What are the risks of Risk Management? - Chapter 15

What is the essence of claim 9?

As manager you spend a lot of time worrying about how to avoid risks. We have ethical, legal and financial responsibility for managing risks. Organizations have turned risk management into a specialty. They develop safety programs to reduce the chances of accidents.

But it isn’t possible to achieve perfect protection. So we have to make choices. We have to decide which risks to worry about and how to protect ourselves. Fortunately, there is a basic type of risk-management strategy that lets us to do just that.

The basic steps in effective risk management:

  1. Systematically identify the risks that might affect our plans.

  2. Focus on the most worrisome risks. We can do that by estimating the likelihood and the impact of each of the risks. Then we can calculate which risks pose the greatest threat.

  3. Develop risk mitigation plans to reduce the biggest ones and / or minimize their potential damage. These risk mitigation plans can set milestones for progress, and can alert us when our safety margin is getting too small.

  4. Implement these plans.

  5. Track whether the risk-mitigation plans are working. If a project begins to run into trouble, we increase our monitoring. We identify new risks and iterate the process.

These 5 steps promise to help us manage the risks to which we are exposed.

Claim 9: Our plans will succeed more often if we identify the biggest risks and find ways to eliminate them.

The risk management strategy works effectively in well-ordered industries that have enough experience to reliably identify the risks in advance. In contrast, we struggle to apply these 5 steps to risk management in complex projects.

How can the risks be identified?

Working in well-ordered situations in mature industries, risk analysts can use historical data to compile lists of risk factors, making step 1 go more smoothly. In complex situations, in which context affects what can go wrong, these lists become less helpful.

When we look at projects that failed, the most devastating risk factors often turn out to be things no one expected or was even thinking about.

When people are unfamiliar with the landscape, we shouldn’t have high expectations for this first step of the risk-management process.

The risks of speaking out

One of the barriers to carrying out step 1 of the RM process is that people are often unwilling to publicly describe potential problems. Even when organizations have people who notice the early signs of problems, they may be unwilling to speak out because they are afraid of disrupting the harmony of the team. And they are afraid of being ostracized and marginalized.

Authentic dissenters or “devils advocates” want to critique plans and find weaknesses. Autentic dissenters may be disliked even when they have helped the group to do a better job.

The PreMortem method also described in chapter 4 encourages team members to identify risks at the beginnings of the project to get all the concerns on the table. The PreMortem method asks the team members to imagine that a plan or project has failed. The PreMortem method doesn’t ask anyone to take on the role of devil’s advocate.

The PreMortem method shows the team that authentic dissent is valued, and that everyone can contribute by flagging potential problems. This way of trying to identify risks at the start seems to keep the project team alert and to prevent the team from fixating on a plan it may have to change or fixating on goals it may have to replace.

However, it can’t identify all the risks.

Where lies the focus on the most worrisome risk?

Estimate the probability and the impact of each risk, then calculate which risks pose the greatest threat. The formal way to carry out this process is Probabilistic Risk Assessment. It lets you enter objective judgments of the probability and the impact of each risk you have identified and then calculate the risks you most need to worry about.

Problems: Everything is changing, there is no generic checklist of risks for example. Probabilities aren’t stable and past data aren’t necessarily relevant. Conditions change. Even without these complications, step 2 of the RM process depends on accurate estimates of probabilities and impacts. But we are notoriously bad at generating these kinds of estimates.

Methods of risk and reliability assume that a system can be described as parts, or subsystems, that can each fail with a certain probability. Although this bottom-up approach to risk and reliability analysis has been highly successful for technological systems, it is ill suited to understand failures of humans or socio-technical systems. These systems cant meaningfully be decomposed into parts. Their parts interact strongly, and they interact differently depending on the context. RM calculations reassure us, because they are so quantitative and official looking. However, numerical calculations can disguise overconfidence.

What are risk-mitigation plans?

The risk mitigation plans should protect us by reducing the main risks and / or minimizing their potential damage. These plans describe what we should keep an eye on, when we should sound an alarm, and how we should react in case of a problem.

Paradoxically, in unpredictable environments the risk defenses can become part of the problem. Mintzberg points out that planning reduces commitment and reduces flexibility. Once a plan is developed, the managers relax because they have safeguards in place. People in the organization may lower their guard, believing that the risk-mitigation plans have ensured their safety.

Weick and Sutcliffe note that plans create mindlessness instead of mindful anticipation of the unexpected.

They identified three ways that plans, such as risk-mitigation plans can reduce mindfulness:

  • Plans sensitize us to expect some things, but that mean ignoring other things that we don’t expect.

  • Plans tell the organization how to react, so they may not notice how their organizations’ capabilities have eroded.

  • Routines can’t handle novel events, but plans are built around routines.

These limitations don’t mean that we should stop making any plans but rather that we should realize that planning will not guarantee success and may actually increase the risks. RM plans are built to counter the previous threats that were encountered, but may get in the way of noticing and reacting to the next threats. RM plans can themselves introduce risk.

Implement the risk-mitigation plans

What happens each time the project plan itself changes? Each of these alterations can change the risk profile. Must risk managers continually revise their mitigation plans?

RM plans still rely on safety officers, who tend to become co-opted by the managers simply by working together harmoniously. Most attempts to set up alarm systems fail, because the alarms get ignored.

How to track whether the risk-mitigation are working?

If a project starts to run into trouble, we increase our monitoring. We also identify and iterate the process. Our tracking will necessarily increase as the plan itself runs into difficulty. If we are managing project that is having trouble, we need our energy to recover. The successes of RM are in well-ordered projects, in mature industries. Risk-management specialists get angry with me for questioning their methodology. They point to all the places that use risk management, but they haven’t shown me any data demonstrating that the methods do any good under complex conditions.

Three different concepts of ‘risk’

We can distinguish at least three different ways people think about risk, exemplified by:

  1. The safety officers who use a prioritize and reduce strategy.

  2. Calculate-and-decide strategy.

  3. Program managers who use a threat avoidance strategy.

Prioritize and reduce: Only applies to people such as safety officers and risk managers. They are the ones who try to carry out the five-step strategy and who use Probabilistic Risk Assessment to quantify the risks they face.

A risk is here a potential adverse event that has a given probability of occurring and an impact that can be estimated. The RM approach estimates probabilities and impacts in order to prioritize which risks to worry about the most. The prioritize and reduce approach comes into play when we need to preserve assets that may be jeopardized, or when we need to safeguard project plan. It makes the most sense for well-ordered domains.

Calculate and decide: Decision researchers define risks in terms of gambles.

Example: When you flip a coin, you know the chance of it coming up heads is 50 percent, and when you wager money on that outcome you can calculate the chances of winning. If you invest that money in a treasury bill, the rate of return is much smaller than the gamble on the coin flip, but the chance that you will lose your money is also much smaller.

In this sense of risk, actions lead to known outcomes that occur with specific probabilities. Investors rely on the calculate-and-decide framework. They are happy with risk as long as it has the appropriate potential for reward. The goal of investors is to make good gambles, in relation to the level of risk they accept.

Anticipate and adapt

Chief executive view risks as threats. They want to avoid threats, but they know that they will have to take some gambles in order to reap the reward. Therefore, they try to manage the risks, but in a different way than the risk management school describes.

The CEO’s methods of approaching risk are different from the calculate-and-decide methods that decision researchers use. That explains why CEOs don’t listen to the researchers. The CEO approach to risk is also different from the approach of the risk-management school, which advocates the prioritize-and-reduce strategy, with its emphasis on quantitative prioritization. That strategy may be relevant for some mature industries, but not for the complex challenges.

Unintended consequences

Claim 9 (that our plans will succeed more often if we identify the biggest risks and then find ways to eliminate them) will make us overconfident when we are in complex and ambiguous situations and we are unlikely to identify the biggest risks in advance and unlikely to be able to eliminate them.

Replacement

In complex situations, we should give up the delusion of managing risks. We can’t foresee or identify risks, and we can’t manage what we can’t see or understand. Too often risk management gets aimed in the wrong direction.

Weick, Suttclife and Obstfeld contrasted the culture of high reliability organizations to the culture of organizations that suffer higher accident rates. The high-reliability culture prefers to learn from the near misses rather than wait to learn from accidents. Their culture expects all workers to stay alert for any anomalies. The difference in mindset gives them a greater ability to anticipate, avoid and manage.

The concept of an adaptive mindset has given rise to a new discipline of resilience engineering. Woods and Hollnagel and others have described resilience engineering as a means of designing projects, organizations, and systems to be adaptable and to withstand unpredictable risks. Resillience engineering seeks to improve an organization’s ability to reconfigure in order to manage unexpected disturbances. Resilience engineering can be thought of as risk management by discovery.

The replacement for claim 9 is that we should cope with risk in complex situations by relying on resilience engineering rather than attempting to identify and prevent risks.

Resilience engineers don’t wait for accidents or black swans. They assess the way the organizations responded to small disturbances in the past.

Why does claim 9 matter?

It matters because the 5 step process that works nicely in well-ordered settings is usually not effective for managing risks in unpredictable settings. Worse is that such a process can lull an organization into complacency.

It matters because organizations that try to eliminate risk are playing so as not to lose, which increases the chances that they will lose.

It matters because we need to develop resilience as a tactic for protecting ourselves against risk.

It matters because we need to develop resilience as a tactic for protecting ourselves against risk. We need to engage in Risk Management by Discovery.

As manager you spend a lot of time worrying about how to avoid risks. We have ethical, legal and financial responsibility for managing risks. Organizations have turned risk management into a specialty. They develop safety programs to reduce the chances of accidents.

But it isn’t possible to achieve perfect protection. So we have to make choices. We have to decide which risks to worry about and how to protect ourselves. Fortunately, there is a basic type of risk-management strategy that lets us to do just that.

Image

Access: 
Public

Image

Join: WorldSupporter!

Join with a free account for more service, or become a member for full access to exclusives and extra support of WorldSupporter >>

Check: concept of JoHo WorldSupporter

Concept of JoHo WorldSupporter

JoHo WorldSupporter mission and vision:

  • JoHo wants to enable people and organizations to develop and work better together, and thereby contribute to a tolerant and sustainable world. Through physical and online platforms, it supports personal development and promote international cooperation is encouraged.

JoHo concept:

  • As a JoHo donor, member or insured, you provide support to the JoHo objectives. JoHo then supports you with tools, coaching and benefits in the areas of personal development and international activities.
  • JoHo's core services include: study support, competence development, coaching and insurance mediation when departure abroad.

Join JoHo WorldSupporter!

for a modest and sustainable investment in yourself, and a valued contribution to what JoHo stands for

Check: how to help

Image

 

 

Contributions: posts

Help others with additions, improvements and tips, ask a question or check de posts (service for WorldSupporters only)

Image

Image

Share: this page!
Follow: Psychology Supporter (author)
Add: this page to your favorites and profile
Statistics
3292
Submenu & Search

Search only via club, country, goal, study, topic or sector