IMPLEMENTATION OF RISK MANAGEMENT IN THE
GOVERNMENTS OF ASIAN COUNTRIES
Introduction
The implementation of risk management is a proven practice that provides many
benefits (Susilo, 2018). Through risk management, managers will avoid the shock effect of
potentially disruptive conditions in the future. This shock effect does not occur because
management has predicted this condition in advance. When this unexpected condition occurs,
management has prepared itself with a mitigation program so that the negative impact can be
minimized.
Risk management as a specialized and significant process is a relatively new approach.
The concept of risk management was first declared in 2004 when the COSO Commission
issued COSO ERM. Through Risk Management, managers are directed to identify early on
the potential that can interfere with achieving goals. Potential disturbances are then analyzed
to determine the mitigation that must be done so that potential disturbances can be minimized
so that they do not have an impact on efforts to achieve goals.
In the world there are at least two moments that prompted the establishment of risk
management (Aebi et al., 2012). The Asian Financial Crisis during 1998-2000 and the Enron
and Worldcom events. The Asian Financial Crisis hit many countries in the Asian region.
Banking was the sector most affected by the 1998 economic crisis. The collapse of banks
during the 1998 economic crisis occurred because they were not prepared for the risk of
drastic currency depreciation against the USD in a short period of time. Therefore, in the early
2000s, banks in Asian countries began to implement risk management and followed by
implementation in corporations. The implementation of risk management was then followed
by other sectors such as corporations in various industries. Early identification of risks and
preparation of mitigation plans will provide confidence and the ability of corporations to
anticipate various possibilities that will hinder efforts to achieve goals. Through risk
management, Indonesian banks and corporations were able to survive the world crisis in 2008.
Governments and other public sectors have learned the benefits of implementing risk
management. As the government has set objectives, and thorough risk management,
government officials will identify potential obstacles that could potentially disrupt the process
to achieve the objectives. When potential obstacles are identified, the office will design and
prepare mitigations to reduce the adverse impact of the obstacles. Risk Management has a role
in policy selection and decision making (Bracci et al., 2021).
This research will examine and identify how Asian governments implement risk
management. The paper will provide dynamic figures among these countries. Risk
Management is a new concept, only established in the early 2000s. The public sector and
governments will adopt risk management in key activities.
Implementation in government is not easy (Hudin & Hamid, 2014). Risk management
must prove itself to have a real and necessary contribution to assist the management of the
government administration. It is suspected that this has not been perceived so that it has not
fully implemented risk management ideally and has become a permanent part of the
organization of a state agency. This article will conduct a literature review on risk
management in general and risk management in the government sector. In addition, the article
will also conduct a review of the implementation of risk management in several other
countries for consideration. This research will attempt to identify a literature review with risk
implementation specifically in Asian governments.
Methods
The research is conducted with a systematic literature review through a review starting
from a search for literature related to risk management in general and then filtering to be
associated with risk management for governments in general and Asian governments in
particular. This research will also explain the implementation of risk management in selected
countries among Asians.
Risk management implementation in government is obtained through information on
government structures or risk practices on government websites. Facts represent risk
implementation.
When analyzing the application of risk in government, this study is supported by
relevant risk research in the same country. The application of risk management in government
has learned from government websites on the internet. Risk management in these countries is
supported by relevant journals.
Results And Discussion
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.
Overview of Risk Management
Risk management has now become an integral part of the corporate sector and the
public sector. Risk management has a positive influence and is part of the decision-making
process for better decision making (Cole et al., 2017). The decision-making process is better
because management with the help of risk management can choose the best alternative.
The alternative selected through the risk management process is the best. The process
of selecting and determining alternatives is carried out by considering the various risks
associated with each alternative. After going through the assessment process, management
will determine the alternative that has the most acceptable risk to management. This is one of
the contributions of risk management in the decision-making process.
Then through the application of risk management, managers and leaders will identify
various factors that can interfere with achieving goals. These confounding factors are then
analyzed and responses are developed so that the impact on efforts to achieve goals can be
managed properly. The application of risk management has an impact on avoiding the shock
effect of a condition that disrupts the future because it has been predicted in advance.
This concept emerged after the crisis. Risk management is a valuable legacy of crisis
learning. COSO Internal Control-Integrated Framework was published in 1992 to improve the
appearance in financial reporting among American companies in the 1980s. Meanwhile,
COSO ERM 2004 also came after many companies went out of business because they were
unable to anticipate unexpected problems such as the cases of Enron, Worldcom, in the early
2000s, and the Southeast Asian financial crisis in 1998-1999.
