RISK ASSESSMENT WITHIN THE FRAMEWORK OF RISK
IDENTIFICATION,
RISK ANALYSIS, AND RISK EVALUATION
As a management tool, risk assessment is powerful as it provides fact-based
and science-based decision-making in safety, security, and sanitation. The trifocal
functions of risk assessment as overarching process shall be conducted through
the discipline of risk identification, risk analysis, and risk evaluation. It follows
that risk shall be communicated to all levels of organization to understand the
risk, to promote awareness and to gain support. It is the aim of risk management
to apply a process in identifying risks, setting the risk to an acceptable level and
keeping the residual risk at that level.
Risk management is conceptually presented in Figure 1.1.
Note: Adapted from the Philippine National Standards 31000:2018
(PNS ISO 31000:2018).
Figure 1.1. Framework of the Book for Risk Assessment
At the end of this unit, the students must be able to differentiate the three main tasks of
risk assessment—risk identification, risk analysis, and risk evaluation in the context of risk
management to be subsequently applied in tourism and hospitality industries' aspect of safety,
security, and sanitation.
Module 1. Risk Identification
o Describe the principles of risk management.
o Define risk as used in risk assessment.
o Summarize the factors to consider in risk identification.
o Discuss the importance of risk identification to risk assessment.
WHAT I KNOW?
1. True or False: Risk management are overall activities to direct and
control an organization with regard to the effect of uncertainty on
objectives.
2. True or False: The purpose of risk management is the creation and
protection of value in an organization.
3. True or False: Risk can only be expressed in terms of its likelihood.
Words To Remember
Risk, according to PNS ISO 31000:2018, which is usually expressed in terms of
sources, events, consequences, and likelihood, is the effect of uncertainty on
objectives.
An effect is a deviation from the expected Which can be positive, negative, or
both and can address, create, or result in opportunities
And threats.
Objectives can have different aspects and Categories and can be applied at
different levels.
Risk management is coordinated activities to direct and control an organization
with regard to risk.
A. Risk Management Principles
Creation and protection of value across an organization for performance
improvement, innovation promotion, and goal achievement are the very purpose of
risk management with its principles stated in Figure 1.2. It is then a proactive
management tool in preventing occurrence of possible risk and hazards in the
company's value chain. The principles of effective risk
management as stipulated in Philippine National Standards 31000:2018 (PNS ISO
31000:2018) are as follows:
a. Integrated. Risk management is an integral part of all organizational activities.
b. Structured and Comprehensive. A structured and comprehensive approach to risk
management contributes to consistent and comparable results.
c. Customized. The risk management framework and process are customized and
proportionate to the organization's external and internal context related to its
objectives.
d. Inclusive. Appropriate and timely involvement of stakeholders enables 2 their
knowledge, views, sand perceptions to be considered resulting in improved
awareness and informed risk management.
e. Dynamic. Risk can emerge, change, or disappear as an organization's external
and internal context changes. Risk management anticipates, detects, acknowledges,
and responds to those changes and events in an appropriate and timely manner.
f. Best AvailabIe lnformation. The inputs to risk management based on historical and current
information and on future expectations. Risk management explicitly takes into account any
limitations and uncertainties associated with should such be information timely, clear, and
expectations. available to Information relevant stakeholders.
g. Human and Cultural Factors. Human behavior and culture significantly influence all aspects
of risk management at each level and stage.
h. Continual Improvement. Risk management is continually improved through learning and
experience.
Note: Outlined in the Philippine National Standards 31000:2018 (PNS ISO
31000:2018)
Figure 1.2. Risk Management Principles
B. Risk Assessment and Risk Identification
Risk assessment, which is the overall process of risk identification, risk
analysis, and risk evaluation should be conducted systematically, iteratively, and
collaboratively, drawing on the knowledge and views of stakeholders. It should use
the best available information, supplemented by further inquiry as necessary.
Risk assessment starts primarily with risk identification. The very
purpose of risk identification is to find, recognize, and describe the risks that
might help or prevent an organization
to achieve its objectives. Relevant, appropriate, and up-to-date information
is important in identifying risks.
The organization can us a range of techniques for identifying
uncertainties or may affect one or more objectives. In risk identification, the
following factors and the relationship between these factors should be
considered:
tangible and intangible sources of risk;
causes and events;
threats and opportunities;
vulnerabilities and capabilities;
changes in the external and internal context;
indicators of emerging risks;
the nature and value of assets and resources
consequences and their impact on objectives
limitations of knowledge and reliability of information
time-related factors
biases
assumptions; and
beliefs of those involved
Consequently, the organization should identify risks, whether or not their
sources are under its control. Consideration should be given that there may be more
than one type of outcome, which may result in a variety of tangible or intangible
consequences.
C. Types of Risks
Whether a risk will result to a positive or negative outcomes, uncertainty
will' always exist. As such, it can be viewed as an opportunity or threat to any
tourism-related enterprise. Tourism, as One of the keys for economic
development, can be viewed as double-edge sword can bring both beneficial and
detrimental effects to a tourism destination.
As Hopkin (2018) emphasized, risks can be categorized into four as shown in Figure
1.3:
Compliance (mandatory) risks. As the name suggests compliance risks involve government-
mandated licenses and business permits and requirements. It may constitute business clearance
from a barangay level, municipal level, or city level, internal revenue offices, security
exchange, license to operate, compliance to fire and building code, and insurance among
others.
Hazard (or pure) risks. These are the risks that can prevent and deter the achievement of
company's goals, missions and objectives. Typical examples include insurable-type risks to
include fire, typhoon, flood, earthquake, and injury among others, causing normal operations
to be affected by 'loss, breakdown, theft, and other threats. Hopkin (2018) als o provided
operational-disruption examples caused by people premises, processes, and products (4Ps) as
summarized in Table 1.1.
Examples of Disruption
Category
People Lack of people skills and limited resources
Improper behavior by a manager
Unexpected absence of key associates
Sickness, illness, or injury to associates
Premises No enough prohibition
Damage or contamination to premises
Damage of physical assets
Theft of physical assets
Processes Failure of IT hardware or software
Interference due to computer virus and hacker
Mismanagement of information
Communication or transport failure
Products Poor product or service quality
Supplier failure
Delivery of defective goods or its pasts
Logistics failure
Table 1.1
Categories of Operational Disruption
Control risks. These are risks that can cause uncertainty or doubt about the ability to
achieve company's goals, missions, and objectives. One classical example of control
risk T is internal financial control protocols. If control protocols are removed, there
might be uncertainty on what will happen. Further, control protocols are dependent on
the successful management: of company's resources and effective implementation.
Opportunity risks. These are risks that are usually deliberately sought or embraced by
the organization specifically for the future long-term success of any organization. These
risks arise because the organization is seeking to enhance the achievement of goals,
missions, and objectives. Some organizations are willing to invest in high-risks business
strategies in anticipation of high return on investment: