Skip to main content

Chapter 5 · 7 hours

Project Risk Analysis and Management

IOE past exam questions

Past questions and answers

26 questions set from this chapter, 6 of them more than once; 1 is most repeated (set, or a close variant set, in 3 or more exams). Most repeated first.

  • Most repeated · 3 of 26 exams
  • Asked 3 times
  • 2080 Baisakh · 4 marks
  • 2076 Asoj · 4 marks
  • 2078 Bhadra · 6 marks

What are the strategies for risk response planning? Why is risk response planning important in a project? What are the response strategies for negative risk?

Answer

Risk response planning

Risk response planning is the process of developing options and actions to improve opportunities and reduce threats to the project objectives, after the risks are identified and analysed. It assigns an owner for each response and puts the cost and time for it into the plan.

Strategies for risk response planning

  • For negative risks (threats): avoid, transfer, mitigate (reduce), accept.
  • For positive risks (opportunities): exploit, share, enhance, accept.
  • Contingent response: a plan used only if a trigger event occurs.

Why it is important

  1. Gives a planned action before the risk happens, so loss is smaller.
  2. Reduces the probability and impact of threats and increases opportunities.
  3. Sets responsibility (risk owner), time and budget (contingency reserve).
  4. Protects cost, schedule and quality objectives.
  5. Helps decisions on insurance, contract type and reserves.
  6. Gives confidence to the client, lenders and the team.

Response strategies for negative risks

StrategyMeaningExample
AvoidChange the plan so the risk cannot occur or its impact is removedShift a bridge site away from unstable slope; change to proven design
TransferShift the impact and ownership of the risk to a third party (it is not removed)Insurance (CAR policy), performance bond, fixed-price contract, subcontract
Mitigate (reduce)Reduce the probability and/or the impact to an acceptable levelExtra soil tests, early procurement, quality control, training, safety measures
AcceptDo nothing now (passive) or keep a contingency reserve (active)Minor price change accepted with contingency of 5%

The best strategy is chosen by comparing the cost of the response with the expected loss. High-probability, high-impact risks are avoided or reduced; low-probability, high-impact risks are transferred (insurance); small risks are accepted.

  • Asked 2 times
  • 2081 Baisakh · 2+4 marks
  • 2080 Bhadra · 2+4 marks

Define risk. Explain the different types (categories) of project risk.

Answer

Definition

Risk is an uncertain event or condition which, if it occurs, has a positive or negative effect on the project objectives (scope, time, cost, quality). It is measured by the probability of the event and the size of its impact: Risk = Probability x Impact.

Types (categories) of project risk

CategoryExamples in a project
Technical riskFaulty design, new or unproven technology, poor geotechnical data, change in specifications
Schedule (time) riskLate site handover, late approvals, slow work, monsoon delay, strikes
Cost riskWrong estimate, price rise of cement, steel, fuel, exchange rate change, variations
Financial riskDelay in payment or loan release, interest rate change, cash-flow shortage
Management / organisational riskPoor planning, weak coordination, lack of skilled staff, unclear responsibility
Contractual / legal riskUnclear contract clauses, disputes, claims, land acquisition and court cases
Political and social riskPolicy change, bandh, local opposition, corruption, compensation conflict
Environmental / natural riskFlood, landslide, earthquake, adverse weather, environmental clearance problems
Safety and health riskAccidents, collapse, health hazards at site
Market / commercial riskFall in demand, change in tariff, competition, supplier failure

Other classification

  • By nature: pure risk (only loss is possible, e.g. fire, accident, flood) and speculative / business risk (gain or loss is possible, e.g. price change, market demand).
  • By source: internal risk (inside the control of the project team: estimate, design, management, labour, equipment) and external risk (outside control: government policy, weather, inflation, market, law).
  • By effect: negative risk (threat) and positive risk (opportunity).
  • By knowledge: known risks (identified and can be planned) and unknown risks (cannot be foreseen, handled by contingency reserve).
  • Asked 2 times
  • 2074 Asoj · 1+4 marks
  • 2078 Bhadra · 6 marks

Define risk management. Describe the steps of risk management. As a project manager, how will you manage risk in a project?

Answer

Definition

Project risk management is the systematic process of planning, identifying, analysing, responding to, and monitoring and controlling risks in a project, so that the chance and effect of negative events are reduced and the chance of positive events is increased.

Steps of risk management

  1. Risk management planning: decide the approach, team, roles, budget, tools, risk categories, probability-impact scales and reporting. The output is the risk management plan.
  2. Risk identification: find the risks which may affect the project and document them in a risk register (brainstorming, checklist, Delphi, SWOT, interviews, experience).
  3. Qualitative risk analysis: rank the risks by probability and impact using a probability-impact matrix to find priority risks.
  4. Quantitative risk analysis: estimate the numerical effect of the main risks on cost and time (expected monetary value, decision tree, sensitivity analysis, Monte Carlo simulation).
  5. Risk response planning: select the strategy for each risk (avoid, transfer, mitigate/reduce, accept) and prepare contingency plans and reserves.
  6. Risk monitoring and control: track identified risks, watch for new risks, check the response is working, update the risk register and report.

Managing risk in my project as project manager

  1. Prepare a risk management plan at the start and assign a risk owner to each risk.
  2. Identify risks with the team and stakeholders; keep a risk register.
  3. Prioritise by a probability-impact matrix; calculate EMV of the top risks.
  4. Choose responses: avoid (change design or site), transfer (insurance, performance bond, fixed-price contract), mitigate (testing, early procurement, training), accept with contingency reserve (usually 5 to 10% of cost and time).
  5. Include the response actions in the schedule and budget.
  6. Hold regular risk review meetings, track triggers, update the register and report to the client.
  7. Keep records of lessons learned for future projects.
  • Asked 2 times
  • 2082 Baisakh · 4 marks
  • 2076 Asoj · 4 marks

Write down the tools and techniques used for risk identification in a project.

Answer

Risk identification is the process of finding and documenting the risks that may affect the project. It is done at the start and repeated during the project. The output is the risk register.

