1 / 6100%
Risk Management
Risk is an uncertain event. If it does, it will have a positive or negative effect
on one or more organizational goals. Risk is actually something that creates an
opportunity for an event and all its unpleasant consequences. Risk is basically
defined as a multidimensional concept of the likelihood of dangerous events and
uncertainties affecting organizational goals. Risk is widely used to describe an
event that relates to the likelihood of an outcome occurring, where there is
uncertainty with respect to the future, while the possibility of more than one
outcome and the final outcome is unknown or uncertain. Risk is generally defined
as a combination of consequences and associated probabilities or uncertainties.
On the other hand, understood as a situation involving the potential occurrence of
an intentional harmful event, risk is generally defined as an active triplet or value,
threat, and vulnerability.
Every organization defines its long-term and short-term goals based on its
vision and mission, which has a set of operational plans to achieve them. These
programs have the potential to be associated with threats and opportunities in
achieving organizational goals. The goal of implementing risk management
standards in most organizations is to increase productivity and reduce program
deviations. Therefore, risk management serves to organize in a structured manner
the actions necessary in identifying, evaluating, and responding to risks in a
project. The success or failure of a project in achieving its predetermined goals
depends largely on the suitability of its execution system. Effective risk
management is essential to achieve project objectives and meet sustainable
development (Safaeian, 2022) because risk requires a strong understanding of
how to manage uncertainty and complexity (Noor, 2018). Uncertainty and
probability cannot be ignored in the context of risk management if we want to
make good decisions (Amundrud, 2017). Risk management seeks to identify the
right balance between return and risk. Certain risks are accepted if justified, both
from a technical and financial point of view (Unni, 2020).
Risk management is a systematic process in carrying out initial
identification, analysis, planning, and control of risks in an organization with the
aim of minimizing adverse effects and events and maximizing the possibility and
impact of positive events, where this is referred to as opportunities. Risk
management is also defined as the identification of risks as well as the process of
assessing and applying specific methods to reduce risks to an acceptable level.
Most managers in organizations recognize the need for risk management which is
considered a key process in the most difficult risk assessment and prioritization
activities (Sousa, 2021)(Jokar, 2021) (Kheradmand, 2021) because it is closely tied
to the effort to "control" the unknown by applying knowledge based on the world
order (Noor, 2018).
There are two stages of the process in project risk management as follows:
1. Risk assessment including risk identification, analysis, and prioritization. 2. Risk
management includes risk management planning, risk prevention measures,
follow-up, and corrective actions. (Barghi, 2020). The process is important as a
technique used to reduce a lot of costs in the end and make better management
decisions. If organizations do not consider the dimension of uncertainty or
possibility, there is a risk of misdirection in decision-making on the use of
resources (Amundrud, 2017). Each generation source is an asset with unique
performance and risk attributes. Therefore, estimating the optimal production
composition can be considered an asset allocation problem. The reward is the
benefit of the investment, while the risk is uncertainty regarding the possibility of
causing financial losses (Unni, 2020).
Risk managers and development teams will be better equipped to deal with
risks and their impacts if they identify risks early and create mitigation plans to
deal with them rather than strategize to deal with risks as they occur. If this has
been applied by the organizational team, more projects will be completed on time
and within the allocated budget.
However, this task can be very complex and inefficient if risk management
is not considered from the beginning of the project (Fakhratov, 2020). Risk is
necessary for a valid contract (Noor, 2018) so risk managers must be able to
provide a unified standardized model of the risk management process that
balances the interests of all stakeholders and then identifies and develops
allocation mechanisms to manage the identified risks. Managers must be able to
manage the multi-step process in risk management well which typically includes
risk identification, analysis, response plan, response implementation, and
ongoing risk monitoring as part of the overall risk management strategy of the
project. At various levels of organizations, from the international government level,
to the company, to, the individual level, it is very necessary to characterize the
level of risk (Amundrud, 2017). Risk control is achieved through portfolio
optimization which allows for greater diversification.
Companies must establish and maintain appropriate systems and controls
to manage operational risks. This is usually caused by errors or shortcomings in
administrative processes and systems. These systems and controls typically
cover the entire operational lifecycle of an organization. Therefore, they must
reflect the various activities that are carried out, integrated, and updated regularly
to reflect customer needs and market changes.
