NAME: KEVIN T
MIDIWA
REG NUMBER: C16128163X
PROGRAMME: BSSCM
LEVEL: 2.1
CODE: CUSCM205
In the 21st century risk management occupies an important role in business activities.
Discuss the key components of an organization of your own choice .
INTRODUCION
As a project manager or team member, you manage risk on a daily basis; it’s one of the most
important things you do. If you learn how to apply a systematic risk management process, and
put into action the core risk management process steps, then your projects will run more
smoothly and be a positive experience for everyone involved.
A common definition of risk is an uncertain event that if it occurs, can have a positive or
negative effect on a project’s goals. The potential for a risk to have a positive or negative effect
is an important concept. Why? Because it is natural to fall into the trap of thinking that risks have
inherently negative effects. If you are also open to those risks that create positive opportunities,
you can make your project smarter, streamlined and more profitable. In this case I shall
emphasize on Chinhoi University of technology as an organization and the components include
Key terms
Risk management
It is the identification, analysis, assessment, control and minimization of the unacceptable
risks .organization may use risk transfer, avoidance, assumptions or a combination of both
strategies in proper management of future events.
Body
Identify the Risk
As once said the first step in the risk management process is to identify the risk and before a
certain risk occurs, there are some indicators that may occur which may show the source and
impact of that certain risk. Early warning indicators of Chinhoyi University of Technology may
relate to individual risks in which case they are more likely to be identified within the risk
register for a specific risk or at the project level. There are various techniques for determining an
aggregated risk level, and these are often stated in numerical terms. In combination of with risk
categories, such aggregated risk levels and their numerical status, may be monitored against an
agreed maximum. Such agreed maximums may be used as an early warning indicator to take
some form of predefined action. The use of probability and impact metrics are likely to be used
as early warning indicators as well as the effectiveness of risk response actions. However, there
are some activities that occur at campus which may not have early warning indicators but they
have a great negative impact to the reputation of the university and its property. Such risks may
not be identified or anticipated by the risk management team of the university.
Analyze the risk
The second step or component Once the risks identified by the risk management team
determine the likelihood and consequence of each risk. This helps them develop an
understanding of the nature of the risk and its potential to affect the reputation of the university
and its objectives. This information is also input to the Project Risk Register.
Evaluate or Rank the Risk
The CUT risk management team evaluates or rank the risk by determining the risk magnitude,
which is the combination of likelihood and consequence. You make decisions about whether the
risk is acceptable or whether it is serious enough to warrant treatment. These risk rankings are
also added to your Project Risk Register.
Based on the priority risks identified, their drivers or root causes and their susceptibility to
measurement, management decides on the appropriate risk response. There are four categories of
risk responses – avoid, accept, reduce and share. These responses may be applied to groups of
related risks consisting of natural families of risks sharing fundamental characteristics (e.g.,
common drivers, positive or negative correlations, etc.) consistent with a portfolio view. The
organization first decides whether to accept or reject a risk based on an assessment of whether
the risk is desirable or undesirable. A desirable risk is one that is inherent in the entity’s business
model or normal future operations and that the company believes it can monitor and manage
effectively. An undesirable risk is one that is off-strategy, offers unattractive rewards or cannot
be monitored or managed effectively. If chinhoi university of technology chooses to accept a
risk, it can accept it at its present level, reduce its severity and/or its likelihood of occurrence or
share it with a financially capable, independent party. They then evaluate or rank the risk by
determining the risk magnitude, which is the combination of likelihood and consequence. They
make decisions about whether the risk is acceptable or whether it is serious enough to warrant
treatment.
Control the risk
At Chinhoyi University of Technology there are security personals at every entrance and exit
points. This is insisted so as to reduce the risk of theft in campus and also to maintain order.
Individuals have to declare their assets and electrical gadgets when they are entering the campus
so as to avoid loss of the university’s property in a situation where by people will be claiming
that it would be their property. In circumstances where by individuals are not familiar with this
risk management strategy, property will be confiscated so as to allow investigations of the actual
owner of that certain gadget or asset. However, this strategy is not very effective since on exit
points they do not search thoroughly especially to those using vehicles. This loop hence the risk
of theft to small items can be very high. More so, thorough searching on exit points may result in
long queues at those exit points and hence individuals time consumption and management is
compromised.
Monitor the risk
The ICT department of Chinhoyi University of Technology has installed firewalls to protect the
intranet of Chinhoyi University “Eagle”. There is strict monitoring of the type and context of
information within the intranet. The ICT department can track a computer`s location using the
internet protocol address., for example the sharing of any pornographic information is not
allowed, if any information is sent using the university intranet can be tracked back to the
sending computer. This prevents the risk of sharing of such explicit information within the
university. Also the ICT department has secured the students data base, the accounting data base
and the administration data base using passwords to authorize access. This reduces the impact of
hacking. This intranet system of the university is secured from the risk of viruses by antiviruses
preventing the risk of computerized system crushing. The ICT Sector uses a top-down and
functions-based approach to assess and manage risks to its critical functions to promote the IT
infrastructure‘s assurance and resiliency, and to protect against cascading consequences based on
the Sector‘s interconnectedness and the critical functions ‘interdependencies
Planning
This is also referred to as Risk Response Planning. During this step you assess your highest
ranked risks and set out a plan to treat or modify these risks to achieve acceptable risk levels.
