Live data from Hacker News

Risk management is not project management

mattrucker.com

31–40 of 84 posts

Re: Risk management is not project management

#31
post #9

"We do not want the risk. The 3rd party must be accountable for this." Repeat ad infinitum. While it may look like that, dialog happens not because client representatives are dumb. It's because they are afraid. They have toxic corporate culture. It's not safe to fail or discuss possibility of failure. The usual, honestly. So they just want to have a chance to blame someone else and survive when everything goes south.…

that's ironic.

If you choose a 3rd party partner in the company I work for and that partner fails: it reflects badly on you, do it more than once and it can be pretty detrimental to your future inside the company.

You are responsible for the third parties you vouch for.

FWIW this is not ideology, this actually happened.

Re: Risk management is not project management

#32
post #31
post #9

"We do not want the risk. The 3rd party must be accountable for this." Repeat ad infinitum. While it may look like that, dialog happens not because client representatives are dumb. It's because they are afraid. They have toxic corporate culture. It's not safe to fail or discuss possibility of failure. The usual, honestly. So they just want to have a chance to blame someone else and survive when everything goes south.…

that's ironic. If you choose a 3rd party partner in the company I work for and that partner fails: it reflects badly on you, do it more than once and it can be pretty detrimental to your future inside the company. You are responsible for the third parties you vouch for. FWIW this is not ideology, this actually happened.

Only if the third party need vouching for.

IBM survives in large part because they are a third party you can hire without really putting your own neck out there as the biz folks trust them.

At a prior job it was CGI. CGI got a ton of work as when they failed, the lower level people didn't get blamed. Any other vendor would have led to the negative reflection you mentioned.

Re: Risk management is not project management

#33
P.E.R.T. was designed by smart people for smart people.

1. It colocates responsibility into time-bounded nodes

2. It offers concurrent redundancy to bypass high-risk teams

3. It may hide the global context from participants engaged in adversarial behavior

4. It decomposes into traditional project planning timelines for presentations

DevOPs/Agile is only good if your firm bills by the hour.

The paradox of cost optimizing labor for a fixed cost infrastructure investment often undermines the stated goal of a timely product launch. It is often not a risk mitigation decision, but rather a lack of respect for professional staff,

Most firms that needed the backbone resurrected almost always had a few overworked and underpaid staff that jumped to a better company before the IT debt came due.

You are probably thinking this is only for small firms, but even >$8B market cap firms fall into the same golden goose egg parable.

The mistake technical people make is assuming they could ever fix these political/structural issues with logic.

Good luck, and a wonderful seasons greetings =)

Re: Risk management is not project management

#34
post #31

Earlier quoted context omitted.

that's ironic. If you choose a 3rd party partner in the company I work for and that partner fails: it reflects badly on you, do it more than once and it can be pretty detrimental to your future inside the company. You are responsible for the third parties you vouch for. FWIW this is not ideology, this actually happened.

Only if the third party need vouching for. IBM survives in large part because they are a third party you can hire without really putting your own neck out there as the biz folks trust them. At a prior job it was CGI. CGI got a ton of work as when they failed, the lower level people didn't get blamed. Any other vendor would have led to the negative reflection you mentioned.

Depends, my CFO got a lot of flak for choosing to use PwC when it turned out they couldn't deliver.

PwC was seen by him to be the safe choice because they were so large and essentially industry standard. He got flak because he didn't do appropriate due diligence. That was his job, so...

Re: Risk management is not project management

#36

Earlier quoted context omitted.

You can outsource the Responsibility but you can never outsource the Accountability.

Sure you can! Consultants/contractors are hired for that all the time.

Whoever hired and oversees the consultant is accountable for their work.

Who do people point at when the consultant drops the ball on their responsibility? The person overseeing the consultant. Meaning the person overseeing is ultimately accountable even if they aren’t doing the work.

These nuances are important in project management.

Re: Risk management is not project management

#37
post #25

Wasn't familiar with RACI acronym: RACI is an acronym derived from the four key responsibilities most typically used: responsible, accountable, consulted, and informed. It is used for clarifying and defining roles and responsibilities in cross-functional or departmental projects and processes. I wish more people briefly defined acronyms at first usage in a document.

I agree, but it's a hard balance to strike and depends on the writer's target audience. RACI is a pretty common acronym for anyone doing project management professionally. I'd not define REST, HTTP, etc; in an engineering doc.

Re: Risk management is not project management

#38
I've always seen risk management as essential to project management, not a separate concept. It's a way to manage expectations. The same work and results will get you a very different outcome if you managed risk and expectations from the start.

Re: Risk management is not project management

#39
post #7

Earlier quoted context omitted.

This is because often the perception is that it works. Even the GDPR contains some subtle mistakes. In the case of a breach it is the controller that is responsible for reporting the breach to the DPA of the country where they reside, but it is the processor that usually becomes aware of the breach. So processors that don't report breaches to their customers are giving plausible deniability to the controllers they wo…

> This is because often the perception is that it works. Yes. But how can this idea persist? I mean one of life's basic rules is: No one care more about you than you. To pretend otherwise is silly. At a company level (read: bebolden to shareholders) its borderline negligent. Wishful thinking worked in kindergarten. It's not something working adults should be embracing so strongly. Right?

Well, yes, right, but that doesn't seem to stop anybody. I even see this sort of stuff in the boardrooms of companies that should know better. I don't know what drives it, maybe some sense of reinforcement from getting away with similar stuff in the past?

Re: Risk management is not project management

#40
post #38

I've always seen risk management as essential to project management, not a separate concept. It's a way to manage expectations. The same work and results will get you a very different outcome if you managed risk and expectations from the start.

It is. The article isn’t really talking about actual risk management, as far as I can see.
Post reply on HN