Essentials of Risk Management

TM
Frederic L. Casagrande, PMP®
 Introduction
 Risk Management Governance
 Risk Management Culture
 Key elements of a Risk Register
 Risk Assessment Approaches
The Speaker
What is a Risk?
 2009 – Vice-Chair (PMI® PMO Specific Interest Group)
 2011 – Vice-President (PMI® PMO Community of Practice)
 2011 & 2012 – Program Chair (PMI® PMO Symposium)
 2013 – Judge (PMI® PMO of the Year® Award)
 2007 – Director of PMO (Interoute)
 2008 – Head of PMO (Universal Studios)
 2009 – PMO Director (AMER Group)
 2011 – Head of PMO (Emiraje Systems)
 2014 – Program Governance & Controls (ENEC)
An uncertain event or condition that, if
it occurs, has a positive or negative
effect on a project’s objectives
Practice Standard for Project Risk Management
PMI (2009)
An
Dr. David Hillson “The Risk Doctor” (2007)
Governance Key Objectives
Constitutive Elements
 Governance defines actions, grants power and verifies
performance. In Risk Management, it has several key Objectives:
◦ Define Project Specific Risk Scorecard
◦ Determine Project Risk Categories (and eventually sub-categories)
◦ Prepare the Risk Register Structure (aligned to the Project WBS)
◦ Ensure a Known Estimate at Completion (EAC) is given for the Project
◦ Define the Risk Appetite and the level of Project Risk Management effort
◦ Break down the Risk Impact into further categories – at minimum –
Financial Impact, Schedule Impact and Performance Impact (but additional
impact categories may be added, should they be required for Enterprise
Risk Management purposes, e.g. Reputation or Health & Safety)
 Governance can be established through a series of linked
documents that flow-down the requirements:
◦ A Policy Framework (e.g. a Project Specific Risk Management Policy,
and/or an Enterprise Risk Management Policy)
◦ An Enterprise Risk Management Guideline (that defines company-
wide mechanisms for dealing with risks)
◦ A Project Risk Management Plan (based on a project specific
customization of the Enterprise Guideline, if available)
◦ A Risk Management Process and its relevant Process Assets (forms,
templates, risk register, etc)
 Keep it simple
◦ A single Policy is enough
◦ Two pages is enough
 Define a clear purpose
◦ “To enforce Risk Management best practices”
 Define a scope of application
◦ Project Specific; Portfolio Related or All Company Operations
 Define Roles & Responsibilities
 Empower the Risk Manager
 SIGN-OFF BY CEO
 A more elaborated document, describing the Risk
Management Process in greater detail
 If the Risk Management Policy is established for a single
project, this might be combined with the Risk Management
Plan
 Otherwise, provides general rules that are not project
specific:
◦ How to operate within the Risk Management Process
◦ How to use the Risk Management Process Assets
◦ How to communicate Risks at various stakeholders level
Level Very Low Low Medium High Very High
Probability 1 to 20% 21 to 40% 41 to 60% 61 to 80% 81 to 99%
Financial Impact
Insignificant cost
increase
x < 0.25%
(of contract value)
Minor cost
increase
0.25% <= x < 0.5%
(of contract value)
Moderate cost
increase
0.5% <= x < 1%
(of contract value)
Critical cost
increase
1% <= x < 2%
(of contract value)
Catastrophic cost
increase
x >= 2%
(of contract value)
Schedule Impact
Insignificant time
increase to the
most critical
milestone or very
low time impact
Time increase to
the most critical
milestone(s) or
minor schedule
delays
Time increase to
the most critical
milestone(s) or
moderate
schedule delays
Time increase to
the most critical
milestone(s) or
critical schedule
delays
Time increase to
the most critical
milestone(s) or
catastrophic
schedule delay
Performance
Impact
Very minor scope
decrease, quality
degradation
barely noticeable
Only very
demanding
scenarios or minor
areas of scope
affected
Quality reduction
requires customer
approval, major
areas of scope
affected
Scope/Quality
reduction
unacceptable to
customer
Final project
deliverable is
useless
 In a multi-project environment, each project will have a
specific Risk Management Plan, flowing down from the ERM
Guideline if it exists, and from the Policy Framework. It is
the Reference Document
 It provides Project Specific metrics & KPI’s, and project
specific scorecards that have been approved and signed off
by the Project Manager and Senior Management
 It does not have to be a separate document and can be an
integrated section of the Project Management Plan
 Their number and forms can vary from one organization to
another, but it is recommended that they include at
minimum the following four Process Assets:
◦ Risk Identification Form
◦ Contingency Release Form
◦ Risk Register Template
◦ Risk Reporting Template
Critical Success Factors
Shoot the Messenger
Risk
Management
Success
Integrate with
Project
Management
Recognize the
Value of Risk
Management
Individual
Commitment &
Responsibility
Open & Honest
Communication
Organizational
Commitment
Scale Risk Effort
to Project
Risk
Management
