Risk Analysis and Review (RAR) is the second phase of the Business Continuity Management (BCM) Planning Methodology and forms the foundation for developing effective business continuity strategies.
Before an organisation can determine how it will continue to operate during a disruption, it must first understand the threats that could disrupt its operations, assess the potential consequences of those threats, and identify appropriate measures to reduce risk to an acceptable level.
For ALPS Healthcare (ALPS), Risk Analysis and Review is particularly important because the organisation serves as Singapore's national healthcare supply chain agency, responsible for the procurement, warehousing, inventory management, and distribution of pharmaceuticals, medical devices, and healthcare consumables supporting the public healthcare system.
Disruptions affecting ALPS can have cascading consequences across hospitals, polyclinics, community healthcare providers, and ultimately patient care.
The risk landscape facing ALPS continues to evolve.
Traditional operational risks such as fires, power failures, equipment breakdowns, and transportation disruptions are now accompanied by increasingly sophisticated cyberattacks, ransomware incidents, supply chain disruptions, geopolitical instability, pandemics, climate-related events, and shortages of critical medical products.
As healthcare supply chains become increasingly interconnected and digitally enabled, the potential for single-point failures affecting multiple healthcare institutions has increased significantly.
The objective of the Risk Analysis and Review Phase is not simply to identify threats, but to understand how these threats may affect ALPS' critical business functions, evaluate the effectiveness of existing controls, determine residual risks, and establish priorities for mitigation.
This enables ALPS to make informed decisions regarding investments in resilience, recovery capabilities, supplier diversification, technology safeguards, and operational improvements.
This chapter presents a practical four-step Risk Analysis and Review methodology specifically tailored to ALPS Healthcare.
The methodology aligns with the principles of ISO 22301 and supports the development of a resilient Business Continuity Management System to protect Singapore's healthcare supply chain.
The objectives of this phase are to:
The Risk Analysis and Review process consists of four integrated steps.
|
Step |
Description |
Primary Deliverables |
|
Step 1 |
Identifying Risks |
Threat Catalogue, Asset Register, Risk Inventory |
|
Step 2 |
Assessing Risks |
Risk Assessment Matrix, Risk Register |
|
Step 3 |
Mitigating Risks |
Risk Treatment Plan, Control Improvement Programme |
|
Step 4 |
Continuous Review |
Updated Risk Register, Management Review Reports |
The four steps form a continuous cycle that ensures ALPS Healthcare's risk profile remains current and responsive to changes in the healthcare supply chain environment.
Identify all credible threats that could disrupt ALPS Healthcare's critical business functions, supporting infrastructure, personnel, suppliers, technology, facilities, and healthcare supply chain operations.
Risk identification should be comprehensive and involve representatives from all business units.
ALPS should gather risk information from multiple sources, including:
Typical risk categories include:
Potential risks include:
|
Risk Category |
Example Risk |
|
Supply Chain |
Failure of an overseas pharmaceutical manufacturer |
|
Logistics |
National transportation disruption delaying deliveries |
|
Warehouse Operations |
Fire affecting a central warehouse |
|
Cold Chain |
Refrigeration system failure compromising vaccine storage |
|
Information Technology |
Warehouse Management System (WMS) outage |
|
Cybersecurity |
Ransomware attack affecting procurement systems |
|
Suppliers |
Insolvency of a critical medical supplier |
|
Human Resources |
Shortage of qualified warehouse personnel during a pandemic |
|
Utilities |
Extended power outage affecting distribution operations |
|
Regulatory |
Import restrictions on critical medical products |
|
Public Health |
Pandemic resulting in extraordinary demand for medical supplies |
Evaluate each identified risk by analysing its likelihood of occurrence and its potential impact on ALPS Healthcare's operations.
Risk assessment provides a consistent method for prioritising management attention and resource allocation.
Each risk should be evaluated based on:
|
Likelihood |
Description |
|
Rare |
Highly unlikely to occur |
|
Unlikely |
Could occur occasionally |
|
Possible |
May occur periodically |
|
Likely |
Expected to occur under certain conditions |
|
Almost Certain |
Expected to occur frequently |
|
Impact |
Description |
|
Insignificant |
Minimal operational effect |
|
Minor |
Limited disruption |
|
Moderate |
Noticeable impact requiring management intervention |
|
Major |
Significant disruption to multiple business functions |
|
Severe |
Enterprise-wide disruption affecting healthcare supply continuity |
A ransomware attack targeting the procurement and inventory management systems may be assessed as:
This assessment indicates that immediate mitigation and recovery planning are required.
