1 / 22100%
RISK MANAGEMENT PRINCIPLES
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 6
Introduction:
Every activity carries a risk of success or failure. Risk is a combination of the likelihood and
severity of an event. The greater the potential for an event to occur and the greater the impact it
has, the event is considered to contain high risk. According to Hanafi (2006), Risk is a danger,
result or consequence that can occur as a result of an ongoing or ongoing or future process.
According to Airmic (2010) risk is the effect of target uncertainty, the effect of uncertainty can
be positive or negative, in other words risk is the possibility of situations or circumstances that
can threaten the achievement of the goals and objectives of an organization or individual. The
impact of the risks posed is very large, so risk management is an important aspect that must be
considered by the company. Its application can help companies in obtaining protection from
various risks in achieving business goals. According to Bramantyo (2008), risk management is a
structured and systematic process of identifying, measuring, mapping, developing alternatives
for handling risk, and monitor and control risk handling. Risk Management is a risk management
that aims to increase the value of the company in facing organizational problems
comprehensively (Hanafi, 2009). Risk management is defined as the process of identification,
measurement and financial control of a risk that threatens the assets and income of a company or
project that can cause damage or loss to the company (Smith, 1990). According to Bramantyo
(2008), risk management is a structured and systematic process to identify, measure, map,
develop alternative risk treatments, and monitor and control risk treatment.
Risk Management Principles:
The existence of risks in program activities must be anticipated by approaching the process of
identification, analysis, and management of consequences by the organization. Risk management
is an important part because with risk management, the organization is able to take risks
appropriately so as to minimize losses. Risk management can be more effective, so
companies/organizations must adhere to the principles of risk management.
1.
Risk Management Principles According to Leo J. Susilo, Victof Riwu Kaho ISO 31000
Risk management is part of management's responsibility and is an integral part of the
organization's normal processes as well as part of all project and change management
processes. Risk management is not a stand-alone activity that separate from the main
activities and processes in the organization.
a.
Risk Management Creates and Protects Value.
Risk management contributes by increasing the likelihood of achieving company goals
in real terms. It also provides improvements in safety, health, regulatory compliance,
environmental protection, public perception, product quality, reputation, corporate
governance, efficiency and operations.
b.
Risk Management is an Integrated Part of All Organization's Business Process.
Risk management is part of management responsibility and is an integral part of
organizational, project, and change management processes. Risk management is not an
activity that stands alone and is separate from the activities and processes of the
organization in achieving goals.
c.
Risk Management is Part of the Decision-Making Process
Risk management helps decision-makers to make decisions on the basis of available
options with as much information as possible.
d.
Risk Management Specifically Addresses Aspects of Uncertainty
Risk management specifically addresses the aspect of uncertainty in the decision-
making process. Management estimate what the nature of uncertainty is and how it
should be handled.
e.
Systematic, Structured, and Timely Risk Management
The systematic, structured and timely nature of this risk management approach
contributes to the efficiency and consistency of risk management. As such, the results
can be compared to provide results and improvements.
f.
Risk Management Based on Best Available Information
Experience, observation, estimates, expert judgment and other available data. However,
it must be realized that all of this information has limitations that must be considered in
the decision-making process, both in modeling risk and the differences of opinion that
may occur among experts.
g.
Risk Management is Tailored to the User
Risk management should be aligned with the internal and external context of the
organization, as well as the organization's goals and the risk profile it faces.
h.
Risk Management Considers Human and Cultural Factors
The implementation of risk management must recognize the perceived organizational
capabilities and objectives of each individual within and outside the organization,
especially those that support or hinder the achievement of the organization.
i.
Risk Management Should Be Transparent and Inclusive
To ensure that risk management remains relevant and up-to-date, stakeholders and
decision-makers at all levels of the organization must be effectively involved. This
involvement should also allow stakeholders to be well represented and have the
opportunity to express their opinions and interests, especially in formulating risk
criteria.
j.
Risk Management is Dynamic, Recurring, and Responsive to Change
As new events occur, both inside and outside the organization, the risk management
context and existing understanding also changes. Risk management is constantly
watching, sensing, and responding to change.
k.
Risk Management Should Facilitate Continuous Improvement of the Organization
The organization's management should continuously develop and implement
improvements to the risk management strategy and increase the maturity of risk
management implementation, in line with other aspects of the organization.
2.
Risk Management Principles According to ISO 31000: 2018
Referring to ISO 31000:2018, in order for risk management to be more effective,
companies/organizations must adhere to the principles of risk management. The following
are the principles of risk management:
a.
Integrated
Risk management is an integral part of all organizational activities. It makes perfect
sense to make it a requirement in order to support goal achievement, improve
performance, and drive innovation.
b.
Structured and Comprehensive
Structured and comprehensive risk management contributes to consistent and
comparable results. This principle is not limited to the risks within the organization, but
also includes the risks that the organization brings in contact with our organization.
c.
Customizable
The risk management framework and process can be adjusted in proportion to the
external and internal context of the organization in relation to its objectives. The needs
of the organization and the risks that the organization must manage to achieve its goals
must be adjusted both now and in the future.
d.
Inclusive
Appropriate and well-timed stakeholder engagement allows their knowledge, views and
perceptions to be considered. This results in increased awareness and information
management. This engagement is necessary so that they can contribute to the
communication and consultation, monitoring and review processes.
e.
Dynamic
Emerging risks can change, and disappear following the organization's changing
external and internal context. Risk management anticipates, detects, recognizes and
responds to such changes and events in an appropriate and timely manner.
f.
Good Information Available
All data for risk management is based on previous and current information, as well as
future expectations. Good information should be timely, clear, and available to provide
to relevant stakeholders. The simplest of these principles is how risk management can
possibly be aimed at creating value if we are in an organizational context unable to
explain what value is to be achieved.
g.
