1 / 24100%
INTEGRATING TOP-LEVEL DECISIONS HOW THE TOP-DOWN
APPROACH ENHANCES RISK MANAGEMENT
ARIZONA STATE UNIVERSITY
IEE 454 – RISK MANAGEMENT
WEEK 1
Introduction:
Every entity in running its business is inseparable from all the risks it faces. Risks and
benefits are like two things that have the same surface and the same opportunity whether risk
or value is dominant. Risk is related to environmental uncertainty. This uncertainty is
possible because there is not enough information available about what will happen.
Uncertainty can have a beneficial or detrimental impact. In the face of an ever-changing
environment, the risks that will be faced are important to be managed properly for the benefit
of the business in the future.
Every decision and attitude taken by management must be managed properly, especially
the economic use of resources. Careful planning of possible risks that will occur will reduce
potential losses. Risk management should be designed in such a way that future losses can be
minimized. Various models have been developed and implemented in the industry.
A. Type of Management Model Risk
1. Process-based Risk Management Model:
The risk management approach model proposed by Umar (1998) is shown in Figure 2.1.
This approach is known as the risk management process model, including: identifying and
assessing the risks that will occur, setting policies, taking action, and monitoring risks. The
process is continuous and if implemented to the fullest, risk management will contribute to
management in analyzing business strengths and weaknesses.
2. Risk Management Model Based on Management Level:
The risk management model looks at the involvement of management and stakeholders in
identifying risks through three types of approaches as follows:
a. Top down-approach
The decision-making process is focused at the central level. This approach is carried out
through: full top-down mode and prevailing top-down mode. In this case, risks can be
listed at the departmental level, unit heads cannot add risks at the unit level. Similarly,
the business risk register is taken directly from the detailed operational risk register.
b. Bottom-up approach
Decisions are taken at the operational management level that staff can make and can be
registered online.
c. Mixed approach
The decision-making process involves top management and unit leaders and justifies and
manages risk (bottom-up). Risks will be seen and assessed at every line of management.
3. Risk Management Framework Model
a. Risk Identification:
A common process for formulating risk management is to match the level of risk
with predetermined standards, desired outcomes and other characteristics. Identification
is made of existing and potential risks. At the time of identification, it is necessary to
identify the characteristics and factors causing the risk, design a suitable research
methodology, obtain alternative decisions and analyze them. Next step, implement the
decided alternatives, supervise the implementation and evaluate the decisions that have
been carried out.
b. Risk analysis:
This analysis is needed to measure risk from the aspects of potential loss and
probability of occurrence. There are two approaches to risk analysis referring to JICS
infoNet (Wijayantini, 2012), namely qualitative analysis (among others, brainstorming,
multidisciplinary group evaluation) and quantitative analysis (network analysis,
probability analysis, computer simulation numerical analysis, customer satisfaction
survey and market survey).
c. Risk response:
Stakeholders are involved in planning decision-making with respect to handling each
risk that will occur. Furthermore, these risks need to be followed up with a certain
response in handling the risk.
d. Risk evaluation:
A process will be evaluated to see the achievement of the risk management approach
with the suitability of the plan. This evaluation is followed up to reassess the existence of
identified risks and unidentified risks. The evaluation is aimed at better understanding
the characteristics of the risk. A better understanding of a risk will make it easier to
control.
4. Capability Maturity Model Integration (CMMI):
To benefit from risk management (Shah, et al: 2009), first have a view of the risk
management approach, models to facilitate the process as well as guidelines to improve the
risk management approach. Second, risk management and project planning must be
integrated. This requires a risk management process based on the CMMI capability maturity
model with four attributes of the risk maturity model.
5. Model Risk Exposure Calculator:
The simplest model for managing inherent risk is the "Risk Exposure Calculator"
developed by Simons (2008). It is used to assess internal pressures that give rise to increased
risk, identify "pressure points" in three areas (growth, culture and information management)
and after evaluation to keep the organization in one of three defined zones: Safe Zone,
Cautious Zone and Dangerous Zone.
6. Risk Maturity Model (RMM):
This model, proposed by Hillson (1997), has four standard maturity levels, namely naive,
novice, normalized and neutral measured in four attributes: culture, process, experience and
application. This model is widely used in the UK.
7. Capability Maturity Model Integration (SEI CMMI):
A model that has wide visibility is SEI CMMI which originated from the Software
Engineering Institute of Carnegie Mellon university USA. The model is described in six
levels (in terms of continuous representation) of capability and maturity referred to as
Incomplete (rank 0), Performed (rank 01), Managed (rank 02), Defined (rank 03),
Quantitatively Managed (rank 04) and Optimization (rank 05). Each level is clearly
characterized and defined, allowing organizations to self-assess against an agreed scale.
