Att_4_TTP_for_Integrating_Risk_Into_Program_Plans_doc_v1.0.pdf
PDF 854 KB Posted
- Attached to
- Business Transformation Federal contract opportunity
- Solicitation number
- FA7014-16-R-3004
About this file
Integrating Risk into Program Plans v1.0
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Draft_solicitation_combined_questions_sheet_-_final_3_21_16_V2.pdf | ||
| Att_1_TTP_for_Work_Breakdown_Structure_doc_v1.0.pdf | ||
| Att_2_TTP_for_Integrated_Master_Schedule_doc_v1.0.pdf | ||
| Attachment_1_DD_254_Item_13_continuation_20_Oct_15_(1).doc | DOC document | |
| Att_5_TTP_Impact_Analysis.pdf | ||
| BT_IDIQ_PWS_Reviewed_-_3_1_16.docx | DOCX document | |
| Tab_2_DRM_Handbook_in_AF_BMA_20160113_MG_signed.pdf | ||
| Att_3_TTP_Schedule_Based_Estimating_doc_v1.0.pdf | ||
| Attachment_3_BT_FOOU.docx | DOCX document | |
| Attachment__2__VGSA__BT_12_11_15_ISPM_Draft_Sig.pdf | ||
| Attachment_1_Pricing_Sheet_(1).xlsx | XLSX spreadsheet | |
| BT_T.O._01_PWS_V1.1PK.docx | DOCX document | |
| Attachment_1_Pricing_Sheet_(1).xlsx | XLSX spreadsheet | |
| FA7014-16-R-3004_draft_RFP_19_Feb_16.pdf | ||
| Attachment_4_DD254_BT_03_Dec_15_signed.pdf |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
TTP for Integrating Risk into Program Plans v1.0
22 July 2014
AIR FORCE TACTICS,
TECHNIQUES AND PROCEDURES
TTP FOR INTEGRATING RISK INTO PROGRAM PLANS V1.0
22 JULY 2014
VERSION 1.0
UNCLASSIFIED
THIS PAGE INTENTIONALLY LEFT BLANK
Support
For additional information or questions about this document refer to:
https://cs.eis.af.mil/afdbt/afee/
Series
This series of Air Force (AF) Tactics, Techniques and Procedures (TTP) includes:
Version Management
Name and Rank Date
Summary of Changes
Name of Change Author Approval Date
Table of Contents
Support
Series
Version Management
Summary of Changes
Table of Contents
Table of Figures
1. Introduction
2. SDDP Applicability
3. Integrating Risk into Program Plans
3.1 Entry Criteria
3.2 Procedures
3.2.1 Step 1: Establish and Populate a Risk Register
3.2.2 Step 2: Determine Which Risks Require Mitigation Activities
3.2.3 Step 3: Develop Risk Mitigation Plans
3.2.4 Step 4: Integrate and Resource Load Risk Activities into Schedule
3.2.5 Step 5: Monitor and Report Metrics on Risk Mitigation Activities
4. Conclusion
Appendix A: DOTMLPF-P Implementation Plan Development (SDDP Step 2)
Appendix B: M-Implementation Plan Development (SDDP Step 3)
Appendix C: Program Plan Development (SDDP Step 4)
Appendix D: Program Risk Register Example
Appendix E: BOE Capture Form Example
Acronyms
Table of Figures
Figure 1: Integrated Risks in the Program Schedule
Figure 2: TTP for Integrating Risk into Program Plans SDDP Applicability
Figure 3: Risk Register Example
Figure 4: Sequence Risk Mitigation Activities
Figure 5: Link Completion of Risk Mitigation Activities
Figure 6: Risk Mitigation Actions
Figure 7: Risk Management Results
Figure 8: Risk Register Example
Figure 9: Basis of Estimate Form Example
1. Introduction
Risk planning is a core activity for any capability delivery initiative, beginning from the moment a user describes a problem or identifies a mission need, until a capability is delivered that resolves that need. As the initiative moves forward, identified risks must be analyzed in order to determine effective mitigation activities. These risk mitigation activities must be integrated into program plans, with resources, duration and costs. Milestones should also be entered in the schedule to effectively monitor risk mitigation activities, assess the continued probability of the realization of the identified risks, and report results through regularly scheduled risk performance measurement reporting.