Human and Cultural Factors
Human behavior and culture are influential at every level of risk management. Both
people and culture are interrelated and equally important factors. Organizational culture
or risk culture is important because it will relate to the daily implementation of
organizational tasks. Of course, the role of the leadership here is also very important
because it must set an example and also motivate all components in the organization.
h.
Continuous Improvement
This principle increases the effectiveness of risk management. This continuous
improvement becomes a continuous cycle using the Plan Do Check Action method.
3.
Risk Management Principles According to Jody Moses
Risk management aims to minimize harm to ourselves and others in various situations. Some
risk management principles that must be considered by companies in carrying out their
organizational activities include;
a.
Risk Identification
The process of systematically and continuously identifying possible risks or losses to
the company's assets, liabilities, and personnel. This risk identification process is
perhaps the most important process, as it is from this process that all risks that exist or
may occur on a project, must be identified.
b.
Risk Analysis
Collect data and consider the risks that will occur, both small and large risks, as well as
prepare assistance for risk management. Analysis Risk analysis includes determining
the source of risk, likelihood and impact of the risk that will occur.
c.
Risk Control
Efforts to implement appropriate controls to obtain a balance in terms of security,
usability, and financing of a company.
d.
Risk Financing
A way to cover financial losses that cannot be prevented by the risk control techniques
applied.
e.
Claims Management
Managing losses incurred. When a loss occurs, a claim can be filed to recover damages
4.
Risk Management Principles According to the Australian Institute of project Management
Building a good risk management plan will help protect the company's resources, reputation,
and employees. In addition, every organization communicates risk differently, and has its
own internal culture and risk management protocols. The risk management process should
integrate internal and external contexts when planning for risk. All companies and
organizations manage risk slightly differently. However, there are 7 key risk management
principles that can be used when looking to integrate a risk management plan into a
company, including;
a.
Ensure Risks are Identified Early
Identify potential risk causes and design preventive and response measures should they
occur. Once risks are identified and sourced, they need to be measured.
b.
Factors in Organizational Goals and Objectives
Each organization will have different desired outcomes and priorities and these should
be integrated into the risk management plan. The risk strategy should be consistent with
the overall goals and culture of the organization.
c.
Manage Risk in Context
Context very important when considering risk, as each organization will have a different
level of tolerance for risk. Various factors (political, technological, legal, social, etc.)
will affect organizations and industries differently. In addition, each organization
communicates risk differently, and has its own internal culture and risk management
protocols. The risk management process should integrate internal and external contexts
when planning for risk
d.
Involving Position Holders
Throughout the risk management process, stakeholders should be involved in the
decision-making process. By utilizing stakeholders for risk planning, the company will
identify and gain insight into potential risks that may not have been considered.
e.
Responsibilities and Roles
Risk management may be owned by a single individual such as a project manager or
change manager, it should be operated by transparency and visibility. Everyone should
know the role they play in reducing risk and responsibilities should be clear and
inclusive throughout the risk management process. The more people who participate,
the more risks can be managed creatively and effectively. Every team member should
be dynamic, flexible and responsive. Everyone should be empowered to deal with risks
at their own level.
f.
Create a Risk Review Cycle
After identifying risks and creating a risk management plan or strategy, it is important
not to have a set and forget mentality. During each step in the process, all risks should
be evaluated and any interventions or countermeasures should be applied if necessary as
well as communicating any changes with stakeholders in a timely manner.
g.
Strive for Continuous Improvement
Seek to adapt to the way the company manages risk and take this learning forward to
manage risk within the company.
5.
Risk Management Principles According to PMBOK
Various organizations have established principles for risk management. There are principles
of risk management by the International standardization Organization and by the Project
Management Body of Knowledge. The Project Management Body of Knowledge (PMBOK)
has laid down 12 principles of risk management, namely;
a.
Organizational Context
Every organization is affected to varying degrees by various factors in its environment
(Political, Social, Legal, and Technological, Social, etc). For example, an organization
may be immune to changes in import duties whereas a different organization operating
in the same industry and environment may face severe risks. There are also marked
differences in communication channels, internal culture and risk management
procedures. Therefore, risk management should be able to add value and be an integral
part of the organization's processes.
b.
Involvement of Stakeholders
The risk management process should involve stakeholders at every decision-making
step. They must remain aware of even the smallest decisions made. Further, it is in the
interest of the organization to understand the role that stakeholders can play at each
step.
c.
Organizational Objectives
When dealing with risk, it is important to keep the organization's goals in mind. The risk
management process must explicitly address uncertainty. This requires being systematic
and structured and keeping the big picture in mind.
d.
Reporting
In risk management communication is key. The authenticity of information must be
ensured. Decisions must be made based on information best available and there should
be transparency and visibility regarding the same.
e.
Roles and Responsibilities
Risk Management should be transparent and inclusive. It should take into account the
human factor and ensure that each knows his or her role at each stage of the risk
management process.
f.
Support Structure
Structure supporting underscores the importance of the risk management team. Team
members should be dynamic, diligent and responsive to change. Each member must
understand his or her interventions at each stage of the project management lifecycle.
g.
Early Warning Indicators
Monitor for early signs of risks that translate into active issues. This is achieved through
constant communication by one and all at every level. It is also important to activate and
empower each to deal with threats at their level.
h.
Early Warning Indicators
Continuously evaluate inputs at each step of the risk management process - Identify,
assess, respond and review. Observations are very different in each cycle. Identify
reasonable interventions and remove unnecessary ones.
i.
Supportive Culture
Do brainstorming and activate a culture of questioning, discussion. This will motivate
people to participate more.
j.
Continual Improvement
Be able to improve and enhance your risk management strategies and tactics. Use your
learning to access the way you view and manage sustainable risk.
RISK MANAGEMENT FRAMEWORK
Definition of Risk Management Framework:
In carrying out risk management activities, every company or other business institution has a
basis of reference as the basis for implementation, commonly referred to as a risk management
framework. The purpose of the risk management framework is so that the company can manage
risks more effectively which is a reference in preparing strategic plans, making decisions and
controlling risks in activities carried out by the company.