Tools and techniques

  1. Documentation review: study the project plan, drawings, contracts, assumptions, previous reports to find inconsistencies and weak points.
  2. Information gathering techniques:
    • Brainstorming: a team (engineers, client, contractor) freely lists possible risks.
    • Delphi technique: experts give anonymous opinions in rounds until they agree.
    • Interviews: talking with experienced people and stakeholders.
    • Root cause analysis: find the basic cause behind a risk and then more risks from it.
  3. Checklist analysis: a list prepared from past similar projects (e.g. hydropower or road projects) is checked item by item.
  4. Assumption analysis: test whether the assumptions (e.g. availability of land, material price) are valid and complete.
  5. Diagramming techniques: cause-and-effect (fishbone) diagram, flow charts, influence diagrams.
  6. SWOT analysis: strengths, weaknesses, opportunities and threats of the project are used to find risks and opportunities.
  7. Expert judgement and lessons learned: use experts and records of earlier projects.
  8. Prompt list / PESTLE: political, economic, social, technological, legal and environmental categories used as prompts.

The best result comes when several techniques are combined and the project team, experts and stakeholders are all involved.

  • Asked 2 times
  • 2075 Asoj · 8 marks
  • 2082 Baisakh · 4 marks

Explain and justify that risk transfer and risk reduction are techniques of risk response planning in any project.

Answer

Risk response planning selects the action for each analysed risk. The main strategies for threats are avoid, transfer, reduce (mitigate) and accept. Risk transfer and risk reduction are both response techniques because each one plans an action, owner and cost before the risk occurs, and each one lowers the final effect on project objectives.

Risk transfer

Transfer means shifting the negative impact and ownership of the risk to another party, usually with a payment (premium or higher contract price). The risk does not disappear, but the loss is paid by the other party.

  • Insurance (contractor's all risk, workmen compensation, third party)
  • Performance bond / bank guarantee, advance payment guarantee
  • Fixed-price (lump-sum) contract, which transfers cost risk to the contractor
  • Subcontracting special works, warranties and indemnity clauses

Justification: it is planned in advance, has a cost, and it reduces the owner's exposure to a major loss (e.g. flood damage to a bridge is paid by the insurer). It is best for low-probability, high-impact risks.

Risk reduction (mitigation)

Reduction means taking action to lower the probability or the impact of the risk to an acceptable level.

  • More soil investigation to reduce design risk
  • Early ordering of cement and steel to reduce price and delay risk
  • Training, safety measures, quality control, prototypes, backup equipment
  • Splitting the work into packages and parallel suppliers

Justification: it attacks the cause of the risk, it is planned with a budget in the schedule, and it is usually cheaper than the loss. It is best for high-probability risks that are inside the control of the team.

Conclusion on both

PointTransferReduction
EffectMoves the impact to another partyLowers probability or impact
CostPremium or contract priceCost of preventive action
Best forRare but severe risksFrequent and controllable risks

As both are planned, resourced and assigned before the event, both are risk response planning techniques. In a hydropower project, floods are transferred by insurance and geological risk is reduced by detailed investigation.

  • Asked 2 times
  • 2073 Shrawan · 5 marks
  • 2070 Chaitra · 2 marks

Explain with a suitable example how risk transfer is taken as risk response planning. (What methods can be used in risk management after identifying a major risk?)

Answer

Risk transfer in risk response planning

Risk transfer is a response strategy in which the project owner shifts the negative impact and responsibility of a risk to a third party, who accepts it for a fee. The risk still exists, but the loss is borne by the other party. It is chosen after analysis, mainly for risks with low probability and very high impact, or for risks the other party can manage better.

Example: construction of a highway bridge

Risk: flood or earthquake damage during construction, and contractor delay or failure.

  1. Insurance: the contractor takes a Contractor's All Risk (CAR) policy; if flood damages the work, the insurer pays for repair.
  2. Performance bond: a bank guarantee (usually 5 to 10% of contract price) is taken so that the bank pays if the contractor fails.
  3. Fixed-price (lump sum) contract: the cost overrun risk is transferred to the contractor.
  4. Liquidated damages: delay risk is transferred by a clause charging the contractor per day of delay.

The owner pays a premium or a higher price, but is protected from a very large loss.

Methods used after identifying a major risk

  • Avoid the risk (change plan, design or site)
  • Transfer it (insurance, contract, guarantee)
  • Mitigate / reduce it (preventive action, extra investigation)
  • Accept it (with a contingency reserve)
  • Monitor it and prepare a contingency plan with triggers
  • 2071 Chaitra · 2+5+5 marks

Define risk. Explain various sources of project risks. Describe the important steps of risk management.

Answer

Definition

Risk is an uncertain event or condition which, if it occurs, has a positive or negative effect on the project objectives (scope, time, cost, quality). It is measured by the probability of the event and the size of its impact: Risk = Probability x Impact.

Sources of project risk

  1. Technical sources: incomplete or wrong design and drawings, inadequate survey and investigation, difficult geology, new technology, quality of materials and workmanship.
  2. Estimating and planning sources: unrealistic cost estimate and schedule, missing activities, over-optimistic productivity, poor risk allowance.
  3. Management sources: weak project manager, poor coordination between client, consultant and contractor, lack of skilled manpower, poor monitoring and decision making.
  4. Financial sources: shortage of funds, delay in release of budget or payment, inflation, interest and exchange rate changes.
  5. Contractual and legal sources: vague contract documents, variation orders, claims and disputes, change in laws, land acquisition and compensation problems.
  6. Political and social sources: government change and policy change, bandh and strikes, local community demand, corruption, security situation.
  7. Natural and environmental sources: flood, landslide, earthquake, heavy rain, climate change, environmental impact and clearance requirements.
  8. Resource and market sources: shortage or price rise of material, fuel, labour and equipment; supplier delay; transport problem (especially in remote areas of Nepal).
  9. Human and safety sources: accidents, labour dispute, health problems, errors and negligence.

