The Death of Risk Management. Michael Gaydar Chief Systems Engineer, NAVAIR



Similar documents
DRAFT RESEARCH SUPPORT BUILDING AND INFRASTRUCTURE MODERNIZATION RISK MANAGEMENT PLAN. April 2009 SLAC I

Software Risk Management

RISK MANAGEMENT GUIDE FOR DOD ACQUISITION

Earned Value Management Systems Application Guide

RISK MANAGEMENT GUIDE FOR DOD ACQUISITION

Introduction to Risk Management for Software Projects. Peter Kolb. Distributed and Outsourced Software Engineering, ETH Zurich

Risk Workshop Overview. MOX Safety Fuels the Future

Earned Value Management Systems Application Guide

Organization. Project Name. Project Overview Plan Version # Date

Risk Review Process Basics

Review of Muskrat Falls Project Cost and Schedule Management Processes and Controls

The Program Managers Guide to the Integrated Baseline Review Process

Portfolio Management 101:

Achieving True Risk Reduction through Effective Risk Management

ITRM Guideline CPM Date: January 23, 2006 SECTION 4 - PROJECT EXECUTION AND CONTROL PHASE

PROJECT RISK MANAGEMENT

Scheduling Process Maturity Level Self Assessment Questionnaire

Project Zeus. Risk Management Plan

System Development Life Cycle Guide

White Paper. PPP Governance

Project Management Office (PMO)

IndigoBlue Governance Framework

Project Management Issues in the Finance Transformation Arena

AUDIT REPORT REPORT NUMBER Information Technology Professional Services Oracle Software March 25, 2014

Module 1 Diploma of Project Management

Essential Views of the Integrated Program Management Reports. Thomas J. Coonce Glen B. Alleman

Improving the Predictability of the CapEx Portfolio

National IT Project Management Methodology

How To Manage Project Management

ownership We increase return on investment by We deliver reliable results by engaging

Assessing the Appropriate Level of Project, Program, and PMO Structure

Motivations. spm adolfo villafiorita - introduction to software project management

ENTERPRISE RISK MANAGEMENT POLICY

Session 4. System Engineering Management. Session Speaker : Dr. Govind R. Kadambi. M S Ramaiah School of Advanced Studies 1

Written Testimony. Mark Kneidinger. Director, Federal Network Resilience. Office of Cybersecurity and Communications

How PRINCE2 Can Complement PMBOK and Your PMP Jay M. Siegelaub Impact Strategies LLC. Abstract. About PRINCE2

Project Risk Management Handbook: A Scalable Approach

How To Write A Project Management Plan

Following up recommendations/management actions

Introduction to the CMMI Acquisition Module (CMMI-AM)

+ The Killer Question For Every Manager

P3M3 Portfolio Management Self-Assessment

INFORMATION TECHNOLOGY PROJECT REQUESTS

Qualitative analysis: Analyzing the construction schedule Baker Tilly Virchow Krause, LLP

Crosswalk Between Current and New PMP Task Classifications

Information Technology Project Oversight Framework

Off-the-Shelf Software: A Broader Picture By Bryan Chojnowski, Reglera Director of Quality

Appendix E Program Management Plan Template

Part One: Introduction to Partnerships Victoria contract management... 1

CHAPTER 3: MANAGING IMPLEMENTATION PROJECTS

Root Cause Analysis Concepts and Best Practices for IT Problem Managers

Risk Management Framework

Project Management Planning

Supplier Risk Management. Presented By Bill Gibson, DCMA HQ Date: May 2001

ITIL A guide to incident management

UNITED STATES AIR FORCE. Air Force Product Support Enterprise Vision

Strategies for Project Recovery» A P M S O L U T I O N S R E S E A R C H R E P O R T

Project Management Professional (PMP) Examination Content Outline

WHY DO I NEED A PROGRAM MANAGEMENT OFFICE (AND HOW DO I GET ONE)?

GAO DEFENSE DEPARTMENT CYBER EFFORTS. More Detailed Guidance Needed to Ensure Military Services Develop Appropriate Cyberspace Capabilities

OE PROJECT CHARTER Business Process Management System Implementation

Yale University Incident Management Process Guide

Systems Engineering. August 1997

The Role and Development of an Enterprise Architect: A Devil s Advocate Perspective

Purpose: Content: Definition: Benefits: outputs outcomes benefits Business Case dis-benefit Key Responsibilities: Approach: Executive Developed

Appendix V Risk Management Plan Template

Software Project Models

WORKFORCE COMPOSITION CPR. Verification and Validation Summit 2010

SCRAM: A Method for Assessing the Risk of Schedule Compliance

PROJECT MANAGEMENT PLAN Outline VERSION 0.0 STATUS: OUTLINE DATE:

IEEE Software Engineering Risk Management: Measurement-Based Life Cycle Risk Management PSM 2001 Aspen, Colorado

Software Quality Subcontractor Survey Questionnaire INSTRUCTIONS FOR PURCHASE ORDER ATTACHMENT Q-201

Project Management Toolkit Version: 1.0 Last Updated: 23rd November- Formally agreed by the Transformation Programme Sub- Committee

NIE 14.1 INTEROPERABLE SOFTWARE VOICE CLIENT SOLUTION

ENGINEERING COMPETENCIES ENTRY LEVEL ENGINEER. Occupation Specific Technical Requirements

PROCUREMENT MANAGEMENT PLAN <PROJECT NAME>

Pursuing Execution Excellence

Recognizing and Mitigating Risk in Acquisition Programs

Space project management

Risk/Issue Management Plan

Project Management Certificate (IT Professionals)

