter 3 of the Hillson
and Simon text).
Answer: The project size is calculated by a tool called project sizing matrix. Project sizing tool helps determine the importance of the project to the organization and demonstrates the risk level. It calculates the project size used in the standardized ATOM criteria of risk management. The installation of the hardware and software equipment is intertwined with the IT system and as per the value of the money given ($100,000), it qualifies as a large project. As well the criteria and weighted values demonstrates that it is a large project (Dobson, & Dobson, 2012).
The standard ATOM risk management process is the only means through which the project size can be calculated. The complex technicality and global business venture are the factors boosting the appropriateness of the standard ATOM risk management process (Hillson, & Simon, 2012). Technical complexity, project cost and international organizational venture are the main facilitators of the ATOM management. The extensive project resource requirement and high value also contributed on the selection of the project sizing matrix (Dobson, & Dobson, 2012).
The most considered risk in the implementation of the project is technical risk, due to the level of expertise in multiple disciples required to implement the IT integration (Hillson, & Simon, 2012). Another challenges originates from the companies to deal with different interface of hardware and software. The IT integration or merger has geographical impact on the regions and host countries. Though, global interface provides advantage of technological advancement capability, it also constitutes complex technical risks leading to schedule delays, scope creep and budget swelling.
Project Sizing Tool
· Greater than 75 - Project is large - This implies that an extended ATOM risk management process is needed
· Between 35 and 74 Project is Medium -This implies that a standard ATOM risk management process is needed
· Less than 35 Project is small - This implies that a decreased ATOM risk management process is required
|
CRITERION |
Criterion Value=2 |
Criterion Value=4 |
Criterion Value=8 |
Criterion Value=16 |
Criterion n score |
|
Strategic importance |
Contributes less to business objective |
Contributes significantly |
More significant contribution |
Vital to the business |
8 |
|
Commercial/ contractual complexity |
Lacks commercial arrangements |
Deviates slightly from the business commercial |
New commercial practices |
Outstanding commercial practices |
4 |
|
External constraints and dependencies |
None |
Slightly influence the project |
Major objectives rely on external factors |
External factors are determinants of business success |
8 |
|
Requirement stability |
Well explained objectives |
Minor changes and uncertainty in requirements |
Greater proportion of uncertainty |
Requirements are negotiated |
8 |
|
Technical complexity |
Lacks new technology |
Facilitates existing products/services |
Innovation on the novel products |
high innovation of the products |
8 |
|
Market sector regulatory characteristics |
Lacks regulatory requirements |
Regulatory framework is standardized |
Pose challenges to regulatory requirements |
High rate of regulation |
4 |
|
Project value |
Low project value |
Project value is significant ($250k-1M) |
Proportionately large project value ($1-3M) |
Large project (>$3M) |
8 |
|
Project duration |
Duration <3 months |
Duration 3-12 months |
Duration 1-3 years |
Duration>3 years |
4 |
|
Project resources |
Project team is small |
Project team is of medium size |
Project team is large with external contractors |
Have internal corporation together with ventures |
8 |
|
Post-project liabilities |
- |
Exposure is acceptable |
Relatively significant exposure |
Punitive exposure |
4 |
3. Select the risk tools and techniques, and complete the Risk Tools and Techniques section of the Risk Management Plan for both the qualitative and quantitative aspects of the project. Provide a rationale for the selection.
Answer: Techniques and tools and for the project are designed using the extended ATOM risk management process (Hillson, & Simon, 2012). The process of devising the risk management process uses the daily report of risks, project issue, successful practices and status updates using the center of the communication forum (Dobson, & Dobson, 2012). To support the risk management process, the following tools and techniques are use;
Initiation stage
· Risk Management Plan produced at the onset of the project and constantly applied by the management of the project.
· Establish RMO to help the project management officer on in regard to project’s objectives and scope
Identification
Risks are identified using the techniques of;
· Functional area supervisor, each receive, document, and report risks that may affect the project
· Identified risks are assessed and evaluated by the RMO then distributed to stakeholders for assessment, expansion, concurrence and resolution (Dobson, & Dobson, 2012)
· RMO maintains the oversight to ensure consistent and timely report
· A memorandum of agreement will help stakeholders on issues that can impact project’s schedule or budget.
