There isn't an art to risk management---but there certainly are processes to follow to protect your project and organization.
Most risks will fall under one or more of the following areas:
- Process
- Business/Financial
- Legal/Contractual
- Technical
- Physical
- Operational
Our risk identification, analysis, mitigation and control process involves asking:
- What is possible based on experience and past history?
- What is likely to occur, using a rating system?
- What can we do about the most likely risk(s)? Can we transfer them? Avoid them altogether?
- What would trigger a risk event? How would we know that it is about to happen?
- What will happen if and when such an event occurs?