Your Risk Matrix Is a Lie

15. Juni 2020
Kategorien
Newsletter abonnieren

Your Risk Matrix Is A Lie
Risk management is at the core of good project management. 
 
Or as Tim Lister says “Risk management is project management for adults”.  
 
The standard approach is to use a risk matrix to classify project risks based on their probability and impact, then give each one a ‘risk score’ by multiplying the two numbers. Then you rank the risks by score and address the top ones first. 
 
Risk matrices have been widely praised and adopted as simple but effective approaches to risk management. 
Your Risk Matrix Is A Lie
And as many risk matrix practitioners and advocates have pointed out, constructing, using, and socializing risk matrices within an organization requires no special expertise in quantitative risk assessment methods or data analysis.
 
So in terms of “understanding and managing risk”, it seems to work.
 
Unfortunately it doesn’t.
 
It is unfit for purpose. It actually may even be doing more harm than good.

Sh!t in, sh!t out

Things go wrong from the very start. Namely with the probability estimates you put into your risk matrix.
 
Human beings are not very good with non-linear risks. Our instincts evolved to help us deal with immediate physical dangers in our environment. So we can tell whether an oncoming car is likely to hit us, for example. 
 
But the more complex the risk, and the more factors are involved, the less helpful our gut instinct is. And project management risks are some of the most complex risks in the world.
 
It’s extremely difficult to say how likely it is that an information breach or ransomware incident will actually occur. So most people rely on gut instinct, on the grounds that it’s better than nothing.
 
But if you ask someone to gauge the likelihood of a project risk — even someone with very deep knowledge — they will be hard pressed to give you an accurate answer. For instance, what’s the likelihood of a key supplier or system integrator going bust? Is it low, medium or high? Why do you say that? How do you know?
 
It’s a similar story with impact. In theory, it’s easier to get a reasonably good idea of financial impact by thinking about management time, developer hours, lost sales and reputation damage. But people rarely bother, because the risk matrix is only asking for a simple assessment anyway.

Enter the matrix

So the information you put into your risk matrix is hopelessly inaccurate. But then the matrix itself makes things even worse.
 
Because these matrices have such a low resolution, they make very different risks look alike. For example, in a 3×3 matrix (low, medium, high on both axes), risks with 67% probability and 99% probability are both “high”. 
 
Clearly, you’d want to address the 99% risk first. But when you come to rank your risks, you have no way of knowing which one is worse based on the matrix.
 
What’s more, the matrix gives equal weight to probability and impact, so an incident with 1% probability and $500,000 impact has the same priority as one with 0.2% probability and $2,500,000 impact.
 
In fact, in some fairly common situations (mathematically speaking, when probability and impact are negatively correlated), you’d actually be better off choosing the matrix square at random. 
 
Yes, you read that right — pin your matrix to the wall, throw a dart for each risk and you’ve got a better chance of picking up the most important ones. 
 
The risk matrix can be, quite literally, worse than useless.

Dangerous illusion of control

The problem with the risk matrix is that it feels scientific. It promises a quick, simple solution to a wicked problem without taking up loads of time, or asking you to do too many hard computations.
 
Before, you had no idea about risks. But now, you’ve put them in neat little boxes and given them solid-sounding scores. You “understand and manage your risks”, or so it seems.
 
But all you’ve really done is creating a story that gives you a dangerous illusion of control.
 
Not only is there no proof that risk matrices work, there’s actually proof of the opposite. 
 
Using the matrix actively hampers firms’ efforts to deal with risk, absorbing time, money and effort for no benefit at all
 
In a nutshell: Don’t rely on your risk matrix to understand and manage your risk.
Tags

Das könnte Sie auch interessieren

The Five Elements of a Strong Governance Structure for Critical Projects

16. Januar 2025

Every executive has nightmares about that project—the one that spirals into an unmitigated disaster.  In general there are four ways a project can end up in a boardroom-shaking failure that can destroy value, reputations, and trust in one fell swoop. 1. The Titanic Failure: The project chugs along, oblivious to the iceberg ahead, burning millions

Weiterlesen

Why Every Critical Project Needs Independent Reviews

14. Januar 2025

«Trust, but verify.» That timeless adage applies as much to critical projects as it does to diplomacy. Without an independent review, even the best-run projects can veer off course, leaving organizations blindsided by delays, cost overruns, or outright failures. Here’s the uncomfortable truth: internal stakeholders are often too close to the project to see the

Weiterlesen

Why Every Critical Project Needs an Executive Sponsor

13. Januar 2025

Launching a critical project without an executive sponsor is like sending a ship to sea without a captain—good luck steering through the storm. Projects don’t fail because of bad intentions. They fail because of a lack of alignment, authority, and support.  That’s where the executive sponsor steps in—not just as a figurehead but as the

Weiterlesen

Why Every Critical Project Needs a Dedicated Project Manager

12. Januar 2025

Far too often, organizations assign critical projects to people who already have full-time roles or, worse, delegate management to a loosely organized team with no single point of accountability. The results? Missed deadlines, blown budgets, and a whole lot of finger-pointing. Here’s the hard truth: if the project is important, it deserves a dedicated project

Weiterlesen

Case Study 21: The Australian Securities Exchange (ASX) $250 Million CHESS Blunder

6. Januar 2025

The Australian Securities Exchange (ASX) embarked on an ambitious journey to replace its 25-year-old Clearing House Electronic Subregister System (CHESS) with a state-of-the-art, blockchain-based platform.  Initially envisioned as a groundbreaking project to enhance efficiency, security, and scalability, the CHESS replacement project quickly turned into a cautionary tale.  The initiative faced repeated delays and escalating costs

Weiterlesen

Project Recovery

2. Januar 2025

  Projects fail for a variety of reasons. Especially technology projects have a low success rate. Typically more than half of them are considered a failure. If your current in-house or outsourced software or web development project is off track, chances are I can bring the necessary input and expertise to get the job done. Troubled projects

Weiterlesen

When $100 Million Technology Projects Fail, It’s the Board’s Fault—Every Single Time

2. Januar 2025

In Switzerland, rumors suggest that both Bank Julius Bär and Raiffeisen Schweiz are grappling with failed technology projects, each costing over $100 million so far. Bank Julius Bär is reportedly trying to replace its existing core banking system for the Swiss booking center with Temenos, while Raiffeisen Schweiz is attempting to build a modern e-banking

Weiterlesen

10 Essential Questions Every Board Should Ask About Technology

16. Dezember 2024

Board members play an important role in steering organizations through the complexities of technology initiatives.  To fulfil this role effectively, it’s essential to ask the right questions that probe the strategic, operational, and risk aspects of technology projects.  Here are ten critical questions every board should consider: 1) How does this technology initiative align with

Weiterlesen

Independent Board Advisory

16. Dezember 2024

Effective boards provide clarity, governance, and oversight to steer organizations toward success. However, large technology initiatives, digital transformations, and innovation efforts often challenge even the most seasoned boards.  My Board Advisory service empowers boards and board members to navigate the complexities of modern technology decisions with confidence and precision. As a trusted advisor and experienced

Weiterlesen

Case Study 20: The $4 Billion AI Failure of IBM Watson for Oncology

7. Dezember 2024

In 2011, IBM’s Watson took the world by storm when it won the television game show Jeopardy!, showcasing the power of artificial intelligence (AI). Emboldened by this success, IBM sought to extend Watson’s capabilities beyond trivia to address real-world challenges.    Healthcare, with its complex data and critical decision-making needs, became a primary focus. Among

Weiterlesen
Next