Risk Management
CMIE 6213
Faculty of Engineering and Built Engineering
Lecturer: Prof Dr Dzuraidah Abd Wahab
What is Risk?
• Risk implies future uncertainty about deviation from expected earnings or expected outcome.
Risk measures the uncertainty that an investor is willing to take to realize a gain from an
investment. ([Link]
• Risk is the chance or probability that a person will be harmed or experience an adverse health
effect if exposed to a hazard. It may also apply to situations with property or equipment loss, or
harmful effects on the environment.
([Link]
• What is the difference between risk and hazard?
Difference between Risk and Hazard
• Risk is the chance, high or low, that • A hazard is something that can cause
any hazard will actually cause harm.
somebody harm’.
• Examples of hazards: working with
• A risk would be a danger that these heavy machinery, using chemicals at
situations may pose; for example, work, a poorly set up workstation or
physical injury, chemical burns, strained office relationships.
increased stress levels.
[Link]
[Link]
• Risk management is the process of identifying, assessing and controlling to an
organization's capital and earnings.
• Risk management allows organizations to prepare for risks or threats be it
expected/predictable or the unexpected.
In the case of a digital companies, what are the risks or threats?
• IT security threats and data-related risks
• How do you control?
Examples of risks for example in banks
• Credit risk
• Market risks
• Operational risks
What causes these risks to
Risks common to all other organisations happen
• Product Development risks
• Reputation risks
• Supply chain risks
• Human Resource risks
• IT risks
• Financial risks
Benefits of Risk Management
Other than for cost reasons, risk management benefits in terms of the
following [1]:
• Creates a safe and secure work environment for all staff and customers.
• Increases the stability of business operations while also decreasing legal
liability.
• Provides protection from events that are detrimental to both the company
and the environment.
• Protects all involved people and assets from potential harm.
• Helps establish the organization's insurance needs in order to save on
unnecessary premiums.
Risk Management Approaches
• Risk avoidance - while the complete elimination of all risk is rarely possible, a risk
avoidance strategy is designed to deflect as many threats as possible in order to
avoid the costly and disruptive consequences of a damaging event.
• Risk reduction - companies are sometimes able to reduce the amount of damage
certain risks can have on company processes. This is achieved by adjusting certain
aspects of an overall project plan or company process, or by reducing its scope.
• Risk sharing - sometimes, the consequences of a risk are shared, or distributed
among several of the project's participants or business departments. The risk
could also be shared with a third party, such as a vendor or business partner.
• Risk retaining - sometimes, companies decide a risk is worth it from a business
standpoint, and decide to keep the risk and deal with any potential fallout.
Companies will often retain a certain level of risk if a project's anticipated profit is
greater than the costs of its potential risk.
Limitations in Risk Management
• Many risk analysis techniques such as creating a model or simulation; require
gathering large amounts of data. This extensive data collection can be expensive
and is not guaranteed to be reliable.
• The use of data in decision making processes may have poor outcomes if simple
indicators are used to reflect the much more complex realities of the situation.
Similarly, adopting a decision throughout the whole project that was intended for
one small aspect can lead to unexpected results.
• Lack of analysis expertise and time. Computer software programs have been
developed to simulate events that might have a negative impact on the company;
require trained personnel with comprehensive skills and knowledge in order to
accurately understand the generated results.
Other limitations include:
• A false sense of stability. Value-at-risk measures focus on the past instead of the
future. Therefore, the longer things go smoothly, the better the situation looks.
Unfortunately, this makes a downturn more likely.
• The illusion of control. Risk models can give organizations the false belief that
they can quantify and regulate every potential risk. This may cause an
organization to neglect the possibility of novel or unexpected risks. Furthermore,
there is no historical data for new products, so there's no experience to base
models on.
• Failure to see the big picture. It's difficult to see and understand the complete
picture of cumulative risk.
• Risk management is immature. An organization's risk management policies are
underdeveloped and lack the history to make accurate evaluations.
ISO 31000 on Risk Management
• Guidelines, provides principles, a framework and a process
for managing risk.
• It can be used by any organization regardless of its size, activity or
sector.
• Provides direction on how companies can integrate risk-based
decision making into an organization’s governance, planning,
management, reporting, policies, values and culture.