Steps of risk management

  1. Risk management planning: decide the approach, team, roles, budget, tools, risk categories, probability-impact scales and reporting. The output is the risk management plan.
  2. Risk identification: find the risks which may affect the project and document them in a risk register (brainstorming, checklist, Delphi, SWOT, interviews, experience).
  3. Qualitative risk analysis: rank the risks by probability and impact using a probability-impact matrix to find priority risks.
  4. Quantitative risk analysis: estimate the numerical effect of the main risks on cost and time (expected monetary value, decision tree, sensitivity analysis, Monte Carlo simulation).
  5. Risk response planning: select the strategy for each risk (avoid, transfer, mitigate/reduce, accept) and prepare contingency plans and reserves.
  6. Risk monitoring and control: track identified risks, watch for new risks, check the response is working, update the risk register and report.
 Plan -> Identify -> Qualitative -> Quantitative
   ^                                     |
   |                                     v
 Monitor and control  <-----------  Response planning
  • 2070 Asar · 1+5+4 marks

Define 'risk'. Explain various sources of project risk. Elaborate risk response planning.

Answer

Definition

Risk is an uncertain event or condition which, if it occurs, has a positive or negative effect on the project objectives (scope, time, cost, quality). It is measured by the probability of the event and the size of its impact: Risk = Probability x Impact.

Sources of project risk

  1. Technical sources: incomplete or wrong design and drawings, inadequate survey and investigation, difficult geology, new technology, quality of materials and workmanship.
  2. Estimating and planning sources: unrealistic cost estimate and schedule, missing activities, over-optimistic productivity, poor risk allowance.
  3. Management sources: weak project manager, poor coordination between client, consultant and contractor, lack of skilled manpower, poor monitoring and decision making.
  4. Financial sources: shortage of funds, delay in release of budget or payment, inflation, interest and exchange rate changes.
  5. Contractual and legal sources: vague contract documents, variation orders, claims and disputes, change in laws, land acquisition and compensation problems.
  6. Political and social sources: government change and policy change, bandh and strikes, local community demand, corruption, security situation.
  7. Natural and environmental sources: flood, landslide, earthquake, heavy rain, climate change, environmental impact and clearance requirements.
  8. Resource and market sources: shortage or price rise of material, fuel, labour and equipment; supplier delay; transport problem (especially in remote areas of Nepal).
  9. Human and safety sources: accidents, labour dispute, health problems, errors and negligence.

Risk response planning

Risk response planning develops options and actions to reduce threats and increase opportunities, using the results of risk analysis. Each response has an owner, a cost, a time and a trigger.

Strategies for negative risks (threats)

StrategyMeaningExample
AvoidChange the plan so the risk cannot occur or its impact is removedShift a bridge site away from unstable slope; change to proven design
TransferShift the impact and ownership of the risk to a third party (it is not removed)Insurance (CAR policy), performance bond, fixed-price contract, subcontract
Mitigate (reduce)Reduce the probability and/or the impact to an acceptable levelExtra soil tests, early procurement, quality control, training, safety measures
AcceptDo nothing now (passive) or keep a contingency reserve (active)Minor price change accepted with contingency of 5%

Strategies for positive risks (opportunities)

StrategyMeaning
ExploitMake sure the opportunity happens (assign best staff to finish early)
ShareGive ownership to a party best able to catch the opportunity (joint venture)
EnhanceIncrease probability or impact of the opportunity
AcceptTake the benefit if it comes, without extra effort

Output: risk register update, risk-related contracts (insurance, bonds), contingency reserve for time and cost, fall-back plans and the project plan updates. The response should cost less than the expected loss and should not create new risks.

  • 2079 Bhadra · 6 marks

Describe the different sources of risk.

Answer

Project risk comes from the many uncertain conditions in and around a project. The main sources are:

  1. Technical sources: incomplete or wrong design and drawings, inadequate survey and investigation, difficult geology, new technology, quality of materials and workmanship.
  2. Estimating and planning sources: unrealistic cost estimate and schedule, missing activities, over-optimistic productivity, poor risk allowance.
  3. Management sources: weak project manager, poor coordination between client, consultant and contractor, lack of skilled manpower, poor monitoring and decision making.
  4. Financial sources: shortage of funds, delay in release of budget or payment, inflation, interest and exchange rate changes.
  5. Contractual and legal sources: vague contract documents, variation orders, claims and disputes, change in laws, land acquisition and compensation problems.
  6. Political and social sources: government change and policy change, bandh and strikes, local community demand, corruption, security situation.
  7. Natural and environmental sources: flood, landslide, earthquake, heavy rain, climate change, environmental impact and clearance requirements.
  8. Resource and market sources: shortage or price rise of material, fuel, labour and equipment; supplier delay; transport problem (especially in remote areas of Nepal).
  9. Human and safety sources: accidents, labour dispute, health problems, errors and negligence.

These sources are grouped as internal (technical, estimating, management, human) and external (political, natural, market, legal). Knowing the sources lets the team look for risk systematically using checklists.

  • 2081 Bhadra · 6 marks

Projects in Nepal are usually completed over budget with delayed completion time. What are the major sources of risk that are associated with such projects in Nepal?

Answer

Many Nepali projects (roads, hydropower, buildings, irrigation) finish late and over budget. The main sources of risk are:

  1. Weak planning and design: incomplete survey, drawings and cost estimate; lack of detailed investigation; unrealistic schedule; many design changes in construction.
  2. Land acquisition and compensation: delay in getting site, right of way, forest clearance, tree cutting and utility shifting.
  3. Procurement and contractor problems: lowest-bid award to weak contractors, abandoning of work, poor capacity, slow bid process, contract termination.
  4. Funding and payment delays: late release of budget, payment delay, shortage of counterpart fund, dependence on donors.
  5. Political and administrative factors: frequent change of government and officials, delay in approvals, bandh, local interference, corruption.
  6. Natural and geographic factors: monsoon floods, landslides, earthquake, difficult terrain, remote access and short working season.
  7. Shortage of material and labour: price rise of cement, steel and fuel; transport cost; shortage of skilled labour due to migration abroad; blockade.
  8. Weak management and supervision: poor monitoring, lack of coordination between agencies, weak project management skill.
  9. Contract and dispute issues: variation orders, claims, arbitration, unclear contract.
  10. Environmental and social issues: EIA and IEE delay, public opposition, protests by affected people.

Most of these risks are not analysed or planned in advance in Nepali projects, which explains the cost and time overrun.

  • 2074 Chaitra · 2+6+2 marks

Define risk and its types. How could you manage risk in a project effectively? Justify with the risk management cycle.

Answer

Definition and types

Risk is an uncertain event or condition which, if it occurs, has a positive or negative effect on the project objectives (scope, time, cost, quality). It is measured by the probability of the event and the size of its impact: Risk = Probability x Impact.

CategoryExamples in a project
Technical riskFaulty design, new or unproven technology, poor geotechnical data, change in specifications
Schedule (time) riskLate site handover, late approvals, slow work, monsoon delay, strikes
Cost riskWrong estimate, price rise of cement, steel, fuel, exchange rate change, variations
Financial riskDelay in payment or loan release, interest rate change, cash-flow shortage
Management / organisational riskPoor planning, weak coordination, lack of skilled staff, unclear responsibility
Contractual / legal riskUnclear contract clauses, disputes, claims, land acquisition and court cases
Political and social riskPolicy change, bandh, local opposition, corruption, compensation conflict
Environmental / natural riskFlood, landslide, earthquake, adverse weather, environmental clearance problems
Safety and health riskAccidents, collapse, health hazards at site
Market / commercial riskFall in demand, change in tariff, competition, supplier failure
  • By nature: pure risk (only loss is possible, e.g. fire, accident, flood) and speculative / business risk (gain or loss is possible, e.g. price change, market demand).
  • By source: internal risk (inside the control of the project team: estimate, design, management, labour, equipment) and external risk (outside control: government policy, weather, inflation, market, law).
  • By effect: negative risk (threat) and positive risk (opportunity).
  • By knowledge: known risks (identified and can be planned) and unknown risks (cannot be foreseen, handled by contingency reserve).

Managing risk effectively: the risk management cycle

   +-------------------+
   |  Risk planning    |
   +---------+---------+
             v
   +-------------------+      +--------------------+
   | Risk identification| --> | Risk analysis      |
   +-------------------+      | (qualitative and   |
             ^                |  quantitative)     |
             |                +---------+----------+
   +---------+---------+                v
   | Monitoring and    | <-- +--------------------+
   | control           |     | Risk response      |
   +-------------------+     | planning           |
                             +--------------------+

The cycle is repeated through the project life, because new risks appear and old ones change as the project moves from planning to implementation.

Steps and how they manage risk

  1. Risk management planning: decide the approach, team, roles, budget, tools, risk categories, probability-impact scales and reporting. The output is the risk management plan.
  2. Risk identification: find the risks which may affect the project and document them in a risk register (brainstorming, checklist, Delphi, SWOT, interviews, experience).
  3. Qualitative risk analysis: rank the risks by probability and impact using a probability-impact matrix to find priority risks.
  4. Quantitative risk analysis: estimate the numerical effect of the main risks on cost and time (expected monetary value, decision tree, sensitivity analysis, Monte Carlo simulation).
  5. Risk response planning: select the strategy for each risk (avoid, transfer, mitigate/reduce, accept) and prepare contingency plans and reserves.
  6. Risk monitoring and control: track identified risks, watch for new risks, check the response is working, update the risk register and report.

Justification

The cycle is justified because risk management is continuous: planning sets rules, identification and analysis find and rank risks, response planning decides actions, and monitoring checks and feeds new information back to identification. Doing it in cycle makes sure no new risk is left unmanaged and responses stay effective as the project changes.

  • 2075 Chaitra · 10 marks

Define risk, its types and sources. As a project manager, how would you rectify the possible risks on your project? Give your answer considering all possible steps that fall under risk management.

Answer

Risk

Risk is an uncertain event or condition which, if it occurs, has a positive or negative effect on the project objectives (scope, time, cost, quality). It is measured by the probability of the event and the size of its impact: Risk = Probability x Impact.

Types of risk

  • By nature: pure risk (only loss is possible, e.g. fire, accident, flood) and speculative / business risk (gain or loss is possible, e.g. price change, market demand).
  • By source: internal risk (inside the control of the project team: estimate, design, management, labour, equipment) and external risk (outside control: government policy, weather, inflation, market, law).
  • By effect: negative risk (threat) and positive risk (opportunity).
  • By knowledge: known risks (identified and can be planned) and unknown risks (cannot be foreseen, handled by contingency reserve).

Main categories: technical, schedule, cost, financial, management, legal, political, environmental, safety and market risk.

Sources of risk

  1. Technical sources: incomplete or wrong design and drawings, inadequate survey and investigation, difficult geology, new technology, quality of materials and workmanship.
  2. Estimating and planning sources: unrealistic cost estimate and schedule, missing activities, over-optimistic productivity, poor risk allowance.
  3. Management sources: weak project manager, poor coordination between client, consultant and contractor, lack of skilled manpower, poor monitoring and decision making.
  4. Financial sources: shortage of funds, delay in release of budget or payment, inflation, interest and exchange rate changes.
  5. Contractual and legal sources: vague contract documents, variation orders, claims and disputes, change in laws, land acquisition and compensation problems.
  6. Political and social sources: government change and policy change, bandh and strikes, local community demand, corruption, security situation.
  7. Natural and environmental sources: flood, landslide, earthquake, heavy rain, climate change, environmental impact and clearance requirements.
  8. Resource and market sources: shortage or price rise of material, fuel, labour and equipment; supplier delay; transport problem (especially in remote areas of Nepal).
  9. Human and safety sources: accidents, labour dispute, health problems, errors and negligence.

