Att_4_TTP_for_Integrating_Risk_Into_Program_Plans_doc_v1.0.pdf

PDF 854 KB Posted

Attached to
Business Transformation Federal contract opportunity
Solicitation number
FA7014-16-R-3004
Issued by
Department of the Air Force Headquarters District Washington

About this file

Integrating Risk into Program Plans v1.0

View the file

Other files for this federal contract opportunity

Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

TTP for Integrating Risk into Program Plans v1.0

22 July 2014

AIR FORCE TACTICS,

TECHNIQUES AND PROCEDURES

TTP FOR INTEGRATING RISK INTO PROGRAM PLANS V1.0

22 JULY 2014

VERSION 1.0

UNCLASSIFIED

THIS PAGE INTENTIONALLY LEFT BLANK

Support

For additional information or questions about this document refer to:

https://cs.eis.af.mil/afdbt/afee/

Series

This series of Air Force (AF) Tactics, Techniques and Procedures (TTP) includes:

Version Management

Name and Rank Date

Summary of Changes

Name of Change Author Approval Date

Table of Contents

Support

Series

Version Management

Summary of Changes

Table of Contents

Table of Figures

1. Introduction

2. SDDP Applicability

3. Integrating Risk into Program Plans

3.1 Entry Criteria

3.2 Procedures

3.2.1 Step 1: Establish and Populate a Risk Register

3.2.2 Step 2: Determine Which Risks Require Mitigation Activities

3.2.3 Step 3: Develop Risk Mitigation Plans

3.2.4 Step 4: Integrate and Resource Load Risk Activities into Schedule

3.2.5 Step 5: Monitor and Report Metrics on Risk Mitigation Activities

4. Conclusion

Appendix A: DOTMLPF-P Implementation Plan Development (SDDP Step 2)

Appendix B: M-Implementation Plan Development (SDDP Step 3)

Appendix C: Program Plan Development (SDDP Step 4)

Appendix D: Program Risk Register Example

Appendix E: BOE Capture Form Example

Acronyms

Table of Figures

Figure 1: Integrated Risks in the Program Schedule

Figure 2: TTP for Integrating Risk into Program Plans SDDP Applicability

Figure 3: Risk Register Example

Figure 4: Sequence Risk Mitigation Activities

Figure 5: Link Completion of Risk Mitigation Activities

Figure 6: Risk Mitigation Actions

Figure 7: Risk Management Results

Figure 8: Risk Register Example

Figure 9: Basis of Estimate Form Example

1. Introduction

Risk planning is a core activity for any capability delivery initiative, beginning from the moment a user describes a problem or identifies a mission need, until a capability is delivered that resolves that need. As the initiative moves forward, identified risks must be analyzed in order to determine effective mitigation activities. These risk mitigation activities must be integrated into program plans, with resources, duration and costs. Milestones should also be entered in the schedule to effectively monitor risk mitigation activities, assess the continued probability of the realization of the identified risks, and report results through regularly scheduled risk performance measurement reporting.

This Tactics, Techniques and Procedures (TTP) document provides instruction and guidance for performing the following:

Determining which risks require mitigation activities

Developing risk mitigation plans

Integrating and resource loading the risk mitigation plans into the program schedule

Illustration of monitoring and reporting metrics on risk mitigation activities which will be further detailed in a TTP for Program Control

In addition to describing how to integrate risks into program plans, this TTP provides direction for continuously conducting risk activities to effectively manage priority risks throughout the lifecycle to assure successful delivery of mission capabilities to the Warfighter.

2. SDDP Applicability

The Air Force (AF) Service Development and Delivery Process (SDDP) generates necessary and sufficient program requirements, documentation, and planning to support rapid user-centric solutions to Warfighter needs and enables early program planning activities. The TTP for Integrating Risk into Program Plans is applicable to work plans prepared to support actions associated with the execution requirements. All identified risks from various sources throughout the lifecycle should be documented in the Program Risk Register. The following TTPs have provisions, and/or describe steps, for identifying risks:

TTP for Work Breakdown Structure (WBS)

TTP for Integrated Master Schedule (IMS)

TTP for Schedule-Based Estimating

The TTP for Integrating Risk into Program Plans is initiated during SDDP Step 2, and is used to proactively manage throughout the program, coming to a completion at SDDP Step 6, as illustrated in Figure 2. The black arrows representing the Risk TTP/Risk Register touch points to other outputs, and the bidirectional arrows feed into the IMS, Schedule-Based Estimating, and Impact Analysis

TTPs. Additionally, one arrow represents a single feed from IT Capability Testing into the TTP for

Integrating Risk into Program Plans.

