CACS407 Software Project Management

Software Project ManagementUnit 512 min read

Software Risk Management: Types, Impact & Mitigation

Unit 5 of Software Project Management: Explores risk identification, classification, assessment, mitigation, and monitoring in software projects, with real-world examples from Nepali tech firms like Daraz and Ncell.

TAKEAWAYS:

  • Software risks are uncertain events that can derail timelines, budgets, or quality if unmanaged.
  • Risks are classified into technical, organizational, external, and project-specific categories.
  • Mitigation strategies include risk avoidance, transfer, reduction, and acceptance.
  • Tools like risk matrices, SWOT analysis, and Monte Carlo simulations help prioritize risks.
  • Real-world example: Ncell’s 4G rollout risked delays due to spectrum allocation uncertainty (mitigated via government negotiations).
  • Exam focus: Compare risk types, apply mitigation techniques to case studies, and use risk matrices.

1. Definition and Importance of Software Risk Management

Software risk management (SRM) is the systematic process of identifying, analyzing, and responding to risks that threaten a project’s success. Risks can arise from technical complexity, resource constraints, or external factors like market changes.

Why is it critical?

  • Prevents cost overruns (e.g., Daraz’s failed inventory system upgrade cost ₹50M due to poor risk planning).
  • Ensures timely delivery (e.g., Pathao’s ride-hailing app faced delays from third-party API failures).
  • Maintains quality (e.g., NTC’s fiber-optic network rollout avoided downtime via redundancy planning).

2. Risk Identification: Where Do Risks Come From?

Risks emerge from internal project factors and external uncertainties. Common sources:

0.80.90.70.60.50.40.60.70.50.4Requirements GatheringDesign PhaseDevelopmentTestingDeploymentMaintenanceThird-Party APIsGovernment ApprovalsHardware Failures
Risk sources across software development phases (weight = relative risk frequency based on Nepali tech case studies)
111110.50.5Requirements GatheringDesign PhaseDevelopmentTestingDeploymentMaintenance
Common phases where risks originate in software projects (weight = typical risk frequency)

A. Technical Risks

  • Unclear requirements: Misinterpreted user needs (e.g., eSewa’s early mobile wallet app had usability flaws).
  • Technology limitations: Legacy system incompatibility (e.g., NEPSE’s trading platform upgrade failed due to outdated APIs).
  • Complexity: Over-engineering features (e.g., Khalti’s multi-currency wallet had hidden integration bugs).

B. Organizational Risks

  • Resource shortages: Skilled developer scarcity (Nepal’s tech firms often face this).
  • Stakeholder conflicts: Misaligned priorities between teams (e.g., Daraz’s logistics vs. IT teams).
  • Cultural barriers: Poor communication in distributed teams (e.g., Ncell’s remote IT support delays).

C. External Risks

  • Market changes: Sudden demand shifts (e.g., YouTube’s early ad-based model risked user backlash).
  • Regulatory hurdles: GDPR compliance for Nepali fintech apps (e.g., eSewa’s data privacy risks).
  • Natural disasters: Server outages (e.g., NTC’s earthquake-proof data centers).

D. Project-Specific Risks

  • Schedule slippage: Unrealistic deadlines (e.g., Pathao’s app launch was delayed by 3 months).
  • Budget overruns: Hidden costs (e.g., Ncell’s 5G infrastructure exceeded estimates by 20%).

3. Risk Classification: A Taxonomy

Risks are categorized based on their origin, impact, and likelihood. Below is a structured classification:

mindmap
  root((Software Risks))
    Technical
      Unclear Requirements
      Technical Debt
      Integration Failures
    Organizational
      Resource Constraints
      Stakeholder Misalignment
      Poor Communication
    External
      Market Volatility
      Regulatory Changes
      Natural Disasters
    Project-Specific
      Schedule Delays
      Budget Overruns
      Scope Creep
      Example: Ncell's 5G spectrum delay (External → Project-Specific)
Risk taxonomy with Nepali tech examples integrated
Unclear RequirementsTechnical DebtIntegration FailuresTechnicalResource ConstraintsStakeholder MisalignmentPoor CommunicationOrganizationalMarket VolatilityRegulatory ChangesNatural DisastersExternalSchedule DelaysBudget OverrunsScope CreepProject-SpecificSoftware Risks
Hierarchical classification of software risks by origin

Key Insight:

  • Technical risks are often controllable (e.g., code reviews).
  • External risks are uncontrollable (e.g., government policy changes).

4. Risk Assessment: Measuring Impact and Likelihood

Assessment quantifies risks using probability vs. impact matrices. A typical 3x3 matrix (low/medium/high):

022.54567.590Ncell 4G Spectrum Delay90Daraz API Failure60Pathao App Latency40NEPSE Trading Platform Upgrade75
Likelihood scores (1-100) for key Nepali tech risks (based on project audits)
Likelihood Low Impact Medium Impact High Impact
Low Accept Monitor Mitigate
Medium Monitor Mitigate Avoid/Transfer
High Mitigate Avoid/Transfer Critical

Example:

  • Risk: Ncell’s 5G spectrum allocation delay.
    • Likelihood: High (government approvals are slow).
    • Impact: High (delays customer rollout).
    • Action: Transfer risk via government negotiations.

