134
RISK CONTROL TECHNIQUES
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 6
16.1 TYPE CONTROL:
There are various controls that can be applied to hazard risks. The most convenient
classification system is to describe these controls as preventive, corrective, directive and
detective. This is the risk classification system suggested in the Orange Book. Table 16.1
provides a more detailed description of each of these four types of hazard controls. With
respect to hazard risk, preventive, corrective, directive and detective (PCDD) control options
represent a clear hierarchy of controls. The relationship between these four types of controls
and the dominant risk response for different risk levels is illustrated in the risk matrix shown
in Figure 16.1. Table 16.2 provides examples of these four types of controls in relation to
health and safety risks.
Preventive controls are designed to limit the likelihood of an unwanted hazard event
occurring. The majority of controls implemented in organizations in response to hazard risks
are preventive controls. For health and safety risks, preventive controls would include
substituting less hazardous materials in the activity or closing the activity so that employee
exposure to dust or fumes is eliminated. Examples of preventive controls for fraud risks are
shown in Table 16.2. Corrective controls are designed to correct undesirable circumstances
and reduce unacceptable risk exposures. They provide a key method by which risks are
treated so that they become less likely to occur and/or their impact is greatly reduced. In
general, corrective controls are designed to improve the situation. For example, a machine
guard is a corrective control.
There is debate about disaster recovery planning (DRP) and business continuity
planning (BCP) and whether they fit into the PCDD classification of different types of hazard
risk controls. Some organizations consider DRP and BCP to be directive controls, whereas
others argue that they are corrective controls. An alternative approach is to say that DRPs and
BCPs are concerned with crisis management and cannot be easily classified as a PCCD type
of control and should be considered a fifth type of control. In reality this argument, like many
others about terminology, is not helpful. When an organization is faced with a crisis, it will be
in a much better position to cope if plans have been considered and made before the crisis
135
arises. Sometimes crisis management will involve using alternative facilities that were in
place before the crisis arose. It could be argued that this is corrective control.
In all cases, crisis management will involve directives to the parties involved on how
they should behave if a crisis arises. It can be said that this is directive control. Typically,
detective controls relate to the identification of circumstances where risks have materialized at
a fairly low level with limited impact and consequences. Obviously, DRP and BCP relate to
circumstances where risks have materialized at the crisis level. Therefore, it is not appropriate
to classify DRP and BCP as detective controls.
The bow-tie representation of the risk management process is a convenient way of
to describe the role of the four types of control. Preventive controls are relevant to actions
taken before the event occurs. The nature of detective controls means that they relate to
circumstances after the event has occurred. Corrective and directive controls can be relevant
to loss prevention, damage limitation, and cost control. These are the three phases of loss
control. The relevance of control types to the bow-tie presentation of the risk management
process is shown in Figure 16.2. For illustration, this figure uses the same building damage
hazard as shown in Figure 11.2.
Directive controls are designed to ensure that certain outcomes are achieved. In health
and safety terms, directive controls would include instructions given to employees to follow,
for example, in the use of personal protective equipment. Training on how to respond to
certain risk events and detailed instructions and procedures are directive controls. Directive
controls also relate to actions to be taken in the event of a loss to limit damage and contain
costs. Detective controls are designed to identify occasions when undesirable outcomes have
occurred. Controls are intended to detect when these undesirable events occur, to ensure that
things do not deteriorate further. An example of detective controls in a project is conducting
post-incident reviews. There is a clear hierarchy of control effectiveness represented by the
sequence of preventive, corrective, directive, and finally detective. Preventive controls are
clearly the most effective, followed by controls that correct adverse circumstances.
Providing training and direction to staff is a weaker level of control, and detective
controls only ensure that an adverse event has occurred. The importance of DRP and BCP
should not be underestimated. Both are cost control methods designed to ensure minimum
disruption after the risk of harm has materialized, so they are aligned with detective controls.
However, DRPs and BCPs do not fit into the PCDD classification system for controls, as they
are post-loss procedures. Some control classification systems include BCPs and DRPs as a
fifth control category. The example in the box below illustrates that an organization would use
all four types of controls to build a robust set of risk responses. A road transport company
136
would use all four types of controls to reduce road traffic accidents.
Application of 4T:
Take for example a road transportation company and the desire to reduce the number
of road traffic accidents per million miles traveled, and the options to reduce this number. The
company can look at the hierarchy of preventive, corrective, directive and detective controls
and decide on the following:
•
The scope for introducing preventive controls includes reviewing vehicle routes and
realistic estimates on delivery schedules so that drivers do not have to drive
dangerously to arrive on time.
•
The types of corrective controls to be introduced include enhanced maintenance
procedures and better arrangements for drivers to report vehicle malfunctions.
•
Enhanced directive controls will be based on defensive driver training and the
provision of vehicle driver handbooks with practical advice that is easy to understand
and follow.
•
While some detective controls are already implemented through the use of
tachographs in vehicles, companies may decide to also introduce regular reviews of
driver's licenses to check for penalty points.
Other controls that a transportation company might evaluate include regular inspections of
vehicles to find and report damage, and a review of fuel consumption to identify drivers with
aggressive driving styles. The company is then in a position to introduce a structured and
measurable loss control program to reduce the overall cost of operating the vehicle fleet.
16.2 RISK ZONE HAZARD:
Although the 4Ts of hazard response can be illustrated on a simple risk matrix, such as
Figure 16.1, the options are not so obvious. It can be seen that tolerance and termination
options converge at the center of the risk matrix. It is unreasonable to suggest that small
increases in risk likelihood and potential impact will completely change an organization's
approach to a particular risk.
Figure 16.3 provides a slightly more realistic analysis by providing a diagram that
builds on Figure 16.1. Figure 16.3 illustrates that there are three zones in the risk matrix, as
the cautious and concerned areas merge into a central zone. The comfort zone is
predominantly for events with a low likelihood/low impact. As can be seen, there is a level of
potential impact that will always fall within the comfort zone. Likewise, there is a level of risk
likelihood that is always considered so low that it will not occur. However, as the likelihood
137
of risk and potential impact increases, a point is reached where judgment is required as to
whether the risk should be tolerated. Judgment is required within the precautionary zone and
action will usually be taken to address and/or transfer the risk within that zone. The line
separating the caution zone from the zone of concern represents the organization's risk
appetite. The caution zone and the zone of concern together depict the variability of
acceptable risk levels and can be thought of as the organization's tolerance for acceptable
variability or volatility in a given risk level.
