IMPLEMENTATION OF RISK MANAGEMENT IN BANKING
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 3
8.1
Introduction:
This decade the Indonesian banking industry is faced with increasingly complex risks
due to the diverse business activities of banks experiencing rapid development, requiring banks
to increase the need for the implementation of risk management to minimize the risks
associated with banking business activities. The implementation of risk management in banks
in Indonesia is directed in line with the new global standards issued by the Bank for
International Settlement (BIS) with a new capital concept where the capital calculation
framework is more risk sensitive and provides incentives for (improvement of Basel I), as
adopted by Bank Indonesia through regulation No. 5/8/PBI/2003 concerning the
Implementation of Risk Management for Commercial Banks so that Indonesian banks can
operate more prudently and its application is adjusted to the objectives, business policies, size
and complexity of the business and the ability of banks in terms of finance, supporting
infrastructure and human resources. With this provision, banks are expected to be able to carry
out all their activities in an integrated manner in an accurate and comprehensive risk
management system.
8.2
Banking Risk Management:
Risk management in banks can be done with several risk management processes,
namely the process of identification, monitoring, risk control and risk management information
systems. Risk identification includes understanding the types of risks throughout the bank's
activities carried out to analyze the sources and causes of risk and its impact (Goyal, 2010)
where the type of risk is divided into two groups of risks, namely financial risks and non-
financial risks. As shown in Figure 1 that financial risks include market risk and credit risk
which are the two pillars in Basel II while Non Financial Risk which is a risk that refers to risks
that may affect the bank's business growth, sales of products and services, failure of possible
strategies aimed at business growth and other risks may arise due to management failure,
competition, non-availability of products/services, external factors and others. Operational Risk
is part of non-financial risk which is defined as the risk of loss due to inadequacy or failure of
internal processes and systems or due to external events, in the implementation of Basel II is
pillar two.
Furthermore, banks need to measure risk in accordance with the characteristics and
complexity of business activities. Credit risk is measured through borrower risk, industry risk
and portfolio risk. Market risk is measured by the risk of changes in interest rates, liquidity
risk, foreign currency risk and hedging risk. While operational risk includes measurement of
strategic risk, capital risk, political risk and legal risk from each banking business activity. In
addition, the effectiveness of risk management implementation needs to be supported by risk
control by considering the results of risk measurement and monitoring (Bank Indonesia, 2011).
In the context of finance and economics, risk can be defined as the volatility or standard
deviation of the net cash flow of a company/business unit (Heffernan, 1995). Some economists
categorize risk according to the activities undertaken by banks, namely market risk, risk of
changes in economic conditions (Flannery and Gutentag, 1979; Guttentag and Herring, 1988),
operational risk, and management risk (Mullin, 1977; Graham and Horner, 1988). In addition,
there are other risks that can cause bank losses but are difficult to detect at an early stage, such
as interest rate risk and sovereign risk (Stanton, 1994).
Based on Basel II from the Bank for International Settlement (BIS), there are 8 types of
risks inherent in the banking industry, namely credit risk, market risk, liquidity risk, operational
risk, legal risk, strategic risk, reputation risk, and compliance risk. However, experience shows
that there are major risks that often arise and cause a bank to face various complicated
problems
Bank Indonesia classifies the 8 (eight) types of risk generally divided into 2 (two) risk
categories, namely those that can be measured (quantitative) and risks that are difficult to
measure (qualitative) as follows:
1. Risks that can be measured (quantitative) include:
a.
Credit Risk
b.
Market Risk
c.
Liquidity Risk
d.
Operational Risk
2. Risks that are difficult to measure, namely
a.
Legal Risk
b.
Reputation Risk
c.
Strategy Risk
d.
Compliance Risk
To meet the future needs of bank supervision, the current system of bank supervision
which is based on Compliance audit, which is inadequate and needs to be expanded with risk
management based supervison (Bank Indonesia, 2001). Risk based supervison is a supervisory
system based on the management of risks that may arise and will be faced by banks in the
future (forward looking).
8.4
Implementation of Risk Management:
Based on the Financial Services Authority Regulation Number 18/POJK.03/2016 dated
March 16, 2016 concerning the Implementation of Risk Management for Commercial Banks
and Circular Letter of the Financial Services Authority Number 34/SEOJK.03/2016 dated
September 1, 2016 concerning the Implementation of Risk Management for Commercial
Banks, the Bank has a risk management policy established by the Decree of the Board of
Directors of the Bank Number 056/182/DIR/ MJR/KEP dated September 7, 2017 concerning
Guidelines for Implementation of Risk Management Policy. The implementation of risk
management in the Bank includes 4 (four) pillars in accordance with the aforementioned laws
and regulations, namely:
1. Active supervision of the Board of Directors and Board of Commissioners
2. Efforts Risk management policies and procedures and the establishment of risk limits
3. Adequacy of risk identification, measurement, monitoring and control processes and risk
management information systems.
4. Comprehensive internal control system
Based on the Circular Letter of the Financial Services Authority Number
14/SEOJK.03/2017 dated March 17, 2017 regarding the Assessment of the Health Level of
Commercial Banks, the composite factor of the Bank Health Level assessment consists of 4
(four) components, namely: Risk Profile; Governance; Earnings; and Capital.
8.5
Risk Management Organization:
The organization of risk management in the Bank is led by a Director who is
responsible for risk management, namely the Director of Compliance and Risk Management.
To assist the Compliance and Risk Management Director, the Bank has established a Risk
Management Work Unit (SKMR), namely the Corporate Risk Management Division which is
responsible to the Board of Directors, to perform the evaluation function of risk management
independently. risk management independently.
8.6
Risk Evaluation Process:
The Company's Risk Management Division prepares Risk Evaluation Reports
periodically, namely quarterly, and submits these reports to various levels of management
including the Board of Commissioners, as well as to relevant external parties such as the
Financial Services Authority. In addition, the Company's Risk Management Division has
coordinated with the Internal Audit Division to discuss audit findings as material for risk
evaluation and risk minimization. The findings are submitted to the Corporate Risk
Management Division for mitigation in accordance with the 8 (eight) risks and solutions to the
findings are provided. One example of the findings of a Risk Management Audit of
Commercial Bank A with the following conditions:
The risks inherent in Bank A's business in accordance with the provisions of the
Financial Services Authority are 8 (eight) risks. An explanation of each of these risks is as
follows:
1.
Credit Risk:
Based on the Financial Services Authority Regulation Number 18/POJK.03/2016, credit
risk is defined as the risk arising from the failure of other parties to fulfill their obligations,
including credit risk due to debtor failure, credit concentration risk, counterparty credit risk,
and settlement risk.
Credit risk management at Bank A until December 2019 has been optimally pursued as
reflected in the credit risk profile assessment rating in December 2019 which is moderate. As
for the quality of credit risk management implementation related to the active supervision of
the Board of Commissioners and the Board of Directors, it has been running in accordance
with its function so that the general assessment of the quality of credit risk management
implementation is fair, so that the composite rating for credit risk is rating 3.
