1 / 20100%
RISK MANAGEMENT CONCEPT
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 2
5.1
Introduction:
Effective risk management is essential for successful modernization with regard to
organizations and production processes. Actually, risk management, on the one hand, leads to
strengthening the overall governance of the organization by supporting the decision-making
process when choosing priorities; on the other hand, it points to identifying, analyzing, and
eliminating uncertainties that may hinder change and development.
Starting or growing a business always requires taking risks. On this basis, it is
obviously important to identify, analyze, control and manage these risks, so it would be best to
use a methodological framework.
In implementing risk management in an organization, there is inevitably a fear of
"analytical weakness", a fear that so much time will be spent examining problems and potential
problems that do not exist and have never been resolved. There is also anxiety with regard to
administrative overload. Project managers are often among the busiest people in an
organization. They worry that they have to do so much more, and risk management is just one
more administrative function that they don't have time for.
As a result, risk sometimes becomes a secondary issue. In organizations where success
is the norm and failure Rarely, risk management is relegated to obscurity in the hope that
project managers will be able to deal with project issues as they occur.
Risks are considered a secondary issue only as long as the organization's luck holds out
or until a great opportunity is missed. Sooner or later, bad things happen to projects that are
already underway, and project managers without a clear strategy end up paying the price.
Regardless of whether it is calculated in terms of lost resources, messed-up schedules, or
budget overruns, the consequences of such failures will have to be borne by the project
manager.
Needless to say, there is also a stigma associated with risk management. It is considered
the "dark side" of a project (Carl L., 2015). When applied inconsistently, risk management
makes good risk managers appear pessimistic and resistant, whereas those who do not take a
proactive stance towards risk are perceived as team players. Therefore, the only time a project
manager can truly succeed as a risk manager, both individually and organizationally, is when
that manager has the support of the organization and its practices. That is why a clear and well-
developed set of risk practices and protocols is essential for the long-term survival of any
project organization.
5.2
Risk:
Risk has become the focal topic of many disciplines, professional activities, and
practical actions. The areas where risk is being addressed range from natural hazards,
technological threats, working conditions, ambient health impacts, crime, terrorism, and
pollution to leisure activities.
All risk concepts have one prerequisite: the possibility of human action. At any
moment, individuals, organizations or society as a whole face several options for taking action
(in this case including doing nothing), each of which is associated with potential positive or
negative consequences. Thinking about risk helps people to choose the one option that
promises more benefits than harms over all other options. If the contingent nature of our
actions is taken for granted, the term "risk" indicates the possibility that undesirable states of
reality (adverse effects) may occur as a result of natural events or human activities.
This definition implies that humans can, and will, make causal connections between
actions (or events). Consequences can be changed either by modifying the original activity or
event, or by reducing its impact. Therefore, the definition of risk contains three elements: an
outcome that impacts human value; the likelihood of occurrence (uncertainty); and the specific
context in which the risk may materialize (Buc, et al., 2009). Based on this, a structural
instrument was created to differentiate the concept of risk and to inform discussions on future
contributions and challenges:
1. Scope of negative effects: What are the undesirable outcomes, and who determines what
undesirable means?
2. Conceptualization of uncertainty: How can we specify, qualify, or quantify the likelihood
of undesirable outcomes?
3. Aggregation rules for practical purposes in specific contexts:
How do we combine outcomes, likelihoods, and other risk-related factors into a
common concept? enable risk comparison, prioritization, inclusion of social or cultural context,
and effective risk communication?
5.2.1
External vs Internal Risk Sources:
Risks originate both inside and outside the environment of a particular organization. For
example, many of the risks we face are beyond our control, as they arise outside of our area.
Government regulations fall into this category. Companies that produce hazardous materials,
for example chemical companies, are always worried that the government will change
environmental laws in such a way that it is difficult to manufacture their products cost-
effectively. Other examples of external sources of risk include the actions of competitors, acts
of nature (e.g. severe flooding disrupts the distribution of goods, etc.). Since external risks are
beyond our control, the direct actions we can take to deal with them are limited. However, we
can still manage these risks by developing strategies to deal with them effectively once an
unwanted risk event occurs.