When the likelihood of the risk and the potential impact are increasing, the critical line
is reached. When the risk is above the critical line, the organization will be concerned about
tolerating the risk and will want to stop exposure to it. Under certain circumstances, The
organization will not be able to stop these risks, either because they represent business
interests or because they relate to the high risk/high reward strategy that has been adopted by
the board.
16.3 PREVENTIVE CONTROL:
Table 16.1 provides a brief description of the nature of preventive controls. This is the
most important type of risk control, and all organizations will use preventive controls to deal
with certain types of risks. Prevention or elimination of all risks is not possible in a cost-
effective manner, nor is it desirable for the future of the organization and the continuation of
certain activities. Examples of preventive controls include segregation of duties, where no
person has the authority to act without the consent of another when paying bills. Also, the
expense system should prevent the same person from ordering goods and then authorizing
payment for them. In health and safety terms, preventive controls include the elimination or
removal of hazards and providing less risky substitutes. For example, hazardous chemicals
used in cleaning operations can be replaced with less hazardous alternatives.
The advantage of preventive controls is that they eliminate the hazard, so no further
consideration is required. In reality, this may not be a cost-effective option and may not be
possible for operational reasons. The disadvantage of preventive controls is that useful
activities may be eliminated and outsourced or replaced with something less effective and
efficient. Health and safety practitioners refer to the elimination of hazardous activities 'to the
extent reasonably practicable'. Achieving something to the extent reasonably practicable
involves balance the costs in terms of time, trouble and money against the benefits in terms of
the reduced level of risk achieved. For example, reducing the risk of collapse can be achieved
in underground mines by the provision of support beams and props. However, the extent to
which this is reasonably practicable needs to weigh the cost of providing these props against
138
the level of risk reduction that will be achieved in the mine.
16.4 CORRECTIVE CONTROL:
Table 16.1 provides a brief description of the nature of corrective controls. Corrective
controls are the next option after it has been decided that preventive controls are not
technically feasible, operationally desirable or cost-effective. Corrective controls are capable
of producing a fully satisfactory result, where the current level of risk is reduced until it
matches the organization's risk appetite. Examples of corrective controls can be found in
occupational health and safety management. Engineering containment through barriers or
guards is a very well-established type of corrective control. With respect to fraud exposure,
the use of passwords or other access controls can be considered a corrective control. Staff
rotation and regular change of supervisors also fall under this category of controls.
The advantage of many corrective controls is that they are simple and cost-effective.
Also, they do not require that existing practices and procedures be eliminated or replaced with
alternative work methods. Controls can be implemented within the framework of existing
activities. The disadvantage of some corrective controls is that the marginal benefits achieved
may be difficult to quantify or confirm as cost-effective. Sometimes, corrective controls are
over-engineered and the costs are disproportionate to the benefits achieved. It is for risk
management practitioners and internal auditors, as well as employees themselves, to identify
where costly and/or ineffective corrective controls have been implemented. Very often,
corrective controls are put in place due to regulatory requirements. These may not be
satisfactory from the organization's point of view and incur additional costs and/or
inefficiencies. However, the organization must ensure that an appropriate level of corrective
control is achieved to meet the minimum requirements of the legislation.
The design and implementation of corrective controls is often the cause of discussion
and even disagreement. For example, there are sometimes discussions with building
occupants about installing sprinklers as corrective controls that will activate in the event of a
fire and reduce fire damage. Occupants of premises with computer installations will often say
that sprinklers in computer rooms are not appropriate. While understanding that water does
damage computer installations, the fire department will usually counter the objection by
pointing out that 'water causes damage, but fire destroys'. While this analysis is correct and
sprinklers prevent total destruction, the disadvantages and unintended consequences of
installing additional controls always need to be carefully considered.
139
16.5 DIRECTIVE CONTROL:
Table 16.1 provides a brief description of the nature of directive control.
Organizations will be familiar with directive controls, as staff need to be informed of the
correct way of performing certain tasks. Where tasks involve a degree of risk, documented
procedures, along with information, training and instruction, can be seen as directive controls.
Therefore, directive controls tend to be applied for most risks, regardless of whether other
types of controls are also in place. An example of a directive control is the requirement to
wear personal protective equipment when performing potentially hazardous activities. Staff
will need to be trained in the correct use of the equipment and a level of supervision will be
required to ensure that the equipment is used correctly.
The advantage of directive controls is that risk control requirements can be explained
during normal training and instruction sessions provided to staff. However, directive controls,
especially with regard to health and safety risks, represent a low level of control that may
require constant supervision to ensure that the correct procedures are followed.
Although directive controls are themselves an unsafe and unreliable method of risk
control, they will always be a component in the overall approach to risk control adopted by
any organization. Developing systems, procedures and protocols is important for any
organization. However, there is a danger that if the procedures developed are not implemented
in practice, the organization will be more vulnerable to allegations of poor risk control.
Developing detailed risk control procedures is an indication by the organization that risks
exist and need to be managed. However, failure to implement the identified procedures will
leave the organization unable to defend itself by claiming that it was unaware of the risks.
The value and relevance of directive controls is clear. Chapter 18 discusses business
continuity planning and the importance of providing clear direction to the public regarding
crisis management as an immediate priority, followed by disaster recovery and finally,
ensuring business continuity. Contracts, including insurance policies, are also a form of
directive control, as discussed in Chapter 17 on insurance and risk transfer. All contracts
provide written directions to people on how they should respond when a particular set of
circumstances, such as an insurance claim, arise.
An important aspect of directive control that is often overlooked is that when
When an unexpected event occurs, it is usually directive control that is introduced as an
immediate response to that unexpected event. The hierarchy of control described in Table
16.2 represents a desirable situation in an established and stable state. However, when the
unexpected has been detected, the order in which new controls will be introduced may be
somewhat different. The initial response will likely involve the introduction of directive
140
controls and/or preventive controls, if the event is an immediate risk, especially if it is a safety
risk. This immediate response will then allows corrective controls to be designed and
implemented when a new set of circumstances becomes apparent and/or stabilized.
16.6 DETECTIVE CONTROL:
Table 16.1 provides a brief description of the nature of detective controls. As
suggested in the title, detective controls are procedures that identify when a hazard has
materialized. Detecting that a hazard has materialized some time after the event is not entirely
satisfactory, but may be justified in certain circumstances. Sometimes, other controls may not
be able to completely eliminate the possibility of a risk materializing. Examples of detective
controls include stock or asset checks to ensure that stock or assets are not taken without
authorization. A bank reconciliation exercise can detect unauthorized transactions. In addition,
post-implementation reviews can detect learnings from the project that can be applied in the
future. Detective controls are closely related to the review and monitoring carried out as part
of the risk management process.