Risk management is then applied to many companies. Companies after studying the
crisis that occurred gained many benefits from implementing risk management. The
application of this approach made many companies survive the global crisis in 2008 and 2018.
There were even companies that failed because they were unable to mitigate the impact of the
crisis that occurred (Fadun, 2013).
As a system, risk management consists of certain steps. For each step, there is a key
success factor (KSF). The stages are: (1) Readiness of the organization to implement risk
management; (2) Formulating risk management design and implementation; (3) Managing it
in risk management administration. The key successes of each stage contribute something to
success. Strategy plays an important role since resource allocation and effort contribution to
the Risk Management System (RMS) project from the preparation and readiness, design, and
implementation stages. Ahmed and Manab (2016) concluded to make RMS successful
requires seven factors. These factors are Compliance, Risk Culture, Risk Management
Information System, Risk Knowledge Sharing, Competence, Innovation, and Leadership.
From these key success factors, the author concludes that to achieve success in a risk
management system, a combination of many factors is required. These factors are leadership,
culture, competencies, and information systems. The success story of risk management
implementation is not just a merger but also in many organizations (I. Ahmed & Manab,
2016).
The Risk and Insurance Management Society (RIMS) defines "the key to the success
of ERM practices depends on the level of maturity an organization demonstrates in seven
behavioral attributes". The seven behavioral attributes are:
Adoption of an ERM-based approach
ERM process management
Risk appetite management
The root causes of discipline
Uncovering risks
Performance management
Business resilience and sustainability.
The seven attributes are part of the RIMS Risk Maturity Model (RMM) for ERM
assessment.
In recent years, when an organization decides to start implementing risk management,
there is guidance from professional regulatory bodies. Professional organizations have
researched risk management continuously and issued guidance on it. The product of this
research is a framework.
There are currently two main frameworks in the field of risk management. These
frameworks are COSO Enterprise Risk Management (ERM) and ISO 31000. These
frameworks are very powerful and clear to explain the paradigm, process, and implementation
of risk management (Fox, 2018; Frigo & Anderson, 2014). COSO ERM was first published in
2004. In its development, COSO ERM has been updated in 2017. While ISO 31000 was
published in 2009 and then updated in 2018. These two frameworks are a reference for
organizations that implement risk management. The concept can be applied in Industry and
Public Sector.
Management should implement one or a combination of all risk frameworks within
their organization. The framework describes the boundaries and guidelines for implementing
risk management. From the framework, we conclude that there are environments and stages of
risk management implementation. Technically, the stages of risk management are from
objectives to reporting. All risk management frameworks are flexible and can be implemented
in many types of organizations, including Risk management is not a new concept in the US
federal sector. It has been used in the private and public sectors for decades.
Risk Management in the Public Sector
The growth of risk management is not limited to the private sector but has also
affected the public sector. Mirroring the private sector, the public sector now generally sees
risk management as an important dimension of good governance and as an aid in the
achievement of organizational objectives. The various governance codes that have been
implemented in parts of the public sector are an expression of this (Paape & Speklé, 2012).
Although both risk management concepts can be applied in the private and public
sectors, the public sector has unique problems. This problem lies in management objectives
where companies focus on generating profits. The government sector has the main objective
of providing services to the public but still has to survive and thrive. The growth of risk
management in the public sector has been slower than in the private sector. At the same time,
currently, the theory of risk management in the public sector is lacking and explanations are
limited (Bracci et al., 2021).
The public sector is less risky than the private sector. Governments have more
certainty than corporations. The government as an organization has goals in the short and long
term. Risk management refers to a process that serves as an essential component of corporate
governance, as it directly affects the achievement of the organization's business objectives.
Risk communication in the public sector is often overlooked.
The public sector or government also then implements risk management. Risk
management can be applied to the government (Bracci et al., 2021). Risk Management is one
of the critical successes in any government system (Abdul Gani et al., 2020). The main risk
management concepts are COSO ERM and ISO 31000, similar within companies. The risk
framework is universal and can be applied to organizations of any kind. Through risk
management, it will increase the possibility of achieving the targets and objectives of the
activities that have been set and minimize the possibility of failure. When management
successfully mitigates risks, the likelihood of achieving targets and objectives increases.
The government and public sector utilize the application of risk management to
improve the quality of the accountability process. By using risk management as part of the
accountability tool, the Government will submit a more comprehensive accountability report
(Palermo, 2014). In recent years risk management in the public sector is growing. Risk
management is part of the new public management (Bodemann et al., 2015).
