SlideShare a Scribd company logo
1 of 32
PMI OVOC 10th Annual
Project Management Symposium
October 12 – 14, 2010
Unleashing the Power of
Project Management
Template V3
Managing Risk and Opportunity
in IT Projects
Robert Venczel
3 Key Learning Points
1. Describe the risk management process
– Definitions, utility theory, steps, responsibilities, etc.
– Corporate strategy relationship
2. Explain the RiskIT Model
– IT goals, associated metrics, and IT-related risks
– IT project risk management
– Risk scenarios and implementation of controls
3. Application of IT risk management
– Case study
2Presented at PMI OVOC Project Management Symposium 2010
Your Presenter
• Robert Venczel, MBA, CMA, CISA, PMP, CIA
• Bivium Executive Consulting Ltd.
• Over 18 years of management consulting experience
in both public and private sectors in the areas of:
– Project and programme risk management
– IT project management and governance
– IT audit
– Business strategy
3Presented at PMI OVOC Project Management Symposium 2010
Agenda
• Risk Management Process – A Quick Review
• Project Risk Management
• IT Risks vs. Overall Risk Universe
• IT Project Risk Management Continuum
• Case Study – SuperSoftware Inc.
4Presented at PMI OVOC Project Management Symposium 2010
What is Risk?
• Risk is defined as this uncertainty of outcome,
whether positive opportunity or negative threat, of
actions and events.*
*Orange Book (UK) Definition
5Presented at PMI OVOC Project Management Symposium 2010
RM Process
• Risk Identification
• Risk Assessment
• Risk Mitigation and Monitoring
• Risk Reporting
6Presented at PMI OVOC Project Management Symposium 2010
The Riskit Risk Management Cycle
7Presented at PMI OVOC Project Management Symposium 2010
Source: Kontio, J , Getto, G. and Landes. D. (1998),Experiences in improving risk management processes using the concepts of Riskit
method, SIGSOFT’98 sixth International Symposium on the Foundations of Software Engineering.
Risk Identification
• Types of risk:
– Organization-wide vs. programme/project
– External vs. internal
– Inherent vs. residual
• Risk identification:
– Using common methodology
– From top down and from bottom up
• Part of short- and long-term business planning
process
• Continuous not a one-time exercise
8Presented at PMI OVOC Project Management Symposium 2010
Risk Assessment
• Utility theory
• Likelihood and impact
• Need to develop a simple scoring/weighting
methodology that can be applied on a consistent
basis across the organization.
9Presented at PMI OVOC Project Management Symposium 2010
Impact vs. Likelihood
10Presented at PMI OVOC Project Management Symposium 2010
Addressing Risks / Risk Tolerance
 Tolerate
 Treat
 Transfer
 Terminate
 Risk tolerance vs. risk appetite
11Presented at PMI OVOC Project Management Symposium 2010
Risk Management/Risk Mitigation
• Identification of mitigating actions and controls
• Ensuring that mitigating actions and controls are
implemented (risk owners)
• Monitoring and reporting on the effectiveness of
mitigating actions and controls
• Reporting and escalating problems up the
management chain
12Presented at PMI OVOC Project Management Symposium 2010
Risk Mitigation Plan
• Choosing the most appropriate “treatment” or
combination of treatment options
• Costs and efforts vs. benefits
• Risk treatment itself can introduce risks
13Presented at PMI OVOC Project Management Symposium 2010
Risk Monitoring and Reporting
• Review periodically:
– If the status of risks has changed or new risks emerged
– The effectiveness of the mitigation strategies against
indicators
– The validity of the initial assumptions
– The existence of appropriate contingency plans
• Reporting:
– Status, performance and results
– Trends and patterns
14Presented at PMI OVOC Project Management Symposium 2010
RM Responsibilities for Risk Owners vs.
Risk Managers
– Risk Owners:
• Deemed ultimately accountable for the effective management of specific risk
categories
• Do not necessarily own or control all aspects of the risk
• Depend on others to help mitigate the risks
• Risk Managers:
• Responsibility for the risk management process
• Have the authority to manage risks
15Presented at PMI OVOC Project Management Symposium 2010
PMBOK® - Project Risk Management
Project Risk Management Processes
• Plan Risk Management
• Identify Risks
• Perform Qualitative Risk Analysis
• Perform Quantitative Risk Analysis
• Plan Risk Responses
• Monitor and Control Risks
16Presented at PMI OVOC Project Management Symposium 2010
Source: PMI’s PMBOK Guide, Fourth Edition (2008)
Opportunity vs. Risk
• On the positive side… new business initiatives
successfully enabled by IT
• On the negative side… IT projects misaligned
with the strategic objectives; waste of
resources due to failed projects; etc.
17Presented at PMI OVOC Project Management Symposium 2010
Defining IT Goals and Enterprise
Architecture for IT
18Presented at PMI OVOC Project Management Symposium 2010
