Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Tuesday, June 5, 2012

A New Approach to Qualitative Risk Management


This week’s Sidewise Thinking post is hardcore project management, for those of you who are interested in that sort of thing. The chart and approach to qualitative risk analysis comes from my recent AMACOM self-study sourcebook, Project Risk and Cost Analysis, but the words are original to this blog piece.

Qualitative risk analysis as expressed in the PMBOK® Guide has always given me a headache. The definition is confusing and badly written. That’s not just my opinion, it’s the common experience of lots of people taking project management seminars. (Certainly it's true of my seminars, but I’ve seen many other trainers struggle with this as well.) The problem isn’t with the individual tools. They are easy enough to understand and apply, and the utility is reasonably obvious. But when you look at the similarities and difference between qualitative and quantitative risk analysis using the official PMBOK® (11.3, 11.4) definitions, some problems arise.

·      Qualitative risk analysis is the process of prioritizing risks for further analysis by assessing and combining their probability of occurrence and impact.
·      Quantitative risk analysis is the process of numerically analyzing the effect of identified risks on overall project objectives.

When people first encounter this, the response is a great big "Huh?" I don't really blame them. Here's why.

To see the problem in PMBOK, start with the most obvious difference between the two types: quantitative risk analysis uses numbers and qualitative risk analysis uses "prioritization." In practice, these amount to the very same thing.

How do you value a risk? According to the book, you multiply its probability of occurrence by the impact should it occur, expressed by the formula R = P x I. For example, a ten percent risk of losing a thousand dollars turns into 0.1 x $1,000, or $100. If the cost of dealing with that risk is less than $100, it’s clearly a good investment. (It’s always worth noting that the reverse isn’t necessarily true. Spending more than $100 may well be a good idea, but you may have to prove it.) That's the quantitative way.

In the qualitative approach, according to PMBOK, you might say the probability is LOW and the impact is, say, MEDIUM (depends on the size of the project). You look on a grid to see where the terms intersect (usually LOW). But that's the same thing as saying LOW x MEDIUM = LOW, or P x I again.

In other words, the “numerical analysis of effect” and “combined probability and impact” are, for all practical purposes, synonyms — the very definition of risk says so. That creates a lot of blurring between the two processes, especially in terms of their utility. No matter which technique you use, you end up with a priority ranking of your project’s risks. (You also get analytical data about those risks.) Then you move on to risk response planning.

Prioritizing risks gives you only a two-dimensional sort: higher or lower. That’s quantitative risk analysis — whether you use actual dollars and percents, or whether you use a scale of high, medium, and low. You rank the risks into a numerical hierarchy. And that's it.

Prioritizing risks isn't nearly all you need to be doing. In this post, I want to give you a new way to think the two kinds of risk analysis.

You need to organize your list of identified risks in three dimensions, based on the initial choices you must make. Some risks require more rapid response than others, severity notwithstanding. Some risks affect the project but aren’t yours: they may belong to the customer, your boss, or other departments in the organization. If you’re running an IT project and you identify legal risks, you probably should route those risks to the general counsel rather than deal with them yourself. Some risks have solutions — and others have no solution at all.


Using the accompanying chart, let’s look at those choices.

IMPACT: The first gateway is to examine a risk’s impact. Forget probability: if the impact is low enough, you’re done with the risk. If the cost of the risk if $50 and the project is $5 billion, it’s irrelevant whether it happens or not. Granted, first impressions can be deceiving and the impact of a given risk can change over the lifespan of the project, so you don’t want to throw this list away.

PROBABILITY: Only then should you think about the probability of occurrence. If you are lucky enough to have real numbers, good for you. More often, you’ve got a vague idea (it’s pretty likely to happen, or maybe it’s very unlikely) or you don’t have any idea at all about the probability.

Here’s where you deal with the R = P x I formula, whether you’re using 0.1 x $1000 or a high, medium, and low scale from a table (Low x Medium = Low). And yes, when determining impact, you have to extend your vision from the impact on the work package to the impact on the project as a whole, and from there to the impact on outside people and organizations.

At the end, you put more risks on the parking lot. Perhaps the impact is serious enough to be noticed, but the probability is ridiculously remote. You make sure that the risks that get further action are the ones with the highest net value.

According to PMBOK, you're done — but you aren't.

URGENCY: Risk responses follow the Godzilla Principle: baby problems are easier to deal with than full-grown problems. The available set of responses to a given risk tends to deteriorate over time. Even if some risks have higher value, you need to move urgent risks to the front of the queue. It’s less important whether the risk event is coming up soon; the key question is when your solutions expire. So we’ve already violated the priority order we established in the previous step — another tip-off that prioritizing risks by probability and impact isn’t nearly enough to do the job.

OWNERSHIP: If there’s no reason for a risk to jump to the head of the line, we go back to the prioritized list of risks, but with another question: do these risks fall under the jurisdiction of the project manager or team? As we noted, legal risks usually belong to the legal department, rather than, say, IT. Other risks may fall generally into our project, but if the impact is great enough, higher levels of the chain of command usually get the final say-so.

Transferring risk, in other words, often doesn’t wait until risk response planning — when we need to pass the buck, we pass it early in the process. Of course, we’re often responsible for providing information and options to the people who own the decision, and sometimes responsible for implementing the solutions they devise, but the key question of ownership has already been settled.

ACTIONABLE: Our remaining pile of risks shrinks with each step, but before we start on the process of planning our risk responses, there’s still one more sort that needs to be done. Do these risks have answers? In other words, can we find a potential proportionate and cost-effective response to the risk that doesn’t create serious negative consequences as a side effect?

If the answer is yes, we have our tentative risk solution. We accept the risk and move forward to risk response planning.

ACCEPTABLE: If the answer is no, we have a decision to make. We can decide to accept the risk
Maybe we add something to the contingency allowance for dollars or time. Maybe we come up with a recovery plan. But either way, we move forward.

But if the risk is too serious, moving forward may be a very bad idea indeed. We have to re-think the project. Maybe we modify it. Maybe we cancel it. Either way, we’re no longer going ahead with the original vision.

* * *

No matter what approach we use, we plan risk responses for some risks, but not all of them. In the PMBOK model, we plan risk responses based on the priority of the risk. As you’ve seen, however, that’s not enough. Think of qualitative risk analysis as the overall process of sorting risks not merely by P x I, but by the nature of the initial actions you should take.

     Is it SERIOUS? If not, accept it.

     Is it LIKELY? If not, accept it.

     Is it URGENT? If it is, act on it now.

     Is it MINE? If not, transfer it.

     Is it ACTIONABLE? If so, act on it.

     If not, is it ACCEPTABLE? If not, rethink the project.

Tuesday, April 3, 2012

Some Notes About Decision Making

Some of this material appears in my chapter in Applied Space Systems Engineering: Space Technology Series, which I wrote a few years ago. While originally aimed at making mission-critical decision in a complex engineering environment, some of the ideas are more generally applicable.



“A decision,” wrote author Fletcher Knebel, “is what a man makes when he can’t find anybody to serve on a committee.”

Committees and teamwork are often an essential part of decision-making, but even in that framework, each of us must sooner or later take our stand, knowing full well the range of potential consequences. In an organization, a decision-making process must often be open and auditable. We must know not only the decision we make, but also the process that led us to that decision.

Decisions often require tradeoffs. A perfect solution may not exist. Each potential choice may have a downside, or may be fraught with risk. In some ways, making the least bad choice out of a set of poor alternatives takes greater skill and courage than making a conventionally “good” decision. Napoleon Bonaparte observed, “Nothing is more difficult, and therefore more precious, than being able to decide.”

