0% found this document useful (0 votes)
189 views23 pages

Apply Risk Management Processes

Uploaded by

Amha Seyoum
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
189 views23 pages

Apply Risk Management Processes

Uploaded by

Amha Seyoum
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd

PHARMA COLLEGE

Marketing and Sales Management


Learning Guide
Unit of Competence: IDENTIFY RISK AND
APPLYINGRISK MANAGEMENT PROCESSES
Learning out comes
Lo1. Identify risks

Lo2. Analyze and evaluate risks

Lo3. Treat risks

Lo4. Monitor and review effectiveness of risk treatment/s

Occupational Standard: Marketing and Sales management Level IV


Unit Title Identify and Apply Risk Management Processes

Unit Code LSA MSM 4 13 1221

Unit Descriptor This unit describes the performance outcomes, skills and
knowledge required to identify risks and to apply established
risk management processes to a subset of an organisation or
project's operations that are within the person's own work
responsibilities and companies operation.

Elements Performance Criteria

1. Identify risks
1.1The context is identified for risk management
1.2Risks are identified using tools, ensuring all reasonable
steps have been taken to identify all risks
1.3Identified risks are documented in accordance with relevant
policies, procedures and legislation
2. Analyze and
2.1Risks are analyzed and documented in consultation with
evaluate risks
relevant stakeholders
2.2Risk categorization is undertaken and level of risk
determined
2.3Analysis processes and outcomes are documented
3. Treat risks
3.1Appropriate control measures are determined for risks and
assessed for strengths and weaknesses
3.2Control measures are identified for all risks
3.3Risks relevant to whole of organization or having an impact
beyond own work responsibilities and area of operation are
referred to others as per established policies and procedures
3.4Control measures are chosen and implemented for own area
of operation and/or responsibilities
3.5Treatment plans are prepared and implemented
4. Monitor and
4.1Implemented treatment/s is/are regularly reviewed against
review
measures of success
effectiveness of
4.2Review results are used to improve the treatment of risks
risk
4.3Assistance is provided to auditing risk in own area of
treatment/s
operation
4.4Management of risk is monitored and reviewed in own area of
operation

Variable Range

Context May include but not limited to:


 Any related projects or organisations
 Any resources, including physical assets, which are vital to
operations
 Key operational elements and service of the organisation
 Organisation or project, how it is organised and its
capabilities
 Own role and responsibilities in relation to overall project or
organisation design
Risks May include but not limited to:
 Commercial and legal relationships
 Economic circumstances and scenarios
 Human behaviour
 Individual activities
 Management activities and controls
 Natural events
 Political circumstances
 Positive risk
 Technology - technological issues
Tools May include but not limited to:
 Documentation to assist in process of identifying risk, and
assessing impact and likelihood of occurrence
 Standard instruments developed for the organisation and
contextualised for sections of the workplace's operations,
such as checklists and testing procedures
 Tools to prioritise risks, including where relevant, numerical
scoring systems for risks
Stakeholders May include but not limited to:
 Contractors
 Employees
 Financial managers
 Insurance agents
 Managers
 Public
 Service providers
 Suppliers
 Unions
 Volunteers
Risk categorisation May include but not limited to:
 Likelihood of risks:
 Almost certain
 Likely
 Possible
 Unlikely
 Rare
 Consequences of risks:
 Insignificant
 Minor
 Moderate
 Major
 Catastrophic
 Current control measures
Level of risk May include but not limited to:
 Low, treated with routine procedures
 Moderate, with specific responsibility allocated for the risk,
and monitoring and response procedures implemented
 High, requiring action, as it has potential to be damaging to
the organisation or project
 Extreme, requiring immediate action, as it has potential to be
devastating to the organisation or project
Control measures May include but not limited to:
 Hierarchy of controls:
 Reduction in likelihood of risks
 Reduction of consequences of risks
 Retention of risks
 Risk aversion
 Transfer of responsibility of risks
Measures of May include but not limited to:
success  Costs
 Reductions in impact
 Reductions in likelihood
 Reductions in occurrence

Evidence Guide

Critical aspects of Must demonstrate knowledge and skill of competence to:


competence
 Identification, analysis and evaluation of risks
 Demonstrated understanding of personal role in relation to
wider organizational or project context
 Demonstrated understanding of risk management processes
and procedures
Underpinning Must demonstrate knowledge of:
Knowledge and
Attitudes  National standards for risk management
 Key provisions of relevant legislation from all levels of
government that may affect aspects of business operations,
such as:
 Anti-discrimination legislation
 Ethical principles
 Codes of practice
 Privacy laws
 Environmental issues
 Occupational health and safety
 Organizational policies and procedures relating to risk
management processes and strategies
 Auditing requirements relating to risk management
Underpinning Must demonstrate skills to:
Skills
 Literacy skills sufficient to read and understand a variety of
texts; and to write, edit and proofread documents to ensure
clarity of meaning, accuracy and consistency of information
 Research and data collection skills to monitor and evaluate
risks
 Problem-solving skills to appropriately address identified
risks
Resources Access is required to real or appropriately simulated situations,
Implication including work areas, materials and equipment, and to
information on workplace practices and OHS practices.

