.st0{fill:#FFFFFF;}

Risk Management in PRINCE2 Projects 

 January 4, 2017

By  Dave Litten

PRINCE2 Risk Management

Whenever we undertake a project, risk is inevitable since projects enable change and whenever you have a change it introduces uncertainty and hence risk. We therefore need to understand how to apply risk management.

A risk is defined as an uncertain event which should it occur, will have an effect on the project meeting its objectives. These uncertain events can be positive in which case it would be called an Opportunity, when negative it is called a Threat. Both need to be controlled in risk management.

When carrying out risk management, the purpose is to reduce the probability and impact of threats and to increase the probability of opportunities and their positive impact. It is helpful to consider that and risk is an event that may all may not occur in the future, but if it does occur it will have an impact on the project objectives.

Effective risk management entails clearly identifying each risk, and estimating it in terms of its probability and impact and controlling it by taking appropriate action and ensuring such action has the desired effect.

In the Starting Up a Project process which takes place before the project starts, any known risks are captured in the Daily Log. This is the start of risk management. The Project Mandate may contain known risks via Corporate or Programme Management. When creating and assembling the Project Brief, any known risks are captured, particularly those within the outline Business Case.

The Risk Management Strategy.

Before getting into the details of risk management, it is important to establish HOW risks will be managed with a project. This is captured in the Initiation Stage and forms part of the Project Initiation Documentation in the form of the Risk Management Strategy which describes how risk management will be used and implemented within the project.

The risk management strategy should include, among other things, tools and techniques to be used the responsibilities for risk management actions, the scales to be used for calibrating and estimating probability and impact, the risk categories as to be defined, their proximity, and risk trigger indicators.

For contingency or fallback actions, a risk budget should also be agreed. This budget is used to pay for any such risk actions as part of risk management, should they be needed.

When using management by exception, the risk tolerance or risk appetite should be agreed between the project manager and the project board and included within the Risk Management Strategy document.

The Risk Register should be created early in the project, as it is a vital tool that contributes to risk management, and used to capture all details and the status of each risk identified. The project manager is responsible for ensuring that risk management is implemented properly but there will be the need for risk owners for all risks, and these owners may be other people involved in the project.

The Risk Management Steps.

The first step in the risk management procedure is to identify the risks, and this is normally done within a risk workshop. Other useful sources of possible risks, is to review lessons from previous projects. Yet more sources include organisational risk checklists, or the use of industry-wide checklists or tables.

Many people make risk management mistakes by naming risks such as “there is a risk is that the project may come in late” — but this is in error, because that statement is not the risk itself, but its impact. It is helpful to consider that the source of the risk is called the risk cause (the potential trigger points for each risk), the risk event describing the area of uncertainty, and the risk effect which he describes the risk in fact on the project objectives.

The next step is to estimate and evaluate each risk, and there are various estimation techniques that may be used within risk management:

Cause and Effect Diagram (Ishikawa Diagram)

This is also known as a fish-bone diagram. It is used to “reverse engineer” the risk impact back to its possible causes:

Probability trees. Links up a diagrammatic representations of possible events shown as linked rectangles each with a probability and impact. When connected together, the aggregated value of project risk can be determined. These help the decision-makers to determine possible outcomes, and recommends suitable actions as part of risk management.

Expected value. This technique multiplies the cost of the risk impact with the probability of the risk occurring. For example, if the cost of a risk was £8,000, and the probability equal to 40%, then the expected value would be £ 3,200. Summing all of these expected values together will give the aggregated risk expected monetary value of the project for use in risk management.

Pareto Analysis. This is often called the 80/20 rule, from the observation that 20% of the risks will have the most impact on a project, and allows management to focus their risk management attention on managing and controlling those risks.

The probability impact grid. This is a table with the vertical axis scaled in probability and the horizontal axis scaled in impact. Suitable scales are determined, typically 10% probability, as very low through to very high between 70 to 90% of ability. The impact scale usually covers from very low to very high. The grid is used to provide an assessment of the severity of a risk and so enable risks to be ranked such that risk management effort can be prioritized.

