1 / 24100%
CRISIS MANAGEMENT
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 5
A.
Introduction:
An organizational crisis-an event perceived by managers and stakeholders as highly
salient, unexpected, and potentially disruptive-can threaten an organization's goals and have
profound implications for its relationship with stakeholders (Bundy, Pfrarrer, Short, &
Coombs, 2017). Crisis management has become a common charge for organizational
managers given the nature of today's business environment influenced by the effects of
globalization and high market dynamics. In this world, crises can be considered more or less
permanent. This fact requires control and prediction that will prevent the potential disruption
of organizational balance and stability. In general, crisis management can be understood as a
process that directs organizational activities to capture and evaluate warning signals of
potential crises (Mitroff and Pearson, 1993; Mitroff and Alpaslan, 2003; Paraskevas, 2006;
Sahin, Ulubeyli and Kazaza, 2015).
A crisis is a turning point in the life of a company (Coombs & Holladay, 2010). A
crisis is also an unregulated event that causes negative and extraordinary things. Crises are
significant uncertainties and threats that, if handled inappropriately, will impact a business,
sector or stakeholder.
In general, a crisis is a situation in which a situation or event has more negative
consequences for a business or organization than otherwise. An organization generally
cannot anticipate the occurrence of a crisis that could jeopardize its existence because a
crisis is by its very nature a circumstance that cannot be anticipated. A "crisis," as defined by
Devlin (2007), is a turbulent period for an organization with possible undesirable outcomes.
This suggests that an organization may experience undesirable outcomes during a crisis
because it is in an unstable state. Crises have several characteristics that can distinguish a
crisis from an issue. The following are some of the characteristics of a crisis:
1. Explicit events
2. Emergencies are surprising and can happen at any time.
3. Uncertainty in information is created by crisis.
4. Induce fear.
5. Affects business operations
6. Possible conflict.
B.
Causes of Crisis:
Factors that cause crises in various businesses. The after-effects of a corporate crisis
include the following:
1. Causes of crisis that do not cause problems The company experienced a crisis, but it is over
and there are no more problems.
2. Causes crisis events that generate additional problems These events result in additional
problems for the business.
3. Regulated crisis and its causes This event is caused by another party's regulation.
Internal or external businesses can also be the cause of a crisis. Crises that originate
from within the company are caused by mistakes made by the business itself and not the
internal business harming other parties. Meanwhile, crises are caused by external factors
such as disease outbreaks, financial difficulties, and natural disasters.
Meanwhile, according to (Mazur and White, 1998) the causes of emergencies include:
1. Technology crisis
In most cases, this crisis affects businesses that use technology or depend on
technology. Companies will face significant threats if the technology used is damaged.
2. Confrontation Crisis
This crisis was triggered by a movement of people who disagreed with the company's
decisions. Community groups held performances and other developments with the aim of
putting the organization into a state of emergency.
3. Criminal crisis
It happens because a number of individuals or a group of people have committed a
criminal offense that causes harm to the business world.
4. Crisis Management Failure
These crises are the result of groups with special powers abusing their power or
making poor decisions and strategies.
5. The new threat of crisis
This crisis does not have the same four causes as before. Companies face threats such
as annexation, mergers, and liquidation.
C.
Types of Crisis:
According to (Morissan, 2008), types of crisis can be divided into three categories:
1. Immediate crisis
Due to its sudden and unpredictable nature, this crisis is best avoided. To prepare prior
comprehensive plan for this crisis, top management must provide direction. Since lower
management will experience confusion, conflict, and delays in crisis resolution if central
management does not provide direction, top management is responsible for the management
of this crisis.
2. A new crisis breaks out
This kind of crisis can occur even if management has a plan to deal with it. This
indicates that top management does not need to issue special directives to resolve the
conflict, but it does not rule out the possibility that management will make strategic mistakes
that will cause crisis escalation and result in greater losses.
3. The continuing crisis
Despite the best efforts of central management or each division to address it, this type
of crisis can last for months or even years.
D.
Crisis Management:
Crisis management is an organizational exercise in managing emergencies that occur.
According to Yuliastina (2017), the nature and duration of the crisis will determine how the
company responds. If a company develops an efficient and well-executed strategy, the crisis
will not occur until the next stage, indicating that the strategy is successful.
Meanwhile, as stated by (Zeng et al., 2018), crisis management is a dynamic process
for making decisions during a crisis. To improve the situation and make it easier to achieve
the desired benefits, crisis management is needed.
According to Coombs & Holladay (2010), there are four proactive and selective steps
in crisis management:
1. Management places a strong emphasis on observing the surrounding environment and
identifying early warning signs of a crisis.
2. Management designs strategies to prevent crises.
3. Steps taken when an emergency occurs in the organization.
4. Keep in touch with stakeholders who have connections with the company so that
partnerships and cooperation can continue.
