1.2.4 Define Risk Management Processes

Risk management is a continuous and iterative process that includes updating procurement or project related risk documents and their associated risk management plans. It emphasizes communication of risks and actions taken to mitigate them. Risks can include key technical, schedule, and cost risks associated with procurement or the overall project, and they are typically evaluated using expert judgement against their likelihood of occurence and their consequence, either on a qualitative or semi-quantitative basis (see Section 2.8 of NP-T-3.21).

Organizations procuring NPPs should have documented risk management structures that define the chain of authority, communication structure, and management framework with which risk management and the decision processes will occur. For risk management to be effective, it should be an integral part of an organization’s management system (e.g., standards, procedures, directives, policies, and other management documentation). A typical risk management framework is described in IAEA-TECDOC-1209. Shown below, it consists of steps to identify risks, identify techniques or strategies to manage those risks, implementing those techniques and then monitoring their effectiveness.

A typical deliverable of risk management processes is a regularly updated risk management plan and ‘risk register’ (or ‘risk log’). A sample risk register is in the ‘Tools’ section below. Such documents inform all stakeholders about how and by whom the identified risks will be managed (accepted, avoided, mitigated/enhanced, or transferred), what residual risk remains following mitigation actions, and what monitoring will be done. Such plans can be made mandatory as part of project or procurement funding steps, and also be done routinely as part of regular organizational risk reviews.

Risk allocation should be done in a compromising and educated manner, recognizing the unique circumstances of each specific project. Some owners mistakenly believe that they can through the contracting process transfer all construction project risk to the primary construction vendor (in this case typically the NPP supplier). The primary construction vendor might then in turn push risk to the lower-tier parties in the contracting arrangement. As a consequence, parties with the least amount of control and influence over many of the risk-producing factors and decisions can often carry the majority of the construction risk burden. Ultimately the project risk rests with the owner, and so the owner needs to actively manage the various risks present with the project, and make concious decisions regarding the advisability and practicality of which risks to attempt to transfer to other project participants.

The Construction Industry Institute (CII) has developed a “Two-Party Risk Assessment and Allocation Model” that is designed to identify, assess, and allocate risk before project execution so that risk management efforts during project performance are minimized. Its “Integrated Project Risk Assessment (IPRA) tool” can be used to assess the degree of risk on any project, but it is especially useful for developers of complex projects in unfamiliar venues or localities. These and other CII construction risk-management related tools are listed below.

Securing project insurance is a risk mitigation tool that is discussed in NG-T-4.1.

Tools