0% found this document useful (0 votes)
10 views6 pages

Effective Risk Management Strategies

This document describes the basic principles of risk management. It defines key terms such as risk, probability, impact, and risk factors. It also explains the qualitative and quantitative approaches to risk analysis.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views6 pages

Effective Risk Management Strategies

This document describes the basic principles of risk management. It defines key terms such as risk, probability, impact, and risk factors. It also explains the qualitative and quantitative approaches to risk analysis.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Risk Management

Risk management is the discipline that


aims to identify, assess, and prioritize the risks related to the activities of an organization,
whatever the nature or origin of these risks, to address them methodically
in a coordinated and economical way, in order to reduce and control the probability of
feared events, and reduce the potential impact of these events.

In this regard, it is a component of the business strategy aimed at reducing the probability
of failure or uncertainty of all factors that may affect his business project. Management
continuous monitoring of a company's risk matrix requires the vision and vigilance of the leader and
its advice and frameworks, to readjust it to the realities of the field and the regulatory systems that
apply.

In large companies, there are specialized teams led by a ...


risk manager. Its role is to manage the risks of the company that
employment. Medium-sized companies are still not very concerned about management of
risks. According to a study by the auditing firm Mazars, which surveyed about 200 companies
showing revenues of 100 million to several billion euros, the risks they
The ones that worry the most are those that can lead to a penalty for the client, followed by the risks.
techniques or operational. Next come the industrial, legal, tax risks and
computer science1.

Summary

1 - Businesses and uncertainties


o 1.1 - Definition of the term 'risk'
o 1.2 - Part of uncertainty
o 1.3 - Risk factor
o 1.4 - Impact and Severity
2 - Finesse of risk analysis
o 2.1 - Qualitative management
o 2.2 - Severity scale and time scale
o 2.3 -Quantitative risk management

3 -Steps and principles of risk management


o 3.1 - Perception and explanation
o 3.2 - Risk Assessment
o 3.3 - Risk Management
o 3.4 - Risk management measures
o 3.5 - Control
4 - Specific approaches to risk management
o 4.1 - Project Risk Management
o 4.2 - Management of societal risks
o 4.3 - Hazard Study
o 4.4 - Financial Risk Management
o 4.5 - Vulnerability Study

Businesses and uncertainties

Definition of the term 'risk'


According to the ISO Guide 73 - Vocabulary of Risk Management2who was reviewed during the
development of the ISO 31000:2009 standard – Risk management — Principles and guidelines
guidelines3the risk is newly defined as "the effect of uncertainty on objectives" and
is added as a note4that "A risk is often characterized in reference to events and
potential consequences or a combination of both.

The risk is the combination of four factors: a hazard, a probability of occurrence,


the gravity of its acceptability5. Danger is an event feared (by itself and by
its consequences), the "risk" is therefore not to be confused with danger, but results from what
this danger has a certain probability of manifesting and would lead to consequences of a
certain gravity5The criticality of a risk results from the combination of the impact (or effect or severity)
and of the probability of a risk (AFNOR).

Part of uncertainty

On a day of great departure, traffic jams are not a 'risk': they are almost a certainty.

The portion of uncertainty that genuinely represents a risk is usually low, meaning that
the 'normal' course of a reasonable activity is one where the intended objective is achieved (unless
accident). This does not mean that there is little uncertainty in a reasonable project, but
rather than the level of uncertainty usually encountered is normally controlled, and is not
likely to compromise the achievement of the objective. For example, if I intend to cross a
Driving in the city, I will clearly have no certainty about the state of the red lights, but one
by compensating the other I can generally hope to make this crossing within a fairly
predictable, while accepting a certain residual risk (low) of 'taking all the lights'
"red" and arriving late, despite the buffer I had taken.

Unlike the assessment of impact, the probability of a feared event can


generally be evaluated objectively, even if it is in a very approximate manner: the
The realistic or non-realistic character of a scenario can in principle be subject to analysis and examination.
critique not involving subjective judgment, even if it is often unnecessary in practice to
carry out a very detailed analysis.

When the risk is subject to a quantified analysis, its probability of occurrence is therefore
normally low, even very low. If the probability of a scenario presented as 'risk'
is estimated at more than a dozen percent, it is actually an alternative scenario of
the activity; and if it exceeds 50%, what we qualify as 'risk' has actually become the
a scenario that a reasonable forecast should consider as a reference.

Risk factor

Psychoactive substances are a risk factor for driving a vehicle.

The risk factor (sometimes called peril or danger) is a present element that is likely to affect.
to cause a risk, that is to say the occurrence of the accident.

The factors of risk oneself qualifying by their domain (human, cultural


material, technical (toxic risk, thermal, explosion..., legal, etc.) or their point
application (the project itself, and the organization within which it will be embedded). They are
quantify in terms of uncertainty and/or complexity.