A risk management framework is defined as a set of components that provide a foundation for
designing, implementing, evaluating, and improving in an integrated manner based on strong
leadership and commitment.
Leadership and commitment serve as the foundation, while the surrounding cycles of integration,
design, implementation, evaluation and improvement will interconnect to achieve organizational
goals tailored to the needs of the organization. The following are the components of a risk
management framework;
The framework is based on the principles of risk management by implementing the following
elements of risk management;
1.
Integrated
Risk management is the integrated activities of parts of an organization.
2.
Structured and comprehensive
A structured and comprehensive approach to risk management will contribute to consistent
and comparable results.
3.
Customized
The risk management framework and process are tailored to the organization's context, both
internal and external, in accordance with the organization's objectives.
4.
Inclusive
Customize and involve stakeholders according to their knowledge, views and perceptions.
This will result in awareness and informed risk management.
5.
Dynamic
Risks can arise, change or disappear in accordance with changes in the context of the
organization both internally and externally. Risk management anticipates, detects, accepts
and responds to changes and events appropriately and in a timely manner.
6.
Best available information
Risk management inputs are based on historical and current information, as well as future
expectations. Risk management explicitly addresses limitations and uncertainties associated
with information and expectations. Information should be immediate, clear and available to
relevant stakeholders.
7.
Human and cultural factors
Human behavior and culture significantly affect all aspects of risk management at every
level and stage.
8.
Continual improvement
Risk management always makes continuous improvements through learning and experience.
Components of the Risk Management Framework
In achieving its goals, a company faces many challenges and fulfills its role in society and
economic development. The conditions of economic instability and disruption, the information
and communication technology revolution, and the development of the knowledge economy will
create risks that were previously unforeseen. Companies or organizations need leaders who are
reliable in facing every challenge that comes.
In order to achieve risk management, an organization needs to develop what is called a risk-
aware culture, this is in order to be ready for all risks, where strong leadership becomes a key
factor Important. Many organizations claim to incorporate risk management into the running of
their organizations, but this should not be just a statement or a slogan without any real action.
We need to integrate risk management into organizational governance, organizational activities
and decision-making processes. Therefore, top leadership support is essential. In the risk
management framework, leadership and commitment are at the top, without which the rest of the
framework becomes difficult to execute.
Leadership and Commitment:
Leadership and Commitment are central or foundational to the risk management framework.
Leadership is an ability or power within a person to influence others in accordance with
organizational goals. Commitment is a form of obligation that binds a person to something,
either Leadership is described by company leaders or top management who have the
responsibility and accountability to commit and be bound in carrying out risk management. In
other words, risk management is carried out through policies, authority, duties, responsibilities
and accountability at the organizational level in accordance with organizational goals.
Leadership is therefore crucial to the successful implementation of risk management, as is the
support of commitment (an agreement to carry out in earnest) to the decisions that have been
taken and agreed upon.
Leadership and commitment at the top management of an entity/organization should be
manifested in the following ways;
1.
Establish and authorize risk management policies;
2.
Ensure that organizational culture and risk management policies are aligned with
organizational performance indicators;
3.
Align risk management objectives with organizational goals and strategies;
4.
Ensure regulatory and legal compliance;
5.
Establish accountability and responsibility at appropriate levels within the organization;
6.
Ensure that necessary resources are allocated to risk management;
7.
Communicating benefits management benefits to all stakeholders; and
8.
Ensure that the framework for risk management always remains viable.
Risk Management Integration:
Risk management includes an element of integration, which means the merging or blending of
different things into a unified whole. Integration in risk management means that risk
management is integrated as a unit in the company or organization system. The framework must
be based on the principle of integration, which means that risk management becomes an
inseparable part or is integrated into the governance, leadership and commitment of the
company.
With the integration between every part of the company's system is important because it will be
interrelated in every activity concerning risk management, because one part will be able to affect
other parts because it is part of the process implemented in the company or other service fields.
Risk management must be integrated into all organizational processes and practices in a way that
is relevant, effective, and efficient so that it cannot be separated.
In action or activity, the risk management process should be part and parcel of the organization's
processes. Risk management is integrated into the company's policy development, business and
strategic planning and review, and change management processes.
In the implementation of risk management principles, it can be realized that risk management is
an integrated part of all processes in the organization and wherever possible is also part of
decision making.
Therefore, an organization-wide risk management plan should be in place to ensure that risk
management policies are in place implemented and that risk management is integrated into all
organizational practices and processes.
In planning Risk management can be integrated into strategic planning. Risk management
should be integrated during the annual planning process or also be considered during budget
preparation, where the budget also considers the company's risk mitigation that will be carried
out. In addition, risk reviews can also be used in various considerations related to decision
making in the organization, or in the performance appraisal process.
Risk Management Design:
In a risk management framework, design includes several things, namely understanding the
organization and its context, affirming risk management commitment, establishing roles,
authorities, responsibilities and accountabilities, allocating resources, and preparing for
communication and consultation.
Organizational understanding is an important part of designing a framework for risk
management, the level of understanding in the organization significantly affects the
implementation of risk management in both internal and external contexts.
The results of understanding and evaluating the internal and external context will then be taken
into consideration in creating a risk management framework in an organization, and also for
establishing a context. Establishing a context is defining the external and internal parameters that
are taken into account when determining the scope of risk management and management and risk
criteria in developing risk management policies.
Based on the understanding and evaluation of the existing organization, the external context of
the organization is then evaluated, which may include, but is not limited to:
1.
Cultural and social, political, legal, regulatory, financial, technological, economic, natural
and competitive environments, whether international, national, regional or local;
2.
Key drivers and trends that have an impact on the organization's goals; and related
relationships, perceptions and values of external stakeholders.
Implementation of Risk Management:
After the risk management design is created and established, the next step is implementation or
execution within the risk management framework. If the risk management design is implemented
well, then the risk management framework can ensure the risk management process has become
part of all company or organization activities.
