1 / 34100%
ANALYZING KEY PERFORMANCE INDICATOR WITH BASED RISK
MANAGEMENT
I.1. INTRODUCTION
All companies must have dreams, goals, and plans about the future of their company. Goals
are defined as future conditions that the company wants and is trying to realize. Goals are
very important because companies are established to fulfill a purpose, and it is the goals that
define and determine that purpose.
A plan is a blueprint used to achieve goals, and determine the allocation of resources, time,
tasks, and other necessary actions (Richard, 2010). Especially in companies that focus on
profit oriented, namely profit-oriented companies (business organizations).
In this case the company must have a strategy to win the market by improving the company's
internal performance. Improving the company's internal performance is expected to provide
business stability to the company for the long term so that it can survive in an increasingly
competitive market. However, due to limited resources, companies cannot follow up on
performance improvement actions for all Key Performance Indicators (KPIs) simultaneously
so that management must be able to select KPIs that have a major influence on achieving
company goals.
To measure the extent to which the strategies that the company has carried out to achieve the
vision and mission, it requires Key Performance Indicators which also function as a
measuring tool and measure the extent to which the achievement of the company's vision and
mission is achieved vision and mission of the company. Every strategy setting, in a job or
business process/company always has a measure of success. Without a measure of success, it
is difficult to evaluate the extent to which a company or a person in a business process can be
said to be effective. Determining the success indicators of business strategies, work or
business processes is in fact the need of employers and employees. Measurement of business
process productivity is the answer to the desire of shareholders who always want feedback on
the health (healthy or sick) of their business. Therefore, the existence of Key Performance
Indicators is the answer to the desire of employees who always want a more objective
measure in assessing the results of their work (Arini, 2015).
In this research, efforts are made to arrange KPIs in performance measurement according to
priorities by identifying the risks of each KPI that can hinder the achievement of related
KPIs. The process of identifying risk events uses ISO ISO 31000 as a guide. While the
Analytical Hierarchy Process (AHP) method is used to obtain the weight of each risk that has
been identified. The AHP method was chosen because it has proven to be widely used in
various fields (ToloieEshlaghy & Homayonfar, 2011). KPIs were then organized based on the
weight of the risks.
1.2 PROBLEM FORMULATION
Based on the above background, the problem formulation in this study is as follows:
How to analyze the Risk Management Based Key Performance Indicator in the Company?
2.1 KEY PERFORMANCE INDICATOR
Banerjee & Buoti (2012), say Key Performance Indicators are scaled and quantitative
measures used to evaluate organizational performance in order to achieve organizational
targets. KPIs are also used to determine measurable objectives, see trends, and support
decision making. Key Performance Indicator is a measure that is quantitative and gradual for
the company and has various perspectives and is based on concrete data, and becomes the
starting point for determining goals and developing organizational strategies (Iveta, 2012).
According to Warren (2011), Key Performance Indicator or KPI has the meaning of a
measurement used to assess how an organization implements the strategic vision that has
been determined. The strategic vision itself can be intended as a goal that refers to how the
organization's strategy can be integrated interactively in the overall strategy of the
organization.
2.1 Best Practiced Risk Management ISO 31000:2009
The International Organization for Standardization (ISO) issued a standard framework for
managing risk, namely ISO 31000: 2009 with the title "Risk Management-Principles and
Guidelines on Implementation". This standard was issued to assist companies in managing
risk. Because of its generic nature, this framework can be applied to various types of
companies, groups or individuals. ISO 31000:2009 provides guidance in designing,
implementing and maintaining risk management processes within an organization.
2.2 RISK MANAGEMENT
Risk Management In the large Indonesian dictionary, risk has a definition as an unpleasant
(harmful, dangerous) result of an action or action. Meanwhile, risk management is a formal
process that enables the identification, assessment, planning and management of risk (Merna
& Thani, 2008). This is because the risks that occur and are not anticipated actually
contribute greatly to the occurrence of losses that can make the company's achievements not
achieved and can cause considerable losses to the organization. For this reason, the need for
risk management that is able to take into account the risks and their impacts and the ability to
overcome these risks has begun to be felt. Basically, risk management is a preventive
measure against risks that may occur.
2.2.1 Benefits of Risk Management
According to Darmawi, (2011), the benefits of risk management provided to the company can
be divided into 5 (five) main categories, namely:
1. Risk management may be able to prevent a company from failing.
2. Risk management directly supports profit improvement.
3. Risk management can provide indirect returns.
4. The manager's peace of mind that comes from being protected against pure risk is a
non-material asset to the company.
5. Risk management protects the company from pure risk, and since creditors customers
and suppliers prefer protected companies, it indirectly helps improve the public image.
2.2.1 Risk Components Business
Risk Compensation To make it easier for an organization to identify the risks it must face,
risks should be classified first. Many studies who have divided these risks into various
categories such as Frame (2003) who divides business risks into 5 main components.
1. Market Risk
Market risk is related to maintaining the company's products in the market or
maintaining and increasing the company's market share. Price competition, changes in
consumer policy, product cycles in the market and others.
2. Financial Risk
The risk suffered by investors as a result of the inability of stock and bond issuers to
fulfill their obligations to pay dividends or interest or interest and loan principal.
3. Regulatory Risk
Regulatory risk is related to the impact of regulatory products issued by the government
on the business fields engaged by the company. In general, before a regulation is
enacted, the government will conduct socialization for a certain period of time with the
aim that related industries can prepare themselves for the enactment of these rules.
4. Project Risks
Risks that arise in a project due to mismatches between planning and implementation in
the field such as project schedules that are delayed or even threatened with not being
completed on time, experiencing cost overruns or inability to achieve the desired
specifications, causing rejection by the customer.
5. Operational Risk
Risks arising from malfunctioning internal systems, human error, or system failure. The
source of operational risk is the most extensive compared to other risks, which comes
from operational and service activities, accounting, information technology systems,
management information systems or human resource management systems. In some
risk management implementations in companies, market risk, regulatory risk and
project risk are also referred to as business risk.
