SlideShare a Scribd company logo
2
Most read
3
Most read
4
Most read
Ā© 2017 ONE BCG. All Rights Reserved.
Software Risk Analysis
2
Ā© 2017 ONE BCG. All Rights Reserved.
Table of Contents
Presentation focuses on the below stated items :-
• What is a Risk?
• Types of Risks
• Examples of Risks
• Why does Risk arouse?
• Why bother with Risks?
• Risk Analysis and Management
• Elements of Risk Analysis
• Strengths of Risk Analysis
• Limitations of Risk Analysis
• Conclusion
• Case Study
3
Ā© 2017 ONE BCG. All Rights Reserved.
What is a Risk?
• Probability of loss ā€˜or’ potential negative event that may or may not occur in the
future.
• Loss can be anything i.e. increase in production cost, development of poor quality
software, not meeting project deadlines, etc.
- Software Risk: Possibility of suffering from loss in the Software Development
Process.
• Risk is caused due to the lack of information, time or future uncertainty.
• It provides an opportunity to develop the project better.
• There’s a difference between a Problem and a Risk.
- A problem is an event that has already occurred, but Risk is something that’s
unpredictable.
4
Ā© 2017 ONE BCG. All Rights Reserved.
Types of Risks
• Software Risk can be of two types:
– Internal Risks
• Come from risk factors within the organization and arise during normal
operation.
• Within the control of the project team and are often forecastable, and thus
can be avoided or mitigated.
• Mainly arise from human ā€˜or’ technical factors.
– External Risks
• Difficult to control and come from risk factors outside the
organization/project.
• Beyond the control of the project team.
• Mainly stem from legislative, environmental or political changes.
5
Ā© 2017 ONE BCG. All Rights Reserved.
Examples of Risks
Example 1:
Scenario
• The team is working on a project and the developer walks out of the project due to
unavoidable circumstances.
• Another person is recruited in his place and he doesn’t work on the same platform.
• A new developer converts it into the platform he is comfortable with.
• Now the project has to yield the same result in the same period.
A risk that can be drawn from the above Scenario.
• Whether the team will be able to complete the project on time or not and that’s the
Risk of Schedule.
6
Ā© 2017 ONE BCG. All Rights Reserved.
Examples of Risks
Example 2:
Scenario
• BA has elicited requirements on what the Solution should deliver.
• BA thus prepares the RSD (Requirement Specification Document) and sends it to
stakeholders for feedback.
• Most of the stakeholders respond and are requested for sign-off.
Risks that can be drawn from the above Scenario
• Requirements change before sign-off.
• Stakeholders misunderstand the RSD.
• A few key stakeholders are unavailable to participate.
• One stakeholder refuses to sign-off.
7
Ā© 2017 ONE BCG. All Rights Reserved.
Why does Risks arouse?
• Software Risks arise mainly of three possible cases:
– Known Knowns
• Risks are known to the entire project/team.
• These are defined in the Project Management Plan.
• Example: Project delay due to not having enough developers.
– Known Unknowns
• The risks project team is aware of but is unsure whether they still exist or not.
• Example: Requirements from the client are not captured properly and this fact
is known to the project team. However, whether the client has communicated
all the information properly or not is unknown to the project.
– Unknown Unknowns
• Risks about which organization is unaware of.
• Example: They are generally related to working with technology ā€˜or’ tools that
you have no idea about but your client wants to work that way.
8
Ā© 2017 ONE BCG. All Rights Reserved.
Risk Analysis and Management
• Risk Analysis and Management involves the identification of the areas of
uncertainty that could negatively affect value; Analyze and Evaluate those
uncertainties; and also develops and manages the Ways of dealing with the Risks.
• Risk Management is an ongoing activity i.e. continuous consultation and
communication with stakeholders helps to both identify new Risks and to monitor
the identified Risks.
• The Project Team can develop plans for avoiding, reducing, or modifying the Risks,
and when necessary, implementing these plans.
9
Ā© 2017 ONE BCG. All Rights Reserved.
Elements of Risk Analysis - Identification
• The goal is to identify a comprehensive set of relevant Risks and to minimize the
unknowns.
• Risks are discovered and identified through a combination of expert judgment,
stakeholder input, experimentation, past experiences, and historical analysis of
similar initiatives and situations.
• A Risk event could be due to one occurrence, several occurrences, or even a non-
occurrence.
