Elliot Book Chapter 9: Risk Assessment and Treatment

Foundations of Risk Identification

  • Identification must occur before management; organizations must identify both existing and emerging risks.

  • International standards like ISO31000ISO\,31000 and COSOERMCOSO\,ERM define identification as an initial step. COSOERMCOSO\,ERM specifically uses the term event identification.

  • Traditional risk identification focuses on loss exposures, or negative risks, that could interfere with achieving primary goals.

  • Key risks possess the greatest potential effect on an organization's ability to meet its objectives.

Risk Identification Tools and Approaches

  • Loss histories provide quantitative and qualitative data on known risks but serve as lagging indicators.

  • Checklists are easy for non-professionals to use and can be organized into the 44 quadrants of risk: financial, strategic, operational, and hazard.

  • Interviews and workshops involve stakeholders to identify risks in work activities before events occur.

  • Escalation or threshold triggers identify risk by comparing current transactions to prescribed criteria.

  • Audits (internal and external) identify negative risks as well as opportunity risks.

  • Top-down approaches involve senior management determining significant threats; disadvantages include a limited view of risks percolating in lower levels of the organization.

  • Bottom-up approaches include realistic employee observations but can be time-consuming to analyze.

Team-Based Identification Techniques

  • Facilitated Workshops: Rely on brainstorming and diverse groups to identify combined and cascading effects of risks.

  • Delphi Technique: Uses anonymous opinions from a group of experts through multiple rounds of queries (typically 22 rounds) to reach a consensus and eliminate group bias.

  • Scenario Analysis: Projects potential consequences of risks to assist in prioritization; it requires internal cross-functional teams for multidimensional views.

  • HAZOP (Hazard and Operational Study): A comprehensive review used primarily for complex scientific or engineering systems by subdividing projects into small components.

  • SWOT: An acronym for strengths, weaknesses, opportunities, and threats; it is used to determine the feasibility of new projects. Strengths and weaknesses are internal factors, while opportunities and threats are external.

Risk Registers

  • A risk register is a tool developed at the risk owner level that links specific activities to identified risks and evaluation results.

  • Best practices indicate that registers should be dynamic, interactive matrices updated continually by risk owners.

  • Registers prioritize risks based on organizational significance rather than simple formulas.

  • Dashboards and diary features in Risk Management Information Systems (RMISRMIS) facilitate follow-up and prioritize high-impact risks.

Risk Mapping and Appetite

  • Risk maps provide a visual matrix of likelihood and impact (consequences) to prioritize risks.

  • Risk Appetite: The total exposed amount an organization wishes to undertake based on risk-return trade-offs.

  • Heat Mapping: The use of colors (e.g., Red, Yellow, Green) to represent different levels of combined impact and likelihood.

  • Inherent Risk: The risk level before any treatment is applied.

  • Residual Risk: The current level of risk remaining after treatment efforts.

  • Optimum Risk: The level of risk that is specifically within an organization's risk appetite.

  • Risk Zones: Red zone risks should be exploited, controlled, or transferred; yellow zone risks should be evaluated by cost-benefit; green zone risks are managed via normal operational procedures.

Risk Treatment Process and Techniques

  • Treatment decisions are based on risk assessment (identification and analysis) and involve a continuous process of examination and implementation.

  • Avoidance: Ceasing or never undertaking an activity to eliminate the possibility of potential gains or losses.

  • Modification: Changing the likelihood or impact. For hazard risks, this includes loss prevention (frequency reduction) and loss reduction (severity reduction, such as sprinkler systems).

  • Transfer: Sharing risks through contractual arrangements, joint ventures, or insurance.

  • Retention: Assuming risk in which gains and losses are kept within the organization; it is often used for residual risk.

  • Exploitation: Maximizing expected gains for events with primarily positive potential outcomes.

Project Risk Management and the Critical Path

  • Project risk management focuses on completing goals within quality, time, budget, and boundary constraints.

  • Scope Statement: A clarifying document detailing objectives, deliverables, potential costs, and success measurements.

  • Critical Path: The sequence of activities in a project that takes the longest time to complete, determining the overall project length.

  • Slack Time: The amount of time an activity can be delayed without affecting the overall completion time; calculated as the difference between latest and earliest start/finish times.

  • Buffer: The sum of all slack times for activities on a critical path.

  • Internal risks include project scope flaws and human resource losses.

  • External risks include natural perils, political risks, commercial/social expectations, and technology evolution or obsolescence.