According to Gonzales-Herrero & Pratt's book (Nurdyansya, 2018), the four main
crisis events and strategies to overcome them are as follows:
1. Problem Management:
This phase, also known as the emphasis on environmental scanning, is when
businesses seek to identify the early warning signs of a crisis and begin planning a response.
When a company is at this stage, it develops a plan to implement prevention strategies first.
2. Planning:
Prevention Planning is the basis of this crisis management, and the company has
identified the cause of the crisis, which is close to and will result in losses, at this stage.
When the cause of the crisis is found and the company's profit potential decreases, the
business begins to develop a strategy on this basis.
Companies begin to take action during this phase, which is referred to as preventive
planning. The goal of this phase is to prevent a larger crisis from occurring. If the company
does not take action, it will monitor the problem, correlate the monitoring results with the
minor damage that has begun to occur, and begin to exercise control over the situation so
that the crisis does not get bigger (Coombs & Holladay, 2010).
3. Crisis:
Company when currently is experiencing crisis. The company is difficult to manage, but the
situation is dangerous and on the verge of collapse. However, the company will incur huge
losses and cannot be saved if it is not in the collapse phase; consequently, a lot has to be
sacrificed.
This stage occurs when the reason for the emergency is known (Sellnow and Seeger,
2013). Crisis is the name for this phase. The focal point of emergency executives at this
stage is more on executing the plans that have been developed previously. The team
assigned to this phase has made observations that led to the development of these plans.
Leaders at this stage will carry out various activities in dealing with emergencies, especially
to maintain the image and reputation of the organization so that partners and society in
general can continue to believe in the organization so that organizational goals can also be
achieved.
4. Post-Crisis:
Post-crisis issue indicators regarding the causes of the crisis continue to be publicized
in the media, and various parties, including stakeholders, continue to discuss the issue.
However, the company's reputation is not significantly affected as a result of these
discussions (Coombs & Holladay, 2010). Therefore, it is important for management to
continue to observe and discuss the issue in public to increase public trust in the business.
Public trust will also grow as a result of the crisis and the company's resilience in dealing
with it. Companies that successfully resolve crises show that stakeholders and the general
public respond positively.
To achieve a goal, management strategies are basically planning, organizing, acting,
and controlling. However, the strategy must show how operational tactics to achieve these
goals (Onong Uchjana, 2009). It should not serve as a road map that only provides direction.
Next comes the meaning of organizing, coordinating, acting, and controlling, to be more
specific:
1. Planning
What will be done within a certain period of time, at a certain cost, and with the
necessary resources to achieve predetermined results are all aspects of planning. In an effort
to achieve predetermined goals and objectives, planning is also an initial thought. The best
procedure for achieving organizational goals is outlined in planning by setting goals, rules,
plans, and other matters. In accordance with the general policy that has been set, the final
result, which is the focus of planning, becomes the subject of the management process
effectively and efficiently.
2. Organizing
Organizing is making an organized system of work or design, so that each part will
form a unity and generally have an impact, in the end, it can also be called a plan of work
duties and obligations. Organizing incorporates the most common way to arrange and share
work, authority, and assets among individuals of an association so that they can accomplish
hierarchical objectives productively. To ensure that management is effective and efficient,
organizing serves to ease the execution of tasks and the supervision of each team.
3. Implementation (Actuating)
Implementation is a movement made by the initiative to direct, direct, manage each
individual exercise assigned to perform business actions. Leaders assist their employees in
carrying out their responsibilities effectively by developing the right atmosphere. In contrast
to organizing and planning for more abstract aspects. The goal is for management
procedures to function effectively and efficiently in accordance with anticipated plans.
Onong Uchjana, 2009).
4. Supervision/Evaluation (Controling)
Supervision and Evaluation (Control) Supervision plays an important role in
management because it determines the implementation of work in an orderly, directed, and
organized manner. Although it is good to plan, organize, and act, the goals that have been set
will not be achieved if the work is not carried out in an orderly, directed, and organized
manner. Consequently, control involves the supervision of all activities to ensure that they
are directed towards the goal and enable the achievement of the goals that have been set.
Cangara, 2014).
Events that are beyond our control are called crises. It impacts the strategic direction at
a certain level (individual, organization and business), so immediate action is required.
Because they have political implications and the potential to result in legal decisions, issues
can originate from individuals or interest groups and then become public debates. The
outcome may be harmful or prevent activities. Every issue has a cycle.