Rectifying the risks as project manager

I would apply the full risk management process:

  1. Risk management planning: decide the approach, team, roles, budget, tools, risk categories, probability-impact scales and reporting. The output is the risk management plan.
  2. Risk identification: find the risks which may affect the project and document them in a risk register (brainstorming, checklist, Delphi, SWOT, interviews, experience).
  3. Qualitative risk analysis: rank the risks by probability and impact using a probability-impact matrix to find priority risks.
  4. Quantitative risk analysis: estimate the numerical effect of the main risks on cost and time (expected monetary value, decision tree, sensitivity analysis, Monte Carlo simulation).
  5. Risk response planning: select the strategy for each risk (avoid, transfer, mitigate/reduce, accept) and prepare contingency plans and reserves.
  6. Risk monitoring and control: track identified risks, watch for new risks, check the response is working, update the risk register and report.
 Impact ->   Low      Medium     High
 Prob.
 High       Medium     High      High
 Medium      Low      Medium     High
 Low         Low       Low      Medium

Practical actions: keep a risk register with owners, take insurance and performance guarantees (transfer), do extra investigation and early procurement (reduce), change the design or site for severe risks (avoid), keep a contingency reserve of 5 to 10% (accept), hold monthly risk meetings and update the register.

  • 2081 Baisakh · 2+4 marks

Elaborate the risk management cycle. How can project risk be managed effectively?

Answer

Risk management cycle

   +-------------------+
   |  Risk planning    |
   +---------+---------+
             v
   +-------------------+      +--------------------+
   | Risk identification| --> | Risk analysis      |
   +-------------------+      | (qualitative and   |
             ^                |  quantitative)     |
             |                +---------+----------+
   +---------+---------+                v
   | Monitoring and    | <-- +--------------------+
   | control           |     | Risk response      |
   +-------------------+     | planning           |
                             +--------------------+

The cycle is repeated through the project life, because new risks appear and old ones change as the project moves from planning to implementation.

  1. Plan: decide approach, roles, tools and scales.
  2. Identify: list risks by brainstorming, checklists, Delphi, SWOT.
  3. Analyse: qualitative ranking, then quantitative effect on cost and time.
  4. Respond: avoid, transfer, reduce or accept; prepare contingency.
  5. Monitor and control: track risks, review, update and report.

Managing risk effectively

  • Start risk management early, in the planning stage, and keep it through all phases.
  • Involve all stakeholders and experts in the identification.
  • Keep a live risk register with owner, trigger and response for each risk.
  • Focus on the top risks by priority (probability x impact, EMV).
  • Put the response in the schedule and budget, with contingency reserve.
  • Use contracts, insurance and guarantees to transfer risk.
  • Review regularly, learn from past projects, and communicate the risk status to the client.
  • 2080 Bhadra · 2+4 marks

How could you effectively manage risk in a project? Explain the qualitative and quantitative risk management system.

Answer

Managing risk effectively

  1. Plan the risk process and assign responsibility.
  2. Identify risks early with the team and stakeholders; keep a risk register.
  3. Analyse and rank the risks (qualitative, then quantitative).
  4. Plan responses: avoid, transfer, reduce, accept; add contingency reserve.
  5. Monitor, control and update the risks through the project life.

Qualitative risk analysis

It assesses each risk by probability and impact on a descriptive scale to set priority. It is quick and needs no detailed data.

 Impact ->   Low      Medium     High
 Prob.
 High       Medium     High      High
 Medium      Low      Medium     High
 Low         Low       Low      Medium

Tools: probability-impact matrix, risk categorisation, urgency assessment, expert judgement.

Quantitative risk analysis

It gives a numerical estimate of the effect of the priority risks on cost and time.

  • Expected monetary value: EMV = probability x impact (money)
  • Decision tree: compares choices with probability and money outcomes
  • Sensitivity analysis: which variable (e.g. cement price) most affects the result
  • Monte Carlo simulation: repeated random runs to get the probability of finishing within a given cost or time
  • PERT: three-point estimates for duration
  • 2079 Bhadra · 6 marks

Explain the different methods of qualitative and quantitative analysis of risk.

Answer

Qualitative risk analysis methods

Qualitative analysis ranks risks by probability and impact using ordinal scales (low, medium, high).

  1. Probability and impact assessment: each risk is given a rating.
  2. Probability-impact matrix: combines the two to give priority.
 Impact ->   Low      Medium     High
 Prob.
 High       Medium     High      High
 Medium      Low      Medium     High
 Low         Low       Low      Medium
  1. Risk categorisation: grouping by source (technical, financial, etc.) to find the problem areas.
  2. Risk urgency assessment: risks needing early response are made first.
  3. Expert judgement and interviews.

Quantitative risk analysis methods

Quantitative analysis puts numbers to the effect of the risk.

  1. Expected monetary value (EMV): EMV = P x I. Example: P = 20%, loss = Rs 10 lakh gives EMV = Rs 2 lakh.
  2. Decision tree analysis: branches show decisions and chance outcomes; the branch with the best expected value is chosen.
  3. Sensitivity analysis: change one variable at a time; the tornado diagram shows the most sensitive one.
  4. Simulation (Monte Carlo): many random runs of the cost or schedule model give a distribution and the probability of meeting the target.
  5. PERT three-point estimate: te=(a+4m+b)/6t_e = (a + 4m + b)/6 and variance ((b−a)/6)2((b-a)/6)^2.
  6. Interviewing and probability distributions from experts.

Qualitative is quick and used for all risks; quantitative is slower and used for the high-priority risks.

  • 2076 Chaitra · 2+6+4 marks

Define project risk management. What is qualitative and quantitative risk analysis? What are the major steps that you take in managing risks?

Answer

Project risk management

Project risk management is the systematic process of planning, identifying, analysing, responding to, and monitoring and controlling risks in a project, so that the chance and effect of negative events are reduced and the chance of positive events is increased.

Qualitative and quantitative risk analysis

Qualitative analysis ranks risks by their probability and impact using descriptive scales (very low to very high). It is fast, cheap and used first. Tools: probability-impact matrix, risk categorisation, risk urgency assessment, expert judgement, risk data quality assessment.

Quantitative analysis gives numerical values of the effect of risk on the project objectives. It is applied to the high-priority risks. Tools: expected monetary value (EMV = probability x impact), decision tree analysis, sensitivity analysis (tornado diagram), simulation (Monte Carlo) and PERT three-point estimation.