Source: ISACA’s COBIT® 4.1 Framework for IT Governance and Control (2007)
IT Risk vs. Overall Risk Universe
19Presented at PMI OVOC Project Management Symposium 2010
Source: ISACA’s The Risk IT Framework (2009)
IT Project Risk Management Continuum
20Presented at PMI OVOC Project Management Symposium 2010
Needs and
Requirements
Specifications
Contractor/Team
Selection
Design and
Development
Systems
Integration
Conceptual
Design
Demonstration/
Validation
Engineering,
Manufacturing,
Development,
and Production
Maintenance
and Major
Upgrade
System Complexity vs. Risk
21Presented at PMI OVOC Project Management Symposium 2010
Risk(technical;cost;schedule)
Complexity (technology; team; expertise; etc.)
IT Risk Management Supports Success
By enabling IT project management to:
• Deal effectively with potential future events that
create uncertainty.
• Respond in a manner that reduces the likelihood that
objectives will not be achieved and increases the
likelihood of success.
22Presented at PMI OVOC Project Management Symposium 2010
Practicing Risk Management
• Integrate IT project risk management with business planning
and priority setting
• Promote use of the common language, framework, and
process
• Use common tools, techniques and models for risk mapping
and monitoring
• Use of risk management concepts in decision making and
reporting
• Consult and communicate with internal and external
stakeholders throughout the process
• Monitor, evaluate, and adjust systems, processes, and
practices
23Presented at PMI OVOC Project Management Symposium 2010
IT Project Risk Scenario Example
24Presented at PMI OVOC Project Management Symposium 2010
Beta Test
Successful
Users not ready to
use the new
software
Cost: $15K+
Unsuccessful
Project terminated
because of changed
business priorities
Cost: $100K+
Project delayed
Time: 1 month
Cost: $20K+
Software development project
Case Study – SuperSoftware Inc.
• Software development project
• Stakeholders
• Team
• Risks
• Evaluation of risks (quantitative vs. qualitative)
• Mitigation, monitoring and reporting
• Lessons learned
25Presented at PMI OVOC Project Management Symposium 2010
Conclusions
• Get senior management’s buy in and support for a
risk-aware culture.
• Use risk management people who understand the
business and information technology, and are also
good communicators.
• Successful IT risk management is all about
connection and alignment with business strategy.
26Presented at PMI OVOC Project Management Symposium 2010
Additional Resources
• Committee of Sponsoring Organizations of the Treadway Commission (COSO) Enterprise Risk
Management – Integrated Framework
• Risk management: Principles and guidelines - International Standard, ISO 31000: 2009
• Australian/New Zealand Standard for risk management - AS/NZS 4360:2004
• Risk management policies, directives and standards developed by the Treasury Board
Secretariat (TBS’s) to guide good management across the Canadian Federal Government:
– Integrated Risk Management Framework (IRMF)
– Integrated Risk Management Implementation Guide
– Policy on Active Monitoring
– Risk Management Policy
– Draft Core Management Controls
– Management Accountability Framework (MAF) criteria.
• PMI’s PMBOK Guide, Fourth Edition (2008)
• ISACA’s COBIT® 4.1 Framework for IT Governance and Control (2007)
• ISACA’s The Risk IT Framework (2009)
• ISACA’s The Risk IT Practitioner Guide (2009)
27Presented at PMI OVOC Project Management Symposium 2010
For more information…
• Thank you for your participation today!
• For more information on the contents of this
presentation, please feel free to contact me as
follows:
– Robert Venczel, MBA, CMA, CISA, PMP, CIA
– Bivium Executive Consulting Ltd.
• “Achieving Excellence Through Change”
– rvenczel@biviumconsulting.ca
– 613-843-7629
28Presented at PMI OVOC Project Management Symposium 2010
Copyright Notice
• The contents of this presentation are Copyright © 2010 by the
presenter and PMI OVOC.
• Permission is granted for participants to print the
presentation handouts for use during the conference and
later personal reference.
• PMI OVOC reserves the right to store this content for archival
purposes as a record of conference proceedings and to
publish this content electronically for the purpose of
disseminating conference proceedings to conference
participants.
• All other use, storage, retrieval, distribution, or reproduction
must be authorized in advance, in writing.
29Presented at PMI OVOC Project Management Symposium 2010
Supplementary Slides
30
Guiding Principles
31Presented at PMI OVOC Project Management Symposium 2010
Source: ISACA’s The Risk IT Framework (2009)
Sample IT Risk Heat Map
32Presented at PMI OVOC Project Management Symposium 2010
Poor communication
Budget overrun
Scope creep
Inadequate functional
requirements
Lack of support from
the top
1.00
1.20
1.40
1.60
1.80
2.00
2.20
2.40
2.60
2.80
3.00
1.00 1.20 1.40 1.60 1.80 2.00 2.20 2.40 2.60 2.80 3.00
Impact
Likelihood
IT Risks