Success
Integrate with
Project
Management
Recognize the
Value of Risk
Management
Individual
Commitment &
Responsibility
Open & Honest
Communication
Organizational
Commitment
Scale Risk Effort
to Project
“If I don’t speak out and this risk realizes, I will be in trouble, but…
If I speak out, they will shoot the messenger!”
 Raising a Project Risk is always a dilemma for a team
member!
 Employees need to feel that they can raise their hands to
identify new risks without fear of adverse consequences on
their jobs!
 For Risk Management to succeed, you need to enable a
culture where the Messenger is no longer Shot…
 This needs a massive mentality change at all levels of the
organization
 Switching to a Risk Culture is no different to any
transformation initiative. You will need to:
◦ Understand your Stakeholders and their Risk Appetite
◦ Commit the Highest Level of the organization to the Risk Culture
◦ Start small and address the low hanging fruits
 Raising a Risk is not a sign of weakness!
 Acknowledging a Proposed Risk is not a sign of failing!
 First proposed during the Project Risk Forum (Prague, CZ,
2008), the concept is to work with various stakeholders
risk profiles
 At the crossroads of Risk Management and Stakeholders
Management
 Enables you to map on a matrix the risk appetite of your
stakeholders groups to build specific “behaviors”
(Communications, Trainings or Awareness Sessions, Hand-
holding, etc.)
 This is essential in multicultural environments!
Objectives of the Risk Register
Structure of the Risk Register
 The Risk Register is a tool that serves several purposes:
◦ Collecting all identified risks, regardless of their source or status
◦ Providing the organization with a clear and complete snapshot of
the overall risk exposure of a project/portfolio/company
 Depending on the platform used (MS-Excel, Integrated Risk
Management Software, ERP), the features will change (e.g.
variance tracking, history graphs, etc.), but those two key
elements have to be present
 You can start with a very simple MS-Excel spreadsheet
 Risk Information
◦ Risk ID Unique Risk Identifier (can include “R” or
“O” to identify opportunities)
◦ Risk Description “There is a Risk that…” (describes impact as well)
◦ Raised Date When has the Risk been identified (form)
◦ Risk Status Proposed, Open/Rejected, Closed/Realized
◦ Risk Owner Accountable for the specific risk
◦ Risk Category Derived from the Risk Management Plan
◦ WBS Highest element impacted by the Risk
◦ Severity Low/Medium/High (Calculated, based on
Scorecard)
 Impact Information
◦ Un-weighted Exposure Estimated by SME
◦ Probability Estimated by SME
◦ Weighted Exposure Calculated
◦ Financial Impact Low/Medium/High (Calculated)
◦ Schedule Impact Low/Medium/High (Estimated by SME)
◦ Performance Impact Low/Medium/High (Estimated by SME)
 Response Information
◦ Strategy Accept/Reduce/Transfer/Avoid
◦ Response Owner Can be different from Risk Owner
◦ Response Description Explains what needs to be done
◦ Response Cost To be compared with the Weighted Risk
 When choosing a platform, bare in mind that the
information contained in the Risk Register must be easy to
filter and compile:
◦ To provide an accurate subset based on specific criteria (Top Risks,
Risks pertaining to a domain of work, a department, a specific
product, or a WBS element)
◦ To provide a unique, demonstrable and undisputed value of the
overall risk exposure for the organization (or the project). This will
give you your requirement for Contingency, and ultimately your
“Risk Index” (the ratio between the exposure level and the available
contingency)
The Best Approach
Top-Down
Bottom-Up
 There is constant argument as to which is the best
approach to risk assessment: Top-Down or Bottom-Up?
 The key there is to identify as many real risks as possible
 How to best enable this? By capturing as many risks as
possible (real ones, duplicates, wrong ones, fake ones, etc.).
Consider the Risk Management process as a funnel. You
need an enormous amount of risks at the entrance to end
with an accurate depiction of your risk portfolio
 For this, you will perform both a Top-Down and a Bottom-
Up Risk Assessment! And you will do so continuously!
 The Top-Down Approach is inherited from the audit
industry. This is where the most senior members of the
team identify the key risks that have an overall impact on
the project or the program
 In most of the cases, those “meta-risks” are already
identified at the bid phase, although they might evolve
over time
 The Bottom-Up Approach assigns risk impact based on the
Work Breakdown Structure of the project
 It typically involves a larger portion of the project team
(ideally … everyone)
 The goal of this exercise is to identify ALL possible risks,
even if it implies to identify the same risk at several levels
 The Risk Manager will “de-duplicate” risks with the
individuals who raised risks deemed identical
Essentials of Risk Management
Essentials of Risk Management
1 of 31

Recommended

RisK, RiSk MaNaGeMeNt & EnterPRise RisK ManaGemeNT by
RisK, RiSk MaNaGeMeNt & EnterPRise RisK ManaGemeNTRisK, RiSk MaNaGeMeNt & EnterPRise RisK ManaGemeNT
RisK, RiSk MaNaGeMeNt & EnterPRise RisK ManaGemeNTSonu Sah
855 views45 slides
Risk management by
Risk managementRisk management
Risk managementAglaia Connect
1.6K views12 slides
Risk Appetite by
Risk AppetiteRisk Appetite
Risk AppetiteHassan Zaitoun
3.1K views12 slides
COSO VS ERM - by
COSO VS ERM - COSO VS ERM -
COSO VS ERM - Naresh Parandhaman
353 views46 slides
Risk Identification PowerPoint Presentation Slide by
Risk Identification PowerPoint Presentation SlideRisk Identification PowerPoint Presentation Slide
Risk Identification PowerPoint Presentation SlideSlideTeam
773 views31 slides
Enterprise risk & risk management - I by
Enterprise risk & risk management - IEnterprise risk & risk management - I
Enterprise risk & risk management - IDr. Shiv S Tripathi
3.2K views20 slides

More Related Content

What's hot

Enterprise Risk Management by
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk ManagementPYA, P.C.
9.3K views29 slides
Risk Management Procedure PowerPoint Presentation Slides by
Risk Management Procedure PowerPoint Presentation Slides Risk Management Procedure PowerPoint Presentation Slides
Risk Management Procedure PowerPoint Presentation Slides SlideTeam
510 views48 slides
Enterprise Risk Management by
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk ManagementCroydon Consulting, LLC
14.3K views21 slides
Corporate Risk Management by
Corporate Risk ManagementCorporate Risk Management
Corporate Risk ManagementShravan Bhumkar
18.9K views15 slides
Risk appetite by
Risk appetite Risk appetite
Risk appetite Michel Rochette
13.3K views30 slides
Introduction to Risk Management by
Introduction to Risk ManagementIntroduction to Risk Management
Introduction to Risk ManagementFAA Safety Team Central Florida
21.3K views44 slides

What's hot(20)

Enterprise Risk Management by PYA, P.C.
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
PYA, P.C.9.3K views
Risk Management Procedure PowerPoint Presentation Slides by SlideTeam
Risk Management Procedure PowerPoint Presentation Slides Risk Management Procedure PowerPoint Presentation Slides
Risk Management Procedure PowerPoint Presentation Slides
SlideTeam510 views
RISK MANAGEMENT: ISSUES, CHALLENGES AND OPPORTUNITY by Ashim Sharma
RISK MANAGEMENT: ISSUES, CHALLENGES AND OPPORTUNITYRISK MANAGEMENT: ISSUES, CHALLENGES AND OPPORTUNITY
RISK MANAGEMENT: ISSUES, CHALLENGES AND OPPORTUNITY
Ashim Sharma516 views
Risk & Risk Management by ansula
Risk & Risk ManagementRisk & Risk Management
Risk & Risk Management
ansula44.2K views
Risk-management by Umesh Gupta
 Risk-management Risk-management
Risk-management
Umesh Gupta19.7K views
Shaping Your Culture via Risk Appetite by Andrew Smart
Shaping Your Culture via Risk Appetite Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite
Andrew Smart2.2K views
Risk Management Fundamentals by mikaelastafrace
Risk Management FundamentalsRisk Management Fundamentals
Risk Management Fundamentals
mikaelastafrace13.1K views
The importance of risk management in business by r2financial
The importance of risk management in businessThe importance of risk management in business
The importance of risk management in business
r2financial34.2K views
Project risk management workshops by shippers1000
Project risk management workshopsProject risk management workshops
Project risk management workshops
shippers100018.3K views
Risk identification by murukkada
Risk identificationRisk identification
Risk identification
murukkada20.9K views

Similar to Essentials of Risk Management

Project/Program Risk management by
Project/Program Risk managementProject/Program Risk management
Project/Program Risk managementShan Sokhanvar (CISM, AWS-SAP, PMP, MCTS)
245 views37 slides
Beyond PMP: Risk Management by
Beyond PMP: Risk ManagementBeyond PMP: Risk Management
Beyond PMP: Risk Managementabhinayverma
990 views16 slides
Critical role of_risk_assessment_in_international_projects_en by
Critical role of_risk_assessment_in_international_projects_enCritical role of_risk_assessment_in_international_projects_en
Critical role of_risk_assessment_in_international_projects_enVyacheslav Guzovsky
458 views55 slides
8. project risk management by
8. project risk management8. project risk management
8. project risk managementMohamed Salah Eldien Mohamed Ali
3K views8 slides
Risk management by
Risk managementRisk management
Risk managementEmad Nassar
194 views57 slides
Project mngmnt risks3.2 by
Project mngmnt risks3.2Project mngmnt risks3.2
Project mngmnt risks3.2Ananya Indrajith
178 views32 slides

Similar to Essentials of Risk Management(20)

Beyond PMP: Risk Management by abhinayverma
Beyond PMP: Risk ManagementBeyond PMP: Risk Management
Beyond PMP: Risk Management
abhinayverma990 views
Critical role of_risk_assessment_in_international_projects_en by Vyacheslav Guzovsky
Critical role of_risk_assessment_in_international_projects_enCritical role of_risk_assessment_in_international_projects_en
Critical role of_risk_assessment_in_international_projects_en
Project Risk Management-Pankaj K Sinha by Pankaj K Sinha
Project Risk Management-Pankaj K SinhaProject Risk Management-Pankaj K Sinha
Project Risk Management-Pankaj K Sinha
Pankaj K Sinha3.1K views
Project Management by Mostafa Ewees by Mostafa Ewees
Project Management  by Mostafa EweesProject Management  by Mostafa Ewees
Project Management by Mostafa Ewees
Mostafa Ewees827 views
Final Class Presentation on Determining Project Stakeholders & Risks.pptx by GeorgeKabongah2
Final Class Presentation on Determining Project Stakeholders & Risks.pptxFinal Class Presentation on Determining Project Stakeholders & Risks.pptx
Final Class Presentation on Determining Project Stakeholders & Risks.pptx
GeorgeKabongah28 views
Presentation Project managment by Malan Bothma
Presentation Project managmentPresentation Project managment
Presentation Project managment
Malan Bothma744 views
project risk management by Ashima Thakur
project risk managementproject risk management
project risk management
Ashima Thakur1.3K views
Risk Analysis In IT Projects - TNS09 by Thomas Danford
Risk Analysis In IT Projects - TNS09Risk Analysis In IT Projects - TNS09
Risk Analysis In IT Projects - TNS09
Thomas Danford1.6K views
Control only.pdf by NmnKmr2
Control only.pdfControl only.pdf
Control only.pdf
NmnKmr26 views
Li Rmp Prep by mchlstldr
Li Rmp PrepLi Rmp Prep
Li Rmp Prep
mchlstldr702 views