Other risks lie directly in our area of control because they occur within the environment
of the organization we belong to. These are internal risks. Examples include risks associated
with using aging equipment, risks posed by hiring an incompetent workforce, and risks
associated with organizational politics. Many of these risks, particularly those related to the
conduct of operations, can be mitigated by fixing the source of the problem. Old equipment can
be replaced, employees can be trained, and competent workers can be hired.
Even within a defined organizational environment, there are internal risks that are
difficult to tackle head-on. Office politics is an example. However, there are defensive
measures that we can take to deal with them indirectly. For example, you can cultivate a good
relationship with two parties that are at odds politically, thus avoiding some of the
disadvantages that may arise when they join the battle.
Because life is full of risks, smart people and well-run organizations strive to manage
them as effectively as possible. Otherwise, they find that they are controlled by events. Good
management has to do with operating proactively, initiating actions that get the organization to
where it needs to be rather than responding to a continuous stream of small and large crises that
steer the organization wherever the current takes it. Risk management is the process of
consciously handling risk.
5.3
Risk Management Concept:
Risk management is a model within an organization aimed at developing the quality of
the management process; it stands out by analyzing events that have not yet materialized in the
organization. Unlike most managerial systems, risk management does not overlap with other
internal controls because it represents a different perspective that includes planning and
control, performance evaluation systems, auditing, quality and so on.
Therefore, risk management helps organizations produce higher levels of service and
product quality because it supports the decision-making process, preparing for difficulties that
may hinder the achievement of strategic goals (Putra, et al., 2019). In summary, the main
objectives of risk management concern protection and reinforcement:
•
Values, ethics and a sense of belonging
•
Tangible and intangible assets
•
Growth of organizational culture
•
Leadership and relationships
•
Process effectiveness and efficiency
•
Resources for strategic priorities
•
Stakeholder satisfaction
That is, risk management is a tool to effectively manage an organization; in fact, it deals
with risks and opportunities that affect the creation or preservation of an entity's value. Risk
management is defined as: "a process, influenced by the entity's board of directors,
management, and other personnel, applied in strategy setting and throughout the enterprise,
designed to identify potential events that could affect the entity, and manage risks to be within
its risk appetite, to provide reasonable assurance regarding the achievement of the entity's
objectives".
Apart from the definition of risk, the objectives of risk management can also be quite
different. Practically speaking, risk management aims to achieve one of two things, which if
studied carefully, appear to be fundamentally different:
•
Direct and individualized management of each risk within the framework of the risk
management policy
•
Global and indirect risk management using security policies adapted to possible risks
•
5.3.1
Risk Management Framework:
The risk management framework has 5 steps, namely (Davidson, 2003):
1. Plan for risk. Be prepared to consciously manage risk. Effective risk management does not
happen by chance. It is the result of careful thinking and planning
2. Risk identification. Regularly scan the organization's internal and external environment for risk
events that might affect its operations and well-being. Through this process, we develop a good
understanding of the bad things we may encounter in our projects and work operations.
3. Assess the impact of the risk both qualitatively and quantitatively. Systematically determine the
consequences associated with its occurrence. Think of consequences that are difficult to
measure through qualitative analysis. Model measurable consequences with quantitative
analysis.
4. Develop a risk handling strategy. Now that you know what risk events you might encounter
(Step 2) and the consequences associated with them (Step 3), develop a strategy to deal with
them. For example, would it help to take out insurance for shipping goods to Thailand? Should
you buy new equipment to replace an old machine that is about to break down?
5. Monitor and control risks. As projects and operations are underway, you need to monitor the
organization's risk space to see if unwanted events have arisen that need to be addressed. If
monitoring efforts identify issues in the process, then steps should be taken to control them
Steps 2 through 4 are risk assessments. At this stage we are invited to prepare ourselves for the
occurrence of undesirable events. Step 5 takes us into the realm of action by asking us to deal
with ongoing problems. Risk management is a combination of risk assessment and action. One
of the major challenges people face in managing risk is bridging the gap between the
anticipated events that emerge through risk assessment and reality.
The review of the risk management process above highlights several points that with
risk management:
1. encourage people to take a conscious and systematic approach to dealing with risk. In doing so,
they help move risk management from the realm of accidental to the realm of proactive.