The advantage of detective controls is that they are often simple to administer. After
all, they are essential in many circumstances where the organization will need an early
warning that other risk control measures have broken down. The disadvantage of detective
controls is that the risk has already materialized before it is detected. It can be argued, of
course, that the fact that detective controls exist will deter certain individuals from trying to
circumvent other risk controls. Fraud detection is often only possible after fraud has occurred.
However, there are considerable advantages in detecting fraud early, so that the nature and
scale of the fraud can be reduced and the scope for similar fraudulent activities in the future
eliminated. The text box discusses the introduction of new financial controls in charities.
Even in health and safety settings, there is scope for the use of detective controls.
Certain work activities have hazards associated with them that can lead to permanent and
serious health problems. By having detective controls to identify the early symptoms of these
poor occupational health conditions, employees will be diagnosed early and further exposure
can be eliminated. Examples of these types of health and safety controls include early
detection of lung diseases from dust exposure, skin conditions such as dermatitis and
eventually deafness caused by occupational noise exposure.
Financial Control for Charity:
The main reason for having financial controls is to reduce the risk of errors and fraud.
Mistakes are likely to result in loss of money, as donors are more likely to give money to
141
charities they can trust. Once you have established your financial controls, they should be
discussed and approved by the trustees. You need to ensure that you have the support of all
trustees before implementing any new controls. Then, implement the financial controls by
noting who is responsible for each control. By making someone responsible for a financial
control, it is more likely to be effective.
Controls are only good if they are relevant; therefore, you need to ensure that you
regularly review your controls to see if they are still effective. As things change, you need to
think about making changes to your controls as your organization evolves. It can be difficult
to make changes to existing controls, but assessing why controls are no longer valid and how
new controls can help the organization will help you implement changes.
INSURANCE AND RISK TRANSFER
17.1 THE IMPORTANCE OF INSURANCE:
Risk transfer is one of the main risk responses available in relation to hazard risk. This
transfer usually occurs through insurance and is often described as risk financing. The basic
principle of insurance is that the insurance company is contracted to pay a certain amount of
money when certain circumstances arise or certain events occur. The insurance contract may
require the insurance company to pay for losses suffered directly by the insured. This is first-
party insurance and includes property damage insurance. Another type of insurance contracts
the insurance company to pay damages to other parties if they have been injured or suffered
losses due to the insured's activities. This is third-party insurance and includes third-party
motor and public/general liability.
An insurance contract is a contract of utmost good faith. This means that the insured
party is obliged to disclose all information relevant to the insurance contract. If this
information is not disclosed, the insurer or underwriter is entitled to refuse to continue to
provide insurance cover and may refuse to pay any claims that arise.
There are advantages and disadvantages associated with using insurance as a risk
transfer mechanism. The advantage is that it provides compensation against expected losses.
Insurance can reduce uncertainty about hazard events that may occur. It can provide economic
benefits to the insured, as the loss may be greater than the insurance premium. Finally,
insurance can provide access to specialist services as part of the insurance premium. These
services may include advice on loss control.
Disadvantages include the delays often experienced in obtaining settlement of
insurance claims and the difficulties that can arise in calculating the financial costs associated
142
with a loss. There may be disputes over the extent of coverage that has been purchased and
the exact terms and conditions of the insurance contract. Finally, the insured may have
difficulty in determining the appropriate indemnity limits for liability exposures. This may
result in under-insurance and subsequent failure to pay claims in full.
There are alternatives to insurance when an organization wants to transfer the financial
impact of a hazard event. Alternatives to insurance are sometimes referred to as alternative
risk transfer or alternative risk financing techniques. Risk financing options available to
organizations include:
•
conventional insurance;
•
contractual transfer of risk;
•
captive insurance company;
•
risk pooling in mutual insurance companies;
•
derivatives and other financial instruments;
•
alternative risk financing mechanisms; and
•
single premium insurance bonds.
Organizations may decide to retain a certain amount of the financial impact associated with a
loss. Risk retention can be achieved by accepting large excesses or deductibles on insurance
policies, deciding not to insure certain risk exposures (self-insurance) or setting up a captive
insurance company. A number of organizations with similar risk exposures may decide to
establish a joint captive insurance company. This is often referred to as risk pooling or
founding a mutual insurance company.
Insurance is a risk transfer or risk sharing response. It represents a post-event cost
containment response to risk. Insurance is most important for low-probability/high-impact
risks, such as asset destruction or payment of liability costs in circumstances where liability
insurance is legally required or large losses are likely. In addition to repairing assets,
insurance is available for the cost of implementing disaster recovery plans and business
continuity plans. Insurance can also be purchased to cover increases in operating costs, as
illustrated in Figure 18.1.
17.2 INSURANCE HISTORY:
Insurance has a very long history that can be traced back to Chinese and Babylonian
traders. There is evidence that marine insurance had become universal among European
maritime nations by the mid-1300s. More recently, the Great Fire of London in 1666 gave rise
to the modern insurance industry. In the 1680s, a coffeehouse (Lloyd's) opened in London,
143
which became a meeting place for parties wishing to insure cargoes and ships and those
willing to underwrite such ventures. Insurance developed rapidly during the 18th and 19th
centuries. Before the formation of incorporated organizations, insurance policies were signed
by individuals whose names and the amount of risk they were prepared to assume were
written under the insurance proposal. This gave rise to the term 'underwriter'.
Modern insurance companies in the United States developed between the mid-1730s
and mid-1750s. The development was often in response to a major disaster, usually a major
fire. There was a significant fire in New York in 1835, and the Chicago Fire of 1871
illustrated the costly nature of fires in urban areas and the need for insurance. The Chicago
Fire of 1871 is discussed in more detail in the box on the next page. Some insurance
arrangements were also associated with protection for dependents after the death of a
monetized member of the household. These arrangements became more formalized with the
establishment of friendly or profitable societies during the 19th century.
The development of liability insurance has a more recent history, stretching back
perhaps only 100 years. Compulsory liability insurance is a requirement in many countries
and has a more recent history of perhaps only 50 years. Compulsory liability insurance is
usually limited in most countries to employers' liability (or workers' compensation) and
motorized third parties.