Recently uploaded

Cracking the Optimism vs Pessimism Code.pptx by
Cracking the Optimism vs Pessimism Code.pptxCracking the Optimism vs Pessimism Code.pptx
Cracking the Optimism vs Pessimism Code.pptxWorkforce Group
36 views18 slides
Sohail Ahmed Profile by
Sohail Ahmed ProfileSohail Ahmed Profile
Sohail Ahmed ProfileSOHAIL AHMED - The Rising STAR
11 views3 slides
v20231127 WHOPE BEMA Day One Sendai Framework Volunteer Workshop Session Zoom... by
v20231127 WHOPE BEMA Day One Sendai Framework Volunteer Workshop Session Zoom...v20231127 WHOPE BEMA Day One Sendai Framework Volunteer Workshop Session Zoom...
v20231127 WHOPE BEMA Day One Sendai Framework Volunteer Workshop Session Zoom...Andrew Networks
51 views40 slides
Narcissism vs Leadership (1).pdf by
Narcissism vs Leadership (1).pdfNarcissism vs Leadership (1).pdf
Narcissism vs Leadership (1).pdfkullmd
12 views5 slides
balixa.io Plan.pdf by
balixa.io Plan.pdfbalixa.io Plan.pdf
balixa.io Plan.pdftycoonone91
30 views29 slides

Recently uploaded(12)

Cracking the Optimism vs Pessimism Code.pptx by Workforce Group
Cracking the Optimism vs Pessimism Code.pptxCracking the Optimism vs Pessimism Code.pptx
Cracking the Optimism vs Pessimism Code.pptx
Workforce Group36 views
v20231127 WHOPE BEMA Day One Sendai Framework Volunteer Workshop Session Zoom... by Andrew Networks
v20231127 WHOPE BEMA Day One Sendai Framework Volunteer Workshop Session Zoom...v20231127 WHOPE BEMA Day One Sendai Framework Volunteer Workshop Session Zoom...
v20231127 WHOPE BEMA Day One Sendai Framework Volunteer Workshop Session Zoom...
Andrew Networks51 views
Narcissism vs Leadership (1).pdf by kullmd
Narcissism vs Leadership (1).pdfNarcissism vs Leadership (1).pdf
Narcissism vs Leadership (1).pdf
kullmd12 views
Intuitively Moving Institutions Towards Global Regulatory Resilience by Ajaz Hussain
Intuitively Moving Institutions Towards Global Regulatory Resilience Intuitively Moving Institutions Towards Global Regulatory Resilience
Intuitively Moving Institutions Towards Global Regulatory Resilience
Ajaz Hussain134 views
TAX ANALYSIS (CASE OF RWANDA).pptx by SadamuFrancois
TAX ANALYSIS (CASE  OF RWANDA).pptxTAX ANALYSIS (CASE  OF RWANDA).pptx
TAX ANALYSIS (CASE OF RWANDA).pptx
SadamuFrancois14 views
What Is Psychological Safety? by Alex Clapson
What Is Psychological Safety?What Is Psychological Safety?
What Is Psychological Safety?
Alex Clapson29 views
Creating Unity Through Systems Thinking - Southern Cross Case Study.pptx by y9v9xbdk72
Creating Unity Through Systems Thinking - Southern Cross Case Study.pptxCreating Unity Through Systems Thinking - Southern Cross Case Study.pptx
Creating Unity Through Systems Thinking - Southern Cross Case Study.pptx
y9v9xbdk7212 views

