Risk Management Practice Gap Analysis
FINC 5133
October 8, 2020
1
Executive Summary
Programmatic risk analysis involves quantifying the impact of risk and uncertainty on
project cost and schedule. Analysts working in the U.S. aerospace and defense industries tend to
be insulated from risk practitioners working in other industries and other countries. This is due to
the need to protect classified information, limited funding for research into risk analysis, and
general disinterest stemming from a not-invented-here mentality. Therefore, there is a gap in
understanding of what external risk practitioners are doing to identify and assess the impact of
risks. This bibliography seeks to find descriptions of risk management practices in other
industries and other countries to find alternative practices that may prove useful in U.S.
aerospace and defense projects.
Diversity of Risk Management Perspectives
A key aspect of this research is to search for a diversity of risk management practices to
which a U.S. aerospace and defense practitioner would not normally be exposed. The papers
collected describe risk management practices in six broad industries. The largest collection came
from the building construction industry with three papers not specifying what type of building
(Kotb et al, 2019; Omer & Aeleke, 2019; Sharma, 2020), one building residential complexes
(Muneer Abdulrahman, 2019), one constructing hostel buildings (Verma & Sawant, 2019), and
one constructing industrial buildings (Insja & Sihombing, 2017). Four papers described some
facet of road construction, including road construction safety (Onyeka & Agunwamba, 2019),
highway construction (Ika Wahyuni et al., 2019), concrete pavement (Arjmand Aghdareh et al.,
2019), and asphalt mixing (Made Cahaya Wardani et al., 2020). Three authors described risk
management in the software industry (Hawari & Heeks, 2010; Lai et al., 2013; Lech, 2015). Also
included were authors discussing shipbuilding (Zaman et al., 2019), research and development
2
(Minasyan, 2019), and the financial industry (Chong et al., 2020).
The research also yielded a global perspective. Eleven different countries were
represented. Four papers discussed Indonesian projects (Made Cahaya Wardani et al., 2020; Ika
Wahyuni et al., 2019; Insja & Sihombing, 2017; Zaman et al., 2019). Four authors described
practices in India (Kiradoo, 2019; Lai et al., 2013; Sharma, 2020; Verma & Sawant, 2019). Other
countries found include Egypt (Selim, 2018), Nigeria (Onyeka & Agunwamba, 2019), United
Kingdom (Lai et al., 2013), Russia (Minasyan, 2019), Iraq (Muneer Abdulrahman, 2019), Iran
(Arjmand Aghdareh et al., 2019), Poland (Lech, 2015), Malaysia (Omer & Aeleke, 2019), Jordan
(Hawari & Heeks, 2010), and the United States (Chong et al., 2020). The case study presented
by Lai et al. (2013) was a joint United Kingdom/India project.
Risk Identification
Risk identification is the process of determining which risks could prevent a project from
achieving the objectives. None of the papers reviewed identified risks to a specific project,
possibly to protect sensitive information. Rather, most discussed general risk categories or
typical risks relevant to a type of project. In all papers describing risk identification, inclusion of
subject matter experts in the process was necessary.
A useful tool in identifying risks is a risk taxonomy. A risk taxonomy is a comprehensive
set of risk categories covering all the risks faced by a project. A risk taxonomy facilitates risk
identification by encouraging those involved to consider all types of risks. The term “risk
taxonomy” is not used by any of the authors. Rather, they refer to developing a list of risk
factors, sources, or categories. The following table contains a list of the taxonomies found.
3
Author
Made Cahaya
Wardani et al.
(2020)
Arjmand
Aghdareh et al.