The outcome of a decision, whether positive or negative, is not in itself proof of the decision’s quality, especially where probability is concerned. The odds may be dramatically in favor of a positive outcome, yet the dice may come up boxcars. Equally, if someone makes a stupid decision but gets lucky, the decision is no less stupid in spite of a good outcome. A good decision process improves our odds and results in the desired outcome the majority of the time.

Decision-making is tightly woven into the risk management process, but one does not follow automatically from another. An engineering evaluation might tell us that there is a 42% probability of an event happening, and that the consequence involves the loss of $20 million and three lives. What the evaluation does not tell us is whether the risk is worth running. Values—organizational values, mission-related values, ethical values—address the consideration of worth.

There are two types of complexity in decision-making. The first, and most obvious, is the technical complexity of the issue and the tradeoffs that may be required. The second, though not always openly addressed, is the organizational complexity: the number of people involved, the number of departments or workgroups that must be consulted, the existing relationships that shape communication among people and groups, the organizational culture, and the pressure of the political process.

Decisions also vary in their importance. Importance can be measured in terms of the consequences of the decision and the constraints imposed on the decision process.

There are two slogans about decision-making: “Don’t just stand there, do something!” and its reverse, “Don’t just do something, stand there!” Both can be worthwhile pieces of advice; the trick is deciding which philosophy applies to the decision at hand. The first question is whether an actual problem exists, and, if so, the nature of that problem. The second is whether an action should be taken, and if so, the nature of that action.

At different times in the decision-making process, consider the opportunities as well as the negative consequences that can result both from the decision to act and from the decision to wait. If the consequences of a missed opportunity are greater, then the appropriate bias is in the direction of action. If an inappropriate decision could cause greater harm, the bias should fall in the direction of delay: gather more information and reassess.

Threats and opportunities both require proactive management, but opportunities even more so. Good luck and bad luck operate differently. If a person, say, loses $100, it’s gone, and all the consequences of that loss flow automatically. If, on the other hand, there’s a $100 bill somewhere in the area, it’s possible to miss it, there is no requirement to pick it up, and no obligation to spend it wisely. Exploiting opportunity requires observation, initiative, and wisdom.

A good process does not necessarily result in a good consequence. Predicting the future is never an exact science, especially when probabilities are involved. Evaluate the decision process separately from the decision outcome. Hindsight is a useful tool, though teams must remember that what seems so clear in light of actual events looked different to the decision-makers.

Tuesday, February 28, 2012

Project: Impossible — Lindbergh Wins the Orteig Prize


My 26th book will be Project: Impossible, an exploration of how people achieved goals any reasonable person would have thought impossible. Here’s a summary of some of the cases covered in the book.

Charles Lindbergh's Flight

What’s impossible about Lindbergh’s famous flight is not that he made it from New York to Paris. That was going to happen within a few weeks anyway. No, what’s impossible is that the underfunded and unknown Lindbergh jumped ahead of highly qualified and lavishly funded competitors.

The Orteig Prize

Crossing the Atlantic by air wasn’t new. The Curtiss NC-4 flying boat did it in 19 days back in 1919, hopping in 50-mile jumps between pre-positioned ships. The following month, British aviators Alcock and Brown flew nonstop from Newfoundland to Ireland. A month after that, the British airship R-34, carrying a crew of 31, made the first lighter-than-air round-trip crossing.

In 1919, French-born New York hotelier Raymond Orteig decided to offer a $25,000 prize the first aviators to fly non-stop from New York to Paris, in either direction.

The first serious attempt at the prize came in 1926, when Frenchman René Fonck crashed on takeoff, killing two. Admiral Richard E. Byrd, famous polar explorer, announced his entry in late 1926. Clarence Chamberlin, practicing for the attempt, set a world endurance record by circling New York City for over 50 hours. From the other side of the Atlantic, Nungesser and Coli readied their Levasseur biplane L'Oiseau Blanc (The White Bird).

By early May 1927, the Chamberlain and Byrd groups were ensconced at adjoining airfields on Long Island, and Nungesser and Coli were getting ready in Paris.

Anyone who thought they’d come in and beat that field was surely a fool.



The Flying Fool

Charles Lindbergh had many nicknames, but the one he despised was given him by the New York Sun: “The Flying Fool.”

He responded, “I take no foolish risks and study out everything I do in the air. I don’t think I am a flying fool.” It is, however, not difficult to understand how the Sun — and others — could have reached that conclusion. Most entries were multi-engine aircraft; Lindbergh flew a single-engine. All the other entrants planned for a crew of at least two to handle the 30+ hour flight. Lindbergh was the only solo entry. Finally, all the other entrants did extensive test flying. Total test flying time for the Spirit of St. Louis amounted to a paltry five and a half hours!

Then there was his safety record. He had only been a pilot for four years, and was famous for only one thing — the most emergency parachute bailouts. In 1924, he collided in mid-air with another Army flying cadet. In his first job post-graduation, he bailed out a second time while serving as test pilot. As an airmail pilot on the St. Louis-Chicago route in 1926, Lindbergh bailed out of not one but two DH-4s when he became lost in storms and ran out of fuel.



The Spirit of Charles Lindbergh

It took ego to enter the race. “Why shouldn’t I fly from New York to Paris?” he wrote in his autobiography. He raised funds from the St. Louis Chamber of Commerce, but had trouble finding a plane. Finally, a small San Diego company, Ryan, offered to build one for him. The Ryan NYP (New York to Paris) had no radio, no parachute, no gas gauges, and no navigation lights. Lindbergh even replaced the leather pilot’s seat with a wicker chair. It was built in record time, only two months.

Two days before Lindbergh was scheduled to leave San Diego for New York, Nungesser and Coli took off from Paris. All the other competitors stopped and waited to see if the Frenchmen would succeed — except for Lindbergh, who set off immediately for New York, setting a speed record en route.

When he reached New York, he learned for the first time that L'Oiseau Blanc had vanished. Charles Lindbergh was back in the race.



The Spirit of Long Island

A lawsuit delayed the Chamberlin group, and Byrd’s America crashed during a practice flight. All the teams were hampered by bad weather, which began to clear on May 19, a few days after Lindbergh finally arrived in New York. Unfortunately, paved runways weren’t yet common in aviation. The field was muddy — too muddy to allow a heavily-laden plane to take off.

But on the morning of May 20, 1927, at 7:52 AM, Charles Lindbergh loaded his plane with four sandwiches, two canteens of water, and 451 gallons of gasoline, and took off. The Spirit of St. Louis barely managed to clear the telephone wires at the end of the runway.

Thirty-three and a half hours later, Charles Lindbergh and the Spirit of St. Louis landed safely in Paris.



Managing the Impossible Project: The Role of Risk

The difference between a possible project and an impossible project is the constraints, the factors that restrict the options available to the leader and team. If the constraints are different, the options are different.

All the teams competing for the Orteig Prize consisted of talented, experienced aviators, engineers, and designers. What distinguishes Lindbergh is the nature and level of risk he was willing to assume.

The technical equation for risk is R = P x I; that is, the price of a risk is the probability of it happening times the impact if it does happen. If there’s a ten percent chance of a $1,000 negative event, the value of the risk is $100, meaning that if you can get rid of the risk for less than $100, it’s a good investment.

