Risk Management Principles & Guidelines (NCBJ) Maj. Hugh Blake Nov. 2011.

Slides:



Advertisements
Similar presentations
1 of 21 Information Strategy Developing an Information Strategy © FAO 2005 IMARK Investing in Information for Development Information Strategy Developing.
Advertisements

Accident and Incident Investigation
A Joint Code of Practice Objectives and Summary Presentation
EMS Checklist (ISO model)
Determining the Significant Aspects
Risk The chance of something happening that will have an impact on objectives. A risk is often specified in terms of an event or circumstance and the consequences.
Appendix H: Risk training slides (sample). What is Risk? “ Risk is the effect of uncertainty on objectives ” AS/NZS ISO31000:2009.
The Aged Care Standards and Accreditation Agency Ltd Continuous Improvement in Residential Aged Care.
Risk Management Policy & Procedures An Overview for Staff Prepared by MSM Compliance Services Pty Ltd.
Information Risk Management Key Component for HIPAA Security Compliance Ann Geyer Tunitas Group
Control and Accounting Information Systems
Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group.
ISO 9001 : 2000.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
Service Design – Section 4.5 Service Continuity Management.
1 INTERNAL CONTROLS A PRACTICAL GUIDE TO HELP ENSURE FINANCIAL INTEGRITY.
Eliot M. Stenzel, CPA,CIA IIA Instructor for many years Risk Based Auditing.
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
The Australian/New Zealand Standard on Risk Management
Title slide PIPELINE QRA SEMINAR. PIPELINE RISK ASSESSMENT INTRODUCTION TO GENERAL RISK MANAGEMENT 2.
1 Risk management and Investigation Peter Roberts
HAZARD AND RISK ASSESSMENT. Today’s Session 1.Taking a look at hazard and risk assessment. 2. Definitions. 3.What hazard and risk management does for.
Project Risk Management Risk Mitigation. Risk Management  The prime objective of risk management is to minimize the impact and probability of the occurrence.
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
Information Systems Controls for System Reliability -Information Security-
Opportunities & Implications for Turkish Organisations & Projects
 This presentation looks at: › What is risk management › How to identify risks › How to implement an effective risk management policy to increase your.
Software Project Management Lecture # 8. Outline Chapter 25 – Risk Management  What is Risk Management  Risk Management Strategies  Software Risks.
Risk Management & Liability Informa Brownfield Hospital Development Summit June 2009.
Project Risk Management. The Importance of Project Risk Management Project risk management is the art and science of identifying, analyzing, and responding.
RISK ASSESSMENT 2010/2011 M.J Ramakgolo. THE PURPOSE The aim of the risk assessment session is to develop the Strategic Risk Profile for the municipality.
Basics of OHSAS Occupational Health & Safety Management System
PROJECT RISK MANAGEMENT Presentation by: Jennifer Freeman & Carlee Rosenblatt
Software Project Management Lecture # 8. Outline Earned Value Analysis (Chapter 24) Topics from Chapter 25.
IAEA International Atomic Energy Agency Reviewing Management System and the Interface with Nuclear Security (IRRS Modules 4 and 12) BASIC IRRS TRAINING.
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Risk Management for Technology Projects Geography 463 : GIS Workshop May
Conducting Compliance Assessments and Building Internal Controls In Pharmaceutical R&D Third Annual Medical Research Summit – Session 2.01 Michael Swiatocha.
Risk Management Policy & Procedures An Overview for Staff Prepared by MSM Compliance Services Pty Ltd.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
Colorado Rural Electric Association 2009 Loss Control Conference NEAR MISSES REPORT/LEARN/USE Presented By: Eldon Humphers, CLCP-CUSA July 14, 2009.
1 Introducing Enterprise Risk Management (ERM) - The KOC Experience November 2012 Khaled Al-Awadhi Risk Management Team Kuwait Oil Company.
Risk Management & Corporate Governance 1. What is Risk?  Risk arises from uncertainty; but all uncertainties do not carry risk.  Possibility of an unfavorable.
Project Management IV1021Fö5 Risk Management. Agenda Project Risk Project Risk Management The Risk Management Process Goal: get an understanding of basic.
RISK MANAGEMENT : JOURNEY OR DESTINATION ?. What is Risk? “ Any uncertain event that could significantly enhance or impede a Company’s ability to achieve.
Risk Management - “Local Government Pitfalls.” IMFO – Sustainability Workshop Risk Management 30 March
Risk Management, FUIEMS, 30 December 2009 Engineering Economics Risk Management Lecture 16 Engineering Economics Risk Management Lecture 16.
Section Topics Risk and control terminology Risk elements
Project Risk Management Planning Stage
SAFETY MANAGEMENT SYSTEM IN TURKISH STATE RAILWAYS (TCDD)
The Risk Management Process
Kathy Corbiere Service Delivery and Performance Commission
ISO Registration Common Areas of Nonconformances.
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
Improving performance, reducing risk Dr Apostolos Noulis, Lead Assessor, Business Development Mgr Thessaloniki, 02 June 2014 ISO Energy Management.
Chapter 13 Risk Management. Chapter Objectives 1.Define risk and risk management 2.Outline key risk issues and types of risk 3.Identify concrete methods.
RISK MANAGEMENT FOR COMMUNITY EVENTS. Today’s Session Risk Management – why is it important? Risk Management and Risk Assessment concepts Steps in the.
DARSHANA RAGHU MANAGEMENT. Risk Management Risk management is the identification, assessment, and prioritization of risks followed by coordinated and.
Organizations of all types and sizes face a range of risks that can affect the achievement of their objectives. Organization's activities Strategic initiatives.
Risk Assessment: A Practical Guide to Assessing Operational Risk
UNDERSTANDING ISO 9001:2008.
An Overview on Risk Management
Software Risk Management
Approaches to Defining Risk
Risk Management Policy & Procedures
COSO and ERM Committee of Sponsoring Organizations (COSO) is an organization dedicated to providing thought leadership and guidance on internal control,
UNIT V QUALITY SYSTEMS.
HUMAN RESOURCE GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE
Lockheed Martin Canada’s SMB Mentoring Program
Information Security Risk Management
Presentation transcript:

