INSTRUCTIONS NOT FOLLOWED:Could you please answer each of the 4 questions not put it all together? The study question is ask you to answer 4 questions not just one.

profileMichelle_Michy
commetsfromlivingstoneeditorialteam.docx

Feedback on Dissertation

Overview comments:

Note below that I have suggested that the objectives are insufficient for an MSc project – I mean this in the sense that they are not worded in such a way as to suggest the right level of depth. However, the overall objective to create a framework for risk management for SMEs is entirely appropriate, so it is just a matter of how the objectives are worded, and then making sure that you achieve the overall one. Despite the missed opportunity to collect primary data from SMEs, I do not suggest that you go and collect primary data for the re-submission – a re-sub should not constitute significant additional data collection and a re-shaping of the project such that it is almost new. I therefore recommend that you improve this as a literature based dissertation – significantly strengthening and deepening your literature review chapters, utilising the project management literature and anything else that you can find that is relevant. Make sure that you structure the literature review chapters so that they tell a coherent story, be critical (compare and contrast different views, studies, models, etc.) and then when it comes to analysing the data as a whole, consider using coding and thematic analysis to help you make sense of the key issues that arise (or any other qualitative data analysis methods you think appropriate). The comparisons of the different risk management processes could be simply compared and discussed directly – look at how many stages there are, whether some of them are similar or the same, which ones are different and why – and from that decide what would be the best model for SMEs. It would also be worth mapping out the overall structure of the process, the strategies for identifying, evaluating risk, etc., and what actions can be taken to mitigate/transfer/avoid the risks (or whether risk acceptance is the best plan). You also need to look at the tools and techniques used to actually identify, monitor and control risks – things like the risk register, risk matrix, etc. - and again, critique them with respect to how useful they would be to an SME. Hopefully my comments below will also help, but think about what the whole thing should look like first, and then work on improving each part in order to achieve that overall picture or story.

Abstract:

Too short and suggested objectives are not sufficient for MSc dissertation – “determine” suggests identifying, rather than assessing, evaluating, analysing or understanding, and therefore indicates a lack of depth to the work. Also, the abstract includes no background context, no justification for the research problem and why the research was needed, and there are no indications of the value to arise from the work. All it offers is a very basic indication of what you did.

Table of Contents and dissertation layout:

· For a dissertation based on secondary data, the Methodology chapter should appear as Chapter 2, since it needs to explain in considerable depth what your data collection strategy was with regard to the databases used, the public info sources (academic, industrial and institutional, i.e., government) used and how you analysed this data.

· Chapter 2, the literature review, looks too basic, especially for a dissertation based on secondary sources only. I would usually expect two or three quite substantial and in-depth literature review chapters for a dissertation based on secondary sources.

· The page numbering is incorrect – Chapter 1 starts on page 7 – it should start on page 1. See the Moodle pages on study skills or for the dissertation layout to find out how to number the pages immediately before Chapter 1 correctly.

· Sub-sections within chapters are not numbered, i.e., 2.1, 2.2, 2.3, 3.1, 3.2., 3.3

· Introduction:

· The basics are there – the importance of risk management, states that risk management strategies designed for large companies are unsuitable for SMEs, and sets the context for Saudi Arabia in terms of their importance to the economy and their poor survival rate, but the link to poor risk management strategy being the cause is not there. There is also no evidence for any of this – no references cited

· The Background Context sub-section defines a particular typology of risk, but there is no explanation as to why just this one is relevant in the context of the project, and there are no sources cited. Also, offers a bit more detail on SMEs and their context in Saudi Arabia, but again, no evidence offered; no sources cited

· The Research Problem sub-section does not discuss the research problem at all. It sets out the key problems for SMEs (important for the background context) but it does not mention risk management; the main focus of the dissertation

· Research Objectives – the overall objective is actually fine and appropriate, but it does not match with what you said in the Abstract. The secondary objectives are also fine, though they are too numerous – some of them could probably be merged

· Research Questions – not clear why you needed these, especially since they seem to be simply the objectives re-phrased as questions. Generally, either research objectives OR research questions is perfectly adequate – having both causes confusion.

· Overall, the chapter needs some re-structuring around the key issues, leading to a clearly set out and justified research problem and objectives. Also, all important statement needs references to support them – referencing supporting material should not be confined only to the literature review. Only the Abstract and the Conclusions chapters generally have no references.

· Literature Review chapter

· Introduction should “set the scene” for what important issues are covered in the chapter (that is, pointing out what the key issues are in the context of this project and why), rather than simply stating what the chapter will cover.

· Only one typology of risk is mentioned, and this differs from the one stated in the Introduction chapter – there is no acknowledgement that there is more than one typology, or a discussion of which is the most relevant for your project and will therefore be used as part of your theoretical framework throughout the work.

