SlideShare a Scribd company logo
IT Project Risk Management Framework The following slides present a  Project Risk Management Framework that can be used to categorize IT Projects by both Business Impact and Project Factor Risk Roelf Woldring WCI (Workplace Competence International Limited) Hillsburgh, Ontario, Canada © 2007 to 2010 www.wciltd.com
To ensure that projects receive a comprehensive  review, all IT project will reviewed using 2 frameworks: Business impact  -  What happens to the business if the project fails? Ensures that smaller projects with a high business impact are not overlooked The risk factor profile of the project What characteristics of the project contribute to its overall riskiness? Provides a consistent classification of a project on a standard project risk profile Sets up the depth to which the following processes will be applied Risk mitigation planning and progress review Project management and progress review Architectural review
Business Impact Framework   To identify projects with a significant business impact (BI), regardless of project size, each project will be reviewed against the following set of questions : Question Business Impact Dimension Given the rating on the previous questions, what is the overall business impact rating for this project? Overall Business Impact Rating What would the impact be on firm’s productivity if the project was not fully implemented? Productivity What would the impact be on the firm’s competitive position if the project were not fully implemented? Competitive Position What would the financial impact be if the project failed to implement on schedule? Financial Impact What would the impact be on the firm’s survival if the project failed to implement on schedule? Survival Time To what extent would the customer be impacted if the project failed to meet the schedule? Reputation What would the impact be on the firm (or its business unit’s) strategic position if the project was not completed? Strategic Significance Impact Rating 1  2  3  4  5  6  7  8  9 10 Low High Medium 1  2  3  4  5  6  7  8  9 10 Low High Medium 1  2  3  4  5  6  7  8  9 10 Low High Medium 1  2  3  4  5  6  7  8  9 10 Low High Medium 1  2  3  4  5  6  7  8  9 10 Low High Medium 1  2  3  4  5  6  7  8  9 10 Low High Medium 1  2  3  4  5  6  7  8  9 10 Low High Medium
Project Risk Assessment Framework  To identify projects with a significant project risk, regardless of project nature, each project will be reviewed against the following set of questions : One More than 3 Well Established New Lots None Most Have Worked  Together Before New to One  Another Most Have Experience With Similar Projects None Less than 10 More than 50 Less than $50K More than $10 million 7 6 5 4 3 2 1 How many of our firm’s business groups or departments will be impacted by the implementation of this project? Organizational Complexity Does our firm have experience with these technologies, or are they new to us, even if established in the IT Industry? Technology: Newness to Firm Is the technology being used to develop or to deliver the project results to the business new in the IT industry? Technology: Newness of Technology Have project team members worked together before on projects, either at our firm, or at other locations? Project Team: Experience Working Together Do project team members have experience with similar types of projects, either at our firm or other locations? Project Team: Experience with Similar Project What is the size of the project team? Project Size:  Team Members What is the size of the project budget? Project Size: $ Risk Rating Low  High Question Project Risk Dimension 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10
Project Risk Assessment Framework continued  To identify projects with a significant project risk, regardless of project nature, each project will be reviewed against the following set of questions : Each risk project dimension that has a “high” rating needs to be addressed with a specific risk mitigation plan or tactic.  Progress on the effectiveness of each risk mitigation tactic will be part of normal project monitoring . Not very visible Inside or outside Firm Very  Visible Yes, Lots No Transaction /  Lots of previous  Experience with at Firm Complex Business Rules / Little Previous Experience 1 Vendor More than 3 11 10 9 8 Given the ratings on the previous project risk dimensions, what is the overall summary risk rating for this project? 12. Overall Project Risk Rating Is this a highly visible project, in that delays in implementation or other project difficulties, will be immediately apparent: inside our firm … outside our firm? Project Visibility Does the project manager’s experience and background include projects of similar size and content? Project Manager: Fit to Project How complex is the business area that will be addressed by the project? Are the business rules straight forward and transactional, or do they involve interacting decision matrixes? Inherent Business Complexity How many outsourced or other vendors are involved in the project, or are crucial suppliers during the life of the project? Vendor Involvement Risk Rating Low  High Question Project Risk Dimension 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10 1  2  3  4  5  6  7  8  9 10
The Psychology of Project Risk Assessment Project team members have to  “believe”  they will succeed in order to be motivated to work hard on the project  This influences their risk assessment – no matter how hard they try to be “ objective ” in their risk assessments, there is a tendency to be “ too positive ” The best business impact and project factor risk assessments are done using  a Delphi approach Get appropriate project team members to do their assessments independently of one another  Get “ a similar number ” of project knowledgeable but not “project involved” people to also do an assessment independently of one another  Average the two Compare them If they match     good probability of accurate assessment   If they don’t and  outside is more negative    use it   If they don’t and outside is more positive     they may not know enough about the project –  use the project team’s
Project Risk Profiles are Summarized in Radar Diagrams  (Also Known As “Spider Nets”) The greater the area inside the  boundary, the higher the project risk profile. Overall Project Risk Rating: 8 10 Project Visibility 11 3 Project Manager Fit 10 8 Business Complexity 9 7 Vendor Involvement 8 9 Organizational Complexity 7 10 Technology New To Our Firm 6 4 Technology New In Industry 5 8 Team Experience As Team 4 8 Team Experience with Similar Projects 3 5 # Team Members 2 5 Project Size: $ 1 Rating
Projects Can be Compared Based  on their Business Impact and Risk Profiles High risk,  high impact,  large projects  require a greater degree of project management and review.  Project A Project E Project B Project C Project D
What happens next? Project Failure has great negative Business Impact Ensure steering committee is headed by  a senior business representative  who will be impacted if the project fails  Committee meets regularly / project status and issue reports distributed to both business and IT senior management Staff project for success  – put the best IT and business people on it  Project has large “project factor risk” Deep architectural and technical review –  by IT architects and technical specialists external to the project Extensive risk mitigation planning Regular project status and issue review by senior IT managers from outside project reporting hierarchy – e.g.  PMO reviews Project status and issue reports distributed to Top IT leaders Project Failure has great negative Business Impact   Project has large “project factor risk” Do everything on both lists Low Business Impact / Low Project Risk Apply normal project management processes and reporting Project A Project E Project B Project C Project D

