SlideShare a Scribd company logo
Risk Analysis in Information Technology Projects   Tennessee Summit ‘09 October 20, 2009 Thomas Danford Chief Information Officer Tennessee Board of Regents
PRESENTATION BACKGROUND  The examples in this presentation are based upon contract work to analyze two major IT projects to develop go forward options, baseline cost estimates, acquisition cost estimates, and risk analysis of the options being considered by the clients.
Goals, Objectives, and Ground Rules Discussion of Current Budgetary Climate Overview of Risk Analysis Techniques and Methodologies Used for major IT Projects The Role of Risk Analysis in Risk Management and Resource Allocation Decisions No Math/Accounting Lessons or Review! Examples are for Illustrative Purposes Only! Focus on Implementation of New Projects
Why Project Risk Analysis? Improved information to support decisions regarding project direction, scheduling, and budget Identify proactive actions that will improve technical solutions, scheduling, and ROI Develop contingencies for known causes of poor project performance  Identify project metrics for project monitoring and status reporting Demonstrate due diligence for audit and compliance requirements
Risk Analysis vs. Risk Management (Risk analysis is broadly defined to include risk assessment, risk categorization, risk communication, risk management, and policy relating to risk. In evaluating large scale IT projects they are typically done independently) What is Risk Analysis? Risk analysis is the systematic study of uncertainties and risks that could be encountered in business, engineering, public policy, and IT (as well as many other areas). What Is Risk Management? Active process of assessing, communicating and managing the risks facing an organization to ensure that an organization meets its objectives.
Risk Analysis & Management Process Project’s Strategic Objectives Risk Analysis Risk Reporting Threats and Opportunities Decision Risk Management Residual Risk Reporting Monitoring Risk Identification Qualitative Risk Estimation Quantitative Risk   Evaluation Analysis Management
Roles in Risk Analysis/Management (In evaluating large scale IT projects risk analysis is typically part of the project evaluation process) Risk Analysts  – identify risks faced, determine how and when they arise, and estimate the severity of impact of adverse outcomes.  Risk Managers  – Mitigate or hedge identified risks.
Primary Methodologies for Risk Analysis Quantitative & Qualitative Risk Analysis Risk Simulation Models Monte Carlo Analysis
Methodologies not easily adapted to IT Project Risk Analysis Risk Simulation Models  – Useful in situations with "flows" of materials or parts, people, etc. with complex interrelationship through a system with multiple steps (logistics, manufacturing, budgeting) Monte Carlo Analysis  – Useful for modeling where there is such significant uncertainty in many inputs that randomizing variables is viable for analysis (economics, oil production, sales)
Qualitative & Quantitative Risk Analysis Qualitative Risk Analysis  – Used to identify potential risks, as well as assets and resources which are vulnerable to these risks. Includes both internally and externally driven risk elements  Quantitative Risk Analysis  – Provides arithmetic assessment of the probability and impact of the identified risks. Quantitative risk analysis is also used to create overall risk scores for the risk elements and project alternatives.
Qualitative Risk Elements Financial Risks Cost of Ownership  Project Scope Cost Benefit Complexity Provisioning Change Management Technology Risks Contracts Governance Communication Environment Management Risks Strategic Risks Competition Requirements Industry Changes Customer Demand Life Cycle Integration State Appropriations Products & Services Recruitment  Re-skilling Politics Technology Advances Maintenance & Upgrades Many risk elements have both external and internal drivers. Hence, those elements overlap.
Ishikawa’s “Fishbone” Technique
Quantifying Risk     Impact on Project   Likelihood Low Medium High     (10) (50) (100) High (1.0) Low Medium High     10 X 1.0 = 10 50 X 1.0 = 50 100 X 1.0 = 100 Medium (0.5) Low Medium Medium     10 X 0.5 = 5 50 X 0.5 = 25 100 X 0.5 = 50 Low (0.1) Low Low Low     10 X 0.1 = 1 50 X 0.1 = 5 100 X 0.1 = 10
 