This Tactics, Techniques and Procedures (TTP) document provides instruction and guidance for performing the following:
Determining which risks require mitigation activities
Developing risk mitigation plans
Integrating and resource loading the risk mitigation plans into the program schedule
Illustration of monitoring and reporting metrics on risk mitigation activities which will be further detailed in a TTP for Program Control
In addition to describing how to integrate risks into program plans, this TTP provides direction for continuously conducting risk activities to effectively manage priority risks throughout the lifecycle to assure successful delivery of mission capabilities to the Warfighter.
2. SDDP Applicability
The Air Force (AF) Service Development and Delivery Process (SDDP) generates necessary and sufficient program requirements, documentation, and planning to support rapid user-centric solutions to Warfighter needs and enables early program planning activities. The TTP for Integrating Risk into Program Plans is applicable to work plans prepared to support actions associated with the execution requirements. All identified risks from various sources throughout the lifecycle should be documented in the Program Risk Register. The following TTPs have provisions, and/or describe steps, for identifying risks:
TTP for Work Breakdown Structure (WBS)
TTP for Integrated Master Schedule (IMS)
TTP for Schedule-Based Estimating
The TTP for Integrating Risk into Program Plans is initiated during SDDP Step 2, and is used to proactively manage throughout the program, coming to a completion at SDDP Step 6, as illustrated in Figure 2. The black arrows representing the Risk TTP/Risk Register touch points to other outputs, and the bidirectional arrows feed into the IMS, Schedule-Based Estimating, and Impact Analysis
TTPs. Additionally, one arrow represents a single feed from IT Capability Testing into the TTP for
Integrating Risk into Program Plans.
Figure 1: TTP for Integrating Risk into Program Plans SDDP Applicability
When the Program Team builds the detailed IMS for the Materiel (M)-solution, the Program
Management activities in the schedule should contain subordinate activities called Risk
Management. Identified risk mitigation activities will be integrated into the schedule and resource loaded. For each priority risk, the planned mitigation activities, dates, and cost of assigned resources should be captured in the schedule. An example of the M-Solution schedule reflecting integration of risk into program plans and the required risk mitigation activities is depicted in Figure 1.
Figure 2: Integrated Risks in the Program Schedule
Specific instructions, provided in the appendices, tailor the process of integrating risk into program plans as information becomes available through the sequenced steps of SDDP.
A. In support of the Doctrine, Organization, Training, Materiel, Leadership, Personnel, Facility and Policy (DOTMLPF-P) Implementation Plan required in SDDP Step 2 – resource loaded risk mitigation activities for the Doctrine, Organization, Training, Leadership, Personnel, Facility and Policy (DOT-LPF-P) actions that implement the reengineered business processes of the Business Reference Model (BRM) are identified using the process described in
Appendix A. These mitigation activities will be integrated into the IMS associated with the
DOTMLPF-P Implementation Plan.
B. For the M-Implementation Plan required in SDDP Step 3 for a Deployable Capability – the integration of risk mitigation activities into the IMS associated with the M-Implementation
Plan following the process in Appendix B.
C. During SDDP Step 4 where a formal IMS is required for the M-Solution, the mitigation activities are resource loaded in the schedule. Each risk mitigation activity should include duration, target start/complete dates, and cost as described in Appendix C.
3. Integrating Risk into Program Plans
The primary stakeholders for integrating risks into program plan activities includes the Sponsor, Cost
Estimating Team, Acquisition Program Manager, and Risk Manager (depending on initiative).