What if it costs more than $100 to get rid of the risk? Well, it may still be a good investment depending on other factors. What’s the value of getting into the history books? What’s the value of being acclaimed the world’s best pilot? The price of a risk and the value of a risk aren't necessarily the same thing.

Accepting an elevated level of risk doesn’t automatically make you a “flying fool.” Sometimes it’s exactly what allows you and your team to achieve the impossible.

Tuesday, April 12, 2011

Project Disasters and Career Management



“My project’s going down the tubes. How do I keep them from making me the scapegoat?”
- RN, Washington, DC

There’s an old joke about the stages in a project life cycle. First comes enthusiasm, then disillusionment, followed quickly by panic. Then comes the search for the guilty, resulting in punishment for the innocent, praise for non-participants, and when everyone sees what a disaster it’s been comes the final stage: figuring out what we should have been doing in the first place.

By the time the project’s in trouble, it’s usually too late to do much about it. That’s why project managers know the real secret is to keep your project out of trouble in the first place. It doesn’t matter whether the problems are actually your fault; it matters whether you could possibly have prevented it, fixed it, or managed it. That’s called risk management, a forward-looking approach to project uncertainties. What could go wrong? Why could it go wrong? And what can you do to prevent the problem or deal with it if it occurs?

A risk management plan can be a huge, formal document or it can be comparatively casual, but either way, you need one. Start with risk identification, a list of potential issues. You can brainstorm with your team, you can ask people who’ve done similar projects, and you can review the documentation (requirements, contracts, statements of work). Prioritize the risks by how serious they are, and take some time to dig into the bigger ones.

There are basically five things you can do about a risk, and your job is to pick the best choice. For example, if you’re the owner or captain of RMS Titanic, and you know there are icebergs in the North Atlantic, you can do the following:


  1. Avoid the risk. Change the course far enough to the south, and there are no icebergs. Of course, the trip will take longer.
  2. Transfer the risk. Buy insurance so that someone else will pick up the bill in the event of sinking.
  3. Mitigate the risk. Mitigation reduces a risk without getting rid of it altogether. For example, the British inquiry into the sinking concluded that the Titanic was going too fast. It might have hit an iceberg anyway, but a slower collision might have reduced the damage. 
  4. Have a contingency plan. More lifeboats (the Titanic only had enough for about a third of its passengers and crew) wouldn’t have prevented the sinking, but would have reduced loss of life.
  5. Accept the risk. Some risks you just have to deal with. If you’ve done everything that seems practical and appropriate, risk isn’t exactly zero. The remaining risk is something you simply accept. Save the rich and leave the poor in steerage.


Risk management is something you do in advance. Once the Titanic hits the iceberg, the game changes from risk management to problem solving. There, unfortunately, the options tend to be dramatically reduced.

What if the project appears to be impossible? People say “nothing’s impossible,” but that’s if you have unlimited time, unlimited resources, and really flexible standards. Are the constraints on the project (time, cost, expected performance) too tight? Is that because of a management decision, or are the constraints imposed by external circumstances? Management decisions may change, but if the money isn’t there or the deadline is unstoppable, management may have no more power than you do.

If a project is impossible as contemplated, that doesn’t mean it’s impossible period. Maybe you can do something different, or do it in a different way. Look for flexibility and opportunity wherever it may be found. If you can’t do everything they’re asking for, perhaps there’s a “good enough” level that meets the objective.

In the aftermath of a big project disaster, there may be some kind of investigation, and if you’re in charge, it’s perfectly reasonable that people will look at you. That doesn’t automatically mean that scapegoating is taking place. Yes, there’s usually blame to go around, and it may be appropriate and fair for you to own a piece of it. Sometimes it’s good strategy to accept your share of any blame early. And, to be perfectly fair, if you’re in charge of the project, you normally deserve at least some share of both credit and blame.

When scapegoating actually occurs, it’s normally an attempt to deflect responsibility from someone higher in the management food chain onto a more vulnerable target: you, for example. And again, you normally have ample warning if you’re paying attention. That person’s goal, remember, isn’t to scapegoat you, it’s to avoid getting himself or herself in hot water. If you can keep that person out of trouble without getting yourself hurt, that may be a win/win. (Don’t yield to the temptation to deflect the trouble onto someone still lower on the food chain, unless that’s the person who’s actually responsible. It’s not only immoral, but other people will notice and your reputation will suffer.)

If everything else fails, advance notice gives you one more opportunity. There’s an old management joke about an outgoing project manager who had some words of wisdom for the incoming one. “I’ve left you three envelopes in my desk drawer, and they have the answers to the first three crises you hit,” the outgoing PM said.

The answer to the first problem was “Blame your predecessor.” To the second, it was “Reorganize the team.” And to the third, it was “Prepare three envelopes.”

Sometimes you have to know how to get while the getting is still good.

Tuesday, March 22, 2011

The Square of Risk

In researching a chapter on risk triage for my book Creative Project Management, I came across a concept known as the PIVOT score. The elements of PIVOT are:

  • Probability — the likelihood a particular risk event will happen
  • Impact — the consequence of the risk event if it happens
  • Vulnerability — the relationship of the threat to core mission, values, and business objectives
  • Outrage — the expectation (E) of how things should be minus the degree of satisfaction (S) with the way things are.
  • Tolerance — the degree of enthusiasm or anger in response to the risk event impact if it happens.


Probability (P), impact (I), vulnerability (V), expectation (E), and satisfaction (S) each get a rating of between 0 and 3. The formula for outrage (O) is:

O = E – S

And the formula for tolerance (T) is:

T = (P x (I + V))O


Outrage, as you can see, is hyperbolic. It has a disproportionate impact of outrage on the final PIVOT score. Let’s imagine the following:

An event is moderately unlikely (P = 1), has a very high impact (I = 3), the event relates to our core business objectives (V = 3), but it’s unlikely to get much publicity because people aren’t too surprised when it happens, so E – S is only 1. The PIVOT score is  (1 x (3 + 3)1, or 6.

Now imagine that the impact is actually low, but it’s the sort of thing that will be smeared all over the headlines and every commentator will talk about it (O = 3). The PIVOT score is  (1 x (1+3))3, or 64! Even though the actual impact in the first instance is three times that of the second case, the PIVOT score of the less serious impact is more than ten times as high as that of the more serious case.

The impact of outrage on risk decisions tends to be disproportionate, especially when the outrage itself is the result of misinformation. Low impact risks take on catastrophic urgency and objectively more serious risks barely ripple the waters.

The confirmed death toll in Japan as I write is approaching 10,000, with the likely death toll predicted to top 18,000. Serious by any measure, but not outrageous because — hey, it was a huge tsunami and earthquake. Do you really expect all the safety procedures to be sufficient? Low outrage means not only less obsessive coverage, but also less pressure to improve safety.

The latest IAEA report I can find (March 17) lists a total of 44 injuries and no deaths. The UK Telegraph reports five workers dead, but I can’t confirm that, or whether they are part of or in addition to the 44. The level of relative outrage — expectation minus satisfaction — is off the wall.

Using outrage as the square (or higher power) of risk dramatically distorts decision-making. Do 9,000+ real deaths truly mean less than some uncounted but low number of potential deaths? In risk management practice, it often does. 

Where the outrage is, so goes the money and the effort. This is not always in our best interest.



From http://xkcd.com/radiation/.

Tuesday, March 15, 2011

Fukushima Number One

As reported in my article "Homer Simpson: Man of the Atom" in Trap Door magazine, I once got to run a nuclear reactor — admittedly, a low-power one used only for training students. This hardly makes me an authority on nuclear power, but I do know something about risk management.

