Wednesday, June 26, 2013

Rolling the Dice without Risk



I love risk but I hate gambling.  Huh?  It's true.  I love taking risks that I can have an effect on the outcome.  I mountain bike, fly air planes and SCUBA dive.  All high risk activities to be sure but while these activities may have higher personal stakes than putting your chips n the line, at least I have a pretty large say in the outcome.  Same goes for business risks.  I don't mind taking risks but I want the odds and and control in my favor.

I was just working with a client the other day and as we were discussing the move into production I started asking how much risk still remained in the design.  One of the biggest areas of risk when dealing with a contract manufacturer is in production design changes.  It opens the door for a whole slew of cost growth from unused inventory costs to production tooling and process change costs.  Startup companies often deal with the fluidity in the design as a matter of course but in order to achieve low production costs the design must be fixed.  Here in lies a dilemma.  Startups need to move fast and rapidly evolve but volume production needs to stay fixed.  How do you deal with this dichotomy?  Manage the Risk.

Let me start by saying risk management will not make all the risk go away.  I have heard people say "Risk management didn't help at all, the stuff that killed us was stuff that wasn't even on the plan."  That's right.  That's the way it's supposed to work.  To borrow a very unpopular quote from a over a decade ago "There are things we know that we don't know, these are the known unknowns and there are things we know we don't know, these are the unknown unknowns".  Sounds like gibberish?  Nope.  Risk management simply deals with what know we don't know and if manage those risks effectively, it allows frees up bandwidth to deal with things we know are unknowns and if we deal with them in an orderly fashion, it allows us the bandwidth to deal with the surprises that come up along the way.

I have a fairly simple risk management recipe that I use and it has worked.  The last company I worked for was able to effectively use it to complete it's product design in very short order.  Yes, we had surprises but we weren't hopelessly mired in a dozen fires such that the surprise ground us to a halt.

I use a risk cube to keep track of the overall risk picture.  This plots probability of occurrence on the horizontal axis and impact of risk on the vertical axis.  Most people use a relative scale of 1 to 5 to rate the probabilities and impacts.  So, the upper right corner of the cube is where all the really bad stuff lives.  In this area you are pretty sure it is going to happen and if it does, things will be bad (project will be late, cost will be high, won't meet some spec, etc).

I start by listing all risks and if you have trouble here some places to look; new developments, tight specs, short schedules, and things you have had trouble with in the past.  Once you have your list, start assessing the likelihood of them coming true and their impact to place them on the cube.  Once you have that lies above the diagonal from the upper left corner to the lower right corner needs to have a mitigation plan.  You can decide if you want to deal with lower probability/impact risks but make sure you are dealing with the critical ones.  Here is Paul's first Risk Management Law Hope is not a Plan.  That means monitoring a large risk doesn't provide any value.  You need to have a strategy.  Sometimes it is a a backup approach, sometimes it is a design change, sometimes it is early testing to identify if the risk is really there but you MUST DO SOMETHING ACTIONABLE to address any highly probable significant risk.  No exceptions. 

The next step is you must review the plan on a regular basis.  The regularity is up to you but you must do it at defined intervals.  I have found weekly works best.  The review accomplishes several things.  First, you need to track the risk reduction plans to make sure they are on track and make any adjustments as necessary.  Second, you need to formally decide to retire risks and get them off the plan if they are truly retired.  Third and finally, you need to look for any new risks.  That's right, this is a dynamic plan.   When new risks emerge, they need to be added to the plan and go through the above process.

I am working with a team that has great product and they are rapidly heading towards production.  The problem is that the last step in their plan is a large scale test.  A great thing to do but when you look at the number of high risk things they need to validate in this test, it gets a little overwhelming.  As I went through the process it became clear that they needed to do a combination of lower level testing and come up with some alternate design approaches so when they got to the system level testing most of the lower level component risks had been retired and they will be able to focus on the large scale system behavior plus any of those unknown, unknowns.

Risk management isn't some mysterious process that involves probability theory and a Ouija Board.  It is simply ranking your risks according to severity, have a plan for the significant risks and updating the plan on a regular basis.  That's it.  There is nothing more to it than that.  If you follow this simple process, I can promise you your life will get better. 

No comments:

Post a Comment