 Impact ->   Low      Medium     High
 Prob.
 High       Medium     High      High
 Medium      Low      Medium     High
 Low         Low       Low      Medium
BasisQualitativeQuantitative
OutputPriority rankNumerical effect (money, days)
DataJudgementStatistical/estimated data
Time and costLowHigh
Applied toAll risksHigh-priority risks

Major steps in managing risks

  1. Risk management planning: decide the approach, team, roles, budget, tools, risk categories, probability-impact scales and reporting. The output is the risk management plan.
  2. Risk identification: find the risks which may affect the project and document them in a risk register (brainstorming, checklist, Delphi, SWOT, interviews, experience).
  3. Qualitative risk analysis: rank the risks by probability and impact using a probability-impact matrix to find priority risks.
  4. Quantitative risk analysis: estimate the numerical effect of the main risks on cost and time (expected monetary value, decision tree, sensitivity analysis, Monte Carlo simulation).
  5. Risk response planning: select the strategy for each risk (avoid, transfer, mitigate/reduce, accept) and prepare contingency plans and reserves.
  6. Risk monitoring and control: track identified risks, watch for new risks, check the response is working, update the risk register and report.
  • 2072 Kartik

Define risk management planning. Explain in detail the internal and external risks in a project. Justify, giving a suitable example, how risk reduction is taken as risk response planning.

Answer

Risk management planning

Risk management planning is the process of deciding how to carry out risk management for a project. It defines the approach, methodology, roles and responsibilities, budget and time for risk activities, risk categories, definition of probability and impact scales, risk thresholds, reporting formats and tracking. The output is the risk management plan, which guides all other risk processes.

Internal and external risks

BasisInternal riskExternal risk
SourceInside the project/organisationOutside the project/organisation
ControlCan be controlled by the project teamCannot be controlled, only reduced or transferred
ExamplesWrong estimate, poor design, weak management, skill shortagePolicy change, inflation, flood, earthquake, bandh
ResponseAvoid, mitigateTransfer, accept, contingency

Internal risks:

  1. Inaccurate cost estimate, schedule and unrealistic bid.
  2. Incomplete and poor design, drawings and surveys.
  3. Weak planning, coordination and project management.
  4. Shortage of skilled labour, engineers and equipment.
  5. Poor financial management and cash-flow problems.
  6. Poor quality control and lack of safety culture.
  7. Delay in decisions, approvals and payments by the client.
  8. Weak contract management and disputes with subcontractors.
  9. Frequent change of design or scope (variations).

External risks:

  1. Political: change of government or policy, bandh, instability.
  2. Economic: inflation, interest and exchange rate changes, material price rise.
  3. Legal: change in tax, law or regulation; court cases.
  4. Natural: flood, earthquake, landslide, extreme weather.
  5. Social: local opposition, land and compensation conflict.
  6. Market: change in demand, tariff or competition.

Risk reduction as risk response planning

Risk reduction (mitigation) is a response strategy that lowers the probability and/or impact of a threat to an acceptable level. It is planned before the risk occurs, with an owner, budget and time, and is part of the risk response plan, so it is risk response planning.

Example (hydropower tunnel project): risk of poor rock condition causing delay and cost overrun. Reduction actions: extra geological drilling and seismic survey before design, a design with flexible support systems, keeping rock support materials in stock and employing an experienced tunnelling contractor. The probability of surprise and the delay are reduced to an acceptable level, so the response was planned and budgeted in advance.

  • 2079 Baisakh

Why is project risk management necessary? What are the different natures of risk? Discuss the major types of risks that might occur in planning and implementing a hydropower project.

Answer

Why project risk management is necessary

  1. Projects are one-time and uncertain; many things can go wrong.
  2. Hydropower and large projects need big investment, so a loss is very costly.
  3. It prevents or reduces cost and time overrun.
  4. It helps to take better decisions and to use resources properly.
  5. It is required by lenders and investors to approve loan.
  6. It improves safety, quality and the chance of success.
  7. It converts problems into planned actions with reserves.

Different natures of risk

  • Pure (insurable) risk: only loss possible (fire, flood, accident).
  • Speculative (business) risk: gain or loss (market price, demand).
  • Internal / external, known / unknown, negative (threat) / positive (opportunity).

Major risks in planning and implementing a hydropower project

PhaseMajor risks
Planning / feasibilityWrong hydrology data (flow), poor geological investigation, wrong demand and tariff forecast
FinancingDelay in loan, high interest, currency change, PPA (power purchase agreement) delay
Licensing / pre-constructionSurvey and generation licence delay, land acquisition and compensation, environmental (EIA) approval, local opposition
DesignDesign error, change in capacity, wrong tunnel/penstock design
ConstructionPoor rock condition in tunnel, landslide, flood in river works, access road problem, contractor failure, accidents, price rise
Commissioning / operationSediment (silt) damage to turbines, low river flow, transmission line not ready, equipment failure, glacial lake outburst flood (GLOF), earthquake

Other main risks are geological and hydrological risk, construction delay, cost overrun, financial and exchange rate risk, political and regulatory risk, environmental and social risk, market and PPA risk (the Nepal Electricity Authority is the main buyer), and natural hazards. These are managed with detailed investigation, insurance, careful contracts, community engagement and contingency reserve.

  • 2072 Chaitra · 1+4 marks

Define project risk. How can risk be analysed? Explain with an example of a hydropower project.

Answer

Project risk

Risk is an uncertain event or condition which, if it occurs, has a positive or negative effect on the project objectives (scope, time, cost, quality). It is measured by the probability of the event and the size of its impact: Risk = Probability x Impact.

How risk is analysed

Risk analysis is done in two stages after identification.

  1. Qualitative analysis: give each risk a probability and an impact rating and place it on the matrix.
 Impact ->   Low      Medium     High
 Prob.
 High       Medium     High      High
 Medium      Low      Medium     High
 Low         Low       Low      Medium
  1. Quantitative analysis: for high-priority risks calculate EMV = probability x impact, and use sensitivity analysis or simulation for the cost and schedule effect.

