Project Risk Analysis & Management

Key Takeaways

  • Project risk is an uncertain event that can affect goals, schedule, resources, costs, stakeholders, or business continuity—not only safety hazards.
  • Feasibility assessment asks whether the project can succeed with available data, authority, time, and technical approach before heavy investment.
  • Impact analysis estimates how a risk event would hit metrics, timing, budget, people, and operations if it occurs.
  • RPN (severity × occurrence × detection) prioritizes failure modes in FMEA-style risk work; higher RPN generally gets earlier action.
  • Risk management is continuous: identify, analyze, prioritize, respond (avoid/mitigate/transfer/accept), and monitor residual risk through DMAIC.
Last updated: July 2026

Project Risk Analysis & Management

Quick Answer: Identify what could threaten project feasibility and success, estimate impact on goals/schedule/resources/costs/stakeholders/continuity, prioritize with tools such as RPN, and manage responses through the life of the DMAIC project—not only at kickoff.

Risk in the Green Belt Context

ASQ CSSGB BoK II.C.7 is at Understand level: know what project risk is, how it is assessed, and how management actions protect delivery. Distinguish two related ideas:

ConceptFocus
Project riskUncertainty that affects delivering the improvement project (data access denied, sponsor leaves, pilot blocked)
Process / product riskFailure modes of the process or design (often FMEA in operations or DFSS)

Both matter. FMEA (severity × occurrence × detection → RPN) is a core Six Sigma risk tool; project risk registers use similar severity/likelihood thinking for schedule and delivery threats. Green Belts should not treat “risk” as only OSHA hazards or only DFMEA rows.

Feasibility: Can This Project Succeed?

Feasibility screening asks whether the proposed project is doable under real constraints. It overlaps project selection filters but continues after charter as conditions change.

Feasibility dimensions

DimensionQuestions
TechnicalDo we have methods/tools skill? Is the measurement system fixable?
DataCan we access, collect, and stratify data in time?
OrganizationalAuthority to change the process? Cross-functional cooperation?
ResourcePeople hours, budget, equipment, IT support?
ScheduleCan DMAIC finish before the business need expires?
Regulatory / complianceWill proposed changes require lengthy approvals?
FinancialIs benefit plausible after cost of analysis and implementation?

Red flags for low feasibility

  • Champion cannot free SMEs for Measure
  • Critical data locked in a vendor system with no extract path
  • Solution space requires capital the organization already rejected
  • Goal demands six-sigma perfection in eight weeks on a chaotic process with no MSA

Feasibility risk does not always kill a project—it may force scope reduction, Black Belt support, or a data-access workstream before Analyze fantasies begin.

Impact: What Gets Hurt If the Risk Hits?

Impact analysis estimates consequences if a risk event occurs. CSSGB topics explicitly connect risk effects to:

Impact areaExamples on a GB project
Goals / Y metricsCannot prove improvement; goal missed; wrong Y optimized
ScheduleTollgate slips; pilot misses peak season; benefits delayed
ResourcesKey analyst pulled; overtime burn; consultant cost spike
CostsBudget overrun; scrap from failed pilot; rework of training
StakeholdersTrust loss; resistance; customer-visible disruption
Business continuity / BCPPilot change interrupts service; single-threaded process fails

Score impact (e.g., 1–5 or 1–10) consistently with how your organization scores FMEA severity when possible, so risk language matches quality language.

Worked example — impact notes:

Risk: “ERP freeze blocks new defect-code field for 10 weeks.”

  • Goals: Baseline still possible on existing codes; Improve IT solution delayed
  • Schedule: Improve → Control may slip one quarter
  • Resources: Team idle or diverted to manual coding audit
  • Costs: Soft savings delayed; possible overtime for manual audit
  • Stakeholders: Finance frustrated; Champion credibility at risk
  • BCP: Low direct ops interruption if pilot is non-production

Documenting multi-area impact prevents “it’s just an IT delay” understatement.

Likelihood, Detection, and RPN

For process FMEA, risk priority often uses:

[ RPN = S \times O \times D ]

  • S (Severity): How bad is the effect if the failure occurs?
  • O (Occurrence): How likely is the cause?
  • D (Detection): How likely are we to detect the failure before it escapes? (High score = hard to detect—worse)

Higher RPN → higher priority for action, with judgment: a severity-10 item with modest RPN may still outrank a high-RPN cosmetic issue. Some organizations add SOD thresholds or prioritize by severity first.