2. Elicits risk events that would not otherwise be recognized. Consequently, it reduces the number
of unforeseen events that managers may encounter in the course of doing work.
3. Allows managers to calculate the consequences of environmental events. With this information
about the impact of risk events, managers can make informed judgments about the direction in
which they want to go
4. Provide managers with guidance on what steps they can take to reduce the likelihood of an
undesirable event arising, and when it does arise, what steps they can take to minimize the
negative impact.
5. Benefits are limited by quantitative or qualitative information, because it is information that
helps us make judgments and ultimately make decisions.
Risk management is the process of utilizing information to help people make decisions.
If information is lacking, the possibility of limiting the amount of effective risk management is
also reduced. If information is plentiful, then risk managers may be able to use a variety of risk
management tools. Ironically, the need for risk management is often greatest in situations
where information is lacking or corrupted.
5.3.2
Benefits of Effective Risk Management:
Risk management applied holistically, as part of a fully integrated project management
process should deliver benefits. Empirical research by Dr. Terry Cooke-Davies who collected
project performance data from benchmarking networks from various industries, showed that
risk management is the single most influential factor in project success. Where risk
management is well implemented, more projects meet plan targets (on average 95% of plan
targets are met). Figure 5.1. presents typical data documenting risk management
responsibilities in projects.
Unfortunately, although risk management is highly influential on project success, the
same study also found that risk management is the lowest scoring of all project management
techniques in terms of effective deployment and utilization, because although organizations
acknowledge about risk management but organizations do not implement effectively. As a
result many projects fail. When implemented correctly, risk management can provide direct
and indirect benefits, as listed in the Association for Project Management- Project Risk
Analysis and Management (APM-PRAM) guide
Based on the table above, it shows that there is nothing wrong in applying the concept
of risk management, because the concept is clear, the process is well-defined, the techniques
are good evidence exists, tools are widely available to support the process, and there are many
training courses to develop risk management knowledge and skills. Therefore, mistakes can
happen during implementation. The problem in implementing risk management does not lie in
"why, what, who, or when". Lack of effective risk management is more often due to not
knowing how to implement risk management.
Not all projects require a formalized risk management approach, but to gain maximum
benefit, risk management should be a systematic process that is applied in a disciplined manner
(Kadir, et al., 2020). Simply put, not every project has to follow every step, but it is mandatory
to apply its basic practices (Carl L., 2015). Many project managers use intuitive reasoning
(guessing) as a starting point in the decision-making process. That's not a bad place to start.
However, truly effective managers will look beyond simple reasoning and experience in
making decisions that involve significant risk.
Even the most experienced project managers have not faced every risk. There are some
risks that they cannot envision or do not fit into their paradigm; and there are still more that
they cannot predict. Some risks are so far beyond any individual's expectations or experience
that they are impossible to consider without external input.
A more in-depth explanation of the implementation of risk management and control
will be discussed in the following chapters.
RISK MEASUREMENT:
6.1
Introduction
Risk is related to everything that is uncertain, which is part of the work life of
individuals and organizations, and can threaten the achievement of individual and
organizational goals. One of the causes is the lack of supporting information. Risk
measurement is carried out to determine the risk and its impact, so as to prioritize the risk of
determining the most appropriate method and combination of methods in tackling and
overcoming risks. (Dionne, 2013) and (Hicham and Ibnalkadi, 2021)
6.2
Risk Measurement Principles
Principles in risk measurement are not only useful as a basis for developing a reliable
risk management model framework. The principles will also determine the success in
implementing the risk management model. Risk measurement principles include:
1. Transparency: all transactions should be provided openly and nothing should be hidden.
2. Accurate measurement, as continuous investment requires accurate measuring techniques and
tools.
3. Quality and timely information, because it will affect the accuracy of measurements and the
quality of decisions to be made, as well as financial and non-financial risks.
4. Diversification needs to be considered with the assumption that risks can occur at any time
according to changes.
5. Independence, both in authority, responsibility.
6. A disciplined decision pattern requires decisions to be consistent.
7. Policies require that goals and strategies be formulated into clear policy manuals and
procedures.