The summary risk profile. This again is a table of probability against impact, but instead of measuring the severity of each risk (probability x impact), it plots each risk as a number much like a scatter diagram so that the spread and severity of risks can be directly seen and used for risk management. For example any risks which have a very high in act and probability would be seen as severe threats and this will enable appropriate actions or counter measures to be determined.

The next step is to plan the appropriate responses, both for threats and opportunities. There are many ways to describe such actions, but the following most of them used:

Threats.

Avoid. An action is planned such that the threat can either no longer have an impact on the project and/or its probability is zero.

Reduce. An action is planned to either reduce the probability of the risk occurring, and/or to reduce the impact of the event should it occur.

Fallback (often called Contingency). An action is planned but only implemented should of the linked risk occur.

Transfer. An action is planned that reduces the financial impact of the threat. Usually, the action is via some form of insurance, or I appropriate clause is in a contract.

Accept. This is the take no action option. The threat should be continuously monitored to ensure that it remains tolerable. This risk management action is often chosen because the risk has a low probability and/or a low impact, or that the costs and effort of any actions out why he the severity of the threat.

Threat or Opportunity

Share. This risk management action is often carried out within contracts using third parties, where a pain/gain formula is agreed should the threat or opportunity occur

Opportunities.

Exploit. Taking action to ensure that the opportunity will happen and that the positive impact will be realized.

Enhance. Taking proactive actions which either enhance the probability all the impact of the event.

Reject. A decision taken not to exploit or enhance the opportunity.

All of the above actions are captured and entered within the risk register, and plans updated to include the above activities and resources as part of risk management.

It is helpful to include the proximity for each risk. This is the time frame of the risk event occurring from the present day. This is helpful in focusing resources on actions for risks in the near future. But it is also helpful in determining when each risk event will occur, as this will have an effect on the severity of the impact.

Throughout a project, new risks can be identified, and existing risks can change their status — for this reason risk management should be seen as an ongoing activity throughout the entire project. It should also be remembered that as issues arise, these can in themselves impact existing risks or cause new risks.

At the end of each stage of a project, the total risk situation needs to be calculated, and used as part of the data for management to make an informed decision as to whether to proceed with the project or not.

At the end of a project, as part of closure, any outstanding risks which would therefore have an impact on the end product’s operational life should be found a new owner, so that such risks can continue to be successfully managed and controlled.

Th effectiveness of risk management actions will be included in the Lessons Report.

Risk management procedure in PRINCE2

PRINCE2 recommends a five step procedure for the risk management; identify, assess, plan, implement, and communicate.  The first four steps sequential but the communicate step is done continuously and therefore is done in parallel with the first four.

Risk management sequence verses procedure steps…

At the high level, risk management consists of just two ‘stages’ if you will…

The could broadly be called risk analysis and the second is risk management. Let me explain…

Risk Analysis.

  • This is where the risks are first identified
  • then evaluated in terms of their probability, impact, proximity, etc…
  • Then suitable responses for each risk is identified and considered
  • Then the best response is selected
Risk Management.
 
This is where:
  • the selected response is included in the relevant plan as an activity (or more), along with the relevant resources needed to carry out that activity.
  • The plan is then approved (the Stage Plan), and the response activity is implemented and it’s effectiveness monitored. If it is not having the desired effect, then some form of corrective action is carried out
  • At the same time, reporting of the risk status occurs within the stage – this will normally include reference within the Checkpoint Report and Highlight Report.

Risk Management Steps.

Dealing with each step in turn:

Identify.  This has two steps to it, the first is Identify Context and the second is Identify Risks.  Identifying the context means determining the project objectives that are at risk and to formulate the Risk management Strategy document which describes how risks will be managed throughout the project.

