Introduction
This skill focuses on laying the foundation for the upcoming course by introducing common risk terms and their definitions. We'll also discuss some core concepts that'll help you throughout this course. There's no sense in waiting so let's jump right in!
Definitions
There are a stack of vocabulary words and phrases that you must understand to pass the PMI-RMP exam. Sometimes it involves understanding the concepts and context of how those vocabulary words are being used in a question scenario. Don't worry: I'm going to take you through a couple of them right now and we'll discuss many more throughout training. By the time you reach the exam, you'll be speaking like an experienced risk manager!
Knowledge Check
Match the risk terms and their definitions.
This interactive assessment is available in the full learning experience.
The Principles of Risk Management
There are seven principles of risk management that help explain the mindset of sound risk methodology and the implementation. This section will address them with plenty of examples, or enablers, to help drive these principles home. Remember, you're firmly in the land of unicorns, or PMI-Land, and not where you currently work. Do your best to draw a clear line between reality and fiction.
The First Three Principles
The Last Four
Knowledge Check
Which risk principle is most concerned with the effects of a risk event?
Risk Attitudes and Influences
Everyone has a "risk attitude" or to put it plainly, how concerned they are about risk events. There are many variables that affect the formation of this attitude and some of them are-
- Experience
- Education
- Past risk event outcomes
- Market volatility
- And the list goes on and on!
This nugget will examine risk attitudes and shed some light on how to determine what yours might be!
Knowledge Check
Which of the following would be an unexpected outcome from a risk appetite misalignment between the CEO and a PM?
Sources of Risk
Some projects can have hundreds, if not thousands of risks! But where do they come from and is there a way to systematically and effectively identify them? The answer to both of those question is a resounding "YES" and this section will provide some details. Let's take a look at these two nuggets!
The RBS
RBS and Prompt Lists
Knowledge Check
What is the primary purpose of a Risk Breakdown Structure (RBS) in risk management?
Test Your Knowledge!
Knowledge Check
Which statement best reflects on one of the Seven Principles of Risk Management?
Knowledge Check
An organization that pursues innovation even when outcomes are uncertain demonstrates which position on the risk attitude spectrum?
Knowledge Check
According to the bullseye model, what happens when a threat hits the outside area in red?
Knowledge Check
Which of the following best describes a "source of risk?"
Knowledge Check
Which Core principle idea is most directly reinforced by using the RBS?
View Transcript
Introduction
0:00Welcome to skill number two of the PMI RNP risk management professional course.
0:06I'm Bob. Thank you for joining me. And I know I dropped a ton of stuff on you
0:11in that first skill.
0:12Well, I'm only going to keep doing it. There's a ton of stuff you have to learn
0:16, piles and piles.
0:18We have to move you out of reality into the land of unicorns, what I call a PMI
0:24land.
0:24So let's do that in skill number two. Let's take a look at the outline.
0:29Oh, and if you didn't notice, I have a different hat. I have my do-good work
0:33hat on by Anthony
0:35and Arino, great sales trainer, great guy. That's his motto. Just do some good
0:40work.
0:41That's what we're going to try and do here. So let's take a look at the skill
0:45outline.
0:45First thing we have to understand is this is foundational stuff. This is why I
0:50have a pyramid.
0:52This is what we're going to look at. I have to lay the groundwork that we're
0:56going to build upon
0:57through the next 28, 29, 30 skills. If we mess this up right here, there's
1:02going to be plenty of
1:03confusion down the road. So let's not do that. Foundational. We're going to
1:08define a bunch of
1:09words you probably think you know, but you actually might be wrong. So that's
1:14the first thing we're
1:15going to do right out of the gate. We're going to talk about the risk
1:18management principles.
1:19Pretty easy stuff there. We're also going to talk about risk attitudes across
1:24the entire spectrum.
1:26There's risk aversion all the way through risk seeking and it's not just your
1:31attitude.
1:32It's your company's attitude across projects and programs, the portfolio. What
1:38about your
1:38investors? What about your customers? What about your end users? There's a huge
1:43spectrum here which
1:44many project managers fail to really appreciate. We're going to talk about the
1:49sources and categories
1:51of risk and they are almost endless, but there's a way to approach them in a
1:55reasonable manner
1:57so you aren't overwhelmed. We're also going to talk about some foundational
2:01relationships across
2:02projects, programs and portfolios and how one builds across another. And the
2:07last thing we're
2:08going to talk about in this particular skill is the alignment across the
2:12standards. Remember,
2:14you have Pembox 7 in play which has a risk chapter. Then you have the practice
2:21guide for risk and
2:22then you have the standard for risk management across projects, programs and
2:27portfolios. So there's
2:29a lot of documentation at play here. I'm going to weave it all together and oh
2:34by the way,
2:35don't forget about the exam content outline which I'm going to touch across
2:39several different
2:40domains there as well.
Definitions
0:00Okay, welcome back. Let's get right into it. Let's start with some definitions.
0:05And here you go.
0:06Here's where we're going to start. We're going to keep it nice and simple,
0:10and then we're going to accelerate a little bit later on. So the first one is
0:14ambiguity.
0:16What is ambiguity? It's really just a lack of understanding. It's a lack of
0:22clarity. It's
0:22how much you think you do or do not know. And think about any particular
0:27project.
0:28When do you have the most confusion or lack of understanding? At the beginning,
0:34as you begin
0:36to learn more, as you identify risk, you have less ambiguity. And projects with
0:43low ambiguity,
0:44meaning you know a lot, are pretty simple. So there's ambiguity. But what about
0:49an individual
0:50risk? An individual risk is an uncertain event or condition. It's uncertain.
