Live data from Hacker News

Risk management is not project management

mattrucker.com

61–70 of 84 posts

Re: Risk management is not project management

#61
post #19

Earlier quoted context omitted.

Sure you can! Consultants/contractors are hired for that all the time.

Point well made, but I think they were trying to correct the usage of Responsibility. Responsible = Who does the work, which, of course you can outsource.

Exactly. This blog post is really about the difference between “Responsible” and “Accountable“ in a RACI. I jokingly define RACI’s R and A as the person who “Really does the work” and the person whose “Ass in on the line” when the project fails.

Re: Risk management is not project management

#62
post #37
post #25

Wasn't familiar with RACI acronym: RACI is an acronym derived from the four key responsibilities most typically used: responsible, accountable, consulted, and informed. It is used for clarifying and defining roles and responsibilities in cross-functional or departmental projects and processes. I wish more people briefly defined acronyms at first usage in a document.

I agree, but it's a hard balance to strike and depends on the writer's target audience. RACI is a pretty common acronym for anyone doing project management professionally. I'd not define REST, HTTP, etc; in an engineering doc.

How hard is it to use ?

Re: Risk management is not project management

#63

You have to know what you and others are optimizing for. In big companies, it's rarely the success of the project. Usually it's a combination of keeping your job and growing your career. Most big companies provide limited upside for success, and the downside risk is higher for the people. Consider: 1. The project is successful. You get a nice little bonus at the end, if anything. Maybe a promotion a year later. 2. Th…

First I would say most organizations aren’t optimizing for anything. They’re accounting constructs. Second, however clumsily done, this is what equity incentives are supposed to achieve. The better you do, and its impact on the actual value of the company, the more your equity is worth. There are obvious problems in the model, but at least it’s slightly deeper thinking than the typical “you get paid don’t you?” model…

I meant what the people are optimizing for. However, even equity has its faults: equity has to vest for it to be worth anything (and later, be exercised for strike + AMT). The expected value of impact could be high, but if they have a higher chance of getting fired and losing their unvested equity, they might not. Many people are risk adverse - for example, would you pay $100k for a 25% chance to win $1 million? Entrepreneurs might say heck yeah, but most employees wouldn't.

I think incentives are part of the solution, but culture is the other part. The organizations views toward risks and failure are going to shape how people place their bets in their career.

Re: Risk management is not project management

#64

Earlier quoted context omitted.

would like to know more about risks, any books you could suggest ? thanks.

The basic idea is discussed in the 1991 paper from Barry Boehm, who also developed the spiral model. This is probably a good start, since it’s an easy read and fairly short. Some newer papers tried to research this topic further using empirical data, but n is usually pretty small and data is usually derived from interviews, rather than direct data from projects. I don’t think there are any recent books on software de…

Interesting, so risks inherently not changing pretty much, we all human after all, cheers.

Re: Risk management is not project management

#65
post #34

Earlier quoted context omitted.

Only if the third party need vouching for. IBM survives in large part because they are a third party you can hire without really putting your own neck out there as the biz folks trust them. At a prior job it was CGI. CGI got a ton of work as when they failed, the lower level people didn't get blamed. Any other vendor would have led to the negative reflection you mentioned.

Depends, my CFO got a lot of flak for choosing to use PwC when it turned out they couldn't deliver. PwC was seen by him to be the safe choice because they were so large and essentially industry standard. He got flak because he didn't do appropriate due diligence. That was his job, so...

If a CFO chooses PwC, 98% of the time they should be fired.

Re: Risk management is not project management

#66
post #25

Wasn't familiar with RACI acronym: RACI is an acronym derived from the four key responsibilities most typically used: responsible, accountable, consulted, and informed. It is used for clarifying and defining roles and responsibilities in cross-functional or departmental projects and processes. I wish more people briefly defined acronyms at first usage in a document.

There are even other forms like RASCI (S for support role)

Re: Risk management is not project management

#67

Earlier quoted context omitted.

