eBook 2: Chapter 3
Risk Analysis and Review Phase of the BCM Planning Methodology for
ALPS Healthcare
Introduction
Risk Analysis and Review (RAR) is the second phase of the Business Continuity Management (BCM) Planning Methodology and forms the foundation for developing effective business continuity strategies.
Before an organisation can determine how it will continue to operate during a disruption, it must first understand the threats that could disrupt its operations, assess the potential consequences of those threats, and identify appropriate measures to reduce risk to an acceptable level.
For ALPS Healthcare (ALPS), Risk Analysis and Review is particularly important because the organisation serves as Singapore's national healthcare supply chain agency, responsible for the procurement, warehousing, inventory management, and distribution of pharmaceuticals, medical devices, and healthcare consumables supporting the public healthcare system.
Disruptions affecting ALPS can have cascading consequences across hospitals, polyclinics, community healthcare providers, and ultimately patient care.
The risk landscape facing ALPS continues to evolve.
Traditional operational risks such as fires, power failures, equipment breakdowns, and transportation disruptions are now accompanied by increasingly sophisticated cyberattacks, ransomware incidents, supply chain disruptions, geopolitical instability, pandemics, climate-related events, and shortages of critical medical products.
As healthcare supply chains become increasingly interconnected and digitally enabled, the potential for single-point failures affecting multiple healthcare institutions has increased significantly.
The objective of the Risk Analysis and Review Phase is not simply to identify threats, but to understand how these threats may affect ALPS' critical business functions, evaluate the effectiveness of existing controls, determine residual risks, and establish priorities for mitigation.
This enables ALPS to make informed decisions regarding investments in resilience, recovery capabilities, supplier diversification, technology safeguards, and operational improvements.
This chapter presents a practical four-step Risk Analysis and Review methodology specifically tailored to ALPS Healthcare.
The methodology aligns with the principles of ISO 22301 and supports the development of a resilient Business Continuity Management System to protect Singapore's healthcare supply chain.
Purpose of Risk Analysis and Review
The objectives of this phase are to:
- Identify threats that may disrupt ALPS Healthcare's operations.
- Understand vulnerabilities across business functions and supporting resources.
- Assess the likelihood and business impact of identified risks.
- Evaluate the effectiveness of existing preventive and detective controls.
- Determine residual risks requiring further treatment.
- Prioritise risks based on organisational impact.
- Recommend practical mitigation measures.
- Provide input to the Business Impact Analysis (BIA) and Business Continuity Strategy (BCS) phases.
- Support informed management decision-making.
- Promote continual improvement of organisational resilience.
Risk Analysis and Review Framework
The Risk Analysis and Review process consists of four integrated steps.
|
Step |
Description |
Primary Deliverables |
|
Step 1 |
Identifying Risks |
Threat Catalogue, Asset Register, Risk Inventory |
|
Step 2 |
Assessing Risks |
Risk Assessment Matrix, Risk Register |
|
Step 3 |
Mitigating Risks |
Risk Treatment Plan, Control Improvement Programme |
|
Step 4 |
Continuous Review |
Updated Risk Register, Management Review Reports |
The four steps form a continuous cycle that ensures ALPS Healthcare's risk profile remains current and responsive to changes in the healthcare supply chain environment.
Step 1 – Identifying Risks
Objective
Identify all credible threats that could disrupt ALPS Healthcare's critical business functions, supporting infrastructure, personnel, suppliers, technology, facilities, and healthcare supply chain operations.
Risk identification should be comprehensive and involve representatives from all business units.