Assessment Competency may be assessed through:


Methods
 Interview / Written Test / Oral Questioning
 Observation / Demonstration
Context of Competency may be assessed in the work place or in a
Assessment simulated work place setting
INTRODUCTION LEARNING GUIDE 11

INTRODUCTION TO THE MODULE

This unit describes the skills and knowledge required to identify


risks and to apply established risk management processes to a
defined area of operations that are within the responsibilities and
obligations of the role.

It applies to individuals with a broad knowledge of risk analysis or


project management who contribute well developed skills in
creating solutions to unpredictable problems through analysis
and evaluation of information from a variety of sources. They may
have responsibility to provide guidance or to delegate aspects of
these tasks to others.

In this unit, risks applicable within own work responsibilities and


area of operation, may include projects being undertaken
individually or by a team, or operations within a section of the
organization.

This learning guide is developed to provide you the necessary


information regarding the following content coverage and topics;

 Identify risks

 Analyze and evaluate risks

 Treat risks
5|Page

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
 Monitor and review effectiveness of risk treatment/s

This guide will also assist you to attain the learning outcome stated in the cover page. Specifically,
upon completion of this Learning Guide, you will be able to;

PERFORMANCE CRITERIA
Performance criteria describe the performance
Elements needed to
describe the demonstrate achievement of the element.
essential
outcomes. 1.1 Identify the context for risk management
1. Identify risks 1.2 Identify risks using tools, ensuring all
reasonable steps have been taken to identify
all risks
1.3 Document identified risks in accordance
with relevantand
2.1 Analyse policies,
documentprocedures, legislation
risks in consultation
2. Analyse and with relevant stakeholders
evaluate risks 2.2 Undertake risk categorisation and determine
level of risk
2.3 Document analysis processes and outcomes

6|Page

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
3.1 Determine appropriate control measures for
3. Treat risks risks and assess for strengths and weaknesses
3.2 Identify control measures for all risks
3.3 Refer risks relevant to whole of organization
or having an impact beyond own work
responsibilities and area of operation to others
as per established policies and procedures
4.1 Regularly review implemented treatment/s
4. Monitor and against measures of
review success
effectiveness of 4.2 Use review results to improve the treatment
INFORMATION SHEET 01 IDENTIFY RISKS

The Risk Management Process


Risk Management is "the systematic application of management
policies, procedures and practices to the tasks of establishing
the context, identifying, analyzing, assessing, treating,
monitoring and communicating" (AS/NZS ISO 31000:2009).

It is an iterative process that, with each cycle, can contribute


progressively to organizational improvement by providing
management with a greater insight into risks and their impact.

Risk management should be applied to all levels of an


organization, in both the strategic and operational contexts, to
specific projects, decisions and recognized risk areas. Risk is
'the chance of something happening that will have an impact on

7|Page

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
objectives'. It is, therefore, important to understand the
objectives of the organization, work unit, project or your
position, prior to attempting to analyze the risks.

A simple process

Risk analysis is often best done in a group with each member of


the group having a good understanding of the objectives being
considered.

1. Identify the Risks: What might inhibit the ability to


meet objectives? E.g. loss of a key team member; prolonged
IT network outage; delayed provision of important
information by another work unit/individual; failure to
seize a commercial opportunity, etc. Consider also things
that might enhance the ability to meet objectives e.g. a
fund-raising commercial opportunity.
2. Identify the Causes: What might cause these things to
occur e.g. the key team member might be disillusioned with
their position, might be head hunted to go elsewhere; the
person upon whom you are relying for information might be
very busy, going on leave or notoriously slow in supplying such
data; the supervisor required to approve the commercial
undertaking might be risk averse and need extra convincing
before taking the risk, etc.
3. Identify the Controls: Identify all the things (Controls)
that you have in place that are aimed at reducing the
Likelihood of your risks from happening in the first place
8|Page