(2019)
Ika Wahyuni et
al. (2019)
Kiradoo (2019)
Lai et al. (2013)
Sharma (2020)
Taxonomy
Supply
Input
Process
Output
Customer
Safety
Quality
Time
Cost
Project
Economic
Planning
Marketing
Criminal
Flood
Investment
Landslide
Human
Service
Construction
damage
Political
Technical
Financial
Demolition
Accident
Environmental
Safety
Market
Business
Financial
Coordination
systems
Objectives
and values
Capabilities
Processes
Information
Technology
Technical
Construction
Physical
Organizational
Financial
Management
Political
Logistics
Design
Table of Risk Taxonomies
4
As shown, in the table below, some papers described conducting a literature review to
develop an initial list of risks. Literature included professional papers, project status reports, and
audit findings. The literature reviews often yielded hundreds of risks. Whenever a risk list is
identified via a literature review, the inevitable second step involves soliciting expert opinion to
determine which risks are most relevant. (Arjmand Aghdareh, 2019, p. 4; Ika Wahyuni et al.,
2019, p. 116; Insja & Sihombing, 2017, p. 4; Sharma, 2020, p. 89)
Identification Technique
Author
Literature Review
Arjmand Aghdareh et al. (2019, p. 4)
Insja & Sihombing (2017, p. 4)
Sharma (2020, p. 89)
Interviews
Ika Wahyuni et al. (2019, p. 116)
Lai et al., (2013, p. 5)
Lech, (2015, p. 5)
Combination of techniques
Made Cahaya Wardani et al. (2020, p. 259)
Hawari & Heeks (2020, p. 12)
Table of Risk Identification Techniques
At a minimum, a risk statement is characterized by an event with a consequence.
Commonly, risk statements are in the format “if A, then B,” where A is an event and B is the
consequence. Few authors used this risk statement format explicitly. For example, Arjmand
Aghdareh et al. (2019, p. 12) listed risk events and then categorized the risk events by impact
category (cost, schedule, safety, and quality). This implies the events described had a negative
impact on the assigned categories.
Risk Analysis
Risk analysis is the process of examining the collection of identified risks and
determining which are of greatest concern. The output is some measure of severity for each risk
by which the entirety of risks can be prioritized. Among the papers researched, the most common
method of analyzing risks is by using rating scales. Use of rating scales is considered quantitative
5
analysis, although the usefulness of the quantitative result may be limited. None of the authors
that used rating scales described how the scales were established. It is assumed the scales have
equal intervals between the points. If the scales were not defined with such care, then algebraic
manipulation of the scores is nonsensical, and the scales should only be used to establish ordinal
relationships.
Risks are typically scored in terms of likelihood and consequence and these values are
used to determine risk severity. Qualitative definitions of each score are provided to facilitate
determination of the quantitative value, as exemplified in the figure below from Made Cahaya
Wardani et al. (2019, p. 260).
Likelihood
Score
Consequence
Score
Frequent
5
Very Large
5
Often
4
Large
4
Infrequent
3
Medium
3
Rare
2
Small
2
Extremely Rare
1
Very Small
1
Example of Risk Scoring Criteria
The risk severity can then be determined in one of two ways. First, the risk severity can
be determined by the product of the likelihood and consequence scores. (Made Cahaya Wardani,
2019, p. 260; Onyeka & Agunwamba, 2019, p. 44) Second, the severity can be determined by
mapping the likelihood and consequence on a 5×5 matrix, with each cell in the matrix designated
a unique severity value. (Muneer Abdulrahman, 2009, p. 155; Zaman et al., 2019, p 5) Muneer
Abdulrahman (2009, p. 155) claims that such a matrix is the dominant method of risk analysis in
the construction of residential complexes in Iraq.
Zaman et al. (2019) converts the 1 through 5 risk scores for likelihood and consequence
into probabilities of occurrence and schedule impact, respectively. The risks are then mapped to
specific project tasks. The risks and project schedule are modeled in a special software tool
capable of performing a Monte Carlo analysis. The output is a probabilistic distribution of the
project completion date. By removing a specific risk from the model and re-running the
simulation, the project manager can assess the benefit of mitigating that risk in terms of schedule
recovery.
In some instances, risk severity was scored directly, without first considering likelihood
and consequence. Muneer Abdulrahman (2019, p. 157) used a questionnaire, given to 108
experts, to score each risk factor on a scale from 1 to 5. Sharma (2020, p. 89) followed a similar
process, but did not disclose their scale. Hawari & Heeks (2020, p. 6) used a ten-point rating
scale to score the design-reality gap of each of the risk categories. The design-reality gap is
defined as the difference between what the project required to be successful (design) and what