A car accident can occur, for example, for a driver who has consumed alcohol,
in the presence of a truck, on a dangerous road, while it is raining (four risk factors),
the probability and impact of the accident being all the more significant as the amount of alcohol consumed increases

by the driver was important, the truck powerful and heavy, the road winding and without visibility,
and the pouring rain (critical points).
Impact and severity

Rain is not necessarily a 'risk' for a walk for two.

An event is perceived as a risk only to the extent that it can have an impact (in
negative principle) on the achievement of a goal one seeks to achieve, or on a value to which
we adhere to and want to respect in our activity. Thus, if I want to organize a walk
family-related, bad weather can be a "risk", either because it would force me to cancel the
exit (abandoned objective), either because it would turn the exit into a bad experience
(compromised comfort value); conversely, if the rain is not considered uncomfortable, it does not
does not constitute a "risk" in the strict sense, but a mere eventuality.

Unlike probability, the assessment of such an impact is necessarily subjective. It


depends on the entity making this assessment, the values it respects, and the importance
that it grants to the potentially compromised project.

In risk analysis and management, 'risk' is, by principle, an event that


negative consequences. It is through misuse of language that we sometimes hear about a 'risk'
to win the lottery" (the correct wording in this case is that one has "a chance of
"to gain"). To talk about unexpected events with positive consequences, one would rather talk about
of an 'opportunity'. The management of opportunities is entirely symmetrical to that of risks
in terms of methods. Everything said about the risks directly translates onto the
opportunities. However, these two aspects differ radically, most of the time, in
terms of expected added value and functions of companies: as a general rule, a company
The responsible person must above all manage their risks at a level that is often quite detailed.
(HSCT risks notably); few are the companies (stock placement, conducting a)
military battle…) where opportunities are indeed managed by the person in charge at the same
title that the risks.
Subtleties of risk analysis

Qualitative management

Example of a qualitative risk assessment, typical of project management: classification by class


impact and probability class (here in five classes).

Although the concepts implemented are essentially the same in all cases, the
the goals and methods used will be very different depending on whether risk management is concerned with
the risk management of a project, to the security analysis of a system, to the control of
functioning of an institution, quality control or internal control, to risks
public health, to the coverage of exchange rate risks...

Thus, the risk analysis of a small project (on the order of twenty people over five years)
will often be satisfied with a three-level probability grid (~10%=possible,
~1%=uncertain, ~0.1%=envisageable) and a grid of consequences at three levels (A=return to
due to the project itself, B=contract not respected, C=manageable with the available margins). In
In fact, managing a project is inherently full of unpredictables, so there is no point in getting oneself
worry about very unlikely scenarios, knowing that the hazards of the project will lead to all
in a way to modify the planning long before anything 'unlikely' happens
the time to occur. For the same reasons, the classes of risks and consequences
can be broad, insofar as the necessary information here is mainly qualitative.

Severity scale and timeline

Example of risk pyramid: frequency and severity vary in opposite directions.


Conversely, the risk analysis on health and safety at work in an industry
Chemistry ICPE will focus on events located on a very broad scale of severity (from
"to cut slightly" up to "toxic cloud causing thousands of deaths outdoors"). In
As a consequence, the expected frequency scale must therefore also be broad.
"week" to "by millions of years"). Indeed, the concerning nature of a risk being
function both of its impact (cost) and its likelihood (probability), that is to say of
the mathematical expectation of loss that it entails (when these elements can be quantified), the
rational risk management leads to prioritizing the reduction of those for which the product 'cost x
Probability is the most important. Therefore, if this analysis is conducted rationally, the
risks that we accept to undergo as is, without taking additional measures, tend to
to all be at the same level "cost x probability", and therefore the cost scale must be broad as well
that of probabilities.

If therefore (to clarify the ideas) "to cut oneself slightly" is judged (subjectively, by the authority
one hundred times less serious than "ten days of sick leave," itself considered ten thousand times
less serious than "a fatal accident", we see that in this hypothesis the scale of severity
Such an ICPE relates to nine orders of magnitude: if it seems ethically acceptable not to
take additional measures as long as 'slightly cutting oneself' occurs only twice
"per week", a rational risk management should then lead to continued reduction
the eventuality of a "toxic cloud causing thousands of outdoor deaths", as long as the probability
of such a catastrophe remains stronger than once "every million years" (that is to say a
probability of 10-6per year).

Quantitative risk management


In this last case, we can understand that purely qualitative management is impossible for
appreciate the respective importance of events spanning nine orders of magnitude. A
safety level preventing a disaster at level 10-6by a year cannot rest on
simple devices, but must rely on design measures and provisions
of safety and multiple independent controls, whose individual reliability is sufficient
so that the probability of their simultaneous failure (itself produces probabilities
individual failures), leaving the door open to disaster, either at the expected level. And
The associated risk analysis can no longer be qualitative, but must be quantified based on
based on objective experience data.

You might also like