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
and, if they do happen, what you have in place to reduce
their impact (Consequence). Examples include: providing a
friendly work environment for your team; multi-skilling
across the team to reduce the reliance on one person;
stressing the need for the required information to be
supplied in a timely manner; sending a reminder before the
deadline; and provide additional information to the
supervisor before he/she asks for it, etc.
4. Establish your Likelihood and Consequence
Descriptors: The likelihood descriptors are fairly generic
however the consequence descriptors may depend upon the
context of your analysis. I.e. if your analysis relates to your
work unit, any financial loss or loss of a key staff member
(for example) will have a greater impact on that work unit
than it will have on the organization as a whole so those
descriptors used for the whole-of-organization (strategic)
context will generally not be appropriate for the Faculty,
other work unit or the individual. The idea is analogous to
how a loss of $300,000 would have less impact on the
organization than it would for an individual work unit. You
will need to establish these parameters in consultation with
the head of the work unit.

5. Establish Risk Rating Descriptors: I.e. what is meant by


a Low, Moderate, High or Extreme Risk needs to be decided
upon from the outset.
6. Add Other Controls: Generally, any risk rated High or
9|Page

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
Extreme should have additional controls applied to it to
reduce the rating to an acceptable level. What the additional
controls might be, whether they are affordable, what priority
might be placed on them etc is something for the group to
determine in consultation with the Head of the work unit.
7. Make a Decision: Once the above process is complete, if
there are still some risks that are rated as High or Extreme,
a decision has to be made as to whether the activity will go
ahead. Sometimes risks are higher than preferred but there
may be nothing more that can be done to mitigate the risk
i.e. they are out of the control of the work unit but the
activity must still be carried out. In such situations,
monitoring and regular review is essential.
8. Monitor and Review: Monitoring of all risks and regular
review of the risk profile is a key part of effective risk
management.

Risk management for directors

Risk management is a critical responsibility for the board. In


order to discharge their duties, directors need to know and
assess the nature and magnitude of risks faced by the
organization. They also need confidence that management has an
effective framework in place to manage those risks.

We’ve developed Risk management for directors: A handbook to


assist those on the governing body of an organisation to:

10 | P a g e

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
 gain clarity about the interaction of governance and risk
management
 avoid confusion in the responsibilities of those with an
oversight role and those with an implementation role
 Achieve focus on embedding risk management within the
strategic framework.

We do not advise directors on how to create an enterprise risk


management system — this is the responsibility of management.
Instead, our handbook assists your board to integrate its
governance and risk management frameworks by equipping you
with questions you can address to management to ensure that
there is an effective risk management framework in place to
manage the organisation’s risks. It will help your board ensure it
deliberations and oversight of management link the alignment of
risk management practices with strategic objectives throughout
the organisation.

About risk management

What is risk?
Defines risk as the chance of something happening that will have
impact on [an organisation’s] objectives. It is measured in terms of
consequences [the outcome] and Likelihood [the rate of
occurrence] and if the risk will have a positive or negative impact.

What is risk management?

11 | P a g e

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
Risk management is increasingly important for Boards,
volunteers, paid staff and stakeholders of all services and is an
essential component of good corporate governance. It is part of
an organisation’s culture, its philosophy, practices and business
processes. It should not be viewed as a separate activity.

Risk management:
 Is a procedure to avoid any negative consequences and
reduce potential legal liability.
 Seeks to address potential problem areas before they occur
and creates a safer environment
 Is a process to test the effectiveness of measures to prevent
events happening that may result in negative outcomes?

The Standard provides a framework for establishing the context,


identifying, analyzing, evaluating, treating, monitoring and
communicating risk and sets out a systematic risk management
approach.

Risks will vary from organization to organization depending upon


the circumstances and the way the organization operates. Risk
management plans should be tailored to specific risks and
operational practices, and should be reviewed regularly.

Who is responsible for risk management?


Managing risk is a shared responsibility of all members of an
organisation. Directors however, have a responsibility to lead and

12 | P a g e

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
provide support.
Management of risk should be integrated into the management
philosophy of an organization.

Why is risk management important for an organization?

A level of risk occurs in all organisations. Governance principles


and the Occupational Health and Safety require that
organisations take reasonable measures to prevent loss, harm or
injury to the organisation and all stakeholders.

Accident and injury can happen even with rigorous OHS


planning, and the fact that an injury occurs does not mean that
someone is liable if all reasonable steps have been taken to
prevent or minimize the risk.