In terms of policy, Bank A always reviews and updates the determination of the limit of
provision of funds following business and organizational developments. In the process of
limiting the provision of funds following business and organizational developments. The
Corporate Risk Management Division provides a review and determination of risk levels in
determining transaction facilities (Counterparty Limit), as well as monitoring of Risk Appetite
and Credit Risk Limits on a regular basis. In terms of strengthening Credit Risk Management,
the Bank also established a Credit Risk Unit/Division that specifically concentrates on lending.
a.
Potential Losses
Potential losses on the Bank's lending activities can arise due to inadequate human resources in
the credit sector, poor internal credit processes, inaccurate and in-depth credit analysis, funding
in high-risk sectors, credit concentration, as well as placement activities or purchase of
securities in companies that are considered less bona fide, causing defaults and causing losses
to the Bank because it must form CKPN, reduction in profit due to loan write-offs, costs
incurred due to the loan settlement process (collection costs, legal proceedings, auction
process), as well as resources that must be allocated in order to collect and restructure loans,
can also result from failure in the settlement process.
b.
Mitigation
Mitigation efforts that can be made against potential losses on credit risk are: improving the
knowledge of credit analysts in the field of credit to be more professional and master their field
of work well, improving systems and procedures in the field of credit, coaching and monitoring
of loans that have been realized, more intensive collection efforts against customers who are
Under Special Attention (DPK) so as not to deteriorate their collectibility, improving credit
supervision functions, applying Prudential Banking principles, supervising systems and
procedures that have been owned, and also analyzing Counterparty carefully and well.
2.
Market Risk:
Market risk management aims to minimize the possibility of negative impacts due to
changes in market conditions on the Bank's capital assets. In accordance with the Financial
Services Authority Regulation, Bank A's market risk management as reflected in the market
risk profile assessment rating in December 2019 is rated Low to Moderate for inherent risk and
fair for the quality of risk management implementation, resulting in a composite rating of 2.
Potential Losses Potential losses arising from market risk can occur on the following matters,
among others, changes in Bank interest rates that have an impact on the Bank's portfolio (the
difference between the Rate Sensitive Asset/RSA & Rate Sensitive Liability/RSL portfolios),
changes in foreign exchange rates where the Bank experiences losses on exchange rate
differences, changes in the price of the Bank's portfolio, changes in the rating or financial
performance of obligors, namely a decrease in the value of a Bank portfolio (on securities or
bonds), inefficient market conditions that affect the accuracy of valuation in transactions so
that it can cause losses at that time (both in the money market and the stock market), as well as
other losses incurred by the deteriorating political situation.
a.
Mitigation
The mitigation efforts that can be made against potential losses on market risk are:
Implementation of floating interest rates, monitoring Net Open Position in accordance with
regulatory requirements, analyzing Counterparties properly and accurately, consideration of
Counterparty ratings, setting and monitoring Dealer Limits, Stop Loss & Cut Loss, Monitoring
off market transactions, good provision of historical data and market potential, application of technical
& fundamental analysis on transactions exposed to market risk, as well as implementation of IRRBB
limits on assets and liabilities that are sensitive to interest rate changes (RSA & RSL).
3.
Liquidity Risk
Liquidity Risk is the risk due to the Bank's inability to meet its maturing obligations
from cash flow funding sources and/or from high quality liquid assets that can be
collateralized, without disrupting the Bank's activities and financial condition. Bank A's
liquidity risk management as reflected in the liquidity risk profile assessment in December
2019 is rated low to moderate for inherent risk and fair for the quality of risk management
implementation, resulting in a composite rating of 2 for liquidity risk.
a.
Potential Losses
Potential losses arising from liquidity risk may occur on the following matters: large-scale
withdrawals outside the company's behavior, rushes, funding activities, non-current or bad
loans, liquidity and maturity profile gaps, limited or reduced potential for credit expansion, or
other broader impacts of the Bank's losses arising from reputational risk.
b.
Mitigation
The mitigation efforts that can be done against potential losses on liquidity risk are as follows
The Bank's objectives are to anticipate and monitor the withdrawal of funds made by customers
in the form of withdrawals through clearing and cash withdrawals of all incoming funds either
through incoming transfers or customer cash deposits (customer behavior), to analyze the
sensitivity of the Bank's liquidity to the largest withdrawal scenario that has occurred, to
increase access to funding sources, to increase and maintain the stability of Third Party Funds.
In addition to maintaining primary reserves, Bank A also maintains secondary reserves and
makes detailed cash flow projections in rupiah against interest rate volatility.
4.
Operational Risk:
Operational risk is defined as the risk of loss arising from inadequate and/or
malfunctioning internal processes, human error, system failure, and/or external events that
affect the Bank's operations. In measuring operational risk, Bank A calculates the capital
requirement for operational risk using the basic indicator approach in accordance with the
Circular Letter of the Financial Services Authority No. 24/SEOJK.03/2016 dated July 14, 2016
regarding the calculation of Risk Weighted Assets (ATMR) for operational risk using the basic
indicator approach.
The approach used in managing operational risk is through determining the most
appropriate mitigation strategy to obtain an optimal balance between operational risk exposure,
the effectiveness of control mechanisms and the level of risk accepted by the Bank.
As of December 2019, Bank A's operational risk management as reflected in the
operational risk profile assessment was rated moderate for inherent risk and fair for the quality
of risk management implementation, resulting in a composite rating of "3" for operational risk.
a.
Potential Losses
With operational risk exposure, it can increase other risk exposures including credit risk,
market risk, liquidity risk, legal risk, liquidity risk, strategic risk and reputation risk, this can
result in potential financial and non-financial losses, another impact of the Bank's operational
risk is a decrease in the Bank's health level so that the Bank cannot carry out business activities
and open office networks and the Bank is in an incentive supervision status from the regulator.
b.
Mitigation
In order to mitigate operational risk, the Bank has a Loss Event Database (LED) application
that is connected to all work units so that work units can input risk events that occur online
through web media (web based). The data collected will be analyzed and mitigated against the
risk event. The Bank also has procedures for the implementation of Operational Risk
Management, Business Continuity Management (BCM) and conducts a Risk Assessment (RA)
process, to measure the potential for disruption/disaster threaten the continuity of the Bank thus
minimizing the potential loss of the Bank.
5.
Legal Risks:
The Bank conducts legal risk identification based on risk factors that include lawsuits
and weaknesses in juridical aspects arising from contracts and agreements made whatever
related to products and services. As of December 2019, Bank A's legal risk management as
reflected in the legal risk profile assessment is rated low to moderate for inherent risk and fair
for the quality of risk management implementation, resulting in a composite rating of "2" for
legal risk.
a.
Potential Losses
The potential loss from legal risk is the existence of lawsuits as a result of weaknesses in legal
or juridical aspects, or the absence of supporting legislation, resulting in financial and non-
financial losses.
b.
Mitigation
By reviewing juridical studies of all possible legal problems that will arise (between the
guarantor, guaranteed, guaranteed) so as to minimize claims, among others, against:
1)
Completeness of document fulfillment & Bank Guarantee requirements
2)
Bank Guarantee realization procedure
3)
Related to the contract/agreement contained in the Bank Guarantee File
6.