Project risk matrix (simpler alternative)

Many project registers use Likelihood × Impact heat maps without detection:

Low impactHigh impact
High likelihoodMitigateAvoid or urgent mitigate
Low likelihoodAccept / watchContingency plan

Know both languages for the exam: RPN for FMEA-style items; likelihood × impact for project registers.

Risk Management Process

A practical loop for Green Belts:

  1. Identify — Brainstorm with team/Champion; review assumptions, interfaces, suppliers, change windows, skills gaps.
  2. Analyze — Feasibility + impact + likelihood (+ detection if FMEA).
  3. Prioritize — RPN or heat map; focus on vital few.
  4. Respond — Choose strategies and owners.
  5. Implement actions — Put mitigations in the WBS and Gantt.
  6. Monitor — Review risks at every tollgate; retire closed risks; add new ones.

Response strategies

StrategyMeaningExample
AvoidChange plan to eliminate riskShrink scope to one plant; drop unfeasible IT change
MitigateReduce likelihood or impactEarly MSA; parallel data path; pilot on low-volume SKU
TransferShift risk (insurance, vendor SLA, another owner)IT owns cutover; finance validates savings method
AcceptKnowingly proceed; may set contingencyAccept minor overtime risk with reserve hours
ContingencyPre-planned reaction if risk triggersBackup sample plan if extract fails by date X

Opportunity risks (positive uncertainty) also exist—e.g., a new system release that could accelerate Improve. Capture them so the team can exploit or enhance upside, not only defend against downside.

Effects on Goals, Schedule, Resources, BCP, Costs, Stakeholders

Exam and practice scenarios often ask you to connect a risk to multiple effect types:

Risk eventPrimary effects
Loss of Champion mid-projectGoals/stakeholders (orphan project); schedule (decisions stall)
MSA fails late in MeasureSchedule (recollect); costs (rework); goals (invalid Y)
Pilot disrupts live customer ordersStakeholders; BCP/service continuity; costs (recovery)
Key SME on medical leaveResources; schedule; analysis quality → goals
Scope creep to “whole enterprise”Schedule; resources; goals (nothing finishes)
Undocumented benefit assumptionsCosts/finance credibility; stakeholder trust at close

Business continuity planning (BCP) angle: When Improve changes a live process, ask: What is the rollback? What is the maximum disruption window? Who is on call? A control plan without a rollback is incomplete risk management for operational processes.

Integrating Risk into DMAIC

PhaseRisk focus
DefineFeasibility, stakeholder resistance, scope risk, charter assumptions
MeasureData access, MSA failure, biased samples
AnalyzeWrong root cause, confounding, skill gaps in stats
ImprovePilot failure, unintended consequential metric harm, implementation cost
ControlSustainment failure, training gaps, detection weakness, documentation loss

Put top risks on the storyboard and tollgate pack. A team that never updates its risk log is not managing risk—it is storing a kickoff artifact.

Common Pitfalls

  • Confusing process FMEA with project risk register (use both when needed)
  • Ranking only by occurrence and ignoring severity-10 safety or compliance items
  • Treating RPN as precision science rather than prioritization aid
  • Accepting all risks with no contingency because “we’re too busy”
  • Ignoring stakeholder and BCP impacts while tracking only schedule
  • Closing the project with residual risks and no owner

Risk Checklist for Green Belts

  • Risk log exists with owner, due date, and status
  • Feasibility rechecked when scope or sponsorship changes
  • Impacts scored across goals, time, resources, cost, stakeholders, continuity
  • High RPN / high heat-map items have response actions in the WBS
  • Pilot includes rollback / BCP thinking
  • Tollgates review residual risk, not only metrics

Understanding project risk analysis and management keeps DMAIC honest: the plan is a hypothesis about the future, and risk work is how the team stays ahead of that uncertainty.

Test Your Knowledge

During Define, a Green Belt learns the only person who can approve extracts from the claims system will be on leave for the entire planned Measure month, and no backup exists. This primarily threatens which risk concepts?

A
B
C
D
Test Your Knowledge

In a process FMEA, a failure mode scores Severity 8, Occurrence 4, and Detection 5. What is the RPN, and how should it generally be used?

A
B
C
D