Non-government organizations may be exposed to risk when:


 They do not have a well functioning governance structure
 Management plans, policies and processes are inadequate
 Staff and volunteer roles and responsibilities are unclear
 They do not require service users to sign consent forms or
waivers
 Equipment and facilities are not safe for intended use
 They have not implemented a comprehensive OHS plan
 Insurance is inadequate or inappropriate
 Operations are not regularly evaluated.

13 | P a g e

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
Implementing a risk management plan
Risk management should be integrated into an organisation’s
operations.
Organizations should develop a risk management policy and a
plan for how the risk management process will be managed.

Risk management plans should describe the:


 Commitment and leadership from management
 Delegation of defined tasks to ensure accountability
 Reporting system – including progress reports, reports
on extraordinary incidents and perceived risks
 Operating procedures

Risk management policy

Risk management policies should be brief, high-level documents


that can be easily understood. A well drafted and regularly
reviewed policy is a risk management tool in itself.
Policies are an organization’s first line of compliance and should
be developed and treated as such. A risk management policy
should be drafted to clearly identify legitimate interests for
which the organisation exists including:
 High quality service provision to meet the needs of the
service users including people with disabilities, older
people, children and carers
 The success and financial viability of the organisation
providing these services

14 | P a g e

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
 The proper organisation and administration of the
organisation
 The rights of older people, people with disabilities and
carers to choice, self determination, independence, privacy
and confidentiality.

External requirements and the public interest should also guide


the policy and the following factors should be considered:
 The policy should be developed to clearly reflect the law and
relevant standards (e.g. the NSW Disability Service
Standards, the HACC National Service Standards)
 Where the system for the formulation, interpretation and
enforcement of the policy works properly and effectively,
that policy is essentially in the public interest
 A clearly expressed and well defined policy which provides
for appeals, natural justice and procedural fairness,
strengthens arguments that the organisation is operating in
the public interest.

Risk management policies and plans are important. They


document the steps an organisation plans to take to minimise
and deal with actual and potential risks.

The Board is responsible for approving the documents and


ensuring the plans are implemented within the organisation.

15 | P a g e

Date: September, 2017


TLM Development Manual
Compiled by: business and finance Department
INFORMATION SHEET 02 ANALYSING AND EVALUATING RISKS

2.2. ANALYSING AND EVALUATING RISKS

Once you have identified and created a list of possible risks to


your business, you need to analyse and evaluate each one.

The most common way of analysing risks is to use a scale that


rates each risk on:

 the likelihood of it occurring


 the consequences of it occurring.

Likelihood scale example


Level Likelihood Description
4 Very likely Happens more than once a year in this
3 Likely industry about once a year in this industry
Happens

Likelihood scale example


Level Likelihood Description
2 Unlikely Happens every 10 years or more in this
1 Very industry
Has only happened once in this industry
unlikely
Consequences scale example
Level Consequen Description
ce
4 Severe Financial losses greater than $50,000
3 High Financial losses between $10,000 and
2 Moderate $50,000
Financial losses between $1000 and
1 Low $10,000 losses less than $1000
Financial

Note: The scales above use 4 different levels; however, you can
use as many levels as you need. Also use descriptors that suit
your purpose (e.g. you might measure consequences in terms of
human health, rather than dollar value).

Once you have established the likelihood and consequences of a


particular risk, you then need to create a risk rating table for
evaluating the risk. Evaluating a risk means making a decision
about its severity and ways to manage it.

Use the following formula to calculate risk rating: Likelihood x


Consequences = Risk rating

For example, you may decide the likelihood of a fire is 'unlikely'


(a score of 2) but the consequences are 'severe' (a score of 4).
Using the tables above, a fire therefore has a risk rating of 8 (i.e.
2 x 4 = 8).

Risk rating table example


Risk Description Action
rating
12-16 Severe Needs immediate corrective action
8-12 High Needs corrective action within 1 month
4-8 Moderate Needs corrective action within 3 months
1-4 Low Does not currently require corrective action

Your risk evaluation should consider:

 the importance of the activity to your business


 the amount of control you have over the risk

 potential losses to your business


 any benefits or opportunities presented by the risk.

Once you have identified, analysed and evaluated your risks,


you need to rank them in order of priority. You can then
decide what methods you will use to treat unacceptable risks.
INFORMATION SHEET 03 TREATING RISKS

3. TREATING RISKS

Risk treatment involves working through options to treat


unacceptable risks to your business. Unacceptable risks range
in severity; some require immediate treatment, others can be
monitored and treated later.

Before you decide which risks treating, you need to gather


information about the:

 method of treatment
 people responsible for treatment
 costs involved
 benefits of treatment
 likelihood of success
 ways to measure and assess treatments.