Sources of Risk Identification
ALPS should gather risk information from multiple sources, including:
- Historical incidents
- Internal audits
- Business continuity exercises
- Cybersecurity assessments
- Supplier assessments
- Industry intelligence
- Government advisories
- Regulatory guidance
- Staff workshops
- Lessons learned from previous disruptions
Major Risk Categories
Typical risk categories include:
- Natural hazards
- Facility-related incidents
- Technology failures
- Cybersecurity threats
- Human resource risks
- Supply chain disruptions
- Utility failures
- Third-party service failures
- Regulatory changes
- Public health emergencies
Examples – ALPS Healthcare
Potential risks include:
|
Risk Category |
Example Risk |
|
Supply Chain |
Failure of an overseas pharmaceutical manufacturer |
|
Logistics |
National transportation disruption delaying deliveries |
|
Warehouse Operations |
Fire affecting a central warehouse |
|
Cold Chain |
Refrigeration system failure compromising vaccine storage |
|
Information Technology |
Warehouse Management System (WMS) outage |
|
Cybersecurity |
Ransomware attack affecting procurement systems |
|
Suppliers |
Insolvency of a critical medical supplier |
|
Human Resources |
Shortage of qualified warehouse personnel during a pandemic |
|
Utilities |
Extended power outage affecting distribution operations |
|
Regulatory |
Import restrictions on critical medical products |
|
Public Health |
Pandemic resulting in extraordinary demand for medical supplies |
Step 2 – Assessing Risks
Objective
Evaluate each identified risk by analysing its likelihood of occurrence and its potential impact on ALPS Healthcare's operations.
Risk assessment provides a consistent method for prioritising management attention and resource allocation.
Assessment Criteria
Each risk should be evaluated based on:
- Likelihood of occurrence
- Operational impact
- Financial impact
- Regulatory consequences
- Healthcare service impact
- Reputational damage
- Recovery complexity
- Existing control effectiveness
Example Risk Assessment Matrix
|
Likelihood |
Description |
|
Rare |
Highly unlikely to occur |
|
Unlikely |
Could occur occasionally |
|
Possible |
May occur periodically |
|
Likely |
Expected to occur under certain conditions |
|
Almost Certain |
Expected to occur frequently |
|
Impact |
Description |
|
Insignificant |
Minimal operational effect |
|
Minor |
Limited disruption |
|
Moderate |
Noticeable impact requiring management intervention |
|
Major |
Significant disruption to multiple business functions |
|
Severe |
Enterprise-wide disruption affecting healthcare supply continuity |
Example – ALPS Healthcare
A ransomware attack targeting the procurement and inventory management systems may be assessed as:
- Likelihood: Likely
- Operational Impact: Major
- Healthcare Impact: Severe
- Financial Impact: Major
- Overall Risk Rating: Extreme
This assessment indicates that immediate mitigation and recovery planning are required.
Step 3 – Mitigating Risks
Objective
Implement preventive, detective, corrective, and recovery controls to reduce identified risks to an acceptable level.
Risk mitigation should balance operational effectiveness, cost, regulatory expectations, and organisational resilience.
Risk Treatment Options
ALPS may choose to:
- Avoid the risk.
- Reduce the likelihood.
- Reduce the consequences.
- Transfer the risk.
- Accept the residual risk.
Categories of Mitigation Measures
Governance Controls
- Policies
- Procedures
- Management oversight
- Internal audits
Operational Controls
- Standard operating procedures
- Inventory management
- Supplier qualification
- Workforce cross-training
Technology Controls
- System redundancy
- Data backups
- Multi-factor authentication
- Network segmentation
- Endpoint protection
Supply Chain Controls
- Multiple suppliers
- Strategic inventory buffers
- Supplier continuity assessments
- Alternate logistics providers
Physical Controls
- Fire protection systems
- Access controls
- Environmental monitoring
- Cold-chain monitoring
- Warehouse security
Example – ALPS Healthcare
To reduce the risk of pharmaceutical shortages resulting from supplier failure, ALPS may implement:
- Multiple approved suppliers for essential medicines.
- Strategic safety stock for critical products.
- Regular supplier resilience assessments.
- Regional sourcing alternatives.
- Emergency procurement procedures.
- Long-term framework agreements with key manufacturers.
- Continuous monitoring of supplier financial health.
Step 4 – Continuous Review
Objective
Maintain an accurate, up-to-date understanding of organisational risks by regularly reviewing changes affecting ALPS Healthcare's operating environment.
