The risk is the potential loss exposure from a threat that disrupts business operations and prevents the organisation from achieving the Minimum Business Continuity Objective (MBCO).
A Threat is an indication or warning of a probable man-made or natural situation that can disrupt an organisation’s operations or services.
A Crisis Scenario describes a (crisis or disaster) situation that might disrupt the business.
In crisis management planning, a crisis scenario is the equivalent of threats, identified as part of the Risk Analysis and Review phase.
The three basic elements of a business crisis are:
The scenario should include stress indicators or observations. Reference the number of hours worked, safety and quality issues, risks, and legal or regulatory concerns in the crisis scenario.
A clear explanation of how the crisis is affected by increased stress on business operations can help reinforce the feeling of an emergency.
The events (or occurrences that happen over time) leading up to the crisis can pertain to people or human resources. Example as shown in Appendix 2: Crisis Types.
When the crisis is clearly defined, and the events leading up to it are known, the organisation can provide an inventory of available resources and the current status of the situation.
They can also create a timeline of the problems that led up to the crisis.
These include actions that have already been taken. Identify the people to contact to take action, including anyone who may be able to assist during the crisis.
You may also want to provide a toolkit of software applications, communication channels, references, or other resources to help crisis responders.
The sources of risk (Australian Government, 2012a) may include:
Elements at risk (Australian Government, 2012a) cover the:
In this chapter, the performance criteria describe the performance needed to demonstrate achievement of the “Element of Risk.” The performance criteria are to:
In the crisis management planning process, the Risk Analysis and Review (RAR) phase focuses on identifying adverse threats and crises affecting organisational assets and on providing risk treatment or crisis strategies for them.
By addressing the major fields of threat exposure, this phase details the risk assessment framework to enable a suitable response.
It identifies the types of crises that could occur in an organisation concerning its weaknesses and limitations.
Threats, either man-made or natural, are situations or conditions that can cause disruption or crisis to an organisation’s operations or services. Threats are generic. They may or may not have an impact on a given organisation.
For example, an organisation may be immune to a certain threat. Alternatively, a particular threat may not apply to an organisation.
Vulnerability refers to threats pertinent to the organisation concerned.
Risk Analysis is the process of evaluating these threats objectively using quantitative or qualitative methods. These methods usually employ some element of likelihood or uncertainty in their evaluation.
For a start, a scan of the horizon is conducted to categorise potential threats by type and cause.
From the sources of risk, these are some of the basic types of crises:
As an example of what each business should be prepared to deal with:
Goh, M. H. (2016). A Manager’s Guide to Implement Your Crisis Management Plan. Business Continuity Management Specialist Series (1st ed., p. 192). Singapore: GMH Pte Ltd.
Extracted from Recognise the Sources of Risk
To learn more about the course and schedule, click the buttons below for the CM-300 Crisis Management Implementer [CM-3] and the CM-5000 Crisis Management Expert Implementer [CM-5].
|
Please feel free to send us a note if you have any questions. |
||