Issue management evolves into crisis management at some point. A crisis is a situation
that marks a turning point that can either make things better or worse. Preventive Measures
to Deal with Issues and Crises The most effective way to deal with crises is preventive
measures, which can include the following:
1. Gain public trust in the company
2. Trying to build trust by working with the media to resolve issues
Curative Measures:
There are several things that need to be done when a crisis hits an organization or
company, such as:
1. Identify the crisis;
2. Isolate the crisis;
3. Managing the crisis
Problem and Crisis Management:
Once the crisis management team has identified the problem, the next step is to
analyze it to know what to do. It is important to take the right actions and decisions:
1. Full information
2. Effective decision-making methods
3. Positive mental attitude
4. Considerable experience and knowledge
5. Crisis management training or decision-making methods
COMPLIANCE RISK MANAGEMENT
A.
Introduction
Compliance is a must in everyday life, especially in companies that are always at risk.
Usually, the bigger the company, the higher the level of risk it faces. Compliance risk is the
risk of a company not complying and/or not implementing the laws and regulations that
apply in a country (Rustam, 2023). The Basel Committee defines compliance risk as the risk
of regulatory and legal sanctions, reputational damage, or financial loss that a bank may
incur due to non-compliance with laws, internal policies, regulations, codes of conduct and
codes of ethics applicable to its business activities (Indonesian Bankers Association, 2018a).
Risk management is a set of methods and procedures used in order to identify,
measure, monitor, and control risks arising from all business activities (Prabantarikso,
Fahmy, Abidin, & Abdulrachman, 2022). Compliance risk management is a process
implemented in order to ensure the company complies with applicable laws or regulations,
compliance standards, or compliance benchmarks. This can be done in various forms, such
as a combination of procedures, documentation, policies, internal audits, third-party audits,
security controls and technology implementation.
Failure to manage compliance risk can result in the closure of the company by the
authorities, and even bankruptcy. Good and timely compliance risk management is expected
to minimize the impact of risks as early as possible (Indonesian Bankers Association,
2018b). Therefore, the main objective of compliance risk management is to ensure that the
risk management process can minimize the probability of negative effects from company
actions that deviate or violate standards, provisions, regulations and laws. By implementing
risk management, it is expected that companies can better measure and control the risks they
face in carrying out their business activities.
B.
The Importance of Compliance Risk Management:
There are several reasons why it is important for companies to implement compliance
risk management, including:
1. Minimizing Legal Concerns:
Fines or legal sanctions imposed by regulators or local governments often cause
material and immaterial losses. Not only will there be fines, often quite large, but the
reputation or image of the company in the eyes of the public or consumers will also be poor.
For example, the legal impact of the lack of accuracy and delay in reporting debtor
information through SLIK is a decrease in health level, suspension of business activities,
capability assessment and administrative sanctions (Putu Evi Nadya Christina, Atmadja, &
Purwanti, 2018). Banks or their employees who have caused customer losses must provide
compensation for providing false information (Armansyah, 2021). Therefore, compliance
can help businesses keep legal issues such as business license revocation, company closure,
lawsuits, and fines at bay.
2. Strengthening Community Relations:
If the company can tell customers, stakeholders and business partners that it
consistently follows all applicable procedures and industry standards, the company's
relationship with society and reputation will improve. Present or display authoritative
certifications obtained by the company on the company's official website at all times. When
consumers see these certificates of compliance, they are likely to have a high level of loyalty
and trust in the company. It is imperative that every company needs to ensure effective
compliance with the law, because in this way, the company's business will more easily grow
to a new level. Islamic banks have an important role to play in maintaining the trust of
stakeholders and the wider community, inadequate attention to all sharia compliance will
expose Islamic banks to the risk of sharia non-compliance (Darmawan, 2022). Compliance
risk management in Islamic banks is very important in order to maintain the trust and
existence of Islamic banks (Rahmayanti, Fadillah, & Syifa, 2020).
C.
Implementation of Compliance Risk Management:
Ideally, the implementation of corporate compliance risk management should at least
include:
1. Active Supervision of Board of Commissioners & Directors:
The company should have a director responsible for the compliance function and
establish a compliance work unit. The board of commissioners should conduct active
supervision of the compliance function by evaluating the implementation of the compliance
function at least twice a year. The BOC should provide suggestions based on the results of
the evaluation of the implementation of the compliance function to improve the quality of
the implementation of the function.
The director who leads the compliance function must meet the independence
requirements, meaning that he/she has no financial, ownership, management, and/or family
relationships with members of the board of directors, members of the board of
commissioners, and/or controlling shareholders that could affect his/her independence. The
managing director and/or his deputy are not allowed to hold concurrent positions with this
position. In addition, they are not allowed to oversee other functions, including business and
operations, risk management, decision-making on business activities, accounting, finance,
asset management, logistics, procurement of goods or services, information technology, and
internal audit.