Other models that can be used in a business entity are the business excellence model of
the European Foundation for Quality Management (EFQM), RiskSIG (PMI: 2002), the HVR
risk maturity model (Simons: 2008) and the AREM method (Suzuki, et al: 2007).
8. ISO 31000 Focus Maturity Model:
A maturity model is a tool towards an increasingly organized and systematic way of
doing business, involving people, organizations and processes. This model is often found in
the context of: data management, information security, and project management. In the
maturity model, the evolution is described through discrete stages. To reach the next level
requires achievement of all previous levels. The maturity model focuses on ISO 31000,
specifying processes and frameworks to define a risk management maturity model. ISO
31000 is sometimes referred to as the "umbrella standard" because there are more than 60
references in the field of risk management that are aligned with this standard (Proenca, et.al:
2017).
ISO 31000 is accepted as a standard regarding the activities that should comprise the risk
management process. Risk management is therefore an iterative process, the context of which
must be established to identify internal and external factors that may affect the rest of the
process activities. Risk assessment is a sub-process of identifying existing risks within a
predefined context, analyzing the identified risks usually regarding their severity, and
evaluation where the identified risks are compared using the previous analysis.
Using the outputs of the risk assessment, stakeholders define a risk treatment plan
consisting of a set of controls (actions) and mitigate the identified risks. Throughout the
activity, all relevant stakeholders need communication and consultation phases to ensure
accurate identification and estimation, monitoring and review phases are needed. Risk
management processes should be integrated both in the management of the organization and
in the practices and culture of the organization and should be tailored to each organization
and its own processes. Risk management activities should be well documented and recorded.
B. Summary Material:
1. Risk models are tailored to the needs of an entity. The existence of a risk management
model is expected to assist management in managing the risks that will occur both from
losses (negative aspects) and the value of an activity.
2. Risks need to be managed given the environmental uncertainties faced by a business
unit.
3. By anticipating risk management modeling as early as possible, it is hoped that a
program/activity run by the organization can be managed from possible business risks
that will occur.
Practice and Evaluation:
1. Why is a risk management model needed in a business?
2. Explain the relationship between risk assessment methods and risk analysis techniques?
3. What are the main activities of the risk management process in accordance with ISO
31000?
4. How can a custom maturity model for risk management be designed that targets the
challenges of different organizations and industries?
5. PT ABC, a company engaged in the sale of medicines and medical devices. The
company wants to expand its business while maintaining excellent service to
customers. On the other hand, PT ABC has not been disciplined in separating personal
family interests from business ventures, so that business income does not reflect the
conditions that should occur. In this case, the principle of separating personal and
business interests has not been separated (business entity). In addition, the situation of
using drugs and taking money from the company (prive) is considered valid and
something common. This condition is a finding and has an impact on the business unit.
Based on the information above, provide a solution using the risk management framework
model, and explain what are the recommendations for management!
BUSINESS RISK IDENTIFICATION
A. Introduction:
We have gone through business in the era of the 4.0 industrial revolution, now it's time to
enter the all-digital 5.0 industrial era (Anonymous, 2022 a). Industrial revolution, a term that
has been quite familiar during the Covid-19 pandemic for about two years. The industrial
revolution is a phenomenon that is quite often studied in schools, lectures, and training,
because of its enormous influence on the world (Hussain et al., 2013a). The industrial
revolution 4.0 is the latest advancement most widely implemented by industry.
Recently, a new idea emerged, the industrial era 5.0, which emerged after the pandemic.
It seems that the pandemic has indeed brought major changes to human life, especially the
economic aspect. Many industries have changed their business models, most of which have
digitized (Pahlephi, 2022). This has resulted in a change in the business model, which was
originally done offline, but has now shifted online. In fact, many people can now work from
anywhere without having to attend the office. Industry 4.0 is basically driven by IoT (Internet
of Things), AI, and automation. The 4.0 era is a major revolution in the development of
human life. Digital technology affects humans in various aspects (Anonymous, 2022 a).
The industrial era 5.0 emerged as the perfection of the 4.0 era, now humans can work
together with robots and artificial intelligence. This industrial era 5.0 utilizes IoT technology
to combine artificial intelligence with the human mind. The industrial era 5.0 is not to replace
humans with robots, but rather support human work (Anonymous, 2022 a).