Risk measurement is carried out after the organization identifies risks. Based on several
opinions from (Hui, Yi- qian, Wan, 2009), (Dionne, 2013) (Broad, Bue et al. 2019), and
(Kirimova, Sorochkina, Savvin Dionne, 2021) in summary the identification steps include:
6.3
Risk Identification
Risk identification is an activity to conduct a systematic and continuous analysis, in an
effort to find the possibility of potential losses. Identification is done to see the threat of
uncertainty faced by the organization. Identification is done differently with different methods,
so that it can be ensured that it is safe for the organization.
Every risk must be identified, if it cannot be identified, then the risk cannot be recognized
(Dionne, 2013) and (Dumitrascu, 2018). As a result, management cannot manage risks
properly.
6.4
Risk Measurement
6.4.1
Measured Dimensions
1. The frequency and number of events that will occur, which can cause losses or direct causes
that cause losses and risks, in a period.
2. The frequency of losses that occur and the severity of an event that causes losses.
The measurement results include the dimension :
a.
Average value of losses in one budget period.
b.
Variation in the value of losses from one budget period to another.
c.
The overall impact of losses, if for example losses are self-inflicted, and should be included in
the analysis, so that the value is not just in rupiah terms.
1. Identify risk characteristics
2.
Measure the risk, develop a measure of the size of the risk
3. Measure the impact of the risk on the organization
4.
Risk evaluation and measurement can be used to
prioritize risks.
Risk measurement is used to obtain information to
determine the combination of risk management tools that are in
accordance with the measured dimensions. Based on the
opinions of (Podzines, Romanovs, 2017), and (Hicham and
Ibnalkadi, 2021) dimensional measurements must include;
6.4.2
Type of Risk Measurement
1.
Loss Frequency Measurement:
A measurement used to determine how many times a type of behavior can happen to an object,
within a certain period of time, generally one year.
There are two things to consider:
a.
Some types of losses that can befall an object.
b.
Several types of objects that can be exposed to a type of loss.
Both of the above reasons greatly affect the probability of potential losses.
The frequency dimension has four categories;
1. Almost nil (No loss)
2. Slight (Almost no loss)
3. Moderate (Slight loss)
4. Definite (There is a loss)
Every loss event will be direct and indirect Direct impact is usually measured using the
concept of acquisition value. Indirect impacts are measured using additional costs, such as rent
and reduced income.
2.
Loss Severity Measurement.:
The measurement of risk of severity is used to determine the magnitude of the loss value,
associated with its effect on the condition of the company, especially financially. The
possibility that a loss occurs from each behavior that causes LOSS consists of: Probability of
maximum loss, Probability of minimum loss, and overall maximum loss from each year. There
are 4 (four) categories of potential losses from the dimension of severity:
1. Normal Loss Expectancy,
2. Probable Maximum Loss,
3. Maximum Foreseeable Loss,
4. maximum possible loss.
3. Concept of Probability:
Loss measurement with the concept of probability is carried out by looking at the dimensions
of frequency, severity associated with the probability of potential loss events. Probability
calculation has two stages as follows:
1)
Define possible outcomes
2)
Estimating the probability of an event
The requirements for determining the probability of an event are twofold:
a.
The probability of an event is between: 0 to 1 (0≤ P ≤1)
b.
The sum of the probabilities is 1
The methods used in calculating the probability of an event include: classical, relative
frequency, and subjective methods. Probability calculations must of course pay attention to
which events are included, because there are 3 events in probability, namely:
1. Mutually exclusive events
2. Inclusive events are.
3. Events that are compound events, both independent and conditionl compount events.
Table 6.2. shows that different measurement techniques will result in different types of
risks. The level of risk measurement starts from simple to sophisticated. From frequency
matrices to more complicated stress-testing. The simplest measurement technique is using the
Frequency and Significance matrix. The measurement is done by categorizing risks into 2
(two) dimensions, namely frequency and significance. The process is:
1. Develop risk standards
2. Apply the standard to the identified risks.
Example Measurement technique using Frequency and Significance matrix.
Step one: risk managers create and set standards: the frequency of occurrence of
adverse events using three criteria, namely low, medium and medium frequency. And using the
loss significance criterion in the normal, medium, and serious categories. The next step applies
the technique to implement a specific risk evaluation.