0:56But if it happens,
0:58it might have a positive or a negative impact on one or more of your project
1:03objectives. It
1:04can be good. It can be bad. It's uncertain. Well, what about overall project
1:10risk? It's the total
1:12effect, the sum of all of those individual risks. And how does it affect your
1:19project,
1:20or your program, or your portfolio, or your overall company's strategic
1:25objectives and vision?
1:27It's the sum. Add it all up. And you get the overall project risk. Now,
1:33opportunities confuse
1:34people because they know about them, but they don't think about them. An
1:39opportunity is an
1:40uncertain event. And if it happens, it might result in a game. And here's an
1:46easy example.
1:47Think about a time you got a coupon in the mail and you thought, wow, if I go
1:52get my oil changed
1:53over here at the Valvoline Express place, I get 50% off. That's an opportunity.
2:00But it's not a gain
2:02until you actually drive your vehicle over there and save 50%. So there's a
2:09life cycle here to
2:11realize that game. Think of it that way. Now, threats are easy. Threats are bad
2:17things. If
2:18something happens, it might result in a negative impact. Let's say you're
2:22worried about driving
2:23down the road and your tires kind of bald and you think, man, if I hit even the
2:28tiniest rock,
2:29I might have a flat tire. Well, that would be bad. That's a threat. Now, issues
2:34are different.
2:35They're on the other side of the coin from threats and opportunities. Threats
2:40and opportunities
2:41are uncertain. They haven't happened. Well, issues have happened. You have
2:48realized them.
2:49An issue is a realized threat. Go back to my previous example. You're driving
2:56down the road,
2:57you hit a nail, boom, you got a flat tire. It is no longer uncertain. Now, you
3:02have to deal with it.
3:03You have to pull over. You have to get the spare out. Hopefully, you have one
3:07and not one of those
3:08little donuts and you have to actually change it. An issue is something you
3:13have to deal with.
3:14You have to take action. Realized opportunities are called benefits. Go back to
3:20my previous
3:21example about that Valvoline Express oil change discount. You realize the
3:26benefit by taking that
3:28coupon and your vehicle there and letting them change your oil. I recently did
3:33that, which is
3:34why I have this example. It was pretty awesome. I'm quite happy with it. Now,
3:39an assumption
3:40is a belief you hold to be true or false and the absence of proof. I believe
3:46the sun will not come
3:48up tomorrow. Well, if it turns out to be the opposite, it could result in a
3:55risk to your project. Now,
3:56obviously, if the sun didn't come up, that would be very bad. But let's switch
4:01the flip there for
4:02a minute. I assume, based on historical information, that the sun is actually
4:07going to rise tomorrow.
4:09That's my belief. But if it doesn't actually come up, it will result in a risk.
4:14Actually,
4:16it's going to be a pretty significant issue. So think about that for a moment.
4:20I assume we'll
4:22get paid and funded all the way through the life cycle of this project. And if
4:26you get funded all
4:27the way through it, no problem. But if you lose funding at a certain point,
4:32that does result in
4:34a risk, something that you may actually have to deal with that will become an
4:39issue. That's an
4:40easy example. A constraint is a condition that limits you. We are constrained
4:45by time. We are
4:46constrained by a particular quality standard. Here's an easy example. We are
4:51constrained by
4:52the hours of work. We can only do work on this project during the maintenance
4:57window between 11
4:58PM and 4 AM in any particular time zone. Why? Let's say data traffic is really
5:05high during the day.
5:06And we can only work on this project, which may be to swap out some sort of
5:11server for increased
5:12capacity at night. Well, why are we doing it at night? Because that's when data
5:18traffic is lowest.
5:19That's the only time we can do it. Now we're constrained by time and the
5:23maintenance window.
5:25We may be constrained by using internal resources only. We may be constrained
5:30by a quality standard
5:32that's six sigma. We may be constrained by a certain amount of money. I don't
5:37know. But a
5:38constraint is something that limits you. And usually when you're limited, it
5:43may result in a risk
5:44event. I think that's going to do it for now. Let's stop right here and take a
5:48breather.
The Principles of Risk Management
0:00Okay, in this section, we're going to talk about the principles of risk
0:03management,
0:04and there are seven principles in the practice guide for risk management,
0:08as well as the standard for risk management, and they're pretty well in line
0:12with one another.
0:13We're going to go through each of them pretty quick, and I'm going to give you
0:16some examples
0:17and ideas to kind of lock it down. I think you'll figure it out pretty quick.
0:21Here's the first one. Strive to achieve excellence in the practice of risk
0:26management.
0:27Wow, sounds a lot easier than it is, but let's take a look at some of the
0:30things you might do.
0:32Continuous improvement in your processes and your tools. Do your processes work
0:37?
0:37Are you using the appropriate tools? For example, if your probability and
0:42impact matrix
0:43doesn't work for everyone, so half of them use it and half of them don't, that
0:47's a pretty lousy tool.
0:49Do you have gaps in your process? If you do, then you probably can work on that
0:54as well.
0:56Increase professional competencies. Get some training. Get a certification.
1:02Attend a class. Have some lunch and learns. Have a senior risk manager. Provide
1:08some sort of
1:09lesson to everyone else to bring them up to the latest and greatest skills.
