Concept 9 of 15

Project risk management

4 questions test this

A risk is an uncertain event or condition that, if it occurs, has an effect on at least one project objective. The event is uncertain, which separates a risk from an issue that has already happened, and the effect is an effect rather than a harm, so opportunities belong inside risk management rather than beside it.

Treating risk as a synonym for threat throws away half the discipline, since a project that only plans to avoid bad outcomes never plans to capture good ones.

Identify, analyse, respond, monitor

Planning risk management settles how risk will be handled on this project, including the categories, the definitions of probability and impact, and who does what.

Identifying risks is continuous rather than an exercise at the start, because new risks appear as the project proceeds and old ones expire. The output is a register naming each risk, its cause and its potential effect, written specifically enough to act on.

Qualitative analysis rates each risk by probability and impact and orders the register accordingly. It is quick and subjective, it is applied to everything, and its purpose is to decide what deserves further attention rather than to produce a number.

Quantitative analysis models the combined effect of risks on the objectives numerically, usually by simulating the schedule or cost model many times, and it produces statements such as a probability of finishing by a date. It is expensive, it is applied only to what qualitative analysis promoted, and many projects never do it.

Planning responses assigns an owner and a strategy to each risk that warrants one. Implementing them is the step most often skipped, since a register full of unexecuted plans is a document rather than a control. Monitoring tracks identified risks, watches for new ones, and evaluates whether the responses are working.

The probability and impact matrix

Qualitative analysis needs a scale that everybody in the room reads the same way, and the matrix is where that scale is written down before any risk is scored against it.

Probability0.900.700.500.300.100.0450.090.180.360.720.0350.070.140.280.560.0250.050.100.200.400.0150.030.060.120.240.0050.010.020.040.080.050.100.200.400.80ImpactHighMediumLowEach cell is theprobability timesthe impact

Impact is scaled unevenly on purpose, so a severe impact counts for far more than four times a trivial one, and a low probability with a severe impact still lands in the top band. On this project anything from 0.18 upward needs a planned response, the band from 0.05 to 0.14 goes on a watch list, and anything below 0.05 is accepted and reviewed at the next cycle.

Where the band boundaries fall is a decision the project makes in advance and writes into the risk management plan. Setting them after the risks are scored lets the boundary move to suit whichever answer somebody already wanted.

Responding to threats

Avoid removes the threat entirely by changing the plan, whether by dropping the component that carries the uncertainty or by extending the schedule so the risky compression is unnecessary. It is the strongest response and it usually costs something.

Transfer moves the impact and the ownership of the response to a third party, through insurance, a warranty or a fixed price contract. The risk does not disappear, and a premium is paid to somebody willing to carry it.

Mitigate reduces the probability or the impact to an acceptable level, which is the most common response and the one people mean when they say a risk is being managed.

Escalate hands the risk upward because it falls outside the project manager's authority. Ownership genuinely leaves the project, and the risk is recorded but no longer actively managed by the team.

Accept acknowledges the risk without acting on it now. Active acceptance sets aside a contingency reserve of time or money, and passive acceptance does nothing beyond documenting the decision and reviewing it.

Responding to opportunities

The five strategies map onto their threat counterparts. Exploit is the mirror of avoid, making certain the opportunity is realised rather than merely likely, such as assigning the strongest engineers to guarantee an early finish that unlocks a bonus.

Share allocates ownership to a partner better placed to capture the benefit, mirroring transfer. Enhance increases the probability or the positive impact, mirroring mitigate. Escalate and accept work exactly as they do for threats.

Ten strategies, five of them mirrored

The strategies pair up. Every threat response has an opportunity response that does the same thing to a positive outcome, and reading them side by side is the fastest way to keep them straight.