The director in charge of the compliance function shall have the duty and
responsibility of at least formulating strategies to encourage the creation of a culture of
compliance, proposing compliance policies or principles to be determined by the board of
directors, determining compliance systems and procedures that are useful in preparing
internal provisions and guidelines. In addition, he is responsible for ensuring that all
systems, procedures, provisions, policies, and business activities of the company are in line
with the provisions of the authorities and the law, minimizing compliance risks,
implementing preventive measures so that policies and/or decisions made by the board of
directors or the head of branch offices abroad do not deviate from the provisions of the
authorities and the law, and monitoring and maintaining the company's compliance with its
commitments to the authorities. The director must provide a report on the implementation of
his duties and responsibilities at least every 3 months to the managing director by
forwarding it to the board of commissioners. Whether or not the management of a bank is
good can be assessed qualitatively based on predetermined management rules (Rizki, 2019).
The company must have a compliance work unit that can take steps to support the
creation of a culture of compliance in all of the company's business activities at all levels of
the organization with a written work program and carry out identification, measurement,
monitoring and control of compliance risks. Assess and evaluate the effectiveness, adequacy
and alignment of the company's policies, systems and procedures with applicable laws and
regulations, as well as review and/or provide recommendations for updates and
improvements to the company's policies, regulations, systems and procedures to comply
with authorities and laws. The work unit is expected to work hard to ensure that the
company's policies, regulations, systems, procedures and business activities are aligned with
regulatory authorities and laws. In addition, the work unit needs to ensure the company's
compliance with its commitments to the authorities, socialize anything related to the
compliance function and applicable provisions to all employees, and become a contact
person related to company compliance issues for internal and external parties.
Officers and employees of the compliance work unit are prohibited from being in a
situation of conflict of interest in the performance of their compliance function duties. In
addition, it is necessary to pay attention to the turnover rate of employees and company
officials in strategic positions, the adequacy of the competence of commissioners and
directors, the adequacy of training programs, and the level of understanding and alignment
with the strategic direction with the company's risk tolerance.
2. Policies, Procedures, and Boundary Setting:
An important part of the overall enterprise risk management strategy is the compliance
risk management strategy. Every company must basically comply with all regulations
related to its business. As a result, the company should not no longer tolerate compliance
risks and therefore make swift and appropriate moves to address them.
Ideally, the company should have a sufficient compliance work program. The
company should ensure the effectiveness of compliance risk management implementation,
especially for the establishment of policies and procedures based on generally accepted
standards, applicable laws and regulations, including those related to the accuracy of setting
limits, and policies to exclude if the execution of transactions exceeds the limits, as well as
enforcing compliance inspection policies through regular procedures. In addition, it concerns
the timeliness of policy communication to all employees at all levels of the organization,
adequate control over new product development, and the adequacy of reporting and data
systems, especially in terms of controlling the accuracy, completeness and integrity of data.
Companies should set compliance risk limits based on the level of risk taken, risk
tolerance and overall corporate strategy, taking into account the ability of the company's
capital to absorb emerging risk exposures and compliance with applicable external
regulations.
3. Risk Identification, Measurement, Monitoring, Control, and Management Information
System (SIM) Processes:
Companies should identify and analyze several factors that may increase their
exposure to compliance risk. These factors include the type and complexity of the
company's business activities, including new products and activities. In addition, the amount
and materiality of the company's non-compliance with internal policies and procedures,
applicable laws, regulations, and sound business ethics practices and standards. Companies
may measure compliance risk using metrics or parameters such as the type, significance and
frequency of violations of applicable regulations, or the company's compliance records, the
actions behind the violations, and violations of generally accepted standards.
Banks identify and analyze several factors that can increase compliance risk exposure
and affect quantitatively to profit and loss and Bank Capital, such as bank business
activities, bank non-compliance and litigation (Hayati, 2017). In practice, forms of
compliance risk in an Islamic bank include the inability to meet the Minimum Capital
Adequacy Requirement (CAR), Statutory Reserves (GWM), Net Foreign Position (NOP),
and Maximum Lending Limit (LLL) (Novita, 2019). An example of compliance risk
measurement is as follows:
PT Bank Syariah Djago's gross profit was 500 million. The risk management
committee determines a Loss Given Event (LGE) of 15%. The risk probability determined
by the company is 20% for risk number 1 & 2, and 50% for risk number 1 & 2.
The company's compliance risk is Rp3,000,000 or 0.6% of gross profit. This means
that, based on the company's compliance risk matrix, the risk is categorized as very low.
Risk SIM, at least includes risk exposure, determination of risk limits, compliance
with risk management procedures and policies, and comparison of realization with risk
management implementation targets. The working unit that carries out the compliance risk
management function should monitor and report the occurrence of compliance risks on a
regular basis or at any time to the company's board of directors. The company needs to
ensure that the company fully complies with the applicable laws in the country where the
branch is located.
In banking, the director responsible for the compliance function must report to OJK on
the implementation of his duties. The report consists of the compliance work plan contained
in the business plan, the compliance report, and a special report on compliance policies
and/or decisions of the board of directors that have deviated from the provisions according
to the director responsible for the compliance function.