Strategic Risk:
Strategic Risk is the risk due to inaccuracy in taking and/or implementing a strategic
decision and failure to anticipate changes in the environment. Environment business
environment. The identification of strategic risk is carried out based on strategic risk factors in
certain functional activities, such as lending, treasury and investment as well as operational and
service activities through a business plan prepared by the Strategic Planning & Performance
Management Division as an elaboration of the General Policy of the Board of Directors.
Strategic risk measurement and its measurement parameters are based on the Bank's
performance, namely by comparing expected results with actual results, evaluating the
performance of work units and checking the progress that has been achieved with the targets
that have been set.
Strategic risk monitoring is carried out by conducting reviews held quarterly for each
Division and quarterly for the review of each branch office. As of December 2019, Bank A's
strategic risk management as reflected in the strategic risk profile assessment is rated low to
moderate for inherent risk and fair for the quality of risk management implementation,
resulting in a composite rating of "2" for strategic risk.
a.
Potential Losses
1)
There are errors in decision-making/business strategy, resulting in non-optimal revenue earned
against costs issued
2)
The launch of new products without a Feasibility Study analyzes the plan for implementing
new products so that the product sales target cannot be optimized.
3)
The launch of a new product must have a principle permit, if not implemented the product will
not be able to run so that it will lose the opportunity to collect third party funds (DPK).
b.
Mitigation:
1)
New products or programs have been included in the Bank's Business plan.
2)
Obtain in-principle license for the Product to be issued.
3)
Conduct based on the applicable SLA and provide explanations regarding the costs and risks
that will occur to Debtors or Customers if they will carry out credit realization or launch new
products and monitor the achievement of total credit from the target that has been set.
7.
Compliance Risk
Compliance risk measurement is conducted to measure potential losses caused by the
Bank's non-compliance and inability to comply with applicable regulations. The amount of
compliance risk is estimated based on the Bank's ability to fulfill all past and future regulations.
These activities include reviewing internal and external audit findings that have not yet
been finalized resolved as well as measuring the frequency and nominal amount of
fines/penalties. The Compliance & Risk Management Director, assisted by the Compliance &
Governance Division, regularly reviews the compliance aspects of the Bank, and in particular
suspicious or unusual transactions.
Until December 2019, Bank A's compliance risk management as reflected in the
compliance risk profile assessment was rated low to moderate for inherent risk and fair for the
quality of risk management implementation, resulting in a composite rating of "2" for
compliance risk.
a.
Potential Losses
The Bank's non-compliance with regulatory regulations and other internal regulations of the
Bank may be subject to administrative sanctions in the form of: written warnings, sanctions to
pay fines, downgrading of the bank's soundness rating, prohibition of opening office networks,
suspension of certain businesses, inclusion of management members, Bank employees, and/or
shareholders in the list of parties who have not passed the fit and proper assessment, and
dismissal of Bank management.
b.
Mitigation
To minimize compliance risk, the Bank also analyzes the events that cause compliance risk by:
1)
Provide risk assessment of new products and new internal regulations before they are
authorized by the Board of Directors.
2)
Perform compliance checklist on certain operational activities.
3)
Conduct a review of internal regulations.
4)
Conduct socialization regulations to divisions and branch offices.
8.
Reputational Risk
Reputation risk is the risk caused by a decrease in the level of stakeholder trust
stemming from various activities including events that are detrimental to the Bank's reputation,
such as negative media coverage, violations of business ethics and customer complaints as well
as other things that can cause reputation risk such as weaknesses in corporate governance,
corporate culture and business practices of the Bank.
Reputation risk measurement based on the Financial Services Authority Regulation
Financial Services Authority Regulation Number 18/POJK.03/2016 in December 2019 has a
rating of Low to Moderate for inherent risk. While the efforts to implement reputation risk
management itself have a fair rating by making efforts to improve the Bank's reputation so that
a composite rating of 2 is obtained.
Reputation risk control efforts carried out by Bank A, through the Corporate Secretary,
are responsible for implementing policies related to handling and resolving negative news or
avoiding counter-productive information and carrying out public service functions in order to
carry out corporate social responsibility, and focusing on 4 (four) aspects including aspects of
banking education and education, culture, health and social aspects including the repair of
inadequate houses (RTLH). As well as improving the Bank's internal policies related to
customer complaints and customer service to minimize the potential for a decline in the Bank's
reputation.
a.
Potential Losses
Reputational Risk can be seen from several indicators including:
1)
Business ethics violations, the quality of a bank's reporting and customer complaints.
2)
Unqualified human resources have the potential for reputational risk losses to customers,
especially for customer service that must be in accordance with applicable service standards.
3)
The existence of negative news in the mass media that is already known by customers and
complaints from customers who experience problems at Bank A that cannot be handled
properly.
b.
Mitigation
Always maintain the Bank's credibility in front of shareholders and stakeholders, respond to all
complaints and negative news about the Bank, and always maintain customer satisfaction by
conducting regular assessments of service levels carried out by frontliners in each branch
office.
8.7
Efforts to Manage Risk:
Risk management as an integral ingredient in business growth and daily business
activities of the Bank is implemented in various efforts, among others:
a.
Presenting opinion from a risk perspective on each of the Bank's new activities and products
including the addition of the Bank's service network.
b.
Continuously improving operational policies and procedures, adjusting risk tolerance limits to
ensure an optimal balance between asset quality and business profitability.
c.
Maintain risk management implementation in line with macroeconomic changes and Bank A's
business development.
In accordance with the Financial Services Authority Regulation No. 18/POJK.03/2016
concerning the Implementation of Risk Management for Commercial Banks, article 23
regulates the Bank's obligation to submit a Bank Risk Profile Report to the Financial Services
Authority on a quarterly basis.
Based on the Circular Letter of the Financial Services Authority Number
34/SEOJK.03/2016 dated September 1, 2016 regarding the Implementation of Risk
Management for Commercial Banks, the risk rating of Conventional Commercial Banks is
categorized into 5 (five) ratings namely 1 (low), 2 (low to moderate), 3 (moderate), 4
(moderate to high) and 5 (high) for inherent risk levels, while for the quality rating of risk
management implementation is categorized into five ratings namely 1 (strong), 2 (satisfactory),
3 (fair), 4 (marginal) and 5 (unsatisfactory).
IMPLEMENTATION OF RISK MANAGEMENT IN COMPANIES
9.1
Introduction:
Recently, there have been many defaults from insurance companies that have harmed
their customers. According to Hastuti (2020) insurance companies that have defaulted are as
follows:
1. PT Asuransi Jiwa Kresna (Kresna Life)
Kresna Life has defaulted on two of its insurance products. The two products are Kresna Link
Investa (K-LITA) and Protecto Investa Kresna (PIK). Referring to the OJK inspection for the
2019 period conducted in February 2020, OJK found a number of violations committed by
Kresna Life, especially in the K-LITA product. Where the K-Lita Kresna product, the
investment benefits offered since June 10, 2019 are quite high, above the average bank deposits
and some even have investment benefits per year reaching 9.75% fixed rate. In February 2020,
to prevent the risk of difficulty paying claims on larger maturing policies and protect the
interests of policyholders, OJK ordered Kresna Life to stop the K- LITA product.