Example: a 20 MW run-of-river hydropower project (assumed)

RiskProbabilityImpact (Rs million)EMV (Rs million)Priority
Flood damage to headworks0.215030High
Poor rock in tunnel0.410040High
Delay in land and compensation0.54020Medium
Price rise of cement and steel0.3309Medium
Transmission line delay0.35015Medium

The total EMV is 30 + 40 + 20 + 9 + 15 = Rs 114 million, which is used to set the contingency reserve. Rock condition and flood are first priority, so they get detailed responses (more drilling, insurance and flood-resistant design).

  • 2072 Chaitra · 5 marks

How can risk be managed? Explain how you manage three risks in the hydropower project you identified above.

Answer

Risk is managed by identification, analysis, response planning and monitoring. For a hydropower project, three main risks are managed as follows.

RiskAnalysisResponse (strategy)
1. Geological risk (poor rock, tunnel collapse)High probability, high impactReduce: extra drilling and geophysical survey, use of rock classification (Q-system), flexible support design; contingency reserve; experienced tunnelling contractor
2. Flood and natural hazardLow probability, very high impactTransfer: Contractor's All Risk insurance; Reduce: design for design flood, diversion works; schedule river works in dry season
3. Delay in land, licence and transmission lineMedium probability, high impactAvoid / reduce: early land acquisition and compensation, community consultation, PPA and licence before financial close, parallel construction of transmission line; liquidated damages in contract

Each risk gets a risk owner, a trigger (e.g. unexpected rock fall, river level rise), a budget in the contingency reserve, and is reviewed in monthly meetings.

  • 2073 Shrawan · 5 marks

How can risk be identified and analysed for a rural road project? Explain the procedure.

Answer

Risk identification for a rural road project

  1. Review documents: DPR, survey, drawings, geotechnical report, estimate.
  2. Site visit and checklist: use a checklist from past rural road projects.
  3. Brainstorming and interviews with the local people, user committee, engineers and contractors.
  4. SWOT and assumption analysis.

Typical risks found: landslide and slope failure, monsoon damage and washout, land and right-of-way dispute, local opposition, material shortage and price rise, contractor with low capacity, late budget release, poor quality of earthwork and drainage, and lack of maintenance.

Risk analysis procedure

  1. Prepare a risk register with description, cause and effect.
  2. Qualitative: rate probability and impact (1 to 5) and score = P x I.
 Impact ->   Low      Medium     High
 Prob.
 High       Medium     High      High
 Medium      Low      Medium     High
 Low         Low       Low      Medium
  1. Quantitative: for top risks, calculate EMV, e.g. landslide with P = 0.3 and cost Rs 20 lakh gives EMV = Rs 6 lakh.
  2. Rank the risks and give priority to high-score risks.
  3. Plan responses (retaining wall and drainage, early land agreement, community participation, inspection), assign owners, and monitor.
  • 2075 Asoj · 8 marks

What would be the impact on a project due to unmanaged risk in a project? Write down the risks in a project in different phases of the project life cycle.

Answer

Impact of unmanaged risk

  1. Cost overrun: unexpected loss is paid from the project budget.
  2. Time overrun: delay in completion and handover.
  3. Poor quality: failure to meet the standards, defects and rework.
  4. Scope reduction or project failure: the project may be stopped or abandoned.
  5. Safety problems: accidents, injury and environmental damage.
  6. Disputes, claims and legal cases between parties.
  7. Loss of reputation and confidence of client, donors and lenders.
  8. Financial problems: loan repayment trouble and low return.
  9. Stress and low morale in the team, as the project moves from one crisis to another.

Risks in different phases of the project life cycle

PhaseTypical risks
Conceptual / initiationWrong need analysis, unclear objectives, unrealistic benefits, political pressure
Planning and designIncomplete survey, wrong estimate, design error, funding not arranged, unrealistic schedule
ProcurementWrong contractor selection, bid collusion, late approvals, price change
Implementation / constructionMaterial and labour shortage, quality failure, weather, accidents, scope change, payment delay, disputes
Commissioning and closingDefects, performance not as designed, delay in handover, claims, lack of training
OperationMaintenance problems, low demand, natural hazards
  • 2082 Bhadra · 2+2+8 marks

Define the risk that may occur in a project. Why is there more chance of occurrence of risk in a construction project? Explain in detail how you effectively manage the different types of risk that may occur in a construction project.

Answer

Risk

Risk is an uncertain event or condition which, if it occurs, has a positive or negative effect on the project objectives (scope, time, cost, quality). It is measured by the probability of the event and the size of its impact: Risk = Probability x Impact.

Why construction projects have more chance of risk

  1. Every project is unique, with new site, design and conditions.
  2. Long duration, so more time for change in price, law and weather.
  3. Outdoor work exposed to rain, flood, earthquake and ground conditions that are not fully known.
  4. Many parties (owner, designer, contractor, subcontractors, suppliers) with different interests.
  5. Large amount of money, labour and equipment at one time.
  6. Dependence on approvals, land and utilities.
  7. Frequent design change and variations.
  8. Hazardous activities, so higher accident risk.
  9. Difficult access and logistics in Nepal.
  10. Use of the lowest-bid system and thin profit margins.

Managing the different types of risk

TypeManagement
Technical / designComplete investigation, design review, peer check, standard codes (reduce)
CostRealistic estimate, price adjustment clause, early purchase of material, contingency (reduce, transfer)
ScheduleDetailed CPM schedule, buffers, resource planning, liquidated damages (reduce)
FinancialFunds plan, assured payment, advance guarantee (transfer, reduce)
Contractual / legalClear contract, dispute board, legal review (avoid)
NaturalInsurance (CAR), seasonal planning, flood-resistant design (transfer, reduce)
SafetySafety plan, PPE, training, inspection (reduce)
Political and socialStakeholder consultation, community benefit, early land (avoid, reduce)
QualityQuality plan, testing, supervision (reduce)

Process followed: plan -> identify -> analyse (qualitative and quantitative) -> respond (avoid, transfer, reduce, accept) -> monitor and control. A risk register with owner, trigger and contingency is kept, and the process is repeated through the project.