4. Internal Control System:
The Company should establish an internal control system for compliance risk when
implementing compliance risk management. The internal control system is used in order to
ensure the company's level of responsiveness to actions that deviate from generally accepted
standards, provisions and applicable laws and regulations. Assessment of the internal control
system in implementing risk management must be carried out by the internal audit work
unit. The implementation of the internal control system at least includes:
a.
Alignment of the internal control system with the type and level of compliance risk inherent
in business activities.
b.
Establishment of authority and responsibility for monitoring compliance with risk
management policies and procedures, and determination of risk limits.
c.
Determine reporting lines and clearly separate functions from operational work units to
control work units.
d.
The organizational structure clearly describes the business activities.
e.
Accurate and timely reporting of financial and operational activities.
f.
Appropriate procedures to ensure the company complies with laws and regulations.
g.
Effective, independent and objective review of the company's operational assessment
procedures.
h.
Risk SIM testing and review.
i.
Complete documentation of operating procedures, scope, and audit results.
j.
Periodic verification and review of significant corporate weaknesses and actions which
retrieved by leadership company to correct deviations that arise.
RISK MONITORING AND REVIEW
A.
Definition of Risk Monitoring and Review:
Risk monitoring is a systematic process of tracking and evaluating the results of the
risk handling process that has been carried out and used as a basis for developing better risk
handling strategies in the future (123dok.com, 2023). Meanwhile, risk review is process
review risk that risks that have been identified and assessed, and evaluate whether the risks
are still relevant and significant, and whether the actions that have been taken are effective
or not (ad-ins.com, 2023). In corporate risk management, risk monitoring is carried out by
the Risk Monitoring Committee formed by and responsible to the Board of Commissioners
in an effort to support the implementation of the duties and responsibilities of the Board of
Commissioners regarding the implementation and supervision of risk management (crms,
2023). Risk monitoring should also be carried out in accordance with the level of risk
identified, and the intensity of monitoring should be adjusted to the factors used in assessing
the level of risk. In the ISO 31000:2018 standard, there are 8 principles of risk management,
including integration, customization, transparency, and monitoring.
So it can be concluded that risk monitoring and review is a systematic and continuous
process carried out by organizations to oversee, evaluate, and update their existing risk
management strategies. This process helps organizations to ensure that risk management
activities remain effective, relevant, and in line with their business objectives. Risk
monitoring and review includes:
1. Monitoring changes in risk
Risk monitoring involves continuous monitoring of identified risks and possible
changes in the level of those risks. This includes changes in the risk's likelihood of
occurrence, potential impact, or external conditions affecting the risk.
2. Evaluate the effectiveness of risk management strategies
Risk review involves regular evaluation of the effectiveness of the risk management
strategies that have been implemented. This includes assessing whether the strategy is
successfully reducing risks, creating opportunities or achieving expected business
objectives.
3. Identifying new risks
The risk monitoring and review process includes recognizing new risks that may not
have been previously identified or that may have been overlooked. Identifying and
managing these new risks ensures that the risk management strategy remains relevant and
effective.
4. Update risk management strategy
Based on the results of risk monitoring and review, organizations may need to update
their risk management strategies. This may include adjustments to mitigation measures,
allocation of different resources, or changes in risk prioritization.
5. Reporting and communication
Monitoring and reviewing risks also includes reporting results and recommendations
to senior management and other stakeholders. This process ensures that up-to-date
information on risks and risk management strategies is available for effective decision-
making.
Overall, risk monitoring and review enables organizations to handle changes in the
business environment and ensure that risk management strategies remain effective in
achieving organizational goals. This process assists organizations in reducing losses,
capitalizing on opportunities, and increasing their resilience to uncertainty.
B.
Importance of Risk Monitoring and Review:
The importance of risk monitoring and review is to ensure and improve the quality and
effectiveness of the design, implementation, and output of risk management processes. Risk
management is the process of identifying, assessing, and controlling threats to an
organization's capital and revenue. Periodic monitoring and review of the process and results
of risk management implementation should be a planned part. The Risk Monitoring
Committee has the responsibility of communicating and consulting with the company's
Board of Commissioners to provide evaluation and advice regarding the company's risk
management process. Risk monitoring is also a systematic process of tracking and
evaluating the results of the risk management process that has been carried out and used as a
basis for developing better risk management strategies in the future (Belle, 2012).
Monitoring and reviewing risks play an important role in an effective risk management
process. The following are some of the reasons why risk monitoring and review are very
important for organizations:
1. Keeping up with changes in the business environment:
The business environment is constantly changing, and monitoring and reviewing risks
allows organizations to stay on track responsive to such changes. By regularly monitoring
risks, organizations can adjust their risk management strategies according to changing
external and internal conditions.