2. PT Asuransi Jiwasraya (Persero)
The Jiwasraya scandal has been widely reported in the mass media. Jiwasraya first announced
defaulted in October 2018. In the announcement, Jiwasraya was unable to pay off customer
policy claims amounting to Rp 802 billion. The Supreme Audit Agency (BPK) also released
the calculation of state losses (PKN) due to the Jiwasraya mega scandal case. As a result, the
amount of PKN calculated by BPK reached Rp 16.81 trillion. The amount consists of stock
investments of Rp 4.65 trillion and state losses due to mutual fund investments of Rp 12.16
trillion. The amount is slightly different from the initial projection of the Attorney General's
Office (AGO) of Rp 17 trillion.
3. PT Asuransi Jiwa Bakrie Life
The default case of the insurance company owned by the Bakrie Group occurred in the
Diamond Investa product which is a type of unit link (insurance and investment). The product
defaulted in 2008 because the company invested too aggressively in the stock market, during
which time stocks collapsed due to the global crisis triggered by the subprime mortgage case in
the United States (US). The Capital Market and Financial Institutions Supervisory Agency
(Bapepam-LK), which has now changed its name to OJK, stated that Diamond Investa's default
reached Rp 500 billion. To resolve this problem, an agreement was reached that Bakrie Life
would pay in installments.
4. PT Asuransi Bumi Asih Jaya
OJK revoked the business license in the Insurance Sector of PT Asuransi Jiwa Bumi Asih Jaya
(BAJ) on October 18, 2013 because it was no longer able to meet the provisions related to
financial health (Risk Based Capital) and the ratio of investment balance to technical reserves
and claims payable. In its journey after being revoked, Bumi Asih Jaya has not been able to
carry out its obligations to so that OJK filed a bankruptcy lawsuit with the Central Jakarta
Commercial Court.
5. Bumiputera Life Insurance 1912
The problems in Bumiputera are more focused on miss management or mismanagement of the
company. In January 2018 the company admitted to experiencing delays in claim payments
within 1 - 2 months due to the lack of premiums generated by the company. At the end of 2018,
the company experienced solvency problems of Rp20.72 trillion, where the recorded assets
amounted to only Rp10.279 trillion but the company's liabilities reached Rp31.008 trillion.
The phenomenon of defaults from insurance companies indicates inadequate
governance and also the application of risk management that is not optimal in preventing
defaults by these insurance companies. The implementation of risk management has a vital role
in preventing the bankruptcy of a company. Therefore, in this section of the book, the problem
formulations include: How is the implementation of risk management in companies and what
risks are found in insurance companies.
The objectives of this book chapter therefore include the following:
1. Knowing the implementation of risk management in the company;
2. Know the types of risks in insurance companies
Based on the formulation of the problem and the objectives of this part of the book, the
implication of this book is to provide new scientific treasures related to the implementation of
corporate risk management and risks contained in insurance companies so that it can be a
reference for readers and further researchers.
9.2
Implementation of Risk Management:
Risk management is the process of identifying, assessing, and controlling risks
associated with the operational activities of an organization or company (Fraser & Henry,
2005; Nugroho, Nugraha, et al., 2021). The aim is to reduce risks and minimize the negative
impact of unavoidable risks (Afoukane et al., 2021; Hoffmann et al., 2013; Nugroho, Badawi,
et al., 2021). Risk management involves the process of risk identification, risk evaluation, risk
management strategy development, risk management strategy implementation, and regular risk
monitoring and review. Risk management is applied in various aspects of business, including
financial, operational, project, environmental, and reputation. The main objectives of risk
management are to maintain business safety and sustainability, improve operational efficiency,
comply with applicable regulations and standards, improve reputation, improve decision
making, and increase shareholder value (Quon et al., 2012; Utami et al., 2021).
Risk management is the activity of identifying, assessing, and controlling risks that may
arise in an organization. The following is according to Muniarty et al. (2020), Nugroho et al.
(2018), Power (2004), and Settembre-Blundo et al. (2021) are several types of risk
management that are generally found in companies that include:
1. Financial Risk Management: Financial risk management involves identifying, assessing, and
controlling financial risks that may affect the financial health of the company. Financial risks
may include market risk, credit risk, liquidity risk, and operational risk.
2. Operational Risk Management: Operational risk management involves the identification,
assessment, and control the risks associated with the day-to-day operations of the organization.
Operational risks may include system failure risks, human error risks, information security risks, legal
risks, and environmental risks.
3. Project Risk Management: Project risk management involves the identification, assessment,
and control of risks associated with a specific ongoing project. Project risks may include cost
risks, schedule risks, technical risks, and human risks.
4. Environmental Risk Management: Environmental risk management involves identifying,
assessing, and controlling risks associated with the environmental impacts of an organization's
activities. Environmental risks may include risks to human health, damage to natural habitats,
and risks to protected species.
5. Reputation Risk Management: Reputation risk management involves identifying, assessing,
and controlling risks related to an organization's reputation. Reputational risks can arise from
the actions of the organization or from the external environment, and can affect the public
perception of the organization.
6. Strategic Risk Management: Strategic risk management involves identifying, assessing, and
controlling risks associated with the long-term goals of the organization. Strategic risks may
include risks to growth, market risks, innovation risks, and financial risks.
The steps to implement risk management mentioned above according to Alhawari et al.
(2012), Barafort et al. (2017), and Nugroho & Malik (2020) in the company are as follows:
1. Risk identification: The first step in implementing risk management is to identify the risks that
the company may face. Risks can come from various factors, such as operational, financial,
legal, environmental and reputational. Risk identification should be done comprehensively and
continuously.
2. Risk evaluation: Once the risks have been identified, the next step is to evaluate the risks to
determine the level of risk and its impact on the company. Risk evaluation involves assessing
the likelihood of the risk occurring and its impact if it does.
3. Develop a risk management strategy: Once the risks have been evaluated, the company should
develop a strategy to manage those risks. Risk management strategies may include risk
reduction, risk transfer, risk acceptance, or risk avoidance.
4. Implementation of the risk management strategy: Once a risk management strategy has been
developed, the company must implement the strategy by taking appropriate actions. This may
involve the development of operational procedures, changes in policies or practices, the use of
new tools and technologies, or changes in organizational structure.
5. Monitoring and reviewing risks: The final step in implementing risk management is to monitor
and review risks on a regular basis. The company must ensure that the risk management
strategies implemented are effective and can handle emerging risks in a timely manner.
9.3
Risks in Insurance Companies:
Like other companies, insurance companies also face risks that may affect their
financial performance and safety (Barafort et al., 2017; Jannah & Nugroho, 2019; Srivastava,
2022). Here are some of the risks that insurance companies often face:
1. Underwriting Risk: Underwriting risk relates to the risk that insurance companies may not be
able to accurately assess risks when setting prices and managing risks. If underwriting risk is
not managed properly, it can lead to financial losses for the company.
2. Investment Risk: Insurance companies have significant investments in investment portfolios.
Investment risk is related to market volatility, interest rate fluctuations, and credit risk. If
investments are not managed properly, this can result in losses to the investment portfolio.
