Training-led Implementation Series
CM_d

[BCM] [P2] [RAR] Assessing Your Risk: Risk Analysis

New call-to-actionRisk Analysis and Review (RAR) phase is one of the first steps undertaken in the BCM plan development cycle.

This RAR phase is conducted not only in business continuity (BC) planning but also for crisis management (CM), crisis communication (CC) and IT disaster recovery [BC | CM | CC | ITDR] planning. 

It may be helpful to know that in CM and CC, this phase is renamed as Crisis Scenario Risk Assessment (CRA).  In IT Disaster Recovery, this phase is known as IT RAR.

This is the first of the "New BCM Manager" series on RAR, which attempts to clarify and answer some common questions you may have before starting the RAR phase of your project.

Moh Heng Goh

New call-to-actionNew call-to-actionBefore developing a business continuity management (BCM) program, a New Manager responsible for business continuity (BC), crisis management (CM), crisis communication (CC), and IT disaster recovery (ITDR) or moving to the Business Unit (BU) unit, especially for BC planning, the BU BCM Coordinator should first conduct a risk assessment to obtain an organisation's risk profile. 

The risk profile provides context for the kinds of threats the organisation faces and gives the New [BC | CM | CC | ITDR] Manager or BU Coordinator an idea of what he is up against.

The risk profile is also important for deciding the type of BC, CM, CC, or IT DR plan to develop.

There are various ways to approach risk assessment in BCM, CM, CC, and IT DR. The current approach is to abide by the ISO22301 BCM Standards.

Another common approach is presented in the ISO 31000 Risk Management Standard. This generic risk management standard can also be used to assess risk in BCM.

You may want to know how the Risk Analysis and Review phase fits into the Planning Methodology.  What is the Planning Methodology?

 

Risk Analysis Process

Only when we have sufficiently understood the organisation would we begin to identify possible threats that could disrupt the organisation.

It is often advantageous to assemble a group of subject matter experts and poll them for their views based on facts and hard-core experience.

Meanwhile, as we speak, there is a risk management standard published by the International Organisation for Standardisation, better known by its acronym ISO. The published ISO 31000 standard is auditable. Hence, it will be good for related disciplines to align with this standard.

While identifying threats, the "New Manager" or, at the BU level, the BU Coordinator would also collect information from the subject matter experts on the likelihood of the threat's occurrence and its potential impact should it occur.

Risk Analysis and Review Process-1

This process of estimating risk likelihood and risk impact is called risk analysis.

To properly implement this step, the "New Manager" should ideally have developed a rating scale for likelihood and impact.

It is generally good practice to use a 5-level scale for higher granularity.

While doing this, keep in mind the organisation’s risk appetite. The impact scale may also be used during the business impact analysis phase.

Risk Ratings and Risks Levels

The product of risk likelihood and risk impact yields a risk rating that indicates how high or low a threat's risk is.

A high-risk rating would undoubtedly indicate a high risk of disruption. This determination of the threat's “riskiness” is called risk evaluation.

It often makes sense to group risk rating values into risk levels, so that threats within the same level grouping can be assigned the same importance and priority for treatment.

The higher the risk level, the greater the priority given to treating the threat.

The following articles on Assessing Your Risk will discuss Treating Your Risk.

 

Terminology

In this reading, you are introduced to the following terminology.

 

BCMPedia Risk Likelihood BCMPedia Risk Impact BCMPedia Risk Rating BCMPedia Risk Level New call-to-action
Risk Likelihood Risk Impact Risk Rating Risk Level Risk Appetite

 

Learn More About Business Continuity Management (BC-CM-CC-ITDR-Audit)

[BL-3-Catalog] What Specialist Level Blended Learning Courses that are Available? Banner [BL-5-Catalog] What Expert Level Blended Learning Courses that are Available?

singapore_flagFunding is available for our Singapore colleagues under the SkillsFuture Funding and WSQ program.

 

New call-to-action New call-to-action New call-to-action New call-to-action [SSG-F][BL-DR-5] What Funding Is Available?

More Information About BCM-5000 [B-5] or BCM-300 [B-3]

BCCE Business Continuity Certified Expert Certification (Size 50)BCCS Business Continuity Certified Specialist Certification (Size 100)To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [B-3] course and the BCM-5000 Business Continuity Management Expert Implementer [B-5] course.

New call-to-action
New call-to-action Register [BL-B-3]*
New call-to-action New call-to-action New call-to-action
FAQ [BL-B-3]

Please feel free to send us a note if you have any questions.

Email to Sales Team [BCM Institute]

 FAQ BL-B-5 BCM-5000
New call-to-action New call-to-action New call-to-action
 

For Your Comments:

 

More Posts

New Call-to-action