3.1 Entry Criteria
As part of Program Planning activities, risk identification sessions were conducted and attended by key stakeholders during the development of the WBS (see TTP for Work Breakdown Structure), IMS (see TTP for Integrated Master Schedule) and Cost Estimates (see TTP for Schedule-Based
Estimating). Depending on where an initiative is within the SDDP lifecycle, any applicable policies/procedures, agency/organization risk posture, or program risk tolerance may apply. Each risk is identified in the Basis of Estimates (BOE) Form by the Estimating Team and the cost and/or schedule impact associated with each risk has been quantified through analysis. Refer to Appendix
E for a BOE Capture Form example.
3.2 Procedures
Integrating risk into program plans is performed by the following five steps.
3.2.1 Step 1: Establish and Populate a Risk Register
The goal of Step 1 is to establish and populate a Risk Register that contains all known risks for the program. The Risk Register serves as a vital tool for capturing, analyzing and updating the status of risks. It also supports continuous tracking of a program’s risk posture and status of mitigation activities.
Detailed Actions:
1. Select a Risk Register tool such as Active Risk Manager (ARM), Microsoft Access or an
Excel spreadsheet. Note: The tool must support the ability to sort data numerically and alphabetically.
2. Ensure the Risk Register allows for entry of discrete records (or rows) for each identified risk and includes, at a minimum, the following fields: a unique Risk Identifier (ID), Risk
Description, Risk Source, Risk Category, Probability, Impact, Risk Score (the product of a given risk’s Probability and Impact), Risk Response, and Risk Priority.
a. Record the value for Probability (from 1 to 5) and for Impact (from 1 to 5) in the Risk
Register as well as the product of a risk’s Probability and Impact (Probability Score x
Impact Score) as the Risk Score.
i. Probability Scores range from Not Likely (1) to Near Certainty (5)
ii. Impact Scores range from Minimal or No Consequence (1) to Severe
Degradation or Jeopardize Program Success (5)
iii. See the DoD guide for risk management for further guidance on Probability and Impact scoring found here: http://www.acq.osd.mil/se/docs/2006-RM-
Guide-4Aug06-final-version.pdf
3. Enter all identified risks into the Risk Register from the sources described 3.1 Entry Criteria as well as risk mitigation activities and resources identified from WBS, IMS and BOE work.
4. Sort the Risk Register using the risk score to prioritize from highest to lowest value.
a. Risk Score of 15 or higher is consider “High Risk”
b. Risk Score of 8 and less than 15 is considered “Moderate Risk”
c. Risk Score below 8 is “Low Risk,” with the exception of an Impact Score of 5 and
Probability of 1 which should be treated as “Moderate Risk” due to impact potential
5. Conduct a meeting attended by program’s stakeholders to review the sorted Risk Register and verify the data and rating for each risk. Record any noted corrections in the Risk Register as required.
The expected outcome of Step 1 is a documented list of risks recorded in the program’s Risk Register.
See Figure 3 (also shown in Appendix D) for a Risk Register example.
http://www.acq.osd.mil/se/docs/2006-RM-Guide-4Aug06-final-version.pdf http://www.acq.osd.mil/se/docs/2006-RM-Guide-4Aug06-final-version.pdf
Risk
ID
IMS
Number Risk Description
Risk
Source
Risk
Category
Risk
Trigger
Proba bility Impact
Risk
Score
Risk
Response
Risk
Priority
MIL-
1.5.1
Poor definition of
DT&E test and evaluation criteria
Test Plan Technical
Performanc e
High #
Defects 4 3 12 Mitigate High
MIL-
1.3
Personnel unavailable due to staffing delays causes delay in validation
Onboardi ng Plan
Schedule
Missed
Milestone s
1 1 1 Accept Low
MIL-
1.6.3
Two extra rooms required within training facility
Training
Plan Physical
Training
Delays 4 1 4 Transfer Low
MIL-
1.7.5
Data compatibility when migrating from Legacy to new GOTS
Data
Reference Model
Technical
High #
Conversio n Errors
2 4 8 Mitigate Moderate
** Note: Risk Priority = High to Moderate requires detailed Mitigation Plan and Integration with Program Plan
Figure 3: Risk Register Example
3.2.2 Step 2: Determine Which Risks Require Mitigation Activities
The goal of Step 2 is to assess the priority of the risks identified and select the high to moderate risks that require detailed mitigation activities. Not every identified risk requires a plan of action with resourced activities. The Program Team must decide which risks will be addressed, based on the premise that there will never be enough time and resources to respond to all risks.