Figure 1: TTP for Integrating Risk into Program Plans SDDP Applicability

When the Program Team builds the detailed IMS for the Materiel (M)-solution, the Program

Management activities in the schedule should contain subordinate activities called Risk

Management. Identified risk mitigation activities will be integrated into the schedule and resource loaded. For each priority risk, the planned mitigation activities, dates, and cost of assigned resources should be captured in the schedule. An example of the M-Solution schedule reflecting integration of risk into program plans and the required risk mitigation activities is depicted in Figure 1.

Figure 2: Integrated Risks in the Program Schedule

Specific instructions, provided in the appendices, tailor the process of integrating risk into program plans as information becomes available through the sequenced steps of SDDP.

A. In support of the Doctrine, Organization, Training, Materiel, Leadership, Personnel, Facility and Policy (DOTMLPF-P) Implementation Plan required in SDDP Step 2 – resource loaded risk mitigation activities for the Doctrine, Organization, Training, Leadership, Personnel, Facility and Policy (DOT-LPF-P) actions that implement the reengineered business processes of the Business Reference Model (BRM) are identified using the process described in

Appendix A. These mitigation activities will be integrated into the IMS associated with the

DOTMLPF-P Implementation Plan.

B. For the M-Implementation Plan required in SDDP Step 3 for a Deployable Capability – the integration of risk mitigation activities into the IMS associated with the M-Implementation

Plan following the process in Appendix B.

C. During SDDP Step 4 where a formal IMS is required for the M-Solution, the mitigation activities are resource loaded in the schedule. Each risk mitigation activity should include duration, target start/complete dates, and cost as described in Appendix C.

3. Integrating Risk into Program Plans

The primary stakeholders for integrating risks into program plan activities includes the Sponsor, Cost

Estimating Team, Acquisition Program Manager, and Risk Manager (depending on initiative).

3.1 Entry Criteria

As part of Program Planning activities, risk identification sessions were conducted and attended by key stakeholders during the development of the WBS (see TTP for Work Breakdown Structure), IMS (see TTP for Integrated Master Schedule) and Cost Estimates (see TTP for Schedule-Based

Estimating). Depending on where an initiative is within the SDDP lifecycle, any applicable policies/procedures, agency/organization risk posture, or program risk tolerance may apply. Each risk is identified in the Basis of Estimates (BOE) Form by the Estimating Team and the cost and/or schedule impact associated with each risk has been quantified through analysis. Refer to Appendix

E for a BOE Capture Form example.

3.2 Procedures

Integrating risk into program plans is performed by the following five steps.

3.2.1 Step 1: Establish and Populate a Risk Register

The goal of Step 1 is to establish and populate a Risk Register that contains all known risks for the program. The Risk Register serves as a vital tool for capturing, analyzing and updating the status of risks. It also supports continuous tracking of a program’s risk posture and status of mitigation activities.

Detailed Actions:

1. Select a Risk Register tool such as Active Risk Manager (ARM), Microsoft Access or an

Excel spreadsheet. Note: The tool must support the ability to sort data numerically and alphabetically.

2. Ensure the Risk Register allows for entry of discrete records (or rows) for each identified risk and includes, at a minimum, the following fields: a unique Risk Identifier (ID), Risk

Description, Risk Source, Risk Category, Probability, Impact, Risk Score (the product of a given risk’s Probability and Impact), Risk Response, and Risk Priority.

a. Record the value for Probability (from 1 to 5) and for Impact (from 1 to 5) in the Risk

Register as well as the product of a risk’s Probability and Impact (Probability Score x

Impact Score) as the Risk Score.

i. Probability Scores range from Not Likely (1) to Near Certainty (5)

ii. Impact Scores range from Minimal or No Consequence (1) to Severe

Degradation or Jeopardize Program Success (5)

iii. See the DoD guide for risk management for further guidance on Probability and Impact scoring found here: http://www.acq.osd.mil/se/docs/2006-RM-

Guide-4Aug06-final-version.pdf

3. Enter all identified risks into the Risk Register from the sources described 3.1 Entry Criteria as well as risk mitigation activities and resources identified from WBS, IMS and BOE work.

4. Sort the Risk Register using the risk score to prioritize from highest to lowest value.

a. Risk Score of 15 or higher is consider “High Risk”

b. Risk Score of 8 and less than 15 is considered “Moderate Risk”

c. Risk Score below 8 is “Low Risk,” with the exception of an Impact Score of 5 and

Probability of 1 which should be treated as “Moderate Risk” due to impact potential

5. Conduct a meeting attended by program’s stakeholders to review the sorted Risk Register and verify the data and rating for each risk. Record any noted corrections in the Risk Register as required.

