Training-led Implementation Series
CM_d

Assessing Your Risk: Risk Analysis

Risk Analysis and Review (RAR) phase is one of the first steps undertaken in the BCM plan development cycle. This RAR phase is conducted not only in business continuity (BC) planning but also for crisis management (CM), crisis communication (CC) and IT disaster recovery [BC | CM | CC | ITDR] planning. 

It may be helpful to know that in CM and CC, this phase is renamed as Crisis Scenario Risk Assessment (CRA).  In IT Disaster Recovery, this phase is known as IT RAR.

This is the first of the "New BCM Manager" series on RAR attempts to clarify and answer some common questions you may have before starting the RAR phase of your project.

Moh Heng Goh

2_Risk Analysis and ReviewBefore developing a business continuity management (BCM) program, a New Manager responsible for business continuity (BC), crisis management (CM), crisis communication (CC), and IT disaster recovery (ITDR) or moving to the Business Unit (BU) unit, especially for BC planning, the BU BCM Coordinator should first conduct a risk assessment to obtain an organization's risk profile. 

The risk profile provides context for the kinds of threats faced by the organization and gives the New [BC | CM | CC | ITDR] Manager or BU Coordinator an idea of what he is up against. The risk profile is also important for deciding the type of BC, CM, CC, or IT DR plan to develop.

There are various ways to approach risk assessment in BCM, CM, CC, and IT DR. The current approach is to abide by the ISO22301 BCM Standards. Another common way is the one presented in the ISO 31000 Risk Management Standard. This generic risk management standard can also be used to assess risk in BCM.

You may want to know how the Risk Analysis and Review phase fits into the Planning Methodology.  What is the Planning Methodology?

Risk Analysis Process

Only when we have sufficiently understood the organization would we begin to identify possible threats that could disrupt the organisation. It is often advantageous to assemble a group of subject matter experts and poll them for their views based on facts and hardcore experience.

Meanwhile, as we speak, there is a risk management standard published by the International Standard Organisation, better known by its acronym ISO. The published ISO 31000 standard is auditable. Hence, it will be good for related disciplines to align with this standard.

While identifying threats, the "New Manager" or, at the BU level, the BU Coordinator would also collect information from the subject matter experts on the likelihood of the threat's occurrence and its potential impact should it occur.

Risk Analysis and Review Process-1

This process of estimating risk likelihood and risk impact is called risk analysis. To properly implement this step, the "New Manager" should ideally have developed a rating scale for likelihood and impact. It is generally good practice to use a 5-level scale for higher granularity.

While doing this, keep in mind the organisation’s risk appetite. The scale for impact may also be used in the business impact analysis phase.

Risk Ratings and Risks Levels

The product of risk likelihood and risk impact results in a risk rating value that indicates how high or low a threat's risk is. A high-risk rating would undoubtedly indicate a high risk of disruption. This determination of the threat's “riskiness” is called risk evaluation.

It often makes sense to group risk rating values to give risk levels so that threats falling within the same risk level grouping can be assigned the same importance and priority for treatment.

The higher the risk level, the more priority would be given to treating the threat.

The following articles on Assessing Your Risk will discuss Treating Your Risk.

Reminder

In this reading, you are introduced to the following terminology.

 

Risk_Likelihood Risk_Impact Risk_Rating Risk_Level Risk_Appetite
Risk Likelihood Risk Impact Risk Rating Risk Level Risk Appetite

 

Learn More About Business Continuity Management (BC-CM-CC-ITDR-Audit)

[BL-3-Catalog] What Specialist Level Blended Learning Courses that are Available? Banner [BL-5-Catalog] What Expert Level Blended Learning Courses that are Available?

singapore_flagFunding is available for our Singapore colleagues under the SkillsFuture Funding and WSQ program.

 

New call-to-action New call-to-action New call-to-action New call-to-action [SSG-F][BL-DR-5] What Funding Is Available?

More Information About BCM-5000 [B-5] or BCM-300 [B-3]

BCCE Business Continuity Certified Expert Certification (Size 50)BCCS Business Continuity Certified Specialist Certification (Size 100)To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [B-3] course and the BCM-5000 Business Continuity Management Expert Implementer [B-5] course.

Register [BL-B-3]* New call-to-action New call-to-action
New call-to-action New call-to-action New call-to-action
FAQ [BL-B-3]

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

 

 FAQ BL-B-5 BCM-5000
[BL-B-3] What is a BCM-300 Blended Learning? New call-to-action [BL-B-5] What is a BCM-5000 Blended Learning Course?
 

For Your Comments:

 

More Posts

New Call-to-action