Risk management plan
   HOME

TheInfoList



OR:

A risk management plan is a document that a project manager prepares to foresee risks, estimate impacts, and define responses to risks. It also contains a risk assessment matrix. A risk is "an uncertain event or condition that, if it occurs, has a positive or negative effect on a project's objectives." Risk is inherent with any project, and project managers should assess risks continually and develop plans to address them. The risk management plan contains an analysis of likely risks with both high and low impact, as well as mitigation strategies to help the project avoid being derailed should common problems arise. Risk management plans should be periodically reviewed by the project team to avoid having the analysis become stale and not reflective of actual potential project risks. Most critically, risk management plans include a risk strategy.


Risk response

Broadly, there are four potential responses to risk with numerous variations on the specific terms used to name these response options: * Avoid – Change plans to circumvent the problem; * Control / mitigate / modify / reduce – Reduce threat impact or likelihood (or both) through intermediate steps; * Accept / retain – Assume the chance of the negative impact (or ''auto-insurance''), eventually ''budget'' the cost (e.g. via a contingency budget line); or * Transfer / share – Outsource risk (or a portion of the risk) to a third party or parties that can manage the outcome. This is done financially through insurance contracts or hedging transactions, or operationally through outsourcing an activity. (Mnemonic: SARA, for Share Avoid Reduce Accept, or A-CAT, for "Avoid, Control, Accept, or Transfer") Risk management plans often include matrices.


Examples

The United States Department of Defense, as part of acquisition, uses risk management planning that may have a Risk Management Plan document for the specific project. The general intent of the RMP in this context is to define the scope of risks to be tracked and means of documenting reports. It is also desired that there would be an integrated relationship to other processes. An example of this would be explaining which developmental tests verify risks of the design type were minimized are stated as part of the test and evaluation master plan. A further example would be instructions from 5000.2DSECNAVINST 5000.2D 3.4.4.1
/ref> that for programs that are part of a
system of systems System of systems is a collection of task-oriented or dedicated systems that pool their resources and capabilities together to create a new, more complex system which offers more functionality and performance than simply the sum of the constituent s ...
the risk management strategy shall specifically address integration and interoperability as a risk area. The RMP specific process and templates shift over time (e.g. the disappearance of 2002 documents Defense Finance and Accounting Service / System Risk Management Plan, and the SPAWAR Risk Management Process).


See also

*
Event chain methodology Event chain methodology is a network analysis technique that is focused on identifying and managing events and relationship between them (event chains) that affect project schedules. It is an uncertainty modeling schedule technique. Event chain me ...
*
Project management Project management is the process of leading the work of a team to achieve all project goals within the given constraints. This information is usually described in project documentation, created at the beginning of the development process. T ...
*
Project Management Professional Project Management Professional (PMP) is an internationally recognized professional designation offered by the Project Management Institute (PMI). As of 31 July 2020, there are 1,036,368 active PMP-certified individuals and 314 chartered chapters ...
* Risk evaluation and mitigation strategy (REMS) * Risk management * Risk management tools * Risk management framework


References

{{Reflist


External links


Creating The Risk Management Plan (template included)

EPA RMP Rule page

Risk Management Guide for DoD Acquisition (ver 6 - ver 5.2 more detailed but obsolete)

Defense Acquisition University, System Engineering Fundamentals (see ch 15)

US DoD extension to PMBOK Guide, June 2003 (see ch 11)

US DoD extension to PMBOK Guide (see ch 11)

US Defense Acquisition Guidebook (DAG) - ch8 testing

DAU Risk Management Plan template
Project management Systems engineering Risk management