Ch4. Risk Management and Quality Management
Risk Management
Risk: An uncertain event that, if it occurs, has a positive (opportunity) or negative (threat) effect on project objectives.
Risk Management Process
- Identify Risks: Brainstorming, checklists, interviews → risk register
- Qualitative Analysis: Probability × Impact prioritization (risk matrix)
- Quantitative Analysis: Numerical analysis (Monte Carlo simulation, decision trees)
- Plan Risk Responses: Strategies for threats and opportunities
- Monitor Risks: Ongoing tracking, identify new risks
Threat Response Strategies
| Strategy | Description | Example |
|---|---|---|
| Avoid | Eliminate the risk cause | Drop a risky technology |
| Transfer | Shift to a third party | Purchase insurance |
| Mitigate | Reduce probability/impact | Increase testing |
| Accept | Acknowledge and monitor | Establish contingency reserve |
Opportunity Response Strategies
| Strategy | Description |
|---|---|
| Exploit | Ensure the opportunity occurs |
| Share | Partner with someone better positioned |
| Enhance | Increase probability or impact |
| Accept | Take advantage if the opportunity arises |
Exam key: Risks include both threats AND opportunities. PMP exam questions frequently test your understanding that a good PM actively pursues opportunities — not just mitigates threats.
Quality Management
Quality vs. Grade
Quality: Degree to which characteristics meet requirements Grade: Category assigned to deliverables with the same functional use but different characteristics
Low grade / high quality: Limited features but flawless execution (acceptable) High grade / low quality: Many features but with defects (unacceptable)
Three Quality Processes
1. Quality Planning: Define quality standards, plan how to achieve them.
2. Quality Assurance (QA): Audit whether processes follow quality standards. Prevention-focused.
3. Quality Control (QC): Inspect deliverables to verify they meet quality standards. Detection-focused.
Quality Tools
Cause-and-Effect (Fishbone/Ishikawa) Diagram
Identifies root causes of a defect:
People → ────────────┐
Machines → ──────────┼──→ Defect (Effect)
Methods → ───────────┘
Pareto Chart
80/20 rule: 80% of defects come from 20% of causes. Focus effort on the vital few causes that produce most problems.
Control Charts
Track process stability over time using upper and lower control limits. Points outside limits signal a process that is “out of control.”
Key Concept Cards
Threats vs. Opportunities ★★★★★ : Risks include both. Threat responses: avoid/transfer/mitigate/accept. Opportunity responses: exploit/share/enhance/accept.
Quality Assurance vs. Quality Control ★★★★★ : QA=process audits (prevention), QC=deliverable inspection (detection). Prevention is more cost-effective than detection.
Pareto Principle ★★★★☆ : 80% of defects come from 20% of causes. Prioritize the most impactful causes first.
Practice Quiz
Q1. A key supplier is at risk of missing the delivery deadline. What risk response strategies are appropriate?
Multiple strategies may apply: Mitigate by identifying and qualifying backup suppliers in advance. Transfer by including contract penalties for late delivery. Accept by adding schedule contingency. If probability and impact are high, Avoid by contracting an alternative supplier immediately. The right choice depends on probability, impact, and cost of response.
Q2. Why is Quality Assurance (fixing processes) more cost-effective than Quality Control (inspecting outputs)?
The cost of fixing a defect grows exponentially the later it’s discovered. A defect found during development might cost 1x to fix; found during testing, 10x; found after delivery to the customer, 100x or more. Preventing defects by improving processes (QA) is fundamentally cheaper than detecting them through inspection (QC).
OIYO Editorial
Editorial DeskThe OIYO editorial desk researches money, law, lifestyle, and self-understanding topics against primary sources and public statistics. Every piece carries source notes and is reviewed on a regular cycle for accuracy and usefulness.