In the risky world of change, PMO is your risk guardian

There is risk all around us.

 

In everyday life risk exists, and we make judgements about risk without even thinking about it. We all identify and assess risks and make decisions to keep ourselves safe. Everything from judging if that coffee too hot, if it’s safe to cross the road or just how late can we leave and still make that meeting on time. We are naturally all risk managers, and when it comes to the repeatable patterns of daily life, we’re pretty good at it. Our ancestors were able to do it too. They could judge the risk of that odd shape in the bushes being a tasty dinner, or a vicious predator eyeing us up. The fact that we’re still here shows we have a long history of brilliant risk management!  

 

So, if we’re all so naturally great risk managers, what’s the problem? 

 

Much of our day-to-day risk management relies on our experience of the world and situations we’ve seen before, ‘I know that coffee is hot because I’ve had hot drinks before’, ‘I can recognise this is a road people drive quickly down, so I’ll go to the crossing’. Using our experience we’re able to short-cut risk management and make quick decisions. The challenge is, we often go beyond our own experiences.   

 

When we deliver change, we do two things which mean our normal pool of experience can quickly run dry.  

 

  • Running a project or programme to achieve a particular goal or strategic outcome may not be your core day-to-day role, you’re doing something new. During change the risk stakes can be high. Investing in change and trying something different you’re taking a risk. It might not work, the project could go wrong and not deliver, the investment might not be enough. You might have undertaken projects or programmes before, but each one will be a different and you may only have undertaken a few major changes, your pool of direct experience to pull from is limited.  
  • Second, by making the change you are altering the repeating patterns of the business and its operations, what were the risks, and ways to manage them before may not be now – our old experiences might no longer be sufficient to protect us from the new world.  

 

Experience tells us that actively identifying and managing risks is key to getting the outcomes you need. Whenever we deliver change, we need to re-think what we know and be more active in our approach to risk management. This is where great PMO can help. An experienced Enterprise, Portfolio, Programme or Programme Management Office (PMO) are experts in active risk management. With the right risk management framework, processes, tools and most importantly, experience they can help you to focus on actively managing the risks that matter and make your change and future operations a success. 

 

How can great PMO support you take an active approach to risk management?

 

The start point to active risk management is to identify the risks we’re dealing with. Most risk management frameworks (RMFs) casually say ‘identify all risks related to the project’. That is no easy feat. A large transformation will easily have hundreds, if not thousands of potential risks. Documenting every possible risk, no matter where from in your risk log means: 

 

  • Lots of Admin: You may spend the majority of your change time updating the risk log, rather than actively managing the risk 
  • Stale risks and bad decisions: The risk log quickly becomes stale, updates aren’t current, information is mis-leading or old meaning you can’t take the right risk management decisions without a laborious refresh of the log 
  • You can’t see the wood for the trees: By capturing every potential risk and worry across the programme you can end up with far too many to sensibly understand, meaning you could be focusing time and effort on the wrong risk. 

 

PMO can help you to identify the right risks to manage. One technique you may want to consider using is a risk breakdown tree. Often when risk identification is needed a team gathers together, often in a room, with a stack of sticky-notes and starts to write down all the things they see which might go wrong, covering a whole wall in their worries. Although getting the collective knowledge and range of insights from the team together is brilliant, an un-structured risk session can result in a poor set of identified risks. Often the worries of the loudest voice or biggest team in the room get over-represented, and whole areas of delivery or operations can be missed. One way you can combat this bias is by using a Risk Breakdown Tree. 

 

What is a Risk Breakdown Tree?

 

A Risk Breakdown Tree is a little like a family tree of potential problems. Start by taking the highest level risk as a pretty generic start, say ‘There’s a risk we won’t deliver the required change outcome’, then break this down to a short sub-set of risks at the next level by asking the simple question ‘why might this happen?’, very similar to a 5 why’s route cause analysis. You’re not looking to identify in one go all possible risks, just simply answer what might cause the level above to happen. You might go down to the next level and identify that the scope of change you have planned might not have the effect you hope, or you might not have the funding or resource to deliver the change needed. At this stage they’re still pretty generic, but by repeating the process of asking ‘why might this happen?’ and breaking down each level one-step at a time, soon you’ll be down in the specifics of your organisation, and you’ll build a picture of risk right across the scope and what the causes and drivers of the risk are.  