Like many of you, I'm following the evolving Fukushima Dai-ichi Nuclear Power Station story with great interest. I'm a pro-nuclear safety conscious environmentalist, if that makes any sense. I think a lot of anti-nuclear sentiment is rooted in emotion rather than analysis, and contains the same anti-science bias that I object to so strongly when practiced by the right wing.

That doesn't make the case for nuclear power a slam dunk by any means. The downsides are obvious and substantial, and the tendency to rely on nuclear power generation to supply plutonium for other purposes has led to what seem to me to be false choices. I'm following with interest the discussion of thorium reactors, and I think the investment we're making in fusion is ridiculously low. That doesn't mean I don't like wind and solar as well. But all forms of power impose risks and costs.

The question in risk management isn't whether a proposed solution has drawbacks (technically known as secondary risks). Most proposed solutions, regardless of the problem under discussion, tend to have secondary risks and consequences.

The three questions about secondary risk that matter are:

  1. How acceptable is the secondary risk? The impact and likelihood of secondary risks can vary greatly. Some secondary risks are no big deal. We accept them and move on. Others are far more serious. A secondary risk can indeed turn out to be much greater than the primary risk would have been.
  2. How manageable is the secondary risk? A secondary risk, like a primary one, may be quite terrible if you don't do anything about it. The key word, of course, is "if." What can be done to manage or reduce the secondary risk? 
  3. How does the secondary risk compare to other options? As I've argued elsewhere, the management difference between "bad" and "worse" is often more important than the difference between good and bad. If the secondary risk of this solution is high, and if you can't do anything meaningful to reduce it, you still have to compare it to your other options, whatever they are.
In the case of nuclear power, the unmitigated secondary risk is unacceptably high. But all that does is demonstrate that the risk needs to be mitigated — reduced to some acceptable level. Ideally, that level is zero, but that may not be possible, and it may not be cost-effective to reduce it beyond a certain point. The leftover risk, whatever it is, is known as residual risk. Residual risk is what we need to worry about. Like with secondary risk, the three questions of acceptability, manageability, and comparison help us judge the importance of the residual risk.

We make one set of risk decisions at the outset of the project. We decide which projects we want to do; we decide what overall direction and strategy we will follow; and we decide what resources to supply. All the decision are informed by how people perceive the risk choices.

As the project evolves, the risk profile changes. Some things we worry about turn out to be non-issues, and other times we are blindsided with nasty surprises. Our initial risk decisions are seldom completely on target, so they must evolve over time.

When disaster strikes, suspicion automatically and naturally falls on the risk planning process. Were project owners and leaders prudent? Armed with the howitzer of 20-20 hindsight, the fact of what did happen carries a presumption of incompetent planning for those who failed to anticipate it. Sometimes it's a fair judgment. Other times not so much.

I'm still working out what I think about the Fukushima case, but some initial indications strike me as positive when it comes to evaluating the quality of the risk planning. The basic water-cooled design of Fukushima made a Chernobyl outcome impossible. The partial meltdown didn't rupture the containment vessel, and although the cleanup will be messy and expensive, it's not likely to spread outside the immediate area.

The effects of radiation may not be known for some time, but even those have to be put into perspective. Non-nuclear power plants, however, cost lives too, even though you don't hear about these disasters as often. A quick Google search turned up the following:

  • September 2010: Burnsville, Minnesota, explosion, no deaths.
  • February 2010: Connecticut, 5 dead
  • February 2009: Milwaukee, 6 burned
  • June 2009: Mississauga, Ontario

And, of course, several thousand people a year die mining coal.

Tuesday, March 8, 2011

Schrödinger's Cat Walked Into a Bar — And Didn't

The famous story of the boxed cat who is simultaneously dead and alive was first proposed as a thought experiment by Austrian physicist Erwin Schrödinger in 1935. The cat came to quasi-life as part of an argument between Schrödinger and Albert Einstein concerning elements of the Copenhagen interpretation of quantum mechanics.

No cats, of course, were actually injured in the making of this theory.

In his 1935 article, Schrödinger wrote:

"One can even set up quite ridiculous cases. A cat is penned up in a steel chamber, along with the following device (which must be secured against direct interference by the cat): in a Geiger counter, there is a tiny bit of radioactive substance, so small that perhaps in the course of the hour, one of the atoms decays, but also, with equal probability, perhaps none; if it happens, the counter tube discharges, and through a relay releases a hammer that shatters a small flask of hydrocyanic acid. If one has left this entire system to itself for an hour, one would say that the cat still lives if meanwhile no atom has decayed. The psi-function of the entire system would express this by having in it the living and dead cat (pardon the expression) mixed or smeared out in equal parts."

“Ridiculous” is the tip-off. Schrödinger didn’t want us to take the cat — or the argument — seriously. But if you move from the realm of quantum mechanics to the realm of our macro reality, Schrödinger's Cat is far from ridiculous: it’s our everyday experience.

Imagine a call comes in from Cat Rescue HQ. That Schrödinger boy is at it again, locking yet another innocent kitty inside that infernal device. As you load up the van, what do you bring? Well, that depends on the state of the cat. So you bring some food and medicine, or a cat carrier — but just in case, you need to pack a pet-size body bag and some disposable gloves.

Operationally, you treat the cat as alive and dead up until the moment the sad (or happy) truth is revealed.

That’s risk management. You have to plan and prepare for a range of outcomes, treating each as in some sense real until the state collapses and time’s final verdict is rendered. It’s seldom wise to believe in a single deterministic future.

Tuesday, March 1, 2011

Four Dimensions of Risk

As a science fiction reader and alternate history writer, I’ve always lived in the future to some extent. From our time-bound perspective, the future is a wave front of uncertainty. Many things are possible, but ultimately only some things will happen.

Today, we have to make decisions about the future, and those decisions necessarily have to be made under conditions uncertainty. That’s the domain of risk, the place where philosophy and statistics meet. Yesterday, I sent in the manuscript for my 24th book, Project Risk and Cost Analysis, for AMACOM’s self-study sourcebook line. It’s been a fascinating project.

Risk is future tense, as opposed to problem, which is present tense. Risks are events that have not yet happened. The events can be good for us, or bad for us. They can have great impact, or little impact. They are more likely or less likely.

The risk environment changes over time. For example, there’s a lot of noise on the issue of climate change. Opponents argue that the science cannot say with certainty that the feared effects of climate change will happen. From a risk management perspective, that’s true, but it’s also completely irrelevant. Hardly anything in the future is really 100 percent (or, for that matter, zero percent) sure to happen. The measurement of a risk today is our estimate of its probability times our estimate of its impact if it happens (usually written R = P x I).

As time moves forward, our knowledge will change. Our estimate of the probability will increase or decrease. Our estimate of the potential impact will be refined. (Estimates of impact, by the way, tend to be more precise and have more agreement than estimates of probability. In the case of climate change, both sides agree on the claimed impact; what they disagree on is the likelihood of that impact occurring.)

And, by somewhere around the year 2050, the argument will eventually go away completely. By then, it will be incontrovertibly clear what has happened. One or both sides will be proved wrong. Uncertainty will collapse; Schrödinger’s cat will be out of the box, alive or dead.

As we move through the life cycle of a project, our vision changes. All risks on a project eventually go away, either by becoming true (problem or good fortune), or by becoming false (no harm, no foul). At the same time, new risks swim into view as we navigate forward through the rocky stream of time.