• A Risk condition could be just one event or a combination of events. One event or
condition may have several consequences, and one consequence may be caused by
several different events or conditions.
10
Ā© 2017 ONE BCG. All Rights Reserved.
Elements of Risk Analysis - Analysis
• Analysis of a Risk involves understanding the Risk and estimating the level of a Risk.
– Sometimes controls may already be in place to deal with some Risks, and these
should be taken into account when analyzing the Risk.
• The likelihood of its occurrence could be expressed as a probability either on a
numerical scale or with values such as Low, Medium, and High.
• The impact of any Risk can be described in terms of cost, duration, solution scope,
solution quality, or any other factor agreed to by the stakeholders such as
reputation, compliance, or social responsibility.
11
Ā© 2017 ONE BCG. All Rights Reserved.
Elements of Risk Analysis - Analysis
• Each Risk can be described in a ā€œRisk Registerā€ that supports the analysis of those
Risks and Plans for addressing them.
12
Ā© 2017 ONE BCG. All Rights Reserved.
Elements of Risk Analysis - Analysis
• The ā€œRisk Impact Scaleā€ is the best way to showcase the impact of Risks.
13
Ā© 2017 ONE BCG. All Rights Reserved.
Elements of Risk Analysis - Evaluation
• The Risk Analysis results are compared with the potential value of the change
ā€˜or’ of the solution to determine if the level of Risk is acceptable or not.
• An overall project Risk level may be determined by adding up all the individual
risk levels.
14
Ā© 2017 ONE BCG. All Rights Reserved.
Elements of Risk Analysis - Treatment
There are four possible ways to deal with Risks:
– Avoid:
Eliminate the threat ā€˜or’ protect the project from its impact. Common actions
that can eliminate Risks are
• Change the scope of the project.
• Extend the schedule to eliminate a Risk to timely project completion.
• Change project objectives.
• Clarify requirements to eliminate ambiguities and misunderstandings.
– Transfer:
This involves moving the impact of the Risk to a third party.
15
Ā© 2017 ONE BCG. All Rights Reserved.
Elements of Risk Analysis - Treatment
– Mitigate:
Reduce the probability or impact of the risk.
This is not always possible and often comes
with a price that must be balanced against the
value of performing the mitigating action.
– Accept:
Sometimes there is no other alternative than to
proceed with the project and accept the Risk.
But producing documentation, holding
meetings, and communicating the Risk with
stakeholders can go a long way toward
minimizing the damage.
16
Ā© 2017 ONE BCG. All Rights Reserved.
Strengths of Risk Analysis
• It can be applied to Strategic Risks which affect the long-term value of the
enterprise; Tactical Risks which affect the value of a change; and Operational Risks
which affect the value of a solution once the change is made.
• An organization typically faces similar challenges on many of its initiatives. The
successful Risk responses on one initiative can be useful lessons learned for other
initiatives.
• The Risk level of a change ā€˜or’ of a solution could vary over time. Ongoing Risk
Management helps to recognize that variation and to re-evaluate the Risks and the
suitability of the planned responses.
• It can transform Risks into a threshold for new opportunities.
• Prevents department isolation.
17
Ā© 2017 ONE BCG. All Rights Reserved.
Limitations of Risk Analysis
• The number of possible Risks to most projects can easily become unmanageably
large. It may only be possible to manage a subset of potential Risks.
• There is the possibility that significant Risks are not identified.
• High dependency on team experience.
• Vague, difficult to implement plans.
18
Ā© 2017 ONE BCG. All Rights Reserved.
Conclusion
• Managing Risks doesn’t mean one will be able to fend off all the unwanted events
from the project but it does imply that when ā€˜or’ if they do happen, you’re prepared
to respond to them.
• No matter how hard one tries, it is impossible to plan for every single Risk.
• As soon as something is noticed that’s not quite right, don't mull over it excessively -
voice it out and collaborate with the project team to develop an effective strategy
for responding to it.
19
Ā© 2017 ONE BCG. All Rights Reserved.
Case Study - Todd Herman Associates
• Situation:
– This company provides various financial, accounting, investment management,
and tax services to its clients. Information Systems play a critical role in
delivering these services.
• Problem:
– This company outsourced much of its Information Systems function.
– Executives and management believed that this arrangement was working well
and that the network / certain applications were being adequately maintained
and protected under the guidance of their network service provider.
