Project Management

When is a risk not a risk (Part 2)

From the Risk Insights from The Risk Doctor Blog
by
David Hillson, The Risk Doctor, shares key tips on understanding and managing risk, blending thought-leadership with expert practical application. Managing risk is easy - find out how!

About this Blog

RSS

Recent Posts

HAPPY NEW YEAR: Two-faced risk management

Zero chance of a zero-risk project

Innovative risk management

Why some risks turn into surprises

Are project opportunities the same as scope screep?

Categories

risk analysis, risk identification, risk management, risk process, risk psychology, risk responses

Date

linkedin twitter facebook Request to reuse this  

Categories: risk identification


The last blog entry addressed the need to distinguish risk from uncertainty. There are an infinite number of uncertainties, but these are only risks if they would affect objectives if they occurred. A risk is “an uncertainty that matters”.

Another common challenge in risk identification is to avoid confusion between causes of risk, genuine risks, and the effects of risks. The PMI®  PMBoK® Guide says that “A risk may have one or more causes and, if it occurs, one or more impacts”. In the most simple case, one cause leads to a single risk which in turn could have just one effect, though of course reality is considerably more complex. How do these three differ?

  • Causes are definite events or sets of circumstances which exist in the project or its environment, and which give rise to uncertainty. Examples include the requirement to implement the project in a developing country, the need to use an unproven new technology, the lack of skilled personnel, or the fact that the organisation has never done a similar project before. Causes themselves are not uncertain since they are facts or requirements, so they are not the main focus of the risk management process.
  • Risks are uncertainties which, if they occur, would affect the project objectives either negatively (threats) or positively (opportunities). Examples include the possibility that planned productivity targets might not be met, interest or exchange rates might fluctuate, the chance that client expectations may be misunderstood, or whether a contractor might deliver earlier than planned. These uncertainties should be managed proactively through the risk management process.
  • Effects are unplanned variations from project objectives, either positive or negative, which would arise as a result of risks occurring. Examples include being early for a milestone, exceeding the authorised budget, or failing to meet contractually agreed performance targets. Effects are contingent events, unplanned potential future variations which will not occur unless risks happen. As effects do not yet exist, and indeed they may never exist, they cannot be managed directly through the risk management process.

Including causes or effects in the list of identified risks obscures genuine risks, which may not receive the appropriate degree of attention they deserve. So how can we clearly separate risks from their causes and effects? One way is to use risk metalanguage (a formal description with required elements) to provide a three-part structured “risk statement”, as follows : “As a result of <one or more definite causes>, <uncertain event or condition> may occur, which would lead to <one or more effects on objective(s)>.”

Examples include the following :

  • “As a result of using novel hardware(a definite requirement), unexpected system integration errors may occur (an uncertain risk), which would lead to overspend on the project (a negative effect on the budget objective).”  
  • “Because our organisation has never done a project like this before (fact = cause), we might misunderstand the customer's requirement (uncertainty = risk), and our solution would not meet the performance criteria (contingent possibility = effect on objective).”
  • “We have to outsource production (cause); we may be able to learn new practices from our selected partner (risk), leading to increased productivity and profitability (effect).”

The use of risk metalanguage should ensure that risk identification actually identifies risks, distinct from causes or effects. Without this discipline, risk identification can produce a mixed list containing risks and non-risks, leading to confusion and distraction later in the risk process.


Posted on: July 02, 2015 03:38 AM | Permalink

Comments (7)

Please login or join to subscribe to this item
avatar
Paulo Marshall Campinas, Sao Paulo, Brazil
Thanks for sharing these posts David. The use of risk metalanguage in the process of identifying genuine risks is very educational.

avatar
anil kukreti Senior engineer | Mobiquity softech pvt ltd Ghaziabad, Uttar Pradesh, India
Causes, Risks and Effects.. nice analogy. Very logical.
I m preparing for PMP credential.
Few days back I was going through Quality Management Knowledge Area and I came to know about Root cause analysis so If I m getting it correct since Risks are direct result causes so risks will be reduced. right ?

avatar
David Hillson The Risk Doctor| The Risk Doctor Partnership Petersfield, Hampshire, United Kingdom
@Paulo: I'm glad you find the risk metalanguage idea helpful. I first described this in an article in PM Network in September 2000! You can access the article here: http://risk-doctor.com/pdf-files/cause0900.pdf.
Since I introduced this idea it has been widely accepted, and seems to be a simple way to ensure that risk descriptions are properly focused.

avatar
David Hillson The Risk Doctor| The Risk Doctor Partnership Petersfield, Hampshire, United Kingdom
@Anil: Thanks for the positive feedback. You're right that if we describe risks using the cause-risk-effect structure, then we can identify root causes that give rise to many risks. If we then tackle those root causes, we can manage related risks together in an efficient way.

avatar
Vincent Guerard Coach - Trainer - Speaker - Advisor| Freelance Mont-Royal, Quebec, Canada
When using the meta language I find it confuse people if we put more than one cause in the statement.

avatar
David Hillson The Risk Doctor| The Risk Doctor Partnership Petersfield, Hampshire, United Kingdom
I think this is a question of familiarity. When introducing the risk metalanguage idea, we usually start with 1:1:1, in other words, one cause gives rise to one risk that would lead to one effect.
The reality is many:many:many. Each cause can produce several risks. A risk may have more than one cause. A risk may affect several objectives. And an effect may result from a range of different risks.
Using this type of N:N:N thinking can be confusing, as you say, if people aren't familiar with the concept or practice of risk metalanguage. But with a more mature team we can create a rich map of causes-risks-effects that can support a powerful analysis of risk exposure.
Here we are straying into a different technique, called system dynamics, which is based on this type of N:N:N model,which is too detailed to describe here!!!

avatar
OR Sunil Kumar Director, PMO| FUJIFILM Medical Systems USA Apex, Nc, United States
Dave, thank you for this nice description of risks with the sample. It is very easy to understand thank you

Please Login/Register to leave a comment.

ADVERTISEMENTS

"Bad artists copy. Good artists steal."

- Pablo Picasso

ADVERTISEMENT

Sponsors