78
6 Justifying the Need for New Approaches
Table 6.1 (continued)
Management specs
Risk evaluation specs
There is the need for governments to have the
ability to undertake or commission
independent reviews, particularly those related
to risk identification and management
People involved in a process, be it a project, a
company, a venture are not the best people to
build a risk assessment, because they are
biased. Third party intervention is absolutely
necessary
Communication has to be fostered thorough a
project and its risk assessment.
Communication allows building trust among
the parties
Don’t ever be afraid to ask questions, like a
child to people that know the system.
Generally they have become “blind” to their
risks
Consequences of hazard occurrences have to
be studied thoroughly: it is not enough to
define a few categories and then select the
worse as often suggested in PIGs applications
Past can never be assumed to equal the future.
At best it can be used as a point estimate
among others. Consequences are always
multidimensional and very with location, time,
etc.
Primary drivers of failure that often lead to
inadequate risk management are primarily due
to:
(1) Ignorance—not being sufficiently aware
of risks
Probability Impact Graphs (PIGs), which
constitute “common practices” in many
industries, don’t fly, because they are
misleading, lend to biases and censoring and
do not give a proper roadmap for future
development and risk mitigations
(2) Complacency—being sufficiently aware
of risks but being overly risk tolerant
and/or optimistic
Unless you understand what is manageable
versus Unmanageable, the future is going to
hurt
(3) Overconfidence—being sufficiently aware
of risks, over estimating ability to deal
with them with arrogance
Manageable risks are the one that can be
mitigated to become tolerable. Unmanageable
risk cannot be brought to be tolerable unless
the system is altered
Tolerance has to be defined in order to allow
proper decision making
Tolerance definition requires transparent
communication with stakeholders
As project evolve through their life there is a
requirement for comprehensive change
management procedures supported by rigorous
risk assessment methodologies
Risk assessment updates have to be simple and
information should be preserved and reused in
the cyclical needed updates
The same as above goes for operations,
monitoring and management, repairs
As above
Human factors that may contribute to failure
must be identified and addressed as they are
“hazards” like any other
Results cannot be delivered in a binary way:
“this system is safe”, or “risks are under
control” do not work anymore
Complexities like inter-dependencies and their
boosting effects have to be studied and
evaluated
Risk assessment has to include
inter-dependencies, common cause failures
(CCF) and cover 360-view of the hazard and
resulting risk landscape. Risk assessment has
to be convergent (all hazards are looked at, no
siloed information)
(continued)
6 Justifying the Need for New Approaches
Table 6.1 (continued)
Management specs
Risk evaluation specs
There is the need for governments to have the
ability to undertake or commission
independent reviews, particularly those related
to risk identification and management
People involved in a process, be it a project, a
company, a venture are not the best people to
build a risk assessment, because they are
biased. Third party intervention is absolutely
necessary
Communication has to be fostered thorough a
project and its risk assessment.
Communication allows building trust among
the parties
Don’t ever be afraid to ask questions, like a
child to people that know the system.
Generally they have become “blind” to their
risks
Consequences of hazard occurrences have to
be studied thoroughly: it is not enough to
define a few categories and then select the
worse as often suggested in PIGs applications
Past can never be assumed to equal the future.
At best it can be used as a point estimate
among others. Consequences are always
multidimensional and very with location, time,
etc.
Primary drivers of failure that often lead to
inadequate risk management are primarily due
to:
(1) Ignorance—not being sufficiently aware
of risks
Probability Impact Graphs (PIGs), which
constitute “common practices” in many
industries, don’t fly, because they are
misleading, lend to biases and censoring and
do not give a proper roadmap for future
development and risk mitigations
(2) Complacency—being sufficiently aware
of risks but being overly risk tolerant
and/or optimistic
Unless you understand what is manageable
versus Unmanageable, the future is going to
hurt
(3) Overconfidence—being sufficiently aware
of risks, over estimating ability to deal
with them with arrogance
Manageable risks are the one that can be
mitigated to become tolerable. Unmanageable
risk cannot be brought to be tolerable unless
the system is altered
Tolerance has to be defined in order to allow
proper decision making
Tolerance definition requires transparent
communication with stakeholders
As project evolve through their life there is a
requirement for comprehensive change
management procedures supported by rigorous
risk assessment methodologies
Risk assessment updates have to be simple and
information should be preserved and reused in
the cyclical needed updates
The same as above goes for operations,
monitoring and management, repairs
As above
Human factors that may contribute to failure
must be identified and addressed as they are
“hazards” like any other
Results cannot be delivered in a binary way:
“this system is safe”, or “risks are under
control” do not work anymore
Complexities like inter-dependencies and their
boosting effects have to be studied and
evaluated
Risk assessment has to include
inter-dependencies, common cause failures
(CCF) and cover 360-view of the hazard and
resulting risk landscape. Risk assessment has
to be convergent (all hazards are looked at, no
siloed information)
(continued)