More Related Content

PDF
Risk Appetite: new challenges to manage an insurance company
PDF
Risk Appetite Caa Dec08 (1)
PDF
Risk appetite
PDF
Grant Thornton - Risk appetite: A market study UK 2012
PDF
Risk Appetite
PDF
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
PDF
127017438_RMA_OperationalRiskAppetite_v1.0
PDF
Risk Appetite: A new Menu under Basel 3? Pieter Klaassen (UBS) voor het Zande...
Risk Appetite: new challenges to manage an insurance company
Risk Appetite Caa Dec08 (1)
Risk appetite
Grant Thornton - Risk appetite: A market study UK 2012
Risk Appetite
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
127017438_RMA_OperationalRiskAppetite_v1.0
Risk Appetite: A new Menu under Basel 3? Pieter Klaassen (UBS) voor het Zande...

What's hot (20)

PPTX
10 Aspects of a Good Risk Appetite Implementation Process
PDF
Irm Risk Appetite
PDF
Governance in Enterprise Risk Management, presented by Michael Lawrence, 10th...
PDF
Conference 2010 Risk Appetite Includes Handouts And Output
PDF
Risk Appetite
PDF
Risk Management Essentials for Bankers
PPT
Setting credit limits
PPS
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
PDF
How to Build an Enterprise Risk Management Framework
PDF
Enterprise Risk Management as a Core Management Process
PPTX
Risk Reimagined! Series- The Relationship Between Strategy, Governance and Ri...
PDF
Risk Health Check
PDF
Risk Culture & Risk Appetite
PDF
Sharing Practice on Enterprise Risk Management (ERM)
PDF
Emergence of the Chief Risk Officer function
PPTX
Aligning strategy decisions with risk appetite, presented by David Shearer, 1...
PDF
Enterprise Risk Management Workbook Series
PPTX
Enterprise Risk Management Erm
DOCX
Enterprise risk management
PPTX
CFO Risk Intelligence - Harvey Christophers
10 Aspects of a Good Risk Appetite Implementation Process
Irm Risk Appetite
Governance in Enterprise Risk Management, presented by Michael Lawrence, 10th...
Conference 2010 Risk Appetite Includes Handouts And Output
Risk Appetite
Risk Management Essentials for Bankers
Setting credit limits
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
How to Build an Enterprise Risk Management Framework
Enterprise Risk Management as a Core Management Process
Risk Reimagined! Series- The Relationship Between Strategy, Governance and Ri...
Risk Health Check
Risk Culture & Risk Appetite
Sharing Practice on Enterprise Risk Management (ERM)
Emergence of the Chief Risk Officer function
Aligning strategy decisions with risk appetite, presented by David Shearer, 1...
Enterprise Risk Management Workbook Series
Enterprise Risk Management Erm
Enterprise risk management
CFO Risk Intelligence - Harvey Christophers
Ad