Chicago fire of 1871:
Around 9 p.m. on October 8, 1871, a fire broke out in a cow shed behind a house in
Chicago. It was an unusually dry summer and the fire jumped quickly from house to house,
then street to street. The fire spread from southwest to northeast, enveloping the business
district. Then the lumber capital of the world, Chicago was a city built primarily of wood.
Chicago's business district is impressive. With the development of railroads and the economic
boom that followed the American Civil War (1861-65), the city boomed.
But the fire raged through four square miles of the metropolis; it destroyed factories,
stores, railroad depots, hotels, theaters, and banks. The fire burned ships on the Chicago River
and consumed almost all of the city's publishing and printing presses. In the end, property
damage amounted to $2.880 million. Nearly 300 people died in the fire and
100,000 people were left homeless. The rebuilding of Chicago was a tremendous undertaking.
Insurance companies in the United States and Europe seized the opportunity, generating the
amount they had to pay for compensation. Cities in the United States and abroad sent $75,000
million in relief funds, and thousands of donated books replenished Chicago's libraries. Soon
Chicago began to attract entrepreneurs, businessmen and renowned architects, who found
144
ways to profit from the reconstruction efforts.
17.3 TYPES OF COVERAGE INSURANCE:
The different types of insurance coverage that an organization may require are
outlined in Table 17.1. In general, there are three reasons why an organization would want to
purchase insurance coverage. In summary, the reasons for purchasing insurance are as
follows:
•
mandatory legal and contractual obligations;
•
balance sheet/profit and loss protection;
•
employee benefits/protection of employee assets.
Table 17.1 provides further information on the different types of insurance available and the
circumstances under which insurance should be purchased. In most cases, the purchase of
insurance is not mandatory. However, most countries require the purchase of insurance under
certain circumstances. Typically, these are liability classes, including insurance coverage to
compensate injured employees and for parties involved in road accidents. Regardless of the
mandatory class, organizations can decide whether to purchase insurance. This decision will
be based on a risk assessment and whether the nature and extent of the risk is within the
organization's hazard tolerance. The cost of insurance (premium) and the extent of insurance
coverage are also important considerations when deciding to purchase insurance whether to
buy insurance. Typically, insurance is purchased for risks with a low/large probability, such as
floods, storm damage, and major fires.
Consider the example of an issuer's insurance needs. Related to legal liability,
The company realizes that it must purchase employers' liability insurance and motor third
party insurance. Also, it is a requirement placed on magazine distributors by wholesalers that
companies purchase libel and slander insurance. To protect its balance sheet and income
statement, the company needs to purchase property damage and business interruption
insurance, along with credit risk insurance and goods in transit insurance.
The issuer may also decide to provide benefits to staff by way of life, critical illness
and private medical insurance, as well as personal accident and travel insurance. For the
benefit of company directors, directors and officers (D&O) liability insurance will be
purchased. By conducting this evaluation, in consultation with a broker insurance, the
company has ensured that it has implemented an insurance program that provides protection
only when necessary, appropriate and cost-effective.
145
17.4 NEEDS EVALUATION INSURANCE:
Table 17.2 provides a checklist for organizations to decide which type of insurance is
required. There are various types of insurance available and the specific activities and features
of the organization will help in deciding which insurance coverage to purchase. Sometimes,
there is a lack of insurance capacity and even if the organization has decided to purchase that
type of insurance, it may not be available at an affordable cost.
There has been a recent trend for organizations to look at the entire portfolio of risks
they face. This enterprise risk management approach to risk has resulted in a careful review of
how much insurance an organization wants to purchase. For example, if there are significant
risks in a project, but insurance is only available for limited risk exposures, purchasing
insurance only for those limited risks may not be appropriate. The company's approach to risk
management has reduced the use of insurance as a risk control mechanism for some
organizations. One of the features of the insurance market is that insurance costs vary
significantly during different cycles of the insurance market. The market will cycle between
soft market conditions (low premiums) and hard market conditions (high premiums) over a 6-
10 year period. When premium rates are high, organizations will tend to buy less insurance
and use more captive insurance companies (as described below). When premium rates are
low, organizations will purchase more insurance as insurance becomes a more cost-effective
control measure.
17.5 PURCHASE INSURANCE:
When looking at purchasing insurance coverage, organizations need to consider the 6Cs of
insurance purchasing, as follows:
•
Cost;
•
Scope;
•
Capacity;
•
Capabilities;
•
Claim;
•
Compliance.
The cost of insurance is determined by the insurance premium required of the
organization. The second component of the cost is the self-insurance rate (including excess or
deductible) imposed by the policy. This means that if a claim occurs, the organization must
pay the first part of the claim before receiving money from the insurance company. Insurance
policies usually have limits, guarantees, and exclusions. This will state that the claim will be
146
denied under certain circumstances. These coverage issues need to be explored in detail by the
organization purchasing the insurance to ensure that adequate coverage is in place. The only
reason to buy insurance is that claims will be paid when one of the identified events occurs.
The history of a particular insurance company in relation to the payment of claims and the
reputation of that insurance company will be an important factor when deciding which
insurance company to appoint.
For very large organizations with considerable assets, one insurance company alone
may not be willing to offer coverage up to the full value of those assets. When purchasing
insurance, organizations need to think about the capacity that the insurance company is
willing to offer in relation to the value of the assets/exposures that need to be insured. Many
insurance companies offer services in addition to insurance. These may include loss control
services and assistance with business continuity planning. The ability of the insurance
company in this area may be an important factor in deciding which insurance company to
choose.
An increasingly important issue for insurance buyers is the financial security, status
and capabilities of insurance companies. The nature of the business model operated by
insurance companies means that they receive premiums at the start of the policy, but do not
have to pay claims until some time, often considerable, after the event or loss. This resulting
in a positive cash flow position for the insurer and associated opportunities to earn investment
income. However, the diversification of insurance companies into high-risk financial activities
has resulted in significant losses for some of them and a decline in their financial status. In
addition, low interest rates and poor stock market performance have resulted in decreased
investment income. Therefore, insurance buyers need to pay more attention to the financial
status or credit rating given to each insurance company when making decisions about which
company to use.