2.3 Risk Management Cycle
In risk management according to Djohanputro (2008), there are 5 systematic stages that must
be carried out, namely:
1.) Risk Identification This stage determines the possible risks of a business process
and the extent of their impact on the organization, documents the characteristics of each
risk and distinguishes between internal and external risks. The main source of the risk
that has the potential to cause a major condition must also be recognized. The impact
on the organization should be determined and categorized into financial,
operational/technical, personnel, and other areas. Techniques that can be used to obtain
the information needed to identify risks include brainstorming, surveys, interviews,
historical information, delphi techniques, questionnaires, SWOT analysis, and others.
In addition to risks, business activities that can be controlled with the aim of reducing
risks must also be identified. Other techniques can use McKenzie's 7S: shared value,
strategy, structure, staff, skill, system, and style.
2.) Risk Measurement This stage assesses the extent to which the impact of events
(events or circumstances) can interfere with the achievement of organizational goals.
The amount of impact can be known from inherent and residual risk, and can be
analyzed in two perspectives, namely: likelihood (tendency or opportunity) and
impact/consequence (the amount of risk realized). Thus, the amount of risk for each
organizational activity is the multiplication of likelihood and consequence. Risk
assessment can use two techniques, namely: (1) qualitative techniques; and (2)
quantitative techniques. Qualitative techniques use several tools such as self-assessment
(low, medium, high), questionnaires, and internal audit reviews. Meanwhile,
quantitative techniques use numerical data obtained from tools such as probability-
based, non-probabilistic models (optimize only consequence assumptions), and
benchmarking.
3.) Risk Mapping Risk mapping is intended to establish risk priorities based on their
importance to the company. The existence of priorities is because the company has
limitations in human resources and the amount of money so that the risk mapping can
be done in a timely manner Companies need to set the right priorities based on the
possible impacts.
4.) Risk Management Model There are several types of risk management models
including conventional risk management models, determination of risk capital,
management organization structure and others. Meanwhile, risk management according
to The Committee of Sponsoring Organizations of the Treadway Commission (COSO,
2004), is divided into 4 actions, namely:
Risk Avoidance♣ Do not undertake activities that create or increase the
occurrence of undesirable risks. If the company wants to do this, it should
consider the potential advantages and disadvantages.
Risk Reduction Also called risk mitigation is an action taken to reduce the
likelihood of risk occurrence or minimize the impact caused.
Risk Sharing♣ Reducing the likelihood of risk occurrence or impact can be done
by sharing or transferring part of the risk to another party. Generally, this
technique is done by buying insurance, entering into a transaction or value
protection contract and handing over the management of an activity to another
party (outsourcing).
Risk Acceptance♣ While certain risks can be eliminated by reducing or
transferring them, some risks must be accepted as a necessary part of an activity.
5.) Monitor and Control Monitor and control are important because:
Management needs to ensure that the implementation of risk management is in
accordance with the plan;
Management also needs to ensure that the implementation of risk management is
effective;
Risk itself evolves, and monitoring and control aims to monitor developments
against the trend of changing risk profiles. These changes have the effect of
shifting the risk map which automatically leads to changes in risk prioritization.
ANALYSIS AND DISCUSSION
This research aims to find out the risk-based KPIs at PT GRC Management, this research is
designed qualitatively by conducting a risk assessment that departs from the Company's
KPIs.
Enterprise Risk Management, according to Hayes (2022), is a system designed to identify and
analyze things that have the potential to hinder the achievement of the Company's goals (risks)
and open business opportunities (opportunities) in every business activity of the Company,
both arising from external and internal factors, as well as preventive and corrective actions
that must be taken.
A process influenced by all Company personnel, applied in setting strategy for the entire
Company environment. Designed to identify potential events that could affect the Company,
and to manage risk in accordance with the Company's risk appetite, in order to provide
assurance over the achievement of the Company's objectives.
3.1 RISK APPROACH
In conducting risk analysis, there are 5 (five) approaches that can be used, namely:
1.) Business Process
A business process is a structured and interrelated collection of activities or work to solve a
problem, produce a product or service, in order to achieve a certain goal. In the business of
PT GRC Management, which is engaged in management training and consulting, the
business process includes 3 things, namely management systems, quality management and
knowledge management.
2.) Target
Goals in business are quantitative objectives and benchmarks for successful business
performance. When formulating SMART goals, they should be specific, measurable, action-
oriented, realistic and timely or specific, measurable, action-oriented, realistic and timeless.
3.) Risk
Risk is a state of uncertainty and the level of uncertainty can be measured quantitatively.
Risk can also be interpreted as a state of uncertainty, where if an undesirable situation
occurs it can cause a loss. Risk associated with this uncertainty occurs due to lack of or
insufficient information about what will happen. Something that is uncertain can be
beneficial or detrimental.
4.) Causes
After determining the risk source environment, the next component of enterprise risk
management is to identify the events that cause the risk to occur. The causes of risk can
come from internal or external parties, which are the factors that cause business risk.
Internal parties mean that they come from the company itself, while external parties are
things outside the company's control.
5.) Impact
Anticipating the possibility of uncertainty in the future, in the context of risk management,
every company must analyze the impact that is likely to occur. So that it can be mitigated as
early as possible.
6.) Mitigation
Risk mitigation is an action taken by the company that is made in a planned and sustainable
manner to reduce or mitigate the possibility of events that have the potential to harm and
endanger the company.
3.2 Who Is A Risk Management
Key Performance Indicator (KPI) has been used in various lines of agencies both in the
government sector, as well as the financial sector such as banking and cooperatives.
Measuring company performance using the Key Performance Indicator approach includes 6
(six) perspectives, namely:
1.) Finance, which aims to see the benefits of assets, optimization of working capital.
2.) Customer (Customer) whose goal is to increase customer satisfaction, create customer
targets that can bring in a lot of profit.
3.) Internal (Process) which aims for full and on-time delivery, technology optimization,
effective relationships with key stakeholders.
4.) Learning and growth, which aims
t o
delegate, increase expertise and adaptability.
Community Environment whose purpose is to support local businesses, leading t o future
employees and community leadership.
5.) Employee Satisfaction which aims for a positive company culture, retention of key staff,
and increased rewards.
3.3 Risk Identification
Event Identification is a process designed and carried out by the Company to identify, know
and document events, the process of searching, finding, recognizing and describing a risk
based on its characteristics.