· Statements are made without proper referencing or explanation – for example, you state on p13 that “some scholars define risk based on positive results while others define it based on positive and negative results”. First, who are these scholars (on each side of the argument)? Cite references for each side. And second, why do they hold different views?

· The definition of risk management and the risk management process are purely descriptive, uncritical and rely on very few sources – the risk management process is explained based entirely on Berg (2010). In any topic, there will be different variations of the process and the underlying theory – at MSc level, you are expected to be aware of the different variations and be able to critically compare them in order to determine which individual approach (or combination of them) best fits what you are trying to achieve in your project, or you expect to best describe or predict what your data will show (where there is primary data).

· Concepts within the risk management process are also not adequately examined – for example what the differences and commonalities are between the quantitative and qualitative approaches mentioned on p15.

· There is no discussion of the tools and techniques used by managers to operationalise the risk management process, e.g., risk register, risk matrix, FMEA, fault tree analysis.

· What was the purpose of the sub-section on types of risk management? It is just a bullet point list – there is no mention of its specific relevance to your analysis, or what you will do with this information

· The Concept of SMEs and Risk Management sub-section should probably be an entire chapter in its own right, in order to go into the topic in sufficient depth for the analysis you plan to conduct, and to achieve Master’s level.

· You state that SMEs either don’t really do any risk management, or they use different strategies to larger companies, but you do not explain why any of these strategies look like – what the specific techniques and tools are, and how they are used.

· The sub-section on Saudi SMEs relies on just two references (and mostly just the one) – you need to demonstrate that this is not an isolated view by using more reference sources.

· The sub-section specifically on Saudi SMEs is useful background context, but it was not clear what was achieved by the sub-sections comparing Saudi with the MENA and GCC countries. Although it is always good to compare with other similar countries, such analysis needs a purpose that is relevant to the overall focus of the project and the analysis. It would therefore be more meaningful to compare the attitudes and use of risk management practices in SMEs across these countries (perhaps in relation to such measures as appropriate and adequate management training) than to simply compare the level of support (in fairly general terms) that there is for SMEs.

· Good to see that there is a sub-section on tools and techniques, but you start again from the premise that there is only one typology of approaches (this time – top down and bottom up, which I’m not sure actually constitute formal approaches), and the risk process you present for the top-down approach is different to the four stage process you introduced earlier in the chapter. There is no acknowledgement or critical discussion of the differences, and there is no initial review of the different approaches before deciding which best fits your purposes.

· Relating to the above point, the sub-section is titled “Risk Management Tools and Techniques”, but what follows is a range of approaches, strategies and frameworks – these are important, but the tools and techniques that underlie these strategies and frameworks are not actually covered. What tools and techniques do the managers actually use in order to carry out the four stage risk management process?

· Again, relating to the above point – this entire sub-section is just a collection of descriptions and definitions for a range of strategies, approaches and frameworks, with no actual comparison and critical discussion aimed at establishing which are the most effective ones, and which are most used by SMEs, and importantly, which are actually best suited to SMEs.

· Not clear why collaboration is discussed, or indeed diversification – these are business strategies that are sometimes used to also manage risk; your focus seems to be on the tools and techniques used to manage risks at the operational level of the business, so the relevance to the project is weak, and this material is irrelevant to this sub-section (Tools and Techniques)

· Why is only the COSO framework explained in detail? You mention others but do not properly describe or critically compare them with COSO.

· There is no mention of the project management literature – risk management is a well-established facet of project management. In particular, authoritative sources such as the PMBOK are not referenced, or key project management organisations such as the PMI (who publish the PMBOK) and APM. You have therefore missed a fundamental section of the literature.

· Conclusions – you have not provided enough evidence and critical evaluation for the conclusions to this chapter to be convincing.

· Overall, the chapter is descriptive and lacks a coherent linking of the various topics covered into a structured discussion and evaluation of the different levels of risk management. Strategies, approaches and frameworks are confused with tools and techniques, the tools and techniques are not actually covered, there is a lack of detail or illustrator examples, there are few references to support the assertions made, and there is no critical comparison of the various approaches, etc. It is a collection of pieces of information about various things, with no attempt to understand how they all fit together – that is, the overall business strategy approach, the risk management approach, the framework that defines how risk management is operationalised, and finally the tools and technique used to actually operationalise risk management. The chapter should also be split into at least two, in-depth chapters – there needs to be sufficient material in these chapters to enable Master’s level analysis and depth.

· Research Methodology chapter

· Although fairly clearly set out in terms of the data collection strategy, there are some inconsistencies with respect to the literature review – for example, the types of risk (hazard, financial, operational and strategic) are not discussed in the literature review (though one or two them are briefly mentioned), and the risk management stages are not the same as either of the two different frameworks previously mentioned. The literature review should form the basis for your data collection and analysis, so there should be no inconsistencies and no new concepts arising in the Methodology chapter. New concepts may however, arise as a result of the data collection (in the case of primary data) and the analysis.

