Risk Analysis and Mitigation Process Manual

(QMS-ISPL-M-RAP)

 

 

 

 

Version No

V20

Prepared by

 

Date

30-01-2015

 

Name

 

Sai Prasad Koneru

 

Signature

 

 

Date

 

30-01-2015

Copy No

 

 

Approved by

Issued to

 

 

 

Name

 

Thomas Glass

 

Signature

 

 

Date

 

30-01-2015

 


Document Amendment Record

 

A-    A-     Added, M- Modified, D- Deleted

Sl.No

Date

Version No

Page No

Change Mode(A/M/D)

Brief description of change

1

06-02-2003

V01

N/A

A

Initial Release

2

06-06-2012

V01

N/A

D

The Company address information is removed from the Footer

3

30-01-2015 

V20 

N/A 

N/A 

Reviewed and base lined 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


Table of Contents

 

1      Introduction....................................................................................................................

1.1         Purpose

1.2         Scope

1.3         Terms and definitions

2      Risk Assessment.............................................................................................................

2.1         Risk identification

2.2         Risk analysis and prioritization

3      Risk Control....................................................................................................................

3.1         Risk management planning

3.2         Risk monitoring and tracking

3.2.1      References

 

 


1         Introduction

When managing projects, one of the first steps is to evaluate the risk attached to the project and define the mitigation plan for the identified risks. Risk tends to be high early in a project when expenditures are low. Conversely, risk tends to be low later in a project when expenditures are high.

 

Accordingly, it is important that an early effort is made to minimize project risks. This must be done early in the project when expenditure is low, rather than later when the expenditure is high. In other words, risk should be dealt with during the project initiation phase and then shifted "up stream" into the later project stages. Frequency of analysis and reporting must be on regular basis throughout the project duration.

1.1      Purpose

The purpose of this process is to

 

·          Identify the potential risks in the project

·          Plan to avoid, mitigate or manage the risks

·          Monitor the risks during the project execution

·          Mitigate the risks during the project execution

·          Handle the risks during the project execution

1.2      Scope

These guidelines are applicable for all projects executed.

The Risk management activities are divided into

 

Risk Assessment

·          Risk Identification & Analysis

·          Risk Prioritization

Risk Control – same as management/handling

·          Risk management planning and

·          Risk monitoring and tracking

1.3      Terms and definitions

 

Abbreviations/Terms

Description

ISPL

Inooga Solutions Private Limited

QMS

Quality Management System

PM

Project Manager

Risk

Events or condition that may occur and whose occurrence has a harmful or negative effect on the project. Project Management must deal with and plan for those situations that are likely to occur whose exact nature is not known before hand.

 

RAMP

Risk Analysis and Mitigation Plan

PMP

Project Management Plan

 

2         Risk Assessment

Risk Assessment consists of two components –

 

·          Risk identification and

·          Risk analysis & prioritization

 

Risk identification focuses on enumerating possible risks to the project. The basic activity is to try to envision all situations that might go wrong in the project execution. For different project types as development or maintenance the risk types applicable may also vary.

 

Risk analysis and prioritization activity considers all aspects (need to specify the aspects) of the risks and prioritizes them for purpose of risk management. Although these two are distinct activities, they are often carried out simultaneously.

2.1      Risk identification

At the time of project initiation, the project manager identifies the project risks. Risk identification is an exercise in envisioning what can go wrong.  Risks are identified under different categories.

The categories of risks are:

·          Business risk

·          Technology risk

·          Process risks

·          Resource risks

·          Customer risks

·          Schedule risk

·          Others

 

These risks are identified along with the category to which they belongs.

Some examples of risks under various categories are: –

 

Category of risk

Classification of Risks

Business risk

·Competitor may introduce the product earlier

·Loss of market opportunities if project is delayed

Technology risk

·Technology is new and not proven

·Project is complex

Process risks

·Process needs to be defined for the project

·Lack of process compliance

Resource risks

·Required skills not available

·Manpower attrition

Customer risks

·Delay in customer feedback

·Changes to requirements

Others

·Tight schedules

·Estimates are not scientific

2.2      Risk analysis and prioritization

The risks identified for the project indicate the possible events that can hinder the project in meeting its goals. The consequences of different risks may be different. While identifying strategies for risk management, it is beneficial to analyze and priorities the risks, so that appropriate strategies can be identified and management energies can be focused on high priority risks.

 

Risk analysis consists of:–

·          Assessment of the probability of the risk occurrence and

·          Level of consequences of the risk.

 

For each risk the probability of risk occurrence as – Low, Medium and High will be identified.

For each risk identify the level of consequence of the risk as – Low, Medium. High and Very High.

 

Based on the combination of probability of occurrence and level of consequence the risk priority (in terms of impact on the project) is determined. An example for identification of the risk priority is given below

 

The following table describes the risk priority (impact on the project) as occurrence and probability matrix. This matrix is part of the PMP.

Probability of occurrence of risk

 

Level of consequences

 

Low

Medium

High

Very high

 

Low

 

Negligible

Negligible

Marginal

Critical

Medium

 

Negligible

Marginal

Critical

Catastrophic

High

 

Marginal

Critical

Catastrophic

Catastrophic

 

The risk priorities are only indicative. Based on the project specific risks, the PM needs to identify the risk priority and assign impact values as per the guidance given below.