More Related Content

What's hot

The project management and information technology context
The project management and information technology contextThe project management and information technology context
The project management and information technology contextAfdalArifAmandaPutra
 
Sameer Mitter | Introduction to Information technology Project Management
Sameer Mitter | Introduction to Information technology Project ManagementSameer Mitter | Introduction to Information technology Project Management
Sameer Mitter | Introduction to Information technology Project ManagementSameer Mitter
 
Project management by hamidun
Project management by hamidunProject management by hamidun
Project management by hamidunDr Hamidun Jaafar
 
Introduction project managemen
Introduction project managemenIntroduction project managemen
Introduction project managemenMostafa Elgamala
 
Project management process groups case study
Project management process groups case studyProject management process groups case study
Project management process groups case studyDhani Ahmad
 
ICT4GOV project management_2
ICT4GOV project management_2ICT4GOV project management_2
ICT4GOV project management_2John Macasio
 
PMP Training Project Integration Management Part 2
PMP Training Project Integration Management Part 2PMP Training Project Integration Management Part 2
PMP Training Project Integration Management Part 2Skillogic Solutions
 
Chapter 3: The Project Management Process Groups: A Case Study
Chapter 3:The Project Management Process Groups: A Case StudyChapter 3:The Project Management Process Groups: A Case Study
Chapter 3: The Project Management Process Groups: A Case StudyShahid Riaz
 
UCISA Major Projects Governance Assessment Toolkit
UCISA Major Projects Governance Assessment ToolkitUCISA Major Projects Governance Assessment Toolkit
UCISA Major Projects Governance Assessment ToolkitMark Ritchie
 
Infographic Slide: What is Project Management?
Infographic Slide: What is Project Management?Infographic Slide: What is Project Management?
Infographic Slide: What is Project Management?OneDeskApp
 
Lecture 06: Advanced Project Management Project Organization and Integration
Lecture 06: Advanced Project Management  Project Organization and IntegrationLecture 06: Advanced Project Management  Project Organization and Integration
Lecture 06: Advanced Project Management Project Organization and IntegrationFida Karim 🇵🇰
 
Introduction To Project Management
Introduction To Project Management Introduction To Project Management
Introduction To Project Management Nada Abandah, OPM3
 
HI600 U02_inst_slides
HI600 U02_inst_slides HI600 U02_inst_slides
HI600 U02_inst_slides ljmcneill33
 
PMP Training Course - Project Management Framework
PMP Training Course - Project Management FrameworkPMP Training Course - Project Management Framework
PMP Training Course - Project Management FrameworkSkillogic Solutions
 