Where measurement techniques are most difficult to quantify, such as technology risk,
scenario analysis techniques are an alternative. The scenario technique involves developing
several scenarios and looking at their impact on the organization.
Probability distribution measurement is done with the aim of to provide a qualitative
description of the probability or frequency of an event. Probability is measured by The ratio of
specific events to the number of possible events, with values between 0 and 1. 0 indicates an
unlikely event and 0 indicates a definite event.
Sample Space (Event scope) is a set of events or observed events. Example: the number
of vehicle accidents in area X in a certain period. Then Set S, includes a sub set or Set E.
If the number of vehicle accidents consists of private and public vehicle segments, then what is
the probability of risk?
The calculation of the risk probability can be done as follows:
1)
Weighting Set E. The basis for weighting is empirical evidence from past experience. Suppose
weight 2 for private vehicles and weight 1 for public vehicles.
2)
Accident probability calculation:
a.
weightlessness: P(E) = E/S
b.
with weight: P (E) = W (E) X W (S) Description:
P (E) = probability of event occurrence. E = sub set or event
S = sample space or set
W = weight of each event
Example: The number of vehicle accidents in Semarang City is known, based on police records
in 2023 there were 100,000 vehicle accidents. From this number,
10,000 are private vehicle accidents and 90,000 are public vehicle accidents. The weight is set
to 1.5. Then the probability of a private vehicle accident:
a.
Unweighted P(E) = 10,000/100,000 = 0.1 = 10%
b.
With weight P (E) = 1,500 = 15%
The results of the risk probability calculation can be classified into 5 (five) categories: Very
rare, Rate, Possible, Likely, and Almost certain.
2.
Notional Risk Approach:
The basis of risk measurement is the value of the exposure or object that is vulnerable to risk.
For example, if a bank lends 50 million rupiah to a customer, then based on the national
approach, the amount of credit risk is 50 million rupiah (Bouteille, 2012).
3.
Risk Sensitivity Approach:
The basis of risk measurement, on how sensitive an exposure is. Exposures are objects that are
susceptible to risk, and to changes in determinants. Or risk determinants.
Example: Degree of operating leverage (DOL), in addition to measuring the sensitivity of
operating profit to changes in sales, also measures business risk.
4.
Risk Volatility Approach:
The basis of measurement is how much the exposure value fluctuates. A commonly used
measure is standard deviation or deviation. The greater the standard deviation of an exposure,
the more the exposure value fluctuates, meaning the riskier the exposure or asset.
5.
Value At Risk (VAR) Approach:
The basis of measurement is the maximum loss incurred on an asset or investment over a
certain period with a certain level of confidence. Measurement with the VAR, standard
deviation data and Z scores from the normal distribution table are required.
6.
Risk frequency and significance matrix approach:
The basis of measurement is done through two processes:
a.
First by developing risk standards
b.
Second, apply standards to the risks that have been identified.
7.
A scenario analysis approach:
It is based on the ability of the organization's managers to predict the conditions that will occur,
as well as the amount of loss. For example, in measuring the level of sophistication, different
types of risk use different measurement techniques.
Risk measurement is always followed by an evaluation of the risk measurement, with
the aim of understanding the characteristics of the risk, so that it is easier to control.
RISK CONTROL
By Irfany Rupiwardani
7.1
Introduction
There are several risks of loss associated with organizations covering various
operational, market, legal, environmental, brand, financial, and property areas. Risk
management needs to be implemented in every organization in order to minimize large losses.
Risks must be assessed and controlled. Organizations need to balance the level of risk with
time, energy, cost and ongoing maintenance in every risk control. When the risk is at a level
that is considered tolerable, then the organization does not need to take further action especially
if the cost and complexity of the control measures are not directly proportional to the targeted
reduction in risk level.
Risk control in risk management is the process of identifying, assessing, and mitigating
risks associated with an activity or business process. The basic objective of risk control is to
reduce or eliminate unwanted risks, or to ensure that such risks can be appropriately managed
if they occur.
According to (Wideman, 2011), uncertainties that arise can be called opportunities,
while uncertainties that result in losses are called risks. Uncertainty about a situation made
based on decisions based on various considerations is called risk.