SOFTWARE RISK MANAGEMENT

Software Risk Management A Practical Guide. February, 2000

Design Principles for Protection Mechanisms. Security Principles. Economy of Mechanism. Least Privilege. Complete Mediation. Economy of Mechanism (2)

Project Start Up. Start-Up Check List. Why a Project Check List? What is a Project Check List? Initial Release 1.0 Date: January 1997

Mitigate Risk for Data Center Network Migration

Project Management Guidelines

Transcription:

The Death of Risk Management Michael Gaydar Chief Systems Engineer, NAVAIR

Self Destruction Risk Identification And Mitigation Is Required On All Programs. However, Poor Implementation And Understanding Of Risk Management Has Resulted In Unacceptable Level Of Risk Assumption. 2

DOD RM Handbook A common misconception, and program office practice, concerning risk management is to identify and track issues (vice risks), and then manage the consequences (vice the root causes). This practice tends to mask true risks, and it serves to track rather than resolve or mitigate risks. 3

Risk Defined DOD Risk Management Guide Risk is a measure of future uncertainties in achieving program performance goals and objectives within defined cost, schedule and performance constraints. RISK IS NOT: Lack of Oversight, Failure to Plan, or Unrealistic Performance Goals 4

Risk Management Risk Management Is Only A Subset Of Project Management Risk Identification Poorly Understood Incorrectly Implemented Risk Mitigation Plans Inadequate Outside Daily Program Management Risk Realization Totally Ignored 5

First Law Of Risk Management Risk Management Programs Require Risky Programs 6

Program Management By The Book Requirements Must Be Achievable And Documented Historically Derived Basis Of Estimate Integrated Master Schedule All Tasks Are Planned And Linked Well Constructed IAW ANSI 748 Critical Path Understood And Managed Fully Integrated Supplier And Government Schedule Dependencies Integrated Data Environment Deliverables Identified In Contractual Language Deliverables Integrated Into Master Schedule Configuration Management Established & Active Timely Problem Resolution Across Contractual Lines Alternate Design Paths For Critical Technologies 7

Risk Avoidance Is The Goal Properly Planned And Executed Programs Inherently Eliminate And Avoid Risk 8

Second Law Of Risk Management Trading Cost-Schedule-Performance Is A Ponzi Scheme 9

DOD Handbook RM Objective The objective of a well-managed risk management program is to provide a repeatable process for balancing cost, schedule, and performance goals within program funding, especially on programs with designs that approach or exceed the state-of-the-art or have tightly constrained or optimistic cost, schedule, and performance goals Successful risk management depends on the knowledge gleaned from assessments of all aspects of the program 10

Categories Of Risk Risk Technical Programmatic Critical Design Elements Depend On Technology That Is Just Not Achievable. Caused By Overreaching Performance Requirements Embedded In KPPs. Resource Estimates (Budget & Schedule) Too Low. Caused By Insufficient BOE Or Optimism. Technical Risk Against KPPs & Thresholds Yields No Trade Space Result: No Resource Increases Will Eliminate Technical Risk. True Technical Risk Will Always Result In A Requirements Disconnect When Realized. True Technical Risk Requires Alternate Design Paths That Deliver Lower, But Acceptable, Levels Of Performance Minimum Acceptable Performance, And Design, Must Be Achievable Within Current State Of Technology. 11

There Must Be Trade Space Congressional Domain Program of Record Contractor & Program Office Domain User Domain CDD Requirements Flexibility Risk Contingency (CAIG) Design Cost Estimate (Proposals) Current EAC Threshold Requirements Threshold Requirements Do Not Support CAIV Margin 12

Third Law Of Risk Management Hope springs eternal until the spring dries up. 13

Ineffective Mitigation Paths Technical Balance Design Against Unproven Technology Pursue Single Design Path Hoping Testing Will Show Compliance Carry Significant (RED) Risk Beyond Design Closure (Roughly PDR) Execution Hope For Optimistic Performance Through Management Challenges Shift Risk To Suppliers In Firm Fixed Price Contracts Fail To Include All Aspect Of Rebaseline In New EAC 14

Effective Risk Mitigation Plan Risk Realization MUST Be Part Of Risk Mitigation Strategy Risk Mitigation Steps Must Address Root Cause Uncertainty Technical: Demonstrate Improved Performance Predictions Or Alternate Design Path Execution: Improve Resource Estimates Technical Performance Measures (TPM) Are Essential To Mitigating Technical Risk Task Identification Is Essential to Mitigating Execution Risk Risk Mitigation Steps Should Not Be A Way To To Buy Time In In The Hope The Risk Will Be Eliminated 15

Fourth Law Of Risk Management You Get What You Pay For First Corollary: You Pay For Nothing-You Get Nothing 16

Risk Mitigation Costs Risk Mitigation Plans Are Unplanned Work Unplanned Work Requires MR To Execute Risk Mitigation Creates It Own Cost & Schedule Risk Unfunded Risk Mitigation Is Unresolved Risk Risk Mitigation Is Is A Pay Me Now Or Or Pay Me Later Decision 17

Summary Risks Are Rooted In Uncertainty Disciplined Use Of PM Tools Is Required To Identify Areas Of Uncertainty (True Risks) Historical Execution And Standard Design Practices Normalize Optimism Money And Time Doesn t Mitigate All Technical Risk-Requirement Relief Only Solution Trade Space Has To Exist Mitigation Plans Must Attack Root Cause Of Risk-Which Is Uncertainty 18

QUESTIONS?