In achieving the company's target, the company also considers operational risk. Operational
Risk is the risk involved in the Company's operational activities that directly or indirectly
arises from the inadequacy or failure of internal processes, people, and systems or from
events beyond the Company's control, including natural disasters;
4.1 Conclusion:
From the research conducted, the following conclusions can be drawn:
1). The performance of PT GRC Management consulting has not been maximized because it
has not reached the target, not achieving a number of targets set in the Company's KPIs.
2).Mitigation carried out has been effective and efficient for the company
3). According to the researchers, all the risks that have been identified are below the tolerance
limit or in accordance with the company's risk appetite.
4.2 Suggestion:
1. Researchers are advised to conduct a comprehensive KPI analysis of the company line
2. The company is advised to carry out continuous monitoring as recommended by the risk
owner.
3. Monitoring the existing risks so that the risk scale can decrease to a minor scale.
2.3 Risk Management Cycle
In risk management according to Djohanputro (2008), there are 5 systematic stages that must
be carried out, namely:
1.) Risk Identification This stage determines the possible risks of a business process
and the extent of their impact on the organization, documents the characteristics of each
risk and distinguishes between internal and external risks. The main source of the risk
that has the potential to cause a major condition must also be recognized. The impact
on the organization should be determined and categorized into financial,
operational/technical, personnel, and other areas. Techniques that can be used to obtain
the information needed to identify risks include brainstorming, surveys, interviews,
historical information, delphi techniques, questionnaires, SWOT analysis, and others.
In addition to risks, business activities that can be controlled with the aim of reducing
risks must also be identified. Other techniques can use McKenzie's 7S: shared value,
strategy, structure, staff, skill, system, and style.
2.) Risk Measurement This stage assesses the extent to which the impact of events
(events or circumstances) can interfere with the achievement of organizational goals.
The amount of impact can be known from inherent and residual risk, and can be
analyzed in two perspectives, namely: likelihood (tendency or opportunity) and
impact/consequence (the amount of risk realized). Thus, the amount of risk for each
organizational activity is the multiplication of likelihood and consequence. Risk
assessment can use two techniques, namely: (1) qualitative techniques; and (2)
quantitative techniques. Qualitative techniques use several tools such as self-assessment
(low, medium, high), questionnaires, and internal audit reviews. Meanwhile,
quantitative techniques use numerical data obtained from tools such as probability-
based, non-probabilistic models (optimize only consequence assumptions), and
benchmarking.
3.) Risk Mapping Risk mapping is intended to establish risk priorities based on their
importance to the company. The existence of priorities is because the company has
limitations in human resources and the amount of money so that the risk mapping can
be done in a timely manner Companies need to set the right priorities based on the
possible impacts.
4.) Risk Management Model There are several types of risk management models
including conventional risk management models, determination of risk capital,
management organization structure and others. Meanwhile, risk management according
to The Committee of Sponsoring Organizations of the Treadway Commission (COSO,
2004), is divided into 4 actions, namely:
Risk Avoidance♣ Do not undertake activities that create or increase the
occurrence of undesirable risks. If the company wants to do this, it should
consider the potential advantages and disadvantages.
Risk Reduction Also called risk mitigation is an action taken to reduce the
likelihood of risk occurrence or minimize the impact caused.
Risk Sharing♣ Reducing the likelihood of risk occurrence or impact can be done
by sharing or transferring part of the risk to another party. Generally, this
technique is done by buying insurance, entering into a transaction or value
protection contract and handing over the management of an activity to another
party (outsourcing).
Risk Acceptance♣ While certain risks can be eliminated by reducing or
transferring them, some risks must be accepted as a necessary part of an activity.
5.) Monitor and Control Monitor and control are important because:
Management needs to ensure that the implementation of risk management is in
accordance with the plan;
Management also needs to ensure that the implementation of risk management is
effective;
Risk itself evolves, and monitoring and control aims to monitor developments
against the trend of changing risk profiles. These changes have the effect of
shifting the risk map which automatically leads to changes in risk prioritization.
ANALYSIS AND DISCUSSION
This research aims to find out the risk-based KPIs at PT GRC Management, this research is
designed qualitatively by conducting a risk assessment that departs from the Company's
KPIs.
Enterprise Risk Management, according to Hayes (2022), is a system designed to identify and
analyze things that have the potential to hinder the achievement of the Company's goals (risks)
and open business opportunities (opportunities) in every business activity of the Company,
both arising from external and internal factors, as well as preventive and corrective actions
that must be taken.
A process influenced by all Company personnel, applied in setting strategy for the entire
Company environment. Designed to identify potential events that could affect the Company,
and to manage risk in accordance with the Company's risk appetite, in order to provide
assurance over the achievement of the Company's objectives.
3.1 RISK APPROACH
In conducting risk analysis, there are 5 (five) approaches that can be used, namely:
1.) Business Process
A business process is a structured and interrelated collection of activities or work to solve a
problem, produce a product or service, in order to achieve a certain goal. In the business of
PT GRC Management, which is engaged in management training and consulting, the
business process includes 3 things, namely management systems, quality management and
knowledge management.
2.) Target
Goals in business are quantitative objectives and benchmarks for successful business
performance. When formulating SMART goals, they should be specific, measurable, action-
oriented, realistic and timely or specific, measurable, action-oriented, realistic and timeless.
3.) Risk
Risk is a state of uncertainty and the level of uncertainty can be measured quantitatively.
Risk can also be interpreted as a state of uncertainty, where if an undesirable situation
occurs it can cause a loss. Risk associated with this uncertainty occurs due to lack of or
insufficient information about what will happen. Something that is uncertain can be
beneficial or detrimental.
4.) Causes
After determining the risk source environment, the next component of enterprise risk
management is to identify the events that cause the risk to occur. The causes of risk can
come from internal or external parties, which are the factors that cause business risk.
Internal parties mean that they come from the company itself, while external parties are
things outside the company's control.
5.) Impact
Anticipating the possibility of uncertainty in the future, in the context of risk management,
every company must analyze the impact that is likely to occur. So that it can be mitigated as
early as possible.
6.) Mitigation
Risk mitigation is an action taken by the company that is made in a planned and sustainable
manner to reduce or mitigate the possibility of events that have the potential to harm and
endanger the company.