Reference has been made to insurance claims and the importance of insurance claims
in the in relation to insurance. Apart from legal and client requirements, the only reason
organizations buy insurance is to cover increased operating costs, recover damage repair costs
and restore business after a loss. In relation to third-party insurance, it is the injured third
party who will file the insurance claim. Handling insurance claims can be a detailed and
forensic exercise. Sometimes claims handling involves complex legal procedures involving
specialist engineers and accountants. Property damage claims may be easier to quantify, but
claims related to the business interruption element of the loss can be very difficult to quantify
and approve.
147
If an organization has devised an adequate business continuity plan, the disruption to
the business and the size of insurance claims will be much reduced. In risk management
terms, relying entirely on insurance to remedy all losses is not enough. Every organization
should look to its business continuity plan to ensure that there are arrangements in place to
guarantee minimum disruption in the event of an adverse event. There are increasing concerns
about compliance issues in relation to insurance policies. Most countries have introduced
insurance premium taxes and these must be paid nationally where an organization has assets
in multiple countries. Sometimes, the requirement to pay the tax may be on a municipal or
regional basis, with payment to the local fire department. Compliance issues have also
extended to the production of insurance contracts before the policy period begins. The timely
issuance of insurance policies is often referred to as 'contract certainty'.
There are also compliance issues related to whether a policy is
accepted/approved/accepted in each country where the organization operates. This can
sometimes form a restriction on the operations of captive insurance companies. Certain
countries may not accept the validity of insurance policies written by unrecognized insurance
companies, including captive insurance companies.
17.6 INSURANCE COMPANY CAPTIVE:
A captive insurance company is an insurance company owned by an organization that
is not involved in insurance. The purpose of a captive insurance company is to provide
insurance capacity for the organization by using its internal financial resources to fund some
type of anticipated loss or insurance claim. The organization that owns the captive insurance
company is often referred to as the parent of the captive, or simply the parent organization.
Generally, captive insurance companies are domiciled in locations that have conducive
regulatory and accounting regimes that encourage the establishment of captive insurance
companies. Domiciles for captive insurance companies include Guernsey, Isle of Man,
Gibraltar, Malta, Luxembourg, Bermuda and Ireland. The nature of captive insurance
companies can vary widely. In theory, such companies can write insurance business directly
into other countries, although compliance issues around policies not being accepted may need
to be carefully considered. It is more common for captive insurance companies to operate as
reinsurers, providing insurance protection to the primary insurer designated by the
organization. This arrangement provides the organization's insurer, often referred to as the
fronting insurer, with a means of receiving reimbursement for certain types of claims up to an
agreed financial limit or risk retention level with the captive insurer.
A typical financial structure for a complex insurance program is illustrated in Figure
148
17.1. The organization will receive deductibles or excesses on different classes of insurance,
and these may differ by class of insurance. The captive insurance company then receives the
next level of loss up to an agreed limit for each individual loss and also up to an agreed limit
for a total loss or an excess cumulative over the policy year. The primary or front insurer will
then be liable for payment of that part of the larger loss that exceeds the captive insurer's
limit. The front insurer will be liable for payment of all losses after the cumulative total for
the captive has been breached. For statutory classes of insurance, the primary or front insurer
will be responsible for payment of the total claim. The front insurer will then recover money
from the captive insurer to the extent that the captive insurer is liable. This can pose a credit
risk to the fronting insurer, although this is usually addressed by the fronting insurer not
making payment until it has received funds from the captive insurer. Some captive insurance
companies accept business from third parties as well as providing insurance for the parent
company. A typical example of a captive insurance company providing third-party insurance
is an extended warranty insurance policy offered by a retailer of electrical goods. Another
example is that a travel agent may arrange for a captive to provide trip cancellation insurance
to customers. The customer will purchase a policy issued by a reputable insurance company,
but the insurance financing will be provided by the captive through reinsurance of the fronting
insurance. By arranging this arrangement, the travel agent should get additional income and
profits from its customers. The advantages of captive insurance companies are as follows:
•
Savings can be achieved in overall insurance costs as lower premiums are often set by
captive insurance companies.
•
Captive insurance companies can gain access to the reinsurance market, where
premium rates and risk capacity can be favorable.
•
By being exposed to insurance claim costs, greater risk awareness and greater concern
about loss control can be achieved.
•
Greater insurance coverage can be offered by captive insurance companies than is
available on the commercial market.
•
Certain tax benefits may be available from owning a captive insurance company,
although these have been reduced in recent times.
The disadvantages of captive insurance companies are as follows:
•
Captives will be exposed to insurance claims that would otherwise be paid by the
commercial insurance market.
•
The parent organization should allocate capital to ensure adequate solvency of the
captive insurance company.
149
•
When large losses are paid by captives, these losses are consolidated to the parent's
balance sheet and the organization eventually pays these losses.
•
Captive writing businesses in other regions may do so without authorization and this
may pose compliance difficulties.
•
Significant administrative costs, time, and effort can be involved in captive
management by parent headquarters personnel.
An example of how the advantages of a captive insurance company are viewed is provided by
the text box below. There are various domiciles suitable for captive insurance companies,
including Guernsey, Ireland and Malta.
Prisoner insurance company benefits:
Over the years, large companies have enjoyed many benefits from operating their own
captive insurance companies. Most were set up to provide coverage where insurance was not
available or prices were unreasonable. These insurance subsidiaries are often domiciled
offshore, primarily in Bermuda or the Cayman Islands. The risk management benefits of these
captives are primary, but their tax advantages are also important. A well-structured and
managed captive insurance company can provide the following benefits:
•
Tax deduction for holding companies for premiums paid to captives;
•
Opportunity to raise funds in the tax domicile;
•
Distribution to owners captives with rate tax income which is favorable;
•
Asset protection from business and personal creditor claims;
•
Reduction of insurance premiums paid by operating companies;
•
Access to lower cost reinsurance markets; and
•
Insuring risks that would otherwise be uninsurable.
BUSINESS CONTINUITY
18.1 BUSINESS CONTINUITY MANAGEMENT :
There has been considerable interest in the subjects of business continuity planning
(BCP) and disaster recovery planning (DRP) in recent times. Several standards have been
published around the world. This illustrates the importance of BCP as an integral part of risk
management. This heightened concern has been reinforced by the potential for major
150
disruptions posed by extreme weather events, terrorist attacks, civil emergencies and the fear
of pandemic flu.
In simple terms, BCP is how an organization prepares for future incidents that could
jeopardize its existence. The range of incidents that should be covered will include everything
from local events such as fires to regional disruptions such as earthquakes or national security
incidents and extend to international events such as terrorism and pandemics.
