When to manage risks in IS projects: An exploratory analysis of longitudinal risk reports
Stefan Hoermann, Michael Schermann, Helmut Krcmar
Abstract
Open-access reader
Stefan Hoermann, Michael Schermann, Helmut Krcmar
Abstract
Open-access reader
Research attributes the mixed performance of IS projects to a poorunderstanding of risks and thus limited capabilities to manage suchrisks. In line with others, we argue that the poor understanding ofrisks is partly due to the fact, that current research almostexclusively concentrates on which risks are important in ISprojects. In contrast to this static view, we focus on the temporalaspect of project risks, i.e., we explore when risks become more orless important during a project. In doing so, we analyze an archiveof risk reports of completed enterprise software projects. Projectmanagers regularly issued the risk reports to communicate thestatus of the particular project. Our findings are as follows: First,risk exposure and thus the perceived importance of risk types doesvary over project phases. Second, the volatility of risk exposurevaries over risk types and project phases. Third, risks of variousorigin exhibit synchronous changes in risk exposure over time.From a research perspective, these findings substantiate the needfor a temporal perspective on IS project risks. Thus, we suggestaugmenting the predominant static view on project risks to helpproject managers in focusing their scarce resources. From apractical perspective, we highlight the benefits of regularlyperforming risk management throughout projects and constantlyanalyzing the project portfolio. In sum, we provide a first time,descriptive and exploratory view on variations in project riskassessments over time.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Research attributes the mixed performance of IS projects to a poorunderstanding of risks and thus limited capabilities to manage suchrisks. In line with others, we argue that the poor understanding ofrisks is partly due to the fact, that current research almostexclusively concentrates on which risks are important in ISprojects. In contrast to this static view, we focus on the temporalaspect of project risks, i.e., we explore when risks become more orless important during a project. In doing so, we analyze an archiveof risk reports of completed enterprise software projects. Projectmanagers regularly issued the risk reports to communicate thestatus of the particular project. Our findings are as follows: First,risk exposure and thus the perceived importance of risk types doesvary over project phases. Second, the volatility of risk exposurevaries over risk types and project phases. Third, risks of variousorigin exhibit synchronous changes in risk exposure over time.From a research perspective, these findings substantiate the needfor a temporal perspective on IS project risks. Thus, we suggestaugmenting the predominant static view on project risks to helpproject managers in focusing their scarce resources. From apractical perspective, we highlight the benefits of regularlyperforming risk management throughout projects and constantlyanalyzing the project portfolio. In sum, we provide a first time,descriptive and exploratory view on variations in project riskassessments over time.
Key concepts: Risk management plan, Project risk management, Risk management, IT risk management, Risk analysis (engineering), Project management, Project portfolio management, Project management triangle