Era 5.0 is driving the balance of industrial efficiency and productivity thanks to the fusion
of technology and human intelligence. For example, there is now a new habit of remote
working where workers can complete their work from anywhere. This requires the help of the
internet, technology and software to exchange work data, communicate with teams, and
assess employee performance (Hussain et al., 2013b). This means that in working remotely,
humans are assisted by technology and artificial intelligence. However, humans are still the
ones doing the work. The remote working system does not replace human labor, but enhances
it with technology.
Business in the era of the industrial revolution 5.0 certainly still has business risks, so we
must assess the potential business risks (Hussain et al., 2013a). The business that we run in
order to increase and develop certainly needs to pay attention to business risks because it can
affect our company's targets, budgets and strategies. In addition, effective risk management
helps prevent network hacking and natural disasters (Anonymous, 2022 a). In addition, our
customer and employee data will not be compromised. It is thus very important to discuss
possible business risks and steps for the business risk identification process. However, some
other related topics are important to mention.
B. Benefits of Risk Management Business:
There are several benefits that can be obtained when a company conducts business risk
management. Among them are:
1.For evaluation and business decisions
Evaluation is the process of assessing and measuring the effectiveness of strategies
that have been used and that have been carried out in the past to achieve the goals of a
company. The results of the business risk analysis will be a material for us to evaluate
whether the business risk analysis is effective. The ways that have been done so far are
the right and appropriate ways to achieve business goals. In addition, so that we do not
make the same mistakes that have been made in the past, causing us to be hampered in
achieving business goals. With evaluation, we will find it easier to make a more
appropriate business decision.
2. Increased productivity and profits:
Productivity is a production activity that is a measure of how well resources are
organized and utilized to achieve optimal results. Through business risk management,
we can be more careful in running a business and avoid falling into the same hole. This
will automatically help us to increase the productivity that occurs, and the profits
obtained will also increase compared to before the business risk management is carried
out.
3. Facilitate cost estimation:
Cost estimation is the calculation of the cost requirements needed to complete an
activity or job. Cost estimation is very important in a business. The inaccuracy of the
estimation of the production process itself, such as the obstruction of the production
process in a company. With risk analysis and management, it will be easier for us to
calculate the estimated costs needed, such as estimating business production costs.
C. Risk Management Process Business:
According to COSO (Committee of Sponsoring Organizations of the Treadway
Commission), there are eight related frameworks in Corporate Risk Management (MRK),
namely:
1. Internal Environment:
This first process relates to the company's operating environment, ranging from risk-
management philosophy, integrity, risk- perspective, risk-appetite, ethical values,
organizational structure, to the delegation of authority carried out by the company.
2. Objective Setting:
The next step is to determine the objectives of the organization so that risks can be
identified, accessed, and managed in accordance with these objectives. We can classify
these objectives into two, namely strategic objectives that focus on realizing the vision
and mission and activity objectives that aim at activities such as operations, reporting and
compliance.
3. Event identification:
Identify potential events that affect an organization's strategy or goal achievement.
These uncertain events can have a positive impact (opportunities), but can also have the
opposite effect, which is more commonly referred to as risk.
4. Risk Assessment:
This step assesses the extent to which the event or situation can interfere with the
achievement of objectives. The magnitude of the impact can be analyzed through two
perspectives, namely likelihood (tendency or opportunity) and impact/consequence (the
magnitude of the realization of the risk).
5. Risk Response:
The organization must determine its response to the results of the risk assessment.
This response can be risk avoidance, risk reduction, risk sharing, and risk acceptance,
depending on the risk at hand.
6. Control Activities:
This process plays a role in developing policies and procedures to ensure that risk
response is carried out effectively. This control activity is in the form of establishing
policies and procedures, safeguarding organizational assets, delegation of authority and
separation of functions, and supervisory supervision.
7. Information and Communication:
The focus of this step is to convey relevant information to relevant parties through
appropriate communication media. Factors that need to be considered in the delivery of
information and communication are the quality of information, direction of
communication and communication tools.
8. Monitoring:
The final step is monitoring, either on-going or separate evaluation. In the
monitoring process, it is important to be aware of obstacles such as reporting
deficiencies, i.e. incomplete or even excessive (irrelevant) reporting.
D. Navigating Risk Business:
The business we run requires sincerity, courage, determination, smart work, hard work,
thorough work and good business management and strategy. However, the business will
progress and develop must know the business risks, so that it is always safe and profitable. In
the development and journey of business, we will face obstacles, challenges and difficulties,
both now and in the future, both easy and difficult obstacles (Hussain, et al, 2013a).