3.2 Who Is A Risk Management
Key Performance Indicator (KPI) has been used in various lines of agencies both in the
government sector, as well as the financial sector such as banking and cooperatives.
Measuring company performance using the Key Performance Indicator approach includes 6
(six) perspectives, namely:
1.) Finance, which aims to see the benefits of assets, optimization of working capital.
2.) Customer (Customer) whose goal is to increase customer satisfaction, create customer
targets that can bring in a lot of profit.
3.) Internal (Process) which aims for full and on-time delivery, technology optimization,
effective relationships with key stakeholders.
4.) Learning and growth, which aims
t o
delegate, increase expertise and adaptability.
Community Environment whose purpose is to support local businesses, leading t o future
employees and community leadership.
5.) Employee Satisfaction which aims for a positive company culture, retention of key staff,
and increased rewards.
3.3 Risk Identification
Event Identification is a process designed and carried out by the Company to identify, know
and document events, the process of searching, finding, recognizing and describing a risk
based on its characteristics.
In achieving the company's target, the company also considers operational risk. Operational
Risk is the risk involved in the Company's operational activities that directly or indirectly
arises from the inadequacy or failure of internal processes, people, and systems or from
events beyond the Company's control, including natural disasters;
4.1 Conclusion:
From the research conducted, the following conclusions can be drawn:
1). The performance of PT GRC Management consulting has not been maximized because it
has not reached the target, not achieving a number of targets set in the Company's KPIs.
2).Mitigation carried out has been effective and efficient for the company
3). According to the researchers, all the risks that have been identified are below the tolerance
limit or in accordance with the company's risk appetite.
4.2 Suggestion:
1. Researchers are advised to conduct a comprehensive KPI analysis of the company line
2. The company is advised to carry out continuous monitoring as recommended by the risk
owner.
3. Monitoring the existing risks so that the risk scale can decrease to a minor scale.
2.3 Risk Management Cycle
In risk management according to Djohanputro (2008), there are 5 systematic stages that must
be carried out, namely:
1.) Risk Identification This stage determines the possible risks of a business process
and the extent of their impact on the organization, documents the characteristics of each
risk and distinguishes between internal and external risks. The main source of the risk
that has the potential to cause a major condition must also be recognized. The impact
on the organization should be determined and categorized into financial,
operational/technical, personnel, and other areas. Techniques that can be used to obtain
the information needed to identify risks include brainstorming, surveys, interviews,
historical information, delphi techniques, questionnaires, SWOT analysis, and others.
In addition to risks, business activities that can be controlled with the aim of reducing
risks must also be identified. Other techniques can use McKenzie's 7S: shared value,
strategy, structure, staff, skill, system, and style.
2.) Risk Measurement This stage assesses the extent to which the impact of events
(events or circumstances) can interfere with the achievement of organizational goals.
The amount of impact can be known from inherent and residual risk, and can be
analyzed in two perspectives, namely: likelihood (tendency or opportunity) and
impact/consequence (the amount of risk realized). Thus, the amount of risk for each
organizational activity is the multiplication of likelihood and consequence. Risk
assessment can use two techniques, namely: (1) qualitative techniques; and (2)
quantitative techniques. Qualitative techniques use several tools such as self-assessment
(low, medium, high), questionnaires, and internal audit reviews. Meanwhile,
quantitative techniques use numerical data obtained from tools such as probability-
based, non-probabilistic models (optimize only consequence assumptions), and
benchmarking.
3.) Risk Mapping Risk mapping is intended to establish risk priorities based on their
importance to the company. The existence of priorities is because the company has
limitations in human resources and the amount of money so that the risk mapping can
be done in a timely manner Companies need to set the right priorities based on the
possible impacts.
4.) Risk Management Model There are several types of risk management models
including conventional risk management models, determination of risk capital,
management organization structure and others. Meanwhile, risk management according
to The Committee of Sponsoring Organizations of the Treadway Commission (COSO,
2004), is divided into 4 actions, namely:
Risk Avoidance♣ Do not undertake activities that create or increase the
occurrence of undesirable risks. If the company wants to do this, it should
consider the potential advantages and disadvantages.
Risk Reduction Also called risk mitigation is an action taken to reduce the
likelihood of risk occurrence or minimize the impact caused.
Risk Sharing♣ Reducing the likelihood of risk occurrence or impact can be done
by sharing or transferring part of the risk to another party. Generally, this
technique is done by buying insurance, entering into a transaction or value
protection contract and handing over the management of an activity to another
party (outsourcing).
Risk Acceptance♣ While certain risks can be eliminated by reducing or
transferring them, some risks must be accepted as a necessary part of an activity.
5.) Monitor and Control Monitor and control are important because:
Management needs to ensure that the implementation of risk management is in
accordance with the plan;
Management also needs to ensure that the implementation of risk management is
effective;
Risk itself evolves, and monitoring and control aims to monitor developments
against the trend of changing risk profiles. These changes have the effect of
shifting the risk map which automatically leads to changes in risk prioritization.
ANALYSIS AND DISCUSSION
This research aims to find out the risk-based KPIs at PT GRC Management, this research is
designed qualitatively by conducting a risk assessment that departs from the Company's
KPIs.
Enterprise Risk Management, according to Hayes (2022), is a system designed to identify and
analyze things that have the potential to hinder the achievement of the Company's goals (risks)
and open business opportunities (opportunities) in every business activity of the Company,
both arising from external and internal factors, as well as preventive and corrective actions
that must be taken.
A process influenced by all Company personnel, applied in setting strategy for the entire
Company environment. Designed to identify potential events that could affect the Company,
and to manage risk in accordance with the Company's risk appetite, in order to provide
assurance over the achievement of the Company's objectives.
3.1 RISK APPROACH
In conducting risk analysis, there are 5 (five) approaches that can be used, namely:
1.) Business Process
A business process is a structured and interrelated collection of activities or work to solve a
problem, produce a product or service, in order to achieve a certain goal. In the business of
PT GRC Management, which is engaged in management training and consulting, the
business process includes 3 things, namely management systems, quality management and
knowledge management.