Detailed Actions:
1. Access the current version of the Risk Register.
2. Sort Risks from Highest to Lowest Score.
3. Optionally - apply a secondary sort on Risk Category to place focus on certain program aspects such as technical, cost or schedule.
4. Apply any additional criteria driven by the organization’s or program’s risk “tolerance” to further refine priority and “draw the cut line” –determining which risks will be mitigated based on objective criteria and priority.
5. Review, with the program’s stakeholders and risk owners, and verify the rating and disposition for each risk, making corrections as appropriate in the Risk Register.
The expected outcome of Step 2 is the documented list of prioritized risks with an indicator for items that require detailed risk mitigation activities. The Risk Register must be updated with an indicator to denote priority risks.
3.2.3 Step 3: Develop Risk Mitigation Plans
The goal of Step 3 is to analyze each priority risk and consider viable options to determine an effective
Risk Mitigation Plan to mitigate the risk threat.
Detailed Actions:
1. Select the set of high to moderate priority risks to be analyzed from the Risk Register.
2. If options and approaches to mitigate risks are incomplete from WBS, IMS and BOE work, conduct brainstorming sessions with the Sponsor, Program Team and key stakeholders (e.g.
functional users, technical leads, and estimating leads) to discuss viable options and supporting mitigation activities (both materiel and resource driven) for each risk.
3. Confirm technical, scope and/or cost impacts of the mitigation activities.
4. Select the best option for each risk to minimize exposure and reduce probability/impact.
5. Build a mitigation plan for each risk describing the selected option and detailed activities required.
6. Sequence the risk mitigation activities to prepare to integrate them into the IMS (Figure 4).
Figure 4: Sequence Risk Mitigation Activities
The expected outcome of Step 3 is a set of Risk Mitigation Plans describing the approach and detailed sequenced risk mitigation activities for each priority risk.
3.2.4 Step 4: Integrate and Resource Load Risk Activities into Schedule
The goal of Step 4 is to integrate the risk mitigation activities into the IMS, including resources and materiel to support each task. The duration, milestones and cost of each risk mitigation activity will also be determined once the resources have been loaded in the IMS.
Detailed Actions:
1. Access the IMS, Risk Register and all Risk Mitigation Plans.
2. Under the Risk Management section of the schedule, create a Task for each priority risk. To support traceability, use the Risk ID# for the Task Description.
3. Review the TTP for Integrated Master Schedule for additional guidance on integrating activities into the IMS.
4. Enter all required risk mitigation activities for each risk.
5. Enter milestones for each risk to measure performance and completion status.
6. Identify resources to perform each risk mitigation activity.
7. Determine the planned duration for each risk mitigation activity based on the resource’s level of experience, availability (e.g. 25%, 50%, 75%, and 100%) and estimated level of effort. The best practice is to allow the IMS to be “duration-driven” and to avoid “hard coding” start/planned end dates if possible.
8. Link completion of Risk Mitigation with the appropriate Management Review in the IMS as shown in Figure 5.
Figure 5: Link Completion of Risk Mitigation Activities
9. Determine the planned cost of each risk mitigation activity if resource rates are loaded in the scheduling tool. See the TTP for Integrated Master Schedule for reference.
10. Repeat Detailed Actions 4-9 for all risk mitigation plans.
The expected outcome of Step 4 is the IMS loaded with risk mitigation activities, milestones, required resources, and the planned duration and cost.
3.2.5 Step 5: Monitor and Report Metrics on Risk Mitigation Activities
Steps 1-4 complete the integration of risk into program plans. Step 5 is provided for illustrative purposes and will be further detailed in a TTP for Program Control. The goal of Step 5 is to prepare to actively monitor the risk mitigation activities and provide status on performance metrics such as:
Risk Activity Tracking (schedule planned vs. actual) with corrective actions/thresholds
Return on Investment (ROI) of Risk Mitigation Actions
Detailed Actions:
1. Implement a process to routinely monitor risk mitigation activities captured in the IMS, which are typically an element of the Program Control function performed by the Management
Team. Evaluate the progress and effectiveness of the planned mitigation activities, including milestone status.