1:13There's always
1:14something you can do to be better. Promote a risk awareness culture. If you've
1:19ever been on the
1:20Metro, they like to say if you see something, say something. This is in WDC of
1:26the Washington
1:27District of Columbia area, northern Virginia. You know what I'm talking about.
1:31What they're
1:32basically saying is this job doesn't belong to any one person. It belongs to
1:37all of us. If you
1:38have an opportunity to bring awareness to the rest of us, then do that. Don't
1:43ignore it and say,
1:44well, that's someone else's job because that's a really poor attitude. Provide
1:49ethical and
1:50transparent communications. If you see something is wrong, don't ignore it.
1:55Bring it up. Be transparent.
1:57Don't wait two or three days to see if it gets better. Talk about it now. There
2:03's an ethical
2:04issue here. If you wait because you're worried about getting in trouble or
2:08getting someone else
2:09in trouble and it blows up in everyone's face, there's an honesty issue there.
2:16You may or may
2:16not feel that way, but it's true. Both of those last two go together. If you
2:22see something,
2:23say something. Let's talk about the next one. Align your risk management of the
2:28organizational
2:29strategy and governance practices. This needs to be an alignment from the
2:34strategic level
2:35to the tactical level and there should be no disconnect. Your strategy and
2:40responses should
2:42support the big picture. The company has a vision. There's the present state
2:47and the future state
2:48and that vision and the actions you take between now and then should take you
2:53there. Well, risk
2:55governance from the top should be an alignment all the way to the bottom. So
3:00your responses at the
3:02bottom should not interfere or negatively impact your direction at the top.
3:08Everything has to be
3:10integrated from the high level to the bottom level or you're going to have a
3:14problem. Have
3:15appropriate oversight levels and accountability. If you're trying to standard
3:20ize your risk management
3:21across the entire organization, then you can't have risk governance in each
3:27individual silo.
3:29You need to take it to the enterprise level and make sure you have it there.
3:33And that's just one
3:34example. It depends on what you're trying to do and then have accountability.
3:40You can have
3:41responsibility without accountability. And I think you know what I'm talking
3:45about.
3:46Integrate risk across your people, your processes and your domains. Risk
3:50management is not a standalone
3:53part of your project. It is integrated into scope and schedule and quality and
3:59people. It is integrated
4:01across engineering and IT and operations and sales and marketing. It should be
4:07seamless and
4:08interwoven across all of them. Otherwise, you're going to have disconnects. You
4:15're going to have
4:16gaps that will result in problems. Have performance feedback loops. Now in
4:21agile, they do this very
4:22well. There's a daily stand up where the developers can talk about what they
4:27worked on yesterday and
4:28what they might work on today and anything that got in the way of what they
4:31were working on.
4:32Agile does this very well. And often, there's also a sprint review where they
4:39get feedback from
4:40their stakeholders, clients, customers and users. On the predictive side of the
4:45house, we are terrible
4:47at integrating a feedback loop with something more than once a month or once a
4:52quarter.
4:53It should be much more often. And then if you add a hybrid project to it where
4:58you got two frameworks
5:00running at the same time and lots of different connection points, you
5:03absolutely need a feedback
5:06loop because what if hardware is waiting for software and neither side knows
5:11what the other is
5:12doing. This is harder than it sounds like, but it's worth it. Let's move on to
5:17the next one. Focus on
5:19the most impactful risks. What are we talking about? In one example, impact is
5:26greater than
5:27probability. I don't care if you have an 80% probability of a risk occurring
5:33with a small to
5:34minimal impact. It's the impact that matters. Now compare that to a risk that
5:41has a 10% probability
5:43of occurrence and a catastrophic impact. You can clearly see that one of them
5:50is far worse than
5:51the other. And that's what you should be paying attention to. Those that have
5:56the greatest impact.
5:57Encourage a balanced risk view to capture opportunities. What it means is don't
6:03just look for threats.
6:05Losses. Bad stuff. Make sure you are also looking for opportunities, benefits,
6:12gains,
6:12have a balanced approach. Quantify the impact when needed to rank the value.
6:20You can qualify
6:21your risk as saying it's low, medium, or high. But that doesn't tell people the
6:26whole story.
6:28If you quantify it and say, well, it has an impact of 10,000, 50,000, 100,000,
6:34or a $1 million legal
6:37fine, that's how you can rank the value of those impacts. Dollars and cents
6:44always get noticed.
6:45And the last one here, align attention to risk appetite and reevaluate those
6:52risks often.
6:54If your risk averse, meaning you don't like risk, your head should be on a sw
6:59ivel looking for risk
7:00events left and right. If your risk neutral, you will be paying less attention.
7:07If you are
7:08risk seeking, you may just let them come at you left and right like mosquitoes
7:12near a swamp. I don't
7:13know. But you need to align your appetite, your client's appetite, your company
7:20's appetite,
7:21to their awareness of what's going on around them. Because if they are risk a
7:26verse,
7:27they need to reevaluate those risks far more often than if they are risk
7:32seeking.
The Principles of Risk Management
0:00Okay, welcome back. Let's jump right into the next principle, balance
0:05realization of value
0:06against the overall risk. What does it mean? It means think of the cost
0:11benefits analysis.
0:13Is the benefit of this project? Is the benefit of this outcome greater than the
0:20cost to pursue it?
0:22For example, let's say you want to invest $5,000 and you have two options.