– Top Executives, however, wanted to validate this belief, both for their peace of
mind, as well as to be able to answer questions from clients, auditors, and
bankers.
20
Ā© 2017 ONE BCG. All Rights Reserved.
Case Study - Todd Herman Associates
• Solution:
– Our approach was to perform an Initial Risk Assessment related to network,
infrastructure and security technologies in use, to assess the level of Risks
associated (High, Medium, or Low).
– The team performed the Risk Assessment taking into consideration the various
factors such as network availability, data security, etc.
• Results after Assessment and Recommendations:
– Several areas that management had not truly assessed were shown to have
better security than believed.
– The internal and external threat assessments identified specific steps required
to mitigate several remaining Risks.
– Upon completion of these steps, management responsible for the Information
Systems function was better able to assess potential Risks, through knowledge
and techniques learned during this engagement
21
Ā© 2017 ONE BCG. All Rights Reserved.
You can measure opportunity with the same yardstick that measures the
risk involved. They go together.
– Earl Nightingale
22
Ā© 2017 ONE BCG. All Rights Reserved.
Thank You !

More Related Content

PPTX
Risk Management
Kinza Razzaq
Ā 
PDF
The importance of properly describing risks, presented by Peter Simon, 10th O...
Association for Project Management
Ā 
PPTX
Project mngmnt risks3.2
Ananya Indrajith
Ā 
PDF
Risk Management
Glen Alleman
Ā 
PDF
Options based decisions processes
Glen Alleman
Ā 
PPTX
Risk Mitigation Epics Purdue 10 Sept 2008
enginerd
Ā 
PDF
Applying risk radar (v2)
Glen Alleman
Ā 
PDF
Managing Risk in Construction Contracts and Projects - 2016 Brochure
Angelin Soosaipillai, LL.B.
Ā 
Risk Management
Kinza Razzaq
Ā 
The importance of properly describing risks, presented by Peter Simon, 10th O...
Association for Project Management
Ā 
Project mngmnt risks3.2
Ananya Indrajith
Ā 
Risk Management
Glen Alleman
Ā 
Options based decisions processes
Glen Alleman
Ā 
Risk Mitigation Epics Purdue 10 Sept 2008
enginerd
Ā 
Applying risk radar (v2)
Glen Alleman
Ā 
Managing Risk in Construction Contracts and Projects - 2016 Brochure
Angelin Soosaipillai, LL.B.
Ā 

What's hot (20)

PDF
Project examples for sampling and the law of large numbers
John Goodpasture
Ā 
DOC
Agile project management and normative
Glen Alleman
Ā 
PDF
Managing risk with deliverables planning
Glen Alleman
Ā 
PDF
Notional cam interview questions (update)
Glen Alleman
Ā 
PDF
Probabilistic Cost, Schedule, and Risk management
Glen Alleman
Ā 
PPTX
Construction Risk Summit "benefit and pits of Construction Risk Management"
bfriday
Ā 
PDF
A Comprehensive Overview and Interpretation of Risk and Uncertainty in Projec...
Dr. Mustafa Değerli
Ā 
PPTX
Project Risk Management and Uncertainty
Baker Khader Abdallah, PMP
Ā 
PDF
Risk Management Framework - Dr. Mustafa Degerli
Dr. Mustafa Değerli
Ā 
PPTX
Project Risk Management
Kaustubh Gupta
Ā 
PPTX
Risk Management
Alastair Dunning
Ā 
PDF
Risk management case study
Eng.Ahmed Said Mohamed Refaei
Ā 
PPTX
Project risk management: Techniques and strategies
DebashishDas49
Ā 
PPT
Iwsm2014 defining technical risk in software development (vard antinyan)
Nesma
Ā 
PPT
Building business continuity through risk management, presented by Kimberley ...
Association for Project Management
Ā 
PDF
Risk Analysis & Risk Management
Grafic.guru
Ā 
PPT
Stephen Ward: Performance uncertainty management is a more effective approach...
Association for Project Management
Ā 
PPT
Risk analysis for project decision-making, presented by Keith Gray, 10th Oct ...