These obstacles are commonly known as business risks. The business that we develop in
addition to getting benefits, we must also be prepared to accept the risks. In fact, for a
business that is already large and spread in several places, it is not impossible to face
obstacles, challenges and difficulties. Business risks are inseparable and become an integral
part of a business or business that we run anywhere and anytime (Hussain, et al, 2013b).
Business risk is the result of business activities that show losses and some problems in a
certain period of time. Business risk is a danger or consequence that may occur in an ongoing
or future business (Pahlephi, 2022).
There are many factors that lead to the occurrence of business risks, ranging from internal
and external conditions (such as disasters, economic shocks, and the like). If not detected as
early as possible, business risks can cause greater losses. Therefore, companies must have the
ability to mitigate, manage and transfer risks.
Business risk is an outcome that may occur in an ongoing or future business. The nature
of business risk itself is uncertain and mostly causes losses (Hussain, et al., 2013a). Business
risk is a situation that is not desired by business people, but business risk itself is always
unavoidable. This risk usually arises because of the business actors themselves, and can arise
due to activities and decisions taken in daily routine activities.
According to Abbas Salim (Pahlephi, 2022), there are three factors that affect uncertainty
that will cause losses. These uncertainties can be caused by factors including: economic
uncertainty, uncertainty caused by nature, and uncertainty caused by human behavior.
In addressing business risks, there are four forms of attitudes that we must take:
1. Risk aversion:
This attitude is often ineffective because avoiding risk means that we do not dare to
take the opportunity to try and overcome risks, and we do not even learn anything. This
action means that we do not take actions that can cause the risk to occur, including not
implementing a business strategy that has been developed.
2. Reducing Risk:
This means finding a course of action to reduce losses from a risk that could occur.
The possibility of the risk occurring remains, but the impact is minimized as much as
possible. For example, a fire detection alarm system, a fire can still occur but the risk of
loss can be reduced with this system.
3. Transferring Risk:
Apart from avoiding and reducing risks, we can also transfer risks. We can transfer
the responsibility to another party by paying for the service. For example, if we own a
glassware company and have to ship it to a place that is quite far away, we can transfer
the responsibility to another party by paying for the service. In the case of long distances
and inadequate roads, it is better to choose to pay a delivery service that has glassware
insurance rather than ourselves or our own employees. Of course, we will transfer the
risk to this delivery party.
4. Accepting Risk
Accepting means that we can only let the loss happen. This attitude is of course taken
if there is no other way to deal with it. For example, if we miscalculate money or send
the wrong goods, of course we inevitably have to accept the loss. Also keep in mind that
if the impact of the loss is too great, then it is better to avoid than accept it.
E. Risk Factors Business:
Internal and external parties are factors that cause business risks. Internal parties mean
coming from the company itself, while external parties are things outside the company's
control. The factors that cause business risks are as follows:
1. Economic Issues:
Economic problems in a country are factors that cause business risks from external
parties. Business activities cannot be separated from the economic activities of a country.
If a country's economy is in trouble, then this can have an impact on other businesses.
2. Natural Disasters:
Natural disasters are factors that cause business risks that come from external parties
over which the company has no control. Examples of business risks such as pandemic
disasters make some businesses adversely affected, there is a volcanic eruption that burns
the company and so on.
3. Human Behavior:
The factor that causes business risk is human behavior. This arises from the
company's internal factors for making inappropriate decisions or policies. Examples of
risks from human behavior such as trust consumers lost, receivables piling up and so on.
F. Types of Risk Business:
In practice, we as entrepreneurs will encounter various kinds of business risks. The types of
business risks are as follows:
1. Marketing Risk:
Marketing risk is a risk that occurs due to inappropriate actions in implementing
marketing strategies so that they fail and the public cannot accept the product properly.
2. Operational Risk:
Operational risks arise as a result of errors and deviations in the company's technical
procedures so that the products produced are not up to standard. This occurs due to
human resources, old technology and so on.
3. Financial Risk:
The next risk that is no less important is financial risk. This is a type of risk that is
often faced by business people. Business failure or misuse of company cash leads to
potential losses.
4. Human Resources Risk:
Human resource risks are also experienced by many business owners. This type of
risk comes from the behavior and conduct of human resources in running the business.
For example, lazy, dishonest, undisciplined labor and the like.
5. Market Risk:
Market risk is controlled by customers or consumers of the company. This is due to
changes and developments in the lifestyle of the target market, the emergence of other
competitors and so on.