The uncertainty of the future inevitably becomes the fact of the present.

Risk can be thought of in four dimensions:


  1. Goodness/Badness. In practice, risk is often used a synonym of threat. But events can be beneficial or harmful, or a mixture. Sometimes you can choose.
  2. Impact. You can find a dollar bill on the sidewalk, or you can find a hundred dollar bill. Both qualify as opportunity. You can lose a dollar, or you can lose a hundred dollars. Both qualify as threats. The difference, in both cases, is impact.
  3. Probability. Most people carry a lot more ones than hundreds, and are more likely to miss and search for a lost hundred. There’s a greater chance of finding (or losing) the smaller amount.
  4. Time. What we knew yesterday is different from what we know today or will know tomorrow. The risks that should concern us, and the choices we can make, do not remain static.
  5. Remediation. What, if anything, can you do about it? What will it cost? The value of a risk all by itself doesn’t tell us much. Only when you compare the value of the risk with the cost of the risk response do you know the shape of the decision space


In thinking about risk, put the risk into context — what’s it’s effect on you and others, and what’s the relative cost of the solution compared to the (risk-based) cost of the problem?

Tuesday, February 8, 2011

Triage for Project Managers (Part Two)



Our triage process has identified the most difficult and challenging projects, and now it’s time to perform a “deep dive” analysis of project difficulty — the final step in our preliminary analysis. The goal is to make sure we have a deeper understanding of the issues. Our earlier question, “What is the minimum decision and minimum action I must take right now?” is one that we must repeat as we move forward in the project.

Unless you’re staring at an Apollo 13-style deadline, with the clock ticking as CO2 levels rise, the right thing, as innumerable after-school specials have taught us, is to Learn More About It.

Difficulty comes in three dimensions: more complexity, tighter constraints, and less certainty. Of course, a project can have difficulty in more than one dimension, and their various combinations produce even more issues.

Complexity

Complexity can exist in both product and project. Project complexity is measured by such factors as the number of work packages, the number of resources, and the number of interactions and linkages. Product complexity is measured by such factors as the number of components, the number of processes, and the number of production steps. The key word here is numbers. Complexity can be counted.

Tools for managing complexity abound. They’re found in classical project management, systems engineering, logistics management, and financial risk management. A good background in probability is useful.

Constraints

Constraints come in many flavors, not merely the Neapolitan mélange of time, cost, and performance. You must obey applicable legislation, ethical codes, regulations, internal policies and procedures, and the laws of physics. They aren’t all created equal, especially in terms of their impact on an individual project.

A constraint is only a constraint if it limits your project performance choices.  If a regulation, for example, keeps you from doing something you’d otherwise do, it’s a constraint. If breaking the regulation would not help you achieve your project goal, it’s not a constraint, but merely a fact. (We’re not advocating breaking the regulation, of course, but merely classifying it in terms of your project universe.)

Constraints, as we noted, can be tight or loose, flexible or inflexible. A tight, inflexible constraint can make a project extremely difficult or even impossible. A constraint that is equally tight, but has flexibility, is much less serious. Equally, a loose constraint, even if inflexible, still gives you room to maneuver.

There are three fundamental strategies for managing constraints: change them, check assumptions, and come up with creative workarounds.

Uncertainty

How firm is the ground on which your project sits? Some of the factors that govern project uncertainty include the stability and likelihood of identified assumptions, the stability of your stakeholder community, the state of competition, the extent of newness, and the level of risk.

The difficulty in measuring uncertainty is the extent of the “unknown unknown” universe, the extent to which we don’t even know what it is we don’t know. In the managing assumptions, an equal problem comes in the form of “unknown knowns,” things that we don’t know that we actually do know.

Complex and Tightly Constrained

When complexity meets tight constraints, the value of the formal tools (project management, systems engineering, logistics management) tends to increase, because driving waste out of the system and driving structural efficiency into the system reduces constraint pressure. Formal systems also provide the necessary data structure to back up negotiations to modify constraints as well as to support creative efforts to move past them.

Complex and Uncertain

Uncertainty, on the other hand, undercuts and weakens the tools needed to manage complexity. Formal systems naturally work less well when the necessary data is unavailable or unreliable. The two main tools to manage complexity and uncertainty are risk management to prepare for known possible risks, and contingency reserves (extra time, extra money, optional requirements) to prepare for unknowns.

Watch out as well for uncertainty caused by complex stakeholder interactions and political maneuvering. The trouble-plagued Denver International Airport (DIA) construction project, delivered in 1994 after a $2 billion cost overrun and a year’s delay, was victimized by a constant tug-of-war among stakeholders ranging from city officials to airlines to various business interests.

Cognitive biases interfere here as well. Not only does weak data increase the role of bias in decision-making, uncertainty can also manifest itself in the form of various biases, especially denial.

Tightly Constrained and Uncertain

While tightly constrained and highly uncertain projects may not be impossible, they are often problematic. It may be legitimate to review whether the project should be attempted in the first place. If you go ahead with the project, failure is a significant risk, so plan for damage control in case of catastrophe.

Negotiating changes in the constraints is usually a worthwhile strategy, but the real problem is that projects in this category are often crisis responses. There were plenty of CO2 filters available for the Apollo 13 lunar module; the problem is that they were on Earth. Management freely gave project teams every resource possible — the problem is, that the range of the possible was very narrow indeed.

Complex, Tightly Constrained, Highly Uncertain

The trifecta of project management comes when a project scores high in each of the three dimensions. In 1991, as the Iraqi military retreated from Kuwait, they set fire to 737 oil wells after placing land mines to keep out firefighting crews. The resultant project to put out those fires fit all of our criteria. While money was available in ample amounts, professionals with the unique skills to handle a problem such as this are in short supply.

The time constraint didn’t have a specific date attached to it, but the environmental damage was such that time pressure was enormous. Risk and uncertainty were extremely high. Commentators at the time speculated that it might not even be possible to extinguish the fires in anything less than years. The dimensions of the problem were not clear at the outset.

Maintain an extreme vigil over your risk portfolio. Spend resources on information. Move forward in small steps, and watch for indications that your assumptions need to be modified.


[Part 1 appeared last week.]

Adapted from Creative Project Management: Innovative Project Options to Solve Problems On Time and Under Budget, by Michael Dobson and Ted Leemann; published by McGraw-Hill and copyright © 2010 by The McGraw-Hill Companies; all rights reserved. Used with permission.

Tuesday, February 1, 2011

Triage for Project Managers

The Very Model of a Modern Surgeon-General

In the opening credits for the TV series M*A*S*H, helicopters swoop in low over the hills carrying their precious cargo of gravely wounded soldiers.  Hawkeye Pierce, surgeon-saint in a Hawaiian shirt, leans over one soldier, a serious expression on his face. He quickly assesses the soldier’s condition, signals a waiting nurse, and soon a line of stretchers is carrying the wounded down Helicopter Hill and into surgery.

If you’ve ever waited in a hospital emergency room, you know what triage is. As its pronunciation suggests, triage is a French word, deriving from trier, to sort or select. It’s a formal way to prioritize medical patients based on the severity of their condition.

Both M*A*S*H and triage have their origin in the work of the same man: Baron Dominique-Jean Larrey, MD, surgeon-in-chief to Napoleon’s armies. Napoleon described Larrey as “the worthiest man I ever met,” and there’s some justice to the categorization. He invented the ambulance (inspired by watching Napoleon’s famous “flying artillery” maneuver around the battlefield), and was a pioneer in the enormously complex logistics for providing care in mass-casualty settings. 

