Live data from Hacker News

Risk management is not project management

mattrucker.com

41–50 of 84 posts

Re: Risk management is not project management

#41
post #34

Earlier quoted context omitted.

Only if the third party need vouching for. IBM survives in large part because they are a third party you can hire without really putting your own neck out there as the biz folks trust them. At a prior job it was CGI. CGI got a ton of work as when they failed, the lower level people didn't get blamed. Any other vendor would have led to the negative reflection you mentioned.

Depends, my CFO got a lot of flak for choosing to use PwC when it turned out they couldn't deliver. PwC was seen by him to be the safe choice because they were so large and essentially industry standard. He got flak because he didn't do appropriate due diligence. That was his job, so...

and, did it materially change his career advancement, promotion, labor market prospects, etc?

Re: Risk management is not project management

#42
post #41
post #34

Earlier quoted context omitted.

Depends, my CFO got a lot of flak for choosing to use PwC when it turned out they couldn't deliver. PwC was seen by him to be the safe choice because they were so large and essentially industry standard. He got flak because he didn't do appropriate due diligence. That was his job, so...

and, did it materially change his career advancement, promotion, labor market prospects, etc?

Yes

Re: Risk management is not project management

#43

Honestly this feels like so much crap. I refuse to believe any project can be planned more than one "phase" out - that is one technical person can sit down and say "yes I see how all the parts can be done and I could do it given time and nothing else". Ie the next step onto a stone across the pond. Anything beyond that is what I call the zipper delusion - the idea that with enough planning we can move ahead like a zi…

in constant search of homey analogies and metaphors - I would say plans that need to work like a zipper, are doomed to fail but plans that will work like a patchwork quilt, give usable results even from the first patch and are resilient to setbacks, and importantly can be industrialised - same patch fabric stitches can speed things up

Re: Risk management is not project management

#44

You have to know what you and others are optimizing for. In big companies, it's rarely the success of the project. Usually it's a combination of keeping your job and growing your career. Most big companies provide limited upside for success, and the downside risk is higher for the people. Consider: 1. The project is successful. You get a nice little bonus at the end, if anything. Maybe a promotion a year later. 2. Th…

First I would say most organizations aren’t optimizing for anything. They’re accounting constructs.

Second, however clumsily done, this is what equity incentives are supposed to achieve. The better you do, and its impact on the actual value of the company, the more your equity is worth. There are obvious problems in the model, but at least it’s slightly deeper thinking than the typical “you get paid don’t you?” model.

Wall Street, particularly front office revenue production, has very much a “you get paid proportional to the impact of your work” model. Often times when I worked in trading my total compensation could be many times my base salary (which while more than a teacher was less than say Amazon’s base salary). The problem though is the “impact” of one’s work can be manipulated by bias or short term acting, or worse what’s called trader option, where you take outsized risks assuming if it blows up and you get fired you can just work elsewhere, but if it doesn’t you make a lot more. But your firm carries the most risk because while your upside is uncapped your downside is capped - but your firms downside is not.

Re: Risk management is not project management

#46
post #28

Earlier quoted context omitted.

> It's because they are afraid. Sometimes it's not. Sometimes it's just because they don't have to make themselves accountable for it because there will be no consequences - if it fails, you get to keep your current position and compensation but also if you succeed you also get to keep those without any gain. In these cases, not making yourself accountable is just the path of least resistance, and one could argue it'…

> not making yourself accountable is just the path of least resistance, and one could argue it's the right call I’ve been frustrated with colleagues who would just do their job to a point of a project critically failing. But in retrospect, I must say they did the right thing. Taking heat as an employee should be voluntary, and it should be compensated, and it usually isn’t. When you see an employee just doing their j…

> Taking heat as an employee should be voluntary, and it should be compensated, and it usually isn’t.

It must be compensated! At the vast, vast majority of companies, the worker bees' compensation is multiple orders of magnitude lower than leadership's. Why should they shoulder the accountability? When you question these stratospheric executive compensations, one of the retorts is always "Well, they are responsible and accountable so that's why they're paid so much."

Don't feel frustrated with a colleague who doesn't get fired when the project fails. Get frustrated with the executive leader 4 notches up on the totem pole who makes $10M/yr for "being responsible", who gets a bonus when the project fails.

Re: Risk management is not project management

#47
post #16

> the project owner is always, in the end, responsible for the success of a project This is very relevant to large government construction projects in the public-private partnership model (aka Alternative Financing and Procurement). These go best when the project sponsor (the gov’t) thinks clearly about what risks the private partner is best places to manage and transfers those risks to them (e.g. managing lots of co…

[deleted]

Re: Risk management is not project management

#48

Honestly this feels like so much crap. I refuse to believe any project can be planned more than one "phase" out - that is one technical person can sit down and say "yes I see how all the parts can be done and I could do it given time and nothing else". Ie the next step onto a stone across the pond. Anything beyond that is what I call the zipper delusion - the idea that with enough planning we can move ahead like a zi…

[deleted]

Re: Risk management is not project management

#49

Where I think this article goes a little wrong is the assumption that a RACI is about risk management. A RACI can tell you who is responsible for running the risk management process, but the R (responsible) and A (accountable), are not meant to move risk and absolve all others. They're just markers for "who is going to get this work done". They are about managing work, not managing the risks that can arise from that…

would like to know more about risks, any books you could suggest ? thanks.

The basic idea is discussed in the 1991 paper from Barry Boehm, who also developed the spiral model. This is probably a good start, since it’s an easy read and fairly short. Some newer papers tried to research this topic further using empirical data, but n is usually pretty small and data is usually derived from interviews, rather than direct data from projects. I don’t think there are any recent books on software development risks, usually it’s just a sub chapter in software engineering books

Re: Risk management is not project management

#50

Companies will pay millions to offload liability. It can get pathological. I especially hate the scenario where you don't even have root or sudo on your own production servers and have to beg for logs and software installs.

That's going to basically force the company to move slower - it could be its demise. If you've got a chance, listen to Lex's recent interview with Jeff Bezos. They talk about two door/one door decisions and how companies should encourage anyone in a large company to take certain decisions without consulting the higher ups.
Post reply on HN