When people plan to sock away money for education or retirement, financial advisers typically recommend developing a balanced portfolio of investments. It would be a mistake to have too many low-risk investments, because the portfolio would just trudge along with marginal growth and not meet its potential. Punters are also warned not to make too many high-risk investments so that they can be reasonably assured of moderate growth with lower-risk funds if their higher-risk investments end up tanking.
IT management experts offer similar advice for striking a balance with IT project investments. Yet few IT and corporate executives make a conscious effort to ensure that their organizations have an adequate balance of low-, medium- and high-risk IT projects in the pipeline at any given time.
"I think companies do a good job on an individual project level of evaluating execution risk. But I don't think they do a good job of evaluating project portfolio risk," says San Retna, A former chief portfolio officer.
Lack of experience
Part of the problem is that most IT and business staffs are inexperienced at reviewing risk, says Jack Duggal, a principal at Projectize Group, a project management consulting firm. Duggal points to an insurance client he helped a few years ago with a risk assessment on a troubled CRM implementation. "The irony is that an insurance company's job is to manage risk but their IT organization couldn't even spell risk," he says. So Duggal and other consultants from his company trained members of the IT organization to identify and analyze risk on both qualitative and quantitative levels.
Despite recent advances in IT governance at some companies, Retna says there's still a lot of confusion about whether project risk management should fall upon individual project managers, on a project management office (PMO) or some other independent entity.
A big problem for many executives is that they frequently confuse risk management with problem management, says Keith Walter, vice president and general manager of global program management at Keane, a business and IT services company. They don't understand the difference between identifying and mitigating risks in a project and resolving problems that pop up during a project, he says.
Despite the hype about the benefits of using IT portfolio management to evaluate and rank projects, few Fortune 1000 companies actually do this, Walter says. And for the handful that do it's typically a one-time project-prioritization exercise. "I don't know if anybody comes into this and says, 'Let's organize IT-business projects by low, medium and high risk'," says Dan Demeter, CIO at Korn/Ferry International, an executive placement company.
One at a time
Like most companies, Korn/Ferry assesses risk on a case-by-case basis as part of project planning.
The company has an IT steering committee for each of its three major business units, plus a corporate IT steering committee. These committees work together to define project requirements, assess risks and approve projects for funding. The groups don't rely as much on formal IT portfolio management techniques as they do on discussing a project's merit "to ensure that everybody has some input," Demeter says.
Barry Cohen, vice president of applications management at Wells Real Estate Funds, says his company's IT department has "a pretty primitive process" for looking at IT project risk. Cohen says risk is discussed as part of each project and is factored into the timeline and cost estimates. "Our ability to handle risk allows us to work on one or two high-risk projects at a time," he says.
Wells' IT department takes a more ad hoc approach to balancing risk in the company's IT project portfolio, Cohen says. But that doesn't mean it's disregarded. His group is typically working on two high-risk projects and five to 10 medium-risk projects at any given time, plus 100 low-risk projects during the course of the year. High-risk projects include those where failure could adversely affect business processes, end users, or the company's affiliates or investors, says Tammy White, director of IT governance.
Although Korn/Ferry and Wells seem satisfied with these less-formal approaches, Bob Charette, director of enterprise risk management services at Cutter Consortium, says companies that do an exceptional job of managing project risks are often also adept at using portfolio management techniques.
- +
Process Trip 04/02/2008 13:07:03
Why Maritz Travel revamped key business processes — and how business and IT came together to make it workWhen Rich Phillips became COO OF Maritz Travel about two and-a-half years ago, he sat down and took a hard look at the big industry picture - +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients? - +
Strategies for Dealing With IT Complexity 24/12/2007 10:30:47
Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. CRM your salespeople will love
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Know thy self: Reduce costs, secure data and ensure compliance with identity management
Achieving the impossible: Unlimited application scalability
Email Archiving Implementation: Five Costly Mistakes to Avoid
Strategies for Eliminating .PST Files
Email Archiving 101—Customer Case Study
Enterprise Wireless WLAN Security
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Vignette Announces 2008 Excellence Awards 2008-11-21 10:50:00+11
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 2008-11-20 17:34:00+11
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 2008-11-20 12:06:00+11
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 2008-11-20 12:04:00+11
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 2008-11-20 12:02:00+11
Choices in Storage Architecture for Oracle Environments
Database systems have always been at the core of the IT landscape. Not only is storage an increasingly large cost component of database investments, but storage architecture can significantly and directly impact the performance, availability, and recovery of data. Read on to explore the interaction between Oracle databases and EMC and Network Appliance storage architectures.









