Project Risk and Procurement Management (UJ Module) Notes: UNISA / UJ Style Study Guide (MPM / Project Management Module)

Project Risk and Procurement Management is a core project management module that equips you to plan, assess, and control risks while ensuring procurement processes deliver value, compliance, and timely outcomes. For the University of Johannesburg (UJ) student, this module typically expects both conceptual understanding and practical application—especially around risk registers, probability–impact reasoning, contract types, procurement ethics, and governance. These notes align with the kind of exam-style learning you see in South African universities (including topics that appear in UJ project management modules and are conceptually similar to content students also revise for UNISA and CUT modules like Project Management, Procurement, and Supply Chain/Risk Management.

Section 1: Project Risk Management Foundations (UJ Project Risk) — From Context to Monitoring

Why risk management matters in projects

Risk management is not “paperwork”; it is a discipline that reduces uncertainty and protects project objectives such as scope, time, cost, quality, safety, and stakeholder satisfaction. In a procurement-heavy project (construction, ICT implementations, consulting service rollouts), risk is often amplified because you rely on third parties whose performance you cannot fully control.

In project risk management, the goal is to:

  1. Identify what might go wrong (or right).
  2. Analyse likelihood and impact.
  3. Plan responses that reduce threats or increase opportunities.
  4. Implement those responses through the project controls and procurement governance.
  5. Monitor and review risk throughout the project lifecycle.

This lifecycle is essential in procurement management because procurement decisions create risks early: vendor selection, contract terms, delivery schedules, payment conditions, specifications, and compliance requirements. If these risks are not considered during procurement planning, they resurface later as claims, disputes, delays, or cost overruns.

The risk management process: a practical exam-friendly model

A commonly examined process framework (aligned with ISO-style thinking and typical project management syllabi) includes the following steps:

  1. Plan Risk Management

    • Define methodology, roles, timing, probability/impact scales, reporting formats, and risk thresholds.
    • Decide how frequently risks will be reviewed (e.g., weekly during procurement evaluation, monthly during execution).
    • Specify who approves risk responses and changes.
  2. Identify Risks

    • Use structured techniques: brainstorming, checklists, interviews, lessons learned from similar projects, process mapping, and data review.
    • Identify both threats (negative risks) and opportunities (positive risks).
  3. Perform Qualitative Risk Analysis

    • Rank risks by probability and impact.
    • Use risk matrix categories (e.g., Low/Medium/High).
    • This supports prioritization for management attention.
  4. Perform Quantitative Risk Analysis (when required)

    • Use numerical methods: expected monetary value (EMV), sensitivity analysis, scenario analysis, sometimes Monte Carlo simulation (if advanced).
    • Quantitative analysis is often limited to high-impact/high-uncertainty items in exams due to time constraints.
  5. Plan Risk Responses

    • Select responses tailored to risk type.
    • Threat responses: mitigate, transfer, avoid, accept (with contingency controls).
    • Opportunity responses: exploit, enhance, share, accept.
  6. Implement Risk Responses

    • Assign owners, budgets, and deadlines for each response.
    • Ensure integration with procurement and schedule baselines.
  7. Monitor and Control Risks

    • Track risk status, triggers, residual risk after response implementation.
    • Update the risk register and escalate issues exceeding thresholds.

Risk categories in procurement-driven projects

For procurement management, risk categories typically include:

  • Contractual risks

    • Ambiguous scope leading to variation orders.
    • Unbalanced contract clauses causing payment delays or disputes.
    • Inadequate performance guarantees.
  • Supplier/vendor risks

    • Vendor financial instability.
    • Delivery delays due to capacity constraints.
    • Quality nonconformance or non-compliance with specifications.
  • Market and economic risks

    • Price escalation of materials or labour.
    • Exchange-rate volatility (especially for imported goods).
    • Supplier shortages or monopolistic pricing.
  • Regulatory and compliance risks

    • Licenses, permits, and local content requirements not met.
    • Labour law compliance issues (health and safety requirements, employment compliance).
    • Data protection or cybersecurity regulations for ICT procurement.
  • Project execution risks

    • Integration risks between new systems and existing infrastructure.
    • Inadequate stakeholder readiness (training, adoption, governance).

In exam answers, categorizing risks can help structure your analysis and show that you understand interdependencies—particularly between procurement and execution.