British Standard BS 31100:2011 defines BCP as:
[A holistic management process that identifies potential threats to the organization and the
impact on business operations that such threats, if realized, could have, and that provides a
framework for building organizational resilience with the capability for effective response to
protect key stakeholders' interests, reputation, brand, and value creation activities.
In the case of a serious incident such as loss of access to premises or failure of a major
part of an organization, it is important to have a well-defined, documented and tested disaster
recovery plan. Such plans inevitably focus on restoring access to IT systems and data, but also
typically include providing alternative premises (if required) and other facilities, as well as
establishing plans for communication with employees and other stakeholders such as
suppliers, customers and the media in times of crisis. Business continuity plans build on this
by establishing a long-term plan for 'business as usual' recovery immediately after a disaster.
A business continuity plan is an essential part of reducing the impact of a hazard incident. The
plan should include arrangements to mitigate the damage caused during the incident and
contain the costs of recovering from it.
A disaster recovery plan is a specialized component of a BCP. If computer systems
fail to operate properly or data becomes corrupted, the organization will need emergency
procedures to ensure that data can be recovered and/or ensure that the organization continues
to exist. There may also be a broader need for a specific plan to manage any crisis that may
result from an operational disaster. The key difference between disaster recovery and crisis
management plans is that Disaster recovery plans will be primarily concerned with actions to
restore the organization's infrastructure and crisis plans will also be concerned with external
stakeholders and actions to manage relevant stakeholder reactions and expectations.
For a printing company, IT systems are critical to the company's operations, as
computer systems process orders, schedule printing, and manage invoices. For such a
company, it may be appropriate to arrange for a mobile emergency computer facility to be
available in the event of a major IT failure. If this decision is taken, a contract should be made
151
with an outside company to deliver duplicate computers in trailers to the company's premises.
The duplicate computers would then be connected and operations would be controlled from
the duplicate computers in the trailer. The success of this arrangement will depend on the
availability of information from backup disks that must be produced at least once per day and
possibly several times per day.
There is much discussion about the nature of business continuity and disaster recovery
in terms of the type of controls they represent. HM Treasury in the UK considers these
controls to be corrective in nature, whereas the Scottish Government considers them to be
directive. In terms of loss control, disaster recovery plans can be seen primarily as damage
limitation controls, whereas business continuity controls are more concerned with cost
control. The discussion of whether disaster recovery and BCP should be considered as types
of control is, perhaps, not fundamentally important. The important issue is that disaster
recovery and business continuity plans are concerned with the circumstances under which the
event occurs or has occurred. To that extent, DRPs and BCPs can be considered a response
when the event occurs and they do not take into account how likely it is that the event will
occur.
An example in personal life is the use of seat belts in cars. Passengers in cars wear seat
belts in the event of a road accident. In many countries, seat belt use is mandatory and
passengers are not required to evaluate how likely they are to be involved in a road accident
when deciding whether to wear a seat belt for a particular trip. Many organizations are now of
the view that BCP should be viewed as having three components. The first response to any
major event is to activate the crisis management plan to ensure an appropriate response to the
crisis and, in particular, ensure that stakeholders are aware of the situation. This requires
effective communication with all stakeholders, so that reputational damage from the incident
can be minimized.
Second, the organization will then attempt to recover from the event by implementing
a disaster recovery plan. However, as the disaster recovery plan is being implemented, the
organization still needs to consider ongoing crisis management. Organizations should ensure
that the implementation of the disaster recovery plan is seen as a second, but sometimes
overlapping, stage in the response to the incident. In fact, in certain circumstances, a disaster
recovery plan will only be possible after the immediate crisis has been contained.
When the implementation of crisis management arrangements is well underway, and
disaster recovery plans have been activated, the organization will then be able to turn its
attention to the third and broader operational issue of business continuity. An example of this
three-stage approach is when there is a serious road traffic accident blocking a main road or
152
highway. The initial response of the emergency services will deal with a crisis that may
involve injury to people and, in certain circumstances, vehicle fires and/or other traffic
speeding towards the incident. When the crisis is quickly contained, the disaster recovery
phase can be implemented and this will include clearing damaged vehicles and/or repairing
road surfaces and crash barriers. It is only when these two phases have been completed that
the road can be reused, or the business continuity aspect, addressed.
If a road traffic accident involves a commercial vehicle or there are allegations that a
driver from an identified company caused the incident, the need for a crisis management
response will extend to the road haulage or transportation company involved in the incident.
Companies should activate their crisis management plans to demonstrate social responsibility
and to ensure minimal damage to their reputation. The road transport company may also wish
to take action during the crisis to support other stakeholders, including the families of drivers
who may have been injured in the incident. Figure 18.1 provides an illustration of disaster
recovery timelines and costs and this will be discussed later in this chapter. The need to
ensure adequate crisis management and effective communication with stakeholders covers the
entire period of disruption (from point A to point D) and possibly beyond.
18.2 BUSINESS CONTINUITY STANDARD :
The British Standards Institute publishes standards on business continuity management
(BCM). This was BS 25999 Part 1 (2006) 'Code of Practice - Business continuity
management' and was followed by BS 25999 Part 2 (2007) 'Business continuity management.
Specification'. It has now been replaced by the internationally accepted standard ISO 22301
(2012) 'Social Security - Business continuity management systems - Requirements'. ISO
22301 is similar to BS25999 and is written in what is becoming the standard structure for
management standards. It describes a plan-do-check-act (PDCA) approach similar to the plan-
implement-measure-learn (PIML) approach used throughout this book and described in detail
in Annex C. ISO 22301 identifies a BCP lifecycle that has the following five components
associated with a Business Continuity Management System (BCMS):
•
Identify important risk factors that are already affecting the organization;
•
understand the needs and obligations of the organization;
•
create, implement, and maintain your BCMS;
•
measures the overall ability to manage disruptive incidents;
•
ensure conformity with the stated business continuity policy.
153
Figure 18.2 provides a model for BCP that is consistent with ISO 22301. Table
18.1 provides a checklist of the main activities involved in BCP. Having a business continuity
plan is recognized as important by most large organizations. Indeed, many governments take
an active role in encouraging businesses (especially small businesses) to develop and
implement adequate business continuity plans.
The main change introduced by ISO 22301 compared to BS 25999 is that ISO 22301
is the first standard to be written using the new high-level structure, which is common to all
new management system standards. This will make integration easy when implementing more
than one management system. The phrase 'preventive measures' has been replaced with
'measures to address risks and opportunities'. ISO 22301 emphasizes more on goal setting,
performance monitoring, and metrics...aligning business continuity with executive
management's strategic thinking.