2.) Target
Goals in business are quantitative objectives and benchmarks for successful business
performance. When formulating SMART goals, they should be specific, measurable, action-
oriented, realistic and timely or specific, measurable, action-oriented, realistic and timeless.
3.) Risk
Risk is a state of uncertainty and the level of uncertainty can be measured quantitatively.
Risk can also be interpreted as a state of uncertainty, where if an undesirable situation
occurs it can cause a loss. Risk associated with this uncertainty occurs due to lack of or
insufficient information about what will happen. Something that is uncertain can be
beneficial or detrimental.
4.) Causes
After determining the risk source environment, the next component of enterprise risk
management is to identify the events that cause the risk to occur. The causes of risk can
come from internal or external parties, which are the factors that cause business risk.
Internal parties mean that they come from the company itself, while external parties are
things outside the company's control.
5.) Impact
Anticipating the possibility of uncertainty in the future, in the context of risk management,
every company must analyze the impact that is likely to occur. So that it can be mitigated as
early as possible.
6.) Mitigation
Risk mitigation is an action taken by the company that is made in a planned and sustainable
manner to reduce or mitigate the possibility of events that have the potential to harm and
endanger the company.
3.2 Who Is A Risk Management
Key Performance Indicator (KPI) has been used in various lines of agencies both in the
government sector, as well as the financial sector such as banking and cooperatives.
Measuring company performance using the Key Performance Indicator approach includes 6
(six) perspectives, namely:
1.) Finance, which aims to see the benefits of assets, optimization of working capital.
2.) Customer (Customer) whose goal is to increase customer satisfaction, create customer
targets that can bring in a lot of profit.
3.) Internal (Process) which aims for full and on-time delivery, technology optimization,
effective relationships with key stakeholders.
4.) Learning and growth, which aims
t o
delegate, increase expertise and adaptability.
Community Environment whose purpose is to support local businesses, leading t o future
employees and community leadership.
5.) Employee Satisfaction which aims for a positive company culture, retention of key staff,
and increased rewards.
3.3 Risk Identification
Event Identification is a process designed and carried out by the Company to identify, know
and document events, the process of searching, finding, recognizing and describing a risk
based on its characteristics.
In achieving the company's target, the company also considers operational risk. Operational
Risk is the risk involved in the Company's operational activities that directly or indirectly
arises from the inadequacy or failure of internal processes, people, and systems or from
events beyond the Company's control, including natural disasters;
4.1 Conclusion:
From the research conducted, the following conclusions can be drawn:
1). The performance of PT GRC Management consulting has not been maximized because it
has not reached the target, not achieving a number of targets set in the Company's KPIs.
2).Mitigation carried out has been effective and efficient for the company
3). According to the researchers, all the risks that have been identified are below the tolerance
limit or in accordance with the company's risk appetite.
4.2 Suggestion:
1. Researchers are advised to conduct a comprehensive KPI analysis of the company line
2. The company is advised to carry out continuous monitoring as recommended by the risk
owner.
3. Monitoring the existing risks so that the risk scale can decrease to a minor scale.
2.3 Risk Management Cycle
In risk management according to Djohanputro (2008), there are 5 systematic stages that must
be carried out, namely:
1.) Risk Identification This stage determines the possible risks of a business process
and the extent of their impact on the organization, documents the characteristics of each
risk and distinguishes between internal and external risks. The main source of the risk
that has the potential to cause a major condition must also be recognized. The impact
on the organization should be determined and categorized into financial,
operational/technical, personnel, and other areas. Techniques that can be used to obtain
the information needed to identify risks include brainstorming, surveys, interviews,
historical information, delphi techniques, questionnaires, SWOT analysis, and others.
In addition to risks, business activities that can be controlled with the aim of reducing
risks must also be identified. Other techniques can use McKenzie's 7S: shared value,
strategy, structure, staff, skill, system, and style.
2.) Risk Measurement This stage assesses the extent to which the impact of events
(events or circumstances) can interfere with the achievement of organizational goals.
The amount of impact can be known from inherent and residual risk, and can be
analyzed in two perspectives, namely: likelihood (tendency or opportunity) and
impact/consequence (the amount of risk realized). Thus, the amount of risk for each
organizational activity is the multiplication of likelihood and consequence. Risk
assessment can use two techniques, namely: (1) qualitative techniques; and (2)
quantitative techniques. Qualitative techniques use several tools such as self-assessment
(low, medium, high), questionnaires, and internal audit reviews. Meanwhile,
quantitative techniques use numerical data obtained from tools such as probability-
based, non-probabilistic models (optimize only consequence assumptions), and
benchmarking.
3.) Risk Mapping Risk mapping is intended to establish risk priorities based on their
importance to the company. The existence of priorities is because the company has
limitations in human resources and the amount of money so that the risk mapping can
be done in a timely manner Companies need to set the right priorities based on the
possible impacts.
4.) Risk Management Model There are several types of risk management models
including conventional risk management models, determination of risk capital,
management organization structure and others. Meanwhile, risk management according
to The Committee of Sponsoring Organizations of the Treadway Commission (COSO,
2004), is divided into 4 actions, namely:
Risk Avoidance♣ Do not undertake activities that create or increase the
occurrence of undesirable risks. If the company wants to do this, it should
consider the potential advantages and disadvantages.
Risk Reduction Also called risk mitigation is an action taken to reduce the
likelihood of risk occurrence or minimize the impact caused.
Risk Sharing♣ Reducing the likelihood of risk occurrence or impact can be done
by sharing or transferring part of the risk to another party. Generally, this
technique is done by buying insurance, entering into a transaction or value
protection contract and handing over the management of an activity to another
party (outsourcing).
Risk Acceptance♣ While certain risks can be eliminated by reducing or
transferring them, some risks must be accepted as a necessary part of an activity.
5.) Monitor and Control Monitor and control are important because:
Management needs to ensure that the implementation of risk management is in
accordance with the plan;
Management also needs to ensure that the implementation of risk management is
effective;
Risk itself evolves, and monitoring and control aims to monitor developments
against the trend of changing risk profiles. These changes have the effect of
shifting the risk map which automatically leads to changes in risk prioritization.