G. Risk Classification Business:
There are several classifications of business risks that entrepreneurs should be aware
of, as follows:
1. By Nature
a. Pure Risk:
The classification of business risk based on its nature is pure risk where the
degree of certainty of loss is considered large. Examples of pure risks include natural
disasters, pandemics and the like.
b. Speculative Risk:
Speculative risk is caused by ill-considered decisions and actions that harm the
company. Examples of speculative risks include debt and the like.
c. Fundamental Risk:
Fundamental risk is a classification of business risk that is borne by the
company's internal parties and cannot be delegated to other parties.
d. Special Risks:
Special risks are risks that stem from events outside of our control and can be
mitigated, such as sinking ships, fires and so on.
e. Dynamic Risk:
Business risk classification is a dynamic risk arising from technological
development and advancement.
2. Based on Displacement:
a. Transferable Risks:
Transferable risk is a classification of risk whose loss burden can be transferred or
transferred to other parties so that the consequences that arise can be resolved, for
example insurance.
b. Untransferable Risk:
This type of risk classification cannot be transferred to other parties, so the
company must be willing to bear it.
3. By Source:
a. Internal Risks:
Internal risks are risks that arise as a result of within the company, such as
employees, operational damage, data leaks and so on.
b. External Risks:
External risks are risks caused by the actions of other parties that are beyond the
company's control, such as theft, natural disasters, government regulations and so on.
H. Risk Identification Business:
Risk identification is identifying potential business risks and analyzing them to learn their
effects on the business.
Risk identification is an effort made to search, find, and know what risks can arise in a
business or company. For example, software development companies and construction
companies may share the risk of losing revenue if they do not upgrade their tools for modern
processes. In addition, the company may also carry its own industry-specific risks such as
potential injuries on the job or intellectual property risks.
Risk identification is important at all stages of a business or company as it helps identify
our biggest challenges and helps create a clearer picture of the overall health of the business.
1. The importance of identifying business risks:
a. Identify industry challenges:
Risks related to the business can be security risks or volatility due to the business
itself. Identifying business challenges or specific risks helps businesses plan for future
costs or obstacles and helps leaders know if they are allocating resources to the right
places.
b. Meet legal standards:
Risk identification helps businesses understand whether they need to meet certain
legal requirements. A business that serves food may have different legal risks than a
company that makes shoes. Food must comply with certain sanitation practices and food
production requires certain state and local licenses.
c. Attractive to investors:
Investors typically look for investments with low risk and high returns. These
investments yield the greatest rewards for the smallest risks and risk identification helps
them understand the full potential of business risks. Knowing the risks they face,
investors can make more informed choices on the businesses they want to support.
d. Make projects more efficient:
Businesses also use risk identification on a smaller scale for individual projects or
practices. Identifying risks early during the project planning phase can help teams
navigate challenges more effectively with planning.
2. How to identify business risks early
In order to be able to handle the risks that may occur in the company, we should start
knowing how to identify business risks early on, here are the reviews.
a. Practicing helicopter view skills:
The first way to identify business risks is to practice helicopter view skills. This skill
teaches you to see from many sides of the business. So not only focus and attention on
one part only, but also pay attention to improving other areas in the company.
b. Thoroughly develop a business plan:
Developing a business plan carefully is the next way to prepare. Before running a
business, you should make a plan of action along with the risks. So you can see which
activities have a high level of risk and must be addressed immediately.
c. Analysis of product maturity level:
The next way to identify business risks is to analyze the level of product maturity.
Before products experience a decline in sales due to consumer saturation, companies
must be prepared to diversify new products. So that when sales of one product drop,
there is already another product that replaces it.
d. Conduct a SWOT analysis:
Conducting a SWOT analysis is the next way to identify business risks. It is important
to know the Strengths, Weaknesses, Opportunities, and Threats of a company. Thus, you
can provide the best treatments to avoid potential risks.
e. Plan risk mitigation strategies:
The next way is to plan a risk mitigation strategy. Risk mitigation is a planned and
sustainable activity to reduce the influence of something that allows risk hazards. So you
can overcome the risk slowly.
f. Document the process well:
Documenting processes properly is an important way to avoid risks such as procedural
errors and production process failures. The entire plan of strategies and actions that have
been implemented in the business are recorded in company reports on a regular basis.
This helps you to analyze and identify which actions are successful and minimize risks.
g. Evaluate performance on an ongoing basis:
From all actions and plans executed, you must evaluate the results. This way, you can
avoid potential recurrence of previous risks and prevent greater risks from occurring in
the future.
I. Summary Material:
1. To improve the business, it is necessary to pay attention to risks because they can
affect the company's targets, budgets and strategies.