0:28Investing
0:29$5,000 over here might yield the benefit of an additional $500. So your total
0:36outcome might be
0:37$5,500. Total investment and outcome. In another example, you might invest that
0:43same $5,000 and
0:45realize $10,000 in benefits. Okay, that's substantially different. $510,000 or
0:55$5,000 if you just doubled
0:57it. I don't know. Then you have to look at the probability of actually
1:01achieving it as a benefit
1:03and possibly the loss. So the benefits of value should outweigh the overall
1:10risk because sometimes
1:12if the risk is so great, you shouldn't even pursue this anymore. And that's
1:17just one idea.
1:18And let me drop some other ones on you. Select responses that maximize the net
1:22benefit too.
1:24If you can avoid a threat versus accepting a threat and your monetary loss is
1:31less by avoiding versus
1:34acceptance, then you should probably do that. If you transfer the impact to
1:39someone else versus
1:42mitigating it yourself because the net benefit is greater, then you should
1:47probably do that.
1:49Here's another easy example. Do you want to pay for your own car repairs if you
1:53're in an accident
1:54or do you want to keep paying that monthly insurance premium and transfer that
1:59impact to them?
2:00That's what we're talking about here. Select the responses that are going to
2:05work best.
2:06Prioritize opportunity enablement or pursuit. If there are opportunities,
2:12benefits gain,
2:13benefits or gains, excuse me, they have a greater priority than avoiding low
2:20impact risk. You should
2:21absolutely be pursuing those opportunities if the benefits are worth it.
2:26Balance the cost with
2:27risk reduction. I talked about that. If it's going to cost me $100,000 to
2:32reduce the impact of a
2:34$50,000 impact, I'm probably not going to do that. But if I can invest $500 in
2:40insurance perhaps
2:41to reduce or remove the impact of a $100,000 threat, then I will do that. There
2:48's a balance there and
2:49you should be able to figure that out pretty quickly. Optimize with lessons
2:53learned. I'm blown
2:54away by how many companies have great lessons learned that they don't share.
2:59And I'm also blown
3:00away by how many risk managers have access to it and they reinvent the same
3:05threats every single
3:07project and they miss the same opportunities every single project. Historical
3:13information
3:14is your greatest source of risk information on any project. Never forget that
3:19and you should be
3:20leveraging it. Foster a culture that embraces risk management. So at the top,
3:26leadership is going
3:27to model and promote risk awareness behavior all across the organization. If
3:33they're walking the
3:34walk, then everyone else will walk the walk. But if they're only talking a good
3:39game and they're
3:40not doing it, that's what everyone else is going to do as well. They say that
3:45leadership starts at
3:46the top and it's the exact same thing for risk management. Your daily routine
3:50should include
3:51risk conversations. What are the daily risks today? If for example, we have a
3:56construction project,
3:57oh, we have a train we're moving. Excuse me. I started to say cold train, but I
4:03'm not sure where
4:04that came from. Oh, these are the weekly risk we have to look forward to. These
4:09are the monthly's
4:10we have to look forward to. And these are the ones we can actually close out.
4:15Risk management
4:16should be the first thing you talk about in every single meeting on a project
4:20at an appropriate
4:21time, especially when you hit execution and beyond, because that's when the
4:25majority of your risk
4:27events are going to occur. Man, I'm stumbling over my words because I'm super
4:32excited to talk about
4:32this. I said it before. I'll say it again. I am a risk nerd. I love this stuff.
4:38Recognize and reward
4:40transparency. A lot of people don't point out something that's wrong with the
4:44risk methodology
4:45because they don't want to air their dirty laundry. They don't want to get
4:48someone else in trouble.
4:49But if I walk into a switch and I see someone working on some kind of electr
4:54ified equipment and
4:55it ain't locked out and tagged out so they can't get knocked out, I'm going to
4:59say something about
5:00it. And I'm going to do it without concern for my own career or theirs because
5:04it's the right
5:05thing to do. Now there's a balance there, but in the cases of life, limb, and
5:12eyesight,
5:12in a very extreme example, it's super important. And promote psychological
5:17safety and cross-functional
5:19collaboration. People shouldn't have to worry about speaking up and getting
5:23crushed by their
5:24manager because they said something that may have made their manager look a
5:27little silly.
5:29Don't do that. If they see something, they should be able to say something
5:33without getting smashed
5:35by the process. A risk is a risk is a risk. Say something. Let's move on.
5:41Principle six,
5:42navigate complexity using risk management to enable successful outcomes. Man,
5:48that's a lot.
5:48Use systems thinking in risk analysis. The risk you're thinking about may not
5:55just affect IT.
5:56It may affect engineering in sales. It may affect operations. It may affect
6:01sales
6:01enablement or sales outreach or whatever it is. Do not view risk in a silo. It
6:08usually affects far
6:09more than you think. Scenario planning enables strategic agility. You may have
6:15multiple responses
6:17for any particular risk and then play them out. Well, if we do this, this is
6:21the likely outcome.
6:23If we do that, this is the likely outcome and the secondary risk. If we do this
6:28,
6:28that might happen. Play these out so you aren't surprised and that will make
6:33you more agile,
6:34especially at the strategic level. Integrate qualitative and quantitative
6:39thinking.
6:40Qualitative, low, medium or high. Real risk, yes or no. Quantitative,
6:45impact in dollars and/or days. The combination of the two will make people pay
6:51attention.
6:52They will have a clear understanding of what you're talking about and use
6:55adaptive risk governance.
6:57There is no one size fits all. Do you need an enterprise level risk oversight
7:03board for a single
7:04project or should you simply have a risk manager in charge at the PMO
7:10responsible for all the projects
7:12and programs in a $50 billion company and the answer to both of those is no.