3. Compliance Risk: Insurance companies must comply with regulations and standards set by
regulators and regulatory bodies. Failure risk is associated with failure to comply with
applicable regulatory and statutory requirements, and may result in sanctions and penalties
from regulatory bodies.
4. Operational Risk: Operational risk relates to disruptions in an insurance company's operations,
including system risk, reputational risk, and human error risk. Operational risk can affect the
financial performance and reputation of the company.
5. Leadership Risk: Leadership risk is related to failure to make the right decisions, poor policies,
or improper risk management by company management. Leadership risk can cause financial
losses and damage the company's reputation.
6. Natural Disaster Risk: Insurance companies also face the risk of natural disasters, such as
earthquakes, storms, and floods. The risk of natural disasters can cause huge losses and affect
the finances of insurance companies.
9.4
Cover
Risk management should be part of the corporate culture and should involve all
employees. All members of the organization should be aware of the importance of risk
management and should adhere to the procedures and practices implemented. In this regard,
proper training and communication can help drive risk management awareness and
compliance. Overall, therefore, risk management provides many benefits to the company. With
effective risk management, companies can reduce risks, improve operational efficiency,
comply with regulations, improve reputation, enhance decision-making, and increase their
competitiveness in the market.
RISK MANAGEMENT IN TECHNOLOGY
10.1
Introduction:
Information technology is something that is currently needed by various parties, both in
the government sector, the education sector through schools, community services, private
companies, even small and medium enterprises, many parties need information technology.
Because various parties need information technology, there is management of information
technology management in IT-based companies. However, there are also risks to the use of
information technology, which need to be managed.
Risk is the possibility of occurrence or due to events, and their impact. According to
Maria (2021), in information technology, risk is the vulnerability of the system to events or
events, as well as the risk of various threats. Risks can be in the form of missed systems or
system failures because they cannot detect input errors due to human error, computer viruses,
data theft by hacking, or skimming. Often, the data taken is not financial data, but personal
identity, which results in NIK and names being misused.
In addition, risks are also due to device malfunctions or disasters. Therefore, there are
also unforeseen risks. But generally, most risks are detectable. Hence, risk management is
required.
Risk management is the process of identifying potential risks, analyzing, and
evaluating, with the aim of controlling, minimizing, or eliminating risks. In the Regulation of
the Financial Services Authority of the Republic of Indonesia Number 11 /POJK.03/2022
concerning the Implementation of Information Technology by Commercial Banks, before risk
management is carried out, entities must first make an Information Technology Strategic Plan.
This plan contains the vision and mission that the entity wants to achieve, related to the
information technology used, or will be used. For example, in banks, there are regulations
regarding information technology risk management in the Regulation of the Financial Services
Authority of the Republic of Indonesia Number 11
/POJK.03/2022 concerning the Implementation of Information Technology by Commercial
Banks. Meanwhile, for non-bank financial services institutions, it is regulated in the Regulation
of the Financial Services Authority of the Republic of Indonesia Number 4 /POJK.05/2021
concerning the Application of Risk Management in the Use of Information Technology by
Non-Bank Financial Services Institutions. In this regulation, the implementation of risk
management is carried out in an integrated manner, starting from planning, procurement,
development, operations, maintenance, evaluation, to the termination and elimination of
Information Technology resources.
Still according to Suyudi (March 17, 2021), policies and procedures for using
information technology include management, development and procurement of hardware and
software, operations, communication networks and network resources, information security,
use of information technology service providers, and electronic financial service providers
used, which are integrated with the system. Ultimately, the human resources who operate the
system and become system administrators and technicians must also be prepared.
Furthermore, companies are also required to have a system recovery plan, and test the
recovery plan. Tests are carried out on all core applications and infrastructure, not only
involving information technology user work units, but even involving ethical hackers.
Due to the various risks of information technology, it is necessary to control the risks
that are likely to occur. In information technology, the following are the stages of risk
management.
10.2
Risk Management Stage:
In the Internal Control System (ICC), the step after ensuring a secure control
environment with an adequate organizational structure, is to design, operate, and evaluate risk-
based information technology. But in risk management, entities must understand at which stage
the system is, related to the System Development Life Cycle (SDLC). According to Maria
(2021), the risk management stage itself includes:
10.2.1
Risk Assessment:
This is the initial stage of risk management, by determining the types of risks faced. As
explained earlier, various types of risks must be identified. According to Kadir (2014: 378), the
types of threats to information technology include:
After identifying the risk, the probability of occurrence is calculated. In this case, the
information system designer must first estimate the impact if this risk occurs, if the security can
be penetrated. However, if the risk is in the form of a disaster, the information system designer
must consider the storage location and how to secure the information technology hardware
used. While the level of impact if the risk occurs, consists of Very Crucial, Crucial, Medium,
Low, and Very Low impacts.
After identifying the probability scale, the system designer then identifies the
probability of occurrence scale. Probability consists of the scales Probable to Occur, Possible
to Occur, Moderately Likely to Occur, Less Likely to Occur, and Extremely Unlikely to Occur.
Based on the clause in ISO 31000, this scale is designed with the following measurements:
Based on this scale, system designers then create a questionnaire to map or assess the
level of risk. The questionnaire created for management and managers of the entity covers
information technology needs, types of risks, and the likelihood of risks arising. The
questionnaire is also intended for users and related parties/stakeholders, even in many entities,
user opinions can be included in the system used, when users log out of the system.
Regarding the assessment of the amount of risk, the experience of other similar entities
and industries is also a reference for the amount of risk value. However, sometimes the
determination of the probability of risk occurrence is subjective, because sometimes it is often
more based on logic and experience.
10.2.2
Risk Evaluation
This stage is related to risk mitigation. Evaluation is carried out to check whether the
risk mitigation that has been carried out can actually reduce the risk, according to the
calculations in the risk assessment. This stage also needs to consider the costs incurred to
secure information technology, with the benefits of risk reduction obtained from the security.
The high risk effect is not only catastrophic, but occurs because the server or database
system crashes/down (Periyadi, 2015). However, according to Maria (2021), security must also
pay attention to the comfort of system users. Now even the use of information technology is
maximized, as a substitute for services from the business employee concerned, because the use
of machines and technology guarantees more comfort and speed of transaction completion.
Thus, the evaluation of risk also has an effect on the organization's income.
In addition, according to Suprihadi (2021: 244), at the system evaluation stage,
It is important to be careful and meticulous, as major problems usually arise during
system implementation. Even though risk mitigation has been carried out, sometimes there are
things that can be penetrated, so that the systems and information technology used are
disrupted. Sometimes entities deliberately leave the old system in place, to avoid new problems
during system implementation. Therefore, the system evaluation stage is very important to
follow up back to the initial stage, by reassessing the risk and changing the way to control the
risk. At the evaluation stage, the database used must also be maintained, so that the original
data is not disturbed. If there are crucial or very crucial risks in the implementation stage, the
evaluation stage can sometimes continue to transition to the new system.
On the other hand, the system evaluation stage is also not only aimed at ensuring that
the system works properly, but also ensuring that the entity gets a return on the funds that have
been invested in the development of the technology.