Where the discussion of this risk management process will be further elaborated in the next
chapter. In general, in implementing the framework, the organization should:
1.
Define the strategy and timing for implementing the framework;
2.
Apply risk management policies and processes to organizational processes;
3.
Comply with laws and regulations;
4.
Ensure that decision-making, including goal development and setting, is aligned with the
benefits of the outputs of the risk management process;
5.
Organize information and training sessions; and communicate and consult with stakeholders
to ensure that the risk management framework remains viable.
Risk management should be implemented by ensuring that risk management processes are
applied through a risk management plan at all relevant levels and functions of the organization as
part of the organization's practices and processes. It is also advisable to implement change
management practices in the implementation of risk management. This is because the
implementation of risk management may have an impact on the number of internal changes that
must occur. The change management in question is an approach to change individuals, teams,
and organizations to the desired future condition45, where the desired condition has been
established outlined in the form of goals to be achieved. With good change management, in
essence, it can also reduce future risks arising from poor change management from the results of
risk management.
Risk Management Evaluation:
Evaluation is a process to measure or assess whether a program or activity is implemented in
accordance with the plan. In the risk management framework, evaluation is carried out to
measure the risk management framework against objectives, implementation plans, indicators
and expected behavior in accordance with the objectives of the organization or company. The
evaluation is carried out periodically so that if there are obstacles that arise, they can be
overcome immediately by monitoring and reviewing as follows:
Monitoring and review are carried out to determine whether assumptions and decisions remain
valid. Where the techniques used include maintaining an effective risk management framework
as well as in each step of the risk management process. In the monitoring process activities
involve regular survey data on actual performance and comparison with expected or required
performance. This involves ongoing inspection or investigation, surveillance, critical
observation, or status determination in order to identify changes from required or expected
performance levels, as well as changes in context. Review, on the other hand, involves periodic
or unannounced checks on the current situation, against changes in the environment, industry
practices, or organizational practices.
This is an activity undertaken to determine the suitability, adequacy and effectiveness of the
framework and processes to achieve the stated objectives. In the review process, the outputs of
monitoring activities are considered. This differs from the definition of an audit, where an audit
is a process of evidence-based, systematic review against predetermined criteria. While every
audit is a review, not every review is an audit. Together, monitoring and review are about
providing assurance that risk management performance is as expected, whether that performance
can be improved and whether changes that have occurred require adjustment or revision of either
the framework or some aspect of the process. Monitoring and review aim to provide reasonable
assurance that risks are being adequately managed, to identify deficiencies in risk management,
and to identify opportunities to improve risk management. Both are necessary in order to ensure
the organization maintains a current understanding of the risks associated with its risk criteria,
consistent with its attitude to risk. Both require an integrated systematic approach to the
organization's general management system.
Monitoring and review activities and actions taken in response to findings are often characterized
as an assurance system because they have the potential to detect and correct weaknesses before
unintended effects occur or to build confidence that risks still meet organizational criteria.
It can also be used to provide internal and external stakeholders with reasonable assurance that
risks are being managed effectively.
As factors in the internal and external context change, so will risks. Similarly, monitoring the
external context can alert the organization to changes that may provide an opportunity for
improved performance or a new activity. By maintaining vigilance to change, to performance, to
nonconformities, and to near events, the organization will be able to identify opportunities for
improvement of the risk management framework and the overall performance of the
organization.
A comprehensive program to monitor and record risk performance indicators aligned with
organizational performance indicators should be in place. The program should provide early
warning of unexpected trends that may require preventive action and intervention. A single
monitoring or review activity may be directed at an individual risk or a number of interrelated
risks. It may focus on the risk or on the controls aimed at that risk.
In order to ensure that risk management is effective and continues to support organizational
performance, the organization should:
1.
Measure risk management performance against various indicators, which are regularly
reviewed for appropriateness;
2.
Periodically measure progress against, and deviations from, the risk management plan;
3.
Periodically review whether the risk management framework, policies and plans are still
appropriate, based on the external and internal context of the organization;
4.
Reporting on risks, the progress of the risk management plan, and the extent to which risk
management policies are being followed; and
5.
Review the effectiveness of the risk management framework.
Risk Management Improvement:
The implementation of a risk management framework also involves improving and then
adapting. Thus, the company must be able to see changes occur both in the internal and external
environment. Then make improvements according to organizational goals.
Based on the results of the monitoring and review, decisions should be made on how the risk
management framework, policies and plans can be improved. These decisions should lead to
improvements in the organization's risk management and risk management culture. If the
organization's existing management practices and processes already include components of risk
management, or if the organization has adopted a formal risk management process for some
types of risks or situations, it should be critically assessed and reviewed in order to determine its
effectiveness and adequacy.
There are several attributes that can be given real indicators to be used to help organizations in
performance measurement for continuous improvement. These attributes are as follows:
1.
Continuous improvement, the focus of continuous improvement in risk management is
through setting organizational performance objectives, measuring organizational
performance, reviewing organizational performance and further modifying processes,
systems, resources, capabilities and skills. For this purpose, explicit performance objectives
need to be published, measured, communicated, and reviewed periodically. Subsequently,
revisions are made to update the processes and performance objectives for the next period by
setting better performance objectives. Risk management performance appraisal is also an
integrated part of the organization's overall performance appraisal system as well as a
measurement system for each department and individual.
2.
Full accountability for risk requires that a designated individual accepts full accountability
for risk control and has a duty to perform risk treatment, the individual also has the
appropriate skills, and has sufficient resources to examine controls, monitor risks, improve
controls and communicate effectively with external and internal stakeholders about risks and
their management. The definition of risk management roles, accountabilities and
responsibilities should be part of the organization's overall induction program. So that the
organization can ensure that accountable individuals are adequately equipped to fulfill their
roles and responsibilities roles and provide them with the authority, time, training, resources
and skills to properly carry out their accountabilities.
3.