7:18You need an appropriate
7:20level of risk oversight based on your industry, the cost, the experience level
7:25of the team,
7:26and so many other factors. I can't even outline them all, but there is no one
7:31size fits all.
7:32And the last principle, continuous improvement. Get better within your risk
7:38competencies.
7:39Institutionalize your lessons learned. Elevate them all to the strategic, to
7:47the enterprise level,
7:48so everyone can share, everyone can see, and everyone can benefit from them.
7:54Audit and mature your risk framework. An audit is all about the process.
7:59Are we following it, yes or no, and does it work, yes or no? If the answer to
8:05either one of those
8:06is no, then something has to change and that's the only way you can get better
8:11across your organization.
8:13Leverage technology and data analytics. Do not make risk decisions based on
8:19your gut instinct.
8:21Let the data drive your decisions. Let AI help you identify risk and quantify
8:27it,
8:28and aggregate piles and piles of information so you can see what historically
8:33has happened
8:34so you don't have to do it again. There are a ton of tech tools out there. Use
8:40them.
8:41And last but certainly not least, encourage a growth mindset around uncertainty
8:47. Uncertainty,
8:48the unknown. Welcome it, look forward to it, embrace it. That's a growth
8:54mindset. Avoiding it,
8:57transferring it into someone else's wheelhouse, that's not my problem, that's
9:03close-minded.
9:04And when you have those kinds of ideas and thoughts, you're going to have a gap
9:08that's going to come
9:09back and bite you in the enterprise, but you know what I'm talking about.
Risk Attitudes and Influences
0:00In this section, we're going to talk about risk attitudes, not a tood, and why
0:05it matters.
0:06A chosen or inherent disposition towards uncertainty that influences a person's
0:12or
0:12an organization's behavior when responding to a risk is actually called, well,
0:19now that I'm
0:19writing it out, your risk attitude, there's yours, and there's your companies.
0:25That's why there are
0:27two levels, the individual level and then the organizational level. And many
0:32times there's a
0:33huge disconnect right here. I might think I'm able to do X, Y, and Z or not
0:38able to do it.
0:40My company may have a completely different idea and that misalignment can lead
0:45to more threats and
0:46missed opportunities or both. So let's take a look at the risk attitude
0:52spectrum. If you're on the
0:54left side, you are risk averse. You do not like uncertainty, you prefer predict
1:01ability. You want
1:02to know as much as you can know about all there is to know before you make a
1:06decision. I get that,
1:08there's nothing wrong with that. And there are some industries where that is
1:12the only way things
1:13get done. Think engineering, making bridges, putting up buildings. It's really
1:18nice when they
1:19don't fall down. So they are certainly risk averse. Within you have risk
1:23neutral. You're comfortable
1:25with the wins and the losses balanced trade-offs. No problem there. Then if you
1:31go to the far side,
1:32you are risk seeking. Think venture capitalism. Think any of the companies
1:37right now that are
1:38scrambling to get AI driven anything out. Those people are trying to be the
1:42first to market with
1:44their AI driven process, their product, their result, whatever it is. And they
1:48're dropping huge money
1:50on these massive data centers to pull it off. So that's the risk attitude
1:55spectrum. Now let's
1:56talk about the components within the attitude. There's a degree of uncertainty.
2:02A person or a
2:03company is willing to accept. And that's called your risk appetite. How much
2:07are you willing to eat?
2:09And it goes all the way back to the spectrum. Averse, very little. Neutral,
2:15some more. Seeking
2:17lots. Within you have the acceptable variation from that degree of uncertainty.
2:24And that is your
2:25risk tolerance. And I have a graphic to explain this very well in just a moment
2:30. So hang on.
2:31But then there's a specific moment or a point where the exposure becomes
2:36intolerable and it needs
2:38to be escalated. That's actually called the risk threshold. Easy enough. Every
2:44one of
2:44us has an appetite with a tolerance and a threshold. And it changes throughout
2:50our career, throughout
2:51our life from project to project, depending upon a bunch of factors that we're
2:57going to get into
2:58in a moment. But let me explain these three components here in this example. If
3:02you look at the grain,
3:04there's your appetite. If these are my threats, I like to stay right here. But
3:11I'm willing to put
3:12up with a little bit of variation, which is my yellow zone, my tolerance zone.
3:18I'll put up with
3:19that. Let's say I'm driving the speed limit. My appetite is 65 miles an hour.
3:24But my tolerance is
3:26up to 75, depending upon whether or not I'm on a highway or I'm on an
3:31interstate. So that's my
3:32tolerance. But my threshold is 76. I do not like to go faster than that faster
3:39than 75, really.
3:41And if traffic is consistently moving faster than that, then I need to escalate
3:46and let my house
3:47spouse drive or I simply need to pull over, find a restaurant and take a break.
3:51And yes,
3:52this is old man talk. This is how I feel about it. But let's go the other way.
3:57Those are threats.
3:59Let's say you are in pursuit of opportunities and you're looking for a discount
4:03. Think of that red
4:05area out there at the bottom where it says monitor. I'm monitoring a 10%
4:09discount for this kind of
4:10material, but I need it to be more. So now it moves into the yellow area and it
4:14's 20 to 25%.
