Exploring trends and developments
in project management today.

Project Smart Logo

Subscribe  Follow Project Smart on Twitter!

Ranking Risks: Rare to Certain, Negligible to Catastrophic

By ExecutiveBrief
Sign Saying Risk

Risks your project or business is exposed to may be worth reviewing now more than ever to see which ones need more attention than others.

Risk is a concept that denotes a potential negative impact to an asset or some characteristic of value that may arise from some present process or future event. In everyday usage, risk is often used synonymously with the probability of a known loss. Risk is measured in terms of impact and likelihood. Since risk is directly correlated to loss, it is important to be able to assess risks in one's business and to address them. Needless to say, inattention to risks can definitely affect a company's bottom line.

Some businesses actually go by without a formal risk assessment policy, nor is there a unit that directly assesses the impact of risks in the organisation. We have been so accustomed to risk in our everyday lives that the tendency is to ignore minor ones and react when major ones occur. Moreover, effective risk management carries with it some costs, which, when presented to stakeholders, naturally would lead to questions on how the costs could be justified.

Risk management is a modern buzzword, but in no means a new science. More and more businesses and organisations recognise the need to identify risks within them so that they can be controlled and mitigated. It is important to exercise risk mitigation when it affects people, the environment, and one's business, to name a few. Risk avoidance cannot make the potential of even greater loss from happening go away.

The question is, as a manager, how would I know which particular sets of risks need a special level of attention? Given limited resources, how would I know which particular types of risks need to be prioritised and addressed?

A risk matrix is a risk assessment tool which exposes aspects of risks that could be subjected to some form of ranking. The matrix has ranges of consequence and likelihood as axes. A risk matrix shows the manager and the decision maker a clearer view of what the risk is, what is involved (in terms of procedural changes, costs, behavioural adjustments, and the like), and what amount of time can be afforded given the severity and probability of the risk event. It can help a manager visualise, in an organised manner, the risks he or she faces in quantitative and qualitative terms and plan and make a more informed decision when the situation arises.

How does one construct an effective risk matrix?

1. Identify what the risk matrix is to be used for

Normally a risk matrix is called for during exercises involving hazard analyses, facility siting studies, and safety audits. Depending on the intended use of the matrix, one may need to establish tolerance or risk acceptability levels and a means of assessing the effectiveness of risk mitigation measures.

2. Define consequence and likelihood ranges

A typical risk matrix is a four by four grid. On the Y (vertical) axis is the "probability/likelihood" description range while on the X (horizontal) axis is the "consequence" range

Sample Risk Matrix

Figure 1: Sample Risk Matrix

Consequences of risks as laid down in the grid use descriptive words and are ranked according to severity: Negligible, Marginal, Critical, and Catastrophic. Negligible risks are the least severe and would be assigned the lowest rank. Inversely, catastrophic risks are those that would be first in the severity ranking. Determine tolerance by assigning dollar values to each severity ranking, as well as some qualitative characteristics of the consequence being described. For example, Negligible Risks are those that involve USD 2,000 but less than USD 10,000 and could result in minor illness or injury to employees not exceeding a day, does not violate laws, or has little or minimal environmental damage and will be assigned Rank 1 in the matrix. Catastrophic Risks are those that involve USD 1M, could result in death or permanent disability, result in irreversible environmental damage or permanent closure to business, and will be assigned Rank 4 in the matrix.

Rank Range Amount of Loss in USD Description of Loss
4 Catastrophic 1M or more
  • Results in death or permanent disability of employees.
  • Irreversible environmental damage.
  • Closure to business.
3 Critical 200,000 but less than 1M
  • Results in partial permanent disability, injuries or illness of 3 employees or more.
  • Reversible environmental damage.
  • Violation of law/regulation.
2 Marginal 10,000 but less than 200,000
  • Injury or illness of resulting in one or more work days lost.
  • Mitigable environmental damage where restoration activities can be done.
1 Negligible 2,000 but less than 10,000
  • Minor illness or injury to employees resulting in one day's absence.
  • Does not violate laws.
  • Little or minimal environmental damage.