The expected outcome of Step 1 is a documented list of risks recorded in the program’s Risk Register.

See Figure 3 (also shown in Appendix D) for a Risk Register example.

http://www.acq.osd.mil/se/docs/2006-RM-Guide-4Aug06-final-version.pdf http://www.acq.osd.mil/se/docs/2006-RM-Guide-4Aug06-final-version.pdf

Risk

ID

IMS

Number Risk Description

Risk

Source

Risk

Category

Risk

Trigger

Proba bility Impact

Risk

Score

Risk

Response

Risk

Priority

MIL-

1.5.1

Poor definition of

DT&E test and evaluation criteria

Test Plan Technical

Performanc e

High #

Defects 4 3 12 Mitigate High

MIL-

1.3

Personnel unavailable due to staffing delays causes delay in validation

Onboardi ng Plan

Schedule

Missed

Milestone s

1 1 1 Accept Low

MIL-

1.6.3

Two extra rooms required within training facility

Training

Plan Physical

Training

Delays 4 1 4 Transfer Low

MIL-

1.7.5

Data compatibility when migrating from Legacy to new GOTS

Data

Reference Model

Technical

High #

Conversio n Errors

2 4 8 Mitigate Moderate

** Note: Risk Priority = High to Moderate requires detailed Mitigation Plan and Integration with Program Plan

Figure 3: Risk Register Example

3.2.2 Step 2: Determine Which Risks Require Mitigation Activities

The goal of Step 2 is to assess the priority of the risks identified and select the high to moderate risks that require detailed mitigation activities. Not every identified risk requires a plan of action with resourced activities. The Program Team must decide which risks will be addressed, based on the premise that there will never be enough time and resources to respond to all risks.

Detailed Actions:

1. Access the current version of the Risk Register.

2. Sort Risks from Highest to Lowest Score.

3. Optionally - apply a secondary sort on Risk Category to place focus on certain program aspects such as technical, cost or schedule.

4. Apply any additional criteria driven by the organization’s or program’s risk “tolerance” to further refine priority and “draw the cut line” –determining which risks will be mitigated based on objective criteria and priority.

5. Review, with the program’s stakeholders and risk owners, and verify the rating and disposition for each risk, making corrections as appropriate in the Risk Register.

The expected outcome of Step 2 is the documented list of prioritized risks with an indicator for items that require detailed risk mitigation activities. The Risk Register must be updated with an indicator to denote priority risks.

3.2.3 Step 3: Develop Risk Mitigation Plans

The goal of Step 3 is to analyze each priority risk and consider viable options to determine an effective

Risk Mitigation Plan to mitigate the risk threat.

Detailed Actions:

1. Select the set of high to moderate priority risks to be analyzed from the Risk Register.

2. If options and approaches to mitigate risks are incomplete from WBS, IMS and BOE work, conduct brainstorming sessions with the Sponsor, Program Team and key stakeholders (e.g.

functional users, technical leads, and estimating leads) to discuss viable options and supporting mitigation activities (both materiel and resource driven) for each risk.

3. Confirm technical, scope and/or cost impacts of the mitigation activities.

4. Select the best option for each risk to minimize exposure and reduce probability/impact.

5. Build a mitigation plan for each risk describing the selected option and detailed activities required.

6. Sequence the risk mitigation activities to prepare to integrate them into the IMS (Figure 4).

Figure 4: Sequence Risk Mitigation Activities

The expected outcome of Step 3 is a set of Risk Mitigation Plans describing the approach and detailed sequenced risk mitigation activities for each priority risk.

3.2.4 Step 4: Integrate and Resource Load Risk Activities into Schedule

The goal of Step 4 is to integrate the risk mitigation activities into the IMS, including resources and materiel to support each task. The duration, milestones and cost of each risk mitigation activity will also be determined once the resources have been loaded in the IMS.

Detailed Actions:

1. Access the IMS, Risk Register and all Risk Mitigation Plans.

2. Under the Risk Management section of the schedule, create a Task for each priority risk. To support traceability, use the Risk ID# for the Task Description.

3. Review the TTP for Integrated Master Schedule for additional guidance on integrating activities into the IMS.

4. Enter all required risk mitigation activities for each risk.

5. Enter milestones for each risk to measure performance and completion status.

6. Identify resources to perform each risk mitigation activity.

7. Determine the planned duration for each risk mitigation activity based on the resource’s level of experience, availability (e.g. 25%, 50%, 75%, and 100%) and estimated level of effort. The best practice is to allow the IMS to be “duration-driven” and to avoid “hard coding” start/planned end dates if possible.