Essentials of Risk Management

  • 2.  Introduction  Risk Management Governance  Risk Management Culture  Key elements of a Risk Register  Risk Assessment Approaches
  • 4.  2009 – Vice-Chair (PMI® PMO Specific Interest Group)  2011 – Vice-President (PMI® PMO Community of Practice)  2011 & 2012 – Program Chair (PMI® PMO Symposium)  2013 – Judge (PMI® PMO of the Year® Award)  2007 – Director of PMO (Interoute)  2008 – Head of PMO (Universal Studios)  2009 – PMO Director (AMER Group)  2011 – Head of PMO (Emiraje Systems)  2014 – Program Governance & Controls (ENEC)
  • 5. An uncertain event or condition that, if it occurs, has a positive or negative effect on a project’s objectives Practice Standard for Project Risk Management PMI (2009)
  • 6. An Dr. David Hillson “The Risk Doctor” (2007)
  • 8.  Governance defines actions, grants power and verifies performance. In Risk Management, it has several key Objectives: ◦ Define Project Specific Risk Scorecard ◦ Determine Project Risk Categories (and eventually sub-categories) ◦ Prepare the Risk Register Structure (aligned to the Project WBS) ◦ Ensure a Known Estimate at Completion (EAC) is given for the Project ◦ Define the Risk Appetite and the level of Project Risk Management effort ◦ Break down the Risk Impact into further categories – at minimum – Financial Impact, Schedule Impact and Performance Impact (but additional impact categories may be added, should they be required for Enterprise Risk Management purposes, e.g. Reputation or Health & Safety)
  • 9.  Governance can be established through a series of linked documents that flow-down the requirements: ◦ A Policy Framework (e.g. a Project Specific Risk Management Policy, and/or an Enterprise Risk Management Policy) ◦ An Enterprise Risk Management Guideline (that defines company- wide mechanisms for dealing with risks) ◦ A Project Risk Management Plan (based on a project specific customization of the Enterprise Guideline, if available) ◦ A Risk Management Process and its relevant Process Assets (forms, templates, risk register, etc)
  • 10.  Keep it simple ◦ A single Policy is enough ◦ Two pages is enough  Define a clear purpose ◦ “To enforce Risk Management best practices”  Define a scope of application ◦ Project Specific; Portfolio Related or All Company Operations  Define Roles & Responsibilities  Empower the Risk Manager  SIGN-OFF BY CEO
  • 11.  A more elaborated document, describing the Risk Management Process in greater detail  If the Risk Management Policy is established for a single project, this might be combined with the Risk Management Plan  Otherwise, provides general rules that are not project specific: ◦ How to operate within the Risk Management Process ◦ How to use the Risk Management Process Assets ◦ How to communicate Risks at various stakeholders level
  • 12. Level Very Low Low Medium High Very High Probability 1 to 20% 21 to 40% 41 to 60% 61 to 80% 81 to 99% Financial Impact Insignificant cost increase x < 0.25% (of contract value) Minor cost increase 0.25% <= x < 0.5% (of contract value) Moderate cost increase 0.5% <= x < 1% (of contract value) Critical cost increase 1% <= x < 2% (of contract value) Catastrophic cost increase x >= 2% (of contract value) Schedule Impact Insignificant time increase to the most critical milestone or very low time impact Time increase to the most critical milestone(s) or minor schedule delays Time increase to the most critical milestone(s) or moderate schedule delays Time increase to the most critical milestone(s) or critical schedule delays Time increase to the most critical milestone(s) or catastrophic schedule delay Performance Impact Very minor scope decrease, quality degradation barely noticeable Only very demanding scenarios or minor areas of scope affected Quality reduction requires customer approval, major areas of scope affected Scope/Quality reduction unacceptable to customer Final project deliverable is useless
  • 13.  In a multi-project environment, each project will have a specific Risk Management Plan, flowing down from the ERM Guideline if it exists, and from the Policy Framework. It is the Reference Document  It provides Project Specific metrics & KPI’s, and project specific scorecards that have been approved and signed off by the Project Manager and Senior Management  It does not have to be a separate document and can be an integrated section of the Project Management Plan
  • 14.  Their number and forms can vary from one organization to another, but it is recommended that they include at minimum the following four Process Assets: ◦ Risk Identification Form ◦ Contingency Release Form ◦ Risk Register Template ◦ Risk Reporting Template
  • 16. Risk Management Success Integrate with Project Management Recognize the Value of Risk Management Individual Commitment & Responsibility Open & Honest Communication Organizational Commitment Scale Risk Effort to Project Risk Management Success Integrate with Project Management Recognize the Value of Risk Management Individual Commitment & Responsibility Open & Honest Communication Organizational Commitment Scale Risk Effort to Project
