Wednesday, February 18, 2009

Risk Management Plan

First of all, people usually begin a project without any plan for how to identify, qualify, mitigate and respond to risk. It is an inescapable fact that when we engage a project we open ourselves up to risk. Too frequently we begin the project with no plan for managing risk, but moreover, I think that even when we do have a plan to manage risk we are only managing risk on one plane. We are not managing risk across the entire investment. I will try to make this distinction clear because it is important.

Most, if not all risk management plans are going to be hatched from knowledge or consideration of the PMBOK risk chapter. That is a good start. The processes identified there are solid and are practical for truly managing risk. The problem is that the problem space from which PMBOK prescribes management is too small. Think about it, PMBOK is very concerned with PROJECTS; temporary endeavors to meet a specific need. In this context you shouldn't realize any of the investment related risks; is it the right platform for the enterprise, technical obsolescence etc. You also shouldn't realize any of the detailed technical risks from actually operating the system or application; are you releasing patches to the OS in a timely manner, who has access to the application server.


Thus the PMBOK-prescribed Risk Management Plan is good for what it is, but it is deficient in managing the full spectrum of risk for most of what we do. Unless you are truly running a Ron Popeil type of project in which you can set it and forget it, you really need to consider both the investment level and detailed technical risks facing your project.

No comments:

Post a Comment