Risk Management Principles & Guidelines (NCBJ) Maj. Hugh Blake Nov. 2011

Why talk about risk? Risk is something that we all face every day. As a company, we have to take risks in pursuit of our commercial objectives. To raise awareness that we all have to manage risk as part of our daily working lives as well as personal.

What do we know about RM? RM is part of our every day lives: Crossing the road- Risk of getting run-over Managing our finances– Risk of going broke Purchase of insurance– Risk of fire, theft, storm Choosing to smoke – Risk of cancer Going for a swim– Risk of drowning The choices we make in choosing to accept these risks is part of who we are

Perception of risk – Simple Example Which method of transportation has the greatest fatality rate? By Boat By Air By Road – Car By Road – Motorbike Walking Cycling Train

Research results By Boat5th By Air7th By Road – Car4th By Road – Motorbike1st Walking2nd Cycling3rd Train6th

Perception of risk contd.. Our perceptions usually determine our view of the level of risk posed by an activity

Attitude to Risk SETTLER Knows that there are risks out there Doesnt want to chance anything PIONEER Understands the Risks Takes chances but stays in control GOPHER Doesnt know whats out there & doesnt care Stays underground where its safe COWBOY Does what he feels like Doesnt think (or care) about the risk Risk Averse Risk Aware Risk Taking Risk Oblivious

Sources of Business Risk

The Effect of Risk control on Performance Managing Risk to Enhance Performance Managing Risk to enhance performance Excessive controls minimise risk and constrain performance Exposed & destroying performance IgnorantManagingObsessed Level of Risk Control Performance Low High

What is Risk Management?

Definition of Risk Management ISO / IRM: Coordinated activities to direct and control an organisation with regards to risk. It generally includes risk: assessment, treatment, acceptance & Communication. Contained in ISO 31,000:2009(E)

RM definition contd… A process whereby organisations methodologically address the risks attaching to their activities with the goal of achieving sustained benefit within each activity and across the portfolio of all activities. Sustained Benefit

Benefits of Implementing the International RM Standards Increase likelihood of achieving objectives Encourage proactive management Improve awareness of need to identify and treat risk throughout the organisation Improve the identification of opportunities and threats Comply with legal and regulatory requirement and international norms Improve mandatory and volutntary reporting

Benefits contd… Improve governance Improve stakeholder confidence and trust Establish a reliable basis for decision making and planning Improve control Effectively allocate and use resources for risk treatment Improve operational effectiveness and efficiency Enhance health and safety performance, as well as environmental protection

Benefits contd… Improve loss prevention and incident management Minimize losses Improve organisational learning Improve organizational resilience

International Standard Principles Creates value Integral par of organisational processes Part of decision making Explicitly addresses uncertainty Systematic, structured and timely Based on the best available information Tailored Takes human and cultural factors into account

Principles contd… Transparent and inclusive Dynamic, iterative and responsive to change Facilitates continual improvement and enhancement of the organisation

RM Framework

2.Establish the risk assessment process

Risk Identification Identify an organisations exposure to uncertainty Widely used approach is to break the risks down into categories: Strategic/commercial risks Economic/financial/market risks Legal, contractual and regulatory risks Organisational management/human factor Political/societal factors Environmental factors/Acts of God Technical/ operational/infrastructural risks

Methods of Identifying Events Facilitated workshop Interviews Targeted questionnaire Process flow analysis Leading Event Indicator and Escalation Trigger Loss event data tracking