10.3
Factors Affecting Risk Management in Technology:
According to Indri Pedia (2021) and Rachmina (2021), risk management also considers
human and cultural factors. Risk management is dynamic, iterative, and must respond
immediately to changes. Thus, the parties in the company related to risk management, both
directors, commissioners, managers, and information technology providers, must have an
integrated risk culture, to secure the information technology used. Not only to secure, but also
to develop the information technology used, according to the needs of the times.
According to the Indonesia Risk Management Professional Association (IRMPA), steps
to create a risk management culture include:
a.
leadership commitment to achieve an understanding of the entity's vision and mission with
management, implementers of activities entities, and related parties/stakeholders, and strive to
implement a risk management culture.
b.
education to related parties/organizational stakeholders about the importance of risk
management
c.
continuous and consistent communication of facts in the implementation of information
technology.
d.
documentation of risk management procedures, implementation, reporting, and evaluation
followed by socialization to relevant parties/stakeholders.
DECISION-MAKING TECHNIQUES IN RISK MANAGEMENT
11.1
Definition:
Humans will face various problems. In an economic perspective; in the creation of the
Goals, Vision, Mission of economic organizations, humans are always faced with problems
regarding "why, who, how, what, & when", as well as other stereotypical questions. The
questions that arise imply that various problems must be solved, if the decision maker wants to
realize the goals, both in the short and long term of the organization. In the problem-solving
procedure, both the individual and the company management will have several alternatives to
choose from. But keep in mind that each alternative will have its own impact. An individual is
also assumed that he will choose a decision in order to maximize satisfaction on the fulfillment
of desires in a rational manner. Rational beings are "forced" to make decisions that can
maximize results because they are driven by reasons regarding the availability of limited
resources.
The theory of scarcity (constraints/scarcity) will force individuals to balance the
perspective between the formulation of rational decisions vis-à-vis taking steps that will
provide benefits optimal. Based on the balance of perspectives, decision-making models and
theories were born. Decision making is a mechanism for assessing and selecting an option. The
determination of decision making is formulated after undergoing several processes of rational
calculation and review of alternatives. Before a conclusion is formulated and implemented,
there are several stages that the decision maker must go through. These stages may include
recognizing the basic problem, preparing alternative decisions that can be chosen, and then
reaching the phase of choosing the best decision.
Decision making is making an assessment and making a choice. However, if we try to
look at the opinions of experts, then we can find so many definitions or definitions of decision
making, including the definition or understanding put forward by G.R. Terry. According to
G.R. Terry, decision making is a selection based on certain criteria for two or more possible
alternatives. According to Claude S. George, JR, decision making is a process carried out by
most managers in the form of awareness, thinking activities, consideration, assessment and
selection among a number of alternatives.
Horold and Cyril O'Donnell argue that decision making is a choice between alternatives
regarding a way of acting, which is the essence of planning, a plan cannot be said without a
decision, a reliable source, instructions or reputation that has been made.
Meanwhile, P. Siagan believes that decision making is a systematic approach to a
problem, collection of facts and data, careful research on alternatives and actions. From several
definitions or notions of decision making that have been put forward, a brief description is
obtained that decision making is the process of choosing the best alternative from several
alternatives that are carried out systematically for problem solving.
A decision is a choice of a strategy of action. Decision making is a management activity
in the form of selecting an action from a set of previously formulated alternatives to solve a
problem or a conflict that occurs in management. However, the decision to be taken can still
contain risks because the results of the decision are not known with certainty. If in a state of
uncertainty, decision makers can know the value of the possibility (probability) of the uncertain
outcome or event, it is said that the decision is at risk. But the existence of this risk certainly
does not prevent decision makers from continuing to make decisions. What must be done is to
reduce the risk incurred in decision making by finding the probability of uncertain events. In
the production process in the manufacturing industry that has a made to stock type, the
production planner must be able to determine the most optimal amount of production. The
problem that occurs is when product demand is not the same for each period.
Decision-making is the process of making a choice from a range of alternatives choices
available. A person is sometimes faced with a situation where they have to make choices
(decisions) from various alternatives. This process is sometimes very difficult because it affects
him and his surroundings. A production leader decides to reduce production when economic
conditions are bad, a general decides to carry out a surprise attack because he knows that the
enemy is not ready and alert. There are many other examples related to decision-making in
everyday life.
In general, a decision is made in order to solve problems or problems (problem solving)
and every decision made must have a goal to be achieved. Almost every day, even every
moment there are always decisions made, for example in households, in offices or in
organizations (government departments and industries, companies, universities) or in society.
Decisions are made by individuals (individuals), organizations, groups of individuals, countries
with one or more goals to be achieved. In this modern world, life demands a lot of decisions to
be made that have both broad and narrow impacts. Regarding effectiveness in achieving the
desired goal.
One of the most important components of the decision process is the information
gathering activity from which an appreciation of the decision situation can be made. If
sufficient information can be gathered to obtain a complete specification of all alternatives and
their effectiveness in the current situation, then the decision is relatively easy. In practice,
however, it is highly unlikely that to collect complete information, given the limited funds,
time and energy.
decision making decision at An organization/company is very important. Generally, in
making a decision, company management considers the risk of each problem solution. In
choosing a solution, an organization/company usually only takes the results of meetings,
discussions and voting among fellow leaders of each division or department. The selection of
solutions in this way has disadvantages, one of which is time consuming if there are the same
problems that occur repeatedly and are less measurable, so that the problem cannot be
overcome properly. So a way is needed to deal with the problem.
11.2
Decision-making Objectives:
Every individual/organization that will make a decision always has a goal related to the
decision it makes. In general, the purpose and purpose of decision making is to solve problems.
The objectives of decision making can be divided into two, namely:
First, a single goal, namely a single retrieval goal occurs if what is produced concerns
only one problem, meaning that once decided, there will be no connection with other problems.
For example, the problem faced is only a problem concerning one aspect, namely financial
problems, then the decision taken only concerns the financial aspect, if the financial problem is
resolved it will not cause other consequences or side effects on other aspects.
Second, dual objectives, namely dual decision-making objectives occur when the
resulting decision involves more than one problem, meaning that one decision taken
simultaneously solves two or more problems that are contradictory or non-contradictory.
Contradictory problems, for example, the problem of meeting material needs for one operating
period. One alternative solution is that these needs are met at once in one purchase of materials.
If so, it will save message costs because it only makes a one-time purchase order, and there is a
possibility of getting a discount for buying in large quantities at once. But on the other hand,
this solution also results in high storage costs because buying in large quantities will cause a
large inventory as well. The material inventory requires storage and maintenance. Another
alternative is to place orders in small quantities, or in other words, the fulfillment of material
needs in one period is done by repeated orders. As a result, the cost of the message is expensive
because you have to make frequent purchase orders. In addition, there is a risk of running out
of materials so that the production process is disrupted because the order has not yet arrived
while the material inventory has run out. On the other hand, the cost of storing and maintaining
materials is relatively small because the amount of material stored is small. In such cases,
decision-making is required with multiple objectives.