Along with other pioneers such as Florence Nightingale and Major Jonathon Letterman, medical director of the Army of the Potomac under General McClellan, Larrey helped transform the face of military medicine, and as a side note changed the way people think about how to utilize limited resources effectively.

Modern medicine is of surprisingly recent vintage. Even the basic idea of the germ theory of disease (see Semmelweis in the cloud tag to your right) only originated in the first half of the 19th century. Medical care for soldiers was appallingly primitive, and throughout all the wars of history far more soldiers died from disease than from combat. It was not until World War II that a combination of more terrible weapons and greatly improved medical care tipped the balance in the other direction.

Military medicine doesn’t just involve the treatment of wounds. To handle mass battlefield casualties requires an enormously complex logistical and administrative apparatus. It’s not enough to be a good doctor; you also have to be a good project manager.

That’s why the concept of triage is so powerful. There is nothing new about the concept of prioritizing, of course. People have sorted, selected, and chosen for as long as there have been choices to make. But priorities are frequently established by a “best guess” method, rather than through a real and meaningful assessment process. An assessment methodology distinguishes real triage from simple prioritizing.

The Hierarchy of Triage

You don’t need to do triage of any sort if you have a single patient (or project), or if there are plenty of resources to go around to accomplish all the work. But that’s seldom the case. You need to perform triage from two different perspectives: not only for the project or projects for which you are responsible, but also so that you understand your relationship to the projects that may potentially compete for the same resources. Both relative and absolute importance have implications for what you do and how you do it Sometimes, your job is to assert the right of way for your projects; other times the right organizational choice is to yield to others.
Initially, you want to make the minimum necessary decision so you can take the minimum necessary action required right now. (You can always do more later.)

Degree of triage required ranges from basic to advanced depending on what’s at stake and what the issues are. Start with the basic process level, and continue as far along the journey as necessary until not only the current project, but also all the projects in your environment, have been accounted for.

Basic Triage

The first stage of medical triage for mass casualties is to separate the victims into three categories:

1.         Those who are likely to live, regardless of what care they receive
2.         Those who are likely to die, regardless of what care they receive
3.         Those for whom immediate care might make a positive difference in outcome.

In project management, Category 1 projects can be identified by large degrees of freedom in the triple constraints of time, performance, and cost. If the schedule is very flexible, performance requirements are modest, and the budget not at issue, there’s not a lot of project management challenge. We often describe smaller Category 1 projects as “tasks. The difference between a task and a project is, after all, merely perspective. Both have the same fundamental characteristics of “temporary and unique.”

Category 2 projects fall are "operationally impossible," meaning they can't be done under the current conditions and constraints. That's not the same thing as saying they're absolutely impossible, of course. Sometimes, current conditions and constraints can change.

Placing a project in Category 2 isn’t something to take lightly. Signs that a project may be in this category include: over-constrained in terms of budget or time, sky-high performance requirements, and high levels of uncontrollable risk. In such cases, you may abandon the project altogether, or perhaps do the very minimum exploratory activities to confirm your analysis. Of course, you may not be the only person whose opinion counts. If you think it’s a Category 2 project but the boss disagrees, you may have to do it anyway — but it's wise to think about self-protection when things go south.

Each triage determination requires an assessment of the specific current situation. Advances in medicine mean that injuries that once were solidly in Category 2 now enjoy remarkable recovery rates.  Similarly, projects once thought impossible also must be reviewed in light of new technologies and circumstances. Relying on outdated paradigms will result in misclassification with corresponding catastrophic results. While miracles are possible, the best doctors and project managers can do is make an informed situational decision using the most current information and technology to achieve the best result.

Category 3 projects need additional analysis, but they also need action. It is in this category that most projects fall.

[Continued next week]

Adapted from Creative Project Management: Innovative Project Options to Solve Problems On Time and Under Budget, by Michael Dobson and Ted Leemann; published by McGraw-Hill and copyright © 2010 by The McGraw-Hill Companies; all rights reserved. Used with permission.

Tuesday, June 29, 2010

Decisions, Decisions


“A decision,” wrote author Fletcher Knebel, “is what a man makes when he can’t find anybody to serve on a committee.”

Committees and teamwork are often an essential part of decision-making, but even in that framework, each of us must sooner or later take our stand, knowing full well the range of potential consequences. In an organization, a decision-making process must often be open and auditable. We must know not only the decision we make, but also the process that led us to that decision.

Decisions often require tradeoffs. A perfect solution may not exist. Each potential choice may have a downside, or may be fraught with risk. In some ways, making the least bad choice out of a set of poor alternatives takes greater skill and courage than making a conventionally “good” decision. Napoleon Bonaparte observed, “Nothing is more difficult, and therefore more precious, than being able to decide.”

The outcome of a decision, whether positive or negative, is not in itself proof of the decision’s quality, especially where probability is concerned. The odds may be dramatically in favor of a positive outcome, yet the dice may come up boxcars. Equally, if someone makes a stupid decision but gets lucky, the decision is no less stupid in spite of a good outcome. A good decision process improves our odds and results in the desired outcome the majority of the time.

There are two types of complexity in decision-making. The first, and most obvious, is the technical complexity of the issue and the tradeoffs that may be required. The second, though not always openly addressed, is the organizational complexity: the number of people involved, the number of departments or workgroups that must be consulted, the existing relationships that shape communication among people and groups, the organizational culture, and the pressure of the political process.

Decisions also vary in their importance. Importance can be measured in terms of the consequences of the decision and the constraints imposed on the decision process. Critical decisions fall into three categories:

• Time critical decisions must be made within a narrow window of time
• Safety critical decisions have the potential for injury or death
• Business/Financial critical decisions can affect the future or funding of the organization

At different times in the decision-making process, consider the opportunities as well as the negative consequences that can result both from the decision to act and from the decision to wait. If the consequences of a missed opportunity are greater, then the appropriate bias is in the direction of action. If an inappropriate decision could cause greater harm, the bias should fall in the direction of delay: gather more information and reassess.

Threats and opportunities both require proactive management, but opportunities even more so. Good luck and bad luck operate differently. If a person, say, loses $100, it’s gone, and all the consequences of that loss flow automatically. If, on the other hand, there’s a $100 bill somewhere in the area, it’s possible to miss it, there is no requirement to pick it up, and no obligation to spend it wisely. Exploiting opportunity requires observation, initiative, and wisdom.

Decisions must reflect goals. A successful project outcome is not necessarily an organizationally desirable outcome. Project managers and technical professionals must consider wider factors. Sometimes the right organizational decision involves hampering or even destroying the project.

Less than ideal circumstances are typically the reality. If there were more money, if the policies were different, if procedures didn’t require this item, the decision frame would be different—and so, likely, would be the decision itself. Generally, technical professionals prefer an emphasis on getting the job done correctly over meeting the schedule, but organizational circumstances may compel the latter.

When teams are involved in the decision, team decision-making considerations come into play. Conflict is not only inevitable, but if managed properly, desirable. The goal is to reach a consensus, which is not necessarily 100% agreement but rather a decision all team members can live with.

Compare the actual to the intended. If there is a discrepancy, the crucial question is “Why?” Knowing the actual results, would the team have done better with a different process? Should the process for future decisions be modified? Is there a trend in outcomes, especially in bad outcomes? If so, there may be process issues.