A key principle suitable for a successful BCP is that the plan must:
•
Comprehensive;
•
cost-effective;
•
practical;
•
effective;
•
maintained;
•
practice.
It is important that the BCP should cover all operations and premises of the organization to
ensure that the plan can facilitate a complete resumption of normal business operations. It is
also important that the plan is cost-effective and proportionate to the risk exposure.
The BCP should be practical and easily understood by staff and others involved in
implementing the plan. Overall, the BCP should be effective as it will recognize the urgency
of specific business components or functions and identify responsibilities to ensure timely
resumption of normal work. To guarantee that the BCP will be effective, it needs to be tested,
maintained and practiced. All staff members must be familiar with the intended operation of
the plan and training needs to be provided. Lessons learned during testing and practice of the
business continuity plan should be incorporated into the plan so that it becomes more
effective. The need for training is emphasized in Figure 18.2 and Table 18.1.
Testing business continuity plans is an important component of ensuring that they will
be appropriate and effective. However, plan testing can be time-consuming and, in some
circumstances, disruptive and expensive. Even the simple example of a fire evacuation drill of
154
a building illustrates that testing procedures will inevitably disrupt normal routine operations.
18.3 SUCCESSFUL BUSINESS CONTINUITY :
The first stage in successful BCP, DRP, and crisis management is to gain a thorough
understanding of the organization and its interactions, both internal and external. Part of
gaining this understanding is to identify the organization's objectives and key dependencies. It
is important to understand the critical functions within the organization and identify key
resources. Determining the BCP strategy will require identifying risks to the business and
decisions about how likely those risks are to materialize. It is also important to understand the
impact of the risks to the business. This assessment should then be used to prioritize risk
handling and to agree on the likelihood and impact of the risks materializing.
Developing and implementing appropriate BCPs and controls for each identified risk
will require a decision on the appropriate risk response. The range of available risk responses
has been discussed as the 4Ts of hazard risk management. In relation to each major risk, a
decision must be made whether to tolerate, address, transfer, or terminate the risk. Building
and embedding a business continuity management (BCM) culture will require good
communication throughout the organization. All stakeholders need to be involved and
engaged in business continuity activities and need to understand the reasons for developing
BCP and DRP. The critical role of all employees in avoiding incidents that could result in
major disruptions must be emphasized.
When developing a BCP, mission-critical activities must be identified, along with key
roles and responsibilities. These can be produced in the form of clear instructions and
checklists. It is important to train, maintain and review the BCP by creating a program to test
the plan, review and amend it if necessary, and train staff to improve understanding of the
plan. BCPs and DRPs should be reviewed at least annually, as well as after plan testing. Also,
if an incident occurs, lessons learned should be incorporated into the plan. The 2009 flu
pandemic provides an example of the importance of BCPs. Advice and guidance was created
for companies and individuals in many countries around the world. The box below provides a
summary of the key points provided in these guides and the practical implications of the flu
pandemic for business continuity. Many governments accept that a pandemic is one of the
most disruptive circumstances that can affect a country.
Pandemic flu:
A pandemic contingency plan for an organization should aim to ensure continuity of
essential operations during an extended period of high levels of illness in the workforce,
155
suppliers and customers. It should ensure that employees are not exposed to a high risk of
infection at their workplace and aim to resume operations quickly and competitively as soon
as the pandemic cycle ends. Critical business processes can be protected by allocating
additional backup personnel, diversifying activities across multiple locations, and maximizing
home-based work.
Additional investment in workplace backup capacity may be required, training more
personnel to take over critical roles, and increasing IT capabilities. Plans should anticipate that
suppliers, equipment providers and support companies will be unable to function for some
time, and supplies of essential supplies should be established. Telecommunications
infrastructure may not be able to meet greatly increased demand.
During a pandemic, employees are likely to get infected from their families, children
or contacts outside the workplace. Social contacts in the workplace then spread the infection
through the workforce. Low-contact work environment practices that minimize the risk of
spreading infection include a well-informed workforce, fewer face-to-face encounters, strict
hygiene, and frequent biological cleaning of common area surfaces. It may eventually be
necessary to close offices to prevent the spread of the deadly virus. Staff recovering from
pandemic influenza cases are unlikely to be infected again and no longer infect others.
Recovered and vaccinated staff can return to work. As the pandemic subsides, resuming
operations quickly and efficiently can be a matter of competition.
Figure 18.1 on page 209 provides a practical example of a DRP and BCP. The
example is based on a broadcasting organization experiencing a major disruption to its main
broadcasting facility at point A on the timeline. The disaster recovery plan will ensure that
broadcasts are resumed at short notice, but these may only be emergency broadcasts. The
emergency broadcast starts from point B on the timeline. Note Figure 18.1 does not include
the cost of repairing or restoring facilities that have been damaged. After a short emergency
broadcast, the organization will be able to start a full broadcast of its normal services from an
alternative location. For example, the broadcaster may move its London broadcast facilities to
studios in Manchester. To do this, however, the Manchester capability would be lost.
Therefore, Image
18.1 shows that the level of service is much better at point C which is the move to
Manchester, but as the Manchester broadcast facility has been lost, the level of service is not
up to the previous level.
There will be increased operating costs from the time of the incident. There will be
costs associated with implementing the disaster recovery plan and further costs associated
with emergency broadcasting and then moving to Manchester. During the period of
156
broadcasting from Manchester, increased costs will occur through temporary accommodation
for staff and upgrades to technical facilities. Finally, from point D on the timeline, the
facilities in London have been repaired and full recovery has been achieved. Figure 18.1
represents a typical set of circumstances for an organization experiencing a major incident.
The level of service disruption will continue for some time and increased operating costs will
be involved. Insurance may be available for the increased operating costs, provided it does not
exceed the indemnity period (duration of disruption) stated in the insurance policy. It is
unlikely that insurance cover will be available to cover losses associated with reduced service
levels from the time the incident occurs until the point of full restoration, unless specific types
of costs or losses are identified and insured.
18.4 BUSINESS IMPACT ANALYSIS (BIA):
An important part of ensuring that adequate business continuity plans and disaster
recovery plans are in place is the completion of a business impact analysis (BIA). The BIA
will identify the critical nature of each business function by assessing the impact of a
disruption to those activities. This information will be required to identify appropriate
continuity strategies for each function. A BIA is similar to a risk assessment conducted as part
of the overall risk management process. However, an important difference from a BCP is that
the emphasis of the BIA is the identification of the relative importance and criticality of each
function, rather than identifying events that could damage a particular function.
Therefore, risk assessment and BIA are interrelated and can be conducted together.
Risk assessment will help in identifying risks that may threaten the achievement of business
continuity objectives. For television companies, broadcast continuity in excess of 99.9 percent
is likely to be a target and may even be a requirement imposed by licensing authorities. Both
risk assessment and BIA require a structured and systematic approach.
Business impact analysis has three clear objectives, as follows:
1. Identify mission-critical activities and the recovery time required in the event of a
disruption. This identification activity will establish the timeframe in which critical
functions must resume after a disruptive event.
2. Establish the potential impact and resource requirements for recovery within agreed
timescales. Business requirements for recovery of critical functions must be
established.
3. Determine whether the possible impact is in accordance with the organization's risk
appetite as a basis for a business continuity strategy. Technical requirements for the
restoration of critical functions also need to be established.
157
Business impact analysis can be based on the sources of disruption described as the 4Ps in
Table 3.2. Once the sources of disruption facing an organization's operations are identified,
conducting a BIA will become simpler. However, the focus of the business impact analysis
will most likely be based on the processes within the organization and how these can be
disrupted. This seems particularly relevant as the continuity of business processes protects the
interests of key stakeholders, reputation, brand, and value creation activities.
18.5 BUSINESS CONTINUITY AND ERM:
There is a clear relationship between BCP and enterprise risk management (ERM).
ERM looks at the risks facing the entire organization and BCP takes the approach that
business continuity arrangements must be in place. The BCP approach is to look at continuity
of operations across the organization. Ensuring continuity is clearly part of the ERM
approach. It should therefore be considered that BCP is part of ERM, but not the whole ERM
activity. Nevertheless, there are strong similarities in the approaches and business continuity
and disaster recovery activities should be carried out in the context of broader ERM
initiatives, as appropriate. Both approaches seek to achieve effective and efficient continuity
of core business processes. The foundation of ERM is that stakeholder expectations and the
core organizational processes that deliver those expectations are the focus of the risk
assessment process. The intent of ERM is to ensure that core processes are maintained.
The continuity of core business processes is also the basis of BCP. The difference in
emphasis is that ERM seeks to identify risks that may affect the effectiveness and efficiency
of core processes. BCP seeks to identify critical business functions that need to be maintained
to achieve business continuity. The approaches are complementary and there are many
similarities between this BCP and ERM style. Page 53 identifying availability constant
prescription drugs as a core process for pharmaceutical companies. It is possible to take an
ERM approach to this core process and identify risks that could disrupt the process. In taking
this risk management approach, the pharmaceutical company will combine ERM and BCP
approaches in a way that clearly focuses on delivering stakeholder expectations.
Scenario planning is a critical component of business continuity and has broader
implications for the successful implementation of enterprise risk management. For financial
institutions, scenario planning involves evaluating the balance sheet capital that would be
required by financial institutions in the event of difficulties similar to the 2007/08 global
financial crisis. This type of scenario planning for financial institutions is commonly referred
to as 'stress testing' and is often a specific requirement of banking regulators.
Scenario planning needs to consider the external and internal context of the
158
organization, as well as business impact analysis. Also, there is a strong link between scenario
planning and crisis management. Disaster recovery planning and business continuity planning
can account for foreseeable incidents, but it is more difficult to forecast every crisis that may
arise. Therefore, a useful aspect of scenario planning is to anticipate highly unlikely
circumstances and then challenge senior management to develop a successful response.
Lessons from scenario planning can then be used to take actions that will increase the
resilience of the organization. The page above the text box describes a scenario planning
approach supported by the UK Government Cabinet Office, in relation to national
infrastructure disruptions, such as electricity supply networks.
The Worst Case Scenario That Makes Sense:
Event standards can be set to establish a level of resilience to extreme events so that a
network or system should be able to continue operating without widespread loss or disruption
to critical services. Describing reasonable worst-case scenarios for hazards will allow
infrastructure owners and operators to identify and assess their resilience, and consider any
gaps in asset or network resilience between event and design and actual or current service
standards.
The ability and capability to manage and respond to events greater than this plausible
worst-case scenario depends on the resilience of their generic organization. Alongside this,
infrastructure owners should consider, in their business continuity plans, the speed at which
they expect to be able to restore services if supply is interrupted for any reason, including
events that are not specifically detailed or that are more serious or extreme than those covered
by the plausible worst-case scenario.
18.6 STATE OF EMERGENCY CIVIL:
In many countries, there is an obligation placed on local governments to ensure the
continuity of local businesses in the event of a major civil emergency. Emergencies can be
triggered by natural disasters such as floods or earthquakes. Alternatively, they can be caused
by terrorism, civil unrest or epidemics/pandemics. The ISO 22300 series of standards deals
with community resilience and the growing importance of this series of standards is also
considered in Chapter 9. Many civil authorities publish guidance for businesses to help them
with their BCPs. For example, the US government provides valuable information on its
website. Also, some trade associations and small business associations offer practical
guidance on BCP, including appropriate actions in the case of a civil emergency.
Most local authorities have a legal responsibility to respond to civil emergencies.
159
Factories and warehouses may have equipment and facilities that could be useful in the event
of a civil emergency. Similarly, retail stores will have food and other items that may be
required for distribution as emergency supplies. Products that may be useful in a civil
emergency would include food, bottled water, clothing and blankets. In addition, schools and
other civilian buildings may be required as accommodation in the event of a civil emergency,
such as the wide-area flooding that is becoming more frequent in some European countries.
Encouraging organizations to make arrangements to ensure business continuity will
benefit local authorities responsible for civil emergencies, as there will be fewer problems and
issues for them to account for in times of emergency. The box below provides a summary of
typical advice given by municipal authorities to small businesses in the local area.
Secure your business:
Thoroughly assessing the disasters that could threaten your company will give you a
clear picture of the most important business areas to secure. Typically, these will be the areas
on which your business depends the most, and which are exposed to the greatest level of risk.
This is the most important part of your plan. Obviously, your premises are critical to your
business to such an extent that you might take them for granted. But you must consider the
long-term impact that damage or destruction of your premises could have on your business.
The same goes for business-critical machinery, plant and equipment.