Figure 2: Sample Consequence Ranking

The Probability axis describes the likelihood of the risk happening and can be assigned either Frequent, Probable, Occasional, Remote, or Improbable, or simply Certain, Likely, Possible, Unlikely, or Rare. Again, it would be helpful to state the likelihood criteria in numeric terms (example, "Possible" means the risk will occur several times in a lifetime but not less than 10 times nor over 100 times in that lifetime) and to assign logical rankings.

Rank Range Probability (over the life of a business) Description
5 Certain Once in 2 years Continually experienced
4 Likely Once in 4 years Will occur frequently
3 Possible Once in 6 years Will occur several times
2 Unlikely Once in 12 years Unlikely, but can be reasonably expected to occur
1 Once in 24 years Unlikely to occur, but possible  

Figure 3: Sample Probability Ranking

Once the criteria for consequence and likelihood has been laid down, proceed to determine specific incidents, events or conditions that pose risk for the business and assign them along the blocks in the matrix. Example of an incident in the office would be "burst pipes and leaks" - this could be assigned in the block Rare (Rank 5 Likelihood) and Negligible (Rank 1 Consequence).

3. Translate the tolerability criteria into the matrix

The design of the matrix should be able to show clearly which of the blocks are intolerable or tolerable. For example, a Possible (Rank 3 Likelihood) intersecting with a Catastrophic (Rank 4 Consequence) would be intolerable for any business, given the description and values you have previously assigned. This block is a clear subject of risk mitigation efforts in the organisation compared to a block (risk) pertaining to a Negligible (Rank 1 Consequence) intersecting with a Certain (Rank 2 Likelihood) which could be addressed, say, with a simple change or adjustment in organisational policy.

Determining Tolerance Points in the Matrix

Figure 4: Determining Tolerance Points in the Matrix

Care in assigning values

Risk matrices are fairly easy to construct and understand. However, one has to be careful in assigning values, taking care not to be overly quantitative and not affording to include what is called a "layer of protection" approach, a means of including protective measures, which, when applied, brings down the risk a level lower. As in all planning and risk management efforts, it is recommended that the risk planner or analyst, even the manager, exercise conservatism in its design as well as point out areas of alarm. Decision makers are recommended to use this tool in policy formulation and include budgetary allocations to address not only persistent risks but also be ready for potentially catastrophic ones.

ExecutiveBrief, the technology management resource for business leaders, offers articles loaded with proven tips, techniques, and action plans that companies can use to better manage people, processes and tools - the keys to improving their business performance. To learn more, please visit: http://www.executivebrief.com External Link

© ExecutiveBrief 2008

Comments page 1 of 1
Click here to add a comment
bob ashley
Posted 525 days ago
Thanks for your efforts on this article. The matrix and supporting explanation is clear, simple, and vivid. I'm the CAO for a small town in Nova Scotia www.town.berwick.ns.ca and your matrix looks like an excellent tool to communicate risk to a local council of elected representatives.

Great work!

bob
@bashley (twitter)
 

Article Categories

Related Articles

10 Golden Rules of Project Risk Management
The benefits of risk management in projects are huge. You can gain a lot of money if you deal with uncertain project events in a proactive manner. Experience shows that 10 golden rules exist to implement risk management successful in your project.

Your Risk Management Process: A Practical and Effective Approach
A solid risk management process can help to make a project run smoothly. By identifying and addressing a list of project risks as part of a larger project management system, many surprises and roadblocks can be eliminated. Learn more about the definition of a risk as well as the steps that should be a part of your business's risk management process and how you can incorporate such a process into all projects going forward.

Project Risk Management: It's Either Contingency Planning Now or Emergency Relief Later
Proper project risk management entails more than simply identification and analysis at the beginning of a project. Risk management must be integrated into the project plan, consistently applied, and clearly communicated throughout the life cycle of the project.

The Top Five Software Project Risks
I recently posted an entry on a risk assessment tool you can download and use. Risk management (or more precisely risk avoidance) is a critical topic, but one that is often dull to read about and therefore neglected. One of the few useful and entertaining books on the subject is "Waltzing with Bears: Managing Risk on Software Projects" by Tom Demarco, Timothy Lister, authors of the ever popular "Peopleware." This post provides a useful summary of their top 5 software project risks.

21 Ways to Excel at Project Management
The popular project management e-book now fully updated and available as a website for the first time.