Risk registers: the backbone of risk documentation

A risk register is a structured log of identified risks, analysed risks, and planned responses. A robust risk register in exams often includes the following columns:

  • Risk ID
  • Risk description
  • Cause(s)
  • Effect(s) on objectives (time/cost/scope/quality)
  • Probability rating
  • Impact rating
  • Overall risk rating
  • Risk owner (responsible person/role)
  • Response strategy (mitigate/transfer/avoid/accept)
  • Action plan / mitigation activities
  • Trigger(s)
  • Contingency plan
  • Status and review date

Example risk register (simplified for learning)

Consider a procurement project: installation of a cloud-based ERP for a retail chain. Sample risks:

Risk ID Risk description Probability Impact Risk rating Response
R1 Vendor delays due to capacity constraints High Medium High Mitigate with delivery milestones and penalty clauses; escalate weekly
R2 Data migration errors Medium High High Mitigate with testing, phased migration, and expert data migration team
R3 Currency fluctuation increases subscription costs Medium Medium Medium Mitigate with hedging/price adjustment clauses; budget contingency

The key exam skill: linking risk to procurement controls. For instance, delivery delays can be mitigated contractually (penalty clauses, service credits) and operationally (governance cadence).

Probability–impact matrices: converting concepts into ratings

A probability–impact matrix turns vague judgments into a consistent ranking. For exam purposes, you can state the method, then apply it:

  • Probability scale (example):

    • 1 = Rare ( <10% )
    • 2 = Unlikely (10–30%)
    • 3 = Possible (30–60%)
    • 4 = Likely (60–80%)
    • 5 = Almost certain ( >80% )
  • Impact scale (example):

    • 1 = Negligible (minimal effect)
    • 2 = Minor (manageable within baseline)
    • 3 = Moderate (requires adjustment)
    • 4 = Major (likely baseline breach)
    • 5 = Severe (major breach; critical failure)

Overall risk score can be Probability × Impact (range 1–25). Thresholds define actions:

  • 1–6: Low
  • 7–12: Medium
  • 13–20: High
  • 21–25: Extreme

Common exam pitfalls in risk management answers

  1. Listing risks without responses

    • Examiners look for “risk → analysis → response”.
  2. Responses that don’t match risk type

    • For supplier delivery delays, vague “monitor closely” is weaker than adding milestone-based reporting and contractual remedies.
  3. Ignoring residual risk

    • After mitigation, risk may remain; you need to show what remains.
  4. No link to procurement

    • Since this module includes procurement management, your risk analysis should explicitly connect procurement decisions to risk outcomes.

Section 2: Risk Analysis Techniques and Procurement Integration — Qualitative, Quantitative, and Contractual Controls

Qualitative risk analysis: ranking and prioritization

Qualitative risk analysis translates probability and impact into qualitative labels. It’s usually expected in exams because it demonstrates judgment and structure.

Key output of qualitative analysis:

  • A prioritized risk list
  • A clear rationale for why certain risks require management attention
  • Identification of risks that can be accepted vs those requiring active response

You can strengthen exam answers by linking to decision thresholds:

  • “Risks rated High (score ≥ 13)** are escalated to procurement steering committee monthly**”
  • “Any risk with impact on cost baseline breaches above 5% triggers immediate escalation.”

Even if your lecturer didn’t specify exact thresholds, using consistent logic and stating assumptions improves clarity.

Quantitative risk analysis: expected value and scenarios

Quantitative methods are often expected as knowledge even if you do a full computation only for one or two risks.

Expected Monetary Value (EMV)

EMV is computed as:

  • EMV = Σ (Probability × Monetary impact) across outcomes.

Example (procurement disruption):

  • If a supplier fails delivery milestone:
    • Probability: 0.3 (30%)
    • Cost impact: R500,000
  • If milestone is met:
    • Probability: 0.7 (70%)
    • Impact: R0 additional cost

EMV = 0.3 × R500,000 + 0.7 × 0
EMV = R150,000

This means investing in mitigation (e.g., stronger supplier governance) should be rational if mitigation costs are less than the EMV or if mitigation reduces both likelihood and impact.

Scenario analysis

Instead of probabilities for many outcomes, scenario analysis considers:

  • Best case, expected case, worst case
  • Useful for procurement risks like exchange rate movements or supplier capacity collapse.