ANALYSIS AND DISCUSSION
This research aims to find out the risk-based KPIs at PT GRC Management, this research is
designed qualitatively by conducting a risk assessment that departs from the Company's
KPIs.
Enterprise Risk Management, according to Hayes (2022), is a system designed to identify and
analyze things that have the potential to hinder the achievement of the Company's goals (risks)
and open business opportunities (opportunities) in every business activity of the Company,
both arising from external and internal factors, as well as preventive and corrective actions
that must be taken.
A process influenced by all Company personnel, applied in setting strategy for the entire
Company environment. Designed to identify potential events that could affect the Company,
and to manage risk in accordance with the Company's risk appetite, in order to provide
assurance over the achievement of the Company's objectives.
3.1 RISK APPROACH
In conducting risk analysis, there are 5 (five) approaches that can be used, namely:
1.) Business Process
A business process is a structured and interrelated collection of activities or work to solve a
problem, produce a product or service, in order to achieve a certain goal. In the business of
PT GRC Management, which is engaged in management training and consulting, the
business process includes 3 things, namely management systems, quality management and
knowledge management.
2.) Target
Goals in business are quantitative objectives and benchmarks for successful business
performance. When formulating SMART goals, they should be specific, measurable, action-
oriented, realistic and timely or specific, measurable, action-oriented, realistic and timeless.
3.) Risk
Risk is a state of uncertainty and the level of uncertainty can be measured quantitatively.
Risk can also be interpreted as a state of uncertainty, where if an undesirable situation
occurs it can cause a loss. Risk associated with this uncertainty occurs due to lack of or
insufficient information about what will happen. Something that is uncertain can be
beneficial or detrimental.
4.) Causes
After determining the risk source environment, the next component of enterprise risk
management is to identify the events that cause the risk to occur. The causes of risk can
come from internal or external parties, which are the factors that cause business risk.
Internal parties mean that they come from the company itself, while external parties are
things outside the company's control.
5.) Impact
Anticipating the possibility of uncertainty in the future, in the context of risk management,
every company must analyze the impact that is likely to occur. So that it can be mitigated as
early as possible.
6.) Mitigation
Risk mitigation is an action taken by the company that is made in a planned and sustainable
manner to reduce or mitigate the possibility of events that have the potential to harm and
endanger the company.
3.2 Who Is A Risk Management
Key Performance Indicator (KPI) has been used in various lines of agencies both in the
government sector, as well as the financial sector such as banking and cooperatives.
Measuring company performance using the Key Performance Indicator approach includes 6
(six) perspectives, namely:
1.) Finance, which aims to see the benefits of assets, optimization of working capital.
2.) Customer (Customer) whose goal is to increase customer satisfaction, create customer
targets that can bring in a lot of profit.
3.) Internal (Process) which aims for full and on-time delivery, technology optimization,
effective relationships with key stakeholders.
4.) Learning and growth, which aims
t o
delegate, increase expertise and adaptability.
Community Environment whose purpose is to support local businesses, leading t o future
employees and community leadership.
5.) Employee Satisfaction which aims for a positive company culture, retention of key staff,
and increased rewards.
3.3 Risk Identification
Event Identification is a process designed and carried out by the Company to identify, know
and document events, the process of searching, finding, recognizing and describing a risk
based on its characteristics.
In achieving the company's target, the company also considers operational risk. Operational
Risk is the risk involved in the Company's operational activities that directly or indirectly
arises from the inadequacy or failure of internal processes, people, and systems or from
events beyond the Company's control, including natural disasters;
4.1 Conclusion:
From the research conducted, the following conclusions can be drawn:
1). The performance of PT GRC Management consulting has not been maximized because it
has not reached the target, not achieving a number of targets set in the Company's KPIs.
2).Mitigation carried out has been effective and efficient for the company
3). According to the researchers, all the risks that have been identified are below the tolerance
limit or in accordance with the company's risk appetite.
4.2 Suggestion:
1. Researchers are advised to conduct a comprehensive KPI analysis of the company line
2. The company is advised to carry out continuous monitoring as recommended by the risk
owner.
3. Monitoring the existing risks so that the risk scale can decrease to a minor scale.
2.3 Risk Management Cycle
In risk management according to Djohanputro (2008), there are 5 systematic stages that must
be carried out, namely:
1.) Risk Identification This stage determines the possible risks of a business process
and the extent of their impact on the organization, documents the characteristics of each
risk and distinguishes between internal and external risks. The main source of the risk
that has the potential to cause a major condition must also be recognized. The impact
on the organization should be determined and categorized into financial,
operational/technical, personnel, and other areas. Techniques that can be used to obtain
the information needed to identify risks include brainstorming, surveys, interviews,
historical information, delphi techniques, questionnaires, SWOT analysis, and others.
In addition to risks, business activities that can be controlled with the aim of reducing
risks must also be identified. Other techniques can use McKenzie's 7S: shared value,
strategy, structure, staff, skill, system, and style.
2.) Risk Measurement This stage assesses the extent to which the impact of events
(events or circumstances) can interfere with the achievement of organizational goals.
The amount of impact can be known from inherent and residual risk, and can be
analyzed in two perspectives, namely: likelihood (tendency or opportunity) and
impact/consequence (the amount of risk realized). Thus, the amount of risk for each
organizational activity is the multiplication of likelihood and consequence. Risk
assessment can use two techniques, namely: (1) qualitative techniques; and (2)
quantitative techniques. Qualitative techniques use several tools such as self-assessment
(low, medium, high), questionnaires, and internal audit reviews. Meanwhile,
quantitative techniques use numerical data obtained from tools such as probability-
based, non-probabilistic models (optimize only consequence assumptions), and
benchmarking.
3.) Risk Mapping Risk mapping is intended to establish risk priorities based on their
importance to the company. The existence of priorities is because the company has
limitations in human resources and the amount of money so that the risk mapping can
be done in a timely manner Companies need to set the right priorities based on the
possible impacts.
4.) Risk Management Model There are several types of risk management models
including conventional risk management models, determination of risk capital,
management organization structure and others. Meanwhile, risk management according
to The Committee of Sponsoring Organizations of the Treadway Commission (COSO,
2004), is divided into 4 actions, namely:
Risk Avoidance♣ Do not undertake activities that create or increase the
occurrence of undesirable risks. If the company wants to do this, it should
consider the potential advantages and disadvantages.
