BCM Planning Methodology

Case Study Exercise [1]: Risk Analysis and Review [A]

Written by Moh Heng Goh | May 13, 2020 1:49:44 PM

Risk Analysis and Review [A]

Using the case scenario given, perform a risk analysis and review (RAR) of the following:

  • The corporate HQs at its given location
  • Any other issues of risk that might have BCM implications

You may make any reasonable assumptions and limitations of your analysis and review but they must be explicitly stated.  These could include existing and historical data and occurrences, additional information and statements about the bank and its operations.

As part of the risk analysis and review process undertaking the following activities  :

[A] Identify Risk and Impact Categories

Identify the main risk and impact categories confronting the organization

For example: financial, operations, regulatory, etc. Devise an appropriate multi-level impact category (VH/ H /M /L/ VL) and state what each of these mean for each of the identified risk categories.

The following provides a probable outcome of such undertaking

Risk and Impact Categories

 

  Impact Remarks
Risk Very High High Medium Low Very Low
Financial            
Operations            
Regulatory & Legal            
             
             

 

[B]  Establish a List of Probable Threats Confronting the Organization

Brainstorm and establish a list of probable threats confronting the organization and which could have BC implications. Rank this list via a rating system agreed among your risk team.

The following could be a probable outcome of such an exercise

Ranking of Threats to Organization

 

  Ranking of Threats

Overall Ranking

(Very High, High Medium, Low, Very Low)
 
Threats Very High High Medium Low Very Low Remarks
Fire              
Pandemic              
               
               
               
               

 

[C] Estimate the Probable Duration of Disruption for each Threats

From your table established above brainstorm and estimate the probable duration of disruption for each threats. What could you conclude about the threats occurrence to the given organization in terms of duration?

 

 

 

 

 

 

 

Link to Sections of Case Study