Live data from Hacker News

Risk management is not project management

mattrucker.com

21–30 of 84 posts

Re: Risk management is not project management

#21

Where I think this article goes a little wrong is the assumption that a RACI is about risk management. A RACI can tell you who is responsible for running the risk management process, but the R (responsible) and A (accountable), are not meant to move risk and absolve all others. They're just markers for "who is going to get this work done". They are about managing work, not managing the risks that can arise from that…

Good approach, very similar to the model I've used. A slight modification I make:

>A 10 on likelihood is "this is certainly going to happen", a 1 is "it very probably won't, but it could".

If something is guaranteed to happen it's no longer a risk, it's an issue, and then needs to be actively addressed to resolve it, starting by adding it to the Issues List. That effort is in contrast to efforts involved in mitigating the likelihood of a risk happening or its impact. E.g. it would likely justify reallocating resources to resolve the issue where, depending on the score of a particular risk, it might not. Also, in terms of reporting, issues are almost always reported to upper management regularly, whereas risks may not be.

Again, really good approach. I don't see risks managed explicitly enough, and I've been managing projects professionally for over 20 years.

Re: Risk management is not project management

#22
post #7

Earlier quoted context omitted.

We don't want the risk so we'll farm it out to another entity that ultimately has even less skin in the game. It boggles the mind that someone can make such a decision *and* stick with it. You'd think that at some point they'd come back down to earth.

This is because often the perception is that it works. Even the GDPR contains some subtle mistakes. In the case of a breach it is the controller that is responsible for reporting the breach to the DPA of the country where they reside, but it is the processor that usually becomes aware of the breach. So processors that don't report breaches to their customers are giving plausible deniability to the controllers they wo…

> This is because often the perception is that it works.

Yes. But how can this idea persist? I mean one of life's basic rules is: No one care more about you than you. To pretend otherwise is silly. At a company level (read: bebolden to shareholders) its borderline negligent.

Wishful thinking worked in kindergarten. It's not something working adults should be embracing so strongly. Right?

Re: Risk management is not project management

#23
You have to know what you and others are optimizing for.

In big companies, it's rarely the success of the project. Usually it's a combination of keeping your job and growing your career.

Most big companies provide limited upside for success, and the downside risk is higher for the people. Consider:

1. The project is successful. You get a nice little bonus at the end, if anything. Maybe a promotion a year later.

2. The project is a failure and people can point part that you were responsible for. You get nothing, or worse, you're fired.

3. The project is a failure, but people can't point at you as the reponsible party. You keep your job, even get a small raise because you did your part.

Part of this is inevitable in my opinion, but organizations should really ask themselves what behavior they're incentivizing and rewarding, especially in a repeated fashion. If your people swing for the fences and miss -- what happens, and how does that compare to the people who bunt or stay on the bench?

Re: Risk management is not project management

#24
This entire exercise seems wrong, or at best, incomplete.

There's a Japanese saying that I found useful:

"Fix the problem, not the blame."

This "accountability" exercise seems here to be viewed as: 'fix the blame in advance'.

Instead, the focus should be to identify the potential problems and reduce the risk that they will occur or mitigate the consequences.

"Accountability" should only be a tertiary tool to generate action to reduce risk or mitigate consequences.

Re: Risk management is not project management

#25
Wasn't familiar with RACI acronym:

RACI is an acronym derived from the four key responsibilities most typically used: responsible, accountable, consulted, and informed. It is used for clarifying and defining roles and responsibilities in cross-functional or departmental projects and processes.

I wish more people briefly defined acronyms at first usage in a document.

Re: Risk management is not project management

#26

Where I think this article goes a little wrong is the assumption that a RACI is about risk management. A RACI can tell you who is responsible for running the risk management process, but the R (responsible) and A (accountable), are not meant to move risk and absolve all others. They're just markers for "who is going to get this work done". They are about managing work, not managing the risks that can arise from that…

I encountered a similar idea in a university project management course, which turned out to not be a completely waste of time, although I've forgotten most of the ideas. It was filled with useful ideas that I'd never encountered during my 10+ years on HN.

Let's compare the typical startup risk management strategy:

The project owner keeps all risks in their head, no formal tracking or acknowledging of risks. People mention risks and mostly go unheard; if the risk is low probability, it's excused, if a risk is high probability but low impact, it's excused. The project owner can't track too many things, so risks are dismissed rather than adding stress to the project owner who tracks it all in their head. If the project owner is feeling good and engaged, the project owner picks their favorite risk and then has a meeting and pressures people into dealing with it somehow. If the project owner is overwhelmed, just ignore the risks.

Re: Risk management is not project management

#27
I would argue that what the author describes is not risk management. It's a CYA game. Risk management is a part of project management.

Real risk management identifies risk and defines mitigations to bring the risk down to an acceptable level. Passing the buck doesn't address the true risk; it only addresses the risk of who is accountable.

Imagine a scenario where you need a new water heater in your home. One of the risks is that a bad installation is that the water heater overpressurizes and blows up. Saying, "I hired a contractor to install it" doesn't mitigate that risk directly. The appropriate mitigation is installing a pressure-relief valve. Hiring a competent contractor can be a means to this end, but it's not a direct mitigation. If you hire a licensed contractor you may pass off the accountability risk but you aren't addressing the over-pressure risk. The client (and author) in this article are confusing what risks are being addressed.

Re: Risk management is not project management

#28
post #9

"We do not want the risk. The 3rd party must be accountable for this." Repeat ad infinitum. While it may look like that, dialog happens not because client representatives are dumb. It's because they are afraid. They have toxic corporate culture. It's not safe to fail or discuss possibility of failure. The usual, honestly. So they just want to have a chance to blame someone else and survive when everything goes south.…

> It's because they are afraid. Sometimes it's not. Sometimes it's just because they don't have to make themselves accountable for it because there will be no consequences - if it fails, you get to keep your current position and compensation but also if you succeed you also get to keep those without any gain. In these cases, not making yourself accountable is just the path of least resistance, and one could argue it'…

> not making yourself accountable is just the path of least resistance, and one could argue it's the right call

I’ve been frustrated with colleagues who would just do their job to a point of a project critically failing. But in retrospect, I must say they did the right thing.

Taking heat as an employee should be voluntary, and it should be compensated, and it usually isn’t.

When you see an employee just doing their job, when a lot more is needed, you can trace it to a spineless leader who does not lead by example.

Re: Risk management is not project management

#29

Where I think this article goes a little wrong is the assumption that a RACI is about risk management. A RACI can tell you who is responsible for running the risk management process, but the R (responsible) and A (accountable), are not meant to move risk and absolve all others. They're just markers for "who is going to get this work done". They are about managing work, not managing the risks that can arise from that…

Good approach, very similar to the model I've used. A slight modification I make: >A 10 on likelihood is "this is certainly going to happen", a 1 is "it very probably won't, but it could". If something is guaranteed to happen it's no longer a risk, it's an issue, and then needs to be actively addressed to resolve it, starting by adding it to the Issues List. That effort is in contrast to efforts involved in mitigatin…

What about something that will certainly happen, but happens probabalistically? You may not know enough to treat it as an "issue" even though you know "something" of the type will happen eventually.

It's a matter of definitions, but something that is certain to happen being a "risk" seems reasonable.

Re: Risk management is not project management

#30
post #13

Odd side note. I asked chat gpt for feedback on the screenshot of a RACI and added some color on the parties involved and the scope of work. It provided some really good analysis and recommendations.

Mind share your prompt and the output, thanks.
Post reply on HN