Search
Functional Areas

Risk assessment

As per UNDP’s Enterprise Risk Management (ERM) framework and ISO 31000:2018, risk assessment consists of three steps:  

  1. Risk identification,  
  2. Risk analysis, and  
  3. Risk evaluation 

Risk assessment is an ongoing and iterative process, completed no less than once a year, through risk reviews. The risk review process is described in the Risk monitoring and review section of this Manual. 

Risk identification: this is the process to identify and describe risks and opportunities that can affect the achievement of objectives (either positively or negatively). UNDP has a number of predefined and prescriptive tools that can inform the various stages of the risk management process. These are available here. However, given each context is unique, it is a good practice to ensure that risk identification leverages a variety of data, sources of information, and methods. 

Common risk identification approaches include: 

  1. Review of the context, scope planning, preliminary schedule planning, and resource plan. This is a critical step in any project management process, and includes a mapping of all the unknowns, strengths, and weaknesses, identified in the work breakdown structure, critical path, detailed project costing, market analysis, estimates, dependencies, etc. This is a multi-functional process and requires technical inputs from the broader Country Office, and regional/global teams. 
  2. Brainstorming, Delphi technique with multi-dimensional teams. This goes beyond discussions with project/programme team. It includes a brainstorming of what could go wrong with technical teams, such as procurement, security, human resources, finance, as well as gender specialist, health, human rights and peace and development advisors, etc. both in country and regional/global offices, inside or outside UNDP. 
  1. Retrospective analysis of earlier projects, past performance, evaluations, reviews, lessons learned. This includes a review of past Global Fund or health implementation projects, both in country and globally. Data can be extracted from risk register/dashboard, evaluations, reviews, lessons learned, audits, interviews, progress reports, etc.



Resources

Functional Area: Risk Management      Project Stage: Grant Making and Signing      Author: UNDP      Language: English      Type: Policies, Procedures and guidance      Topic: UNDP Risk Management Process, Scope and Context, ERM Process      Resource File Format: PDF      Resource Accessibility: Publicly accessible

Functional Area: Risk Management      Project Stage: Grant Making and Signing      Author: UNDP      Language: English      Type: Policies, Procedures and guidance      Topic:      Resource File Format: Word      Resource Accessibility: Publicly accessible