Risk Management for Managers - 5 Simple Steps - YouTube

Channel: QualityGurus

[2]
Welcome to this course on introduction to risk management.
[9]
All types of organizations, face with the some form of risks, which may affect their
[14]
chance of success.
[15]
Understanding the risks, and effectively managing these, will greatly help the organizations,
[22]
in achieving the long term success.
[25]
Risk Management can be an important tool, to eliminate potential problems in an organization.
[30]
Even though the current version of ISO 9001, does not specifically require the use of risk
[36]
management, in the preventive action clause, some of the industry specific standards require
[42]
it specifically.
[44]
For example, the quality management standard for aviation industry, and healthcare industry,
[49]
have risk management requirement, included in the preventive action clause.
[58]
These are the topics covered in this course.
[62]
First we will understand the definitions of risk and risk management.
[66]
Then we will look at five key steps for managing risks.
[73]
Companies face a number of internal and external factors, which make it uncertain, whether
[78]
the company will meet its objectives.
[80]
These uncertain events, or conditions, are called the risks.
[85]
So far in this course, we thought that the risks always have a negative impact.
[90]
Lets be clear here, that the result of a risk, is not always negative.
[98]
Risks are uncertain events.
[100]
These uncertain events could lead to positive or negative results.
[105]
Positive risks are known as opportunities.
[108]
Organizations attempt to avoid, or reduce the impacts of negative risks.
[113]
However when it comes to the positive risks, organizations would like to take maximum advantage
[118]
of these opportunities.
[122]
This slide explains the difference between a risk, and an issue.
[129]
While a risk is a future uncertain event, an issue is an event which has already occurred.
[135]
The concepts of risk appetite, and risk tolerance, are related to the extent to which, an organization
[144]
is comfortable taking risk.
[146]
Taking big risks could be lead to big losses, or big rewards.
[151]
While risk appetite is about the willingness to take risk, risk tolerance is about what
[155]
the organization can bear.
[159]
As discussed on the previous slide, risk is associated with reward.
[168]
Organizations take risks to gain more rewards.
[171]
This is the definition of risk management, taken from wikipedia dot org.
[178]
If you find this definition confusing, then please proceed to the next slide.
[183]
This same definition is presented there, in form of a diagram.
[192]
In risk management, you identify the potential risks, then you assess them so that you know
[197]
which of the identified risks are more critical and which are less.
[201]
Based on that assessment you give more priority to some risks and less to others.
[206]
You can not cover all risks since you have limited resources.
[210]
With this priority you put your resources on high priority risks.
[215]
As we talked earlier a risk can be a negative or positive risk.
[219]
You attempt to minimize the impact of negative risks, monitor then and keep them under control.
[225]
However if it is a positive risk, or an opportunity, you put your resources to maximize the opportunity.
[235]
For risk management process to be effective, these are some of the key principles, that
[240]
should be considered.
[242]
Since the organization is spending resources, to manage risks, it should create value.
[248]
Risk management should be performed systematically, and be integral part of the organization's
[253]
work processes.
[254]
As the organization matures, the types of risks or challenges change.
[260]
The organization should adopt to these changes, and improve the risk management process.
[274]
Risk management is applied in variety of fields such as project management, military, space,
[280]
medical, engineering, plant operation, safety and in financial portfolio management.
[289]
Key benefits of implementing risk management includes fewer shocks and unwelcome surprises;
[296]
effective use of resources, and reassuring stakeholders.
[300]
Instead of being unprepared for the threats and opportunities, that happen during the
[304]
course of a project or business, risk management can help plan and prepare for them.
[309]
This preparedness helps organizations in saving costs and time.
[317]
Risk management process, can be divided into these five key steps.
[321]
It starts with having a risk management plan.
[325]
The next step is to identify the potential risks and prepare a list of all risks.
[331]
This list of risks is then analyzed, using qualitative, and quantitative techniques,
[336]
to identify high priority, medium priority and low priority risks.
[341]
Response is planned for these risks, depending upon the priority.
[346]
Risks are then monitored and controlled.
[348]
We will look at each of these steps, in the following slides.
[356]
Risk management plan specifies the management intent, systems and procedures required for
[361]
managing risks.