Once you decide how to treat identified risks you will need to
develop, and regularly review, your risk management plan.

The following are different options for treating risk.

Avoid the risk

You may decide not to proceed with the activity likely to


generate the risk, where practical. Alternatively, you may
think of another way to reach the same outcome.

Reduce the risk

You can control a risk by:

 reducing the likelihood of the risk occurring - for


example, through quality control processes, managing
debtors, auditing, compliance with legislation, staff
training, regular maintenance or a change in procedures
 reducing the impact if the risk occurs - for example,
through emergency procedures, off-site data backup,
minimising exposure to sources of risk or public
relations.

Transfer the risk

You may be able to shift some or all of the responsibility for


the risk to another party through insurance, outsourcing,
joint ventures or partnerships.

Accept the risk

You may accept a risk if it cannot be avoided, reduced or


transferred. However, you will need to have plans for
managing and funding the consequences of the risk if it
occurs.

Developing and reviewing your risk management plan

A risk management plan details your strategy for treating risks. It


details information about:

 identified risks
 the level of risks
 your planned strategy
 the time frame for implementing your strategy
 the resources required
 the individuals responsible for ensuring the strategy is
implemented.

Your final plan should include appropriate objectives, a


budget and milestones on the way to achieving those
objectives.

Reviewing your risk management plan


The business environment is constantly changing. The type of
risks you face will change as your business develops and grows.
Regularly reviewing your risk management plan is therefore
essential for identifying new risks and monitoring the
effectiveness of your risk treatment strategies.

Common questions

Powered by AI

A systematic risk management approach improves organizational processes by integrating management policies, procedures, and practices that identify, analyze, assess, treat, and monitor risks. This iterative process contributes to continuous improvement, providing management with deeper insights into risks and their impacts, thus allowing for more informed decision-making and operational enhancement .

Directors have a critical responsibility in risk management as they need to understand and assess the magnitude of risks and ensure that management has an effective risk management framework. They provide oversight, integrate governance and risk management within the strategic framework, and ask the right questions to assure themselves of the effectiveness of these frameworks within the organization .

An organization can ensure effective risk treatment monitoring and review by establishing key performance indicators (KPIs), regularly assessing the effectiveness of control measures, adjusting risk mitigation strategies based on results, and engaging in continuous improvement practices. Regular audits, stakeholder consultation, and iterative risk management reviews also contribute to maintaining effective risk control .

Involving stakeholders during the risk analysis and evaluation phase is crucial because it ensures diverse perspectives are considered, leading to a comprehensive understanding of potential impacts and the level of risk. Stakeholders can provide insights into the contextual relevance and operational implications of risks, which aids in developing more effective risk management strategies .

The consequences of risks can vary based on organizational context because different entities face varying impacts from similar risks. For example, a financial loss might be more devastating to a smaller department than an entire organization. Risk assessments should therefore consider the specific context, including departmental dependencies and strategic importance, to accurately evaluate potential outcomes .

The key elements of risk management as outlined in the PHARMA COLLEGE learning guide include identifying risks by determining the context and using tools to ensure comprehensive risk identification, analyzing and evaluating risks with stakeholders to determine risk levels, treating risks by assessing and implementing control measures, and monitoring and reviewing the effectiveness of implemented treatments. These steps ensure that risks are well-managed according to relevant policies and legislation .

Risk categorization helps in managing risks by determining the likelihood and consequences of each risk, which allows organizations to prioritize those risks appropriately. This process facilitates the development of specific control measures, helps in resource allocation, and ensures that higher risk areas receive more attention in terms of monitoring and response .

When identifying risks in a work setting, factors such as the context of risk management, potential economic scenarios, human behavior, and management activities should be considered. Additionally, natural events, technological issues, legal relationships, and the organizational objectives or project goals need to be evaluated to ensure comprehensive risk identification .

The risk management process is iterative because it involves repeated cycles of risk identification, assessment, treatment, and monitoring. This continuous loop allows for the adaptation and refinement of strategies as new risks emerge or as existing risks evolve. It contributes to organizational resilience by ensuring that risk responses are always aligned with the current environment and operational goals .

Control measures can be applied to mitigate identified risks by reducing the likelihood and consequences of risks, retaining or aversing risks, and transferring responsibility when appropriate. Hierarchical controls, such as eliminating hazards, substituting processes, or implementing engineering controls, can effectively lower risk levels. Additionally, organizational policies and training contribute to these measures .

You might also like