  • 17. “If I don’t speak out and this risk realizes, I will be in trouble, but… If I speak out, they will shoot the messenger!”  Raising a Project Risk is always a dilemma for a team member!  Employees need to feel that they can raise their hands to identify new risks without fear of adverse consequences on their jobs!  For Risk Management to succeed, you need to enable a culture where the Messenger is no longer Shot…
  • 18.  This needs a massive mentality change at all levels of the organization  Switching to a Risk Culture is no different to any transformation initiative. You will need to: ◦ Understand your Stakeholders and their Risk Appetite ◦ Commit the Highest Level of the organization to the Risk Culture ◦ Start small and address the low hanging fruits  Raising a Risk is not a sign of weakness!  Acknowledging a Proposed Risk is not a sign of failing!
  • 19.  First proposed during the Project Risk Forum (Prague, CZ, 2008), the concept is to work with various stakeholders risk profiles  At the crossroads of Risk Management and Stakeholders Management  Enables you to map on a matrix the risk appetite of your stakeholders groups to build specific “behaviors” (Communications, Trainings or Awareness Sessions, Hand- holding, etc.)  This is essential in multicultural environments!
  • 20. Objectives of the Risk Register Structure of the Risk Register
  • 21.  The Risk Register is a tool that serves several purposes: ◦ Collecting all identified risks, regardless of their source or status ◦ Providing the organization with a clear and complete snapshot of the overall risk exposure of a project/portfolio/company  Depending on the platform used (MS-Excel, Integrated Risk Management Software, ERP), the features will change (e.g. variance tracking, history graphs, etc.), but those two key elements have to be present  You can start with a very simple MS-Excel spreadsheet
  • 22.  Risk Information ◦ Risk ID Unique Risk Identifier (can include “R” or “O” to identify opportunities) ◦ Risk Description “There is a Risk that…” (describes impact as well) ◦ Raised Date When has the Risk been identified (form) ◦ Risk Status Proposed, Open/Rejected, Closed/Realized ◦ Risk Owner Accountable for the specific risk ◦ Risk Category Derived from the Risk Management Plan ◦ WBS Highest element impacted by the Risk ◦ Severity Low/Medium/High (Calculated, based on Scorecard)
  • 23.  Impact Information ◦ Un-weighted Exposure Estimated by SME ◦ Probability Estimated by SME ◦ Weighted Exposure Calculated ◦ Financial Impact Low/Medium/High (Calculated) ◦ Schedule Impact Low/Medium/High (Estimated by SME) ◦ Performance Impact Low/Medium/High (Estimated by SME)
  • 24.  Response Information ◦ Strategy Accept/Reduce/Transfer/Avoid ◦ Response Owner Can be different from Risk Owner ◦ Response Description Explains what needs to be done ◦ Response Cost To be compared with the Weighted Risk
  • 25.  When choosing a platform, bare in mind that the information contained in the Risk Register must be easy to filter and compile: ◦ To provide an accurate subset based on specific criteria (Top Risks, Risks pertaining to a domain of work, a department, a specific product, or a WBS element) ◦ To provide a unique, demonstrable and undisputed value of the overall risk exposure for the organization (or the project). This will give you your requirement for Contingency, and ultimately your “Risk Index” (the ratio between the exposure level and the available contingency)
  • 27.  There is constant argument as to which is the best approach to risk assessment: Top-Down or Bottom-Up?  The key there is to identify as many real risks as possible  How to best enable this? By capturing as many risks as possible (real ones, duplicates, wrong ones, fake ones, etc.). Consider the Risk Management process as a funnel. You need an enormous amount of risks at the entrance to end with an accurate depiction of your risk portfolio  For this, you will perform both a Top-Down and a Bottom- Up Risk Assessment! And you will do so continuously!
  • 28.  The Top-Down Approach is inherited from the audit industry. This is where the most senior members of the team identify the key risks that have an overall impact on the project or the program  In most of the cases, those “meta-risks” are already identified at the bid phase, although they might evolve over time
  • 29.  The Bottom-Up Approach assigns risk impact based on the Work Breakdown Structure of the project  It typically involves a larger portion of the project team (ideally … everyone)  The goal of this exercise is to identify ALL possible risks, even if it implies to identify the same risk at several levels  The Risk Manager will “de-duplicate” risks with the individuals who raised risks deemed identical