Application of risk management in every decision, every decision in the organization
involves explicit consideration of risk and application of risk management at the appropriate
level, this applies to any level of importance and significance. A record of the meeting and a
record of the decision are provided to demonstrate that an explicit discussion of risk has
taken place.
4.
Continuous communication, strengthened risk management strengthened has continuous
communication with external and internal stakeholders, including comprehensive and
regular reporting on risk management performance, as part of good governance.
Communication is appropriately viewed as a two-way process, such that decisions about the
level of a risk and the need for risk treatment can be made on an informed basis.
Comprehensive and regular external and internal reporting, both on significant risks and on
risk management performance will contribute substantially to effective governance in the
organization.
5.
Fully integrated within an organization's governance structure, risk management is seen as
central to an organization's management process, such that risks are considered in the
context of the effects of uncertainty on objectives.
CREDIT RISK
What is Credit Risk?
In daily life, lending and borrowing is an activity that is commonly found both in villages and
cities. Some of these activities are managed professionally and some are amateur, namely
banking and individuals. With the development of information technology, borrowing or credit
can be done with a mobile phone device (Handphone) where it is easy to get funds with the
compensation that all numbers on the creditor's cellphone can be accessed by online lenders.
Based on research (Priliasari, 2019) states that people are more interested in making online loans
due to the many features that benefit creditors compared to banks, this is inseparable from the
achievement of national economic growth which reached 5.17% in 2018 which recorded the
highest growth since 2014 (Nuryanto et al., 2020). Basically, all human life activities are
inseparable from risks and problems, the greater the risk of an activity, the greater the profit and
benefit from it. In terms of understanding, risk is a form of uncertainty about the circumstances
that will occur in the future, with decisions taken based on the following various considerations
at this time (Madalena & Vannie, 2019). Credit is the provision of money or receivables based
on a loan agreement or agreement between a bank and another party that forces the borrower to
repay the loan after a certain period of time with interest. Credit is defined as the ability to make
purchases or loans with a promise of payment that is postponed within an agreed period of time
(Tektona & Risma, 2020). So that the risk in a credit must exist, this is what makes banking
profitable if it is managed properly. Defaults that occur will be recognized early by banks if risk
mitigation is in the process. The common approaches in this regard are the 4P, 5C and 3R
analysis, so that risk mitigation serves as an initial protection for credit risk in banking
(Kurniasari et al., 2020). When in the book (Pattiapon et al., 2021) states that the risk of credit
risk that will occur due to opportunities that can actually be used is lost and in the future there is
a risk that is equalized in nominal money. Based on Bank Indonesia regulations, which is an
assessment of the health of a bank based on the source of financing / credit, namely NPL (Non
Performing Loan), which is below 5%. This percentage process shows how big the problem of
bad credit is in the community (Hairul, 2020).
The definition of credit risk is an uncertain condition which is the most significant faced by
banks, the success of their business depends on accurate measurement and high efficiency of
existing conditions compared to other conditions (Sari et al., 2020) and the success of their
business depends on accurate measurement and a higher level of efficiency in managing this risk
than other risks. Definition Another thing about credit risk is the comparison of NPL (Non
Performing Loan) with credit channeled by banks (Mukaromah & Supriono, 2020). In research
(Mukaromah & Supriono, 2020). According to (Gayatri et al., 2019) Credit risk is a natural risk
because one of the bank's main activities is to provide credit. To measure credit risk, financial
ratios can be used, namely the number of bad debts (NPL). Pandia states that credit risk is a loss
associated with the inability and/or unwillingness of the borrower to fulfill the obligation to
repay the borrowed funds in full on or after maturity. Credit risk is also present in treasury
activities. Credit risk in treasury operations is also related to the placement of funds with other
banks. In general, investment limits with other banks are clean, meaning that they do not require
the submission of collateral from the receiving bank. Thus, credit risk occurs if the receiving
bank is unable to fulfill its obligation to the lending bank, which is to return the funds at
maturity.
Scope of Credit Risk:
In general, risk management is a series of processes that begin with the identification,
measurement, monitoring, and control of portfolio risk. Therefore, bank managers can always
control risks that do not affect the liquidity level of the bank itself. As intermediaries, banks
always face commercial risks. Commercial risks include credit risk, market risk, liquidity risk,
operational risk and regulatory risk. To exercise prudence and minimize the risk of loss, banks
must conduct trading based on the guidelines and implementation of risk management set by the
government with the principle of hedging. Bank Indonesia, in Bank Indonesia Regulation
No.5/8/PBI/2003, has at least identified four main aspects related to risk management. Second,
establishing policies, procedures and limits. Third is the process of identification, measurement,
monitoring and credit risk management information system. Fourth, credit risk management. In
Indonesia there are two types of banks, namely ordinary banks and rural banks, the difference is
that rural banks are restricted in that they are not allowed to deposit money in the form of credit
cards, current accounts, clearing, foreign exchange transactions and transaction services based on
Law No. 1998. Bank Perkereditan Rakyat has sharia principles, although in reality it does not
(Efriani & Widayati, 2019).
Risk Classification and Risk Types of the Bank:
Risk groupings can be divided into several types depending on the level of loss experienced in
the situation. There are two types of risks namely:
1.
Pure risk is a risk that can cause losses. (Putri et al., 2020) explains that Pure risk is a risk
that if it occurs will definitely cause losses such as theft, natural disasters, fires or accidents.
2.
Speculative risk, which is a risk that can lead to both losses and gains. Other risk
classifications are: [1] systematic risk, which is risk that cannot be diversified (cannot be
eliminated or reduced), and [2] specific risk, which is "risk that can be eliminated through
the process of diversification" (Sayfuddin, 2007). In the same book (Sayfuddin, 2007), Rose
reveals that banks do not only pay attention to stocks and high portfolios alone, but must
also consider the other risks involved, namely:
a.
Credit risk is the risk of loss arising from the inability and/or unwillingness of the
borrower (counterparty) to fulfill its obligation to repay the borrowed funds in full on or
after maturity (Sukma et al., 2019).
b.