· After registering the risk, the risk submitter will record his contact as well for identification
Assessment
· Each identified risk is assessed for probabilistic impact
· Risk is categorized using the standard risk breakdown structure to identify exposure patterns
· The RMO qualitatively describe risks, to enhance understanding and prioritization by functional area supervisors
· The RMO performs qualitative model on the effects of risks for appropriate allocation of resources
· Updates of risk register to incorporate assessment
Response planning
· The RMO develops risk strategies for risk identification
· Identification of specific actions and owners
· Shifting of project resources to address risk assessment
· Update of risk register to include response data
Reporting
· The risk report is done to the PMO from RMO on daily basis
· Risks with higher scale are reported on daily basis while risks with LO or below are reported weekly
· Maintenance of risk register to capture problem, identifying source and risk resolution
Implementation
· The response strategies are implemented through the communication data base
· PMO and RMO monitor the effectiveness of the actions agreed upon, perform processes modification and update necessary project plans
Review
· Qualitative risks are maintained on the risk registry and appropriately tracked for further use
· Quantitative risks are monitored as project influence and reported daily to the PMO
· Meetings on risk review are held weekly by the PMO
· Monthly report submitted to the executive management on all the quantitative risks.
Post Project Review
· Conduct lessons-learned meeting to have all the lessons gathered in relation to risk management on the project
· Come up with an After Action Report document, containing best practices for future IT integration/merger
· Distribute AAR and Risk Registry copies to all stakeholders in a closed meeting
4. Develop the Risk Reviews and Reporting section of the Risk Management Plan based on the project size previously determined.
Answer: The level of risk exposure on the project will be viewed on daily basis for the risk rated higher while those rated LO or below will be viewed weekly (Hillson, & Simon, 2012). The emerging or new risks will be assessed as the existing risks are reviewed while progress depending on the agreed decision is taken and new actions or owners allocated when need arise (Dobson, & Dobson, 2012). Both the PMO and RMO will work in close to monitor the effectiveness of the actions agreed upon, modify and update project plans.
A risk report on qualitative risks will be submitted to the sponsor of the project every month and after major review. On the other side, interested parties in the project will be given an extract on the current reviewed Risk Registry (Dobson, & Dobson, 2012). After completing the project, a risk section is provided for the project’s report on the learned lessons showing the existing threats and opportunities that may affect other similar projects.
5. Define the Probability and Impacts section of the Risk Management Plan and justify the values assigned.
Answer: Probability and impact assessment establishes the probability of the occurrence and impact of risk. It focuses on the impacts caused by risks on the project’s objectives such as budget, schedule, quality and performance. Subject matters, project team members and other stakeholders work together for easy and cheap identification and rate risks as well as determine their likelihood of occurrence (Dobson, & Dobson, 2012).
6. Define the Risk Thresholds section of the Risk Management Plan and justify the values assigned.
Answer: DIGITECH Project being a core project in the overall IT merger, it has a significantly high risk threshold. Therefore, the project will have a repeatable process hence demands a serious consideration of OFIs (Dobson, & Dobson, 2012). The risk threshold of DIGITECH Project is determined based on the value of risk scaled. This happens due to technical risks related to minor switch risk causing a VLO risk computed in relation to the number of days before the problem is rectified (Assessment, 2016). The reduction of a threshold requires the PMO and RMO to always allocate proper resources for immediate rectification of the problems. Also, the rate of monitoring must as well be progressive and always.
References
Assessment, R. (2016). Risk Management Plan. Hertfordshire STEPS, ISL Hertfordshire County
Council.
Dobson, M. & Dobson, D. (2012). Project Risk and Cost Analysis. New York: American
Management Association.
Elmhedwi, T. R., Elmabrouk, S. K., & Sherif, M. A. (2015, March). Practical risk management
plan of Wi-Fi network deployment; case study. In Industrial Engineering and Operations
Management (IEOM), 2015 International Conference on (pp. 1-10). IEEE.
Hillson, D. & Simon, P. (2012). Practical Project Risk Management. The ATOM Methodology,
Second Edition. Tyson Corner: Management Concepts, Inc.