Project Risk Analysis & Management
Key Takeaways
- Project risk is an uncertain event that can affect goals, schedule, resources, costs, stakeholders, or business continuity—not only safety hazards.
- Feasibility assessment asks whether the project can succeed with available data, authority, time, and technical approach before heavy investment.
- Impact analysis estimates how a risk event would hit metrics, timing, budget, people, and operations if it occurs.
- RPN (severity × occurrence × detection) prioritizes failure modes in FMEA-style risk work; higher RPN generally gets earlier action.
- Risk management is continuous: identify, analyze, prioritize, respond (avoid/mitigate/transfer/accept), and monitor residual risk through DMAIC.
Project Risk Analysis & Management
Quick Answer: Identify what could threaten project feasibility and success, estimate impact on goals/schedule/resources/costs/stakeholders/continuity, prioritize with tools such as RPN, and manage responses through the life of the DMAIC project—not only at kickoff.
Risk in the Green Belt Context
ASQ CSSGB BoK II.C.7 is at Understand level: know what project risk is, how it is assessed, and how management actions protect delivery. Distinguish two related ideas:
| Concept | Focus |
|---|---|
| Project risk | Uncertainty that affects delivering the improvement project (data access denied, sponsor leaves, pilot blocked) |
| Process / product risk | Failure modes of the process or design (often FMEA in operations or DFSS) |
Both matter. FMEA (severity × occurrence × detection → RPN) is a core Six Sigma risk tool; project risk registers use similar severity/likelihood thinking for schedule and delivery threats. Green Belts should not treat “risk” as only OSHA hazards or only DFMEA rows.
Feasibility: Can This Project Succeed?
Feasibility screening asks whether the proposed project is doable under real constraints. It overlaps project selection filters but continues after charter as conditions change.
Feasibility dimensions
| Dimension | Questions |
|---|---|
| Technical | Do we have methods/tools skill? Is the measurement system fixable? |
| Data | Can we access, collect, and stratify data in time? |
| Organizational | Authority to change the process? Cross-functional cooperation? |
| Resource | People hours, budget, equipment, IT support? |
| Schedule | Can DMAIC finish before the business need expires? |
| Regulatory / compliance | Will proposed changes require lengthy approvals? |
| Financial | Is benefit plausible after cost of analysis and implementation? |
Red flags for low feasibility
- Champion cannot free SMEs for Measure
- Critical data locked in a vendor system with no extract path
- Solution space requires capital the organization already rejected
- Goal demands six-sigma perfection in eight weeks on a chaotic process with no MSA
Feasibility risk does not always kill a project—it may force scope reduction, Black Belt support, or a data-access workstream before Analyze fantasies begin.
Impact: What Gets Hurt If the Risk Hits?
Impact analysis estimates consequences if a risk event occurs. CSSGB topics explicitly connect risk effects to:
| Impact area | Examples on a GB project |
|---|---|
| Goals / Y metrics | Cannot prove improvement; goal missed; wrong Y optimized |
| Schedule | Tollgate slips; pilot misses peak season; benefits delayed |
| Resources | Key analyst pulled; overtime burn; consultant cost spike |
| Costs | Budget overrun; scrap from failed pilot; rework of training |
| Stakeholders | Trust loss; resistance; customer-visible disruption |
| Business continuity / BCP | Pilot change interrupts service; single-threaded process fails |
Score impact (e.g., 1–5 or 1–10) consistently with how your organization scores FMEA severity when possible, so risk language matches quality language.
Worked example — impact notes:
Risk: “ERP freeze blocks new defect-code field for 10 weeks.”
- Goals: Baseline still possible on existing codes; Improve IT solution delayed
- Schedule: Improve → Control may slip one quarter
- Resources: Team idle or diverted to manual coding audit
- Costs: Soft savings delayed; possible overtime for manual audit
- Stakeholders: Finance frustrated; Champion credibility at risk
- BCP: Low direct ops interruption if pilot is non-production
Documenting multi-area impact prevents “it’s just an IT delay” understatement.
Likelihood, Detection, and RPN
For process FMEA, risk priority often uses:
[ RPN = S \times O \times D ]
- S (Severity): How bad is the effect if the failure occurs?
- O (Occurrence): How likely is the cause?
- D (Detection): How likely are we to detect the failure before it escapes? (High score = hard to detect—worse)
Higher RPN → higher priority for action, with judgment: a severity-10 item with modest RPN may still outrank a high-RPN cosmetic issue. Some organizations add SOD thresholds or prioritize by severity first.
Project risk matrix (simpler alternative)
Many project registers use Likelihood × Impact heat maps without detection:
| Low impact | High impact | |
|---|---|---|
| High likelihood | Mitigate | Avoid or urgent mitigate |
| Low likelihood | Accept / watch | Contingency plan |
Know both languages for the exam: RPN for FMEA-style items; likelihood × impact for project registers.
Risk Management Process
A practical loop for Green Belts:
- Identify — Brainstorm with team/Champion; review assumptions, interfaces, suppliers, change windows, skills gaps.
- Analyze — Feasibility + impact + likelihood (+ detection if FMEA).
- Prioritize — RPN or heat map; focus on vital few.
- Respond — Choose strategies and owners.
- Implement actions — Put mitigations in the WBS and Gantt.
- Monitor — Review risks at every tollgate; retire closed risks; add new ones.
Response strategies
| Strategy | Meaning | Example |
|---|---|---|
| Avoid | Change plan to eliminate risk | Shrink scope to one plant; drop unfeasible IT change |
| Mitigate | Reduce likelihood or impact | Early MSA; parallel data path; pilot on low-volume SKU |
| Transfer | Shift risk (insurance, vendor SLA, another owner) | IT owns cutover; finance validates savings method |
| Accept | Knowingly proceed; may set contingency | Accept minor overtime risk with reserve hours |
| Contingency | Pre-planned reaction if risk triggers | Backup sample plan if extract fails by date X |
Opportunity risks (positive uncertainty) also exist—e.g., a new system release that could accelerate Improve. Capture them so the team can exploit or enhance upside, not only defend against downside.
Effects on Goals, Schedule, Resources, BCP, Costs, Stakeholders
Exam and practice scenarios often ask you to connect a risk to multiple effect types:
| Risk event | Primary effects |
|---|---|
| Loss of Champion mid-project | Goals/stakeholders (orphan project); schedule (decisions stall) |
| MSA fails late in Measure | Schedule (recollect); costs (rework); goals (invalid Y) |
| Pilot disrupts live customer orders | Stakeholders; BCP/service continuity; costs (recovery) |
| Key SME on medical leave | Resources; schedule; analysis quality → goals |
| Scope creep to “whole enterprise” | Schedule; resources; goals (nothing finishes) |
| Undocumented benefit assumptions | Costs/finance credibility; stakeholder trust at close |
Business continuity planning (BCP) angle: When Improve changes a live process, ask: What is the rollback? What is the maximum disruption window? Who is on call? A control plan without a rollback is incomplete risk management for operational processes.
Integrating Risk into DMAIC
| Phase | Risk focus |
|---|---|
| Define | Feasibility, stakeholder resistance, scope risk, charter assumptions |
| Measure | Data access, MSA failure, biased samples |
| Analyze | Wrong root cause, confounding, skill gaps in stats |
| Improve | Pilot failure, unintended consequential metric harm, implementation cost |
| Control | Sustainment failure, training gaps, detection weakness, documentation loss |
Put top risks on the storyboard and tollgate pack. A team that never updates its risk log is not managing risk—it is storing a kickoff artifact.
Common Pitfalls
- Confusing process FMEA with project risk register (use both when needed)
- Ranking only by occurrence and ignoring severity-10 safety or compliance items
- Treating RPN as precision science rather than prioritization aid
- Accepting all risks with no contingency because “we’re too busy”
- Ignoring stakeholder and BCP impacts while tracking only schedule
- Closing the project with residual risks and no owner
Risk Checklist for Green Belts
- Risk log exists with owner, due date, and status
- Feasibility rechecked when scope or sponsorship changes
- Impacts scored across goals, time, resources, cost, stakeholders, continuity
- High RPN / high heat-map items have response actions in the WBS
- Pilot includes rollback / BCP thinking
- Tollgates review residual risk, not only metrics
Understanding project risk analysis and management keeps DMAIC honest: the plan is a hypothesis about the future, and risk work is how the team stays ahead of that uncertainty.
During Define, a Green Belt learns the only person who can approve extracts from the claims system will be on leave for the entire planned Measure month, and no backup exists. This primarily threatens which risk concepts?
In a process FMEA, a failure mode scores Severity 8, Occurrence 4, and Detection 5. What is the RPN, and how should it generally be used?