Threat strategyWhat it doesOpportunity mirrorWhat it does
AvoidRemoves the threat by changing the plan, such as dropping the component that carries the uncertaintyExploitMakes the gain certain rather than likely, such as putting the strongest engineers on the finish that unlocks a bonus
TransferMoves impact and response ownership to a third party, such as insuring the shipment against lossShareGives a partner better placed to capture the gain a stake in it, such as a joint bid with a specialist firm
MitigateReduces probability or impact, such as prototyping the risky interface in the first monthEnhanceRaises probability or the size of the gain, such as briefing the regulator early to make the early approval likelier
EscalateHands a threat outside the project manager's authority to the level that owns it, such as a policy conflictEscalateHands an opportunity beyond the project's remit upward, such as a reusable asset the whole programme could adopt
AcceptTakes the threat knowingly, with a contingency reserve or with nothing beyond a documented decisionAcceptTakes the gain if it arrives, without spending anything to pursue it

Expected monetary value

Expected monetary value puts a single figure on an uncertain outcome by multiplying the probability that it happens by what it would be worth. Threats carry a negative value and opportunities a positive one, so the two can be added together into one number.

RiskProbabilityImpact if it happensExpected monetary value
The supplier misses the integration window0.30£80,000 of extra cost0.30 × 80,000 gives £24,000 of exposure
The regulator approves early, releasing a bonus0.20£50,000 of gain0.20 × 50,000 gives £10,000 of expected gain
The two together£24,000 less £10,000, so £14,000 of net exposure

The £14,000 is what would be set aside as contingency reserve for these two risks, and it is also the number that decides what a response is worth. A mitigation that costs £30,000 to halve the supplier risk saves £12,000 of expected exposure and is a poor trade, whereas one costing £5,000 for the same reduction is an obvious one.

The figure has a well known limitation. The supplier either misses the window and costs £80,000, or does not and costs nothing, and £24,000 is a value the project will never actually see. Expected monetary value earns its keep across a portfolio of risks, where the individual outcomes average out, and it misleads whenever a single large risk is treated as though its expected value were the outcome.

Appetite, threshold and reserve

Risk appetite is the degree of uncertainty an organisation will take on in pursuit of a reward, and it is a stance rather than a number. A risk threshold is the measurable level at which that stance becomes a rule, such as a limit on schedule exposure that cannot be accepted without executive approval.

Reserves are how appetite becomes money. Contingency reserve covers identified risks, sits inside the cost baseline, and is spent by the project manager when a planned response triggers. Management reserve covers unknown risks, sits outside the cost baseline but inside the project budget, and needs management approval before it can be used.

Drawing on contingency is an ordinary act of project management, whereas drawing on management reserve is a change to the baseline, and telling which a situation calls for is usually the whole of the decision.

Secondary and residual risk

Every response creates consequences of its own. A secondary risk arises directly from implementing a response, such as the new supplier brought in to reduce a delivery risk bringing its own reliability problem. Secondary risks are identified, analysed and responded to like any other, and neglecting them is how a mitigation makes the position worse.

Residual risk is what remains after a response has been applied. Mitigation reduces exposure rather than eliminating it, and the leftover portion is accepted deliberately and recorded, which is different from having failed to notice it.

Common misconceptions

Risk means the things that could go wrong.

A risk is an uncertain event with an effect on an objective, and the effect may be positive. Opportunities are managed through the same register and the same processes, with exploit, share and enhance mirroring avoid, transfer and mitigate.

Contingency reserve and management reserve are two words for the same money.

Contingency reserve covers identified risks and sits inside the cost baseline, and the project manager spends it when a planned response triggers. Management reserve covers unknown risks, sits outside the baseline and inside the budget, and needs management approval to release.

Once a response is planned and the risk is mitigated, that risk is closed.

Mitigation reduces exposure rather than removing it, and what remains is residual risk that is accepted deliberately and recorded. The response can also introduce a secondary risk of its own, which is identified and analysed like any other.

4 questions test this concept

Midway through a payments integration the project manager learns that the organisation wide certificate authority contract expires in four months and that its renewal sits with a group procurement function reporting to the chief information officer. If it lapses, this project and several others lose the ability to sign transactions. What is the appropriate response?

  • AAdd a contingency reserve against the delay and accept the risk actively.
  • BMitigate it by building a fallback signing route inside this project.
  • CEscalate the risk, so that ownership passes to the level holding the authority to act on it.
  • DTransfer it by asking the integration supplier to indemnify the project against the lapse.
Check whether it stuck.

One per page, with a worked explanation.

Start the set
Related material
Book
Identifying and Managing Project Risk, On building a register that people actually act on.
Book
Waltzing with Bears, On why projects with no risks worth listing are projects with no value.