Risk Analysis
and Mitigation Process Manual
(QMS-ISPL-M-RAP)
|
Version
No |
V20 |
Prepared by |
|
|
Date |
30-01-2015 |
Name |
Sai Prasad Koneru |
|
Signature |
|
||
|
Date |
30-01-2015 |
||
|
Copy
No |
|
Approved by |
|
|
Issued
to |
|
Name |
Thomas Glass |
|
Signature |
|
||
|
Date |
30-01-2015 |
||
Document
Amendment Record
A- A- Added, M- Modified, D- Deleted
|
Sl.No |
Date |
Version No |
Page No |
Change Mode(A/M/D) |
Brief description of change |
|
1 |
|
V01 |
N/A |
A |
Initial Release |
|
2 |
06-06-2012 |
V01 |
N/A |
D |
The Company address information is
removed from the Footer |
|
3 |
30-01-2015 |
V20 |
N/A |
N/A |
Reviewed and base lined |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Table of
Contents
2.2 Risk analysis
and prioritization
3.2 Risk
monitoring and tracking
1 Introduction
When managing projects, one of the
first steps is to evaluate the risk attached to the project and define the
mitigation plan for the identified risks. Risk tends to be high early in a
project when expenditures are low. Conversely, risk tends to be low later in a
project when expenditures are high.
Accordingly, it is important that an
early effort is made to minimize project risks. This must be done early in the
project when expenditure is low, rather than later when the expenditure is
high. In other words, risk should be dealt with during the project initiation
phase and then shifted "up stream" into the
later project stages. Frequency of analysis and reporting must be on regular
basis throughout the project duration.
1.1
Purpose
The purpose of this process is to
· Identify the potential risks in the
project
· Plan to avoid, mitigate or manage
the risks
· Monitor the risks during the project
execution
· Mitigate the risks during the
project execution
· Handle the risks during the project
execution
1.2
Scope
These guidelines are applicable for
all projects executed.
The Risk management activities are
divided into
Risk
Assessment
·
Risk
Identification & Analysis
·
Risk
Prioritization
Risk Control – same as
management/handling
·
Risk
management planning and
·
Risk
monitoring and tracking
1.3
Terms and definitions
|
Abbreviations/Terms |
Description |
|
ISPL |
Inooga Solutions Private Limited |
|
QMS |
Quality Management System |
|
PM |
Project Manager |
|
Risk |
Events
or condition that may occur and whose occurrence has a harmful or negative
effect on the project. Project Management must deal with and plan for those
situations that are likely to occur whose exact
nature is not known before hand. |
|
RAMP |
Risk
Analysis and Mitigation Plan |
|
PMP |
Project
Management Plan |
2 Risk Assessment
Risk
Assessment consists of two components –
·
Risk identification and
·
Risk analysis & prioritization
Risk identification focuses on
enumerating possible risks to the project. The basic activity is to try to
envision all situations that might go wrong in the project execution. For
different project types as development or maintenance the risk types applicable
may also vary.
Risk analysis and prioritization
activity considers all aspects (need to specify the aspects) of the risks and
prioritizes them for purpose of risk management. Although these two are
distinct activities, they are often carried out simultaneously.
2.1
Risk identification
At
the time of project initiation, the project manager identifies the project
risks. Risk identification is an exercise in envisioning what can go
wrong. Risks are identified under
different categories.
The
categories of risks are:
·
Business risk
·
Technology risk
·
Process risks
·
Resource risks
·
Customer risks
·
Schedule risk
·
Others
These
risks are identified along with the category to which they belongs.
Some
examples of risks under various categories are: –
|
Category
of risk |
Classification
of Risks |
|
Business
risk |
·Competitor
may introduce the product earlier ·Loss of
market opportunities if project is delayed |
|
Technology
risk |
·Technology
is new and not proven ·Project is
complex |
|
Process
risks |
·Process
needs to be defined for the project ·Lack of
process compliance |
|
Resource
risks |
·Required
skills not available ·Manpower
attrition |
|
Customer
risks |
·Delay in customer
feedback ·Changes to
requirements |
|
Others |
·Tight
schedules ·Estimates
are not scientific |
2.2
Risk analysis and prioritization
The risks identified for the project
indicate the possible events that can hinder the project in meeting its goals.
The consequences of different risks may be different. While identifying
strategies for risk management, it is beneficial to analyze and priorities the
risks, so that appropriate strategies can be identified and management energies
can be focused on high priority risks.
Risk
analysis consists of:–
·
Assessment
of the probability of the risk occurrence and
·
Level of
consequences of the risk.
For each risk the probability of
risk occurrence as – Low, Medium and High will be identified.
For each risk identify the level of
consequence of the risk as – Low, Medium. High and Very High.
Based on the combination of
probability of occurrence and level of consequence the risk priority (in terms
of impact on the project) is determined. An example for identification of the
risk priority is given below
The following table describes the
risk priority (impact on the project) as occurrence and probability matrix.
This matrix is part of the PMP.
|
Probability of occurrence of risk |
Level
of consequences |
|||
|
Low |
Medium |
High |
Very high |
|
|
Low |
Negligible |
Negligible |
Marginal |
Critical |
|
Medium |
Negligible |
Marginal |
Critical |
Catastrophic |
|
High |
Marginal |
Critical |
Catastrophic |
Catastrophic |
The risk priorities are only
indicative. Based on the project specific risks, the PM needs to identify the
risk priority and assign impact values as per the guidance given below.
·
Catastrophic
(Value: 1)
·
Critical (Value: 2)
·
Marginal (Value: 3)
·
Negligible (Value: 4)
The PM provides impact values in the
Risk Analysis and Mitigation Plan in the PMP for each risk.
3 Risk control
Once the risks are identified and
prioritized, it becomes very clear which risks should be handled in the project with
highest priority.
Risk
control consist of two major activities-
·
Risk management planning and
·
Risk monitoring and tracking
Risk
management planning consists of identifying strategies needed to minimize the
risk consequences.
Risk
monitoring and tracking consists of periodic review of risks and revision to
the Risk Analysis and Mitigation Plan (RAMP), if needed in the PMP.
3.1
Risk management planning
For
each risk, based on the risk priority, PM identifies mitigation strategy and
risk handling strategy.
Mitigation strategy identifies the actions to be taken before the risk occurs
to minimize risk consequences.
Risk handling strategy identifies the actions to be taken after the risk occurs,
in spite of implementing the mitigation strategies
Some
of the potential risks faced and possible risk mitigation plans and risk
handling plans are shown in the table given below:
Risk |
Risk
Mitigation Plan |
Risk
Handling Plan |
|
Ambiguity/
Change in the requirements |
Negotiate
with the customer and document at the contract time itself how such
situations will be handled. |
Ask
the customer to raise a change request, and negotiate the schedule and
delivery dates. |
|
Incorrect
estimates |
Ensure
that no assumptions are made while estimating. |
Re-estimate
using the additional information available and re-plan. |
|
Unavailability
of required skills |
Inform
the customer. If possible, negotiate to get the team trained before the
initiation of the project. |
Negotiate
with the customer on schedule. If possible, obtain resources from the
customer for consultancy and reviews. |
|
Low
skill level of team members |
Screening
before allocation to the project to ensure presence of sufficient skills in
the team. |
Plan
training on weak areas to raise the skill level of the team. Assign
repetitive tasks to improve the performance of the team members. |
|
Manpower
attrition |
Have
backup team members ready for all the crucial activities in the project. In
case of rare skills have the backup trained. Maintain good technical
documentation to help in faster induction of new people into the team. |
In
cases where a single alternative is not available for backup, try to
granulate the tasks being performed by a crucial team member and get a group
of team members acquainted with the sub-tasks. |
|
Delay
in Customer feedback |
Negotiate
before hand on the response time from the customer |
Communicate
to the customer and add the delay to the schedule |
|
Technical
complexity in the project |
Have
adequate buffers in estimation for handling complexity and/or drop certain
requirements in consultation with customer to reduce the complexity |
Obtain
|
|
Use
of new technology |
Train
the team on new technology. Include buffers for use of new technology. |
Obtain
|
|
Tight
schedule |
Negotiate
with the customer on schedule. Explore the possibility of increasing the
manpower. (This may not always be possible and also works only when the tasks
are fairly independent) |
Negotiate
with the customer on dropping some of the functionality / requirements to
meet the schedule. Monitor the critical path closely. |
|
Lack
of process compliance |
Identify
the cause of non-compliance and train the team if necessary |
Re-plan
the reviews to improve the compliance |
Note:
The risk mitigation plans and risk handling plans shown in the table
above are only indicative. The PM needs to identify the suitable risk
mitigation plans and risk handling plans for the project under consideration.
3.2
Risk monitoring and tracking
The key to risk action planning is
to consider the further consequences of a decision made. The RAMP is to be
maintained as a part of the project plan and needs to be re-visited whenever
changes occur in the project plan. Contingency planning can be used to monitor
the risk and handle it when it occurs.
The project is continuously
monitored for the risks that are identified and also for the occurrence of new
risks. The identified risks and the mitigation plan are discussed in the weekly
and monthly project progress / management review meetings. If required,
transparency may be maintained with the customer so as to obtain
The potential risks and the risk
mitigation plan are reviewed when necessary apart from project progress
meetings (weekly and monthly). Open communication in the team shall be
cultivated to obtain first hand information on potential risks.
The steps that are being taken to
mitigate the risks shall be communicated to the PM/authorized person as part of
the Weekly project progress report and / or Monthly project progress report. Where necessary transparency is maintained with the customer on
potential risks to obtain guidance as well as
Whenever the PMP is modified, the
risks shall be re-assessed and the RAMP shall be revised, if required.
Whenever, risks occur in the project, the project management plan and/or the
project schedule will be revised if necessary. Similarly, when new risks are
identified during project execution, the RAMP will be revised.
Depending on the consequential
impact or degree of customer dissatisfaction due to a risk, it probably needs
to be brought to the notice of senior management. One may also decide to share
some of the risks with the customer, to bring in transparency, especially where
customer could decide to contribute in mitigating the risk.
Situations may arise in the project
execution, when the occurrences of risks become inevitable. The project team
needs to be prepared to handle such risks as and when they happen. If
essential, the team may be trained to face the risks to have a minimal impact
on the execution of the project and the quality of the work products in the
course of events.
3.2.1 References
Project
Management Plan
QMS-ISPL-T-PMP
Weekly
Project Progress Report QMS-ISPL-F-WPP
Monthly
Project Progress Report QMS-ISPL-R-MPP