Scenario analysis in exams can be written as:

  1. Define assumptions (exchange rate, contract price adjustment terms)
  2. Estimate schedule/cost effects under each scenario
  3. Compare results with contingencies

Sensitivity analysis: knowing what drives results

Sensitivity analysis identifies which variables most influence project outcomes. In procurement contexts:

  • Exchange rate (if imported components)
  • Labour cost escalation (construction/services)
  • Supplier lead time variability
  • Defect rates (quality issues)

For example, if a contract price is fixed in USD but payable in ZAR:

  • The largest cost driver may be exchange rate not supplier performance.

In exam writing, sensitivity can be described without heavy computation:

  • “If a 10% change in ZAR/USD results in a cost change of more than 5% of total project cost, exchange rate is a key sensitivity variable.”

Opportunity risk: procurement as a source of value

Many students focus only on threats. A higher-scoring answer includes opportunities.

Examples of procurement opportunities:

  • Early procurement agreements reduce price due to bulk purchasing.
  • Supplier offers better delivery schedules in exchange for longer payment terms.
  • Competitive tendering generates innovation in proposed methods.
  • Framework agreements reduce time spent on repeat procurement cycles.

Opportunities require response planning too:

  • Exploit: ensure the opportunity definitely happens (e.g., reserve capacity with supplier).
  • Enhance: increase probability/impact (e.g., negotiate favourable pricing or service levels).
  • Share: partner with supplier on gains (e.g., performance-based incentives).
  • Accept: no active changes if benefits are minor or uncertain.

Integration: linking risk management with procurement stages

Procurement typically runs through stages such as:

  1. Needs identification and specification
  2. Market approach
  3. Supplier selection
  4. Contract negotiation and award
  5. Order placement and expediting
  6. Delivery/inspection/acceptance
  7. Contract administration and close-out

Risk integration means each stage has risk actions:

Stage 1: Needs identification and specification

  • Risk: scope/specifications are unclear, leading to variation claims.
  • Controls:
    • Requirements documentation
    • Clear measurable acceptance criteria
    • Stakeholder sign-off
    • Use of business cases and procurement planning templates

Stage 2: Market approach

  • Risk: limited supplier competition (monopoly effect), raising costs.
  • Controls:
    • Use appropriate procurement method (open tender vs restricted)
    • Engage market soundings
    • Ensure bid validity periods are realistic

Stage 3: Supplier selection

  • Risk: selecting a vendor that cannot deliver.
  • Controls:
    • Pre-qualification checks (financial health, experience, capacity)
    • Evaluation criteria weighting (quality + delivery)
    • Reference checks and past performance scoring

Stage 4: Contract negotiation

  • Risk: contract clauses cannot enforce performance or payments properly.
  • Controls:
    • Penalty/bonus structures and service credits
    • Clear warranties and performance guarantees
    • Indemnities and limitation of liability terms
    • Change control mechanisms (variation order procedure)

Stage 5–6: Delivery and acceptance

  • Risk: poor quality or late delivery.
  • Controls:
    • Inspection and testing plan (ITP)
    • Expediting schedule and reporting requirements
    • Hold points and acceptance procedures

Stage 7: Contract administration and close-out

  • Risk: claims/disputes accumulate late, causing costly resolutions.
  • Controls:
    • Documented communications
    • Issue logs and formal claim processes
    • Lessons learned and performance reviews

Example: linking contract clauses to two procurement risks

Suppose a municipality procures streetlight upgrades:

  • Deliverables: LED units, installation, testing, commissioning.
  • Two key risks:

Risk A: Late delivery due to shipping delays

  • Contract control: milestone-based delivery schedule; liquidated damages; supplier must provide shipping documents and updated ETA.

Risk B: Quality defect rate exceeds tolerance

  • Contract control: warranty terms; performance guarantee; testing and acceptance at installation; defect rectification timeline.

An exam-friendly response explicitly shows:

  • “Because the risk is late delivery, the chosen response is transfer/mitigate via contractual penalties and milestone governance.”

Root cause thinking: “risk” versus “problem”

A high-mark answer clarifies the difference:

  • Risk is uncertainty about future outcomes.
  • Problem is an issue that already occurred.

