Elliot Book Chapter 9: Risk Assessment and Treatment
Foundations of Risk Identification
Identification must occur before management; organizations must identify both existing and emerging risks.
International standards like and define identification as an initial step. specifically uses the term event identification.
Traditional risk identification focuses on loss exposures, or negative risks, that could interfere with achieving primary goals.
Key risks possess the greatest potential effect on an organization's ability to meet its objectives.
Risk Identification Tools and Approaches
Loss histories provide quantitative and qualitative data on known risks but serve as lagging indicators.
Checklists are easy for non-professionals to use and can be organized into the quadrants of risk: financial, strategic, operational, and hazard.
Interviews and workshops involve stakeholders to identify risks in work activities before events occur.
Escalation or threshold triggers identify risk by comparing current transactions to prescribed criteria.
Audits (internal and external) identify negative risks as well as opportunity risks.
Top-down approaches involve senior management determining significant threats; disadvantages include a limited view of risks percolating in lower levels of the organization.
Bottom-up approaches include realistic employee observations but can be time-consuming to analyze.
Team-Based Identification Techniques
Facilitated Workshops: Rely on brainstorming and diverse groups to identify combined and cascading effects of risks.
Delphi Technique: Uses anonymous opinions from a group of experts through multiple rounds of queries (typically rounds) to reach a consensus and eliminate group bias.
Scenario Analysis: Projects potential consequences of risks to assist in prioritization; it requires internal cross-functional teams for multidimensional views.
HAZOP (Hazard and Operational Study): A comprehensive review used primarily for complex scientific or engineering systems by subdividing projects into small components.
SWOT: An acronym for strengths, weaknesses, opportunities, and threats; it is used to determine the feasibility of new projects. Strengths and weaknesses are internal factors, while opportunities and threats are external.
Risk Registers
A risk register is a tool developed at the risk owner level that links specific activities to identified risks and evaluation results.
Best practices indicate that registers should be dynamic, interactive matrices updated continually by risk owners.
Registers prioritize risks based on organizational significance rather than simple formulas.
Dashboards and diary features in Risk Management Information Systems () facilitate follow-up and prioritize high-impact risks.
Risk Mapping and Appetite
Risk maps provide a visual matrix of likelihood and impact (consequences) to prioritize risks.
Risk Appetite: The total exposed amount an organization wishes to undertake based on risk-return trade-offs.
Heat Mapping: The use of colors (e.g., Red, Yellow, Green) to represent different levels of combined impact and likelihood.
Inherent Risk: The risk level before any treatment is applied.
Residual Risk: The current level of risk remaining after treatment efforts.
Optimum Risk: The level of risk that is specifically within an organization's risk appetite.
Risk Zones: Red zone risks should be exploited, controlled, or transferred; yellow zone risks should be evaluated by cost-benefit; green zone risks are managed via normal operational procedures.
Risk Treatment Process and Techniques
Treatment decisions are based on risk assessment (identification and analysis) and involve a continuous process of examination and implementation.
Avoidance: Ceasing or never undertaking an activity to eliminate the possibility of potential gains or losses.
Modification: Changing the likelihood or impact. For hazard risks, this includes loss prevention (frequency reduction) and loss reduction (severity reduction, such as sprinkler systems).
Transfer: Sharing risks through contractual arrangements, joint ventures, or insurance.
Retention: Assuming risk in which gains and losses are kept within the organization; it is often used for residual risk.
Exploitation: Maximizing expected gains for events with primarily positive potential outcomes.
Project Risk Management and the Critical Path
Project risk management focuses on completing goals within quality, time, budget, and boundary constraints.
Scope Statement: A clarifying document detailing objectives, deliverables, potential costs, and success measurements.
Critical Path: The sequence of activities in a project that takes the longest time to complete, determining the overall project length.
Slack Time: The amount of time an activity can be delayed without affecting the overall completion time; calculated as the difference between latest and earliest start/finish times.
Buffer: The sum of all slack times for activities on a critical path.
Internal risks include project scope flaws and human resource losses.
External risks include natural perils, political risks, commercial/social expectations, and technology evolution or obsolescence.