Organisational risk: Predicting the unpredictable.
We can now add 'cost of living
In short, every organization must be underpinned by a risk register
I tend to begin with a PESTLE (political, economic, social, technological, environmental, and legal) which I combine with a SWOT (strength, weaknesses, opportunities, and threats). If we look at ISO to help us define 'interested party' then they talk of 'those who affect or can be affected'. Examples would include employees, suppliers, regulators, pressure groups, etc.
By using both methodologies in unison, an organisation can populate their risk register and create their own unique risk profile (appetite v capacity v requirement). By doing so, they add meaningful perspective to their strategy and objectives, which in turn informs vision and mission. In times of change, such as now, an organisation can live and die by a risk register.
The secret to having an accurate risk register is matching the management of the document (frequency and competency of review) with the threat landscape/ hazard burden. This is where a risk management professional
Recommended by LinkedIn
There are several proven methods that can help you to accurately quantify risk, these range from sensitivity examinations (often seen as a tornado diagram) to expected monetary value (EMV) analysis (commonly used in decision trees). However, what all quantitative methods deliver are verifiable data sets that leaders can employ to make objective decisions.
It is by following this journey map (or something relatively close) that resilience can be built through solid business continuity management
In summary, an effective risk professional is an evidence-based influencer who coordinates a quorum of discipline experts with external sources to derive an accurate risk-related picture which helps inform your decision making. If you don't have one, you could be living in a...
Managing Director at Operational Wisdom & Logic
2yNice summary. I often also emphasise (somewhat as you hinted wrt ‘managing the document’) that folks clearly understand that risk management requires regular iteration (and challenge) back to the context. It is clearly illustrated in ISO 31000 and most common risk registers can incorporate this imperative easily. SWOT changes (sometimes rapidly). Stakeholders come and go. Hazards and other categories of risk initiators vary and interact. Iteration therefore becomes critical. Merely having ‘a risk register’ is often a source of stagnancy.
Managing Director @ Prism Energy | Innovative Project Delivery
2yWell written piece Steven Harris FIIRSM CMIOSH MSc .
Process Safety Engineer | Founder | Training | Software | Bowtie Diagrams | Safety Case | HAZID | HAZOP | Managing Director | Founder
2yFantastic article Steven Harris FIIRSM CMIOSH MSc . Keep up the good work 👍🏻
Managing Director | HSSE | Risk | Strategy | Brand | Influence | Leadership | Performance | Key Note Speaker | Published Author | University Lecturer (part time) |
2yCheers for the inspiration David 😀