For instance:

  • “Risk: supplier may be late” (future).
  • “Problem: supplier delivered two weeks late” (past).

In procurement, sometimes students only write problems. Better answers write uncertainty plus triggers:

  • Trigger: “If supplier misses one milestone by more than 7 days, activate escalation.”

Section 3: Procurement Management Core Concepts — Methods, Ethics, and Governance in Project Settings

Procurement planning: where procurement risks are born

Procurement planning sets the foundation for how risks will be managed. It determines:

  • What to procure and why
  • How to procure (method)
  • Who will evaluate suppliers
  • What contract terms will be used
  • How performance will be monitored

In exams, “procurement planning” is expected to include risk and compliance thinking, such as:

  • Sourcing strategy
  • Timing relative to the project schedule
  • Estimated costs and budget
  • Bid documentation (technical specs, evaluation criteria)
  • Risk allocation and contractual responsibilities
  • Stakeholder roles and approval authorities

A strong procurement plan also considers “value for money,” not only the lowest price.

Procurement methods: aligning method with risk and complexity

Common procurement methods in South African public and private sector learning contexts include:

  • Open tendering (broad competition)
  • Limited/Restricted tendering (when justified)
  • Request for Quotation (RFQ) (simpler purchases)
  • Competitive bidding/RFP (for complex solutions; evaluation includes technical capability)
  • Direct procurement / sole sourcing (high justification; limited competition)
  • Framework agreements (reuse procurement structures)

In exam-style answers, you should connect method to procurement risk:

  • Open tender reduces supplier selection bias but may take longer.
  • Direct procurement reduces procurement cycle time but increases price/quality risk.
  • Framework agreements can lower repetitive tender risk and speed up delivery.

Procurement documentation: ensuring bids are comparable

Risk increases when bid documents are unclear or inconsistent. Procurement documents typically include:

  • Scope of work / specifications
  • Technical requirements
  • Bill of quantities (where applicable)
  • Evaluation criteria and weighting
  • Pricing schedule and payment terms
  • Bid submission requirements (format, validity period)
  • Contract conditions and draft contract

A key risk: non-comparable bids.

  • If different bidders estimate different scopes due to ambiguous specs, comparison fails.

A practical exam response:

  • “Reduce this risk by using standardized bid templates and providing clarifications through formal bid addenda.”

Supplier evaluation: balancing cost, capability, and risk

Supplier selection should evaluate more than price. Typical evaluation criteria:

  • Technical solution quality
  • Experience and track record
  • Delivery schedule feasibility
  • Financial stability
  • Compliance with specifications
  • Quality assurance approach
  • Post-sales support and service levels
  • Price competitiveness and total cost of ownership (TCO)

A procurement exam answer can include a sample weighting approach:

  • Technical: 60%
  • Delivery capability: 15%
  • Experience/track record: 10%
  • Price: 15%

Your choice should match project priorities. For mission-critical systems (e.g., ERP with downtime cost), delivery capability and technical reliability might be weighted higher.

Ethics and integrity in procurement: avoiding governance failures

Procurement ethics includes:

  • Fairness and transparency
  • Avoiding conflicts of interest
  • Proper handling of confidential bid information
  • Documentation of evaluation decisions
  • Anti-corruption controls

In exam questions, ethics often appears through scenario-based prompts:

  • A tender committee member is related to a bidder.
  • An evaluator “advocates” a supplier without evidence.
  • A bid is amended after submission but before evaluation.

Strong answers state:

  • What the conflict is
  • The risk it creates (biased evaluation, legal challenges, reputational damage)
  • The mitigation (declaration, recusal, audit trail)

Procurement governance: roles and controls

Procurement governance establishes accountability. Typical roles:

  • Requestor / project manager: defines needs and technical scope
  • Procurement officer: runs tender process and ensures compliance
  • Evaluation committee: scores bids against criteria
  • Contract manager: administers performance and reporting
  • Finance: ensures budgeting and payment compliance
  • Internal audit / oversight: monitors process integrity

Governance controls include:

  • Segregation of duties (avoid one person doing everything)
  • Approval limits (who can sign awards)
  • Recordkeeping and audit trails
  • Change control for contract variations

Procurement risk allocation: who pays for what uncertainty?