8. Link completion of Risk Mitigation with the appropriate Management Review in the IMS as shown in Figure 5.

Figure 5: Link Completion of Risk Mitigation Activities

9. Determine the planned cost of each risk mitigation activity if resource rates are loaded in the scheduling tool. See the TTP for Integrated Master Schedule for reference.

10. Repeat Detailed Actions 4-9 for all risk mitigation plans.

The expected outcome of Step 4 is the IMS loaded with risk mitigation activities, milestones, required resources, and the planned duration and cost.

3.2.5 Step 5: Monitor and Report Metrics on Risk Mitigation Activities

Steps 1-4 complete the integration of risk into program plans. Step 5 is provided for illustrative purposes and will be further detailed in a TTP for Program Control. The goal of Step 5 is to prepare to actively monitor the risk mitigation activities and provide status on performance metrics such as:

Risk Activity Tracking (schedule planned vs. actual) with corrective actions/thresholds

Return on Investment (ROI) of Risk Mitigation Actions

Detailed Actions:

1. Implement a process to routinely monitor risk mitigation activities captured in the IMS, which are typically an element of the Program Control function performed by the Management

Team. Evaluate the progress and effectiveness of the planned mitigation activities, including milestone status.

2. Update the Risk Register to reflect changes in the risk event, probability or impact due to mitigation activities.

3. Document proposed revisions to current mitigation activities based on analyzed results of changes to the risk event including cost and schedule impacts:

More or less cost required (resource or materiel)

More or less time required (schedule duration)

4. Document when risks no longer present a threat and include the planned and actual costs of the risk(s) in a Monthly Performance Metrics report.

5. Prepare a Monthly Performance Metrics report capturing analysis of risk performance and current status of risk activities.

Two metrics are captured to measure performance of the risk management activities. Figure 6, Risk

Mitigation Actions, shows the status of risk activities relative to the planned risk mitigation activities.

Since risk management activities are by their very nature critical to an initiative’s success, their timely completion should be held to the highest standards in terms of planned versus actual execution.

Figure 6: Risk Mitigation Actions

Figure 7, Risk Management Results, provides an indication of the efficacy of a program’s risk management activities and their resulting reduction in overall risk profile over time. As risk mitigation is a form of “insurance,” it is expected that for every dollar invested in risk mitigation, the overall risk exposure of the initiative should decline by several times the investment. (The example shows a cumulative ROI represented by the green trend line of approximately 6 as of August 2011.)

Figure 7: Risk Management Results

The expected outcome of Step 5 is critical information to assess the value of efforts taken to minimize risk exposure. Senior leadership can assess overall performance of a Program or a specific risk mitigation action based on risk ROI. Effective planning of risk activities can be determined by assessing plan/actual durations and costs.

4. Conclusion

Integrating risk into program plans will result in a clearly defined approach to both minimize the impact to achieving the desired objectives and track the effectiveness of mitigation activities required to address priority risks. The risk ROI for expended costs against risk avoidance provides senior leadership insight for business decisions made and lessons learned for pursuing additional initiatives.

Furthermore, monitoring the planned vs. actual budget required to mitigate priority risks can be effectively tracked via defined performance measures. Finally, actual costs for realized risks are accurately captured and may be applied to future programs as analogous input.

Appendix A: DOTMLPF-P Implementation Plan Development (SDDP Step 2)

Entry Criteria

An initial Sponsor-led team will have identified the technical, schedule and cost risks associated with the DOTMLPF-P Implementation Plan. The initial team, comprised of the Functional User community and Sponsor, prepares a Risk Register to capture all identified risks and quantified cost for the AF to fully evaluate the mission need through the DOTMLPF-P actions, to include the potential M-Solution.

Process

At the point of developing the DOTMLPF-P Implementation Plan, neither a Course of Action (COA) for the M-Solution or the details of the M-Solution has been defined. Many risks will be identified during this initial estimation phase and will be added to the Risk Register, as well as being captured in the BOEs.

At this point, the Detailed Actions in this TTP are completed against the identified risks in the Risk

Register and the IMS included in the DOTMLPF-P Implementation Plan. Once the Bounder User

Requirements have been completed and the acquisition strategy has been determined, the SDDP Step

2 IMS will need to be revised to integrate the SDDP Step 2 identified risks. The Sponsor is responsible for monitoring the progress against these risk mitigation activities as part of overseeing the DOTMLPF-P Implementation Plan execution.