Comparative Risk Analysis
Comparative Risk Analysis
Risk, Cost, & Schedule
Risk Analysis Explicitly Addresses: Heuristics  – Tendency of people to use "rules of thumb", intuition, educated guesses or even common sense, which doesn't serve very well in complex IT, business, and policy decisions. Cognitive Bias  – Tendency to over-weight the most recent adverse event and projecting current good or bad outcomes too far into the future. Optimism Bias  – The demonstrated systematic tendency for people to be overly optimistic about the outcome of planned actions.  Fear, Uncertainty, and Doubt (FUD)  – Strategy to influence decision making by disseminating negative (dis)information designed to undermine the credibility of a project.
Determining Risk Tips for a Better Analysis Don’t start with any predetermined conclusions Cross-functional team involvement is essential Heuristics as well as cognitive, optimism, and pessimism (FUD) bias must be addressed Deal appropriately with risk and uncertainty
Tangible Benefits of Proactive Risk Analysis Schedule : Improves planning & upstream activities. Costs : Proactive identification of potential cost drivers. Quality : Meeting all scope and feature objectives of the project.
Summary & a Few Caveats Business case requires risk analysis Judgment – art as well as science Heuristics, cognitive, optimism, and pessimism (FUD) bias must be controlled Strategic Misrepresentation Quantitative issues accompany risk (magnitude) Cost and risk should be evaluated together
Additional Resources The Society for Risk Analysis (SRA)  http://www.sra.org/ Risk Management Association  http://www.rmahq.org/RMA/ Thanks for joining me today!!

More Related Content

PPTX
Impact management for everyone
PPTX
Risk management
PPT
Project risk analysis
PDF
Risk Analysis & Risk Management
PPT
“Construction Risk Management”
PDF
Project Risk Management
PPTX
Decision and risk analysis
PPTX
Project risk management: Techniques and strategies
Impact management for everyone
Risk management
Project risk analysis
Risk Analysis & Risk Management
“Construction Risk Management”
Project Risk Management
Decision and risk analysis
Project risk management: Techniques and strategies

What's hot (20)

PPTX
Risk Adjusted Estimating Techniques
PPTX
Construction Risk Summit "benefit and pits of Construction Risk Management"
PPT
Advanced program management risk mitigation and management
PPT
Risk Management
PDF
Software IT risk-management
PPT
Project Management by Mostafa Ewees
ODP
Risk and Uncertainty
PDF
Risk Assessment vs. Risk Management in Manufacturing
PPTX
Project Risk Management
PPT
Quantitative Project Risk Analysis
PPT
Risk analysis for project decision-making, presented by Keith Gray, 10th Oct ...
PDF
Risk Analysis : PMP- Project Risk Management
PPTX
Kuala Lumpur - PMI Global Congress 2009 - Risk Management
PPT
Risk Management
PPT
Technical Risk Management
PPTX
Project mngmnt risks3.2
PDF
IIA Facilitated Risk Workshop
PDF
A Study on Risk Assessment in Construction Projects
PPTX
Quantification of Risks in Project Management
PPTX
Qualitative risk analysis
Risk Adjusted Estimating Techniques
Construction Risk Summit "benefit and pits of Construction Risk Management"
Advanced program management risk mitigation and management
Risk Management
Software IT risk-management
Project Management by Mostafa Ewees
Risk and Uncertainty
Risk Assessment vs. Risk Management in Manufacturing
Project Risk Management
Quantitative Project Risk Analysis
Risk analysis for project decision-making, presented by Keith Gray, 10th Oct ...
Risk Analysis : PMP- Project Risk Management
Kuala Lumpur - PMI Global Congress 2009 - Risk Management
Risk Management
Technical Risk Management
Project mngmnt risks3.2
IIA Facilitated Risk Workshop
A Study on Risk Assessment in Construction Projects
Quantification of Risks in Project Management
Qualitative risk analysis
Ad

Viewers also liked (8)