Project management and information technology context
Project management and information technology contextProject management and information technology context
Project management and information technology contextDhani Ahmad
 
Architecture Project Management. The Open Group® conference, Paris 2016
Architecture Project Management. The Open Group® conference, Paris 2016Architecture Project Management. The Open Group® conference, Paris 2016
Architecture Project Management. The Open Group® conference, Paris 2016Architecture Center Ltd
 

What's hot (20)

The project management and information technology context
The project management and information technology contextThe project management and information technology context
The project management and information technology context
 
Sameer Mitter | Introduction to Information technology Project Management
Sameer Mitter | Introduction to Information technology Project ManagementSameer Mitter | Introduction to Information technology Project Management
Sameer Mitter | Introduction to Information technology Project Management
 
Project management by hamidun
Project management by hamidunProject management by hamidun
Project management by hamidun
 
Introduction project managemen
Introduction project managemenIntroduction project managemen
Introduction project managemen
 
Project management process groups case study
Project management process groups case studyProject management process groups case study
Project management process groups case study
 
ICT4GOV project management_2
ICT4GOV project management_2ICT4GOV project management_2
ICT4GOV project management_2
 
PMP Training Project Integration Management Part 2
PMP Training Project Integration Management Part 2PMP Training Project Integration Management Part 2
PMP Training Project Integration Management Part 2
 
Chapter 3: The Project Management Process Groups: A Case Study
Chapter 3:The Project Management Process Groups: A Case StudyChapter 3:The Project Management Process Groups: A Case Study
Chapter 3: The Project Management Process Groups: A Case Study
 
UCISA Major Projects Governance Assessment Toolkit
UCISA Major Projects Governance Assessment ToolkitUCISA Major Projects Governance Assessment Toolkit
UCISA Major Projects Governance Assessment Toolkit
 
Chapter 3
Chapter 3Chapter 3
Chapter 3
 
Infographic Slide: What is Project Management?
Infographic Slide: What is Project Management?Infographic Slide: What is Project Management?
Infographic Slide: What is Project Management?
 
Project management
Project managementProject management
Project management
 
Lecture 06: Advanced Project Management Project Organization and Integration
Lecture 06: Advanced Project Management  Project Organization and IntegrationLecture 06: Advanced Project Management  Project Organization and Integration
Lecture 06: Advanced Project Management Project Organization and Integration
 
Introduction To Project Management
Introduction To Project Management Introduction To Project Management
Introduction To Project Management
 
HI600 U02_inst_slides
HI600 U02_inst_slides HI600 U02_inst_slides
HI600 U02_inst_slides
 
PMP Training Course - Project Management Framework
PMP Training Course - Project Management FrameworkPMP Training Course - Project Management Framework
PMP Training Course - Project Management Framework
 
Project management and information technology context
Project management and information technology contextProject management and information technology context
Project management and information technology context
 
Architecture Project Management. The Open Group® conference, Paris 2016
Architecture Project Management. The Open Group® conference, Paris 2016Architecture Project Management. The Open Group® conference, Paris 2016
Architecture Project Management. The Open Group® conference, Paris 2016
 
Project management
Project managementProject management
Project management
 
Ch01
Ch01Ch01
Ch01
 

Similar to Managing Risk And Opportunity In IT Projects

Project mgmt services brochure 2013
Project mgmt services brochure 2013Project mgmt services brochure 2013
Project mgmt services brochure 2013Nidhi Gupta
 
Project mgmt services brochure 2013
Project mgmt services brochure 2013Project mgmt services brochure 2013
Project mgmt services brochure 2013Nidhi Gupta
 
Basics in Project Management
Basics in Project ManagementBasics in Project Management
Basics in Project Managementchaitanyakrsk
 
11.0 Project Risk Management Overview
11.0 Project Risk Management Overview11.0 Project Risk Management Overview
11.0 Project Risk Management OverviewDavidMcLachlan1
 
Pm certifications & accreditations
Pm certifications & accreditationsPm certifications & accreditations
Pm certifications & accreditationsmasilamani ramasamy
 