[368]
Risk management plan will provide the definitions of various risk related terms.
[372]
Roles and responsibilities related to risk, and tools and templates, are also included
[378]
in it.
[380]
In a way risk management plan specifies how the next four steps listed on this slide are
[388]
executed in the organization.
[390]
That is, how the organization will identify risks, how these risks will be analyzed, how
[396]
the risk response will be planned, and how the risks will be monitored and controlled.
[407]
Once the plan is in place, identify risks is the first key step in actual management
[412]
of risks.
[413]
This is the process of identifying the potential risks, their root cause, and the risk consequences.
[423]
Risk identification is a systematic process.
[426]
It is a group effort, where subject matter experts from various groups participate.
[437]
The most common tool used in risk identification process, is brain storming.
[442]
In this, the subject matter experts from various groups meet together, and list down all the
[447]
potential risks.
[450]
During brain storming, no identified risk is evaluated, or criticized.
[455]
The intent here is to list down as many possibles risks, in limited time.
[460]
Other tools such as Ishikawa diagram, flow diagram, and SWOT analysis may also be used.
[467]
Here the term SWOT, stands for Strengths, weaknesses, opportunities and threats.
[477]
The outcome of risk identification is a list of risks, or risk register.
[482]
What is done with the list of risks depends on the nature of the risk.
[486]
A few low priority risks may be kept simply as a list of red flag items, and periodically
[492]
monitored.
[493]
Some high priority risks, may go through the rigorous process of assessment, analysis,
[499]
mitigation and planning.
[501]
The next risk management process, that is analyze risks, helps in deciding that.
[511]
Organizations do not have resources to address all risks.
[515]
After having the list of all potential risks, the next logical step is to analyze and prioritize
[521]
risks.
[522]
Some risks may need detailed action plan, and some may just need periodic monitoring.
[528]
Organization may accept some of the risks without any action.
[531]
In this step, that is analyze risks, we will look at how the risks are analyzed and prioritized.
[538]
This is the process of quantifying the risk events, documented in the previous step, so
[546]
that the organization can focus on critical risks.
[553]
For risk analysis, qualitative and quantitative analysis are conducted.
[559]
Qualitative risk analysis is a subjective analysis, and is quick and easy to perform.
[564]
One tool to conduct the qualitative analysis is probability and impact matrix.
[569]
We will cover this tool in next few slides.
[573]
On the other hand, Quantitative risk analysis is the detailed analysis of the risk.
[578]
It is not required to conduct quantitative analysis for all risks, and is conducted when
[583]
it is worth the time and effort required to conduct it.
[588]
Tools to conduct quantitative risk analysis include, expected monitory value analysis,
[593]
Monte Carlo analysis, and decision tree.
[597]
These tools are not covered in this training course.
[602]
As discussed in the previous slide, the Probability and Impact Matrix, is a qualitative risk analysis
[613]
tool.
[614]
This matrix has two aspects, the probability that the risk will actually happen, and the
[620]
potential impact if the risk happens.
[623]
These two are classified from very unlikely, to very likely.
[628]
In the probability and impact matrix, the risk probability, and the risk impact are
[636]
assigned a score of 1 to 9.
[638]
Where 1 is the least, and 9 is the highest.
[641]
A risk score is then calculated, by multiplying these two numbers.
[647]
Instead of assigning a score of 1 to 9, a score of 1 to 3, or a score of 1 to 5 may
[652]
be used.
[654]
These rules are defined in your risk management plan.
[657]
In this course we are using a score of 1 to 9.
[663]
In this example, the group assigns a score of 1 to the probability of risk, and a score
[672]
of 9 to the impact value.
[674]
This means that the risk being discussed, has a very low chance of happening, but if
[679]
it happens, the impact will be very high.
[687]
Since the score of 1 to 9 assigned to the probability, and impact, are subjective, organization
[693]
managing the risk creates some guidelines, to ensure that these are consistent.
[698]
This slide shows a sample table, for assigning probability number.
[703]
The next slide will show a sample impact table.
[707]
This is a sample table, to assign the risk impact number.
[714]
The risk may impact cost, schedule, scope or quality.