2. Update the Risk Register to reflect changes in the risk event, probability or impact due to mitigation activities.
3. Document proposed revisions to current mitigation activities based on analyzed results of changes to the risk event including cost and schedule impacts:
More or less cost required (resource or materiel)
More or less time required (schedule duration)
4. Document when risks no longer present a threat and include the planned and actual costs of the risk(s) in a Monthly Performance Metrics report.
5. Prepare a Monthly Performance Metrics report capturing analysis of risk performance and current status of risk activities.
Two metrics are captured to measure performance of the risk management activities. Figure 6, Risk
Mitigation Actions, shows the status of risk activities relative to the planned risk mitigation activities.
Since risk management activities are by their very nature critical to an initiative’s success, their timely completion should be held to the highest standards in terms of planned versus actual execution.
Figure 6: Risk Mitigation Actions
Figure 7, Risk Management Results, provides an indication of the efficacy of a program’s risk management activities and their resulting reduction in overall risk profile over time. As risk mitigation is a form of “insurance,” it is expected that for every dollar invested in risk mitigation, the overall risk exposure of the initiative should decline by several times the investment. (The example shows a cumulative ROI represented by the green trend line of approximately 6 as of August 2011.)
Figure 7: Risk Management Results
The expected outcome of Step 5 is critical information to assess the value of efforts taken to minimize risk exposure. Senior leadership can assess overall performance of a Program or a specific risk mitigation action based on risk ROI. Effective planning of risk activities can be determined by assessing plan/actual durations and costs.
4. Conclusion
Integrating risk into program plans will result in a clearly defined approach to both minimize the impact to achieving the desired objectives and track the effectiveness of mitigation activities required to address priority risks. The risk ROI for expended costs against risk avoidance provides senior leadership insight for business decisions made and lessons learned for pursuing additional initiatives.
Furthermore, monitoring the planned vs. actual budget required to mitigate priority risks can be effectively tracked via defined performance measures. Finally, actual costs for realized risks are accurately captured and may be applied to future programs as analogous input.
Appendix A: DOTMLPF-P Implementation Plan Development (SDDP Step 2)
Entry Criteria
An initial Sponsor-led team will have identified the technical, schedule and cost risks associated with the DOTMLPF-P Implementation Plan. The initial team, comprised of the Functional User community and Sponsor, prepares a Risk Register to capture all identified risks and quantified cost for the AF to fully evaluate the mission need through the DOTMLPF-P actions, to include the potential M-Solution.
Process
At the point of developing the DOTMLPF-P Implementation Plan, neither a Course of Action (COA) for the M-Solution or the details of the M-Solution has been defined. Many risks will be identified during this initial estimation phase and will be added to the Risk Register, as well as being captured in the BOEs.
At this point, the Detailed Actions in this TTP are completed against the identified risks in the Risk
Register and the IMS included in the DOTMLPF-P Implementation Plan. Once the Bounder User
Requirements have been completed and the acquisition strategy has been determined, the SDDP Step
2 IMS will need to be revised to integrate the SDDP Step 2 identified risks. The Sponsor is responsible for monitoring the progress against these risk mitigation activities as part of overseeing the DOTMLPF-P Implementation Plan execution.
Exit Criteria
The DOTMLPF-P Implementation Plan has been completed and includes the risk ROI to support a comprehensive business case analysis. The Sponsor reviews and approves the plan to pursue the investigation of the M-Solution. Critical risk mitigation activities have been integrated in the IMS and monitored in accordance with this TTP.