The Project Management Institute.pdf
The Project Management Institute.pdfThe Project Management Institute.pdf
The Project Management Institute.pdfTEWMAGAZINE
 
Project Management Fundamentals Course Preview
Project Management Fundamentals Course PreviewProject Management Fundamentals Course Preview
Project Management Fundamentals Course PreviewInvensis Learning
 
Breakthrough competences in the development of public administration
Breakthrough competences in the development of public administrationBreakthrough competences in the development of public administration
Breakthrough competences in the development of public administrationSPOCE Project Management
 
1. Introduction to Project Management and the Project Management Framework
1. Introduction to Project Management and the Project Management Framework1. Introduction to Project Management and the Project Management Framework
1. Introduction to Project Management and the Project Management FrameworkMeshack Shack
 
Project risk management in automotive industry
Project risk management in automotive industryProject risk management in automotive industry
Project risk management in automotive industrySumit Bhattacharya
 
Introduction to ict project management
Introduction to ict project managementIntroduction to ict project management
Introduction to ict project managementmanproy
 
L01 introduction to pm
L01 introduction to pmL01 introduction to pm
L01 introduction to pmAsa Chan
 
romi-pm-03-process-april2013.pptx
romi-pm-03-process-april2013.pptxromi-pm-03-process-april2013.pptx
romi-pm-03-process-april2013.pptxummi1206
 

Similar to Managing Risk And Opportunity In IT Projects (20)

3 Questions PM needs to ask for Stakeholder Management
3 Questions PM needs to ask for Stakeholder Management3 Questions PM needs to ask for Stakeholder Management
3 Questions PM needs to ask for Stakeholder Management
 
Project mgmt services brochure 2013
Project mgmt services brochure 2013Project mgmt services brochure 2013
Project mgmt services brochure 2013
 
Project mgmt services brochure 2013
Project mgmt services brochure 2013Project mgmt services brochure 2013
Project mgmt services brochure 2013
 
Project mgmt services brochure 2013
Project mgmt services brochure 2013Project mgmt services brochure 2013
Project mgmt services brochure 2013
 
PMExpo2017slide Eureka Service - Oracle Prime
PMExpo2017slide Eureka Service - Oracle PrimePMExpo2017slide Eureka Service - Oracle Prime
PMExpo2017slide Eureka Service - Oracle Prime
 
Basics in Project Management
Basics in Project ManagementBasics in Project Management
Basics in Project Management
 
Project Management
Project ManagementProject Management
Project Management
 
13115 intro to project management presentation
13115 intro to project management presentation13115 intro to project management presentation
13115 intro to project management presentation
 
11.0 Project Risk Management Overview
11.0 Project Risk Management Overview11.0 Project Risk Management Overview
11.0 Project Risk Management Overview
 
Pm certifications & accreditations
Pm certifications & accreditationsPm certifications & accreditations
Pm certifications & accreditations
 
The Project Management Institute.pdf
The Project Management Institute.pdfThe Project Management Institute.pdf
The Project Management Institute.pdf
 
Project Management Fundamentals Course Preview
Project Management Fundamentals Course PreviewProject Management Fundamentals Course Preview
Project Management Fundamentals Course Preview
 
Breakthrough competences in the development of public administration
Breakthrough competences in the development of public administrationBreakthrough competences in the development of public administration
Breakthrough competences in the development of public administration
 
1. Introduction to Project Management and the Project Management Framework
1. Introduction to Project Management and the Project Management Framework1. Introduction to Project Management and the Project Management Framework
1. Introduction to Project Management and the Project Management Framework
 
Project risk management in automotive industry
Project risk management in automotive industryProject risk management in automotive industry
Project risk management in automotive industry
 
Introduction to ict project management
Introduction to ict project managementIntroduction to ict project management
Introduction to ict project management
 
Project Management
Project ManagementProject Management
Project Management
 
L01 introduction to pm
L01 introduction to pmL01 introduction to pm
L01 introduction to pm
 
romi-pm-03-process-april2013.pptx
romi-pm-03-process-april2013.pptxromi-pm-03-process-april2013.pptx
romi-pm-03-process-april2013.pptx
 
u-1.ppt
u-1.pptu-1.ppt
u-1.ppt
 

Recently uploaded

Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...pujan9679
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizharallensay1
 
