Thursday, December 11, 2008

risk management


Once risks have been identified and assessed, all techniques to manage the risk fall into one or more of these four major categories:



  • Avoidance (eliminate)

  • Reduction (mitigate)

  • Transference (outsource or insure)

  • Retention (accept and budget)

US Department of Defense, calls these categories ACAT, for Avoid, Control, Accept, or Transfer. (Not to be confused with Defense Acquisition University's use of the acronym for Acquisition Category).


Each risk should have an ID# for tracking and can be maintained in a database (or spreadsheet) with the following columns:


  • ID#

  • name/description

  • POC

  • risk handling category

  • Liklihood / Impact

  • associated action items

  • how it is resolved or closed

A successful summary chart looks like the picture above. This example rolls up six project risks and provides executive level briefing for senior management or clients.


risk = hazard x exposure (or occurance x impact)

No comments:

Program Manager

As a technical leader, I develop a talent pipeline that can deliver client's expectations in a motivating and productive environment.

I have performed multi-discipline engineering on space launch vehicles, satellite command and control software, electronic medical records, and large data center operations.


I am seeking additional opportunities to deliver solutions internationally

resume MBA-Bard Center


I have delivered management and technology consulting solutions for Deloitte, BearingPoint, Department of the Interior, TRICARE Military Health System, Defense Information Systems Agency (DISA), Raytheon, Lockheed, Northrop, and Boeing on various projects in manufacturing, software development, systems engineering, testing, and ITIL management.