Liquidation risk, occurs due to inadequate company funds to pay maturing obligations at
the bank The ratio used to measure liquidation is the Loa to Deposit Ratio (LDR) where
the ratio between the amount of loans provided is divided by the amount of capital, the
greater the LDR, the lower the liquidity of the bank (Korompis et al., 2020).
c.
Market risk, which is the risk that changes in the market value of a bank's assets,
liabilities, and equity could be detrimental to the bank.
d.
Interest rate risk is the possibility that changes in interest rates could negatively affect
the bank's net income, asset value or equity,
e.
Income risk, which is the possibility of a decrease in return on assets (ROA) or return
on equity (ROE) or net earnings,
f.
Solvency risk, which is the possibility of the bank's negative profitability draining its
capital.
Credit Segmentation:
The Bank conducts loan segmentation by considering the unique characteristics of each business
line. Credit segmentation will affect how the bank is treated and the policies that determine
collateral adequacy, credit structure, credit decision-making authority and the like. Although
each bank may differ in defining its loan segments, in general, loan segments can be divided into
personal loans, commercial loans, and business loans.
Each bank has the flexibility to determine the credit limit for this segment. Banks can orient
lending to the complexity of the segment in question.
Credit Categories:
The process of carrying out credit activities is the beginning of credit risk, therefore it is
necessary to know the types of credit products commonly provided by banks, because if there is
a default by the debtor, the potential profit of the company will be delayed (Islamiah & Selvi,
2019).
Defining credit risk begins with the process of conducting credit operations and then identifying
factors that may lead to potential credit risk. Therefore, to be able to identify credit risk, it is first
necessary to know the types of credit products commonly offered by banks. There are various
types of credit that can be provided by banks. In general, types of bank credit can be classified
according to:
1.
Type of asset,
2.
The usefulness of the credit in the debtor's business,
3.
Credit purpose,
4.
Time period,
5.
Type of funds provided (cash or non-cash),
6.
Type of credit currency.
Credit Risk Management:
Credit risk management in banking may include the profiling of credit risks that may arise from
various banking activities, including lending, derivatives trading, instrument trading, and credit
risk management.
Other financial, as well as other banking activities, including those recognized in the banking
system accounting and transaction books. Banks shall manage the credit risk recorded in all
portfolios, including identifying, measuring, monitoring and controlling credit risk, as well as
ensuring that capital and compensation are appropriate to the risks incurred. Banks shall develop
a credit risk strategy that reflects the bank's risk tolerance and the bank's expected return from
credit risks that may arise. The strategy should always take into account economic cycles and
movements. Banks should identify and analyze the credit risk inherent in all products and
transactions. The determination comes from an in-depth review of the existing or potential credit
risk characteristics of banking products/transactions. Banks should clearly understand and
analyze the credit risks associated with more complex business activities (e.g. use of loans for
specific industries, asset securitization, credit derivatives, etc.). Banks need to ensure that risks
associated with new products/operations are integrated into the risk management process and
approved by management. Banks should have a methodology for measuring credit risk to
individual borrowers or counterparties. Banks should also be able to analyze credit risk at the
product and portfolio level to determine specific risk levels or concentrations. The measurement
of credit risk should consider the specific nature of the credit (loans, derivatives and other
financing vehicles), the financial position of the debtors and terms of the VND contract/credit
agreement (term, interest rate reference, etc.). Risk profile to maturity in relation to potential
market changes. Collateral or guarantee aspects and probability of default based on an
assessment using the Bank's internal risk rating need to analyze credit risk data on a regular basis
and use techniques to measure complexity and risk on accurate and frequently validated data.
The effectiveness of the credit risk measurement process is highly dependent on the quality of
the management information system. Information obtained from the system enables the board of
directors and all levels of management to carry out their respective supervisory roles, including
determining the appropriate level of capital to sustain the bank. Therefore, the quality, detail and
timeliness of the information is critical. The measure of prepayment risk is the risk of loss that
may occur if the counterparty fails to fulfill its obligations as agreed within the contractual term.
Banks can measure prepayment risk by summing up the replacement cost, which is the cost of
bringing a similar transaction to market if the customer fails to fulfill its commitment to the
current transaction. If fair market value is not attainable, replacement cost can be calculated by
applying a relevant model and using interest rates and/or exchange rates that are available or
attainable in the market setting. The estimated value is usually determined based on the time
until the contract expires and the expected fluctuations in interest rates and/or exchange rates
over the remaining contract period. This measurement can be done using a variety of statistical
techniques, including probability-based simulation analysis, simulations based on past events,
and simple simulations based on common characteristics. Banks should customize the applicable
risk measurement method for the type of activity and the level of risk associated with the
activity. Banks that actively transact require a system to measure potential credit risk, while
banks that are less active and only act as end-users may use a system to measure credit risk rely
on estimates calculated by agents or other sources independent of the operator. Risk management
measures arise when the bank has fulfilled its payment obligations as agreed in the contract but
has not yet received payment from the counterparty. This is due to a number of factors, including
time zone differences between the two trading parties, operational technical issues, counterparty
defaults, market liquidity restrictions, and more. Payment risk can be measured from the moment
the bank is unable to unilaterally cancel a payment instruction to the counterparty (unilateral
cancellation time) to the moment the bank receives the counterparty's payment (for payment
purposes).
The level and type of payment risk may depend on the settlement/payment method of the
transaction. During this time, the potential risk that may arise is equivalent to the amount of the
transaction that has been paid to the counterparty. In addition to credit risk, payment risk
(especially in forex business) is also associated with other aspects of risk, including liquidity
risk, regulatory risk, and systemic risk. As payment risk becomes credit risk if the counterparty
fails to pay as contracted, the bank's ability to limit credit risk is an important factor in
determining payment risk limits. Banking limits should be set for all customers or partners
before dealing with them. The limit structure for each customer or partner may be defined
differently. The establishment of credit risk limits is generally intended to minimize the risks that
may arise from the centralization of lending. Limits set include at least: credit levels to customers
or counterparties, risk levels to related parties, risk levels by geography or industry, economic
certain. The determination of customer or counterparty limits may be based on quantitative
considerations obtained from financial information, as well as qualitative sources, including the
results of discussions/meetings with the Board of Directors. Therefore, the effectiveness of limit
setting depends on the quality of information available.