2. Business will progress and develop if you know the risks, so that it is always safe and
profitable.
3. Business risks cannot be separated and become an integral part of a business or
business that we run anywhere and anytime. In addressing business risks, there are
four attitudes that can be taken, namely: risk avoidance, risk reduction, risk transfer
and risk retention.
4. Risk identification is important at all stages of a business or company as it helps
identify our biggest challenges and helps create a clearer picture of the overall health
of the business.
5. The importance of risk identification includes: identifying industry challenges,
meeting legal standards, making projects more efficient and attractive to investors.
6. In order to be able to handle the risks that may occur in business, we should start
knowing how to identify business risks early on, namely by: practicing helicopter
view skills; preparing business plans carefully; analyzing product maturity levels;
conducting SWOT analysis; planning risk mitigation strategies; documenting
processes properly; and evaluating performance on an ongoing basis.
7. Identifying potential risks is the first step that reveals what, when, where and how
something may affect the normal operations of our company. Risk identification
involves not only risks that currently affect your business, but also risks that may
occur in the future.
Practice And Evaluation:
1. What challenges do businesses face in the digital age?
2. What do you know about the classification of business risks based on their source?
3. Why is business risk identification so important in business 5.0?
4. Name three ways to identify business risks early on!
5. What factors do you think cause business risks?
LOSS LIST POTENTIAL
Introduction:
Risk management is one of the most important parts of an organization or company's
management strategy. Risk management can increase success and reduce the likelihood of
uncertainty and failure of a company's goals. Risk is associated with the event of the
possibility of something detrimental, unexpected and unwanted. Risk according to Rustam
(2017) is a possibility of unwanted results and can cause losses if not anticipated or managed
properly.
The first stage in the risk management process is identifying risks. According to Darmawi
(2010) risk identification is a continuous and systematic process carried out in identifying the
risk of loss to the results of a project including wealth, liability and company personnel.
Some of the things that company managers do in identifying risks are by way of:
1. Knowing the possibility of losses that may arise.
2. Estimate or measure the size of the risk.
3. Determine the most economical risk management method.
Risk identification is very important for a risk manager, to develop a strategy used to
overcome all potential losses. The main stages in identifying risks according to Abbas (2012)
are:
1. Orientation is the risk manager's understanding of the company's goals and functions.
2. Compile list losses that possible befall the company (check-list).
3. Search for potential losses with a systematic approach based on the list in point (2).
The identification process depends on the type of project/business/enterprise that is
carried out based on the ability or expertise of the risk management team. Some steps that
need to be used in the risk identification process according to Fandini (2011) are:
1. It begins with the collection of events or occurrences that may pose a risk to the
company.
2. Performing risk grouping aims to prevent repetition of events and can help management
in the risk analysis process.
3. The formation of a team involved in identifying risks, this team includes project
members, the project manager of the risk management team, as well as experts from
outside the project team who understand the project, shareholders and risk management
experts.
B. Benefits Disadvantages List Potential:
Identifying risks will result in a list of potential losses from the business. The list of
potential losses or check list is compiled to find out the occurrence of any possibility that
befalls the business. This list can be used as a basis for determining risk control policies.
Sources of information that can be used as material for making a list of potential losses
according to Sriyono (2019) include:
1. Data from insurance companies.
2. Information from Insurance issuing body
3. Information from the American Management Association (AMA)
4. Information from the Insurance Risk Manager bond.
5. Information/Releases from the police.
The benefits of a potential loss list for a company are essentially:
1. A list or chek-list that can support the achievement of various goals, this relates to the
management of companies in general.
2. It is a systematic way to collect information about other companies that are related to
their business activities.
Potential loss registers provide benefits to overall business management activities, the
benefits of potential loss registers for risk managers include:
1. As a reminder to risk managers of the losses that could befall their business.
2. Collector Information that provide overview to mitigate potential risks to the business.
3. Comparator in reviewing the planning and evaluating the implementation of the risks that
have been prepared.
C. Classification of Losses List Potential:
Every business as a whole experiences potential losses, these can be classified by:
1. Loss that occurs to property, which is categorized into:
a. Direct losses are losses that are directly related to the cost of replacing or repairing
assets such as loss of stolen equipment, building fires, or other unforeseen events.
b. Indirect losses are events that cannot be directly linked to the event that occurred,
such as losses caused by equipment or fixed assets reducing their useful functions due
to external factors.
c. Net income loss, which is revenue minus expenses, is a loss caused by the
malfunctioning of production equipment, storage equipment and others due to
damage.