2. Identify new risks:
Monitoring and reviewing risks helps organizations identify new risks that may arise
over time. Identifying and managing these new risks ensures that risk management strategies
remain relevant and effective.
3. Evaluate the effectiveness of risk management strategies:
Monitoring and reviewing risks allows organizations to assess the effectiveness of the
risk management strategies that have been implemented. This assessment can reveal whether
existing strategies are successful in reducing risks or creating opportunities, and whether
changes or adjustments are needed.
4. Ensure accountability and compliance:
Monitoring and reviewing risks ensures that the organization complies with relevant
internal and external regulations, standards, and policies. This process also creates
accountability within the organization, by ensuring that each department or business unit
manages risks in accordance with established policies and procedures.
5. Supports better decision-making:
Monitoring and reviewing risks provides critical information needed for better
decision-making. With a better understanding of risks and the effectiveness of risk
management strategies, management can make better decisions about resource allocation,
priorities and strategic direction.
6. Improving organizational resilience:
Regular monitoring and review of risks helps organizations become more resilient to
uncertainty and change. By adjusting risk management strategies as needed, organizations
can reduce the negative impact of risks and take advantage of opportunities that arise.
Overall, risk monitoring and review is an important element of effective risk
management. This process helps organizations remain responsive to environmental changes,
manage risks more effectively, and achieve their business objectives.
C.
Risk Monitoring and Review Process:
The risk monitoring and review process is an important step in effective risk
management. This process includes a series of activities designed to oversee, evaluate and
update existing risk management strategies. Risk monitoring is carried out by conducting
regular monitoring of the actual performance of the risk management process compared to
the plans or expectations that will result. While risk review is a periodic review or
assessment of current conditions and with a particular focus, for example the effectiveness
of controls against financial or market risks. In monitoring and reviewing risks, it needs to
be done regularly and continuously (inspector.id, 2023). This is done to ensure that the risk
controls that have been implemented are still effective and adequate.
The following are general steps in the risk monitoring and review process (GRC
Indonesia, 2022).
1. Collecting data and information:
The process begins with the collection of data and information related to the identified
risks, including changes in the business environment, the results of the strategy, and the
implementation of the strategy risk management in place, and compliance with relevant
regulations.
2. Risk monitoring:
Keep an eye out for changes in existing risks and identify new risks that may arise
over time. This involves continuous monitoring of identified risks, including changes in the
likelihood of the risk occurring, potential impact, or external conditions affecting the risk.
3. Evaluate the effectiveness of risk management strategies:
Assess the effectiveness of the risk management strategies that have been
implemented, including an assessment of whether they have succeeded in reducing risks,
creating opportunities, or achieving expected business objectives.
4. Identifying areas of improvement:
Based on monitoring and assessment results, identify areas where risk management
strategies can be improved or updated. This may include adjustments to mitigation
measures, allocation of different resources, or changes in risk prioritization.
5. Update risk management strategy:
Implement necessary changes and adjustments to risk management strategies, based
on evaluation results and identification of areas of improvement.
6. Reporting and communication:
Reporting the results of risk monitoring and review to senior management and other
stakeholders, and recommending actions to be taken. This process ensures that up-to-date
information on risks and risk management strategies is available for effective decision-
making.
7. Testing and validation:
Piloted the updated risk management strategy to ensure its effectiveness and
compliance against relevant regulations. This process also includes validating the expected
results of the new risk management strategy.
8. Periodic review:
Conduct periodic reviews of the risk monitoring and review process to ensure its
relevance and effectiveness in managing organizational risks.
By following this process, organizations can ensure that their risk management
strategies remain effective and relevant in the face of changing business environments and
emerging risks over time.
Here are some additional steps that can help in the risk monitoring and review process:
1. Training and education
Provide relevant training and education to employees and management on the risk
management process, including monitoring and review methods. This will help increase
understanding of the importance of risk management and how the monitoring and review
process contributes to the success of the organization.
2. Integrate risk monitoring and review processes into existing business processes
Integrating risk monitoring and review processes into existing business processes will
ensure that risk management becomes an integral part of the organization's operations and
not just a separate task performed sporadically.
3. Using technology
Using technology such as risk management software can help organizations in the
process of monitoring and reviewing risks. These technologies can simplify the process of
data collection, analysis, and reporting, and allow organizations to identify trends and
patterns that may be difficult to see manually.
4. Creating a risk management culture
Encouraging a culture of risk management throughout the organization will help
ensure that monitoring and reviewing risks is a priority for all employees and management.
This culture will include open communication about risk, accountability and support for
effective risk management.
By following these steps and making risk monitoring and review a key part of an
organization's risk management strategy, companies can reduce the negative impact of risks,
capitalize on emerging opportunities, and increase their resilience to uncertainty.
D.
