Information Systems Project Management
Chapter 2: Risk
Risk
Risk Assessment
Every project has an element of risk. One of the primary responsibilities of the project manager is to recognize this risk and take steps to manage it. The types of risks are highlighted in the figure on the right.
One of the risks the project team faces is building a system which does not achieve the benefits forecast for the system. The system may not achieve actual reduction in personnel or workload as originally forecast. In some cases, new systems have turned out to be more expensive to operate than previous systems - without savings in other costs to offset that expense.
Unfortunately, all too often information system projects end up costing more and taking more time to develop than originally forecast. Some experts estimate that as many as 50% of all large information systems projects come in late and over budget. That kind of a record does not exactly inspire confidence in information systems teams!
Another risk to projects is that they will not perform the way they were promised. A system might have poor response time, or be missing part of the functionality that was promised. Problems like this often add more headaches to the maintenance of systems. There isn't time to build the system right, but there is time to fix it later.
Finally, systems are sometimes built which are incompatible with the hardware or software of the existing system. Perhaps the software is developed on a test platform, or a new operating system is installed before than system goes on line. Careful planning can help overcome these types of problems.
Sample Risk Factors
The analysis of risk can contain many elements. If an organization wants to consider as many of the risk factors as possible for a project, they might want to begin by choosing from the following list:
Production Factors
Time until the system is ready to install
Length of disruption during the installation period
Length of the learning curve to properly install the system
Required development time
Hardware requirements
Facility requirements
Impact on system quality
Impact on overall system costs
Impact on personnel requirements
Interaction with current systems and packages
Impact on maintenance requirements
Personnel Requirements
Training requirements
Labor skill requirements
Availability of skilled personnel
Level of work force resistance to system
Change in size of labor force
Impact on sex, age, and racial distributions
Impact on communications between groups
Impact on working conditions
Financial Factors
Net present value of investment
Return on investment
Impact on cash flows
Payout period
Time until break-even
Impact on cash requirements
Marketing Factors
Potential market for system
Probable market share
Ability to control distribution
Ability to control quality
Estimated product cycle
Impact on other systems
Administrative Factors
Impact on or from governmental regulations
Need for consulting help
Reaction of top management and stockholders
Impact on corporate image
Elegance of the new system
Managerial capacity to direct and control the new system
These are but a few of the many factors which can contribute to the overall risk of a project. Many of them are outside of the control of the project manager. Fortunately, there is a smaller subset of risk factors that a project manager can look at which will help control major portions of the risk on an information systems project. These three major risk areas are:
Size,
Structure,
and New Technology [4]
These variables can cause a project to cost more than it should, not be completed on time, or not meet objectives. Consultants estimate that as many as 60% of all systems projects fail in one way or another. Government organizations, utilities and major corporations have all had projects which cost millions more than originally planned, time schedules which stretch into years rather than the months promised, and systems which are not used because they do not meet the needs of the clients. Smaller businesses have gone bankrupt because systems cost much more than anticipated.
The structure of a project relates to how well defined the project is. Most accounting system projects are fairly well defined. The design and operation of elements such as the general ledger, accounts payable and accounts receivable are often defined by standard accounting system practices and corporate policies. A marketing intelligence system, on the other hand, may well be very unstructured at the beginning of a project as both the project team and client struggle to understand what needs to be built.
Of the variables listed, the one that creates the most risk to a project is technology. When projects are undertaken using technology with which the project team is unfamiliar, the risk goes up significantly. If the risk comes from the use of new technology, project mangers need to recognize that risk and plan for it. Training of project team members in the new technology, reliance on expert consultants, and planning for the delays inherent in the implementation of new technology can all help reduce the risk to the project.
Using the Project Manager Tool Kit to Overcome Risk
Each project manager has a set of options or a "tool kits" available to help overcome or at least limit the impact of these types of risks. The decision on which options to exercise should be based on an analysis of the risks in the project. Once the risks are known, then the project manager can choose which options will help the project run better.
The first tool kit is a set of options which can be exercised to help get better user cooperation on a project.
User Integration Tools
Selection of a client or user of the system as project manager
Creation of appropriate steering committees
Corporate
Project
Frequent and in depth meetings of steering committees
Selection of users as team members
User managed change control process
User managed training
User managed system installation
User management of key dates
The second tool kit is a set of options which can be used when you need to have an project team which is well motivated and has high skill sets.
Project Team Integration Tools
Selection of a IS manager or experienced IS professional to lead the project
Frequent team meetings
Frequent formal and informal walkthroughs
Regular distribution of meeting minutes
Selection of team members with previous successful work relationships
Participation of team members in setting goals and deadlines
Managed low turnover
The third tool kit is a set of control techniques for the project.
Project Management Control Techniques
Use of Systems Development Lifecycle
Change control disciplines
Regular walkthroughs and milestone presentations
Regular client sign-offs
Use of Gantt charts for timeline control
Use of PERT and CPM charts for prediction and control
Specifications for deliverables
These are all useful techniques, but ones which need to be applied "as needed" in the project. Different types of risk require different responses. Driving the use of the tool kits should be an understanding of the risks involved.
High Structure/Low Technology
The first type of project is a high structure, low technology project. In this type of project, the structure is well defined and not subject to much change during the course of the project. The technology is of a type that the organization has used before.
High Structure/High Technology
In a high structure, high technology project, the structure still remains stable. The technology, on the other hand, be it hardware or software, is likely to change, causing the project to spiral out of control if not managed carefully.
Low Structure/Low Technology
The low structure, low technology project poses a challenge for the client. In this type of project the client does not have a clear idea of what needs to be done. On the other hand, the project is being build on existing, well known hardware and software.
Low Structure/High Technology
The final type of project is probably the worst of all possible types. In this case the definition of what is wanted will change over time as will the technology.
The key to effective project management lies in taking all of these risk factors into account. Use a risk assessment instrument similar to the one used in the case study to help take these factors into account. Analyze the risk factors to see which ones are contributing the most risk, then utilize the tools and techniques at your disposal to minimize your exposure to risk.