Most Croatian companies, especially smaller ones, still plan the risks of new projects by intuition. This is often detrimental to the project, which is why risks need to be managed systematically, paying full attention to both large and small ones. Only with a good risk assessment can one decide whether to embark on a project or abandon it.
Risk management is one of the ten knowledge areas in project management, an area that cannot be overlooked in any project, regardless of its size. A risk is, by definition, something that can negatively or positively affect the project. The probability of a risk occurring is greater than zero percent and less than one hundred percent, and if it occurs, it affects at least one of the project’s objectives. For example, exchange rate differences can positively and negatively affect project goals. In project management, every organization, whether private or public, should effectively incorporate risk management to reduce negative impacts on project objectives. Risks should not be managed haphazardly and partially, which I often encounter in practice on projects led by ‘self-taught’ project managers who frequently overlook many negative impacts and neglect the positive ones.
Risk Register
The first step in risk management is identification. This requires being aware of all factors that affect the project, as well as scenarios and events that may occur. Risks on the project are identified by all team members. Those who are not directly involved in the project can also participate. During identification, it must always be written in the form of ’cause – risk – consequence’. For example, due to time constraints on the project, there is a risk that people will be dissatisfied due to overwork, which may lead them to leave the project, causing delays.
Risks described in this way can be easily sorted; thus, it is easy to see which factor causes the most risks. It is important to note that in this process, their probability or impact is not assessed, but they are recorded in the so-called risk register, a fundamental document for risk management. Once risks are identified, they are qualitatively analyzed. This is a subjective risk assessment. The result of this step is risk exposure, where major risks are identified, which deserve constant attention, and minor risks, which are on the ‘watch list’, but are no less important.
First Analysis and Planning
The project manager is solely responsible for monitoring the risks on that list. For them to be successful, among other things, they need to be qualified, reliable, and composed in order to approach the situation comprehensively, as panic and defeatism in a crisis are often riskier than the problem at hand. After the risk exposure phase, the first analysis is conducted to determine whether the project continues or is halted due to excessive riskiness. The next step is planning how to deal with risks if they occur.