PPTX
PDF
Om effektiv överlämning från testprojekt till förvaltning
PDF
Vad utmärker en bra förstudie
PDF
Slutrapport stimulera kreativ förnyelse och egna initiativ i hallstavik med s...
PDF
Utvärdera Nu – gör det enkelt att snabbt utvärdera projekt
PDF
Projektforum 2013: Håkan Sjöholm, Projektgranskning
PPTX
Frontit seminarium: Hur kan kommuner nå effektmål och minska resursslöseri i ...
PDF
2012 CIO Summit Presentation
Om effektiv överlämning från testprojekt till förvaltning
Vad utmärker en bra förstudie
Slutrapport stimulera kreativ förnyelse och egna initiativ i hallstavik med s...
Utvärdera Nu – gör det enkelt att snabbt utvärdera projekt
Projektforum 2013: Håkan Sjöholm, Projektgranskning
Frontit seminarium: Hur kan kommuner nå effektmål och minska resursslöseri i ...
2012 CIO Summit Presentation
Ad

Similar to Risk Analysis In IT Projects - TNS09 (20)

PDF
riskmanagement-170228074706trrrrrrrr.pdf
PDF
Information Risk Management - Cyber Risk Management - IT Risks
PPT
05-risk_assesment.ppt
PPT
project_risk_mgmt_final 1.ppt
PDF
Beyond PMP: Risk Management
PPTX
Final Class Presentation on Determining Project Stakeholders & Risks.pptx
PPT
project_risk_mgmt_final.ppt
PPT
project_risk_mgmt_final.ppt
PPT
PMI project_risk_management_final_2022.ppt
PPTX
Project Risk Management (10)
PPT
Risk Identification.ppt
PPTX
Risk Management
PPTX
Project Risk Management
PDF
Assessment Of Risk Mitigation
PDF
Measuring Change Risk for Organisational Decision Making Through a Hierarchic...
PPTX
Mastering Information Technology Risk Management
PPTX
Essentials of Risk Management
PDF
11 project risk management
PPT
112 risk- metrics for risk reduction
PPTX
Software risk, Configuration Management and QA (1).pptx
riskmanagement-170228074706trrrrrrrr.pdf
Information Risk Management - Cyber Risk Management - IT Risks
05-risk_assesment.ppt
project_risk_mgmt_final 1.ppt
Beyond PMP: Risk Management
Final Class Presentation on Determining Project Stakeholders & Risks.pptx
project_risk_mgmt_final.ppt
project_risk_mgmt_final.ppt
PMI project_risk_management_final_2022.ppt
Project Risk Management (10)
Risk Identification.ppt
Risk Management
Project Risk Management
Assessment Of Risk Mitigation
Measuring Change Risk for Organisational Decision Making Through a Hierarchic...
Mastering Information Technology Risk Management
Essentials of Risk Management
11 project risk management
112 risk- metrics for risk reduction
Software risk, Configuration Management and QA (1).pptx

More from Thomas Danford (20)

PPTX
Information and Computer Technology (ICT) Accessibility
PPTX
Success Factors in IT 4 10 and 13
PPT
P2P Legislation EduPol08
PDF
TBR Collaboration Analysis
PDF
CIC Final Report 050406
PDF
Tn 2015 Legislative Compilation
PDF
Elive15 Discussion TBR Performance Metrics
PPTX
Talent Mgmt EDULive
PPTX
Credit Card Computers and Their Application in HE
PPTX
Providing Metrics for Decision Makers CoHEsion13
PPTX
10 Determinants and 13 Ground Rules CoHEsion13
PPTX
Big Data in Higher Ed TENNAIR13
PPTX
TBR Common Data Repository ITS13
PPTX
Ellucian Live ES 2013
PPTX
Colaborative Cloud Poster EDUCAUSE12
PPTX
TBR Business Process Improvement EDUCAUSE12
PPTX
eProcurement TN-Summit 2012
PPTX
Statewide CI Resources TNSCORE12
PDF
An Exploration: Moving Your Enterprise to a Cloud Collaboration
PPTX
Rethinking Disaster Prepardness THEITS12
Information and Computer Technology (ICT) Accessibility
Success Factors in IT 4 10 and 13
P2P Legislation EduPol08
TBR Collaboration Analysis
CIC Final Report 050406
Tn 2015 Legislative Compilation
Elive15 Discussion TBR Performance Metrics
Talent Mgmt EDULive
Credit Card Computers and Their Application in HE
Providing Metrics for Decision Makers CoHEsion13
10 Determinants and 13 Ground Rules CoHEsion13
Big Data in Higher Ed TENNAIR13
TBR Common Data Repository ITS13
Ellucian Live ES 2013
Colaborative Cloud Poster EDUCAUSE12
TBR Business Process Improvement EDUCAUSE12
eProcurement TN-Summit 2012
Statewide CI Resources TNSCORE12
An Exploration: Moving Your Enterprise to a Cloud Collaboration
Rethinking Disaster Prepardness THEITS12