Thoughts adapted from “Decision Making,” by Michael Dobson et al., in Applied Project Management for Space Systems (Space Technology Series), McGraw-Hill, 2008.

Tuesday, April 6, 2010

The Baseball Theory

If you are failing seven times out of ten, most of us would take that as nature’s way of suggesting a different career field. But for a major league baseball player, that’s a .300 batting average – millions of dollars in salary and endorsements, and a shot at the Hall of Fame.

Most of us know that Babe Ruth also held the major league all-time strikeout record. Some of us know Charles Lindbergh’s other record – he’s tied for the most emergency parachute bailouts of all time. His safety record was so poor that the first company he approached to sell him a plane to cross the Atlantic refused him as a customer.

And there’s the infamous screen test report on Fred Astaire: “Can’t sing. Can’t act. Balding. Can dance a little.”

Success writers often tell these stories to give you hope. Yes, you may be a loser, but so were all these other people, and look how they turned out. But that misses the point:

If you are batting 1.000, one thing’s for sure – you’re not playing in the major leagues.

Successful people frequently have a shocking track record of failures and reverses on their way to the show. It’s what we call “paying your dues.” The things that matter have risks associated with them success isn’t free. Losing is an essential part of winning.

The baseball theory of life is very simple. If you don’t swing, you can’t hit. If you do swing, the odds are against you. For some people, that’s a deeply disturbing idea. But you can also look at the baseball theory with great hope: failure isn’t the long, circuitous road to the top; it’s the only way to the top.

In earlier entries, we’ve talked about the concept of risk (R=PxI, or the value of a risk equals the probability of the event times the impact of the event if it happens).

In pure risk (threat only), you can lower your risk by reducing the probability or by reducing the impact. In business risk (threat and opportunity combined, as in an investment decision), you have four ways to improve the situation: reduce the probability or impact of the downside, or increase the probability or impact of the upside.

When it comes to applying the baseball theory, where the odds of success are always low, the big trick is to reduce the consequences of failure. The cheaper it is to fail, the smarter it is to take a chance.

When salespeople cold-call clients, they expect rejection far more often than success, but one success pays the bills for a hundred rejections. People who’ve known me for a long time know I’ve always got some sort of scheme going. Most fail — I doubt I bat better than .200 — but I know how to keep the cost down so that the occasional winner is good enough.

In other words, it’s not whether you win or lose — it’s how you structure your bets.

Tuesday, March 30, 2010

Dobson's Laws (Part 2)

Herewith another collection of my daily SideWise Insights. Enjoy — and be sure to drop them into casual conversation.

Leadership and Motivation

Leadership skills are not fungible. Eisenhower was a great leader; Patton was a great leader; neither could have done the other's job.

While it's useful to tame what can be tamed, most of the management world lives where the wild things are.

The Old Yeller Rule: you have to know when and how to shoot your own dog. Sometimes it's even an act of mercy.

Realism isn't cynicism. A cynic is disappointed that things are what they are. Realists accept the facts and go from there.

It's not enough to learn the lessons an event teaches; you have to *not* learn the lessons it *doesn't* teach.

If someone spends more time and energy scheming to get out of work than it would take to do it, is that person unmotivated?

In the same way expenses rise faster than income, so does responsibility rise faster than authority.

Competition imposes constraints that aren't under your control. This suggests that a portion of your resources be devoted to intelligence.

You have to pay people to get them to work: you personally, not the organization. Respect, gratitude, and support make great paychecks.

"Lessons learned" aren't pleasant, but they're essential for growth. Make watching the game film as pleasant as possible.

There are two very different reasons to delegate: (a) to get stuff off your desk and (b) to train other people. Do some of each every week.

Another proud graduate of the Blanche Dubois School of Leadership: "We rely on the kindness of strangers!"

The job of leaders is making bad decisions, not good ones. When all options are rotten, the decision goes up the ladder.

When I first became a supervisor, I was so naive I actually believed my title meant people would do what I said.

Work is infinite. Resources are finite. Many management problems derive from this essential truth.

Operational definition of quality: It ain't dog food if the dog don't eat it. If no customer or boss wants it, why is it a requirement?

Power and Politics

Your role power is delegated by other people, but your respect power is something you own personally.

Here's a simple test to see if you have office politics in your organization: Do a headcount. If the result is 3 or higher, the answer is yes.

Power is energy that overcomes resistance to achieve work. The corollary of no power = no work.

The power to say "no" is held at lower organizational levels than the power to say "yes." Don't ask someone whose only answer is negative.

If there are multiple stakeholders, the 500 lb. gorilla wins. If there's more than one 500 lb. gorilla, conflict is inevitable.

Your negotiation power is greatest right before you say "yes." As soon as you've said it, your power plummets.

Pick your fights carefully. Some are necessary, some even desirable, but others should be avoided at all costs.

If you tell people they can have what they want, you're a genius. Tell them "no," you're a moron. Spin your "no" so it sounds like "yes."

If the wasps are already swarming, maybe you shouldn't be riling them up even more.

Military retreats don't garner kudos, but managing one takes a lot of planning. If you expect cutbacks, don't wait for the announcement.

Power follows failure like white corpuscles follow disease. Look for the last major failure to find out which department is most powerful.

Keep your friends close, and your customers closer. You need to manage them.

Project Management and Risk Management

Organizational movement up and down the stovepipe is easier; unfortunately, project managers usually need to work sideways.

A project begins life as a gap between where you are and where you want to be. If the project doesn't close the gap, it's a failure.

There are three main project gaps: the official gap, the underlying gap, and one or more hidden agendas. You need to know them all.

All wars are projects, though not all projects are wars. Borrow the best military thinking, but don't confuse problems with actual enemies.

It's not just one damn thing after another, it's usually the same damn thing over and over again. Attack repetitive crises at the roots.

In spite of a quarter-century of project management professionalism, studies show nearly 70% of all projects fail...and the trend is getting worse.

It's well known project management needs to be scaled, but it also needs to be stretched.

Two reasons projects fail: stuff nobody expected and didn't prepare for, and stuff everybody expected...and didn't prepare for.

Success at the project level doesn't mean success at the program level. "The operation was a success, but the patient died."

It's often an advantage to organize your project in stages. Actual results build enthusiasm and commitment.

Identify bad projects early by looking at stakeholder interests and conflicts. Are you being set up as the scapegoat for inevitable failure?

What makes a project challenging? Complexity, constraints, and (un)certainty. Of them, uncertainty is the toughest to manage.

Megaprojects inevitably have megaproblems. Take scale and complexity into account before judging disaster too harshly.

Some objectives are easier to achieve then others, even if they aren't central. It's often smart to pick low-hanging fruit.

Hidden or unstated objectives may be politically sensitive, and can't be spoken out loud without creating problems.

Some key goals are assumed, not stated, but that doesn't mean you're off the hook. Listen carefully to what people don't say.

"Nothing's impossible" implies unlimited resources and time and really flexible performance goals. None of these apply to project managers.

Earning a PMP only means you know the basics. No one ever finishes learning to be a good project manager.

A risk evaluation prices a risk, but price alone doesn't always tell you whether the risk is worth running.

There is no reliable correlation between short-term and long-term outcomes. Bad early can be great later, and vice versa.

If you do something stupid and get lucky, it doesn't validate the quality of your original decision.

Don't drive carpet tacks with a sledgehammer. Most formal systems are way too robust for most normal projects.