4:16Now I can do something about it if I want to. But then it moves into that green
4:22area and it's 30%
4:23off. Now I will absolutely capture that opportunity. And this is why it's
4:29important to understand
4:31your appetite, the deviation you are willing to put up with, and the point
4:37where you will
4:37absolutely go no further or you will escalate. And there are a lot of things
4:42that influence this.
4:43Think about the organizational culture. Whatever leadership is doing, the rest
4:49of the company is
4:50largely going to follow because leaders lead. They set the tone. And then what
4:56about the
4:56history of success and failure? Well, we tried this before 15 times and it didn
5:01't work any time.
5:02So we're not going to do that. Or we tried it a lot and 8 out of 10 times we
5:07were able to capture
5:08those opportunities. So based on your successes and failures, you will continue
5:13to follow that
5:14pattern. But what about your external environment? What about the market
5:17volatility, stocks, bonds,
5:19municipal things, Bitcoin, Ethereum, Doge, whatever it is? What about
5:27regulations? What about stakeholder
5:30expectations for returns and losses? And I'm just musing out loud here for
5:36financial stuff. The
5:38external environment really matters. But what about the project itself? How
5:43complex is it? How
5:45visible is it? Where is the innovation level? Is this something we've done many
5:49times before?
5:50Or is it brand new? What about our resource constraints? Do we have lots or do
5:54we have none?
5:55Think about SpaceX. I am fascinated how quickly we went from just firing
6:02rockets into space,
6:03watching them fall into the ocean and maybe we collect them and maybe we don't.
6:07And suddenly,
6:08they're making them fall exactly where they want them, want them to, excuse me.
6:14And suddenly,
6:15they're catching the small rockets and a couple of them blew up and they went,
6:19so what? We got more rockets. And suddenly, they're landing them on floating
6:24platforms
6:25and it's perfect. And suddenly, they're landing them two at a time. And then,
6:31not long ago,
6:32they caught a huge heavy rocket booster. It was perfect. I'm fascinated by the
6:37tech.
6:38So if you have lots of money to throw in something, the resource constraints
6:43really don't matter at
6:44that point. But what about your stakeholder personalities? Are they optimists?
6:49Are they
6:49pessimists? What about their past experiences? How literate are they as it
6:55relates to risk?
6:56Do they have a preconceived idea about what a risk is or a response is?
7:01Or do you need to help them understand it? And the answer is, I don't know, but
7:06everyone has a
7:07different perception. And then you have your available information. How
7:12confident are you in the data
7:13you're being fed to make a decision? What about the data model? What about the
7:18knowns? What about
7:19the known unknowns? It really does depend. And this alignment between the top
7:24level and the bottom
7:26level really matters. Because if there's a misalignment or it is ignored, you
7:30're going to have inconsistent
7:32responses at various levels of the company. You actually make yourself legally
7:37responsible for
7:38some of these decisions and you get your company on the hook form as well. If
7:42you're overly cautious,
7:44you're going to miss opportunities that your bosses would have preferred that
7:48you captured.
7:48Or if you go the other way, you might escalate two later too often, resulting
7:54in a greater level
7:55of threats occurring than there should be. But if you have it dialed in, you
7:59may actually have
8:01coherent risk decisions. Yes, we sampled the data, we compiled it, we analyzed
8:07it, we captured
8:08that opportunity, we trusted data. Or we looked at the data, the numbers weren
8:14't on our side,
8:15and we passed on that opportunity. But the company that did take the
8:18opportunity, they're now bankrupt.
8:20Your reward to risk ratio is going to be optimized too. You are winning more
8:25than you are losing.
8:26You are avoiding threats. You are capturing opportunities. There's an optimism.
8:32There are
8:32more positive project outcomes. Your responses match the governance. You're not
8:37exposing your
8:38company to liability or yourself. You're not getting fired. You're not getting
8:42dragged into court.
8:43And the culture embraces fact based dialogue. This is what we said would happen
8:49. This is what
8:50actually happened. This is the data that supported that. No one's trusting
8:55their guts. No one's
8:56looking to see if the moon or Mars is in retrograde. They are making fact based
9:01data driven decisions
9:03and they can talk about it. The bottom line is this, proper alignment with risk
9:08attitude from
9:09the top to the bottom between the individual and the organization is no longer
9:13seen as a compliance
9:14exercise. It's a competitive advantage. And that's why it's really important to
9:19know what you're
9:20talking about and who you're talking to from the tactical level to the
9:25enterprise level.
Sources of Risk
0:00"Welcome back and welcome to sources and categories of risk."
0:05I want you to think of it time, if you've ever done this,
0:08where you went to a project meeting and they said,
0:10"Okay, we're going to start ID risk."
0:14It's identification day, give it to me.
0:16What do you got?
0:17And people just randomly say things
0:20or they write down random stuff
0:21or they put them on random post-it notes
0:23and stick them on a board with no rhyme or reason.
0:27You have scope and you have quality
0:29and you have weather events and you have risk events
0:32and you have operational, organizational, human resources.
0:36And there's no rhyme or reason.
0:38It just becomes chaotic.
0:41There's a reason you can't do that.
0:43You need a well-structured view of risk sources
0:48because if you don't have that,
0:50you're going to have a ton of problems later on.
0:53They might not manifest right now,
0:55but they will certainly pop up.
0:57And remember, we're not just talking
0:59about project risk anymore.
1:01We're talking about program level risk,
1:04portfolio level risk, strategic level,
1:08all encompassing company level risks.
1:12So you need a well-structured way to manage that.
1:16Excuse me, I think I eat a bug.
1:19If you have a well-structured view,
1:21you're certainly going to identify more risk.