Recently uploaded (20)

PDF
Power and position in leadershipDOC-20250808-WA0011..pdf
PDF
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise
PPTX
New Microsoft PowerPoint Presentation - Copy.pptx
PDF
Nidhal Samdaie CV - International Business Consultant
DOCX
Business Management - unit 1 and 2
DOCX
unit 1 COST ACCOUNTING AND COST SHEET
PPTX
Probability Distribution, binomial distribution, poisson distribution
PDF
Deliverable file - Regulatory guideline analysis.pdf
PDF
Business model innovation report 2022.pdf
PDF
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
PDF
Chapter 5_Foreign Exchange Market in .pdf
PDF
Dr. Enrique Segura Ense Group - A Self-Made Entrepreneur And Executive
PDF
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
PDF
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
PPTX
Business Ethics - An introduction and its overview.pptx
PPTX
Dragon_Fruit_Cultivation_in Nepal ppt.pptx
PPTX
5 Stages of group development guide.pptx
PPTX
ICG2025_ICG 6th steering committee 30-8-24.pptx
PDF
IFRS Notes in your pocket for study all the time
PPTX
Lecture (1)-Introduction.pptx business communication
Power and position in leadershipDOC-20250808-WA0011..pdf
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise
New Microsoft PowerPoint Presentation - Copy.pptx
Nidhal Samdaie CV - International Business Consultant
Business Management - unit 1 and 2
unit 1 COST ACCOUNTING AND COST SHEET
Probability Distribution, binomial distribution, poisson distribution
Deliverable file - Regulatory guideline analysis.pdf
Business model innovation report 2022.pdf
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
Chapter 5_Foreign Exchange Market in .pdf
Dr. Enrique Segura Ense Group - A Self-Made Entrepreneur And Executive
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
Business Ethics - An introduction and its overview.pptx
Dragon_Fruit_Cultivation_in Nepal ppt.pptx
5 Stages of group development guide.pptx
ICG2025_ICG 6th steering committee 30-8-24.pptx
IFRS Notes in your pocket for study all the time
Lecture (1)-Introduction.pptx business communication