ISO 31000 emphasised the involvement of senior management and the
integration of risk management into the organization which includes:
• develop a statement or policy that confirms a commitment to risk
management
• assigning authority, responsibility and accountability at the
appropriate levels within the organization
• ensuring that the necessary resources are allocated to managing risk.
Risk Management Process in ISO 31000
• Risk identification: identifying what could
prevent us from achieving our objectives.
• Risk analysis: understanding the sources
and causes of the identified risks;
studying probabilities and consequences
given the existing controls, to identify the
level of residual risk.
• Risk evaluation: comparing risk analysis
results with risk criteria to determine
whether the residual risk is tolerable.
• Risk treatment: changing the magnitude
and likelihood of consequences, both
positive and negative, to achieve a net
increase in benefit
• Establishing the context: consists of defining the scope for the risk management
process, defining the organization’s objectives, and establishing the risk
evaluation criteria.
• Monitoring and review: measuring risk management performance against
indicators, which are periodically reviewed for appropriateness.
• Communication and consultation. This task helps understand stakeholders’
interests and concerns, to check that the risk management process is focusing on
the right elements, and also helps explain the rationale for decisions and for
particular risk treatment options.
Using rules in Risk Management
• Some risks can be managed using rules while other require
alternative approaches
• Kaplan and Mikes argued that rules alone will not diminish the
likelihood or the impact of a disaster. For example disaster such as
Deepwater Horizon [2]
Categories of Risks
• Preventable Risks – controllable, internal risks such as inappropriate actions of
employee, breakdown in routine operational processes
• Strategy Risks – not inherently desirable. In this case, risk are accepted in order
to generate superior returns such as a bank lending money to obtain potential
gains; this is an example of risk that cannot be managed using rule based control
model.
• External Risks – risks from outside of the company and are beyond their control
eg natural and political disasters, major macro-economic shifts
Sources of external risks
• Natural and economic disasters with immediate impact e.g and
earthquake, tsunami
• Geopolitical and environmental changes with long term impact e.g
policy changes, war, global warming, depletion of critical natural
resources
• Competitive risks with medium-term impact e.g emergence of
disruptive technology such as internet, smart phones, barcodes
Types of disasters in Malaysia and affecting the industry
• Arguably, of all the disasters in Malaysia, floods are most frequent and bring
the greatest damage annually. Floods are therefore considered as the most
severe type of disaster experienced in Malaysia[3]
• The role of Disaster Management Plan
- Aims to reduce the harmful effects of disaster.
- It must be plan ahead of time.
- To ensure that the organisation is able to continue operating
after disaster.
Flood disaster management in Malaysia involves four phases:
• Prevention/mitigation
• Preparedness
• Response
• Recovery
Some cases of major disasters in Malaysia [4]:
• fire and explosions at the Bright Sparklers factory in Sungai Buloh in 1991 which claimed 22
lives;
• fire and explosions at South Port Klang in 1992 which claimed 10 lives;
• collapse of the Highland Towers apartment blocks in Hulu Kelang in 1993 which claimed 48
lives;
• massive landslide at the Genting Highlands in 1995 which claimed 20 lives;
• mudslides in Pos Dipang, Perak, on 29 August 1996 which claimed 44 lives;
• severe haze episodes in 1997 and 1998 which 506 caused loss in tourist revenues in the
millions of dollars and hospitalized thousands of people;
• landslide at Sandakan, Sabah, in February 1999 due to heavy downpour which claimed 17
lives and damaged 4 houses
Discussion:
How to mitigate risk? Give some examples
• Avoidance
• Reduction
• Spreading
• Transfer
• Acceptance
1. TechTarget. Risk Management. [Link]
management
2. Robert S. Kaplan and Anette Mikes, [Link]/2012/06, June 2012
3. Chan, N. W. 2012. Impacts of Disasters and Disasters Risk Management in Malaysia: The
Case of Floods, in Sawada, Y. and S. Oum (eds.), Economic and Welfare Impacts of Disasters
in East Asia and Policy Responses. ERIA Research Project Report 2011-8, Jakarta: ERIA.
pp.503-551.
4. Abdul Malek, M. 2005 Disasters Management System in Malaysia. Jurutera.
5. Izham Mohamad Yusoff, Aznarahayu Ramli, Nurul Azni Mhd Alkasirah, Norashila Mohd
Nasir. 2018. Exploring the managing of flood disaster: A Malaysian perspective. Geografia.
14(3).