11.3
Decision Making Process:
Decision making is made based on the process of analyzing, deciding, and simulating
through various calculations of possible alternative solutions. The decision-making stage has
several steps:
1. Understanding and stating the basis of the problem. Leaders are often faced with the fact that
problems that are difficult to solve or difficult to identify, are not the basis of a problem.
Leaders can understand the problem at hand in several phases. First, leaders systematically
examine cause-and-effect relationships. Second, leaders analyze changes or normal deviations
of an ongoing problem.
2. Search and process significant analytical data. Once the leader has found and stated the
problem, the leader must formulate a way forward. The first step is for the leader to determine
what data and information is needed to formulate an accurate decision. The second step is to
ensure that the information and data can be obtained in a timely and relevant manner.
3. Development of alternative solutions. The tendency to accept alternative solutions to feasible
decisions will be able to prevent the leader from failing to achieve and optimal solution. The
expansion of a number of alternative solutions makes the leader automatically prevent the
tendency to make hasty decisions, while directing a leader to formulate increasingly effective
decisions. Leaders must determine alternative solutions that are overall capable of solving the
problem, even if the choice is not ideal.
4. Evaluate alternative solutions. After the leader suggests a set of alternative solutions, the leader
must evaluate the set of alternatives. The purpose of the evaluation is to assess the
effectiveness of each alternative solution.
5. Selection of the best alternative solution. Decision making is the result of evaluating various
alternatives available. The selected alternative must be based on the leader's ability to deal with
the consequences that will occur after the implementation of the selected alternative.
6. Decision Implementation. Once the best solution has been selected, leaders must establish a
plan to deal with potential problems that may arise in implementing the decision. In line with
that, leaders need to take into account the various uncertainties and dangers as a consequence
of a decision. In this step, the leaders' decision should also require periodic progress reporting
procedures and develop preventive actions if deviations from the decision implementation
arise.
7. Evaluation of decision outcomes. The implementation of the decision evaluation must be
monitored periodically. The leader will assess whether the implementation has been done well
and the decision has produced the targeted results.
Activities making decision at principle includes at least four activities, namely:
1. The first activity is intelligence. Intelligence activities here are activities
observe the environment for decision-making purposes.
2. Design activities. The activity of finding developing and analyzing various possible courses of
action in order to make a decision.
3. Selection activities, which are activities to choose or determine certain actions from various
alternative actions that can be taken.
4. Review activities. The actions that have been selected are then implemented and evaluated.
When the decision-making process is analyzed, the analysis is actually not much different from
the analysis of the policy process. This is because the components of the policy process are also
components of the decision-making process which include:
(1)
policy problems, (2) policy alternatives, (3) policy actions, (4) policy outcomes, and (5)
policy implementation patterns. These components are sequentially interrelated and connected
by methods. For example, component (1) and component (2) are connected by the forecasting
method. This means that to solve component (1) a forecasting method is needed which
produces various policy alternatives. From component (2) to component (3) a recommendation
method is needed to choose one of the various policy alternatives. Furthermore, from
component (3) to component (4) a monitoring method is needed to monitor the results of the
selected policy. Finally, from component (4) to component (5) or back to component (2) an
evaluation method is needed. If the evaluation shows that the results of policy implementation
are good, then component (5) is a conclusion to be handled when experiencing similar
problems. (siagian, 1998)
11.4
Decision Making Technique:
Four Categories of Decision Making Techniques viz:
(a)
Decision in a state of certainty If all the information needed to make a decision is complete,
then the decision is said to be in a state of certainty (there is certainty). In other words, in a
state of certainty, we can predict the exact result of the action. For example, in a linear
programming problem, we can know how much maximum profit can be obtained after we
know the inventory of each type of material and input requirements for each type of product. In
everyday life, there are many decisions that we make in a state of certainty. We know with
certainty the direction to go to work, our favorite restaurant, or the best medicine. These things
are so routine that they don't require deep thinking. The problem is different when the
government has to regulate non-oil and gas exports from the agricultural sector so that the
amount of foreign exchange earnings from exports is maximized by taking into account
existing constraints. For example, the available land area, the number of farmers, the amount of
seeds and capital available, and the amount of demand. Various Operation Research (OR)
techniques that are classified as certain include linear programming (LP), transportation
problems, assignment problems, net working planning. Solutions regarding decision-making in
situations of certainty are deterministic.
(b)
Decision in a state of risk Risk occurs when the outcome of decision-making although cannot
be known with certainty, but can be known the value of the possibility (probability). For
example, you want to deciding to buy goods. Each item is so neatly wrapped that you can't tell
which items are in good condition and which are defective. Suppose the seller is honest and
you are told that there are 100 items and 99 are defective. Then you have to decide whether to
buy the item or not. If you are a normal person, you probably won't buy the item because the
risk is too great. The probability of getting damaged goods is 99%. But if on the contrary, the
number of damaged items is only 1 piece. Chances are you will buy the item, because the
probability of getting a damaged item is only 1%.
(c)
Decision in a state of uncertainty (uncertainty) Is a situation where we cannot determine a
decision because it has never happened before (first time). In this situation we need to collect
as much information as possible about a problem. With this information, several alternative
decisions can be made so that the probability value can be known. With the probability value
obtained either based on the information you obtained or based on your subjective opinion.
This problem is no longer in uncertainty, but in certainty because the risk that will be accepted
is known. Although the probability value you obtain is a rough estimate. Decision trees can be
used to solve problems under uncertainty.
(d)
Decisions in a state of conflict Sometimes decision-making doesn't always go smoothly. Many
issues that need to be considered in decision-making. Especially if the decision taken is in
conflict or can cause conflict. A conflict situation can occur when the interests of two or more
decision makers conflict with each other (there is a conflict) in a competitive situation.
Decision makers can also mean players in a game. For example, a decision maker (call A)
gains from a course of action. This is because another decision maker (call B) also takes a
certain action.
In decision analysis, the decision maker or player is not only interested in what the
individual does, but also what both (i.e. A and B) do. Therefore, the decisions and actions taken
by each will affect each other either positively (favorably) or negatively (adversely). In
practice, there are many such situations, such as companies involved in competitive market
strategies, new product development, and luring experienced executives. Although seemingly
simple, decisions in conflict situations are often very complex in practice. For example, we are
faced with uncertainty and the actions of the opposing party that could affect the outcome of
the decision. There are many more factors to consider. Decisions in conflict situations can be
solved using game theory.
Management and Decision Making The decisions we make concern various areas such
as, economic, social and cultural. The environment in which we live is very complex with
various components or factors to consider such as law, morality, economic realities, and so on.
So decision making is often not simple. While in reality, we make decisions every day, rarely
do we reflect for a moment on how we actually make decisions. No one is a perfect decision-
maker, but we want to be successful in at least the most important decisions. A career decision,
for example, will direct which path to take.
11.5
Benefits of Risk Management in decision making:
1)
The company has a strong measure as a foothold in making every decision, so that managers
become more prudent and always place measures in various decisions.
2)
Able to provide direction for a company in seeing the influences that may arise both in the
short and long term.
3)
Encourage managers in making decisions to always avoid risk and avoid the effect of losses,
especially financial losses.
4)
Allows the company to obtain a minimum risk of loss.