Companies implement risk management first because the company has the flexibility
to modify business structures and processes so that it can quickly make adjustments.
Companies after learning the benefits can immediately implement risk management.
Meanwhile, the government has constraints in organizational adjustment. This theory is
reflected in the research results in the following section.
The risk management in government research literature for each country is detailed
below.
Indonesia
Risk management in Indonesia has not been fully adopted by public administrations,
including the government (Keban, 2017). In Indonesia, the public sector is considered
relatively safer than the private sector private sector (Anandari & Nuryakin, 2019). Due to the
assumption that the public sector is safer, the growth of risk implementation in government is
slower than in corporations.
Corporations in Indonesia, have implemented risk management starting several years
after the national multidimensional crisis in the late 90s. The implementation of risk started
from the Bank or financial industry in early 2000. And now most corporations in Indonesia
have implemented risk management in their business structure and practices. They have
learned and recognized the benefits of risk management in practice. Risk management has a
significant positive impact on corporations (Muslih & Marbun, 2020).
Following the corporations, several ministries at the center, provinces, and cities
began to implement risk management. Risk management is emerging in the public sector in
Indonesia (Pradana & Rikumahu, 2014). Some governments have implemented risk
management as part of the structure and are formal, and others as ad-hoc or committees.
Formally, there is no risk management that guides the continuity of patterns in achieving
established organizational goals (Nurkholis et al., 2020).
Bangladesh
Bangladesh was the first South Asian country to establish a disaster management
ministry. Risk management has a part of the ministry (Davis, 2014). This is necessary because
Bangladesh is one of the most disaster-prone regions in the world. A large number of natural
and man-made environmental disasters hit the country in the previous years (Khairullina et
al., 2019).
Risk management has been implemented in Bangladesh's Private sector. Regarding
disaster management, the private sector is a key element in strengthening Bangladesh's
Disaster Recovery capacity (Izumi & Shaw, 2014).
Cambodia
Public-Private Partnership (PPP) projects have been implemented in Cambodia since
1993 mostly in the energy sector. Partnerships are an effective risk allocation strategy.
Cambodia has instituted a central PPP unit in the ministry of economy and finance to
coordinate with implementing agencies in preparing, reviewing, and selecting PPP projects
(Sar et al., 2020). Risk Management in Cambodia is implemented through partnerships.
The Royal Government of Cambodia (RGC) has established a Risk Management Unit
(RMU) as the implementing agency (Sreya, 2020). The RGC has established RMUs in every
government office.
China
In China, there are plans to improve public accountability, most government offices
have started to identify and manage risks. They believe it is part of civil society. Public sector
progress follows the private sector. The conditions are the same as other countries.
As the Chinese Government focuses on clean government, and severe penalties for
corruption, most public institutions manage clean government risks. Risks have become part
of their daily activities and they need to reduce the likelihood of their occurrence and mitigate
their losses. It is emphasized that corruption prevention is realized through effective
fulfillment of duties by public departments and analysis of risks in them.
Local governments or municipalities in China have learned from debt management. In
the past, most local governments faced serious problems related to debt management in public
financial management (Guo et al., 2022). And local governments have actively improved
local government debt risk management systems, build and improve local government debt
risk regulatory mechanisms, and manage constraints and barriers to effectively strengthen
local government debt risk management.
India
Risk management in India is more prevalent in corporates than in the public sector.
Many studies reveal that corporate India is aware of risk management techniques and many of
them use the same techniques to manage various risks. But not in the public sector. Many
officials in the public sector ignore risks and the application of risk management techniques is
still in its infancy.
Another study concluded that most construction projects do not have systematic
procedures for dealing with risks. Risk management is done in a very informal way. (Patel,
2013). There is an opinion in India, the government as the insurer of last resort. Government
as Risk Manager.
Japan
As Japan experiences frequent natural disasters, risk management focuses on disaster-
related risks. Natural disaster risk management has been carried out from the community to
the municipal, prefectural, and national levels (Jimee et al., 2019). Japan focuses on
sustainability in any aspect. Sustainability has many dimensions, including various aspects of
environmental, social, and economic sustainability. Risk analysis is related as part of
governance for sustainability (Shiroyama et al., 2012).
Japan has been implementing Public-Private Partnerships for a long time. This is part
of the risk mitigation for each partner. In recent years there is a new concept of "Private
Finance Initiative (PFI)". PFI is based on the concept of clarifying responsibilities with
contractual governance, which solves the problem of ambiguous risk sharing. Since the
definite risk allocation of PFI makes it possible to generate private sector ingenuity, many
successful projects have been implemented to achieve economical and efficient operations
(Matsumoto, 2012). From this point of view, risk management in Japan has been involved
since many years ago and has become part of the interaction.