In recent years, risk management has become a major trend in various discussions,
practices, as well as Training. Risk management can be reduced or even eliminated through
risk control with risk control methods focused on reducing the likelihood of risks occurring and
mitigating the consequences of those risks, which are implemented before, during, or after the
risk occurs.
Risk control is an activity that describes an organization applying measurements in
classifying various existing problems using various management approaches in a
comprehensive and systematic manner. In other words, this is one way to save the company
from losses.
In risk control, the usual steps include identifying risks that may arise, assessing and
analyzing risks, developing appropriate risk management strategies, and implementing
preventive or mitigation measures. The risk control process is carried out on an ongoing basis,
with continuous monitoring and review of risk conditions that change from time to time.
7.2
Causes of Risk:
Risks cannot be avoided but organizations need to control risks. Risk control is aimed at
reducing the likelihood of occurrence, reducing the seriousness or both.
There are several theories that seek to explore the causes of risk, including:
1. Domino Theory
This theory states that the occurrence of an accident can be seen in the following five stages:
a.
Social environment and inborn factors can cause a person to behave in a certain way (high
temperament)
b.
Error Personal, i.e. when personal does not respond correctly in certain situations.
c.
Unsafe acts or physical harm
d.
Accident
e.
Wounded
2. Risk Chain:
Risk that arising can be broken down into several components:
a.
Danger
b.
The environment where Hazard is located
c.
Hazard interaction with the environment
d.
Interaction Result
e.
Consequences of this result (Mekhofer, 1980)
7.3
Risk Control Objectives:
1. The company has power in every decision making. Then a manager will be more careful and
always place a controlling dimension in various decisions.
2. Provide the right direction to the company in seeing the effects that will arise in the short or
long term.
3. Encourage managers in decision-making to avoid the impact of financial losses.
4. In order for the company to experience the minimum risk of loss.
7.4
Importance of Risk Control:
Risk control is essential because risk is a natural part of life and business. Risk can
cause loss and even devastation to individuals, organizations, and society as a whole.
Here are some reasons why risk control is so important (Leitch, 2016):
1. Preventing Losses: Controlling risk helps prevent losses that may occur as a result of
undesirable events.
2. Minimizing Negative Impact: In situations where losses are unavoidable, risk control can help
minimize the negative impact that may occur.
3. Improve Safety: Risk control can improve safety in business and work environments, which
can help prevent accidents and injuries.
4. Maintaining Reputation: Risk control can help maintain a good reputation for the organization
by avoiding events that could damage its image and customer trust.
5. Maintaining Business Continuity: Risk control can also help maintain business continuity by
avoid losses that may threaten business continuity.
With proper risk control, an organization can reduce losses and achieve its goals more
effectively and efficiently.
7.5
Difference between Risk Control and Risk Management
Risk control and risk management are two concepts that are closely related but have
significant differences. The following are the main differences between risk control and risk
management (Crouhy, M., Galai, D., Mark, 2014):
1. Focus: Risk control aims to control identified risks and establish preventive or mitigating
measures to reduce the impact of those risks. Meanwhile, risk management focuses more on
the entire risk management cycle, namely risk identification, analysis, evaluation, control and
monitoring.
2. Scope: Risk control is usually more focused on one or a few specific risks that have been
identified and need to be managed. Risk management, on the other hand, covers all risks
associated with a particular activity or business, including risks that have not yet been
identified.
3. Timing: Risk control is done when risks have been identified and need to be addressed
specifically. Meanwhile, risk management is a process that is carried out continuously and
continuously with the risk management cycle.
4. Objective: Risk control aims to reduce the impact of existing risks or prevent risks from
occurring. Meanwhile, risk management aims to manage risk as a whole to achieve business
objectives or activities more effectively.
5. Methodology: Risk control involves concrete actions to reduce the impact of identified risks,
by means of avoiding risks, transferring risks, reducing risks, or accepting risks. Meanwhile,
risk management involves a holistic approach that includes risk identification, risk analysis,
risk evaluation, risk control, and continuous risk monitoring.
In conclusion, risk control is a part of risk management that focuses on handling
specific risks. Meanwhile, risk management is a holistic approach to overall risk management,
including risk control.