· It is unclear how you conducted your data collection with regard to the country-specific case studies – was this the subject of a separate database search, or was it combined with the one for SMEs and risk management?

· There is no review of how you determined which journals were the most relevant and useful, or the public information sources (particularly the government sources). These must be explained – what was selected, what was not selected, what each source contributed and whether there were any gaps in the overall picture.

· There is no discussion of the data analysis techniques used. The chapter only covers data collection. How did you analyse, make sense of and interpret the data you collected?

· Findings chapter

· The first sub-section should have been merged into the Methodology chapter, since it covers the methodology of the paper search and selection. It even repeats some material from the previous chapter.

· It seems that the “findings” consist of a review of literature referring to different types of risk – this is therefore, in effect, another literature review chapter. This is acceptable in that you are doing research based on secondary data, but you need to be clear about this – that it is a literature review focused specifically on types of risk, and that the findings will form the basis of your analysis.

· It is unclear how you have selected which types of risk to focus on. You indicate that these are “some” of those identified in the literature, suggesting that yours is not an exhaustive list and therefore you made a decision on what to include and what not to – how you made that selection needs to be explained and justified with respect to what was selected and what was not selected and why.

· The types of risk focused on are also very specific – why, for example, just focus on interest rate risk, rather than focusing on financial risk (already at least mentioned previously), of which interest rate risk is just one form? Similarly, raw material risk is just one of potential many risks associated with the supply chain, or a much broader category of external risks (also previously mentioned). There is no apparent logic to these overly narrow categorisations – the previous literature review should provide the basis for your selection of the most relevant types of risk to focus on.

· There is no indication in your discussion of these types of risk that you have tried to determine what SMEs are doing to manage these risks. You are not referring back, for example, to earlier models and frameworks for the management of risk to assess what SMEs are doing. You could, for example, assess whether or not SMEs are essentially accepting, reducing or transferring the risk associated with raw material supply, and how they are doing that. Or if they are not using a discernible risk management strategy, you should demonstrate this through your discussion and then consider which strategy would be appropriate. Indeed, for a more complete analysis, you could assess whether risks are internal or external, how much control they have over those risks, and therefore which is the most appropriate strategy to take.

· Yet another variation on the risk management process appears here on p50; this one with five rather than three or four stages. You need to have discussed all these variants in the lit review and therefore applied the most relevant and appropriate version for your analysis at this stage.

· This is not a “findings” or analysis chapter, it is another basic lit review chapter. It is based largely on large studies, which should give you some depth and scope for cross comparison and depth, but all you have really done with it is describe what you found about a new range of topics (with some cross-over with the prior lit review chapter), with a few comments on their findings, before moving on to the next topic. There is no logical linking between topics and no analysis.

· In looking at the different stages of the risk management process (identify, evaluate, etc.), you need to discuss the techniques used – what tools and techniques are used to identify risk, for example. There is some indication given for financial risks, but not those associated with design, production, the supply chain, etc. you should also be comparing what SMEs do in this regard with what large companies do, or what SMEs in developed countries do (where risk management may be better established among SMEs).

· Strategies are again being confused with tools and techniques – you use the terms interchangeably, and they should not be.

· The section on SME manager behaviours is very appropriate, but it appears as an isolated sub-section, with particular connection with the other sub-sections when in fact, the analysis should try to understand how this knowledge of behaviours, based on risk appetite, education and national/corporate culture affects the strategies used by SMEs, therefore inter-relating with the findings of other sections. So, for example, how exactly does the use of personal connections (used by SMEs) help to mitigate the specific supply chain risks that you identified in an earlier sub-section?

· Overall, this chapter consists mainly of a basic literature review rather than findings and analysis. It also confuses and uses interchangeably strategies, tools and techniques and risk mitigation. You need to show that you understand the differences and how they inter-relate. It also needs re-structuring around the key issues, or a specific framework, such as the risk management process stages, or the known behaviours of SME managers. As it stands, it is a collection of quite disconnected topics, with nothing tying them together. I also see no evidence of the case studies mentioned in the methodology chapter.

· Discussion

· The discussion raises static and speculative risks for the first time since the introduction – since they were not mentioned at all in the lit review or the findings, what relevance do these concepts actually have?

· This is not a discussion chapter – it simply summarises the introduction and some of the initial literature review; it does not consider the implications of the findings, or set out a framework for SMEs to use to manage risk better. Thus, it does not demonstrate how the research objective has been achieved.

· Conclusions and Recommendations for Further Work

· As above, no indication of key findings or their implications, and no indication that you have achieved your research objective – there is no framework offered as a result of this work.

· The recommendations for further work are undermined by the fact that significant areas of literature have been missed – specifically, the project management field, which offers significant research on the operationalisation of risk management.

References

· There are not enough references for a dissertation based purely on secondary sources.