1:24It's a fact.
1:25I've done it a hundred times.
1:27And whenever we start with a list, we get it right.
1:31And here's an easy example.
1:33Think about a time you didn't take a grocery list
1:36to the store.
1:37Did you really get all the stuff you wanted to
1:39or you were supposed to or did you get home and go [garbled]?
1:43I forgot X, Y, and Z and now I gotta go back.
1:46Or you know what, I forgot it.
1:48So now I'm just going to eat something else.
1:50By having a list, you're going to avoid blind spots.
1:54You're also going to reduce exposure
1:57with consistent groupings.
1:59You will miss entire categories
2:02unless you have a well-thought-out list.
2:05And we're gonna get to one rather several in just a moment.
2:09But more importantly,
2:11you're going to begin to identify opportunities.
2:15Threats aren't the only thing out there.
2:18Opportunities, gains, benefits, they exist as well.
2:23So let's get straight to a PMI definition.
2:26Any element alone or in combination
2:30that has the potential to give rise to uncertainty
2:34and achieving objectives.
2:36This is called, wait for it, a source of risk.
2:41Ha, that's it.
2:43And here's the key idea behind them.
2:46Sources describe where those risks might come from.
2:51The problem is they don't go far enough
2:54and actually identify the what specifically that risk is.
2:59So if you tell me, well, here's a great source,
3:04weather events, really?
3:07Atmospheric conditions is your source.
3:10Well, what specifically are we talking about?
3:13Are we talking about hurricanes,
3:15tornadoes, tsunamis, tidal waves, Arctic conditions,
3:20heat-related injuries?
3:21What specifically are we talking about?
3:23Torrential rain, I have no idea.
3:27So here are some common categories.
3:30External, those are things outside the company's control.
3:34Internal, those are things usually
3:37within the company's control.
3:39Technical, that's easy.
3:42Political, strategic,
3:44and then you have projects specific stuff
3:47like scope, schedule, cost, communications,
3:50human resources, whatever it is.
3:53And these are just a couple of categories.
3:57There are a bajillion more.
3:59But here's another key concept.
4:01Sources reveal root causes.
4:04There's something called Pareto's law.
4:06You've probably heard of it.
4:08It is the law of the common few.
4:11Well, as it relates to risk management,
4:14there's the 2080 rule or the 8020 rule,
4:17whichever way you wanna say it.
4:1920% of your root causes result in 80% of your risk events.
4:24And if you can identify what those root causes are,
4:29you can usually avoid or transfer
4:32a whole bunch of risk events.
4:35But if you never identify those root causes,
4:38you will always deal with the effects.
4:41They will happen over and over and over,
4:44which is why Pareto's law is always in effect.
4:47This will bring us to the RBS.
4:51The risk breakdown structure is a higher arch goal.
4:55That's a real word.
4:57Decomposition of identified risk sources
5:01organized in a comprehensive way
5:04to promote risk identification and consistent analysis.
5:09And it's broken down across three levels.
5:12Level one is major categories.
5:14Level two is subcategories all the way down
5:17to specific sources and triggers.
5:19And if you're thinking, wait a minute,
5:22the risk breakdown structure,
5:24where have I heard that before?
5:26Because it sounds suspiciously like
5:28the work breakdown structure
5:31and the organizational breakdown structure.
5:33If you made those connections, you're on point.
5:37It is a graphical, numerical, higher archical
5:42or a higher archy.
5:44It's a way of breaking it down.
5:46And the reason you're doing it here one more time
5:49is so you can have consistent risk identification
5:53and analysis.
5:55Well, let me give you an example.
5:57And there's a lot here.
5:58So I'm just gonna come off screen for a moment
6:00and I'm gonna show you where we're starting.
6:02Let's start over here at this IT project.
6:06That is your major category.
6:08Within you have your subcategories
6:12and you can go down to as many categories
6:14and sub levels as you need to.
6:16Let's worry about technical risk.
6:19Well, underneath technical risk,
6:21we have requirements and design.
6:24And one risk might be incomplete or changing requirements.
6:29And yes, I'm now noticing I misspelled it.
6:32So please hold your laughter to a minimum.
6:35But what about poorly defined user stories
6:37in the agile space or misinterpreted system needs?
6:42This is a way to systematically break it down
6:45into smaller and smaller, lower pieces.
6:49Just like the work breakdown structure.
6:52Why are we doing that?
6:53So we can chase down the root cause.
6:56And let's say there's only one root cause
7:00for all of those in requirements and design.
7:03Wouldn't it be great if we could identify them
7:05and deal with that root cause?
7:07Because if we did, theoretically,
7:09we could wipe out all of those potential risk events.
7:13But let's do one more and then stop this nugget
7:15because I don't wanna get too deep and make it too long.
7:19Let's jump over here to a construction project
7:22and talk about some project management level risk.
7:25Well, what happens if we have inaccurate estimates?
7:29Or we sequence our activities in a lousy way?
7:34Or we don't do enough due diligence
7:36to get approvals or permitting.
7:39What's the impact?
7:41If we can figure out what the root cause is of say,
7:44this one and this one and this one,
7:46and maybe it's connected to that one and that one,
7:49maybe we can wipe them all out
7:51before they materialize into actual issues.
7:55This is why you need a risk breakdown structure.
7:59A clear structured way to identify your sources
8:04and then dig deeper into them to chase those root causes.
Sources of Risk
0:00So the risk breakdown structure, right?