Similar to A Framework for Managing Project Risk (20)

PPTX
Project Risk Management ( With :Decision tree analysi,Simulation,Sensitivity ...
PPT
Project Risk Management - Introduction 2011
PDF
Software Project Management: Risk Management
PPTX
Presentation-RA-R1-30-10-2022.pptx
PPTX
Sincronus 1- Kegiatan SInkronus 1 (PraOrientasi Pelatihan)
PDF
Project Risk fheili
PDF
PPT
Unit 8-risk manaegement (1) -
PPTX
Risk Management
PPT
Project Risk Management for computer science.ppt
PPT
Project Risk management
PDF
SPM RISK PLANNING.pdfddddddddddddddddddddddddddddddddddddddddddddddd
PPT
project_risk_mgmt_final 1.ppt
PPT
Risk management(software engineering)
PPTX
Андрій Мудрий «Risk managemnt: Welcome to Risk World»
PPTX
Андрій Мудрий “Risk managemnt: Welcome to Risk World” Lviv Project Managemen...
PPTX
Risk Management
PPT
Schwalbe-11ProjectRisk.ppt
PDF
risk-management-121021125051-phpapp02 (1).pdf
PPT
Risk-management
Project Risk Management ( With :Decision tree analysi,Simulation,Sensitivity ...
Project Risk Management - Introduction 2011
Software Project Management: Risk Management
Presentation-RA-R1-30-10-2022.pptx
Sincronus 1- Kegiatan SInkronus 1 (PraOrientasi Pelatihan)
Project Risk fheili
Unit 8-risk manaegement (1) -
Risk Management
Project Risk Management for computer science.ppt
Project Risk management
SPM RISK PLANNING.pdfddddddddddddddddddddddddddddddddddddddddddddddd
project_risk_mgmt_final 1.ppt
Risk management(software engineering)
Андрій Мудрий «Risk managemnt: Welcome to Risk World»
Андрій Мудрий “Risk managemnt: Welcome to Risk World” Lviv Project Managemen...
Risk Management
Schwalbe-11ProjectRisk.ppt
risk-management-121021125051-phpapp02 (1).pdf
Risk-management
Ad