Risk management is an ongoing process rather than a one-time exercise.
Review Triggers
The risk profile should be reviewed following:
- Major organisational changes.
- New healthcare services.
- Technology implementation.
- Supplier changes.
- Regulatory updates.
- Cybersecurity incidents.
- Natural disasters.
- Exercise findings.
- Internal audits.
- Actual disruptions.
Periodic Reviews
Regular reviews should include:
- Risk Register updates.
- Emerging threat analysis.
- Control effectiveness reviews.
- Management reporting.
- Internal audit findings.
- Business continuity exercise outcomes.
Example – ALPS Healthcare
Following the implementation of an automated warehouse management system and robotics, ALPS updates its Risk Register to include:
- Automation system failures.
- Robotics software defects.
- Cybersecurity risks affecting warehouse automation.
- Integration failures with procurement systems.
- Increased dependency on cloud services.
Mitigation measures are reviewed and updated to reflect the changing operational environment.
Developing the ALPS Healthcare Risk Register
The Risk Register serves as the central repository for documenting and monitoring organisational risks.
Typical information includes:
|
Field |
Description |
|
Risk ID |
Unique identifier |
|
Risk Description |
Description of the threat |
|
Business Function |
Affected business function |
|
Existing Controls |
Current preventive measures |
|
Likelihood |
Risk probability |
|
Impact |
Consequence rating |
|
Residual Risk |
Remaining risk after controls |
|
Risk Owner |
Responsible manager |
|
Mitigation Actions |
Planned improvements |
|
Review Date |
Next scheduled review |
Example Entry
|
Field |
Example |
|
Risk ID |
RAR-023 |
|
Risk |
Refrigeration failure in pharmaceutical cold room |
|
Business Function |
Cold-Chain Logistics |
|
Existing Controls |
Dual refrigeration units, temperature monitoring, generator backup |
|
Residual Risk |
Medium |
|
Owner |
Warehouse Operations Manager |
|
Mitigation |
Install predictive monitoring sensors and enhance maintenance schedules |
Roles and Responsibilities
Effective risk management requires collaboration across the organisation.
|
Role |
Responsibilities |
|
Senior Management |
Approve risk appetite and review significant risks |
|
BCM Steering Committee |
Provide oversight of the RAR process |
|
BCM Manager |
Coordinate risk assessments and reporting |
|
Business Unit Managers |
Identify and assess operational risks |
|
Information Technology |
Assess technology and cyber risks |
|
Procurement |
Assess supplier and sourcing risks |
|
Warehouse Operations |
Evaluate storage and distribution risks |
|
Quality Assurance |
Assess risks affecting product integrity |
|
Human Resources |
Evaluate workforce continuity risks |
|
Internal Audit |
Provide independent assurance over the RAR process |
Success Factors for ALPS Healthcare
The effectiveness of the Risk Analysis and Review Phase depends on several key success factors:
- Strong executive commitment.
- Organisation-wide participation.
- Comprehensive risk identification.
- Reliable risk assessment methodology.
- Integration with enterprise risk management.
- Regular supplier resilience assessments.
- Continuous monitoring of emerging threats.
- Timely implementation of mitigation measures.
- Effective communication of significant risks.
- Commitment to continual improvement.
Relationship with the Business Impact Analysis
The outputs of the Risk Analysis and Review Phase directly support the next phase of the BCM Planning Methodology—the Business Impact Analysis (BIA).
Specifically, the RAR Phase:
- Identifies the threats that may disrupt business functions.
- Highlights vulnerabilities requiring detailed analysis.
- Supports prioritisation of critical business functions.
- Provides input for determining recovery objectives.
- Informs the development of appropriate business continuity strategies.
By understanding the risks facing ALPS Healthcare, the organisation can focus its Business Impact Analysis on the business functions and dependencies that are most critical to maintaining the continuity of Singapore's healthcare supply chain.
The Risk Analysis and Review Phase provides ALPS Healthcare with a structured and proactive approach to understanding the threats that could affect its ability to procure, store, manage, and distribute essential healthcare supplies.