2. Loss in the form of debt, is a loss in the form of an obligation to another party due to the
fault of the project / business, for example, the provision of compensation.
3. Personnel losses or losses that befall human resources including their families, such as
death, work accidents, incapacity due to age, and limitations of human resource
incapacity.
Based on this classification, a risk manager is needed who has extensive experience and
always studies and evaluates the events or events experienced, so as to be able to deal with
and provide solutions quickly to minimize risks in the event of a loss.
D. Risk Identification Methods
Methods used to identify risks include:
1. Create a questionnaire or questionnaire to analyze risks.
2. Use or analyze financial statements.
3. Create a flow-chart of the flow of goods from raw materials to finished goods ready for
sale.
4. Conduct on-site inspections.
5. Interact with each section/department within the company.
6. Interact with external parties.
7. Analyze contracts that have been made with other parties.
8. Create and analyze statistical records of the various losses suffered.
9. Conduct an environmental analysis.
E. Loss of Assets :
Assets are a set of rights derived from a part of a real asset that has a definite economic
value. These rights are obtained in various ways, so risk managers need to know and
understand the division of assets, causes of losses, types of ownership and be able to calculate
the value of losses.
1. Division of Types of Assets:
Property loss is a loss that befalls the company's property in the form of property such as
land and buildings as well as personal property, namely in the form of goods that are not tied
to land which are divided into:
a. Goods used in production activities and other company activities (raw materials,
auxiliary materials, spare parts, complementary materials and so on).
b. Manufactured goods that the company is ready to sell
2. Causes of Loss:
The causes of losses to property according to Arta, et al (2021) can be divided into:
a. Physical hazards are the costs of losses that arise from non-human causes such as natural
disasters.
b. Social hazards are hazards that arise due to deviations in human behavior from the
prevailing norms such as embezzlement, theft, fraud and deviations in behavior carried
out by humans in groups such as strikes, demonstrations, riots and so on.
c. Economic hazards are hazards of loss caused by the forces of internal and external
factors such as inflation rates, price changes, competition and so on.
3. Property Loss Subject:
With regard to ownership and who is responsible for suffering property losses, it can be
categorized into:
a. Ownership:
Ownership of property is sole ownership that comes from the results of purchases,
confiscations, gifts. If the property is affected by a peril (disaster or calamity), then the
owner will be responsible for the loss.
b. Loans with collateral:
Secured credit is credit that will be granted with collateral. The collateral can be in the
form of tangible or intangible goods. Creditors who provide credit with collateral have
rights or shares in the assets used as collateral. The creditor will suffer losses if the
pledged property is no longer in accordance with the beginning of the pledged time,
causing the non-payment of part or all of the debt.
c. Conditional sale and purchase:
Liability for losses incurred in conditional sale and purchase transactions is dependent on
the conditions specified in the contract in question. The internationally applicable
provisions are known as the Uniform Commercial Code, where the general provisions
can be divided into:
1) Loco warehouse (seller), meaning that all losses that have occurred after the goods
leave the seller's warehouse, will be fully the responsibility of the buyer.
2) Franco warehouse of the company concerned, meaning that goods that have become
the owner of the buyer when they are in the company's warehouse, then the shipping
costs have been paid by the buyer. Therefore, any losses incurred thereafter are the
responsibility of the buyer.
3) Franco warehouse (buyer) or destination, meaning that the new goods belong to the
buyer has been delivered at the buyer's warehouse by the transportation company, so
that any losses that occur before delivery become the responsibility of the seller and
the transportation company acts as the seller's representative.
4) Free Alongside Ship (FAS), which means that the goods become the property of the
buyer when the goods are ready for transportation, so any losses during the
transportation of the goods are the responsibility of the buyer.
5) Collect on Delivery (COD), meaning that the goods still remain the owner of the
seller even though they are in the hands of the buyer until the goods have been paid
in full. So the seller still has a lien on the goods until the price of the goods is paid in
full even though the transportation costs have been paid in full by the buyer.
6) Cost Insurance and Freight (CIF), meaning that ownership of the goods will transfer
to the buyer when the goods are handed over to the transportation company
accompanied by documents such as insurance, transportation and proof of
ownership.
d. Lease:
In general, the lessee does not have any liability for the loss of the leased property
affected by the peril, but there are some exceptions among which if:
1) Under customary law the tenant is liable for damage to the leased property resulting
from the tenant's carelessness.
2) The lease contract stipulates that the lessee must return the property to the landlord
in the same good condition as when it was received, so any damage is the
responsibility of the lessee.