Association for Project Management
Ā 
PDF
12.0 risk management agile+evm (v10.2)
Glen Alleman
Ā 
PDF
Project Risk Management
Kelvin Fredson
Ā 
Project examples for sampling and the law of large numbers
John Goodpasture
Ā 
Agile project management and normative
Glen Alleman
Ā 
Managing risk with deliverables planning
Glen Alleman
Ā 
Notional cam interview questions (update)
Glen Alleman
Ā 
Probabilistic Cost, Schedule, and Risk management
Glen Alleman
Ā 
Construction Risk Summit "benefit and pits of Construction Risk Management"
bfriday
Ā 
A Comprehensive Overview and Interpretation of Risk and Uncertainty in Projec...
Dr. Mustafa Değerli
Ā 
Project Risk Management and Uncertainty
Baker Khader Abdallah, PMP
Ā 
Risk Management Framework - Dr. Mustafa Degerli
Dr. Mustafa Değerli
Ā 
Project Risk Management
Kaustubh Gupta
Ā 
Risk Management
Alastair Dunning
Ā 
Risk management case study
Eng.Ahmed Said Mohamed Refaei
Ā 
Project risk management: Techniques and strategies
DebashishDas49
Ā 
Iwsm2014 defining technical risk in software development (vard antinyan)
Nesma
Ā 
Building business continuity through risk management, presented by Kimberley ...
Association for Project Management
Ā 
Risk Analysis & Risk Management
Grafic.guru
Ā 
Stephen Ward: Performance uncertainty management is a more effective approach...
Association for Project Management
Ā 
Risk analysis for project decision-making, presented by Keith Gray, 10th Oct ...
Association for Project Management
Ā 
12.0 risk management agile+evm (v10.2)
Glen Alleman
Ā 
Project Risk Management
Kelvin Fredson
Ā 
Ad

Similar to Software risk analysis and management (20)

PPTX
Risk Management
Saqib Raza
Ā 
PPT
Risk management(software engineering)
Priya Tomar
Ā 
PPT
Risk analysis and management
gnitu
Ā 
PPTX
OOSE-PRESENTATION.pptx
RanjitKdk
Ā 
PPTX
Mykhailo Hryhorash: Š£ŠæŃ€Š°Š²Š»Ń–Š½Š½Ń ризиками та змінами (UA)
Lviv Startup Club
Ā 
PPT
project_risk_mgmt_final.ppt
avisha23
Ā 
PPT
PMI project_risk_management_final_2022.ppt
DorraLamouchi1
Ā 
PPT
project_risk_mgmt_final.ppt
AyidAlmgati
Ā 
PPT
project_risk_mgmt_final 1.ppt
BetshaTizazu2
Ā 
PPT
Project Risk Management
Nimat Khattak
Ā 
PDF
Risk Management.pdf for college studentds
UdayMann1
Ā 
PDF
risk-management-121021125051-phpapp02 (1).pdf
PriyanshTan
Ā 
PPTX
Project risk analysis
SUBHASISHMAHAKUD
Ā 
PPT
Risk analysis
saurabhshertukde
Ā 
PPT
Software Risk Management updated.ppt
umairshams6
Ā 
PPT
lecture9-190719030941 globalized availab
faiziikanwal47
Ā 
PPT
Software Engineering (Risk Management)
ShudipPal
Ā 
PPT
Riskmanagement software Engineering1.ppt
sirishaYerraboina1
Ā 
PPT
RM_PPT.ppt risk managementfor transmission line
AkdDeshmukh
Ā 
PPT
risk management
Arti Maggo
Ā 
Risk Management
Saqib Raza
Ā 
Risk management(software engineering)
Priya Tomar
Ā 
Risk analysis and management
gnitu
Ā 
OOSE-PRESENTATION.pptx
RanjitKdk
Ā 
Mykhailo Hryhorash: Š£ŠæŃ€Š°Š²Š»Ń–Š½Š½Ń ризиками та змінами (UA)
Lviv Startup Club
Ā 
project_risk_mgmt_final.ppt
avisha23
Ā 
PMI project_risk_management_final_2022.ppt
DorraLamouchi1
Ā 
project_risk_mgmt_final.ppt
AyidAlmgati
Ā 
project_risk_mgmt_final 1.ppt
BetshaTizazu2
Ā 
Project Risk Management
Nimat Khattak
Ā 
Risk Management.pdf for college studentds
UdayMann1
Ā 
risk-management-121021125051-phpapp02 (1).pdf
PriyanshTan
Ā 
Project risk analysis
SUBHASISHMAHAKUD
Ā 
Risk analysis
saurabhshertukde
Ā 
Software Risk Management updated.ppt
umairshams6
Ā 
lecture9-190719030941 globalized availab
faiziikanwal47
Ā 
Software Engineering (Risk Management)
ShudipPal
Ā 
Riskmanagement software Engineering1.ppt
sirishaYerraboina1
Ā 
RM_PPT.ppt risk managementfor transmission line
AkdDeshmukh
Ā 
risk management
Arti Maggo
Ā 
Ad

More from ONE BCG (11)

PPTX
A comprehensive guide to user behavioral analytics
ONE BCG
Ā 
PPTX
What is product development and its process?