Risk Reduction Also called risk mitigation is an action taken to reduce the
likelihood of risk occurrence or minimize the impact caused.
Risk Sharing♣ Reducing the likelihood of risk occurrence or impact can be done
by sharing or transferring part of the risk to another party. Generally, this
technique is done by buying insurance, entering into a transaction or value
protection contract and handing over the management of an activity to another
party (outsourcing).
Risk Acceptance♣ While certain risks can be eliminated by reducing or
transferring them, some risks must be accepted as a necessary part of an activity.
5.) Monitor and Control Monitor and control are important because:
Management needs to ensure that the implementation of risk management is in
accordance with the plan;
Management also needs to ensure that the implementation of risk management is
effective;
Risk itself evolves, and monitoring and control aims to monitor developments
against the trend of changing risk profiles. These changes have the effect of
shifting the risk map which automatically leads to changes in risk prioritization.
ANALYSIS AND DISCUSSION
This research aims to find out the risk-based KPIs at PT GRC Management, this research is
designed qualitatively by conducting a risk assessment that departs from the Company's
KPIs.
Enterprise Risk Management, according to Hayes (2022), is a system designed to identify and
analyze things that have the potential to hinder the achievement of the Company's goals (risks)
and open business opportunities (opportunities) in every business activity of the Company,
both arising from external and internal factors, as well as preventive and corrective actions
that must be taken.
A process influenced by all Company personnel, applied in setting strategy for the entire
Company environment. Designed to identify potential events that could affect the Company,
and to manage risk in accordance with the Company's risk appetite, in order to provide
assurance over the achievement of the Company's objectives.
3.1 RISK APPROACH
In conducting risk analysis, there are 5 (five) approaches that can be used, namely:
1.) Business Process
A business process is a structured and interrelated collection of activities or work to solve a
problem, produce a product or service, in order to achieve a certain goal. In the business of
PT GRC Management, which is engaged in management training and consulting, the
business process includes 3 things, namely management systems, quality management and
knowledge management.
2.) Target
Goals in business are quantitative objectives and benchmarks for successful business
performance. When formulating SMART goals, they should be specific, measurable, action-
oriented, realistic and timely or specific, measurable, action-oriented, realistic and timeless.
3.) Risk
Risk is a state of uncertainty and the level of uncertainty can be measured quantitatively.
Risk can also be interpreted as a state of uncertainty, where if an undesirable situation
occurs it can cause a loss. Risk associated with this uncertainty occurs due to lack of or
insufficient information about what will happen. Something that is uncertain can be
beneficial or detrimental.
4.) Causes
After determining the risk source environment, the next component of enterprise risk
management is to identify the events that cause the risk to occur. The causes of risk can
come from internal or external parties, which are the factors that cause business risk.
Internal parties mean that they come from the company itself, while external parties are
things outside the company's control.
5.) Impact
Anticipating the possibility of uncertainty in the future, in the context of risk management,
every company must analyze the impact that is likely to occur. So that it can be mitigated as
early as possible.
6.) Mitigation
Risk mitigation is an action taken by the company that is made in a planned and sustainable
manner to reduce or mitigate the possibility of events that have the potential to harm and
endanger the company.
3.2 Who Is A Risk Management
Key Performance Indicator (KPI) has been used in various lines of agencies both in the
government sector, as well as the financial sector such as banking and cooperatives.
Measuring company performance using the Key Performance Indicator approach includes 6
(six) perspectives, namely:
1.) Finance, which aims to see the benefits of assets, optimization of working capital.
2.) Customer (Customer) whose goal is to increase customer satisfaction, create customer
targets that can bring in a lot of profit.
3.) Internal (Process) which aims for full and on-time delivery, technology optimization,
effective relationships with key stakeholders.
4.) Learning and growth, which aims
t o
delegate, increase expertise and adaptability.
Community Environment whose purpose is to support local businesses, leading t o future
employees and community leadership.
5.) Employee Satisfaction which aims for a positive company culture, retention of key staff,
and increased rewards.
3.3 Risk Identification
Event Identification is a process designed and carried out by the Company to identify, know
and document events, the process of searching, finding, recognizing and describing a risk
based on its characteristics.
In achieving the company's target, the company also considers operational risk. Operational
Risk is the risk involved in the Company's operational activities that directly or indirectly
arises from the inadequacy or failure of internal processes, people, and systems or from
events beyond the Company's control, including natural disasters;
4.1 Conclusion:
From the research conducted, the following conclusions can be drawn:
1). The performance of PT GRC Management consulting has not been maximized because it
has not reached the target, not achieving a number of targets set in the Company's KPIs.
2).Mitigation carried out has been effective and efficient for the company
3). According to the researchers, all the risks that have been identified are below the tolerance
limit or in accordance with the company's risk appetite.
4.2 Suggestion:
1. Researchers are advised to conduct a comprehensive KPI analysis of the company line
2. The company is advised to carry out continuous monitoring as recommended by the risk
owner.
3. Monitoring the existing risks so that the risk scale can decrease to a minor scale.
2.3 Risk Management Cycle
In risk management according to Djohanputro (2008), there are 5 systematic stages that must
be carried out, namely:
1.) Risk Identification This stage determines the possible risks of a business process
and the extent of their impact on the organization, documents the characteristics of each
risk and distinguishes between internal and external risks. The main source of the risk
that has the potential to cause a major condition must also be recognized. The impact
on the organization should be determined and categorized into financial,
operational/technical, personnel, and other areas. Techniques that can be used to obtain
the information needed to identify risks include brainstorming, surveys, interviews,
historical information, delphi techniques, questionnaires, SWOT analysis, and others.
In addition to risks, business activities that can be controlled with the aim of reducing
risks must also be identified. Other techniques can use McKenzie's 7S: shared value,
strategy, structure, staff, skill, system, and style.
2.) Risk Measurement This stage assesses the extent to which the impact of events
(events or circumstances) can interfere with the achievement of organizational goals.
