9.3 Risk Management
Key Takeaways
- TOGAF distinguishes the initial level of risk, before mitigating actions, from the residual level of risk, after mitigating actions.
- The TOGAF risk management process covers risk classification, risk identification, initial risk assessment, risk mitigation and residual risk assessment, and risk monitoring.
- TOGAF assesses risk impact by combining effect (Catastrophic, Critical, Marginal, Negligible) with frequency (Frequent, Likely, Occasional, Seldom, Unlikely).
- Risk mitigation reduces risk to an acceptable level and can range from monitoring or acceptance to a full contingency plan.
- The Enterprise Architect may identify and mitigate risks, but risks are first accepted and then managed within the governance framework.
9.3 Risk Management
Risk management appears in two learning outcomes: briefly explain risk management (Concepts) and briefly explain the characteristics of architecture risk management and where it is used within the TOGAF ADM (ADM Techniques).
Why Risk Management Matters
There will always be risk with any architecture or business transformation effort. It is important to identify, classify, and mitigate these risks before starting, so they can be tracked throughout the transformation. Mitigation is an ongoing effort, and risk triggers are often outside the scope of the transformation planners (for example, a merger or acquisition), so planners must monitor the transformation context constantly.
An important governance point: the Enterprise Architect may identify the risks and mitigate certain ones, but it is within the governance framework that risks have to be first accepted and then managed.
Two Levels of Risk
| Level | Definition |
|---|---|
| Initial level of risk | Risk categorization prior to determining and implementing mitigating actions |
| Residual level of risk | Risk categorization after implementation of mitigating actions (if any) |
The Risk Management Process
The TOGAF Standard describes these activities:
- Risk classification
- Risk identification
- Initial risk assessment
- Risk mitigation and residual risk assessment
- Risk monitoring (with governance in Phase G)
The ADM Techniques document describes a qualitative approach. A more rigorous quantitative approach is described in the Open FAIR™ Body of Knowledge (the Open Risk Taxonomy and Open Risk Analysis standards), and risk concepts are extended in the TOGAF Series Guide: Integrating Risk and Security within a TOGAF Enterprise Architecture.
1. Risk Classification
Risks can be classified in several ways — for example by time, cost, scope, client expectations, and performance, or by whether they are enterprise-wide or project-level. Classification helps assign responsibility for managing each risk at the right governance level.
2. Risk Identification
The capability maturity and transformation readiness assessments typically generate many risks. Identification documents each risk and sets the strategy to address it throughout the transformation.
3. Initial Risk Assessment
Each risk is assessed for its effect and its frequency, which combine into an impact:
| Effect | Meaning |
|---|---|
| Catastrophic | Critical financial loss that could result in bankruptcy of the organization |
| Critical | Serious financial loss in more than one line of business, leading to loss of productivity and no return on the IT investment |
| Marginal | Minor financial loss in a line of business and a reduced return on the IT investment |
| Negligible | Minimal impact on a line of business's ability to deliver services and/or products |
| Frequency | Meaning |
|---|---|
| Frequent | Likely to occur very often and/or continuously |
| Likely | Occurs several times over the course of a transformation cycle |
| Occasional | Occurs sporadically |
| Seldom | Remotely possible; would probably occur not more than once in a transformation cycle |
| Unlikely | Will probably not occur during the transformation cycle |
The Corporate Risk Impact Assessment matrix combines them:
| Effect ↓ / Frequency → | Frequent | Likely | Occasional | Seldom | Unlikely |
|---|---|---|---|---|---|
| Catastrophic | Extremely High | Extremely High | High | High | Moderate |
| Critical | Extremely High | High | High | Moderate | Low |
| Marginal | High | Moderate | Moderate | Low | Low |
| Negligible | Moderate | Low | Low | Low | Low |
4. Risk Mitigation and Residual Risk Assessment
Risk mitigation is the identification, planning, and conduct of actions that will reduce the risk to an acceptable level. The mitigation effort can range from simple monitoring and/or acceptance of the risk to a full contingency plan calling for complete redundancy, with a correspondingly high cost. After mitigation is planned, the residual risk is assessed using the same classification. A risk identification and mitigation assessment worksheet records, for each risk, the initial effect, frequency, and impact; the mitigation; and the residual effect, frequency, and impact.
5. Risk Monitoring and Governance
Residual risks must be accepted through the governance framework — IT governance, and potentially corporate governance where business acceptance is needed. Once accepted, mitigating actions are carried out and monitored, and risk monitoring continues during Phase G.
Where Risk Management Is Used in the ADM
| ADM phase | Risk activity |
|---|---|
| Phase A | Step "Identify the Business Transformation Risks and Mitigation Activities" |
| Phase E | Step "Confirm Readiness and Risk for Business Transformation" |
| Phase F | Prioritize migration projects through cost/benefit assessment and risk validation |
| Phase G | Risk monitoring and governance of residual risks during implementation |
| Phase H | Step "Manage Risks" — manage EA risks and provide recommendations for IT strategy |
Worked Example
| Risk | Initial effect / frequency → impact | Mitigation | Residual effect / frequency → impact |
|---|---|---|---|
| Data migration corrupts customer records | Critical / Likely → High | Trial migrations, automated reconciliation, rollback plan | Marginal / Seldom → Low |
| Key supplier exits the market mid-program | Catastrophic / Seldom → High | Escrow of source code, second-supplier option | Marginal / Seldom → Low |
| Staff resist new claims process | Marginal / Likely → Moderate | Communications Plan, training, phased rollout | Negligible / Occasional → Low |
The residual risks are presented for acceptance through the governance framework before the Implementation and Migration Plan is finalized.
Common Exam Pitfalls
- Swapping initial and residual risk. Initial is before mitigation; residual is after mitigation.
- Letting the architect accept risk alone. Risks are first accepted and then managed within the governance framework.
- Using a generic probability scale. TOGAF's qualitative scheme uses effect (Catastrophic to Negligible) and frequency (Frequent to Unlikely) to derive impact.
- Thinking mitigation always means redundancy. Mitigation ranges from monitoring or acceptance to full contingency plans.
What is the difference between initial and residual levels of risk in TOGAF?
In TOGAF's qualitative risk assessment, which two dimensions are combined to determine a risk's impact?
According to the TOGAF Standard, where are risks first accepted and then managed?
A risk has an effect of Critical and a frequency of Likely. Using the TOGAF corporate risk impact assessment matrix, what is the impact?