Risk Monitoring and Review Framework
A risk monitoring and review framework is a structured process that involves tracking,
evaluating and escalating risk ratings and the effectiveness of responses taken in managing
risk. The risk monitoring process is very important because risks and the business
environment are dynamic (Bank Permata, 2023). The purpose of the risk monitoring and
review framework is to identify how objectives are likely to be affected, and to analyze risks
in terms of their consequences and probabilities prior to decision making (SNI, 2016b).
In risk management, a risk management framework is a set of components that provide
an organizational foundation and setting for the design, implementation, monitoring, review
and regular improvement of risk management throughout the organization. The foundation
includes policies, objectives, mandates and commitments to manage risk (SNI, 2016a). In
risk monitoring, There are several risk criteria and monitoring guidelines that must be
considered, such as the level of risk identified and the factors used in assessing the level of
risk. Risk monitoring also involves proper reporting and recording of results.
Overall, the risk monitoring and review framework is a structured process that
involves tracking, evaluating and escalating risk ratings and the effectiveness of responses
taken in managing risks. The aim is to identify how objectives are likely to be affected, and
to analyze risks in terms of their consequences and probabilities prior to decision-making.
It can be concluded that a risk monitoring and review framework is a structure that
helps organizations carry out the risk monitoring and review process systematically and
efficiently. Here are the essential elements of a risk monitoring and review framework:
1. Policies and procedures:
Develop clear and detailed policies and procedures regarding the risk monitoring and
review process. This policy should include the objectives, methods, frequency and
responsibilities associated with risk monitoring and review.
2. Roles and responsibilities:
Define clear roles and responsibilities for each individual or team involved in the risk
monitoring and review process. This includes senior management, risk managers, internal
auditors and other relevant stakeholders.
3. Information systems and technology:
Using technology to support the risk monitoring and review process, such as risk
management software, data analysis systems, and reporting tools. These technologies will
assist the organization in efficiently and effectively collect, analyze and report risk-related
information.
4. Reporting and communication:
Develop effective reporting and communication mechanisms to communicate the
results of risk monitoring and review to senior management and other stakeholders. This
reporting should include information on changes in risk, the effectiveness of risk
management strategies, and recommendations for improvements or adjustments.
5. Key performance indicators (KPIs):
Develop relevant and measurable key performance indicators to assess the
effectiveness of the risk monitoring and review process. These KPIs may include metrics
such as the number of risks identified, the level of compliance with policies and procedures,
and the outcome of risk mitigation actions.
6. Periodic review:
Conduct periodic reviews of the risk monitoring and review framework to ensure that
these processes remain relevant and effective in managing organizational risks. This review
should include an evaluation of the policies, procedures, roles and responsibilities,
technology, and communication methods used in the risk monitoring and review process.
7. Training and education:
Provide relevant training and education to employees and management on the risk
monitoring and review framework and how these processes contribute to the success of the
organization.
By following an effective risk monitoring and review framework, organizations can
ensure that their risk management strategies remain effective and relevant in the future.
facing changes in the business environment and risks that arise over time.
In addition, a good risk monitoring and review framework will:
1. Promoting a culture of risk management
Create a culture where risk management is considered a critical part of the
organization's success. This culture will include open communication about risk,
accountability, and support for effective risk management.
2. Integrate risk monitoring and review processes into business processes
Integrate risk monitoring and review processes into existing business processes, so that
risk management becomes an integral part of the organization's operations.
3. Using a proactive approach
Within the framework of risk monitoring and review, organizations should implement
a proactive approach to identify and manage risks before they cause harm or affect the
achievement of business objectives.
4. Adopt a data-driven approach
Using data and analysis to support the decision-making process in risk management. A
data-driven approach will allow organizations to identify risk trends and patterns that may
be difficult to see with manual methods.
5. Engage stakeholders
Involve relevant stakeholders, such as employees, management, board of directors,
regulators, and other external parties in the risk monitoring and review process. By
involving stakeholders, the organization can ensure that the perspectives of the stakeholders
are relevant diverse and valuable views are integrated into the risk management process.
By following an effective risk monitoring and review framework, organizations will
be better equipped to deal with risks and mitigate their negative impact, while capitalizing
on emerging opportunities to achieve business objectives.
E.
Challenges in Risk Monitoring and Review:
In conducting risk monitoring and review, organizations may face several challenges.
Here are some common challenges that may be faced:
1. Limited resources
Organizations may have limited resources, such as time, manpower and budget, which
affects their ability to effectively monitor and review risks.
2. Changes in the business environment
A constantly changing business environment can create new risks or affect existing
ones. Organizations must constantly adjust their risk monitoring and review to accommodate
these changes.
3. Data dependency
Effective risk monitoring and review depends on the availability and quality of data.
However, collecting, managing and analyzing relevant and accurate data can be challenging,
especially if the organization lacks efficient information systems.