Risk allocation is where procurement and risk management meet strongly. Contract design decides who bears specific risks:

  • Supplier bears delivery/quality risks if contract includes performance warranties.
  • Client bears scope change risks if procurement assumes a stable scope.
  • Shared risks include market volatility if pricing clauses allow adjustments.

A strong exam answer links risk allocation to:

  • Incentives (penalties/bonuses)
  • Monitoring and evidence requirements (acceptance tests)
  • Remedy processes (rectification timelines, dispute resolution)

Section 4: Contract Types, Risk Response Strategies, and Procurement Contract Administration

Contract types and why they matter for risk

Contract type affects financial and delivery risk distribution. In project procurement, common contract structures include:

  • Fixed-price contracts

    • Risk: supplier bears many cost overruns; buyer bears risk if scope is not properly defined.
    • Good when scope is stable and specifications are clear.
  • Cost-reimbursable contracts

    • Risk: buyer bears more cost uncertainty.
    • Good when scope is uncertain, but requires strong controls and auditing.
  • Time and Materials (T&M)

    • Risk: cost escalation unless rate caps and usage controls exist.
    • Common in professional services and IT support.
  • Unit-price contracts

    • Used when quantities can vary; payment based on measured units.
    • Risk: measurement disputes; needs clear measurement and verification rules.

In exams, you should connect:

  • Contract stability assumptions
  • Scope clarity
  • Verification and acceptance methods
  • Incentives and claims handling

Contractual risk responses: avoid, mitigate, transfer, accept

Threat responses often take contractual forms:

  • Avoid

    • Don’t procure a service requiring supplier capability you haven’t verified.
    • For example, if vendor experience in data migration is unknown, avoid awarding until you get evidence.
  • Mitigate

    • Add warranties, service level agreements (SLAs), testing requirements, and milestone governance.
  • Transfer

    • Use insurance requirements (where appropriate).
    • Use liquidated damages for late delivery.
    • Transfer certain risks to supplier through performance guarantees and indemnities.
  • Accept

    • If the cost of mitigation is higher than expected loss, accept risk and include contingency:
      • budget contingency,
      • schedule buffers,
      • alternative suppliers,
      • fallback plans.

The exam-marking key: show that the response is realistic and enforceable.

Performance guarantees, service levels, and acceptance criteria

Performance guarantees and service-level requirements are practical ways to control procurement risks.

Examples:

  • Delivery milestone: supplier must meet dates; failure triggers penalty or service credits.
  • Quality: defect thresholds; warranty coverage duration.
  • IT projects: uptime SLA (e.g., 99.5% availability) and support response times.
  • Construction: workmanship standards; inspection at hold points.

Acceptance criteria must be:

  • Measurable
  • Agreed before contract signing
  • Linked to payment triggers

A common failure: “we accept when we feel it is acceptable.” Exams reward measurable acceptance tests:

  • “Acceptance occurs after commissioning test passes all functional checks listed in Appendix A.”

Contract administration: monitoring performance and preventing disputes

Even with strong procurement planning, disputes can arise if administration is weak. Contract administration focuses on:

  • Managing variations/change orders
  • Recording progress and evidence
  • Handling nonconformance
  • Ensuring payment claims are justified
  • Maintaining communication logs and escalation paths

Key tools:

  • Contract management plan
  • Performance reports
  • Site visits/inspection records
  • Change control log
  • Risk register updates linked to contract status

A dispute often becomes expensive when documentation is weak early. In exam answers, highlight:

  • “Maintain an audit trail”
  • “Use formal notices for delays and nonconformance”
  • “Document approvals and instructions”

Change control: linking scope changes to risk and cost

Scope creep is a procurement risk because it creates uncertainty in deliverables and costs. A structured change control procedure typically includes:

  1. Change request submitted with details
  2. Impact assessment (cost, time, quality)
  3. Review by project manager and procurement/contract manager
  4. Approval according to authority matrix
  5. Contract variation issued
  6. Schedule and budget updates
  7. Update risk register if new risks emerge

Exam scenario frequently tests whether you understand:

  • Who can authorize changes
  • What evidence is required
  • How to prevent informal “verbal approvals” that later create claims

Dispute resolution and governance mechanisms

Contract disputes may arise from:

  • Late delivery
  • Unclear scope
  • Defective work
  • Payment withholding

A typical dispute resolution ladder:

  1. Informal negotiation / escalation meeting
  2. Formal notice and negotiation
  3. Mediation
  4. Arbitration/court (depending on contract clauses and legal framework)

In exam answers, show awareness that early resolution is cheaper. Provide a structured response:

  • Identify the cause
  • Evidence required
  • Impact on schedule and cost
  • Proposed remedy and timelines

Worked example: matching risks to contract clauses

Consider a professional services procurement (e.g., risk audit and compliance advisory) delivered over 16 weeks. Three risks and their contract responses:

Risk 1: Supplier under-delivers on milestones

  • Clause: milestone-based payment; acceptance based on deliverable checklists.
  • Remedy: payment withheld until acceptance; apply service credits.

Risk 2: Key personnel not available (resource risk)

  • Clause: named personnel requirement; substitution only with approval and equivalent qualifications.
  • Remedy: re-staff at supplier cost; contract performance deductions.

Risk 3: Scope ambiguity causes rework

  • Clause: detailed scope schedule; requirement for change orders for additional tasks.
  • Remedy: variations priced; change requests processed through formal change control.

This example demonstrates the exam logic:

  • Risk → contractual mechanism → enforcement → remedy.

Section 5: Putting It All Together — End-to-End Project Risk & Procurement Management in Exam Scenarios (UJ-Focused Practice)

Building an end-to-end answer structure (how examiners expect marks)

In UJ-style exam questions, you typically respond to a scenario by covering:

  1. Identify risks relevant to the scenario (procurement and project)
  2. Analyse using probability/impact (qualitative at minimum; quantitative if asked)
  3. Plan responses with a risk register style output
  4. Link responses to procurement actions (tender strategy, supplier evaluation, contract clauses, monitoring)
  5. Discuss governance (roles, approvals, documentation, escalation)
  6. Provide a monitoring plan (triggers, reporting cadence, residual risks)

To help you, here is a repeatable “scenario answer” template:

  • Scenario recap (1–2 lines): what project, what procurement situation, what objectives are threatened.
  • Risk identification (bullet list): 6–10 risks, categorized.
  • Qualitative analysis: select 3–5 critical risks, justify probability and impact ratings.
  • Risk responses: threat/opportunity response type, action plan, and owner.
  • Procurement integration: what you change in tender/contract administration.
  • Monitoring & control: triggers, frequency, reporting, and escalation.

Scenario 1 (procurement delay risk): ERP implementation with vendor delivery uncertainty

Scenario details (for practicing):
A company is implementing a cloud ERP system in 16 weeks. The procurement includes:

  • A vendor delivering configuration and integration services
  • A data migration deliverable
  • Training and go-live support

During tendering, the vendor states capacity availability, but project stakeholders are concerned about delivery reliability.

Step 1: Identify risks

Possible risks:

  1. Vendor delays configuration milestones (threat to schedule)
  2. Key migration resources unavailable (resource risk)
  3. Data quality issues cause migration rework (quality + scope risk)
  4. Change requests increase integration scope (scope creep)
  5. User readiness is low (adoption risk)
  6. Cloud service latency impacts system performance (technical risk)
  7. Procurement governance delays contract finalization (process risk)

Step 2: Qualitative analysis (sample)

Pick top risks:

  • R1 Vendor delays configuration milestones

    • Probability: 4 (Likely)
    • Impact: 4 (Major) because schedule affects go-live
    • Risk score: 16 → High
  • R3 Data quality issues cause migration rework

    • Probability: 3 (Possible)
    • Impact: 4 (Major) due to potential rework and testing delays
    • Risk score: 12 → Medium to High
  • R2 Key migration resources unavailable

    • Probability: 3
    • Impact: 3 (Moderate to Major)
    • Risk score: 9 → Medium

Step 3: Risk responses linked to procurement actions

For R1 (delivery delays):

  • Contractual mitigation/transfer
    • Milestone-based payments
    • Service credits for missed milestones
    • Weekly delivery reporting
  • Operational mitigation
    • Integrated schedule with vendor dependencies
    • Escalation triggers at 7 days slip on any milestone

For R3 (data quality):

  • Mitigate
    • Data profiling before migration
    • Testing and validation plan
    • Dedicated migration team and acceptance criteria for migrated dataset

For R2 (key personnel risk):

  • Transfer/mitigate
    • Named resources clause
    • Replacement rules and approval process
    • Evidence of qualifications and availability

Step 4: Monitoring & control plan

  • Weekly procurement/service status meeting
  • Risk register reviewed every week during the first 8 weeks (configuration/migration peak)
  • Triggers:
    • If any milestone is at risk of missing by >7 days, activate escalation.
    • If data error rate exceeds tolerance thresholds, pause migration and run corrective data mapping.