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in PakistanChallenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistanvineshkumarsajnani12
 
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165meghakumariji156
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...daisycvs
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel
 
Arti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfArti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfwill854175
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentationuneakwhite
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSpanmisemningshen123
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon investment
 
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...meghakumariji156
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Falcon Invoice Discounting
 
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...pujan9679
 
Kalyan Call Girl 98350*37198 Call Girls in Escort service book now
Kalyan Call Girl 98350*37198 Call Girls in Escort service book nowKalyan Call Girl 98350*37198 Call Girls in Escort service book now
Kalyan Call Girl 98350*37198 Call Girls in Escort service book nowranineha57744
 
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service AvailableBerhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Availablepr788182
 
Durg CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN durg ESCORTS
Durg CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN durg ESCORTSDurg CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN durg ESCORTS
Durg CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN durg ESCORTSkajalroy875762
 
GUWAHATI 💋 Call Girl 9827461493 Call Girls in Escort service book now
GUWAHATI 💋 Call Girl 9827461493 Call Girls in  Escort service book nowGUWAHATI 💋 Call Girl 9827461493 Call Girls in  Escort service book now
GUWAHATI 💋 Call Girl 9827461493 Call Girls in Escort service book nowkapoorjyoti4444
 
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...
joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...NadhimTaha
 

Recently uploaded (20)

Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
 
WheelTug Short Pitch Deck 2024 | Byond Insights
WheelTug Short Pitch Deck 2024 | Byond InsightsWheelTug Short Pitch Deck 2024 | Byond Insights
WheelTug Short Pitch Deck 2024 | Byond Insights
 
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in PakistanChallenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
 
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
Arti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfArti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdf
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
 
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
 
Kalyan Call Girl 98350*37198 Call Girls in Escort service book now
Kalyan Call Girl 98350*37198 Call Girls in Escort service book nowKalyan Call Girl 98350*37198 Call Girls in Escort service book now
Kalyan Call Girl 98350*37198 Call Girls in Escort service book now
 
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service AvailableBerhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
 
Durg CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN durg ESCORTS
Durg CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN durg ESCORTSDurg CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN durg ESCORTS
Durg CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN durg ESCORTS
 
GUWAHATI 💋 Call Girl 9827461493 Call Girls in Escort service book now
GUWAHATI 💋 Call Girl 9827461493 Call Girls in  Escort service book nowGUWAHATI 💋 Call Girl 9827461493 Call Girls in  Escort service book now
GUWAHATI 💋 Call Girl 9827461493 Call Girls in Escort service book now
 
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...
joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...
 