The assessment of individual customer limits for customers or counterparties should include
overall limits, limits for each type of risk, and limits for specific functional activities that give
rise to risk. Banks must monitor the actual level of risk to see if it is within regulatory limits.
Therefore, there is a need for a management information system that can capture credit risk for
each borrower and flag exceptions to credit risk limits, ensure that further credit risk exposures
are close to limits that attract management attention, to determine the level of risk in the loan
portfolio, to provide additional loan portfolio analysis, including stress testing. The use of an
internal risk assessment system is an important tool for monitoring the quality of individual loans
and the portfolio as a whole. A well-structured internal risk assessment system is a good way to
separate credit risk from bank credit risk. This will help to more accurately determine the overall
characteristics of the credit portfolio, credit concentration and bad debts. In general, internal risk
assessment systems categorize loans into different classifications that are designed to take into
account risk classifications. A simpler system may be based on satisfactory to unsatisfactory
categories. However, a more comprehensive system will have more classifications to accurately
differentiate credit risk. When designing the system, banks should take into consideration the
risk assessment of the borrower or party counterparty, the risks associated with a particular
transaction, or both. Ratings assigned to each borrower or counterparty should be reviewed
periodically by an independent entity to verify the consistency and accuracy of the ratings. Credit
risk monitoring should be conducted on an ongoing basis by an independent entity by comparing
actual credit risk with established risk limits. Risk managers are responsible for compiling and
distributing timely and accurate risk reports, including facility utilization, credit concentration,
credit quality, cap rate outside/outside the limit, substantial counterparty risk and total credit risk
for each side. Specifically for settlement risk, the trade settlement process needs to be monitored
on a daily basis. Late payments and follow-up actions should be reported daily to management.
Banks must have policies to anticipate the emergence of unusual conditions (stressful situations)
that may cause the bank's risk exposure to exceed predetermined limits. Banks as financial
institutions have the function of collecting money from the public in the form of deposits and
channeling money in the form of credit to the public or other parties in order to improve people's
lives. This is built on the basis of mutual trust between the two parties through management's
commitment to creating good banking performance by maintaining liquidity, solvency and
profitability in a stable position...(Rika Wulandari, 2019)
Bank Risk:
Things that need to be done in managing risk in banking institutions include;
1.
Identifying and Assessing Risk
This stage aims to identify all types of risks inherent in each functional activity that have the
potential to be favorable or unfavorable. The Bank collects and accumulates data on events,
or issues (including losses) that have occurred in the past. All risks, other than credit risk,
market risk, and liquidity risk, especially fraud risk, are included in operational risk.
2.
Assessing and Measuring Risk
This stage aims to obtain an overview of the effectiveness of the implementation of Risk
Management, namely by measuring the sensitivity of products/activities to changes in
factors that affect them under various circumstances. Available
3 activities, namely; (1) assessing key risk areas, (2) measuring the likelihood of occurrence
and impact of risks, and (3) assigning a risk ranking.
3.
Responding to Risk
After identifying and measuring risks, risk managers must control risks by building risk
mitigation programs. The stages are; 1. Define the desired outcome 2. Build options 3.
Select and set strategies.
4.
Communication and Consultation
Communication and consultation on risk management with various interested parties,
especially with Bank Indonesia to make sound risk management decisions.
5.
Monitoring and Reviewing Risk Management
Monitor and review the effectiveness of the risk mitigation program, as a strategy that has
been established and agreed upon. The stages are;
a.
Learn and improve decision-making and risk management processes, both at the local
level and the organization-wide level.
b.
Using criteria and reporting results and performance effectively
c.
Set up an adequate and effective back-up system and procedures to prevent disruptions
in the risk monitoring process and check the back-up.
6.
Integrating Results from Risk Management at All Levels
The results of Risk Management should be horizontally integrated into the Bank's policies.
At this stage it needs to be done;
a.
Establish a number of appropriate scenarios to finance the risk
b.
Provide and maintain adequate financial protection, or hedging, with respect to possible
disasters.
c.
Establish a basis for allocating the risks to be taken over.
Credit Risk Identification:
In managing credit risk, there is a standard that can be referred to, namely ISO 31000, which is a
standard used for both large and small industries (Sambodo et al., 2020). Credit risk is defined as
the failure of debtors to fulfill their obligations to banks (Eprianti, 2019). Common types of
credit provided by banks are:
1.
Type of asset,
2.
The usefulness of the credit in the debtor's business
3.
Credit purpose
4.
Time period
5.
Type of funds provided (cash or non-cash)
6.
Credit currency type Asset type
A key consideration in determining the credit structure is the type of asset to be financed. Fixed
assets are long-term investments that can be financed with equity or in combination with long-
term debt. These assets should be financed with long-term capital. Fluctuating current assets are
current assets with needs that rise and fall according to the development of demand. Because of
their fluctuating and short-term nature, financing can be done with short-term loans such as
overdraft loans or financing of receivables. Lending based on the type of asset can be done in
various ways, including:
1.
Asset Conversion Lending (Seasonal credit)
At in asset conversion lending the bank plans for the entire principal of the loan to be repaid
at the end of the loan period. The source of loan repayment comes from the conversion cycle
of raw materials or merchandise, until the cycle is declared complete, that is, sold to
consumers and paid off. This type of loan is on a self-liquidating basis, meaning that the
loan will be repaid by the debtor when the business cycle is complete.
2.