> It's because they are afraid. Sometimes it's not. Sometimes it's just because they don't have to make themselves accountable for it because there will be no consequences - if it fails, you get to keep your current position and compensation but also if you succeed you also get to keep those without any gain. In these cases, not making yourself accountable is just the path of least resistance, and one could argue it'…

> if it fails, you get to keep your current position and compensation Sounds driven by fear of loss Human emotions do not have an infinite range unlike our human languages. Economic stability or the loss of is a primary driver of productivity in our society

> Sounds driven by fear of loss

How can it be fear of loss when there's absolutely no risk of loss?

> Economic stability or the loss of is a primary driver of productivity in our society

Precisely the point I was making.

Generally people don't care about the corporations they work for, so the only motivation to be better is the possibility of better outcomes for them as individuals - or in some cases, to avoid losing what they have (best performers in theory have a better chance to survive a layoff). Note that I'm not making any judgement on whether this is the best way of motivating people - only that it's the one we currently have.

If there's no risk of loss and no recompense to win (i.e. the only possible outcome is to stay exactly where you are regardless of how much or how little effort and accountability you put in the project) doing as little as possible and taking no accountability is just inertia - it's not moved by fear.

Re: Risk management is not project management

#68
post #24

This entire exercise seems wrong, or at best, incomplete. There's a Japanese saying that I found useful: "Fix the problem, not the blame." This "accountability" exercise seems here to be viewed as: 'fix the blame in advance'. Instead, the focus should be to identify the potential problems and reduce the risk that they will occur or mitigate the consequences. "Accountability" should only be a tertiary tool to generate…

> There's a Japanese saying that I found useful: "Fix the problem, not the blame."

Never mind that they invented that saying because they didn’t want to be held accountable either.

Re: Risk management is not project management

#69
post #56
post #51

Earlier quoted context omitted.

What if managers asked people to set goals with the explicit expectation of failure? Not just “moonshot” but “set 5 goals and you will be judged to succeed if you hit 3/5” Or “set 5 goals and if you hit at least 80% of all 5, you get credit for making them all” The concept is already known to sales orgs with quotas and OTE.

If you have five different goals and only need to hit three of them, you're incentivized to focus all efforts on the three easiest ones, and ignore the other two entirely. Or if you only need to hit 80% of each, to go for all low-hanging fruit until hitting 80%, then shift focus. Non-cynical colleagues will act in as much good faith as they believe the manager is doing when setting the goals. But Goodhart's law lurks…

>If you have five different goals and only need to hit three of them, you're incentivized to focus all efforts on the three easiest ones, and ignore the other two entirely.

That assumes that the three "easiest" goals have known, straightforward, guaranteed ways of attaining them. Naturally there will be some uncertainty, some extrinsic factors, some good and bad luck that will get in that way of any of the goals, so ignoring two goals entirely all year risks that you catch some bad luck on one of your 3 "easiest" goals and don't end up hitting all of them.

>Or if you only need to hit 80% of each, to go for all low-hanging fruit until hitting 80%, then shift focus.

Does that sound so bad, if it's by design?

Re: Risk management is not project management

#70
post #28

Earlier quoted context omitted.

> It's because they are afraid. Sometimes it's not. Sometimes it's just because they don't have to make themselves accountable for it because there will be no consequences - if it fails, you get to keep your current position and compensation but also if you succeed you also get to keep those without any gain. In these cases, not making yourself accountable is just the path of least resistance, and one could argue it'…

> not making yourself accountable is just the path of least resistance, and one could argue it's the right call I’ve been frustrated with colleagues who would just do their job to a point of a project critically failing. But in retrospect, I must say they did the right thing. Taking heat as an employee should be voluntary, and it should be compensated, and it usually isn’t. When you see an employee just doing their j…

At times, people are very insistent on doing the wrong thing. At a certain point as an employee, you have to shrug your shoulders and do what they ask. It's their company.
Post reply on HN