PRINCE2 Risk examples, risk fallback, and risk budget
As with all risk analysis you will be recording risks that you intend to formally manage within the risk register and then determining the risk responses or actions and building all those into the plan.
Because of risk responses, extra work effort activities will need to be added along with any contingency time and this will add additional work effort and cost as well as increased task duration causing potential time extension to the project schedule.
Risks and their appropriate responses should be planned into a project from the outset but you should be checking for new project risks on a continual basis.
New or modified risks may come from within the project as well as external and business risks.
A very common risk to all projects is the availability of staff who are often working on multiple projects at any point in time, and so their availability within a typical work week will be limited from the start.
Because risks often occur at multiple points within the project, the project manager will often need to check on external specialist advice such as legal matters before plan risk responses with the team and this in and of itself can cause additional delays.
Here are some risk examples and the areas that will need checking for most projects:
Risk examples 1.
The project is being run within an operational area and therefore any project activity needs to be cleared and authorized by external individuals and this can cause project delays.
Risk examples 2.
Other on-going projects cause dependencies whether on the creation of products, the use of equipment or facilities or the staff themselves, where a delay in another project may cause your project to experience a similar delay.
Risk examples 3.
The project is being executed in a very dynamic business environment and hence changes are highly likely. For example, the functionality or environment within which the project end product is expected to operate may lead to regular and significant change requirements. These too will cause extra work to be carried out and subsequent delays.
Risk examples 4.
If the project is radically different to previous projects, or for example is using leading edge technology, then the project plan is highly likely to have extra or different unforeseen work occurring leading to significantly different estimates.
Risk example 5. In an effort to manage cash flow, projects are often funded as a series of funding milestone points. Despite the best intentions of financial planning, the release of such funds may be delayed causing similar delays to the project, or worse, having to temporarily release staff back into the organization.
Risk examples 6.
A fixed project end-date or very little tolerance surrounding and in service or operational date. This in and of itself is a very common and significant risk, often caused by poor and nervous time tolerance being set by corporate or programme management.
A second reason may be the lack of available resources so that the project manager can produce a plan with an earlier end-date and thus reducing the risk of missing the fixed end-date.
Risk examples 7.
The project has dependencies upon other internal or external suppliers who have a history of delivering poor quality products and services, or of delivering late.
A similar risk, is that the suppliers are already overstretched with additional work commitments and may have trouble allocating sufficient resources in a timely manner to your project.
Risk examples 8.
Similar to example four, your estimates are likely to be in error because of little or no previous experience of the type of work involved. There are at least two probable causes here, the first is that the process of carrying out the work is not understood, and the second is that the staff creating the products have insufficient knowledge, skills or experience.
Risk examples 9.
Your project may have little choice in the selection of suitable staff to carry out the product creation. This may be due to the lower priority given to your project by your organization, or it could be because you are using trainees and hence the work will take up more time.
Risk examples 10.
I have saved this one for last. Very often project managers wish to take on challenging projects to fast-track their career, and sometimes management will encourage them to do just that.
The corollary of these choices will often mean that the project manager does not have sufficient experience of managing such undertakings. This lack of experience can easily lead to inadequate planning for estimating and risk management, and lack of control in managing the project resources.
Risk fallback
This is often a miss understood area of risk management. Risk or fallback is also known as risk contingency, and is a fallback plan should be connected risk actually occur.
All other risk responses are built into the plan such as response actions to remove or reduce the risk probability and or impact.
Risk fallback actions are often captured and agreed but sometimes are not planned into the project itself. Supposed that the connected risk actually occurs, this will mean that the risk fallback action is now implemented.
Such a risk fallback action will now potentially cause a delay or an overspend due to these pre-thought through but unplanned actions.
It is therefore imperative that any risk fallback actions are not just planned, but also allowed for within the project time and cost.
This then brings me to my final point:
Risk budget
This is a planned budget included as part of the total project budget and is there to facilitate two aspects:
To pay for the management actions of risk management within the project
To pay for the actual work of carrying out the risk responses
Very often a weighted method is used to determine the risk budget. To do this, the actual cost and additional time needed for each risk is multiplied by its probability.
For example if a risk would cause an extra cost of £1000 and a delay of ten days, and the probability of the risk occurring is estimated as 40 per cent, then the risk budget for that risk would be set at £400 and a contingency delay built in of four days.
If this were to be done for all risks within a risk budget for the entire project could be calculated.
Within PRINCE2, there are two management responsibilities for the risk responses and these are called the risk owner and the risk actionee.
The person who takes any risk action is called the risk actionee and the risk owner is the individual who is responsible for overseeing but such actions take place and that they are affective.
Often, the risk owner is the project manager although in the case of business risks for example it may be a member of the project board.
