Risk data quality assessment

A structured review that evaluates how complete, accurate, credible, and timely the project's risk information is. It determines whether current risk data is sufficient for analysis and decision-making or if more data collection is needed.

Key Points

  • Assesses the quality of risk information, not the size of risk exposure.
  • Examines completeness, accuracy, source credibility, consistency, and timeliness.
  • Done early in qualitative risk analysis and revisited as new information emerges.
  • Uses simple, transparent scales (e.g., high/medium/low) with documented rationale and identified gaps.
  • Low-quality data triggers actions such as gathering evidence, validating assumptions, or expert elicitation.
  • Results are recorded in the risk register and guide whether quantitative analysis is appropriate.

Purpose of Analysis

The purpose is to determine whether the available risk data is trustworthy enough to support prioritization, response planning, and potential quantitative analysis. It helps teams avoid false precision and make informed choices about where to invest effort in improving risk information.

Method Steps

  • Define assessment criteria and a rating scale for data quality (e.g., completeness, accuracy, credibility, timeliness, consistency).
  • Inventory each risk’s available data and its sources.
  • Check completeness of key fields (cause, event, effect, triggers, probability, impact ranges, owner).
  • Evaluate accuracy and objectivity by comparing with historical data, benchmarks, and multiple viewpoints.
  • Rate each risk’s data quality and document the justification and evidence.
  • Identify gaps and specify actions to improve data (workshops, expert interviews, data collection, validation).
  • Summarize overall confidence in the risk dataset and decide readiness for further analysis.
  • Record updates in the risk register and communicate results to stakeholders.

Inputs Needed

  • Risk register and any existing risk report.
  • Risk management plan, including data collection approaches and definitions.
  • Assumptions and constraints logs.
  • Stakeholder register and communication preferences.
  • Historical information, lessons learned, and benchmarking sources.
  • Project baselines and plans (scope, schedule, cost) to validate impacts.
  • Previous qualitative or quantitative analyses, if available.

Outputs Produced

  • Updated risk register with data quality ratings and rationales.
  • List of data gaps and an action plan to improve risk information.
  • Summary of overall data confidence for the risk set.
  • Updates to the risk management plan or analysis approach, if needed.
  • Decisions on whether to proceed with prioritization or quantitative analysis.

Interpretation Tips

  • Low data quality does not mean low risk; it often indicates uncertainty that needs attention.
  • Prioritize improving data for high-impact areas, critical path items, and key assumptions.
  • Look for systemic issues (e.g., single-source estimates, outdated data) and address root causes.
  • Use consistent criteria across risks to avoid bias and ensure comparability.
  • Reassess data quality after collecting new information or crossing phase gates.

Example

A project team lists 40 risks. The assessment finds that 15 risks lack defined triggers, 10 have probability estimates from a single stakeholder with known bias, and only 5 have validated cost impacts. Data quality is rated low for 25 risks. The team schedules expert interviews, collects historical data from similar projects, and updates risk statements and impact ranges. They defer quantitative analysis until top risks reach at least medium data quality.

Pitfalls

  • Confusing missing data with low risk and underprioritizing uncertain threats or opportunities.
  • Proceeding to quantitative analysis with weak inputs, creating false precision.
  • Relying on a single source or outdated information without validation.
  • Skipping documentation of rationales, making results hard to defend or improve.
  • Assessing only high-profile risks and ignoring the rest of the register.
  • Treating the assessment as a one-time task instead of a periodic check.

PMP Example Question

During qualitative risk analysis, the team notices many risks have vague descriptions and unverified probability estimates. What should the project manager do next?

  1. Proceed with risk ranking using expert judgment to save time.
  2. Perform a risk data quality assessment and plan actions to improve missing or uncertain information.
  3. Move directly to quantitative risk analysis to obtain precise results.
  4. Close risks with inadequate data and focus only on well-documented ones.

Correct Answer: B — Perform a risk data quality assessment and plan actions to improve missing or uncertain information.

Explanation: Validating the quality of risk data is necessary before ranking or running quantitative analysis. Poor-quality data should trigger evidence gathering and refinement, not be ignored or bypassed.

Advanced Lean Six Sigma — Data-Driven Excellence

Solve complex problems, reduce variation, and improve performance with confidence. This course is designed for professionals who already know the basics and want to apply advanced Lean Six Sigma tools to real business challenges.

This is not abstract statistics or theory-heavy training. You’ll use Excel to perform real analysis, interpret results correctly, and apply tools like DMAIC, SIPOC, MSA, hypothesis testing, and regression without memorizing formulas or relying on expensive software.

You’ll learn how to measure baseline performance, analyze process capability, use control charts to maintain stability, and validate improvements using statistical evidence. Templates, worked examples, and structured walkthroughs help you apply each concept immediately.

Learn through a complete, real-world Lean Six Sigma project and develop the skills to lead data-driven improvements with credibility. If you’re ready to move beyond basics and make decisions backed by data, enroll now and take your Lean Six Sigma expertise to the next level.

Explore the Course


Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course