A Framework for Managing Project Risk

  • 1. IT Project Risk Management Framework The following slides present a Project Risk Management Framework that can be used to categorize IT Projects by both Business Impact and Project Factor Risk Roelf Woldring WCI (Workplace Competence International Limited) Hillsburgh, Ontario, Canada © 2007 to 2010 www.wciltd.com
  • 2. To ensure that projects receive a comprehensive review, all IT project will reviewed using 2 frameworks: Business impact - What happens to the business if the project fails? Ensures that smaller projects with a high business impact are not overlooked The risk factor profile of the project What characteristics of the project contribute to its overall riskiness? Provides a consistent classification of a project on a standard project risk profile Sets up the depth to which the following processes will be applied Risk mitigation planning and progress review Project management and progress review Architectural review
  • 3. Business Impact Framework To identify projects with a significant business impact (BI), regardless of project size, each project will be reviewed against the following set of questions : Question Business Impact Dimension Given the rating on the previous questions, what is the overall business impact rating for this project? Overall Business Impact Rating What would the impact be on firm’s productivity if the project was not fully implemented? Productivity What would the impact be on the firm’s competitive position if the project were not fully implemented? Competitive Position What would the financial impact be if the project failed to implement on schedule? Financial Impact What would the impact be on the firm’s survival if the project failed to implement on schedule? Survival Time To what extent would the customer be impacted if the project failed to meet the schedule? Reputation What would the impact be on the firm (or its business unit’s) strategic position if the project was not completed? Strategic Significance Impact Rating 1 2 3 4 5 6 7 8 9 10 Low High Medium 1 2 3 4 5 6 7 8 9 10 Low High Medium 1 2 3 4 5 6 7 8 9 10 Low High Medium 1 2 3 4 5 6 7 8 9 10 Low High Medium 1 2 3 4 5 6 7 8 9 10 Low High Medium 1 2 3 4 5 6 7 8 9 10 Low High Medium 1 2 3 4 5 6 7 8 9 10 Low High Medium
  • 4. Project Risk Assessment Framework To identify projects with a significant project risk, regardless of project nature, each project will be reviewed against the following set of questions : One More than 3 Well Established New Lots None Most Have Worked Together Before New to One Another Most Have Experience With Similar Projects None Less than 10 More than 50 Less than $50K More than $10 million 7 6 5 4 3 2 1 How many of our firm’s business groups or departments will be impacted by the implementation of this project? Organizational Complexity Does our firm have experience with these technologies, or are they new to us, even if established in the IT Industry? Technology: Newness to Firm Is the technology being used to develop or to deliver the project results to the business new in the IT industry? Technology: Newness of Technology Have project team members worked together before on projects, either at our firm, or at other locations? Project Team: Experience Working Together Do project team members have experience with similar types of projects, either at our firm or other locations? Project Team: Experience with Similar Project What is the size of the project team? Project Size: Team Members What is the size of the project budget? Project Size: $ Risk Rating Low High Question Project Risk Dimension 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10
  • 5. Project Risk Assessment Framework continued To identify projects with a significant project risk, regardless of project nature, each project will be reviewed against the following set of questions : Each risk project dimension that has a “high” rating needs to be addressed with a specific risk mitigation plan or tactic. Progress on the effectiveness of each risk mitigation tactic will be part of normal project monitoring . Not very visible Inside or outside Firm Very Visible Yes, Lots No Transaction / Lots of previous Experience with at Firm Complex Business Rules / Little Previous Experience 1 Vendor More than 3 11 10 9 8 Given the ratings on the previous project risk dimensions, what is the overall summary risk rating for this project? 12. Overall Project Risk Rating Is this a highly visible project, in that delays in implementation or other project difficulties, will be immediately apparent: inside our firm … outside our firm? Project Visibility Does the project manager’s experience and background include projects of similar size and content? Project Manager: Fit to Project How complex is the business area that will be addressed by the project? Are the business rules straight forward and transactional, or do they involve interacting decision matrixes? Inherent Business Complexity How many outsourced or other vendors are involved in the project, or are crucial suppliers during the life of the project? Vendor Involvement Risk Rating Low High Question Project Risk Dimension 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10 1 2 3 4 5 6 7 8 9 10
  • 6. The Psychology of Project Risk Assessment Project team members have to “believe” they will succeed in order to be motivated to work hard on the project This influences their risk assessment – no matter how hard they try to be “ objective ” in their risk assessments, there is a tendency to be “ too positive ” The best business impact and project factor risk assessments are done using a Delphi approach Get appropriate project team members to do their assessments independently of one another Get “ a similar number ” of project knowledgeable but not “project involved” people to also do an assessment independently of one another Average the two Compare them If they match  good probability of accurate assessment If they don’t and outside is more negative  use it If they don’t and outside is more positive  they may not know enough about the project – use the project team’s
  • 7. Project Risk Profiles are Summarized in Radar Diagrams (Also Known As “Spider Nets”) The greater the area inside the boundary, the higher the project risk profile. Overall Project Risk Rating: 8 10 Project Visibility 11 3 Project Manager Fit 10 8 Business Complexity 9 7 Vendor Involvement 8 9 Organizational Complexity 7 10 Technology New To Our Firm 6 4 Technology New In Industry 5 8 Team Experience As Team 4 8 Team Experience with Similar Projects 3 5 # Team Members 2 5 Project Size: $ 1 Rating
  • 8. Projects Can be Compared Based on their Business Impact and Risk Profiles High risk, high impact, large projects require a greater degree of project management and review. Project A Project E Project B Project C Project D
  • 9. What happens next? Project Failure has great negative Business Impact Ensure steering committee is headed by a senior business representative who will be impacted if the project fails Committee meets regularly / project status and issue reports distributed to both business and IT senior management Staff project for success – put the best IT and business people on it Project has large “project factor risk” Deep architectural and technical review – by IT architects and technical specialists external to the project Extensive risk mitigation planning Regular project status and issue review by senior IT managers from outside project reporting hierarchy – e.g. PMO reviews Project status and issue reports distributed to Top IT leaders Project Failure has great negative Business Impact Project has large “project factor risk” Do everything on both lists Low Business Impact / Low Project Risk Apply normal project management processes and reporting Project A Project E Project B Project C Project D