The amount of impact can be known from inherent and residual risk, and can be
analyzed in two perspectives, namely: likelihood (tendency or opportunity) and
impact/consequence (the amount of risk realized). Thus, the amount of risk for each
organizational activity is the multiplication of likelihood and consequence. Risk
assessment can use two techniques, namely: (1) qualitative techniques; and (2)
quantitative techniques. Qualitative techniques use several tools such as self-assessment
(low, medium, high), questionnaires, and internal audit reviews. Meanwhile,
quantitative techniques use numerical data obtained from tools such as probability-
based, non-probabilistic models (optimize only consequence assumptions), and
benchmarking.
3.) Risk Mapping Risk mapping is intended to establish risk priorities based on their
importance to the company. The existence of priorities is because the company has
limitations in human resources and the amount of money so that the risk mapping can
be done in a timely manner Companies need to set the right priorities based on the
possible impacts.
4.) Risk Management Model There are several types of risk management models
including conventional risk management models, determination of risk capital,
management organization structure and others. Meanwhile, risk management according
to The Committee of Sponsoring Organizations of the Treadway Commission (COSO,
2004), is divided into 4 actions, namely:
Risk Avoidance♣ Do not undertake activities that create or increase the
occurrence of undesirable risks. If the company wants to do this, it should
consider the potential advantages and disadvantages.
Risk Reduction Also called risk mitigation is an action taken to reduce the
likelihood of risk occurrence or minimize the impact caused.
Risk Sharing♣ Reducing the likelihood of risk occurrence or impact can be done
by sharing or transferring part of the risk to another party. Generally, this
technique is done by buying insurance, entering into a transaction or value
protection contract and handing over the management of an activity to another
party (outsourcing).
Risk Acceptance♣ While certain risks can be eliminated by reducing or
transferring them, some risks must be accepted as a necessary part of an activity.
5.) Monitor and Control Monitor and control are important because:
Management needs to ensure that the implementation of risk management is in
accordance with the plan;
Management also needs to ensure that the implementation of risk management is
effective;
Risk itself evolves, and monitoring and control aims to monitor developments
against the trend of changing risk profiles. These changes have the effect of
shifting the risk map which automatically leads to changes in risk prioritization.
ANALYSIS AND DISCUSSION
This research aims to find out the risk-based KPIs at PT GRC Management, this research is
designed qualitatively by conducting a risk assessment that departs from the Company's
KPIs.
Enterprise Risk Management, according to Hayes (2022), is a system designed to identify and
analyze things that have the potential to hinder the achievement of the Company's goals (risks)
and open business opportunities (opportunities) in every business activity of the Company,
both arising from external and internal factors, as well as preventive and corrective actions
that must be taken.
A process influenced by all Company personnel, applied in setting strategy for the entire
Company environment. Designed to identify potential events that could affect the Company,
and to manage risk in accordance with the Company's risk appetite, in order to provide
assurance over the achievement of the Company's objectives.
3.1 RISK APPROACH
In conducting risk analysis, there are 5 (five) approaches that can be used, namely:
1.) Business Process
A business process is a structured and interrelated collection of activities or work to solve a
problem, produce a product or service, in order to achieve a certain goal. In the business of
PT GRC Management, which is engaged in management training and consulting, the
business process includes 3 things, namely management systems, quality management and
knowledge management.
2.) Target
Goals in business are quantitative objectives and benchmarks for successful business
performance. When formulating SMART goals, they should be specific, measurable, action-
oriented, realistic and timely or specific, measurable, action-oriented, realistic and timeless.
3.) Risk
Risk is a state of uncertainty and the level of uncertainty can be measured quantitatively.
Risk can also be interpreted as a state of uncertainty, where if an undesirable situation
occurs it can cause a loss. Risk associated with this uncertainty occurs due to lack of or
insufficient information about what will happen. Something that is uncertain can be
beneficial or detrimental.
4.) Causes
After determining the risk source environment, the next component of enterprise risk
management is to identify the events that cause the risk to occur. The causes of risk can
come from internal or external parties, which are the factors that cause business risk.
Internal parties mean that they come from the company itself, while external parties are
things outside the company's control.
5.) Impact
Anticipating the possibility of uncertainty in the future, in the context of risk management,
every company must analyze the impact that is likely to occur. So that it can be mitigated as
early as possible.
6.) Mitigation
Risk mitigation is an action taken by the company that is made in a planned and sustainable
manner to reduce or mitigate the possibility of events that have the potential to harm and
endanger the company.
3.2 Who Is A Risk Management
Key Performance Indicator (KPI) has been used in various lines of agencies both in the
government sector, as well as the financial sector such as banking and cooperatives.
Measuring company performance using the Key Performance Indicator approach includes 6
(six) perspectives, namely:
1.) Finance, which aims to see the benefits of assets, optimization of working capital.
2.) Customer (Customer) whose goal is to increase customer satisfaction, create customer
targets that can bring in a lot of profit.
3.) Internal (Process) which aims for full and on-time delivery, technology optimization,
effective relationships with key stakeholders.
4.) Learning and growth, which aims
t o
delegate, increase expertise and adaptability.
Community Environment whose purpose is to support local businesses, leading t o future
employees and community leadership.
5.) Employee Satisfaction which aims for a positive company culture, retention of key staff,
and increased rewards.
3.3 Risk Identification
Event Identification is a process designed and carried out by the Company to identify, know
and document events, the process of searching, finding, recognizing and describing a risk
based on its characteristics.
In achieving the company's target, the company also considers operational risk. Operational
Risk is the risk involved in the Company's operational activities that directly or indirectly
arises from the inadequacy or failure of internal processes, people, and systems or from
events beyond the Company's control, including natural disasters;
4.1 Conclusion:
From the research conducted, the following conclusions can be drawn:
1). The performance of PT GRC Management consulting has not been maximized because it
has not reached the target, not achieving a number of targets set in the Company's KPIs.
2).Mitigation carried out has been effective and efficient for the company
3). According to the researchers, all the risks that have been identified are below the tolerance
limit or in accordance with the company's risk appetite.
4.2 Suggestion:
1. Researchers are advised to conduct a comprehensive KPI analysis of the company line
2. The company is advised to carry out continuous monitoring as recommended by the risk
owner.
3. Monitoring the existing risks so that the risk scale can decrease to a minor scale.
Students also viewed