Exit Criteria

The DOTMLPF-P Implementation Plan has been completed and includes the risk ROI to support a comprehensive business case analysis. The Sponsor reviews and approves the plan to pursue the investigation of the M-Solution. Critical risk mitigation activities have been integrated in the IMS and monitored in accordance with this TTP.

Appendix B: M-Implementation Plan Development (SDDP Step 3)

An initial Sponsor-led team will have identified the technical, scope and cost risks associated with the M-Implementation Plan. The initial team, comprised of the Functional User community and

Sponsor, prepared a Risk Register to capture all identified risks and quantified cost for the M-Solution implementation activities and the DOT-LPF-P Change Management actions associated with the M-

Solution.

Process

At the point of developing the M-Implementation Plan, a COA has been selected but the detailed requirements of the M-Solution have not been fully defined. Many risks will be identified during this initial estimation phase and will be added to the Risk Register, as well as being captured in the BOEs.

The risks associated with the DOT-LPF-P non-materiel actions are also captured in the Risk Register.

At this point, the Detailed Actions in this TTP are completed against the identified risks in the Risk

Register and the IMS included in the M-Implementation Plan. The initial risk mitigation planning activities are completed and integrated into the IMS in the M-Implementation Plan deliverable package for review and approval. The Sponsor is responsible for monitoring the progress against these risk mitigation activities as part of overseeing the M-Implementation Plan execution.

Exit Criteria

The M-Implementation Plan has been completed and includes the risk ROI to support a comprehensive business case analysis. The Sponsor reviews and approves the plan to pursue the implementation of the M-Solution. Critical risk mitigation efforts have been included in the IMS and monitored in accordance with this TTP.

Appendix C: Program Plan Development (SDDP Step 4)

A Program Manager-led team will have identified the technical, schedule, and cost risks associated with the SDDP Step 4 IMS. The Program Team, including the Functional User community and

Sponsor, have prepared a Risk Register to capture all identified risks and quantified cost for the M-

Solution implementation activities and the DOT-LPF-P Change Management actions associated with the M-Solution. At the point of developing the SDDP Step 4 IMS, fully detailed and baselined

Bounded User Requirement of the M-Solution has been delivered.

Process

At this point, the Detailed Actions in this TTP are completed against the identified risks in the Risk

Register and the SDDP Step 4 IMS. The initial risk mitigation planning activities are completed and integrated into IMS for review and approval. The Sponsor and Program Manager are responsible for monitoring the progress against these risk mitigation activities as part of overseeing the SDDP Step

4 IMS execution.

Exit Criteria

The SDDP Step 4 IMS has been completed and includes the risk ROI to support a comprehensive performance measurement against the implementation of the M-Solution and the delivery of deployable capability.

Appendix D: Program Risk Register Example

Risk

ID

IMS

Number Risk Description

Risk

Source

Risk

Category

Risk

Trigger

Probab ility Impact

Risk

Score

Risk

Response

Risk

Priority

MIL-

1.5.1

Poor definition of DT&E test and evaluation criteria

Test Plan Technical

Perfor-mance

High #

Defects 4 3 12 Mitigate High

MIL-

1.3

Personnel unavailable due to staffing delays causes delay in validation

Onboarding Plan

Schedule Missed

Milestones 1 1 1 Accept Low

MIL-

1.6.3

Two extra rooms required within training facility

Training

Plan Physical

Training

Delays 4 1 4 Transfer Low

MIL-

1.7.5

Data compatibility when migrating from

Legacy to new GOTS

Data Reference

Model

Technical High #

Conver-sion Errors

2 4 8 Mitigate Modera te

** Note: Risk Priority = High to Moderate requires detailed Mitigation Plan and Integration with Program Plan

Figure 8: Risk Register Example

Appendix E: BOE Capture Form Example

Figure 9: Basis of Estimate Form Example

Acronyms

Acronym Definition

AF Air Force

ARM Active Risk Manager

BOE Basis Of Estimate

BRM Business Reference Model

COA Course Of Action

DOD Department of Defense

DOTMLPF-P Doctrine, Organization, Training, Materiel, Leadership, Personnel, Facility and Policy

DOT-LPF-P Doctrine, Organization, Training, Leadership, Personnel, Facility and Policy

ID Identifier

IMS Integrated Master Schedule

M Materiel

ROI Return On Investment

SDDP Service Development and Deployment Process

TTP Tactics, Techniques and Procedures

WBS Work Breakdown Structure

File details come from the government source that posted it. Updated .