ONE BCG
Ā 
PPTX
Why effective communication with clients is necessary?
ONE BCG
Ā 
PPTX
An ultimate guide to SOLID Principles, developers must know.
ONE BCG
Ā 
PPTX
How Artificial intelligence and machine learning are different?
ONE BCG
Ā 
PPTX
What is Agile and Scrum, their guiding principles and methods?
ONE BCG
Ā 
PPTX
Prototype: Its methods, techniques, and key features.
ONE BCG
Ā 
PPTX
How to prepare a project for automated deployment?
ONE BCG
Ā 
PPTX
What is Load, Stress and Endurance Testing?
ONE BCG
Ā 
PPTX
What is security testing and why it is so important?
ONE BCG
Ā 
PPTX
Brushing skills on SignalR for ASP.NET developers
ONE BCG
Ā 
A comprehensive guide to user behavioral analytics
ONE BCG
Ā 
What is product development and its process?
ONE BCG
Ā 
Why effective communication with clients is necessary?
ONE BCG
Ā 
An ultimate guide to SOLID Principles, developers must know.
ONE BCG
Ā 
How Artificial intelligence and machine learning are different?
ONE BCG
Ā 
What is Agile and Scrum, their guiding principles and methods?
ONE BCG
Ā 
Prototype: Its methods, techniques, and key features.
ONE BCG
Ā 
How to prepare a project for automated deployment?
ONE BCG
Ā 
What is Load, Stress and Endurance Testing?
ONE BCG
Ā 
What is security testing and why it is so important?
ONE BCG
Ā 
Brushing skills on SignalR for ASP.NET developers
ONE BCG
Ā 

Recently uploaded (20)

PDF
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
Ā 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
Ā 
PPTX
The Future of AI & Machine Learning.pptx
pritsen4700
Ā 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
Ā 
PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
Ā 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
Ā 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
Ā 
PDF
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
Ā 
PDF
Presentation about Hardware and Software in Computer
snehamodhawadiya
Ā 
PDF
Brief History of Internet - Early Days of Internet
sutharharshit158
Ā 
PDF
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
Ā 
PDF
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
Ā 
PDF
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
Ā 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
Ā 
PDF
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
Ā 
PDF
Software Development Methodologies in 2025
KodekX
Ā 
PDF
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
Ā 
PDF
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
Ā 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
Ā 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
Ā 
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
Ā 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
Ā 
The Future of AI & Machine Learning.pptx
pritsen4700
Ā 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
Ā 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
Ā 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
Ā 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
Ā 
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
Ā 
Presentation about Hardware and Software in Computer
snehamodhawadiya
Ā 
Brief History of Internet - Early Days of Internet
sutharharshit158
Ā 
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
Ā 
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
Ā 
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
Ā 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
Ā 
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
Ā 
Software Development Methodologies in 2025
KodekX
Ā 
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
Ā 
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
Ā 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
Ā 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
Ā 

Software risk analysis and management

  • 1. Ā© 2017 ONE BCG. All Rights Reserved. Software Risk Analysis
  • 2. 2 Ā© 2017 ONE BCG. All Rights Reserved. Table of Contents Presentation focuses on the below stated items :- • What is a Risk? • Types of Risks • Examples of Risks • Why does Risk arouse? • Why bother with Risks? • Risk Analysis and Management • Elements of Risk Analysis • Strengths of Risk Analysis • Limitations of Risk Analysis • Conclusion • Case Study
  • 3. 3 Ā© 2017 ONE BCG. All Rights Reserved. What is a Risk? • Probability of loss ā€˜or’ potential negative event that may or may not occur in the future. • Loss can be anything i.e. increase in production cost, development of poor quality software, not meeting project deadlines, etc. - Software Risk: Possibility of suffering from loss in the Software Development Process. • Risk is caused due to the lack of information, time or future uncertainty. • It provides an opportunity to develop the project better. • There’s a difference between a Problem and a Risk. - A problem is an event that has already occurred, but Risk is something that’s unpredictable.