[725]
Once we have assigned a risk probability number, and an impact number, these are plotted on
[730]
the probability and impact matrix.
[732]
A simple example of that is shown here.
[736]
Let us look at the four boxes shown here.
[739]
Risks towards the top right corner, are of critical importance, since these are High
[743]
impact and high probability risks.
[747]
These are your top priorities risks, that you must pay close attention to.
[752]
Risks in the bottom left corner are low impact, and low probability risks.
[757]
You can often ignore them.
[759]
Risks in the top left corner, are of moderate importance, since these are Low impact, and
[764]
high probability risks.
[766]
If these things happen, you can cope with them, and move on.
[771]
However, you should try to reduce the likelihood, that they'll occur.
[776]
Risks in the bottom right corner, are high impact, and low probability risks, and these
[781]
are very unlikely to happen.
[783]
For these, you should do what you can to reduce the impact, and you should have contingency
[788]
plans in place, just in case they occur.
[795]
This and the next slide, show examples of probability and impact matrix.
[800]
In this example, a score of 1 to 9 is assigned to the probability, and the impact.
[806]
This is an example of the probability and impact matrix, where the probability, and
[814]
the impact, are assigned a value between very low, to very high.
[823]
Once we have analyzed risks, the next step in risk management, is to plan risk response,
[829]
for each identified risk.
[833]
When planning a risk response, we attempt to reduce the impact and chance, of negative
[840]
risks, and enhance the impact and chance, of positive risks.
[847]
This slide shows the four risk responses, for negative risks, and the corresponding
[855]
responses for positive risks.
[857]
In the next eight slides, we will look at each of these responses.
[863]
In risk avoidance, we completely eliminate the possibility of the risk.
[870]
An example might be to use a old and proven process, instead of new and risky process.
[876]
Risk can also be avoided by improved communication, providing information, or acquiring an expert.
[887]
If you can not avoid a risk completely, you attempt to mitigate it.
[891]
The purpose of risk mitigation is to reduce the size of the risk exposure.
[895]
This is done by either reducing the probability of the risk, or by reducing the impact.
[902]
The risk transfer strategy aims to pass ownership for a particular risk to a third party.
[911]
It is also important to remember that risk transfer almost always involves payment of
[915]
a risk premium.
[916]
A Cost and benefit analysis might be done, to ensure that the cost of transferring risk
[922]
is justified.
[926]
Acceptance of a risk means that the probability, and or the severity, of the risk is low enough,
[931]
that we will do nothing about the risk, unless it occurs.
[935]
There are two kinds of acceptance, active and passive.
[940]
Acceptance is passive, when nothing at all is done to deal with the risk.
[944]
Acceptance is active, when we decide to make a contingency plan, for what to do, when the
[950]
risk occurs.
[951]
The next four slides, will deal with the risk responses for positive risks, or opportunities.
[962]
The first response to deal with the positive risk is to exploit it.
[966]
This response tries to remove any uncertainty, so that the opportunity is certain to happen.
[975]
The enhance response, focuses on the root cause of the opportunity, and goes on to influence
[980]
those factors, which will increase the likelihood of the opportunity occurring.
[988]
Sometimes exploiting a positive risk is not possible, without collaboration.
[993]
A partnership with a different group, department, or company may be required, to exploit a positive
[999]
risk Just like dealing with negative risks, we
[1006]
may actively or passively accept a positive risk.
[1010]
Acceptance of a risk means that the probability, and or the severity, of the risk is low enough,
[1015]
that we will do nothing about the risk, unless it occurs.
[1024]
Once we have identified risks, analyzed then and made a plan to deal with them, the next
[1029]
step is to monitor and control the risks.
[1034]
A risk management program is never finished.
[1040]
Risk monitoring and control, should be ongoing and continual.
[1045]
New risks will emerge, and existing risks will disappear.
[1049]
You have to stay on top of it.
[1053]
While monitoring and controlling risks, unexpected risks occur.
[1058]
These unexpected risks are the risks, which you did not identify in your risk identification
[1064]
process.
[1065]
A workaround is created to deal with such risks.
[1072]
Thank you for attending this course at QualityGurus.com.