5)
With a risk management concept that is designed in detail, it means that
The company has established a sustainable direction and mechanism.
In addition, we can also get the benefits of how to make decisions, as follows;
1. Decision Making under Definite Conditions
You need to know that this condition must arise when the decision maker knows with certainty.
In a state of certainty, the information obtained must be accurate, measurable, and reliable. We
know the cause-and-effect relationship and can guess what could happen in the future.
Then, such conditions usually exist in the case of routine and repetitive decisions. The Linear
Programming tool is a good tool to use to generate optimal solutions to problems under certain
conditions.
2. Risk Based Decision Making:
When a manager does not have perfect information or has conflicting information, there is
potential for risk. In a risky situation, the decision maker has incomplete information about the
available alternatives but has a good idea of the probability of the outcome for each alternative.
In making risk-based decisions, managers must determine the probability of each alternative
based on available information or based on their experience. Popular approaches used in this
condition include: Expected Monetary Value (EMV) and Expected Opportunity Loss (EOL).
3. Decision Making under Uncertain Conditions
These decisions are most importantly made in complex environments under uncertain
circumstances. Uncertainty arises when we cannot predict the future and conditions are
volatile. The decision maker does not know all the alternatives available, the risks associated
with each, and the consequences of each alternative or its probability.
In this situation, a manager does not have complete information about the alternatives and any
information available, even if he has information, is not useful in dealing with the uncertainty.
So managers need to make certain assumptions about the situation to provide a reasonable
framework.
For example, a company that decides to expand its operations in a foreign country may
not know much about the country's culture, laws, economic and political environment. The
political situation may be so volatile that even experts cannot predict a possible change of
government. Popular approaches used in this situation include: Maximax, Maximin, Minimax,
Minimax Regret, Laplace, and Hurwick.
4. A Cutting-edge Approach to Decision Making under Uncertain Conditions
Nowadays, there are several modern techniques to improve the quality of decision-making
under uncertain conditions. The most popular include: risk analysis, decision trees, and
preference theory.
a. Risk Analysis:
Managers who follow this approach analyze the size and nature of the risks involved in
choosing a particular course of action. For example, when launching a product, a manager must
carefully analyze each of the following variables the cost of launching the product, the cost of
producing it, the capital investment required, the price, the size of the potential market and the
percentage of the market.
Risk analysis involves quantitative and qualitative risk assessment, risk management and risk
communication and provides managers with a better understanding of the risks and benefits
associated with proposed actions. The decision is a trade-off between the risks and benefits
associated with a particular action under conditions of uncertainty.
b. Decision Tree:
The decision tree technique is considered one of the best ways to analyze a decision. The
decision tree approach contains a graphic of alternative courses of action and the possible
outcomes and risks associated with each course of action. By using a "tree" diagram that
depicts the decision points, each event and the probability in action, this decision-making
technique allows the decision maker to trace the optimal path or course of action.
c. Preference or Utility Theory:
This is another approach to decision-making under conditions of uncertainty. This approach is
based on the assumption that individuals' attitudes towards risk vary. Some individuals are
willing to take only smaller risks, while others are willing to take bigger risks. Seeing the
explanation above, hopefully those of you who read can easily understand the benefits of risk
management and how to make decisions.
11.6
Simple Decision Making Technique:
1. Network Analysis
Network Analysis is one of the planning techniques used in the operational research approach.
This analysis technique helps us to make decisions on several options faced with a number of
different factors.
The steps in this decision-making technique are: 1) List all the options we have set, and all the
factors we consider important in the decision-making process.
2) Place both in a table, where the options are placed in rows and the factors in columns. 3)
Establish the relative importance of all factors. Show this in the form of a number. The number
is used to measure the level of preference with the importance of the factor. 4) Rate each
selected factor, from 0 (very bad) to 3 (very good). 5) Multiply each value we give with the
relative importance value we set. 6) The highest preferred value is the correct solution to the
problem. Example: A person wants to buy a car that can carry a lot of goods, but also has to be
able to be used to style the look of an elite and elegant businessman. The desired car must also
have the appearance of a sports car. What car should he choose to fulfill these criteria?
2. Plus Minus Implication Technique
PMI decision-making technique weighs the plus and minus implications of a choice. This
technique is used to see the pros and cons of the decision to be made. 1) The steps in the PMI
technique are described as follows: 2) Draw a table with headings for each column: plus,
minus, implication
3) In the plus column, write all the positive consequences of the choice 4) In the minus column,
write all the negative consequences of the choice. 5) In the implication column, write down all
the implications and possible outcomes of the choice, both positive and negative. 6) Assign a
value to each consequence assigned. In this case, the assessment is subjective. (Set the scale!)
7) Total up all the values. A positive result indicates that the option should be taken, a negative
value otherwise. Case example: A company decides to open a new branch office. The tentative
option is to locate the office in the city center. How does the company decide?
3. Field Strength Analysis
This technique is used to look at all the forces that support and hinder a decision. By analyzing
the power factors, we can strengthen the forces that support a decision, and reduce the
influence of the forces that hinder the formation of the best decision. The steps for the
technique are:
1)
List all the forces in favor in one column, and the forces against in the other column.
2)
Assign a score to each strength, from 1 (weak) to 5 (strong).
3)
Draw a diagram that shows all the forces, both supporting and hindering the decision and their
scores.
Example: A factory owner is deciding whether or not he will install new manufacturing
equipment from his factory. As a manager, You are asked to analyze the factors that led to the
best decision for the factory. The next step taken is to ask whether or not the established plan
will be carried forward. This technique will help us determine how to increase the chances of
the plan's success. For this purpose, we will be faced with two choices:
a.
Increase supporting forces so that goals can be achieved optimally
b.
Reduce the number of forces that stand in the way of the set goal. Generally, the solution to
produce a successful selection of the final decision is through step two/neutralizing the
downside.
In the case above, employees of a factory that will use new technology have resistance
to change. They also act uncooperatively if decision support powers are applied. Based on the
results of the analysis, you as a decision maker can make the following changes:
1. Conduct employee training. This will increase costs, but it will reduce labor overtime and
eliminate the fear of implementing new technology.
2. The application of technology will generate important new strengths to support business
growth.
3. New machines will generate a number of new types of jobs for employees.
4. The implementation of machines will increase wages even though it increases productivity. In
this case, costs will increase, but the risk of overtime work is reduced by as much as
.
The impact of new equipment on the environment can be reduced by implementing a
pollution control system. Cost and Benefit Analysis The cost and benefit analysis technique is a
technique used to decide on possible changes to the alternative options that have been
considered.
This technique is fairly easy to use as it simply calculates the estimated value of the
benefits of an action, and subtracts the costs that will arise. Cost-benefit analysis is generally
done by applying financial analysis techniques. All costs and benefits are thus converted into
money as the main denominator. The costs of an event are calculated in detail, and then the
costs are subtracted from the available benefits. Case example Your company is deciding to
implement a computer-based sales processing and relationship management system. The
problem is that the company has only a few computers, and the salespeople are clueless. The
benefits of implementing a computer-based system are that salespeople can contact more
customers, so they can provide higher-quality and more reliable services. Another benefit is
that employees can work more effectively and efficiently.