Asset Protection Lending
Loans on the basis of asset protection loans are long-term loans, there is no plan to repay the
principal at the end of the production period, but the loan is made on the principle of
continuity, that is, the business will continue without a period. For example, working capital
to finance the inventory and receivables of a metallurgical company, credit used to finance
the inventory of iron and building materials, and financing of accounts receivable with a
reasonable turnover rate. Another source of repayment that can be used to lower loan
interest rates is new money from business owners, such as additional capital deposits.
3.
Cash flow Lending
Cash flow lending is a long-term loan that is used, among others, to finance the purchase of
fixed assets or investments. With cash flow lending, it is expected that the entire principal
loan will be repaid at the end of the loan period, in accordance with the predetermined
principal repayment schedule.
Based on usability
1.
Investment Credit
Investment loans are long-term loans used for investment purposes. Investment loans can
also be used for the purchase of capital goods or trade. Repayment of investment loans must
come from business results that generate sufficient cash flow to be able to fulfill the debtor's
obligations to the bank.
2.
Working capital loans
Working capital loans are loans used for the working capital needs of business operations.
Working capital loans to finance inventory and receivables will continue to be incorporated
into the business, with the most appropriate being a permanent, long-term working capital
loan.
Based on credit purpose:
Consideration of the credit decision maker is the key to a risk that will occur in the granting of
credit in the future, as for the things that are considered:
1.
Ensure that credit is granted in accordance with banking regulations and credit guidelines as
per established guidelines.
2.
Ensure that credit is granted on the basis of an honest and objective credit analysis
assessment based on reasonable conditions, applying correct principles and independent of
the influence of other parties related to the credit request.
3.
Trust that the loan provided can be repaid within the agreed timeframe.
4.
Confidence that future loans will not turn into bad debts or non-performing loans (NPLs).
5.
The credit limit or the amount of credit given does not exceed the verification of the
collateral value (Chosyali & Sartono, 2019).
From this explanation, credit is classified based on purpose, namely:
1.
Productive Credit
Credit is used to increase business volume (sales) or production, and generate cash flow for
the benefit of business owners and to repay credit obligations. For example: Credit to open a
business, credit to run a restaurant, etc.
2.
Consumptive credit
Credit is used for consumption and unproductive credit. For example, credit to buy a car,
credit to employees, credit to buy electronics, credit to own a house, etc.
Credit Risk Measurement:
Credit risk is measured by measuring inherent risk, which is the risk inherent in lending
activities. The measurement of inherent credit risk is carried out by determining the potential loss
due to credit risk, i.e. measuring how much the possibility of errors in the credit process, then
determining the impact that can be caused if the potential risk becomes a reality. For example,
credit risk will be high if the bank extends credit to an area where the bank is not familiar with
the characteristics of the marketing area. This is because in an unfamiliar area, the possibility of
making mistakes is high (probability of default) will be greater, and if something goes wrong,
there will be a large impact (loss given default). This potential loss is known as expected loss or
EL, which is the multiplication of probability of default (PD) with loss given default (LGD).
Credit risk is measured using the UL (Unexpected Loss) parameter, which is a deviation from
EL, meaning that the potential EL estimate misses the original estimate. For example, if it is
initially estimated that the probability of the number of loans in the non-performing category is
1% (PD = 1%), with the amount of loss in the event of a problem averaging 50% of outstanding
loans (LGD = 50%), then EL is 1% multiplied by 50% or = 0.5%. Credit risk is if it turns out that
the number of non-performing loans misses 2%, and the LGD also misses the original estimate,
which is greater than 50%. PD (Probability of Default) is calculated from the bank's internal
rating system.
Credit Analysis:
To carry out credit analysis has stages that are carried out, including qualitative analysis.
Qualitative analysis is known to have several types and methods, namely credit analysis with the
5C and 7P principles. for 5C, namely (Desda & Yurasti, 2019)
1.
Character analysis
This analysis can be done by conducting direct surveys by the credit team, both marketing
and credit risk teams. Then credit analysis can also be seen from BI Cheking obtained from
the submission of prospective debtors, from this information a credit analyst knows from the
beginning the character of the prospective debtor.
2.
Capacity analysis
This is done by looking at the customer's ability to pay the loan credited each month. The
credit analyst team usually gets this capacity from the calculation of the ability to pay and
the capacity of collateral.
3.
Capital analysis
This capital analysis is carried out by assessing the capital owned by prospective debtors by
looking at current and non-current assets.
4.
Conditional analysis
This analysis looks at the general condition of the prospective debtor and the future
conditions of the potential to pay the credit.
5.
Colleteral analysis
This analysis is carried out by paying attention to the guarantee provided by the prospective
debtor against the loan to be granted.
As for the 7p analysis, among others:
1.
Personality or personality is done to see the personality of prospective debtors
2.
Purpose is the intent and purpose of the prospective debtor applying for credit
3.
Party means the distribution of bank credit by sorting credit into several groups
4.
Payment is the way the loan is paid by the customer
5.
Prospect is to see the possibility and expectation of credit financed.
6.
Profitability, namely financing by banks that in the future provide benefits to both parties
7.
Protection is the protection of the credit usually with credit insurance
Conclusion:
In daily life, lending and borrowing is an activity that is commonly found both in villages and
cities. Some of these activities are managed professionally and some are amateur, namely
banking and individuals. So that the risk in a credit must exist, this is what makes banking
profitable if it is managed properly. Credit risk is a natural risk because one of the main activities
of the bank itself is to provide credit. In general, risk management is a series of processes that
begin with the identification, measurement, monitoring, and control of portfolio risk. As an
intermediary, banks always face commercial risk. Second, establish policies, procedures, and
limits. Risk groupings can be divided into several types depending on the level of loss
experienced in the situation, risks that can cause losses and profits. This type of loan is on a self-
liquidating basis, meaning that the loan will be repaid by the debtor when the business cycle has
been completed. For example, working capital to finance the inventory and receivables of a
metallurgical company, credit used to finance iron and building materials inventory, and trade
receivables financing with a reasonable turnover rate.
Students also viewed