Malaysia
Enterprise risk management in Malaysia is similar to government structures that do
not work well to mitigate potential risks. Malaysia has implemented risk management as a
current practice in business and managing the prime minister's office (Waseem-Ul-Hameed et
al., 2017). The implementation of risk management in Malaysia is through the risk
management committee (Rimin et al., 2021).
Enterprise Risk Management is a holistic risk management concept and in Malaysia
the implementation of ERM has started in 2011. The private sector has taken the initiative to
implement ERM and was followed by the public sector. The implementation of risk in the
public sector is done by the risk management committee.
Pakistan
Risk management in Pakistan, similar to other countries, has been initiated by banks
and corporates. The banking sector in Pakistan has grown during 2002-2007, and risk
management has also grown in banking.
Risk management in the public sector is embedded in activities. Similar to Bangladesh
for disaster risk management, Pakistan has organized a risk office (Cheema et al., 2016). For
other activities, risk management is handled by the Risk Committee (R. Ahmed et al., 2016).
Philippines
Risk implementation in the Philippine government has been organized through formal
positions. There is a risk office that handles risk management in the government (Fernandez
& Shaw, 2013). When facing the risk of natural disasters, the Philippine Government
organizes Community-Based Disaster Risk Management (CBDRM). CBDRM aims to reduce
risks from natural disasters (Fernandez et al., 2012).
Qatar
Risk management in the Government of Qatar is managed through the risk
management department in government offices. The risk management department has a role
to establish interfacing departments to manage risks (Abd Rahman, 2020).
In the Corporate and Banking Sectors, Risk Management has been implemented as
part of the business. By implementing risk management, the business will run more carefully
(Alhammadi et al., 2020).
Singapore
Singapore organizes risk management under the government's risk office. The Singapore
government has followed the private or corporate sector for risk implementation. Singapore
corporates have implemented risk management earlier than the public sector.
South Korea
Risk management in the South Korean government has been managed by risk
management committees or on an ad hoc basis (Jun & Rowley, 2014) and (Bae et al., 2016).
Risk management is used by the government through committees.
Thailand
In Thailand, risk management is part of a public organization's responsibility to the
country's population and assets. In government offices, there are risk management units
(Wandee et al., 2017).
United Arab Emirates
The United Arab Emirates (UAE) has become the largest market for Public-Private
Partnership (PPP). Through the scheme, all risks of projects or activities in the government
have been shared by two parties. The UAE government conducts risk management by ad-hoc
committees in PPP (Al Saadi & Abdou, 2014) and (Alzaabi et al., 2020).
Vietnam
Vietnam manages risk management through an office. The government manages risks
by an office such as Community-Based Disaster Risk Management in Vietnam. In Vietnam,
the public sector is managed by a formal structure.
Findings
The implementation of risk management in Asian countries varies. The facts of risk
management implementation in Asian countries are:
Risk management has been implemented in a formal structure
In this condition, the Government has organized risk management with a formal
structure and part of the government organization.
Risk management has been implemented through a blended formal and informal model
The government is said to be blended, having implemented risk management with
formal structures in some ministries, with the rest implementing on an ad hoc basis. The
government is in the process of organizing and managing risk management to a formal
organization.
Risk management has been implemented through ad-hoc committees
Some Asian countries have implemented risk management through organizing or
informal committees. The committee members are a combination of various departments in
the government sector. These facts were deduced from information during the literature
review and research.
From the analysis of risk management literature in each country, the following
conclusions were drawn:
Eight countries have implemented formal structures: Bangladesh, Cambodia, China,
Japan, Philippines, Qatar, Singapore, and Thailand.
Three countries implement blended risk management: Indonesia, Pakistan and Vietnam.
And Four countries have not implemented formal risk management: India, Malaysia,
South Korea, and the United Arab Emirates.
Conclusion
Based on the results and discussion of the research, it can be concluded that risk
management has been implemented in the business and provides an early warning system to
management of potential obstacles in the future. With the implementation of risk, the
likelihood of achieving goals increases.
The government has followed suit to implement risk management. Through the
implementation of risk, governments have the motivation to increase the likelihood of
achieving goals. The fact that in Asian countries the implementation of risk management is
very diverse. Some Asian countries have implemented risk management as part of the
government structure, some countries have not formally implemented risk management, and
some countries have blended.