 

Doing this type of Risk Breakdown Tree can encourage the group to think about the full breadth of delivery, and not only focus on their area of expertise. By asking ‘why might this happen?’ you will naturally drive out worries and help people think of the specifics of the risks with real causes rather than a huge list of worries and concerns. You may end up breaking risks down to a low level which is great, but it can also be useful to pull back up a level or two when you capture your risks – remembering we want to avoid creating admin for the sake of admin! 

 

Creating the risk log

 

Once a set of risks has been identified it’s time to start capturing risks and adding them to the log. A good risk description is powerful both to communicate with others about the risks and challenges you face, and to help you clarify your own understanding of the specific risk being discussed. Using a risk description structure like ‘There is a risk that [EVENT] caused by [TRIGGER] resulting in [IMPACT]’ can really help you create clear risks. In this structure, we have the Event – the thing which might happen, the Trigger – what will cause the Event to happen and the Impact – what is the downside of this happening. Using this structure can help as it’s possible for the same risk event have by multiple triggers, each needing a different management response. 

 

Having identified and captured a clear set of risks which cover the full scope of change, it’s now time to identify which risks really need management attention. To pick the right risks to focus on we need to look at two key criteria. How likely the risk is to occur – Likelihood and if it does occur how bad will it be – Impact. For each of these criteria, how they are assessed will be specific to your business – you might consider Impact across a number of dimensions such as financial, reputational, and regulatory impacts or just a simple 1-5 scale to capture the different impacts in one go such as: 

 

Insignificant – If this event were to occur there will be little/no impact on the programme activities or reputation

 

  • Committed business benefits will still be realised 
  • Delivery costs will not significantly change (<2% variance to cost) 
  • Delivery timescales will be unaltered 

 

Low – A minor event which would give only small-scale impacts to the programme delivery

 

  • Minor delay to benefits realisation (<1wk) 
  • Delivery costs suffer small impact (<5% variance to cost) 
  • Delivery timescales or resources needed may be slightly impacted 

 

Moderate – A risk which would cause notable but not serious impacts to one of many workstreams

 

  • Business benefits likely to still be achieved by may be delayed 
  • Delays to the delivery (>1month) or increased costs (<10% variance to cost) 
  • Approach and business case may require re-assessment to confirm they remain valid 

 

High – A severe event which could reduce the achievement of business benefits which could alter the desirability of the business case

 

  • Business benefits not fully achieved 
  • Significant delays (+1month) or increased costs (+10% variance to cost) 
  • Business case may require review prior to continuing activities/spend 

 

Very High – If this major event were to occur there would be critical damage to the programme or significant impact on a business area

 

  • Business benefits will not be achieved/significant business disbenefits would occur 
  • Programme would require a major review of approach, scope and/or costs 

 

Likelihood could also be a simple scale: 

 

  • Remote Chance 
  • Low Chance 
  • As likely as not 
  • More likely than not 
  • Almost Certain 

 

Criteria like this can mean different things to different people, so you could add a percentage chance of happening. Here though we are trying to predict the future, which is difficult at the best of times and risk management can need to rely on experience more than science. It is particularly important that all parties are assessing risks based in the same criteria. The criteria need to be consistent across management levels, a Very High impact to a workstream would be very different to a Very High impact to the Enterprise or a Portfolio.  

 

A Great PMO are experts at helping create the right assessment criteria for your business and change, allowing people to assess risks consistently and communicate about them clearly, rolling the right information up management levels. 

 

With our set of clearly described risks, we can quickly identify our most significant risks requiring attention. By plotting a risk heat-map of impact against likelihood we can clearly visualise the most impactful and likeliest risks needing our attention. It can also be a good idea to plot the direction of travel of risks using an initial assessment, current and even target – are the risk management actions having the desired effect? Are we on course to manage our risk down to an acceptable level? 

Are you looking for critical business transformation?

Let’s talk real change
Relevant insights and customer stories
Sign up to our eNewsletter

Get the latest news, relevant insights and expertise from our change experts

Marketing updates confirmation(Required)
Privacy policies confirmation(Required)