3) The lessee makes changes to the leased property in order to benefit from the
changes.
e. Bailments:
Agreements between the bailee (the person or entity who temporarily controls another
person's property) and the bailor (the owner of the goods) are called bailments. The
liability for losses resulting from such bailments depends on the content of the
agreement. However, the bailee must be liable for the loss of the property temporarily in
his possession. Some characteristics of this relationship (bailments) are:
1) Identity of property ownership is in the hands of the bailor
2) Ownership of property is temporarily in the hands of bailee
3) The transfer of ownership or control to another person of property must constitute a
transfer of position from a bailee and must have the consent of the bailor.
f. Easement:
It is the right of a person to use property that does not belong to him from the right of use
is recognized by the owner. If there is a loss, then the utilization of the property is the
responsibility of the person who uses or utilizes.
g. License:
It is a privilege that has been granted by the owner of the property to another party to use
the property for a more specific purpose. If there is a loss due to such use, the loss is the
responsibility of the owner or in accordance with the agreed agreement.
4. Calculating Loss Value:
Some basic measurement methods used in estimating the value of losses that have
occurred include:
a. Calculate the true cost of assets.
b. Based on book value.
c. Based on the tax assessed value.
d. Calculate the cost of remanufacturing.
e. Based on market value.
f. Calculate cost replacement minus depreciation and obsolescence.
F. Liability for Loss of Other Parties :
Responsibility for the loss of other parties arises due to the possibility of the company's
activities causing intentional or unintentional loss of property or other personnel. Legal
liability is broadly divided into civil liability and civil criminal liability. Civil liability must
be assumed by a person or business entity arising from contract, negligence, fraud and arising
from other acts.
Liability for actions in relation to others arises because of the employee's own actions and
arises because of the relationship of contact or cooperation between the perpetrator and the
company. Meanwhile, harmful actions related to the implementation of a contract are
categorized as violations. So that anyone who violates the contents of the contract and causes
losses must be responsible for these losses.
Companies should be responsible for personnel losses incurred by employees and their
families. The company should pay attention to personnel losses due to:
1. To attract and retain high-quality employees.
2. To increase employee work productivity.
3. As one of the materials in collective bargaining agreements with employee organizations.
4. To take advantage of the benefits provided by the tax system relating to the provision of
social security.
5. As an effort to improve employee welfare beyond the salaries and wages that have been
given.
6. To build a corporate image related to HR management.
7. To comply with statutory provisions relating to employee welfare.
8. As an excuse for companies that do not want to include their employees in the labor
insurance program.
The categories of liability for personnel losses are divided into:
1. Direct losses, which are losses due to work accidents that have a direct impact on the
company, include:
a.Medical expenses or compensation for work accidents that result in minor, severe,
disability and even death. So that the company must pay medical expenses and
accident benefits in accordance with applicable regulations.
b. Damage to production facilities is caused by accidents such as fire, and other
damage, so the company will incur insurance costs for production equipment or
increase security costs to reduce the level of risk.
c. Fixed labor wages must be paid to employees who are victims of accidents.
2. Indirect losses include:
a. Loss of man-hours in the event of a workplace accident that causes activities to be
temporarily halted to assist the injured, respond to the incident, repair damage and
investigate the accident.
b. Production losses accidents can have an impact on production losses caused by
damage to equipment and injuries to workers, so the company must temporarily stop
production which can have an impact on lost opportunities for profit.
c. Social costs of accidents have a social impact on both the victim's family and the
surrounding social environment.
d. Accident investigation costs, which include the costs of investigating the cause of
the accident, visiting the injured workers, arranging and determining and continuing
to replace the injured workers, and recruiting and training new workers.
e. Consumers' trust and image of the company becomes negative because it is
considered not to care about safety, inconvenience and damage the environment.
Because building a company image is a tough thing and requires a long process.
G. Summary Material:
1. Risk is a situation that will be faced by a person or company that may experience a loss.
2. To reduce risk, continuous risk identification is required before the occurrence of an
event that can cause loss or damage (direct cause of loss). These identifications include:
property, liability, and personal losses.
3. Identifying risks will result in a list of potential losses that are essential for a manager to
develop a complete strategy to overcome and reduce all potential losses.
Practice and Evaluation:
1. Why is risk identification so important for companies?
2. Mention the benefits of a potential loss list for the company!
3. Explain why analyzing financial statements is one method of identifying risks!
4. Explain the causes of potential losses!
5. Explain the difference between direct and indirect losses!
s
Students also viewed