4. Risk complexity
The risks faced by an organization may be complex and interrelated, making
monitoring and reviewing risks more difficult. Organizations must able to identify and
understand the relationship between different risks in order to manage them effectively.
5. The need for effective communication
Effective communication between management, employees, and other stakeholders is
essential for successful risk monitoring and review. However, creating effective
communication channels and ensuring a clear understanding of risks and risk management
strategies can be challenging.
6. Organizational culture
Building a strong risk management culture across an organization may be difficult,
especially if there is resistance to change or a lack of understanding of the importance of risk
management.
7. Compliance with regulations
Organizations may face challenges in complying with relevant regulations and
ensuring that their risk monitoring and review complies with legal and industry
requirements.
8. Measuring effectiveness
Measuring the effectiveness of risk management strategies and risk monitoring and
review processes can be challenging. Developing relevant and measurable key performance
indicators (KPIs) to assess this effectiveness requires careful thought and planning.
Addressing these challenges requires commitment from senior management, allocation
of adequate resources, use of appropriate technology, and an approach that is continuously
adapted to the changing business environment and organizational needs.
F.
Technology in Monitoring and Risk Review
Technology plays an important role in risk monitoring and review, as it can help
organizations collect, analyze, and report risk information more efficiently and effectively.
Here are some of the technologies often used in risk monitoring and review:
1. Risk management software
Software solutions specifically designed to help organizations manage their risks.
Common functionalities include risk identification, risk assessment, risk monitoring and
review, and reporting. Some popular risk management software include RSA Archer,
MetricStream, and Riskonnect.
2. Data analysis system
Systems that help organizations collect, manage, and analyze relevant data for risk
monitoring and review. These technologies may include data analytics tools such as
Microsoft Power BI, Tableau, or Qlik Sense, as well as big data analytics platforms such as
Hadoop and Apache Spark.
3. Artificial intelligence (AI) technology and machine learning
Algorithms AI and learning machine learning can be used to identify patterns and trends in
risk data, helping organizations predict risks that may arise and optimize management
strategies their risk.
4. Real-time monitoring system
Systems that allow organizations to monitor risks in real-time or near real-time. These
technologies can include IoT (Internet of Things) sensors, network monitoring systems, and
social media monitoring tools.
5. Reporting software
Tools that help organizations create, manage, and distribute risk reports to relevant
stakeholders. Examples of reporting software include Microsoft Power BI, Tableau, and
Qlik Sense.
6. Geographic information system (GIS)
Technology that allows organizations to visualize and analyze risk data based on
geographic location. GIS can help organizations identify risks associated with geographic
factors, such as natural disasters or climate change.
7. Incident management system
A system that helps organizations track and manage risk incidents as they occur, and
analyze incident data to identify patterns and take preventive action.
By integrating these technologies into the risk monitoring and review process,
organizations can improve the efficiency and effectiveness of their risk management, as well
as reduce the potential loss or negative impact of the risks faced.
G.
Risk Monitoring and Review Case Example:
Bank XYZ is a bank that operates in several countries. To maintain business stability
and sustainability, the bank needs to manage various risks, such as credit risk, market risk,
liquidity risk, and operational risk. Here is a case example of how Bank XYZ uses risk
monitoring and review to manage these risks:
1. Risk identification
Bank XYZ identifies the key risks it faces through discussions with various business
units, regulators, and other external stakeholders. They used risk identification methods such
as SWOT analysis, brainstorming, and Delphi technique.
2. Risk assessment
XYZ Bank assesses the identified risks by considering the likelihood of occurrence
and potential impact. They use risk assessment methods such as business impact analysis
(BIA), decision tree analysis, and Monte Carlo simulation.
3. Risk mitigation
Bank XYZ develops appropriate risk mitigation strategies to reduce the negative
impact of the risks it faces. These strategies include portfolio diversification, credit
performance monitoring, use of derivative instruments to manage market risk, and
implementation of an operational risk management system.
4. Risk monitoring and review
XYZ Bank regularly monitors and reviews the risks it faces, as well as the
effectiveness of the risk mitigation strategies it has implemented. They use technologies
such as risk management software, data analysis systems and real-time monitoring tools to
support this process.
5. Risk reporting
XYZ Bank reports relevant risks and risk mitigation strategies to the board of
directors, regulators, and other stakeholders. They use reporting software to efficiently
create and distribute risk reports.
6. Risk communication and consultation
XYZ Bank ensures that all employees and other stakeholders understand the risks it
faces and their role in managing those risks. They use training programs, regular meetings,
and other communication channels to promote a strong risk management culture.
By implementing effective risk monitoring and review, XYZ Bank can proactively
manage the risks it faces, reduce potential losses, and ensure compliance with regulatory
requirements. This ultimately helps the bank achieve its business objectives and protect
stakeholder interests.
Students also viewed