NPPE Risk Management and Liability 2 — Questions and Answers
Question 1: In a qualitative risk assessment for an engineering project, risks are typically evaluated based on which two dimensions?
- Budget and schedule
- Probability of occurrence and severity of impact (Correct answer)
- Stakeholder concern and media coverage
- Design complexity and construction difficulty
Correct answer: Probability of occurrence and severity of impact
Qualitative risk assessment evaluates risks on a matrix of probability (likelihood of occurrence) and impact (severity of consequences), allowing prioritisation of risks requiring mitigation.
A risk matrix (or probability-impact matrix) is the standard tool for qualitative risk assessment in Canadian engineering projects. Each identified risk is assessed for: (1) probability — how likely is the risk to materialise? (low/medium/high); (2) impact — if it does materialise, how severe are the consequences to scope, cost, schedule, quality, safety, or environment? (low/medium/high). Risks scoring high on both dimensions are priority risks requiring active mitigation or transfer. This approach allows project teams to focus risk management resources on the most significant risks. Quantitative risk analysis (using numerical probabilities and cost impacts) may follow for high-priority risks.
Question 2: An engineering firm's risk register identifies that a major subcontractor is likely to become insolvent during a project. Which risk response strategy best addresses this risk?
- Ignore the risk since it is the subcontractor's problem
- Require the subcontractor to post a performance bond and payment bond before commencing work (Correct answer)
- Accept the risk and establish a contingency fund
- Transfer the risk by requiring the owner to deal directly with the subcontractor
Correct answer: Require the subcontractor to post a performance bond and payment bond before commencing work
Performance and payment bonds transfer the financial risk of subcontractor insolvency to a surety company, which guarantees completion of the work and payment of sub-subcontractors and suppliers if the bonded contractor defaults.
Performance bonds guarantee that if the bonded contractor (subcontractor) defaults, the surety will either complete the work or pay the owner the cost to complete up to the bond penalty. Payment bonds guarantee that sub-subcontractors, suppliers, and workers are paid even if the bonded contractor becomes insolvent. Together, they address both completion risk and lien risk for the project. Requiring bonds before work commences is a standard risk transfer mechanism in Canadian construction contracts for high-risk subcontractors. The cost of bonding (bond premium) is typically borne by the contractor and reflected in the quoted price.
Question 3: Which principle in risk management holds that it is better to prevent failures than to detect and correct them after they occur?
- The corrective action principle
- The prevention over detection principle (or 'prevention is better than cure') (Correct answer)
- The residual risk principle
- The risk acceptance principle
Correct answer: The prevention over detection principle (or 'prevention is better than cure')
Prevention-oriented risk management reduces failures before they occur, which is typically more cost-effective and protects safety more reliably than relying on detection and correction after failures happen.
A foundational concept in quality management and risk management (from ISO 31000 and ISO 9001) is that prevention is more effective and less costly than correction. In engineering practice: designing-in safety features prevents accidents rather than relying on post-accident responses; quality control during design and construction prevents rework; fatigue analysis during design prevents structural failures. This principle is reflected in the 'cost of quality' concept where prevention costs are far lower than failure costs. For professional engineers, it also reflects the ethical obligation to anticipate and prevent foreseeable harm rather than simply responding to harm after it occurs.
Question 4: Under Canadian tort law, which type of liability does not require proof of negligence or fault?
- Vicarious liability
- Strict liability (Correct answer)
- Joint liability
- Contributory negligence
Correct answer: Strict liability
Strict liability imposes liability on a party regardless of fault or negligence — the mere fact of causing the harm is sufficient. It applies in specific contexts such as ultra-hazardous activities or under certain statutes.
Strict liability makes a party liable for harm caused by their activity regardless of fault, negligence, or intent. In Canadian law, strict liability in tort is typically limited to: (1) the rule in Rylands v Fletcher (escape of dangerous things from land), and (2) certain statutory regimes (e.g., some environmental acts, nuclear liability). For engineers, strict liability risk arises in activities involving inherently dangerous substances or processes. Most engineering liability claims are negligence-based (requiring proof of fault), but engineers designing systems involving hazardous materials, nuclear activities, or reservoir impoundment should be aware of strict liability exposure.
Question 5: What is a 'risk register' in project risk management, and what information does it typically contain?
- A list of claims made against the engineering firm's insurance policy
- A living document recording identified project risks, their probability, impact, risk response plans, and assigned owners (Correct answer)
- A legal document listing excluded risks under the project contract
- A regulatory filing required under provincial safety legislation
Correct answer: A living document recording identified project risks, their probability, impact, risk response plans, and assigned owners
A risk register is a dynamic project management tool that captures identified risks, their analysis (probability, impact), planned responses, and the person responsible for managing each risk.
A risk register is a central project management document that is created during risk identification and updated throughout the project lifecycle. It typically contains: (1) risk ID and description, (2) risk category, (3) probability assessment (qualitative or quantitative), (4) impact assessment, (5) risk response strategy and specific actions, (6) risk owner (person responsible for monitoring and managing the risk), (7) current status, and (8) residual risk after response. The risk register is a 'living document' — it is updated as new risks are identified, existing risks change, and responses are implemented. For NPPE candidates, understanding the risk register as a tool is important for both project management and risk management questions.
Question 6: Which statement best describes 'residual risk' in engineering risk management?
- The risk remaining after initial risk identification
- The risk remaining after risk response measures have been implemented (Correct answer)
- The risk that cannot be assigned to any project participant
- The risk associated with design errors only
Correct answer: The risk remaining after risk response measures have been implemented
Residual risk is the level of risk remaining after risk responses (avoidance, transfer, mitigation, acceptance) have been implemented. Some level of residual risk always remains and must be accepted or managed with contingency.
No risk response completely eliminates a risk. After implementing mitigation, transfer, or avoidance strategies, the remaining risk is the 'residual risk.' For example: after implementing engineering controls for a process hazard, some probability of failure still remains — that is the residual risk. Risk management plans must explicitly address residual risk by either: accepting it (within the organisation's risk tolerance), adding further controls to reduce it, or carrying contingency reserves to fund the consequences if it materialises. NPPE risk management questions may distinguish between inherent risk (before responses), residual risk (after responses), and secondary risk (new risks created by the response itself).
In a qualitative risk assessment for an engineering project, risks are typically evaluated based on which two dimensions?