Implement preventive, detective, corrective, and recovery controls to reduce identified risks to an acceptable level.
Risk mitigation should balance operational effectiveness, cost, regulatory expectations, and organisational resilience.
ALPS may choose to:
To reduce the risk of pharmaceutical shortages resulting from supplier failure, ALPS may implement:
Maintain an accurate, up-to-date understanding of organisational risks by regularly reviewing changes affecting ALPS Healthcare's operating environment.
Risk management is an ongoing process rather than a one-time exercise.
The risk profile should be reviewed following:
Regular reviews should include:
Following the implementation of an automated warehouse management system and robotics, ALPS updates its Risk Register to include:
Mitigation measures are reviewed and updated to reflect the changing operational environment.
The Risk Register serves as the central repository for documenting and monitoring organisational risks.
Typical information includes:
|
Field |
Description |
|
Risk ID |
Unique identifier |
|
Risk Description |
Description of the threat |
|
Business Function |
Affected business function |
|
Existing Controls |
Current preventive measures |
|
Likelihood |
Risk probability |
|
Impact |
Consequence rating |
|
Residual Risk |
Remaining risk after controls |
|
Risk Owner |
Responsible manager |
|
Mitigation Actions |
Planned improvements |
|
Review Date |
Next scheduled review |
|
Field |
Example |
|
Risk ID |
RAR-023 |
|
Risk |
Refrigeration failure in pharmaceutical cold room |
|
Business Function |
Cold-Chain Logistics |
|
Existing Controls |
Dual refrigeration units, temperature monitoring, generator backup |
|
Residual Risk |
Medium |
|
Owner |
Warehouse Operations Manager |
|
Mitigation |
Install predictive monitoring sensors and enhance maintenance schedules |
Effective risk management requires collaboration across the organisation.
|
Role |
Responsibilities |
|
Senior Management |
Approve risk appetite and review significant risks |
|
BCM Steering Committee |
Provide oversight of the RAR process |
|
BCM Manager |
Coordinate risk assessments and reporting |
|
Business Unit Managers |
Identify and assess operational risks |
|
Information Technology |
Assess technology and cyber risks |
|
Procurement |
Assess supplier and sourcing risks |
|
Warehouse Operations |
Evaluate storage and distribution risks |
|
Quality Assurance |
Assess risks affecting product integrity |
|
Human Resources |
Evaluate workforce continuity risks |
|
Internal Audit |
Provide independent assurance over the RAR process |
The effectiveness of the Risk Analysis and Review Phase depends on several key success factors:
The outputs of the Risk Analysis and Review Phase directly support the next phase of the BCM Planning Methodology—the Business Impact Analysis (BIA).
Specifically, the RAR Phase:
By understanding the risks facing ALPS Healthcare, the organisation can focus its Business Impact Analysis on the business functions and dependencies that are most critical to maintaining the continuity of Singapore's healthcare supply chain.
The Risk Analysis and Review Phase provides ALPS Healthcare with a structured and proactive approach to understanding the threats that could affect its ability to procure, store, manage, and distribute essential healthcare supplies.
Through the four-step process of identifying, assessing, mitigating, and continuously reviewing the risk environment, ALPS develops a comprehensive understanding of the vulnerabilities affecting its people, facilities, technology, suppliers, logistics networks, and critical business functions.
Given ALPS' strategic role in supporting Singapore's public healthcare system, effective risk management extends beyond protecting internal operations.
It requires continual collaboration among healthcare institutions, pharmaceutical manufacturers, logistics providers, technology partners, and government agencies to strengthen resilience throughout the healthcare supply chain.
By maintaining an up-to-date Risk Register, implementing appropriate controls, and regularly reviewing emerging threats, ALPS enhances its ability to anticipate disruptions, minimise operational impacts, and sustain the uninterrupted delivery of critical healthcare supplies.
The outputs from this phase—including the Threat Catalogue, Risk Register, Risk Assessment Reports, and Risk Treatment Plans—provide essential inputs to the Business Impact Analysis (BIA) Phase.
In the next chapter, ALPS Healthcare will identify its critical business functions, analyse operational dependencies, determine recovery priorities, and establish recovery objectives that form the basis of its business continuity strategies and plans.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
| C6 | C7 | C8 | C9 | C10 |
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]
|
Please feel free to send us a note if you have any questions. |
||