Process and system risk can be defined as a process or system failure due
to poor design, complexity, or poor performance, resulting in operational losses.
As a result, businesses may face a variety of problems, including an inability to
fulfill orders, poor quality control, manufacturing errors in final finishes,
irregularities, and an inability to protect information. As reliance on computer
systems increases across companies, information technology now has the
potential to turn the risk of small manual processing errors into major disruptions.
Although not specifically stated in the dictionary definition, control in the
business sense is not the plural form of control. Perhaps, the best way to explain
the difference between the two is that control in general is about means and
control in business is about ends. Synonyms for control are measurement and
information. Synonyms for control are direct and restrictive. The control handles
pre-recorded events. Control is concerned with providing strategic direction and
future events. Financial management, therefore, refers to the recording of past
financial events to provide information to managers to determine future direction.
Thus, the control has an important time component. As with ships, turning or
stopping requires considerable early warning. Any delay in information will
minimize the options available. Control in a company includes: (1) control cannot
be objective or neutral, (2) control must focus on results, and (3) control
distinguishes between measurable and non-measurable events. There are three
main characteristics required for both. Business communication requires
standard controls. This allows, for example, finance, marketing, and business
development to be structured and formatted in exactly the same way, making it
easy to combine, evaluate, and view trends across departments.
The risk with control is a lack of quality. Unless it is economical, reasonable,
accurate, timely, simple, and actionable, it hinders rather than improves
management. The fewer effects required to gain control, the better the control
design will be. The less control you need, the more effective it will be. Controls
should be meaningful because they measure important issues or events and
relate to key business objectives. Control must be meaningful and balanced (i.e.
not open to interpretations that could lead to inappropriate or ineffective behavior)
in order to have such an impact. A congruence control is a control that determines
the exact magnitude of the ratio. "We have a 21% market share" sounds pretty
good, but it's usually imprecise and meaningless. Timely control is necessary to
ensure sufficient time to act before a negative event turns into a serious adverse
event. Simple controls should be easy to understand. Otherwise, it would be
confusing and time-consuming.
Any company that is listed on the stock exchange and is required to comply
with the Listing Rules and Handbook must notify Finite State Automaton (FSA) of
any operational risks that may have a significant regulatory impact. These
requirements include significant failure of the system and its controls, significant
operating losses, or notice of intent to enter into or materially modify a material
outsourcing agreement. So control alone is not enough. If it doesn't work, you
should be able to tell the difference. A pre-placed trigger point is required to issue
a finite state machine (FSA) notification when certain parameters are exceeded.
Companies in regulated industries must ensure compliance with the
restrictions in place. An example is the pharmaceutical industry which is subject
to many trade-offs and controls. The price and profit realization of branded drug
manufacturers are regulated by the Pharmaceutical Pricing System (SPHO). SPHO
has three objectives: 1) Securing safe and effective drugs at reasonable prices for
the National Health Service; 2) Fostering a strong and profitable pharmaceutical
industry with continuous R&D capabilities; and 3) competitive efficiency;
facilitating the development and delivery of innovative medicines. The
pharmaceutical industry also has to face pressure from other parties. In 2005, the
Department of Commerce released a survey on the pricing practices of
pharmaceutical companies. The Treasury Department has been putting pressure
on it to address the wasteful public health spending.
Businesses must make provision to resume critical process or system
operations if they are unavailable or broken. These risks are related to information
technology and unreliable service providers that can disrupt business processes.
Proactively managing these risk attributes requires knowledge of incident and
conflict/problem management, information technology service management,
business continuity, and disaster recovery. In many organizations, a temporary
failure of a critical computer system can cause significant business disruption.
Additionally, permanent damage to critical servers and software applications can
disrupt business operations for days.
Risk indicators are used to facilitate quantitative assessment and risk
monitoring as well as periodic risk mitigation measures. Establishing indicators is
only valuable if data is collected and reviewed regularly and a specific response
plan is developed to address the findings. An initial review can determine that
more information needs to be gathered to implement a more meaningful answer.
Metrics are tailored to specific service businesses and operational conditions.