7.6
Risk Control Methods
Several risk control methods can be carried out, according to ISO 31000 in (Vorst, C.,
Budiman, 2018), among others:
1. Avoidance. The risk avoidance method is carried out by avoiding activities or situations that
have the potential to cause risk. An example is a company not continuing to invest in a project
that is considered to have too high a risk.
Some basic characteristics of risk aversion should be considered:
a.
There is no possibility to avoid risk, the greater the risk, the more difficult it is to avoid it,
for example if you want to avoid all liability risks, then all activities must be stopped.
b.
Potential benefits or advantages that may be obtained due to ownership goods,
employment of employees, or responsibility for the activity may be lost if risk controls are
implemented.
c.
The smaller the perceived risk, the greater the likelihood of new risks being created. For
example, by avoiding the risk of shipping and replacing it with land transportation, the risk
associated with land transportation will be greater.
2. Reduction. Risk reduction methods are carried out by reducing the frequency or impact of risks
that arise. An example is a company that regularly backs up data to reduce the risk of data loss
due to system failure.
3. Transfer. The risk transfer method is carried out by transferring the risk to another party, for
example by buying insurance or contracting the work to a third party.
Risk transfer can be done in three ways:
a.
The risky property or activity can be transferred to another party, either expressly stated,
or following a contract.
Example: A company that sells one of its buildings automatically transfers the risks
associated with the ownership of the building to the new owner. There are also
companies that hand over part of their company's activities to a contractor, with the aim
of transferring all the risks associated with the work.
b.
Transferring risk.
Example: In the case of a building rental, the tenant can transfer risk to the landlord
regarding any liability for damage to the building caused by the tenant.
c.
Risk financing transfers create loss exposure for the transferee. Cancellation of the
agreement by the transferee can be seen as a third way of transferring risk control. With
such rescission, the transferee is not legally liable for the losses that it had originally
agreed to pay.
4. Acceptance. The risk acceptance method involves accepting the risk without taking significant
control measures. An example is a company that accepts the risk that its revenue will decrease
during the holiday season due to decreased consumer activity.
5. Mitigation. Risk mitigation methods are carried out by reducing or preventing the possibility of
risk occurrence. An example is a company that puts up warning signs in construction areas to
prevent accidents from occurring at the site.
6. Investigation. The risk investigation method is carried out by finding out more details about the
risks that arise, both frequency and impact, so that companies can better control risks. An
example is a company that conducts a cybersecurity survey to find out the risks associated with
hacker attacks.
Each company can choose risk control methods according to its needs and situation. It
is important to conduct regular risk evaluations and update the risk control strategy if
necessary.
7.7
Risk Control Principles
Risk control principles are an approach to reducing risk or loss in a situation or activity.
Some of the risk control principles that are commonly used as a reference according to ISO
31000: 2018 are:
1. Risk Identification: The first step is to identify possible risks in a situation. This can be
accomplished by conducting a risk analysis that includes identifying the source of the risk, the
type of risk, and the potential impact of the risk.
The steps in loss control are identifying and analyzing:
a.
Losses that have been incurred. To obtain loss information, the Loss Controller must build:
A network of information providers and loss reporting forms
b.
Hazards that cause harm or that may cause harm in the future This step requires: A
comprehensive reporting system and continuous inspection.
2. Risk Evaluation: Once the risk has been identified, the next step is to evaluate the risk by
considering its severity, probability, and impact. This risk evaluation can help in determining
the actions that need to be taken to control the risk.
3. Risk Control Planning: Once the risks have been evaluated, the next step is to plan the actions
to be taken to control the risks. At this stage, it is necessary to prioritize actions based on the
level of risk and the availability of available resources.
4. Risk Control Implementation: Once the planning is done, the next step is to implement the
planned actions to control the risks. The implementation of this risk control includes the
implementation of policies, procedures, and controls that are in accordance with the risks
faced.
5. Monitoring and Evaluation: Once control measures are implemented, the next step is to
monitor and evaluate the effectiveness of the controls implemented. The evaluation is carried
out to find out whether the controls that have been implemented are effective in reducing risk
or not. If not, then further improvement and development is needed.
6. Adjustment: If the evaluation shows that the implemented controls are not effective, the final
step is to make adjustments to the implemented controls or take new control measures to
address the identified risks.