Managing Risk And Opportunity In IT Projects

  • 1. PMI OVOC 10th Annual Project Management Symposium October 12 – 14, 2010 Unleashing the Power of Project Management Template V3 Managing Risk and Opportunity in IT Projects Robert Venczel
  • 2. 3 Key Learning Points 1. Describe the risk management process – Definitions, utility theory, steps, responsibilities, etc. – Corporate strategy relationship 2. Explain the RiskIT Model – IT goals, associated metrics, and IT-related risks – IT project risk management – Risk scenarios and implementation of controls 3. Application of IT risk management – Case study 2Presented at PMI OVOC Project Management Symposium 2010
  • 3. Your Presenter • Robert Venczel, MBA, CMA, CISA, PMP, CIA • Bivium Executive Consulting Ltd. • Over 18 years of management consulting experience in both public and private sectors in the areas of: – Project and programme risk management – IT project management and governance – IT audit – Business strategy 3Presented at PMI OVOC Project Management Symposium 2010
  • 4. Agenda • Risk Management Process – A Quick Review • Project Risk Management • IT Risks vs. Overall Risk Universe • IT Project Risk Management Continuum • Case Study – SuperSoftware Inc. 4Presented at PMI OVOC Project Management Symposium 2010
  • 5. What is Risk? • Risk is defined as this uncertainty of outcome, whether positive opportunity or negative threat, of actions and events.* *Orange Book (UK) Definition 5Presented at PMI OVOC Project Management Symposium 2010
  • 6. RM Process • Risk Identification • Risk Assessment • Risk Mitigation and Monitoring • Risk Reporting 6Presented at PMI OVOC Project Management Symposium 2010
  • 7. The Riskit Risk Management Cycle 7Presented at PMI OVOC Project Management Symposium 2010 Source: Kontio, J , Getto, G. and Landes. D. (1998),Experiences in improving risk management processes using the concepts of Riskit method, SIGSOFT’98 sixth International Symposium on the Foundations of Software Engineering.
  • 8. Risk Identification • Types of risk: – Organization-wide vs. programme/project – External vs. internal – Inherent vs. residual • Risk identification: – Using common methodology – From top down and from bottom up • Part of short- and long-term business planning process • Continuous not a one-time exercise 8Presented at PMI OVOC Project Management Symposium 2010
  • 9. Risk Assessment • Utility theory • Likelihood and impact • Need to develop a simple scoring/weighting methodology that can be applied on a consistent basis across the organization. 9Presented at PMI OVOC Project Management Symposium 2010
  • 10. Impact vs. Likelihood 10Presented at PMI OVOC Project Management Symposium 2010
  • 11. Addressing Risks / Risk Tolerance  Tolerate  Treat  Transfer  Terminate  Risk tolerance vs. risk appetite 11Presented at PMI OVOC Project Management Symposium 2010
  • 12. Risk Management/Risk Mitigation • Identification of mitigating actions and controls • Ensuring that mitigating actions and controls are implemented (risk owners) • Monitoring and reporting on the effectiveness of mitigating actions and controls • Reporting and escalating problems up the management chain 12Presented at PMI OVOC Project Management Symposium 2010
  • 13. Risk Mitigation Plan • Choosing the most appropriate “treatment” or combination of treatment options • Costs and efforts vs. benefits • Risk treatment itself can introduce risks 13Presented at PMI OVOC Project Management Symposium 2010
  • 14. Risk Monitoring and Reporting • Review periodically: – If the status of risks has changed or new risks emerged – The effectiveness of the mitigation strategies against indicators – The validity of the initial assumptions – The existence of appropriate contingency plans • Reporting: – Status, performance and results – Trends and patterns 14Presented at PMI OVOC Project Management Symposium 2010
  • 15. RM Responsibilities for Risk Owners vs. Risk Managers – Risk Owners: • Deemed ultimately accountable for the effective management of specific risk categories • Do not necessarily own or control all aspects of the risk • Depend on others to help mitigate the risks • Risk Managers: • Responsibility for the risk management process • Have the authority to manage risks 15Presented at PMI OVOC Project Management Symposium 2010
  • 16. PMBOK® - Project Risk Management Project Risk Management Processes • Plan Risk Management • Identify Risks • Perform Qualitative Risk Analysis • Perform Quantitative Risk Analysis • Plan Risk Responses • Monitor and Control Risks 16Presented at PMI OVOC Project Management Symposium 2010 Source: PMI’s PMBOK Guide, Fourth Edition (2008)
  • 17. Opportunity vs. Risk • On the positive side… new business initiatives successfully enabled by IT • On the negative side… IT projects misaligned with the strategic objectives; waste of resources due to failed projects; etc. 17Presented at PMI OVOC Project Management Symposium 2010
  • 18. Defining IT Goals and Enterprise Architecture for IT 18Presented at PMI OVOC Project Management Symposium 2010 Source: ISACA’s COBIT® 4.1 Framework for IT Governance and Control (2007)