This scenario demonstrates the integration: procurement decisions (contract clauses, evaluation criteria, milestone definitions) directly control project risks.

Scenario 2 (procurement cost escalation): construction materials and exchange-rate volatility

Scenario details:
A construction project procures materials with costs influenced by international supply chains. The contract includes price risks due to exchange-rate movements. Project leadership wants to reduce the chance of budget overruns.

Risk identification (procurement + market risks)

Common risks:

  1. Exchange-rate volatility increases costs
  2. Supplier passes through price increases without justification
  3. Currency clauses ambiguous, leading to disputes
  4. Delays cause overhead cost escalation
  5. Quality compromises to reduce cost (threat to compliance/safety)
  6. Insufficient contingency in procurement budget

Quantitative angle (exam practice)

Assume (for practice) a simplified approach:

  • If exchange rate shifts, additional expected cost is computed using probability:
    • Probability of significant exchange-rate increase: 0.4
    • Expected additional cost under that scenario: R800,000
    • Probability otherwise: 0.6 → additional cost R0 (simplification)

EMV additional cost = 0.4 × R800,000 = R320,000

Even if the exact numbers differ in your exam, the method is essential:

  • Use EMV to justify contingency or hedging strategy.
  • Compare mitigation cost vs expected loss.

Risk responses with procurement contract terms

  • Mitigate

    • Price adjustment clause formula tied to official exchange-rate index
    • Advance purchase strategy for long-lead items
    • Supplier pricing validity periods for tender-to-order stage
  • Transfer

    • Contract includes supplier responsibility for internal inefficiencies but not for market index shocks (or vice versa depending on negotiation position)
    • Insurance where applicable
  • Accept with contingency

    • Maintain contingency budget based on risk analysis results
    • Create a cost risk reserve and formal approval process for drawdown

Governance and disputes prevention

Ambiguous clauses cause disputes. You can score well by stating:

  • “Use clear contractual definitions and formulas for adjustments.”
  • “Provide audit trail for exchange-rate data used.”
  • “Include dispute resolution timeline for adjustments.”

Scenario 3 (ethics and governance): tender evaluation conflict of interest

Scenario details:
A tender committee member has a close family relationship with a bidder. The bidder’s proposal is scored highly by the committee, and others suspect bias.

Identify the risks

  • Conflict of interest leading to unfair evaluation
  • Legal/regulatory challenge to award decision
  • Reputational damage and audit findings
  • Potential contract suspension or termination risk
  • Time loss due to procurement process delays

Qualitative analysis (example)

  • Probability of audit/legal review: 3 (Possible)
  • Impact: 5 (Severe) because procurement may be invalidated
  • Risk score: 15 → High

Risk responses (procurement governance)

  • Avoid

    • Immediate disclosure and recusal of the committee member
    • Replace the member with an independent evaluator
  • Mitigate

    • Ensure evaluation scores are supported by written evidence against agreed criteria
    • Maintain complete audit trail of scoring rationale
  • Transfer

    • Not always appropriate for ethics risk; governance is the mitigation.
  • Monitor

    • Internal audit review of evaluation process
    • Document the corrective actions and approvals

This scenario often appears in procurement ethics modules; strong answers emphasize documentation, transparency, and fairness.

Scenario 4 (opportunity management): framework agreement and speed-to-value

Scenario details:
A project needs recurring services (e.g., monthly compliance testing). Instead of tendering each time, the organization considers using an existing framework agreement.

Opportunity risks

  • Opportunity: reduce procurement cycle time
  • Opportunity: standardize deliverables and reduce evaluation overhead
  • Threat (still present): performance risk if framework supplier is weak for special tasks

Risk response strategy

  • Exploit opportunity by using framework for routine tasks.
  • Mitigate performance risk by adding:
    • Task-specific scope statement
    • Supplier performance scorecard used at each call-off
    • Quality acceptance and reporting requirements

Governance integration

  • Ensure framework call-offs follow authorization and budget rules.
  • Update risk register: even opportunity-driven procurement needs monitoring.