Risk Analysis Risk analysis is concerned with the probability and impact of individual risks, taking into account any interdependence. Probability is the evaluated likelihood of a an event actually happening, including consideration of frequency of occurrence Impact is the evaluated effect or result of a particular risk actually happening

Example of Risk Probability Framework ProbabilityCriteria Very low0-5% (extremely unlikely, or virtually impossible) Low6-20% (low but not impossible) Medium21-50% (Fairly likely to occur) High51-80%(more likely to occur than not) Very high>80%(almost certain to occur)

Example of Impact Framework Cost Impact Very low $0 to $100,000 Low>$100,000 to <$500,000 Medium>$500,000 to <$1,000,000 High>$1,000,000 to < $5,000,000 Very high>$5,000,000

Impact Contd… Budgetary Impact Very low 0 to 3%: Negligible effect on projected cost Low3 to 10%: Small increase Medium10 to 30%: Significant increase High30 to 75%: Large increase Very high>75% Major increase

Identify Key Business Objectives (1) Identify Key Processes; Dependencies and Enablers (2) Identify key Threats and Indicators (3) Identify likelihood and Severity/impact of Occurrence of Threat (4) Assess Countermeasures (5) Develop Action Plan (6) XXX Ltd. Risk Management Value Chain XXX Ltd. Risk Management Value Chain

Business Objectives Identified: The management of XXX Ltd. production Inventory outlined their primary objective as the ability to efficiently meet the production demand for raw materials. However, to achieve this goal, the following sub-objectives / enablers would have to be met: 1. Proper Material Requirement Planning (MRP) and forecasting. 2. Efficient execution of the Purchasing Plan. 3. Proper receipt, storage and maintenance of stores. 4. Proper issue procedure. 5. Proper accounting for perpetual inventory.

What will be the IMPACT on the ability to achieve the object? NegligibleSmallNoticeableSignificantMajor LIKELIHOOD (A): - If it is not occurring, how likely is it to occur? Unlikely to OccurLikely to occur rarely Likely to occurHighly likely to occur Certain to occur LIKELIHOOD (B): - If event is already occurring, how often does it occur? RarelyOccasionallyFrequentlyDailyContinuously URGENCY (A): - How soon is action required to prevent impact? year6 months1 quarter1 month1 week URGENCY (B): - How soon is action required to mitigate impact? Year6 months1 quarter1 monthImmediately Risk Ranking Table The following is used to assign impact, probability and urgency weights to identified risks / issues.

EnablersThreats Countermeasure In Place Is threat occurring Probability & frequency rating Recommended Countermeasure Yes No ProbFreq Efficient inventory computer based management system System failure due to crash, virus or physical destruction of hardware Information contained on system is backed-up on a routine basis and storage is done off- site XL Existing countermeasure is adequate Accurate input information Staff mistakes and negligence resulting in inaccurate physical stock checks Managements supervision and vigilance XL Conduct stock counts with a minimum of two independent counters. With the assistance of the IAD, establish documented counting procedure and train staff accordingly. Improper operation of the system due to incompetence of staff Recruitment of qualified individuals and training of staff XL Existing countermeasure is adequate Inaccurate supplier information Verification procedure for incoming stores XL Existing countermeasure is adequate Frequent physical stock count Poor planning and management Stock count scheduled and verified by Internal Audit Department XL Existing countermeasure is adequate Efficient internal control system at all stages of management Poor supervision and management Performance evaluation system as well as the productivity incentive system XL Sanction must be brought against managements and supervisors negligence Lack of documentation of accepted procedures All procedures documented under ISO XL Existing countermeasure is adequate Production Inventory: Proper accounting for perpetual inventory (FIFO & Expiration)

SrlRiskALEImpactLikeli hood UrgencyScoreRankRemark 01 System failure due to crash, virus or physical destruction of hardware th 02Staff mistakes and negligence resulting in inaccurate physical stock checks nd Improper operation of the system due to incompetence of staff nd Inaccurate supplier information th 03Poor planning and management th 04Poor supervision and management st Lack of documentation of accepted procedures rd Production Inventory: Assessment and ranking of threats facing the enablers of objective #4

Risk Treatment Can involve: Avoiding the risk – not to start or continue an activity taking or increasing risk in order to pursue an opportunity removing the risk source Changing the likelihood Changing the consequences Transferring the risk or sharing with another party Retaining the risk by informed decision

Monitor performance and modify as needed

Summary All entities exist to provide value for its stakeholders Uncertainty presents risks and opportunities – with potential to erode / enhance value All entities face uncertainty – managements challenge balance the risk and opportunities RM provides management with a framework to effectively deal with uncertainty – the associated risks and opportunities – and enhance their capability to build value.

Organisations make and save money by taking risks and lose money by not effectively managing risk Thank you!!