Identify risks is to capture all threats and opportunities that may affect the project objectives, and an effective way of doing this is within a risk management or planning workshop.

The next step in risk management is Assess, and this also has two steps; Estimate and Evaluate.  

Estimating each risk is determining their probability and impact, and for this a sensible set of scales will need to be chosen.  There are also several risk management estimation techniques.

Another aspect of risk management which needs to be determined is their proximity.  Proximity is the time duration measured from today for when a specific risk may occur.  This is helpful in prioritizing risks and evaluating their impact by understanding when they will occur.

A useful way to represent the total risk situation is to plot each risk on a Summary Risk Profile. This is a simple matrix plotting probability on the vertical axis against impact on the horizontal axis. Each risk will be represented by its reference number and the resulting picture will look like a scatter diagram.

The purpose of the Evaluate step in risk management is to assess the aggregated affect of all identified threats and opportunities.  From here, an assessment can be made on the overall severity of the risks facing the project.

The risk severity needs to be checked that it is within the risk tolerance band set by the project board. Risk severity is often expressed as a monetary value determined by multiplying its probability by the financial impact. If this is done for each risk, and then summed, it is called the Expected Monetary Value.

The Plan step determines the possible risk management responses for each threat and opportunity with the intent of removing or reducing the threats and maximizing the opportunities.  An important factor in selecting each response is ensuring a balance between the cost of the response against the probability and impact of the risk occurring.

Examples of responses to a threat include Avoid, taking some different action, Reduce by reducing the probability/impact, Fallback, having a contingency plan to reduce the impact should the risk occur, Transfer, using some form of insurance or a third party, Share in terms of a pain/gain formula, or Accept by choosing to do nothing but to continue monitoring the situation.

For opportunities, the responses are; Exploit, taking some action to ensure the opportunity will happen, Share, the same as for threats, Enhance, which enhances the probability/impact by taking action now, and Reject, which is a deliberate decision not to exploit or enhance the opportunity.

The parallel Communicate step within risk management, relates to the use of various reports throughout the project.  These are the Checkpoint Reports, Highlight Reports, End Stage Reports, End Project Reports, and Lessons Reports.

This course is DEPRECATED

The old PRINCE2 6th Edition Foundation and Practitioner syllabus was upgraded in 2024. Check out the brand NEW PRINCE2 7th Edition Masterclass, covering all the current syllabus, training material and online exam benefits HERE

5.0
Prince2 Practitioner Masterclass

Your Route To PRINCE2 6th Edition Practitioner

Study PRINCE2 6 Foundation and Practitioner Exams with our famous on-line course with streaming HD Video Lessons, study guides and mock exams. In the last fifteen years we have had 6,000+ Academy students successfully transform their careers as PRINCE2 Practitioners.

  • Bite Sized Lessons  The sheer size of PRINCE2 can be daunting. The Masterclass will guide you through the syllabus in easy to consume bite sized lessons
  • Be prepared and confident for the exams  Test your knowledge in a fun, entertaining environment with the PRINCE2 Foundation & practitioner exam revision tools
  • Enjoy yourself!  This PRINCE2 Foundation & Practitioner online course is broken into bite-size lessons, combining leading edge multimedia and interactive exercises for optimum enjoyment and knowledge retention
  • Feel confident with full tutorial support  Benefit from fast access to experienced, one-to-one learning support as you study via email and phone, so there is no need to feel isolated while you are learning
  • Take your time  Study at your own pace by bookmarking your progress and picking up where you left off at a speed that suits you

Dave Litten


Dave spent 25+ years as a senior project manager for UK and USA multinationals and has deep experience in project management. He now develops a wide range of Project Management Masterclasses, under the Projex Academy brand name. In addition, David runs project management training seminars across the world, and is a prolific writer on the many topics of project management.

Your Signature

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}
Insert Content Template or Symbol

Join NOW!

Boost Your Career Now!

15% Discount on all courses with Coupon Code - PROJEX15