Common metrics are: 1. bank loans against lines of credit; 2. raw material cost; 3.
income; 4. default of third parties; 5. shareholder complaints; 6. lawsuits; 7.
business continuity activities; 8. customer complaints; 9. Guarantee Agreement
and Confiscation Agreement.
Commitment Fulfillment, A process risk common to all businesses
related to transaction processing. Transaction risk is usually (but not exclusively)
related to manufacturing. The main business risk arises from failure to deliver on
promises made to customers in terms of time, quality, and quantity. This includes
errors that can occur at every stage of a business transaction including pricing,
design, manufacturing, sales, confirmation, and documentation. At every stage of
the trading process, the company is exposed to risks that may cause financial,
reputational and/or customer losses. For example, pricing errors in signing
contracts can lead to decreased profitability or losses and compliance issues can
cause customers to stop doing business with your company.
Production Process, Process risk (litigation) is generally a product defect.
Control charts have been used in manufacturing (Eppen 2001) in (Chapman, 2011)
to measure variability. The goal is to continuously reduce process variability until
no errors become an achievable target. Japan companies are world leaders in the
adoption and refinement of process improvement (risk reduction), and the quality
of their products is a testament to their variability management philosophy. Eppen
explained that Total Quality Management (TQM) began to have a major impact on
U.S. manufacturing in the late 1970s. U.S. electronics group Motorola has placed
process improvement at the top of its company's strategy. Motorola's approach,
known as the Six Sigma system, guides all of Motorola's processes, not just
manufacturing. The basic idea is to improve the process so that the chances of a
practical error can be zero. The purpose of a company's quality control is to carry
out variations (risks) throughout the production process of goods and services.
Documentation risk, Documentation risk can be considered as part of the
transaction risk because it is a step in the overall transaction process. Any
decision made because the information contained in the document is incomplete,
inaccurate, inconsistent, open to interpretation, and untimely or otherwise may
lead to untrue or erroneous business activities. This can lead to the wrong decision
when buying a company. As a form of documentation, contracts (Lam, 2003) are a
significant source of documentation risk, as evidenced by the large number of
legal cases. Every company, as a rule, has contracts with a number of third parties
at the same time. They are a potential source of controversy and disagreement that
can lead to legal action. When a dispute arises, senior management can be
diverted from their core responsibilities and disputes that have to be resolved in
court can take up a lot of time in management
Product Variation Risk is a risk experienced by manufacturers where
customers require: (1) specific features of their product that when added
distinguish the product from identical products and (2) products that are modified
to be shipped to a specific destination, when the product is typically distributed
among multiple locations (Eppen 2001) in (Chapman, 2011). Risk relates to the
burden of the process and how successfully it is responded to. Eppen cites the
sale of printers in Western Europe by electronics manufacturer HewlettPackard as
an example of variable risk, as follows. In general, different resources and
instruction sets are required for printers in each country. In its original design, the
power source was an integral part of the printer. The printer was assembled in
Vancouver, Washington, packaged along with the appropriate instruction
documents and shipped to a European warehouse. The process was redesigned
based on the delay principle. The printer can be assembled in the US and shipped
in bulk to warehouses in Europe. When the order arrives, the printer and its
corresponding power cord and instructions will be packaged and shipped to the
customer. These changes substantially reduce the level of inventory needed to
meet uncertain demand. Eppen explains that this is especially important for
products that measure obsolescence within a few months.
Based on his experience as a group risk insurance manager at Glaxo
Wellcome, Reddaway notes that for large organizations around the world, aspects
of operational risk management responsibility, both in the process, with theft, risk
accumulation, and recovery described, comprise these three main areas
(Reddaway & Glinski, 2001). Global companies face serious problems, namely
piracy and theft in regions such as Eastern Europe and Latin America. He puts the
risk of accumulation that arises when the shipment of goods and batches of goods
or containers gather in one place, such as while waiting for transportation, on a
ship, or in a customs warehouse. Reddaway also refers to a situation where
international regulations can stipulate that compensation must be made
according to the weight of the cargo rather than the actual commercial value of
the goods. Mitigation measures are referred to as legal and technical advice to
demonstrate the carrier's negligence and urge settlement based on actual
commercial value to the contrary.
Students also viewed