Risk Analysis In IT Projects - TNS09

  • 1. Risk Analysis in Information Technology Projects Tennessee Summit ‘09 October 20, 2009 Thomas Danford Chief Information Officer Tennessee Board of Regents
  • 2. PRESENTATION BACKGROUND The examples in this presentation are based upon contract work to analyze two major IT projects to develop go forward options, baseline cost estimates, acquisition cost estimates, and risk analysis of the options being considered by the clients.
  • 3. Goals, Objectives, and Ground Rules Discussion of Current Budgetary Climate Overview of Risk Analysis Techniques and Methodologies Used for major IT Projects The Role of Risk Analysis in Risk Management and Resource Allocation Decisions No Math/Accounting Lessons or Review! Examples are for Illustrative Purposes Only! Focus on Implementation of New Projects
  • 4. Why Project Risk Analysis? Improved information to support decisions regarding project direction, scheduling, and budget Identify proactive actions that will improve technical solutions, scheduling, and ROI Develop contingencies for known causes of poor project performance Identify project metrics for project monitoring and status reporting Demonstrate due diligence for audit and compliance requirements
  • 5. Risk Analysis vs. Risk Management (Risk analysis is broadly defined to include risk assessment, risk categorization, risk communication, risk management, and policy relating to risk. In evaluating large scale IT projects they are typically done independently) What is Risk Analysis? Risk analysis is the systematic study of uncertainties and risks that could be encountered in business, engineering, public policy, and IT (as well as many other areas). What Is Risk Management? Active process of assessing, communicating and managing the risks facing an organization to ensure that an organization meets its objectives.
  • 6. Risk Analysis & Management Process Project’s Strategic Objectives Risk Analysis Risk Reporting Threats and Opportunities Decision Risk Management Residual Risk Reporting Monitoring Risk Identification Qualitative Risk Estimation Quantitative Risk Evaluation Analysis Management
  • 7. Roles in Risk Analysis/Management (In evaluating large scale IT projects risk analysis is typically part of the project evaluation process) Risk Analysts – identify risks faced, determine how and when they arise, and estimate the severity of impact of adverse outcomes. Risk Managers – Mitigate or hedge identified risks.
  • 8. Primary Methodologies for Risk Analysis Quantitative & Qualitative Risk Analysis Risk Simulation Models Monte Carlo Analysis
  • 9. Methodologies not easily adapted to IT Project Risk Analysis Risk Simulation Models – Useful in situations with "flows" of materials or parts, people, etc. with complex interrelationship through a system with multiple steps (logistics, manufacturing, budgeting) Monte Carlo Analysis – Useful for modeling where there is such significant uncertainty in many inputs that randomizing variables is viable for analysis (economics, oil production, sales)
  • 10. Qualitative & Quantitative Risk Analysis Qualitative Risk Analysis – Used to identify potential risks, as well as assets and resources which are vulnerable to these risks. Includes both internally and externally driven risk elements Quantitative Risk Analysis – Provides arithmetic assessment of the probability and impact of the identified risks. Quantitative risk analysis is also used to create overall risk scores for the risk elements and project alternatives.
  • 11. Qualitative Risk Elements Financial Risks Cost of Ownership Project Scope Cost Benefit Complexity Provisioning Change Management Technology Risks Contracts Governance Communication Environment Management Risks Strategic Risks Competition Requirements Industry Changes Customer Demand Life Cycle Integration State Appropriations Products & Services Recruitment Re-skilling Politics Technology Advances Maintenance & Upgrades Many risk elements have both external and internal drivers. Hence, those elements overlap.
  • 13. Quantifying Risk     Impact on Project   Likelihood Low Medium High     (10) (50) (100) High (1.0) Low Medium High     10 X 1.0 = 10 50 X 1.0 = 50 100 X 1.0 = 100 Medium (0.5) Low Medium Medium     10 X 0.5 = 5 50 X 0.5 = 25 100 X 0.5 = 50 Low (0.1) Low Low Low     10 X 0.1 = 1 50 X 0.1 = 5 100 X 0.1 = 10
  • 14.  
  • 17. Risk, Cost, & Schedule
  • 18. Risk Analysis Explicitly Addresses: Heuristics – Tendency of people to use "rules of thumb", intuition, educated guesses or even common sense, which doesn't serve very well in complex IT, business, and policy decisions. Cognitive Bias – Tendency to over-weight the most recent adverse event and projecting current good or bad outcomes too far into the future. Optimism Bias – The demonstrated systematic tendency for people to be overly optimistic about the outcome of planned actions. Fear, Uncertainty, and Doubt (FUD) – Strategy to influence decision making by disseminating negative (dis)information designed to undermine the credibility of a project.
  • 19. Determining Risk Tips for a Better Analysis Don’t start with any predetermined conclusions Cross-functional team involvement is essential Heuristics as well as cognitive, optimism, and pessimism (FUD) bias must be addressed Deal appropriately with risk and uncertainty
  • 20. Tangible Benefits of Proactive Risk Analysis Schedule : Improves planning & upstream activities. Costs : Proactive identification of potential cost drivers. Quality : Meeting all scope and feature objectives of the project.
  • 21. Summary & a Few Caveats Business case requires risk analysis Judgment – art as well as science Heuristics, cognitive, optimism, and pessimism (FUD) bias must be controlled Strategic Misrepresentation Quantitative issues accompany risk (magnitude) Cost and risk should be evaluated together
  • 22. Additional Resources The Society for Risk Analysis (SRA) http://www.sra.org/ Risk Management Association http://www.rmahq.org/RMA/ Thanks for joining me today!!