How can you minimize the probability of the negative risks as well as enhancing the
opportunities? You create risk mitigation strategies, preventive plans and contingency plans in
this step. And you add the risk treatment measures for the highest ranking or most serious risks
to your Project Risk Register.
Evaluation
When selecting suppliers and awarding tenders, the university follow its proper procedures in
accordance to the procurement act. Certain stage are to be followed like visiting the supplier`s
premises. Documentation of transactions should be dated and accurate that is from the purchase
order to the delivery note. This avoids the risk of dealing with bogus suppliers
Treat the Risk.
This is also referred to as Risk Response Planning. During this step you assess your highest
ranked risks and set out a plan to treat or modify these risks to achieve acceptable risk levels.
How can you minimize the probability of the negative risks as well as enhancing the
opportunities? You create risk mitigation strategies, preventive plans and contingency plans in
this step. And you add the risk treatment measures for the highest ranking or most serious risks
to your Project Risk Register.
Monitor Risk
Risk is about uncertainty. If you put a framework around that uncertainty, then you effectively
de-risk your project. And that means you can move much more confidently to achieve your
project goals. By identifying and managing a comprehensive list of project risks, unpleasant
surprises and barriers can be reduced and golden opportunities discovered. The risk management
process also helps to resolve problems when they occur, because those problems have been
envisaged, and plans to treat them have already been developed and agreed. You avoid impulsive
reactions and going into “fire-fighting” mode to rectify problems that could have been
anticipated. This makes for happier, less stressed project teams and stakeholders. The end result
is that you minimize the impacts of project threats and capture the opportunities that occur. Risk
monitoring is very important because it gives information about the execution of the plan and its
effectiveness and gives a good insight into the way the risk has developed or changed overtime.
By monitoring and evaluating the strategy, the entrepreneurs are able to get better insights of
their work that will help them to adopt an adequate course of action that fits their company goals
and specific circumstances.
The ICT department of Chinhoyi University of Technology has installed firewalls to protect the
intranet of Chinhoyi University “Eagle”. There is strict monitoring of the type and context of
information within the intranet. The ICT department can track a computer`s location using the
internet protocol address., for example the sharing of any pornographic information is not
allowed, if any information is sent using the university intranet can be tracked back to the
sending computer. This prevents the risk of sharing of such explicit information within the
university. Also the ICT department has secured the students data base, the accounting data base
and the administration data base using passwords to authorize access. This reduces the impact of
hacking. This intranet system of the university is secured from the risk of viruses by antiviruses
preventing the risk of computerized system crushing. The ICT Sector uses a top-down and
functions-based approach to assess and manage risks to its critical functions to promote the IT
infrastructure‘s assurance and resiliency, and to protect against cascading consequences based on
the Sector‘s interconnectedness and the critical functions ‘interdependencies
.
CONCLUSION
In conclusion, risk management is essential to an organization since it helps in the development
of strategies to be implemented to reduce the impact of risks. At Chinhoyi University of
Technology apply the different risk management strategies to different sectors of the university
such as the canteen department, procurement department, academic department, central service
department and the administration department.
REFERENCES
Torbun Juul Anderson. (2010). Perspectives on Strategic Risk Management. Oxford University Press.
New York.
Allen, B. (2007). The best laid plans of Risk. Longman Press. New York.
J.F Bradlery. (2005). Risk Perspectives. Pricewater house Coopers. London.
Flyvbjerg, Bent. (2003). Megaprojects and Risk: An Anatomy of Ambition. Cambridge University Press.
Britain.
Crockford, Neil. (1986). An Introduction to Risk Management 2nd Edition. Woodhead-Faulkner.
Cambridge. United Kingdom.
Dorfman, Mark S. (2007). Introduction to Risk Management and Insurance 9th Edition. Englewood
Cliffs, N.J. Prentice Hall.
Hubbard, Douglas. (2009). The Failure of Risk Management: Why It's Broken and How to Fix It. John
Wiley & Sons. New Jersey.
Torbun Juul Anderson. (2010). Perspectives on Strategic Risk Management. Oxford University Press.
New York.
Allen, B. (2007). The best laid plans of Risk. Longman Press. New York.
J.F Bradlery. (2005). Risk Perspectives. Pricewater house Coopers. London.
Flyvbjerg, Bent. (2003). Megaprojects and Risk: An Anatomy of Ambition. Cambridge University Press.
Britain.
Crockford, Neil. (1986). An Introduction to Risk Management 2nd Edition. Woodhead-Faulkner.
Cambridge. United Kingdom.
Dorfman, Mark S. (2007). Introduction to Risk Management and Insurance 9th Edition. Englewood
Cliffs, N.J. Prentice Hall.
Hubbard, Douglas. (2009). The Failure of Risk Management: Why It's Broken and How to Fix It. John
Wiley & Sons. New Jersey.