5. Risk Mitigation Strategies

Once risks are identified, proactive measures reduce their impact. Strategies include:

sequenceDiagram
    participant Ncell
    participant Govt
    participant TechTeam

    Ncell->>Govt: Request 5G spectrum approval
    Govt-->>Ncell: Delayed response (High Risk)
    Ncell->>TechTeam: Build redundant towers
    TechTeam-->>Ncell: Mitigation complete
    Ncell->>Govt: Negotiate early approval
    Govt-->>Ncell: Approved (Risk Transferred)
Ncell's risk transfer and reduction strategy for 5G rollout

A. Risk Avoidance

  • Avoid the risk entirely by changing project scope.
    • Example: Daraz dropped a feature requiring third-party APIs (risk: vendor lock-in).

B. Risk Reduction

  • Minimize probability/impact via controls.
    • Example: Ncell added redundant servers to prevent outages.

C. Risk Transfer

  • Shift risk to a third party.
    • Example: eSewa outsourced fraud detection to a cybersecurity firm.

D. Risk Acceptance

  • Acknowledge risk if mitigation costs > benefit.
    • Example: Pathao accepted minor app latency risks for faster launch.

6. Risk Monitoring and Control

Risks evolve over time. Continuous tracking ensures timely responses:

  1. Risk Register: A table tracking risks, owners, and mitigation plans.

    | Risk ID | Description               | Likelihood | Impact | Owner   | Mitigation Plan       |
    |---------|---------------------------|------------|--------|---------|-----------------------|
    | R001    | Spectrum delay (Ncell)     | High       | High   | Govt. Liaison | Negotiate timeline    |
    | R002    | API failure (Daraz)        | Medium     | Medium | Tech Lead | Backup API integration |
    
  2. Regular Reviews: Monthly risk audits (e.g., NEPSE’s trading platform updates).

  3. Escalation Paths: Define when to notify stakeholders (e.g., if a risk becomes "critical").


7. Real-World Examples: Risks in Nepali Tech

Example 1: Ncell’s 4G Rollout

  • Risk: Spectrum allocation delays from DoT.
  • Impact: 6-month delay in customer rollout.
  • Mitigation: Ncell negotiated early approvals and built redundancy in towers.

Example 2: Daraz’s Inventory System Upgrade

  • Risk: Third-party warehouse API failures.
  • Impact: Order fulfillment delays.
  • Mitigation: Daraz duplicated APIs and tested failover mechanisms.

Example 3: eSewa’s Mobile Wallet Security

  • Risk: Fraudulent transactions.
  • Impact: Reputation damage.
  • Mitigation: eSewa implemented two-factor authentication and partnered with cybersecurity firms.

8. Risk Management Tools and Techniques

Tool/Technique Description Example Use Case
SWOT Analysis Identifies strengths, weaknesses, opportunities, threats. Daraz’s market expansion risks.
Monte Carlo Simulation Models probability distributions for cost/time. Ncell’s 5G budget forecasting.
Risk Breakdown Structure (RBS) Hierarchical risk categorization. NEPSE’s trading platform risks.
Checklists Standardized risk items (e.g., "Is vendor contract signed?"). Pathao’s app development risks.

9. Exam Tip: How to Score Full Marks

  1. Define risks clearly:

    • "A risk is an uncertain event that, if it occurs, affects project objectives."
    • Avoid: Vague answers like "risks are bad things."
  2. Use real-world examples:

    • "Ncell’s 4G rollout risked delays due to spectrum allocation, mitigated via government negotiations."
  3. Compare mitigation strategies:

    • "While avoidance eliminates risk, transfer shifts it to a third party—both have trade-offs."
  4. Apply risk matrices:

    • "For NEPSE’s trading platform, a high-impact risk (cyberattack) requires mitigation, not acceptance."
  5. Link to project phases:

    • "Risk management is critical in the planning phase (identification) and execution phase (monitoring)."

In the real world

  1. Daraz’s Order Fulfillment Queue

    • Idea: Risk of supplier delays (external risk).
    • How it’s managed: Daraz uses real-time inventory tracking and backup suppliers to mitigate delays.
    • Worked example: During the 2020 lockdown, Daraz’s risk register flagged warehouse staff shortages. They hired temporary workers and automated sorting to reduce impact.
  2. Ncell’s Network Redundancy

    • Idea: Risk of single-point failures (technical risk).
    • How it’s managed: Ncell deploys dual fiber-optic cables and automatic failover switches.
    • Worked example: During the 2015 earthquake, Ncell’s redundant towers kept 90% of calls operational.
  3. eSewa’s Fraud Detection

    • Idea: Risk of unauthorized transactions (organizational risk).
    • How it’s managed: eSewa uses AI-based fraud detection and transaction limits.
    • Worked example: In 2022, eSewa detected ₹5M in fraudulent transactions within hours, reversing them before customer loss.

Exam Practice Question

Question: A software project for a Nepali bank’s mobile app faces risks like "poor user adoption" and "cybersecurity threats." Classify these risks, assess their likelihood/impact, and suggest mitigation strategies.

Model Answer:

  1. Classification:

    • "Poor user adoption" → External (market risk).
    • "Cybersecurity threats" → Technical (vulnerability risk).
  2. Risk Matrix:

    Risk Likelihood Impact Action
    User Adoption Medium High Marketing push (mitigation)
    Cybersecurity High High Encryption + audits (avoidance)
  3. Mitigation:

    • User adoption: Conduct beta testing and user training campaigns.
    • Cybersecurity: Implement end-to-end encryption and regular penetration tests.

Based on the TU BCA syllabus for Software Project Management (CACS407), unit 5.

Discussion

Loading…