 

·       Catastrophic     (Value: 1) 

·       Critical               (Value: 2) 

·       Marginal           (Value: 3) 

·       Negligible         (Value: 4) 

 

The PM provides impact values in the Risk Analysis and Mitigation Plan in the PMP for each risk.

3         Risk control

Once the risks are identified and prioritized, it becomes very clear which risks should be handled in the  project with highest priority.

 

Risk control consist of two major activities-

·          Risk management planning and

·          Risk monitoring and tracking

 

Risk management planning consists of identifying strategies needed to minimize the risk consequences.

Risk monitoring and tracking consists of periodic review of risks and revision to the Risk Analysis and Mitigation Plan (RAMP), if needed in the PMP.

3.1      Risk management planning

For each risk, based on the risk priority, PM identifies mitigation strategy and risk handling strategy.

Mitigation strategy identifies the actions to be taken before the risk occurs to minimize risk consequences.

Risk handling strategy identifies the actions to be taken after the risk occurs, in spite of implementing the mitigation strategies

 

Some of the potential risks faced and possible risk mitigation plans and risk handling plans are shown in the table given below:


Risk

Risk Mitigation Plan

 

Risk Handling Plan

Ambiguity/ Change in the requirements

Negotiate with the customer and document at the contract time itself how such situations will be handled.

Ask the customer to raise a change request, and negotiate the schedule and delivery dates.

Incorrect estimates

Ensure that no assumptions are made while estimating.

Re-estimate using the additional information available and re-plan.

Unavailability of required skills

Inform the customer. If possible, negotiate to get the team trained before the initiation of the project.

Negotiate with the customer on schedule. If possible, obtain resources from the customer for consultancy and reviews.

Low skill level of team members

Screening before allocation to the project to ensure presence of sufficient skills in the team.

Plan training on weak areas to raise the skill level of the team. Assign repetitive tasks to improve the performance of the team members.

Manpower attrition

Have backup team members ready for all the crucial activities in the project. In case of rare skills have the backup trained. Maintain good technical documentation to help in faster induction of new people into the team.

In cases where a single alternative is not available for backup, try to granulate the tasks being performed by a crucial team member and get a group of team members acquainted with the sub-tasks.

 

Delay in Customer feedback

Negotiate before hand on the response time from the customer

Communicate to the customer and add the delay to the schedule

Technical complexity in the project

Have adequate buffers in estimation for handling complexity and/or drop certain requirements in consultation with customer to reduce the complexity

 

Obtain support from experts in handling technical complexity

Use of new technology

Train the team on new technology. Include buffers for use of new technology.

Obtain support from Experts/Customer on the technology-based issues.

Tight schedule

Negotiate with the customer on schedule. Explore the possibility of increasing the manpower. (This may not always be possible and also works only when the tasks are fairly independent)

 

Negotiate with the customer on dropping some of the functionality / requirements to meet the schedule. Monitor the critical path closely.

 

Lack of process compliance

Identify the cause of non-compliance and train the team if necessary

Re-plan the reviews to improve the compliance

 

Note:  The risk mitigation plans and risk handling plans shown in the table above are only indicative. The PM needs to identify the suitable risk mitigation plans and risk handling plans for the project under consideration.

3.2      Risk monitoring and tracking

The key to risk action planning is to consider the further consequences of a decision made. The RAMP is to be maintained as a part of the project plan and needs to be re-visited whenever changes occur in the project plan. Contingency planning can be used to monitor the risk and handle it when it occurs.

The project is continuously monitored for the risks that are identified and also for the occurrence of new risks. The identified risks and the mitigation plan are discussed in the weekly and monthly project progress / management review meetings. If required, transparency may be maintained with the customer so as to obtain support from the customer in monitoring the project for possible risks. 

 

The potential risks and the risk mitigation plan are reviewed when necessary apart from project progress meetings (weekly and monthly). Open communication in the team shall be cultivated to obtain first hand information on potential risks.

 

The steps that are being taken to mitigate the risks shall be communicated to the PM/authorized person as part of the Weekly project progress report and / or Monthly project progress report. Where necessary transparency is maintained with the customer on potential risks to obtain guidance as well as support in mitigating/handling the risks.

 

Whenever the PMP is modified, the risks shall be re-assessed and the RAMP shall be revised, if required. Whenever, risks occur in the project, the project management plan and/or the project schedule will be revised if necessary. Similarly, when new risks are identified during project execution, the RAMP will be revised.

Depending on the consequential impact or degree of customer dissatisfaction due to a risk, it probably needs to be brought to the notice of senior management. One may also decide to share some of the risks with the customer, to bring in transparency, especially where customer could decide to contribute in mitigating the risk.

 

Situations may arise in the project execution, when the occurrences of risks become inevitable. The project team needs to be prepared to handle such risks as and when they happen. If essential, the team may be trained to face the risks to have a minimal impact on the execution of the project and the quality of the work products in the course of events.

 

3.2.1      References

Project Management Plan                                QMS-ISPL-T-PMP

Weekly Project Progress Report                                  QMS-ISPL-F-WPP

Monthly Project Progress Report                     QMS-ISPL-R-MPP