Appendix B: M-Implementation Plan Development (SDDP Step 3)
An initial Sponsor-led team will have identified the technical, scope and cost risks associated with the M-Implementation Plan. The initial team, comprised of the Functional User community and
Sponsor, prepared a Risk Register to capture all identified risks and quantified cost for the M-Solution implementation activities and the DOT-LPF-P Change Management actions associated with the M-
Solution.
Process
At the point of developing the M-Implementation Plan, a COA has been selected but the detailed requirements of the M-Solution have not been fully defined. Many risks will be identified during this initial estimation phase and will be added to the Risk Register, as well as being captured in the BOEs.
The risks associated with the DOT-LPF-P non-materiel actions are also captured in the Risk Register.
At this point, the Detailed Actions in this TTP are completed against the identified risks in the Risk
Register and the IMS included in the M-Implementation Plan. The initial risk mitigation planning activities are completed and integrated into the IMS in the M-Implementation Plan deliverable package for review and approval. The Sponsor is responsible for monitoring the progress against these risk mitigation activities as part of overseeing the M-Implementation Plan execution.
Exit Criteria
The M-Implementation Plan has been completed and includes the risk ROI to support a comprehensive business case analysis. The Sponsor reviews and approves the plan to pursue the implementation of the M-Solution. Critical risk mitigation efforts have been included in the IMS and monitored in accordance with this TTP.
Appendix C: Program Plan Development (SDDP Step 4)
A Program Manager-led team will have identified the technical, schedule, and cost risks associated with the SDDP Step 4 IMS. The Program Team, including the Functional User community and
Sponsor, have prepared a Risk Register to capture all identified risks and quantified cost for the M-
Solution implementation activities and the DOT-LPF-P Change Management actions associated with the M-Solution. At the point of developing the SDDP Step 4 IMS, fully detailed and baselined
Bounded User Requirement of the M-Solution has been delivered.
Process
At this point, the Detailed Actions in this TTP are completed against the identified risks in the Risk
Register and the SDDP Step 4 IMS. The initial risk mitigation planning activities are completed and integrated into IMS for review and approval. The Sponsor and Program Manager are responsible for monitoring the progress against these risk mitigation activities as part of overseeing the SDDP Step
4 IMS execution.
Exit Criteria
The SDDP Step 4 IMS has been completed and includes the risk ROI to support a comprehensive performance measurement against the implementation of the M-Solution and the delivery of deployable capability.
Appendix D: Program Risk Register Example
Risk
ID
IMS
Number Risk Description
Risk
Source
Risk
Category
Risk
Trigger
Probab ility Impact
Risk
Score
Risk
Response
Risk
Priority
MIL-
1.5.1
Poor definition of DT&E test and evaluation criteria
Test Plan Technical
Perfor-mance
High #
Defects 4 3 12 Mitigate High
MIL-
1.3
Personnel unavailable due to staffing delays causes delay in validation
Onboarding Plan
Schedule Missed
Milestones 1 1 1 Accept Low
MIL-
1.6.3
Two extra rooms required within training facility
Training
Plan Physical
Training
Delays 4 1 4 Transfer Low
MIL-
1.7.5
Data compatibility when migrating from
Legacy to new GOTS
Data Reference
Model
Technical High #
Conver-sion Errors
2 4 8 Mitigate Modera te
** Note: Risk Priority = High to Moderate requires detailed Mitigation Plan and Integration with Program Plan
Figure 8: Risk Register Example
Appendix E: BOE Capture Form Example
Figure 9: Basis of Estimate Form Example
Acronyms
Acronym Definition
AF Air Force
ARM Active Risk Manager
BOE Basis Of Estimate
BRM Business Reference Model
COA Course Of Action
DOD Department of Defense
DOTMLPF-P Doctrine, Organization, Training, Materiel, Leadership, Personnel, Facility and Policy
DOT-LPF-P Doctrine, Organization, Training, Leadership, Personnel, Facility and Policy
ID Identifier
IMS Integrated Master Schedule
M Materiel
ROI Return On Investment
SDDP Service Development and Deployment Process
TTP Tactics, Techniques and Procedures
WBS Work Breakdown Structure
File details come from the government source that posted it. Updated .