A Risk Management Standard
A Risk Management Standard
Introduction
This Risk Management Standard is the
result of work by a team drawn from the
major risk management organisations in
the UK, including the Institute of Risk
management (IRM).
In addition, the team sought the views and
opinions of a wide range of other
professional bodies with interests in risk
management, during an extensive period of
consultation.
Risk management is a rapidly developing
discipline and there are many and varied
views and descriptions of what risk
management involves, how it should be
conducted and what it is for. Some form of
standard is needed to ensure that there is an
agreed:
1. Risk
Risk can be defined as the combination of
the probability of an event and its
consequences (ISO/IEC Guide 73).
2. Risk Management
Risk management is a central part of any
organisations strategic management. It is
the process whereby organisations
methodically address the risks attaching to
their activities with the goal of achieving
sustained benefit within each activity and
across the portfolio of all activities.
The focus of good risk management is the
identification and treatment of these risks.
Its objective is to add maximum
sustainable value to all the activities of the
organisation. It marshals the
understanding of the potential upside and
downside of all those factors which can
affect the organisation. It increases the
probability of success, and reduces both
the probability of failure and the
uncertainty of achieving the organisations
overall objectives.
Risk management should be a continuous
and developing process which runs
throughout the organisations strategy and
the implementation of that strategy. It
should address methodically all the risks
surrounding the organisations activities past,
present and in particular, future.
2
IRM: 2002
Modification
The Organisations
Strategic Objectives
Risk Assessment
Risk Analysis
Risk Identification
Risk Description
Risk Estimation
Risk Evaluation
Risk Reporting
Threats and Opportunities
Formal
Audit
Decision
Risk Treatment
Residual Risk Reporting
Monitoring
Risk management protects and adds value to the organisation and its stakeholders through
supporting the organisations objectives by:
3. Risk Assessment
Risk Assessment is defined by the ISO/
IEC Guide 73 as the overall process of risk
4. Risk Analysis
4.1 Risk Identification
Risk identification sets out to identify an
organisations exposure to uncertainty. This
requires an intimate knowledge of the
organisation, the market in which it operates,
the legal, social, political and cultural
environment in which it exists, as well as the
development of a sound understanding of its
strategic and operational objectives,
including factors critical to its success and the
threats and opportunities related to the
achievement of these objectives.
Risk identification should be approached
in a methodical way to ensure that all
significant activities within the organisation
have been identified and all the risks
flowing from these activities defined.
All associated volatility related to these
activities should be identified and
categorised.
Business activities and decisions can be
classified in a range of ways, examples of
which include:
4ABLE
2ISK $ESCRIPTION
1. Name of Risk
2. Scope of Risk
3. Nature of Risk
4. Stakeholders
5. Quantification of Risk
6. Risk Tolerance/
Appetite
Medium
Low
Description
Indicators
High
(Probable)
Medium
(Possible)
Low
(Remote)
IRM: 2002
Description
Indicators
High
(Probable)
Favourable outcome is
likely to be achieved in one
year or better than 75%
chance of occurrence.
Medium
(Possible)
Reasonable prospects of
favourable results in one
year of 25% to 75% chance
of occurrence.
Low
(Remote)
5. Risk Evaluation
When the risk analysis process has been
completed, it is necessary to compare the
estimated risks against risk criteria which
the organisation has established. The risk
criteria may include associated costs and
benefits, legal requirements, socio8
7. Risk Treatment
Risk treatment is the process of selecting
and implementing measures to modify the
risk. Risk treatment includes as its major
element, risk control/mitigation, but
extends further to, for example, risk
avoidance, risk transfer, risk financing, etc.
2OLE OF THE 2ISK -ANAGEMENT
&UNCTION
Depending on the size of the organisation
the risk management function may range
from a single risk champion, a part time
risk manager, to a full scale risk
management department. The role of the
Risk Management function should include
the following:
IRM: 2002
2ESOURCES AND
)MPLEMENTATION
The resources required to implement the
organisations risk management policy
should be clearly established at each level of
management and within each business unit.
In addition to other operational functions
they may have, those involved in risk
management should have their roles in coordinating risk management policy/strategy
clearly defined. The same clear definition is
also required for those involved in the audit
and review of internal controls and
facilitating the risk management process.
Risk management should be embedded
within the organisation through the
strategy and budget processes. It should be
highlighted in induction and all other
training and development as well as within
operational processes e.g. product/service
development projects.
13
10. Appendix
2ISK )DENTIFICATION 4ECHNIQUES
EXAMPLES
2ISK !NALYSIS -ETHODS AND
4ECHNIQUES
EXAMPLES
Brainstorming
Questionnaires
Business studies which look at each
business process and describe both the
internal processes and external factors
which can influence those processes
Industry benchmarking
Scenario analysis
Risk assessment workshops
Incident investigation
Auditing and inspection
HAZOP (Hazard & Operability
Studies)
Upside risk
Market survey
Prospecting
Test marketing
Research and Development
Business impact analysis
Both
Dependency modelling
SWOT analysis (Strengths, Weaknesses,
Opportunities, Threats)
Event tree analysis
Business continuity planning
BPEST (Business, Political, Economic,
Social, Technological) analysis
Real Option Modelling
Decision taking under conditions of risk
and uncertainty
Statistical inference
Measures of central tendency and
dispersion
PESTLE (Political Economic Social
Technical Legal Environmental)
Downside risk
Threat analysis
Fault tree analysis
FMEA (Failure Mode & Effect Analysis)
14
6 Lloyds Avenue,
London EC3N 3AX
Facsimile 020 7709 0716
Email [email protected]
www.theirm.org
This document is available for download free of charge from the website of the Institute of Risk Management