  • 4. 4 Ā© 2017 ONE BCG. All Rights Reserved. Types of Risks • Software Risk can be of two types: – Internal Risks • Come from risk factors within the organization and arise during normal operation. • Within the control of the project team and are often forecastable, and thus can be avoided or mitigated. • Mainly arise from human ā€˜or’ technical factors. – External Risks • Difficult to control and come from risk factors outside the organization/project. • Beyond the control of the project team. • Mainly stem from legislative, environmental or political changes.
  • 5. 5 Ā© 2017 ONE BCG. All Rights Reserved. Examples of Risks Example 1: Scenario • The team is working on a project and the developer walks out of the project due to unavoidable circumstances. • Another person is recruited in his place and he doesn’t work on the same platform. • A new developer converts it into the platform he is comfortable with. • Now the project has to yield the same result in the same period. A risk that can be drawn from the above Scenario. • Whether the team will be able to complete the project on time or not and that’s the Risk of Schedule.
  • 6. 6 Ā© 2017 ONE BCG. All Rights Reserved. Examples of Risks Example 2: Scenario • BA has elicited requirements on what the Solution should deliver. • BA thus prepares the RSD (Requirement Specification Document) and sends it to stakeholders for feedback. • Most of the stakeholders respond and are requested for sign-off. Risks that can be drawn from the above Scenario • Requirements change before sign-off. • Stakeholders misunderstand the RSD. • A few key stakeholders are unavailable to participate. • One stakeholder refuses to sign-off.
  • 7. 7 Ā© 2017 ONE BCG. All Rights Reserved. Why does Risks arouse? • Software Risks arise mainly of three possible cases: – Known Knowns • Risks are known to the entire project/team. • These are defined in the Project Management Plan. • Example: Project delay due to not having enough developers. – Known Unknowns • The risks project team is aware of but is unsure whether they still exist or not. • Example: Requirements from the client are not captured properly and this fact is known to the project team. However, whether the client has communicated all the information properly or not is unknown to the project. – Unknown Unknowns • Risks about which organization is unaware of. • Example: They are generally related to working with technology ā€˜or’ tools that you have no idea about but your client wants to work that way.
  • 8. 8 Ā© 2017 ONE BCG. All Rights Reserved. Risk Analysis and Management • Risk Analysis and Management involves the identification of the areas of uncertainty that could negatively affect value; Analyze and Evaluate those uncertainties; and also develops and manages the Ways of dealing with the Risks. • Risk Management is an ongoing activity i.e. continuous consultation and communication with stakeholders helps to both identify new Risks and to monitor the identified Risks. • The Project Team can develop plans for avoiding, reducing, or modifying the Risks, and when necessary, implementing these plans.
  • 9. 9 Ā© 2017 ONE BCG. All Rights Reserved. Elements of Risk Analysis - Identification • The goal is to identify a comprehensive set of relevant Risks and to minimize the unknowns. • Risks are discovered and identified through a combination of expert judgment, stakeholder input, experimentation, past experiences, and historical analysis of similar initiatives and situations. • A Risk event could be due to one occurrence, several occurrences, or even a non- occurrence. • A Risk condition could be just one event or a combination of events. One event or condition may have several consequences, and one consequence may be caused by several different events or conditions.
  • 10. 10 Ā© 2017 ONE BCG. All Rights Reserved. Elements of Risk Analysis - Analysis • Analysis of a Risk involves understanding the Risk and estimating the level of a Risk. – Sometimes controls may already be in place to deal with some Risks, and these should be taken into account when analyzing the Risk. • The likelihood of its occurrence could be expressed as a probability either on a numerical scale or with values such as Low, Medium, and High. • The impact of any Risk can be described in terms of cost, duration, solution scope, solution quality, or any other factor agreed to by the stakeholders such as reputation, compliance, or social responsibility.
  • 11. 11 Ā© 2017 ONE BCG. All Rights Reserved. Elements of Risk Analysis - Analysis • Each Risk can be described in a ā€œRisk Registerā€ that supports the analysis of those Risks and Plans for addressing them.