  • 19. IT Risk vs. Overall Risk Universe 19Presented at PMI OVOC Project Management Symposium 2010 Source: ISACA’s The Risk IT Framework (2009)
  • 20. IT Project Risk Management Continuum 20Presented at PMI OVOC Project Management Symposium 2010 Needs and Requirements Specifications Contractor/Team Selection Design and Development Systems Integration Conceptual Design Demonstration/ Validation Engineering, Manufacturing, Development, and Production Maintenance and Major Upgrade
  • 21. System Complexity vs. Risk 21Presented at PMI OVOC Project Management Symposium 2010 Risk(technical;cost;schedule) Complexity (technology; team; expertise; etc.)
  • 22. IT Risk Management Supports Success By enabling IT project management to: • Deal effectively with potential future events that create uncertainty. • Respond in a manner that reduces the likelihood that objectives will not be achieved and increases the likelihood of success. 22Presented at PMI OVOC Project Management Symposium 2010
  • 23. Practicing Risk Management • Integrate IT project risk management with business planning and priority setting • Promote use of the common language, framework, and process • Use common tools, techniques and models for risk mapping and monitoring • Use of risk management concepts in decision making and reporting • Consult and communicate with internal and external stakeholders throughout the process • Monitor, evaluate, and adjust systems, processes, and practices 23Presented at PMI OVOC Project Management Symposium 2010
  • 24. IT Project Risk Scenario Example 24Presented at PMI OVOC Project Management Symposium 2010 Beta Test Successful Users not ready to use the new software Cost: $15K+ Unsuccessful Project terminated because of changed business priorities Cost: $100K+ Project delayed Time: 1 month Cost: $20K+ Software development project
  • 25. Case Study – SuperSoftware Inc. • Software development project • Stakeholders • Team • Risks • Evaluation of risks (quantitative vs. qualitative) • Mitigation, monitoring and reporting • Lessons learned 25Presented at PMI OVOC Project Management Symposium 2010
  • 26. Conclusions • Get senior management’s buy in and support for a risk-aware culture. • Use risk management people who understand the business and information technology, and are also good communicators. • Successful IT risk management is all about connection and alignment with business strategy. 26Presented at PMI OVOC Project Management Symposium 2010
  • 27. Additional Resources • Committee of Sponsoring Organizations of the Treadway Commission (COSO) Enterprise Risk Management – Integrated Framework • Risk management: Principles and guidelines - International Standard, ISO 31000: 2009 • Australian/New Zealand Standard for risk management - AS/NZS 4360:2004 • Risk management policies, directives and standards developed by the Treasury Board Secretariat (TBS’s) to guide good management across the Canadian Federal Government: – Integrated Risk Management Framework (IRMF) – Integrated Risk Management Implementation Guide – Policy on Active Monitoring – Risk Management Policy – Draft Core Management Controls – Management Accountability Framework (MAF) criteria. • PMI’s PMBOK Guide, Fourth Edition (2008) • ISACA’s COBIT® 4.1 Framework for IT Governance and Control (2007) • ISACA’s The Risk IT Framework (2009) • ISACA’s The Risk IT Practitioner Guide (2009) 27Presented at PMI OVOC Project Management Symposium 2010
  • 28. For more information… • Thank you for your participation today! • For more information on the contents of this presentation, please feel free to contact me as follows: – Robert Venczel, MBA, CMA, CISA, PMP, CIA – Bivium Executive Consulting Ltd. • “Achieving Excellence Through Change” – rvenczel@biviumconsulting.ca – 613-843-7629 28Presented at PMI OVOC Project Management Symposium 2010
  • 29. Copyright Notice • The contents of this presentation are Copyright © 2010 by the presenter and PMI OVOC. • Permission is granted for participants to print the presentation handouts for use during the conference and later personal reference. • PMI OVOC reserves the right to store this content for archival purposes as a record of conference proceedings and to publish this content electronically for the purpose of disseminating conference proceedings to conference participants. • All other use, storage, retrieval, distribution, or reproduction must be authorized in advance, in writing. 29Presented at PMI OVOC Project Management Symposium 2010
  • 31. Guiding Principles 31Presented at PMI OVOC Project Management Symposium 2010 Source: ISACA’s The Risk IT Framework (2009)
  • 32. Sample IT Risk Heat Map 32Presented at PMI OVOC Project Management Symposium 2010 Poor communication Budget overrun Scope creep Inadequate functional requirements Lack of support from the top 1.00 1.20 1.40 1.60 1.80 2.00 2.20 2.40 2.60 2.80 3.00 1.00 1.20 1.40 1.60 1.80 2.00 2.20 2.40 2.60 2.80 3.00 Impact Likelihood IT Risks