  • 2080 Baisakh · 2+4 marks

Why is risk analysis important during project planning? What might be the different types of risk in a project?

Answer

Importance of risk analysis in project planning

Risk analysis estimates the probability and effect of risks, so planning can use realistic information.

  1. Gives a realistic cost estimate and schedule with proper contingency.
  2. Ranks the risks, so effort and money go to the most serious ones.
  3. Helps to select suitable response strategies (avoid, transfer, reduce, accept).
  4. Supports decision making on go/no-go, design options and contract type.
  5. Reduces surprises, delays and cost overrun during implementation.
  6. Helps lenders and investors to judge viability.
  7. Improves communication on uncertainty among stakeholders.

Types of risk in a project

CategoryExamples in a project
Technical riskFaulty design, new or unproven technology, poor geotechnical data, change in specifications
Schedule (time) riskLate site handover, late approvals, slow work, monsoon delay, strikes
Cost riskWrong estimate, price rise of cement, steel, fuel, exchange rate change, variations
Financial riskDelay in payment or loan release, interest rate change, cash-flow shortage
Management / organisational riskPoor planning, weak coordination, lack of skilled staff, unclear responsibility
Contractual / legal riskUnclear contract clauses, disputes, claims, land acquisition and court cases
Political and social riskPolicy change, bandh, local opposition, corruption, compensation conflict
Environmental / natural riskFlood, landslide, earthquake, adverse weather, environmental clearance problems
Safety and health riskAccidents, collapse, health hazards at site
Market / commercial riskFall in demand, change in tariff, competition, supplier failure
  • 2074 Asoj · 1+2+2+2 marks

Define project risk. Differentiate between internal and external risks. What are the sources of internal risks in Nepal in the present context? Explain internal risks for the implementation of a hydropower project in Nepal.

Answer

Project risk

Risk is an uncertain event or condition which, if it occurs, has a positive or negative effect on the project objectives (scope, time, cost, quality). It is measured by the probability of the event and the size of its impact: Risk = Probability x Impact.

Internal and external risks

BasisInternal riskExternal risk
SourceInside the project/organisationOutside the project/organisation
ControlCan be controlled by the project teamCannot be controlled, only reduced or transferred
ExamplesWrong estimate, poor design, weak management, skill shortagePolicy change, inflation, flood, earthquake, bandh
ResponseAvoid, mitigateTransfer, accept, contingency

Sources of internal risk in Nepal at present

  1. Inaccurate cost estimate, schedule and unrealistic bid.
  2. Incomplete and poor design, drawings and surveys.
  3. Weak planning, coordination and project management.
  4. Shortage of skilled labour, engineers and equipment.
  5. Poor financial management and cash-flow problems.
  6. Poor quality control and lack of safety culture.
  7. Delay in decisions, approvals and payments by the client.
  8. Weak contract management and disputes with subcontractors.
  9. Frequent change of design or scope (variations).
  10. Weak procurement and contract management in public agencies, and low capacity of local contractors.
  11. Migration of skilled workers abroad, causing labour shortage.

Internal risks in implementing a hydropower project in Nepal

  1. Estimating and design: inadequate hydrology and geology data, which gives wrong capacity, cost and schedule.
  2. Project management: weak management, late decisions and poor coordination between the developer, EPC contractor and consultants.
  3. Financial: difficulty in financial closure, equity shortage, cost overrun, delay in loan release.
  4. Contract: unclear scope, variation claims, disputes with civil, hydromechanical and electromechanical contractors.
  5. Technical and quality: poor construction of tunnel/headworks, delay in equipment supply, sediment-handling design faults.
  6. Resources: shortage of skilled labour and equipment at remote sites.
  7. Safety: accidents in tunnels and river works.
  8. Interface: the transmission line and power house not ready at the same time.
  • 2070 Chaitra · 2+8 marks

Define risk and risk management. Explain the internal risks of any construction project that a Nepalese construction company is facing.

Answer

Risk and risk management

Risk is an uncertain event or condition which, if it occurs, has a positive or negative effect on the project objectives (scope, time, cost, quality). It is measured by the probability of the event and the size of its impact: Risk = Probability x Impact.

Project risk management is the systematic process of planning, identifying, analysing, responding to, and monitoring and controlling risks in a project, so that the chance and effect of negative events are reduced and the chance of positive events is increased.

Internal risks faced by a Nepalese construction company

Internal risks arise inside the company or project and can be controlled by management.

  1. Estimating and bidding risk: very low bids to win the contract (lowest-bid system), wrong quantity or rate analysis, so loss on the work.
  2. Financial risk: cash-flow shortage because of late payment from the client, high bank interest, working capital and bank guarantee limits.
  3. Management and planning risk: poor planning and scheduling, weak site management, lack of professional managers, family-based decisions.
  4. Human resource risk: shortage of skilled workers, engineers and operators due to foreign migration; low productivity; labour disputes.
  5. Equipment and material risk: old equipment, breakdown, shortage of cement and steel, poor purchase planning, high stock cost.
  6. Quality risk: weak quality control, rework, penalties and loss of reputation.
  7. Safety risk: accidents because of low safety practice; injury claims.
  8. Contractual risk: misunderstanding contract terms, claims not made on time, penalty (liquidated damages) for delay, disputes with subcontractors.
  9. Technology risk: low use of modern methods and software.
  10. Ethical and legal risk: tax, VAT and labour act non-compliance, corruption allegations, blacklisting.
  11. Subcontractor and supplier risk: default or delay.

Management of these internal risks

Improve estimate accuracy, keep cash-flow forecasts, train workers and engineers, maintain equipment, set up a quality and safety system, read contracts carefully, keep documentation for claims, and maintain a risk register reviewed monthly.

Questions from Old Question Collection (CE 701) (IOE CE 701 exam papers from 2065 Shrawan to 2082 Bhadra). Answers are written for this site; check them against your class notes.

Chapter titles and hours from the IOE syllabus ↗