By applying these risk control principles, it is expected that risks can be managed more
effectively and losses can be reduced or avoided altogether.
7.8
Risk Control Environment
The risk control environment is the internal and external factors that influence an
organization's ability to identify, evaluate and respond to risks. These factors include
organizational culture, organizational structure, regulatory environment, and internal policies
and procedures. (Krisnandi, 2019)
Here are some examples of factors that can affect the risk control environment:
1. Organizational culture: An organizational culture that supports risk management and
compliance can influence the extent to which risks are properly managed.
2. Organizational structure: A clear and well-organized organizational structure can facilitate risk
identification and management.
3. Regulatory environment: Strict regulatory environments can help organizations reduce risk, but
they can also make managing risk more complicated and costly.
4. Internal policies and procedures: Clear and well-structured policies and procedures can help
organizations manage risks effectively.
5. Technology: Technology can help organizations identify and manage risks more effectively,
such as through the use of risk analysis tools or risk management software.
6. Workforce: Employees trained and skilled in risk management can help organizations better
identify and manage risks.
All these factors can interact with each other and affect the overall risk control
environment. Therefore, organizations should pay attention to all such factors and ensure that
they support effective and efficient risk management.
7.9
Risk Control Hierarchy
One appropriate way to assess controls and identify new control measures by
considering how effective they are is with the risk management hierarchy. This risk control
hierarchy utilized when conducting risk assessment, hazard control and risk minimization
activities.
In layman's terms, this risk control hierarchy has been used in determining how to
implement effective and feasible control solutions. There are control methods at the top of the
chart that are potentially more effective and protective than the methods at the bottom listed in
the chart information by NIOSH (The National Institute for Occupational Safety and Health.
1. Eliminated
While it is the most effective in reducing hazards, it tends to be the most difficult to implement
in the process. It may be inexpensive in cost and easy to use but in process, equipment and
procedure changes may be required. Remove or replace hazards.
2. Replaced
Changeover is a common control activity of concern. Advances in technology and
manufacturing make alternatives safer and readily available, such as current equipment with
low noise and vibration levels. Substituting a different substance may have less risk, such as
cleaning solutions.
3. Technical Control
Engineering controls are a suitable way to control hazards at source. Anything can be designed
and built to make the workplace safer. This type of control generally provides a safer
environment for everyone and not just individuals. For example, enclosures to separate the
hazard from everyone outside it. Ventilation of hazardous fumes or gases at their source means
cleaner and safer air for everyone. Engineering controls are preferable to administrative
controls and personal protective equipment for controlling exposure to workers on the job
because they are designed to eliminate the hazard at its source, before it comes into contact
with workers. Well-designed engineering controls can be very effective in protecting workers.
The cost of engineering controls may be higher than the cost of administrative controls or even
personal protective equipment. But over a long period of time, the operational costs will be
lower, and in some cases in other areas, can provide cost savings.
4. Administrative Control:
Sometimes it may not be possible to reduce further risk in replacing equipment or appliances.
However Companies can reduce risks through improvements in work patterns and monitoring.
Work systems with safe work permits can be used as a requirement for high-risk activities.
Training and induction can be conducted to increase employee awareness. Routine and
scheduled activities can be used to maintain safety. Such as inspection, testing, good layout and
cleaning.
5. PPE (Personal Protective Equipment):
This is the last resort and the least effective. It is lower in the hierarchy but not unimportant. If
there is a risk, PPE will be the right choice to protect the individual. It will provide protection if
it is properly selected for the hazard, used and maintained properly. PPE programs may be
relatively cheap to set up, but in the long run can be expensive. This way of protecting workers
has also proven to be less effective than other measures that require significant effort from the
affected workers. Companies cannot just choose one type of risk control. For complete
protection, reducing risk to a safe level requires multiple levels of control.
For example, in terms of paint spraying activities, companies can replace oil-based paint with
water-based paint (substitution). Employees can choose to work in closed rooms with fixed
ventilation (control techniques). Implement work patterns and reduce exposure time of
hazardous substances and cleaning schedules (administrative control). Provide employees with
gloves and goggles to prevent skin and eye contact (PPE).
Students also viewed