Information Systems Project Management

Chapter 2: Risk

Chapter 2

Risk

Risk Assessment

Every project has an element of risk. One of the primary responsibilities of the project manager is to recognize this risk and take steps to manage it. The types of risks are highlighted in the figure on the right.

One of the risks the project team faces is building a system which does not achieve the benefits forecast for the system. The system may not achieve actual reduction in personnel or workload as originally forecast. In some cases, new systems have turned out to be more expensive to operate than previous systems - without savings in other costs to offset that expense.

Unfortunately, all too often information system projects end up costing more and taking more time to develop than originally forecast. Some experts estimate that as many as 50% of all large information systems projects come in late and over budget. That kind of a record does not exactly inspire confidence in information systems teams!

Another risk to projects is that they will not perform the way they were promised. A system might have poor response time, or be missing part of the functionality that was promised. Problems like this often add more headaches to the maintenance of systems. There isn't time to build the system right, but there is time to fix it later.

Finally, systems are sometimes built which are incompatible with the hardware or software of the existing system. Perhaps the software is developed on a test platform, or a new operating system is installed before than system goes on line. Careful planning can help overcome these types of problems.

Sample Risk Factors

The analysis of risk can contain many elements. If an organization wants to consider as many of the risk factors as possible for a project, they might want to begin by choosing from the following list:

Production Factors

Time until the system is ready to install

Length of disruption during the installation period

Length of the learning curve to properly install the system

Required development time

Hardware requirements

Facility requirements

Impact on system quality

Impact on overall system costs

Impact on personnel requirements

Interaction with current systems and packages

Impact on maintenance requirements

Personnel Requirements

Training requirements

Labor skill requirements

Availability of skilled personnel

Level of work force resistance to system

Change in size of labor force

Impact on sex, age, and racial distributions

Impact on communications between groups

Impact on working conditions

Financial Factors

Net present value of investment

Return on investment

Impact on cash flows

Payout period

Time until break-even

Impact on cash requirements

Marketing Factors

Potential market for system

Probable market share

Ability to control distribution

Ability to control quality

Estimated product cycle

Impact on other systems

Administrative Factors

Impact on or from governmental regulations

Need for consulting help

Reaction of top management and stockholders

Impact on corporate image

Elegance of the new system

Managerial capacity to direct and control the new system

These are but a few of the many factors which can contribute to the overall risk of a project. Many of them are outside of the control of the project manager. Fortunately, there is a smaller subset of risk factors that a project manager can look at which will help control major portions of the risk on an information systems project. These three major risk areas are:

Size,

Structure,

and New Technology [4]

These variables can cause a project to cost more than it should, not be completed on time, or not meet objectives. Consultants estimate that as many as 60% of all systems projects fail in one way or another. Government organizations, utilities and major corporations have all had projects which cost millions more than originally planned, time schedules which stretch into years rather than the months promised, and systems which are not used because they do not meet the needs of the clients. Smaller businesses have gone bankrupt because systems cost much more than anticipated.

The structure of a project relates to how well defined the project is. Most accounting system projects are fairly well defined. The design and operation of elements such as the general ledger, accounts payable and accounts receivable are often defined by standard accounting system practices and corporate policies. A marketing intelligence system, on the other hand, may well be very unstructured at the beginning of a project as both the project team and client struggle to understand what needs to be built.

Of the variables listed, the one that creates the most risk to a project is technology. When projects are undertaken using technology with which the project team is unfamiliar, the risk goes up significantly. If the risk comes from the use of new technology, project mangers need to recognize that risk and plan for it. Training of project team members in the new technology, reliance on expert consultants, and planning for the delays inherent in the implementation of new technology can all help reduce the risk to the project.

Using the Project Manager Tool Kit to Overcome Risk

Each project manager has a set of options or a "tool kits" available to help overcome or at least limit the impact of these types of risks. The decision on which options to exercise should be based on an analysis of the risks in the project. Once the risks are known, then the project manager can choose which options will help the project run better.

The first tool kit is a set of options which can be exercised to help get better user cooperation on a project.

User Integration Tools

Selection of a client or user of the system as project manager

Creation of appropriate steering committees

Corporate

Project

Frequent and in depth meetings of steering committees

Selection of users as team members

User managed change control process

User managed training

User managed system installation

User management of key dates

The second tool kit is a set of options which can be used when you need to have an project team which is well motivated and has high skill sets.

Project Team Integration Tools

Selection of a IS manager or experienced IS professional to lead the project

Frequent team meetings

Frequent formal and informal walkthroughs

Regular distribution of meeting minutes

Selection of team members with previous successful work relationships

Participation of team members in setting goals and deadlines

Managed low turnover

The third tool kit is a set of control techniques for the project.

Project Management Control Techniques

Use of Systems Development Lifecycle

Change control disciplines

Regular walkthroughs and milestone presentations

Regular client sign-offs

Use of Gantt charts for timeline control

Use of PERT and CPM charts for prediction and control

Specifications for deliverables

These are all useful techniques, but ones which need to be applied "as needed" in the project. Different types of risk require different responses. Driving the use of the tool kits should be an understanding of the risks involved.

High Structure/Low Technology

The first type of project is a high structure, low technology project. In this type of project, the structure is well defined and not subject to much change during the course of the project. The technology is of a type that the organization has used before.

High Structure/High Technology

In a high structure, high technology project, the structure still remains stable. The technology, on the other hand, be it hardware or software, is likely to change, causing the project to spiral out of control if not managed carefully.

Low Structure/Low Technology

The low structure, low technology project poses a challenge for the client. In this type of project the client does not have a clear idea of what needs to be done. On the other hand, the project is being build on existing, well known hardware and software.

Low Structure/High Technology

The final type of project is probably the worst of all possible types. In this case the definition of what is wanted will change over time as will the technology.

The key to effective project management lies in taking all of these risk factors into account. Use a risk assessment instrument similar to the one used in the case study to help take these factors into account. Analyze the risk factors to see which ones are contributing the most risk, then utilize the tools and techniques at your disposal to minimize your exposure to risk.