0:02Wow, but it doesn't just end there.
0:05Remember, we're not only talking about the project level now,
0:10we're talking about all levels across the organization.
0:13So think about the portfolio level.
0:15Strategic level risks, do you have an RBS for that?
0:20You might be talking about investment choices
0:23or major resource allocations.
0:25Think about the COVID-19 years, 2020 and through 2022,
0:31major supply chain shortages.
0:33Shoot, you couldn't get toilet paper for a while.
0:37Think about how some of those resources,
0:39not really toilet paper, might impact the company's portfolio
0:43at that level.
0:45But then you have the program level,
0:46where you have the interdependencies,
0:48the linkages across multiple projects.
0:51And then you have the project level itself,
0:54those tactical risks tied to deliverables.
0:58But here's some key takeaways here.
1:00The higher the level, the more interdependent the risk.
1:04Basically, the higher the level, the greater the reach,
1:08the greater the impact that risk is going to have.
1:12Because portfolio level risks influence business priorities.
1:17Project level risks influences execution and delivery.
1:21So we're running all the way up and down the stairs now.
1:26Tactical level, project level, operational level,
1:31program level, multiple program levels,
1:34portfolio level, initiative level, company level.
1:39This is bonkers.
1:40So a well-structured plan, a well-structured list,
1:46and appropriate risk breakdown structure
1:49is the only way you're going to survive this moving forward
1:52to actually maximize value delivery within your company,
1:57your portfolio, your program, and your project.
1:59But why does it really matter?
2:02Let me just lay this out one more time.
2:05If you don't have categories, your lists
2:08are going to be repetitive and random.
2:10And that randomness is going to keep those root causes hidden.
2:14You're not going to find them.
2:15It's also going to be really hard to assign risk owners.
2:19The risk owner is the person designated,
2:22they either volunteer or they're
2:24volunteered, to actually ensure the risk response happened.
2:29Well, then you have a risk action owner.
2:31And we're going to get to both of these later on.
2:34The action owner is the person that actually does this stuff.
2:38Let's say you are a project manager for a construction
2:41company, and you have heavy equipment.
2:44Well, the yard foreman is going to be the risk owner.
2:47If something happens with the bucket loader,
2:49he's going to make sure that the bucket loader driver does
2:53what he or she is supposed to do for that particular issue.
2:58So you have the risk owner, the action owner.
3:01And if you never get to the root causes,
3:04you're going to have a really tough time making sure
3:06that the right person is assigned to those roles.
3:10And because it's all willy-nilly crazy, it's going to be random.
3:14And that's going to overwhelm your stakeholders
3:16when you report it.
3:17They're not going to see a rhyme or a reason or a pattern.
3:20They're going to see chaos.
3:22And this is your fault as a project manager.
3:25If you have a risk, if you have appropriate categories,
3:29you're going to have a logical grouping for analysis
3:33and reporting.
3:34Sorry, I had to pull my face off of there.
3:37And those risk clusters will expose your root causes.
3:42And they almost always pop up really quickly.
3:46When you have three or four risk events
3:48and they're all tied together, it doesn't take long
3:51to drill into the root cause.
3:52And once you have order within the chaos,
3:55it's not going to be hard to assign the appropriate owner.
3:59If someone says, well, there's an engineering risk,
4:02do I just randomly assign it to the engineering director
4:06and let him assign it to a risk manager?
4:09But if I have a well-drilled down risk,
4:12I might potentially be able to assign it
4:15to the specific engineer working that shift
4:18and that particular piece of equipment,
4:20because that's what you want.
4:22Who should be assigned?
4:23The people most closely associated with that work.
4:27And so that's why you want those risk owners very clearly
4:30identified and not volatile.
4:33Because you can actually create another risk
4:36by assigning someone who's not qualified to deal with it.
4:40And we're going to talk about this many more times
4:42throughout this training.
4:44You're also going to have better decision making.
4:46Because again, at a minimum, you have three levels
4:50of reporting and decisions to make.
4:52Project, program, portfolio.
4:55And at a minimum, you might have three kinds
4:57of projects, predictive, hybrid, agile.
5:02There's a lot to this.
5:04So RBS-based categories are going to make your risk
5:08register scalable, auditable, easier to communicate.
5:13Because at some point, you're going
5:15to have to justify your methodology.
5:18I used an RBS.
5:20This is the one I used.
5:22These are my categories, subcategories, and specific risks.
5:26We went down four or five levels.
5:28And I can go down as many levels as appropriate
5:31for my project, my experience level, my team,
5:35geographical location, technology involved,
5:39and the list goes on and on.
5:41So let me give you some common examples for RBSs.
5:46Well, there's PESL, political, economic, social,
5:50technological, legal, external.
5:53That's just one.
5:56There's also T-COP.
5:57I always say T-COP, but I know it's T-COP.
6:00Technical, environmental, cost, operational, political.
6:04It can be whatever you want it to be.
6:07And you can customize it based on your industry,
6:10which is what I always recommend.
6:12But do not forget the danger associated with hybrid.
6:16And there is one.
6:17You should strive to create a specific hybrid model
6:22for your hybrid projects.
6:24And that's it.
6:24The structure behind risk breakdown structures
6:29as it relates to risk identification.
6:32Because if you can't identify them, you can't analyze them.
6:36If you can't analyze them,
6:37you can't figure out how to respond.
6:39And if you have no response,
6:41acceptance is the only thing you can do.
6:43And I promise you, things will go from bad to worse.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year