Through the four-step process of identifying, assessing, mitigating, and continuously reviewing the risk environment, ALPS develops a comprehensive understanding of the vulnerabilities affecting its people, facilities, technology, suppliers, logistics networks, and critical business functions.
Given ALPS' strategic role in supporting Singapore's public healthcare system, effective risk management extends beyond protecting internal operations.
It requires continual collaboration among healthcare institutions, pharmaceutical manufacturers, logistics providers, technology partners, and government agencies to strengthen resilience throughout the healthcare supply chain.
By maintaining an up-to-date Risk Register, implementing appropriate controls, and regularly reviewing emerging threats, ALPS enhances its ability to anticipate disruptions, minimise operational impacts, and sustain the uninterrupted delivery of critical healthcare supplies.
The outputs from this phase—including the Threat Catalogue, Risk Register, Risk Assessment Reports, and Risk Treatment Plans—provide essential inputs to the Business Impact Analysis (BIA) Phase.
In the next chapter, ALPS Healthcare will identify its critical business functions, analyse operational dependencies, determine recovery priorities, and establish recovery objectives that form the basis of its business continuity strategies and plans.
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]


![[BCM] [ALPS] [Full Banner] Implementing Business Continuity Management for ALPS Healthcare](https://no-cache.hubspot.com/cta/default/3893111/a577c05a-ab89-4043-9a89-1dea0d883afc.png)

![[BCM] [ALPS] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/eb6856d2-cbb2-4a76-b237-7bd842e84226.png)

![[BCM] [ALPS] [E2] [C3] Risk Analysis and Review](https://no-cache.hubspot.com/cta/default/3893111/74b8cdd9-6407-4d41-bfa9-1c382a227c82.png)
![Banner [Summary] [BCM] [E2] [C3] Risk Analysis and Review](https://no-cache.hubspot.com/cta/default/3893111/a7beedb7-3b4e-4374-ae50-974a76b94b61.png)
![[BCM] [ALPS] [3/4 Banner] Implementing Business Continuity Management for ALPS Healthcare](https://no-cache.hubspot.com/cta/default/3893111/5bb3d163-ccf4-4942-8e51-90cb0e0de84f.png)
![[BCM] [ALPS] [E2] [C1] Business Continuity Management Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/34a98265-b1ac-4365-8fb1-b89701c81850.png)
![[BCM] [ALPS] [E2] [C2] Project Management](https://no-cache.hubspot.com/cta/default/3893111/2a25b902-93e0-4adc-9793-121a2849bfab.png)
![[BCM] [ALPS] [E2] [C4] Business Impact Analysis](https://no-cache.hubspot.com/cta/default/3893111/eedd40d9-b511-4e16-96de-58834c1e7d92.png)
![[BCM] [ALPS] [E2] [C5] Business Continuity Strategy](https://no-cache.hubspot.com/cta/default/3893111/404ab765-7f69-49dd-ac4a-b9079f065d1c.png)
![[BCM] [ALPS] [E2] [C6] BCM Plan Development](https://no-cache.hubspot.com/cta/default/3893111/4df32844-f3fe-4e88-b9e0-c33cd4f354f5.png)
![[BCM] [ALPS] [E2] [C7] Testing and Exercising](https://no-cache.hubspot.com/cta/default/3893111/be2eeb3c-4b1a-4d42-bebd-0a30e1047952.png)
![[BCM] [ALPS] [E2] [C8] Program Management](https://no-cache.hubspot.com/cta/default/3893111/52497940-4ed8-4ee5-b5e9-0a1b21e83f29.png)
![[BCM] [ALPS] [E2] [C9] Summary](https://no-cache.hubspot.com/cta/default/3893111/c702d1dd-d76e-4015-8be8-58641496151a.png)
![[BCM] [ALPS] [E2] [C10] Back Cover of eBook 2](https://no-cache.hubspot.com/cta/default/3893111/7f72c39b-5844-4487-92a5-c9d0f38f0bad.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