  • 12. 12 Ā© 2017 ONE BCG. All Rights Reserved. Elements of Risk Analysis - Analysis • The ā€œRisk Impact Scaleā€ is the best way to showcase the impact of Risks.
  • 13. 13 Ā© 2017 ONE BCG. All Rights Reserved. Elements of Risk Analysis - Evaluation • The Risk Analysis results are compared with the potential value of the change ā€˜or’ of the solution to determine if the level of Risk is acceptable or not. • An overall project Risk level may be determined by adding up all the individual risk levels.
  • 14. 14 Ā© 2017 ONE BCG. All Rights Reserved. Elements of Risk Analysis - Treatment There are four possible ways to deal with Risks: – Avoid: Eliminate the threat ā€˜or’ protect the project from its impact. Common actions that can eliminate Risks are • Change the scope of the project. • Extend the schedule to eliminate a Risk to timely project completion. • Change project objectives. • Clarify requirements to eliminate ambiguities and misunderstandings. – Transfer: This involves moving the impact of the Risk to a third party.
  • 15. 15 Ā© 2017 ONE BCG. All Rights Reserved. Elements of Risk Analysis - Treatment – Mitigate: Reduce the probability or impact of the risk. This is not always possible and often comes with a price that must be balanced against the value of performing the mitigating action. – Accept: Sometimes there is no other alternative than to proceed with the project and accept the Risk. But producing documentation, holding meetings, and communicating the Risk with stakeholders can go a long way toward minimizing the damage.
  • 16. 16 Ā© 2017 ONE BCG. All Rights Reserved. Strengths of Risk Analysis • It can be applied to Strategic Risks which affect the long-term value of the enterprise; Tactical Risks which affect the value of a change; and Operational Risks which affect the value of a solution once the change is made. • An organization typically faces similar challenges on many of its initiatives. The successful Risk responses on one initiative can be useful lessons learned for other initiatives. • The Risk level of a change ā€˜or’ of a solution could vary over time. Ongoing Risk Management helps to recognize that variation and to re-evaluate the Risks and the suitability of the planned responses. • It can transform Risks into a threshold for new opportunities. • Prevents department isolation.
  • 17. 17 Ā© 2017 ONE BCG. All Rights Reserved. Limitations of Risk Analysis • The number of possible Risks to most projects can easily become unmanageably large. It may only be possible to manage a subset of potential Risks. • There is the possibility that significant Risks are not identified. • High dependency on team experience. • Vague, difficult to implement plans.
  • 18. 18 Ā© 2017 ONE BCG. All Rights Reserved. Conclusion • Managing Risks doesn’t mean one will be able to fend off all the unwanted events from the project but it does imply that when ā€˜or’ if they do happen, you’re prepared to respond to them. • No matter how hard one tries, it is impossible to plan for every single Risk. • As soon as something is noticed that’s not quite right, don't mull over it excessively - voice it out and collaborate with the project team to develop an effective strategy for responding to it.
  • 19. 19 Ā© 2017 ONE BCG. All Rights Reserved. Case Study - Todd Herman Associates • Situation: – This company provides various financial, accounting, investment management, and tax services to its clients. Information Systems play a critical role in delivering these services. • Problem: – This company outsourced much of its Information Systems function. – Executives and management believed that this arrangement was working well and that the network / certain applications were being adequately maintained and protected under the guidance of their network service provider. – Top Executives, however, wanted to validate this belief, both for their peace of mind, as well as to be able to answer questions from clients, auditors, and bankers.
  • 20. 20 Ā© 2017 ONE BCG. All Rights Reserved. Case Study - Todd Herman Associates • Solution: – Our approach was to perform an Initial Risk Assessment related to network, infrastructure and security technologies in use, to assess the level of Risks associated (High, Medium, or Low). – The team performed the Risk Assessment taking into consideration the various factors such as network availability, data security, etc. • Results after Assessment and Recommendations: – Several areas that management had not truly assessed were shown to have better security than believed. – The internal and external threat assessments identified specific steps required to mitigate several remaining Risks. – Upon completion of these steps, management responsible for the Information Systems function was better able to assess potential Risks, through knowledge and techniques learned during this engagement
  • 21. 21 Ā© 2017 ONE BCG. All Rights Reserved. You can measure opportunity with the same yardstick that measures the risk involved. They go together. – Earl Nightingale
  • 22. 22 Ā© 2017 ONE BCG. All Rights Reserved. Thank You !