The most overlooked question is "Why?" If you don't know, even if you're on time, on budget, and to spec, you haven't done the job.

All wars are projects, but not all projects are wars. Wars have conscious opponents. Don't confuse ordinary risk with actual malice.

You are never the only game in town. What other projects are going on? How's the overall organization's health? Adjust accordingly.

The project isn't necessarily what they tell you it is. It isn't necessarily even what they think it is. Your job is to figure out what it really is.

Projects live in a finite universe, bounded by the triple constraints of time, cost, and performance.

The triple constraints of time, cost, and performance are never equally constraining. What drives your project? What is most flexible?

On any project, make sure you know where "good enough" is. Even Tiger Woods needs to know what par is.

Why People Don’t Do What You Want

Performance problem come in three varieties: "don't know," "can't do," or "won't do." Each has a different solution.

"Don't know" problems are communications failures. Don't expect your team to perform the Vulcan mind meld.

"Can't do" problems may require training, tools, someone else, or you may have to change what you're asking.

"Won't do" problems are about motivation. Everyone's motivated. Some work harder to get out of work than it would take to do it.

There are three reasons for a “Won’t Do”:

If performance is punished (reward for a bad project is an even worse one), expect motivation to drop quickly.

If failure is rewarded (screw up a job, get an easier one), expect failure.

If performance doesn't seem to matter, people put it on the bottom of the "to do" list, as they should.

Whenever someone isn't doing what you want, remember there are only these three reasons: don't know, can't do, and won't do.


Copyright © 2010 Michael Dobson, and made freely available under the Creative Commons attribution license.

Tuesday, January 12, 2010

Risk Management and Global Warming, Part 2

In last week’s installment, I laid out a risk management approach as it applied to global warming.

In summary, a risk is some event (threat or opportunity) that has a probability of happening, and has an impact if it does happen. The value of the risk is the probability times the impact (R=PxI). Compare the value of the risk to what it would cost to shrink it or make it go away. Sometimes it’s cheaper to deal with the risk, sometimes it’s cheaper to accept it.

When it comes to global warming, most of us have some doubt. To have an educated opinion about something, you need an education. I’m not a climate scientist, nor do I play one on TV. Any opinion I have on the subject has to be tinged with uncertainty.

But risk is all about uncertainty.

More About Probability

The sum of all the probabilities of the possible outcomes is one, or 100%.

  • What’s the chance of flipping heads or tails on a coin? 100%. (Yes, I’m neglecting the possibility it lands on the edge.)
  • What’s the chance of rolling a 1, 2, 3, 4, 5, or 6 on a six-sided die? Well, 100%.
  • What’s the chance that the effect of any global warming turns out to be either positive, nothing, minor, moderate, serious, or catastrophic? ______%
Oh, let’s not always see the same hands.

What's Your Risk Number?

If you’re not persuaded by the science, if you’re unsure what level of action — if any — is prudent, here’s how to calculate your own risk value. That gives you a financial base to work from in evaluating proposed responses.

Let me be clear up front — this is an extremely simple model that leaves out or abstracts hundreds of important considerations. (I'm open to suggestions.) This model has one purpose: to provide a number that has enough meaning to help you compare the cost of potential solutions to the cost of accepting whatever risk you may think is present.

The number also helps compare where you are in comparison to someone else, which can help bring clarity to a discussion. If person A thinks the risk should be valued at $25 billion tops, and person B thinks a conservative valuation of the risk is more like $5 trillion, then we know something about how each person sees the world.

The common ground in any argument is always and necessarily the lowest number on the table. In the discussion above, the common ground is any response to the risk that costs less than $25 billion. (A lot of people who oppose action support continued study, which is certainly part of the family of legitimate risk responses.)

Download the Spreadsheet

I've developed a spreadsheet that does this automatically for you. The link is below. Just click to download the Excel file to your desktop.

Click here to download my Global Warming Risk Calculator spreadsheet. (Permission is given to distribute it freely; in fact, please do.)

Using the Global Warming Risk Calculator

To perform this exercise, you have to divide 100% (the sum total of all the possible outcomes) among the following categories, based on how likely you think each outcome is. I’ve put down a potential cost number for each outcome; feel free to change the number if you evaluate the impact differently. And, while you’re at it, if you think there should be more outcome categories, add those too. But you still can only divide a total of 100% among them.

For purposes of illustration, I’ve added in my own personal probability guesses. As you can see, I’m not exactly a died-in-the-wool true believer.
  • Positive. Climate change is a net benefit for the world. (Economic impact: -$1 trillion — save or make money) (My guess: 0.9%, with a leftover .01% chance for Very Positive, -$10 trillion)
  • Nothing happens. (Economic impact: $0) (My guess: 32%)
  • Minor. There are some spotty problems, but they’re manageable. (Economic impact: $1 trillion) (My guess: 30%)
  • Moderate. There are significant increase in major weather catastrophes; regional crises more common. (Economic impact: $5 trillion) (My guess: 30%)
  • Serious. Global warming impact becomes the dominant geopolitical issues of the time. (Economic impact: $10 trillion) (My guess: 5%)
  • Catastrophic. There are massive die-offs, huge geographic dislocations, and major coastal flooding. (Economic impact: $25 trillion) (My guess: 2.9%, with the remaining 0.1% for the $100 trillion life-as-we-know-it-is-over jackpot.)
The next step is to calculate the expected monetary value (EMV) of the risk. That’s the PxI for each of the steps above.
  • Positive (= 0.9% x -$1 trillion, plus 0.1% x -$10 trillion)
  • Nothing (= 32% x $0)
  • Minor (= 30% x $1 trillion)
  • Moderate (= 30% x $5 trillion)
  • Serious (= 5% x $10 trillion)
  • Catastrophic (= 1.9% x $25 trillion, plus 0.1% x $100 trillion)
Add those answers together, and that’s how much money I think the risk is worth. When you plug in your numbers, you’ll get your valuation of risk.

On the second page of the spreadsheet, you'll see a UN-prepared chart on the cost of reducing carbon emissions by 2050 to achieve various targets. I've turned those GDP percentages into actual dollars, then converted those back to 2010 present value numbers.

The spreadsheet will automatically compare your valuation of the risk against the various UN targets, and tell you whether according to your own risk assessment whether the cost is too much or worth considering.

Try It Yourself!

I’ll wait.

.
.
.
.
.
.
.
.


How did you value the risk? Please post it as a comment. I'd love to know what you think.

Now What?

What, in your opinion, does that number suggest to you?

My global warming risk number is $2.86 trillion, and as you can see I’m not a passionate believer in imminent global catastrophe. That’s quite a bit of money; I was a little surprised at the answer when I did the math. (As my friend Misha pointed out in his comment on the previous installment, with that much money, at least some should surely be spent on mitigating secondary impact, as costs often fall heavier on the poor.)

Comparing that number to the cost of stabilizing CO2 emissions, it looks like I'm in favor of action, though that 450 ppm target is a close thing. But for 550 ppm, the numbers look good to me.

Obviously, I’d just as soon we don’t spend all that money unless we really have to. It’s always okay to spend less if that solves the problem. But with that much at stake, it seems to me that prudence argues for at least some significant action.

It also argues for continued research and refinement. Those probability and impact assessments won’t stay static. They may get worse, or they may get better.

And as they change, so too should our own opinions and beliefs.

And In The End...

I'm neither expecting to nor intending to change anyone's opinion on this question. I'm simply looking for common ground and a different way to frame this intractable issue.

What's your number? I'd really like to know