This scenario shows that procurement management is not only about avoiding failure; it is also about capturing value while controlling new uncertainties.

Exam-ready: concise risk register and procurement action mapping (practice deliverable)

Below is a compact “study template” you can replicate in exams. It combines risks, analysis, responses, and procurement actions.

Template: top risks and response mapping

  1. Risk: Supplier delivery delay

    • Cause: capacity shortage, shipping delays
    • Effect: schedule slip, extended overhead
    • Probability: 4; Impact: 4 → High
    • Response: Mitigate + Transfer
      • Milestone-based payment
      • Liquidated damages/service credits
      • Weekly progress reporting and expediting
    • Procurement action: include clauses and enforce acceptance at milestones
    • Trigger: >7 days slip on any milestone → escalation meeting
  2. Risk: Quality nonconformance

    • Cause: inadequate workmanship/testing
    • Effect: rework, failure to pass inspections
    • Probability: 3; Impact: 4 → Medium/High
    • Response: Mitigate
      • Inspection and testing plan
      • Acceptance criteria and warranty requirements
    • Procurement action: define tests in contract; specify warranty/rectification timeline
    • Trigger: defect rate above tolerance threshold → pause acceptance and corrective action
  3. Risk: Scope ambiguity

    • Cause: unclear specifications
    • Effect: variations, claims, schedule/cost increases
    • Probability: 3; Impact: 3 → Medium
    • Response: Avoid + Mitigate
      • detailed scope schedule
      • change control procedure mandatory for variations
    • Procurement action: standard contract conditions and require formal change orders
    • Trigger: any additional work proposed informally → require written change request
  4. Risk: Governance failure / unethical evaluation

    • Cause: conflict of interest, poor documentation
    • Effect: procurement challenged and delayed
    • Probability: 3; Impact: 5 → High
    • Response: Avoid + Mitigate
      • disclosure and recusal
      • evidence-based evaluation and audit trail
    • Procurement action: document scoring rationale; internal audit check
    • Trigger: conflict disclosed → immediate recusal and process review

How to score high in UJ exams for this module

To maximize marks, practice writing answers that:

  • Use structured headings (risks, analysis, responses, procurement integration, monitoring)
  • Provide a risk register style output for the top risks
  • Show “procurement-to-risk linkage” explicitly (contract clauses, evaluation criteria, governance controls)
  • Avoid generic statements (“monitor closely”) without specifying mechanisms
  • Include triggers, owners, and timelines in response planning
  • Demonstrate awareness of both threats and opportunities

Quick revision: key terms you should confidently define

  • Risk register: a controlled log of risks with analysis, responses, and status.
  • Probability–impact matrix: tool for ranking risks based on likelihood and consequence.
  • EMV (Expected Monetary Value): expected cost/benefit based on probability-weighted outcomes.
  • Risk response (threat/opportunity): strategies like mitigate/transfer/avoid/accept or exploit/enhance/share/accept.
  • Milestone-based payments: payment tied to defined deliverables and acceptance criteria.
  • Service credits/penalties: contractual remedy for performance shortfalls.
  • Acceptance criteria: measurable conditions required to approve deliverables and release payment.
  • Change control: formal procedure for scope changes and contractual variations.
  • Conflict of interest: personal or relational conditions compromising impartial evaluation.
  • Contract administration: ongoing management of performance, variations, documentation, and claims.

Final study checklist (before your test)

Use this checklist to review your readiness:

  • I can describe a full risk management process from planning to monitoring.
  • I can build and explain a risk matrix and risk register.
  • I can compute or outline EMV and scenario logic for a risk.
  • I understand procurement methods and how choice affects risk.
  • I can link procurement decisions (specs, evaluation, contract clauses) to specific risks.
  • I can explain contract administration and change control clearly.
  • I can respond to ethics/governance scenarios with evidence-based controls.
  • I can produce an exam-style answer structure for scenario questions.

If you want, I can also generate 2–3 full exam practice questions with memo-style answers specifically tailored to “Project Risk and Procurement Management (UJ Module)” and aligned with the kind of scenario prompts students typically receive in South Africa.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare