SlideShare a Scribd company logo
1 of 25
© Operational Excellence Consulting. All rights reserved.
ISO 31000:2018
Risk Management
© Operational Excellence Consulting. All rights reserved.
© Operational Excellence Consulting. All rights reserved. 2
Learning Objectives
Understand the
concept of risk as the
uncertainty on
objectives.
Understand risk
management
principles, framework
and process in the
context of a Risk
Management
System.
Appreciate the value
of ISO 31000 as the
benchmark for best
practice in managing
risk.
NOTE: This is a PARTIAL PREVIEW. To
download the complete presentation, please
visit: https://www.oeconsulting.com.sg
© Operational Excellence Consulting. All rights reserved. 3
Contents
2 The Three Pillars of ISO 31000
1 Introduction & Key Concepts of ISO 31000
© Operational Excellence Consulting. All rights reserved. 4
About ISO
§ Non-governmental organization (NGO) established in
1947, based in Geneva, Switzerland
§ Has a membership of over 160 national standards
institutes from countries in all regions of the world
§ The world’s largest developer of voluntary International
Standards, based on global and market relevance
© Operational Excellence Consulting. All rights reserved. 5© Operational Excellence Consulting. All rights reserved. 5
Why are Standards Important?
Facilitates
business
interaction
Communication
Enables
companies to
comply with
relevants laws and
regulations
Compliance
Speeds up the
introduction of
innovative
products and
services to the
market
Innovation
Provides
interoperability
between new and
existing prodcucts,
services and
processes
Interoperability
© Operational Excellence Consulting. All rights reserved. 6
What is ISO 31000?
§ An international standard that provides principles and
generic guidelines on risk management
§ Generic approach:
‱ Not specific to any industry or sector
‱ Can be applied to any type of risk (financial, technological,
natural, project)
‱ Can be applied to any type of organization
‱ Can be applied to organizational activities such as decision
making
© Operational Excellence Consulting. All rights reserved. 7
The ISO 31000 Family
GUIDELINES
RISK
MANAGEMENT
ISO 31000:2018
Risk management
guidelines
IEC 31010:2019
Risk assessment
techniques
ISO Guide
73:2009
Risk management
vocabulary
TECHNIQUESVOCABULARY
© Operational Excellence Consulting. All rights reserved. 8
Objectives of ISO 31000
§ Helps organizations develop
a risk management strategy
to effectively identify and
mitigate risks
§ Develop a risk management
culture where employees and
stakeholders are aware of
the importance of monitoring
and managing risk
© Operational Excellence Consulting. All rights reserved. 9
What is “Risk”?
§ Risk is present in everything we do
§ Risk can be a threat or an opportunity
§ Anything that could harm, prevent, delay or enhance
your ability to achieve your objectives
§ ISO 9001:2015, ISO 14001:2015, ISO 22301:2012 and
ISO 45001:2018 are all risk-based standards
© Operational Excellence Consulting. All rights reserved. 10
Examples of Risk
Damage to
reputation or
brand
Cyber crime
Political
risk
Terrorism
Digital
currency
Infectious
diseases
Economic
downturn
© Operational Excellence Consulting. All rights reserved. 11
Definition of Risk
§ In ISO 31000, Risk is defined as:
The effect of uncertainty on your
objectives.
© Operational Excellence Consulting. All rights reserved. 12
Why Do We Need to be Aware of Risk?
§ Risk is something that we all
face every day
§ As a company, we have to
take risks in pursuit of our
commercial objectives
§ To raise awareness that we all
have to manage risk as part of
our daily working lives as well
as personal
© Operational Excellence Consulting. All rights reserved. 13
Benefits of Adopting ISO 31000 Standard
§ Increase the likelihood of achieving objectives
§ Encourage proactive management
§ Identify and treat risk throughout the organization
§ Improve the identification of opportunities and threats
§ Comply with relevant legal and regulatory requirements
and internal norms
§ Improve financial reporting
§ Improve governance
§ Establish a reliable basis for decision making
© Operational Excellence Consulting. All rights reserved. 14
The Three Pillars
of ISO 31000
Leadership
and
Commitment Risk
Evaluation
Risk
Analysis
Risk
Identification
Risk Assessment
Risk Treatment
Scope, Context, Criteria
COMMUNICATION&
CONSULTATION
MONITORING&REVIEW
RECORDING & REPORTING
Integrated
Continual
Improvement
Human and
Cultural
Factors
Best
Available
Information
Dynamic Inclusive
Customized
Structured
and
Comprehensive
Value Creation
and
Protection
Principles (Clause 4)
Framework (Clause 5) Process (Clause 6)
Source: Adapted from ISO 31000:2018 Risk Management Guidelines
© Operational Excellence Consulting. All rights reserved. 15
Risk Management Principles
§ Core concept of ISO 31000: The purpose of risk
management is the creation and protection of value
§ Eight Principles (concepts) communicate the value of
risk management, explain its intention and purpose and
are the foundation for managing risk
§ The principles are required for an effective risk
management – they are the core concepts of risk
management!
© Operational Excellence Consulting. All rights reserved. 16
Risk Management Framework
§ Leadership and Commitment
(top management and – where
applicable oversight bodies)
‱ Customizing and implementing
the framework
‱ Issuing a policy statement
‱ Allocating the necessary
resources
‱ Assigning authority, responsibility
and accountability
Leadership
and
Commitment
© Operational Excellence Consulting. All rights reserved. 17
DESCRIPTION
Risk identification § What could prevent us from achieving our objectives?
Risk analysis
§ Understanding the sources and causes of the identified risks;
studying probabilities and consequences given the existing
controls, to identify the level of residual risk.
Risk evaluation § Comparing risk analysis results with risk criteria to determine
whether the residual risk is tolerable.
Risk treatment § Changing the magnitude and likelihood of consequences, both
positive and negative, to achieve a net increase in benefit.
Risk Management Process
© Operational Excellence Consulting. All rights reserved. 18
Risk Management Process
§ Risk assessment
‱ Should be conducted systematically, iteratively
and collaboratively
‱ Tools for risk management can be found in
ISO/IEC 31010
‱ Risk assessment is the process of
Ø Risk identification
Ø Risk analysis, and
Ø Risk evaluation
Risk
Evaluation
Risk
Analysis
Risk
Identification
Risk Assessment
Risk Treatment
Scope, Context, Criteria
COMMUNICATION&
CONSULTATION
MONITORING&REVIEW
RECORDING & REPORTING
© Operational Excellence Consulting. All rights reserved. 19
Risk Management Process
§ Risk identification
‱ Find, recognize and describe risks that might
help or prevent an organization achieving its
objectives
‱ Relevant, appropriate and up-to-date information
is important in identifying risks
‱ A risk not identified is a risk not analyzed, not
evaluated and not treated
§ The biggest risk of all is not to consider the
risks of your objectives!
Risk
Evaluation
Risk
Analysis
Risk
Identification
Risk Assessment
Risk Treatment
Scope, Context, Criteria
COMMUNICATION&
CONSULTATION
MONITORING&REVIEW
RECORDING & REPORTING
© Operational Excellence Consulting. All rights reserved. 20
Risk Management Process
§ Risk evaluation
‱ Its purpose is to support decisions
‱ It involves comparing the results of risk analysis
with the established risk criteria to determine
where action is required. Decisions might be to:
Ø Do nothing further
Ø Consider risk treatment options
Ø Undertake further analysis
Ø Maintain existing controls
Ø Reconsider objectives
Risk
Evaluation
Risk
Analysis
Risk
Identification
Risk Assessment
Risk Treatment
Scope, Context, Criteria
COMMUNICATION&
CONSULTATION
MONITORING&REVIEW
RECORDING & REPORTING
© Operational Excellence Consulting. All rights reserved. 21
ISO 31000 Key Clause Structure (4-6)
4. Principles 5. Framework 6. Process
Value creation and protection
§ Integrated
§ Structured and comprehensive
§ Customized
§ Inclusive
§ Dynamic
§ Best available information
§ Human and cultural factors
§ Continual improvement
5.1 General
5.2 Leadership and commitment
5.3 Integration
5.4 Design
5.4.1 Understanding the organization
and its context
5.4.2 Articulating risk management
commitment
5.4.3 Assigning organizational roles,
authorities, responsibilities and
accountabilities
5.4.4 Allocating resources
5.4.5 Establishing communication and
consultation
5.5 Implementation
5.6 Evaluation
5.7 Improvement
5.7.1 Adapting
5.7.2 Continually improving
6.1 General
6.2 Communication and
consultation
6.3 Scope, context and criteria
6.3.1 General
6.3.2 Defining the scope
6.3.3 External and internal context
6.3.4 Defining risk criteria
6.4 Risk management
6.4.1 General
6.4.2 Risk identification
6.4.3 Risk analysis
6.4.4 Risk evaluation
6.5 Risk treatment
6.5.1 General
6.5.2 Selection of risk treatment
options
6.5.3 Preparing and implementing risk
treatment plans
6.6 Monitoring and review
6.7 Recording and reporting
© Operational Excellence Consulting. All rights reserved. 22
Your Risk Management Checklist
1. Do you have a risk management plan (it does not have to be
lengthy or complicated)?
2. Have you identified and captured your risks in a risk register?
3. How have you evaluated and prioritized your risks?
4. Have you engaged the appropriate stakeholders in the risk
identification and evaluation processes?
5. What about risk owners? Does each risk have a risk owner?
6. Have the risk owners developed risk response plans for the
highest risks?
7. Are you facilitating a review of your risks periodically, resulting in
updates to the risk register and effective risk responses?
© Operational Excellence Consulting. All rights reserved.
About
Operational Excellence
Consulting
© Operational Excellence Consulting. All rights reserved. 24
About Operational Excellence
Consulting
§ Operational Excellence Consulting is a management
training and consulting firm that assists organizations in
improving business performance and effectiveness.
§ The firm’s mission is to create business value for
organizations through innovative operational excellence
management training and consulting solutions.
§ OEC takes a unique “beyond the tools” approach to enable
clients develop internal capabilities and cultural
transformation to achieve sustainable world-class excellence
and competitive advantage. For more information, please visit
www.oeconsulting.com.sg
© Operational Excellence Consulting. All rights reserved.
END OF PREVIEW
To download this presentation,
please visit:
www.oeconsulting.com.sg

More Related Content

More from Operational Excellence Consulting

Seven Advanced Tools of Quality (Seven Advanced QC Tools)
Seven Advanced Tools of Quality (Seven Advanced QC Tools)Seven Advanced Tools of Quality (Seven Advanced QC Tools)
Seven Advanced Tools of Quality (Seven Advanced QC Tools)Operational Excellence Consulting
 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness PosterISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness PosterOperational Excellence Consulting
 

More from Operational Excellence Consulting (20)

Digital Strategic Business Planning Methodology
Digital Strategic Business Planning MethodologyDigital Strategic Business Planning Methodology
Digital Strategic Business Planning Methodology
 
Root Cause Analysis (RCA)
Root Cause Analysis (RCA)Root Cause Analysis (RCA)
Root Cause Analysis (RCA)
 
Business Process Reengineering (BPR)
Business Process Reengineering (BPR)Business Process Reengineering (BPR)
Business Process Reengineering (BPR)
 
5 Steps of Problem Solving
5 Steps of Problem Solving5 Steps of Problem Solving
5 Steps of Problem Solving
 
Seven Advanced Tools of Quality (Seven Advanced QC Tools)
Seven Advanced Tools of Quality (Seven Advanced QC Tools)Seven Advanced Tools of Quality (Seven Advanced QC Tools)
Seven Advanced Tools of Quality (Seven Advanced QC Tools)
 
Seven Basic Tools of Quality (Seven Basic QC Tools)
Seven Basic Tools of Quality (Seven Basic QC Tools)Seven Basic Tools of Quality (Seven Basic QC Tools)
Seven Basic Tools of Quality (Seven Basic QC Tools)
 
Problem Solving & Visualization Tools
Problem Solving & Visualization ToolsProblem Solving & Visualization Tools
Problem Solving & Visualization Tools
 
PDCA Problem Solving Process & Tools
PDCA Problem Solving Process & ToolsPDCA Problem Solving Process & Tools
PDCA Problem Solving Process & Tools
 
8D Problem Solving Process & Tools
8D Problem Solving Process & Tools8D Problem Solving Process & Tools
8D Problem Solving Process & Tools
 
Digital Transformation Process Poster
Digital Transformation Process PosterDigital Transformation Process Poster
Digital Transformation Process Poster
 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness PosterISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
 
Four Steps of Jidoka Poster
Four Steps of Jidoka PosterFour Steps of Jidoka Poster
Four Steps of Jidoka Poster
 
Lean Startup: Build-Measure-Learn Process Poster
Lean Startup: Build-Measure-Learn Process PosterLean Startup: Build-Measure-Learn Process Poster
Lean Startup: Build-Measure-Learn Process Poster
 
AIDA Marketing Model Poster
AIDA Marketing Model PosterAIDA Marketing Model Poster
AIDA Marketing Model Poster
 
TPM: One-Point Lessons Poster
TPM: One-Point Lessons PosterTPM: One-Point Lessons Poster
TPM: One-Point Lessons Poster
 
4M Analysis Poster
4M Analysis Poster4M Analysis Poster
4M Analysis Poster
 
Hoshin Planning Poster
Hoshin Planning PosterHoshin Planning Poster
Hoshin Planning Poster
 
Customer-Centricity
Customer-CentricityCustomer-Centricity
Customer-Centricity
 
Lean Daily Management System (LDMS) Poster
Lean Daily Management System (LDMS) PosterLean Daily Management System (LDMS) Poster
Lean Daily Management System (LDMS) Poster
 
Business Model Canvas
Business Model CanvasBusiness Model Canvas
Business Model Canvas
 

Recently uploaded

M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Russian Call Girls In Gurgaon ❀8448577510 âŠčBest Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❀8448577510 âŠčBest Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❀8448577510 âŠčBest Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❀8448577510 âŠčBest Escorts Service In 24/7 Delh...lizamodels9
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒anilsa9823
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfAmzadHosen3
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Roland Driesen
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756dollysharma2066
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxWorkforce Group
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxpriyanshujha201
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Trucks in Minnesota
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 

Recently uploaded (20)

M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Russian Call Girls In Gurgaon ❀8448577510 âŠčBest Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❀8448577510 âŠčBest Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❀8448577510 âŠčBest Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❀8448577510 âŠčBest Escorts Service In 24/7 Delh...
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdf
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 

ISO 31000:2018 (Risk Management) Awareness Training

  • 1. © Operational Excellence Consulting. All rights reserved. ISO 31000:2018 Risk Management © Operational Excellence Consulting. All rights reserved.
  • 2. © Operational Excellence Consulting. All rights reserved. 2 Learning Objectives Understand the concept of risk as the uncertainty on objectives. Understand risk management principles, framework and process in the context of a Risk Management System. Appreciate the value of ISO 31000 as the benchmark for best practice in managing risk. NOTE: This is a PARTIAL PREVIEW. To download the complete presentation, please visit: https://www.oeconsulting.com.sg
  • 3. © Operational Excellence Consulting. All rights reserved. 3 Contents 2 The Three Pillars of ISO 31000 1 Introduction & Key Concepts of ISO 31000
  • 4. © Operational Excellence Consulting. All rights reserved. 4 About ISO § Non-governmental organization (NGO) established in 1947, based in Geneva, Switzerland § Has a membership of over 160 national standards institutes from countries in all regions of the world § The world’s largest developer of voluntary International Standards, based on global and market relevance
  • 5. © Operational Excellence Consulting. All rights reserved. 5© Operational Excellence Consulting. All rights reserved. 5 Why are Standards Important? Facilitates business interaction Communication Enables companies to comply with relevants laws and regulations Compliance Speeds up the introduction of innovative products and services to the market Innovation Provides interoperability between new and existing prodcucts, services and processes Interoperability
  • 6. © Operational Excellence Consulting. All rights reserved. 6 What is ISO 31000? § An international standard that provides principles and generic guidelines on risk management § Generic approach: ‱ Not specific to any industry or sector ‱ Can be applied to any type of risk (financial, technological, natural, project) ‱ Can be applied to any type of organization ‱ Can be applied to organizational activities such as decision making
  • 7. © Operational Excellence Consulting. All rights reserved. 7 The ISO 31000 Family GUIDELINES RISK MANAGEMENT ISO 31000:2018 Risk management guidelines IEC 31010:2019 Risk assessment techniques ISO Guide 73:2009 Risk management vocabulary TECHNIQUESVOCABULARY
  • 8. © Operational Excellence Consulting. All rights reserved. 8 Objectives of ISO 31000 § Helps organizations develop a risk management strategy to effectively identify and mitigate risks § Develop a risk management culture where employees and stakeholders are aware of the importance of monitoring and managing risk
  • 9. © Operational Excellence Consulting. All rights reserved. 9 What is “Risk”? § Risk is present in everything we do § Risk can be a threat or an opportunity § Anything that could harm, prevent, delay or enhance your ability to achieve your objectives § ISO 9001:2015, ISO 14001:2015, ISO 22301:2012 and ISO 45001:2018 are all risk-based standards
  • 10. © Operational Excellence Consulting. All rights reserved. 10 Examples of Risk Damage to reputation or brand Cyber crime Political risk Terrorism Digital currency Infectious diseases Economic downturn
  • 11. © Operational Excellence Consulting. All rights reserved. 11 Definition of Risk § In ISO 31000, Risk is defined as: The effect of uncertainty on your objectives.
  • 12. © Operational Excellence Consulting. All rights reserved. 12 Why Do We Need to be Aware of Risk? § Risk is something that we all face every day § As a company, we have to take risks in pursuit of our commercial objectives § To raise awareness that we all have to manage risk as part of our daily working lives as well as personal
  • 13. © Operational Excellence Consulting. All rights reserved. 13 Benefits of Adopting ISO 31000 Standard § Increase the likelihood of achieving objectives § Encourage proactive management § Identify and treat risk throughout the organization § Improve the identification of opportunities and threats § Comply with relevant legal and regulatory requirements and internal norms § Improve financial reporting § Improve governance § Establish a reliable basis for decision making
  • 14. © Operational Excellence Consulting. All rights reserved. 14 The Three Pillars of ISO 31000 Leadership and Commitment Risk Evaluation Risk Analysis Risk Identification Risk Assessment Risk Treatment Scope, Context, Criteria COMMUNICATION& CONSULTATION MONITORING&REVIEW RECORDING & REPORTING Integrated Continual Improvement Human and Cultural Factors Best Available Information Dynamic Inclusive Customized Structured and Comprehensive Value Creation and Protection Principles (Clause 4) Framework (Clause 5) Process (Clause 6) Source: Adapted from ISO 31000:2018 Risk Management Guidelines
  • 15. © Operational Excellence Consulting. All rights reserved. 15 Risk Management Principles § Core concept of ISO 31000: The purpose of risk management is the creation and protection of value § Eight Principles (concepts) communicate the value of risk management, explain its intention and purpose and are the foundation for managing risk § The principles are required for an effective risk management – they are the core concepts of risk management!
  • 16. © Operational Excellence Consulting. All rights reserved. 16 Risk Management Framework § Leadership and Commitment (top management and – where applicable oversight bodies) ‱ Customizing and implementing the framework ‱ Issuing a policy statement ‱ Allocating the necessary resources ‱ Assigning authority, responsibility and accountability Leadership and Commitment
  • 17. © Operational Excellence Consulting. All rights reserved. 17 DESCRIPTION Risk identification § What could prevent us from achieving our objectives? Risk analysis § Understanding the sources and causes of the identified risks; studying probabilities and consequences given the existing controls, to identify the level of residual risk. Risk evaluation § Comparing risk analysis results with risk criteria to determine whether the residual risk is tolerable. Risk treatment § Changing the magnitude and likelihood of consequences, both positive and negative, to achieve a net increase in benefit. Risk Management Process
  • 18. © Operational Excellence Consulting. All rights reserved. 18 Risk Management Process § Risk assessment ‱ Should be conducted systematically, iteratively and collaboratively ‱ Tools for risk management can be found in ISO/IEC 31010 ‱ Risk assessment is the process of Ø Risk identification Ø Risk analysis, and Ø Risk evaluation Risk Evaluation Risk Analysis Risk Identification Risk Assessment Risk Treatment Scope, Context, Criteria COMMUNICATION& CONSULTATION MONITORING&REVIEW RECORDING & REPORTING
  • 19. © Operational Excellence Consulting. All rights reserved. 19 Risk Management Process § Risk identification ‱ Find, recognize and describe risks that might help or prevent an organization achieving its objectives ‱ Relevant, appropriate and up-to-date information is important in identifying risks ‱ A risk not identified is a risk not analyzed, not evaluated and not treated § The biggest risk of all is not to consider the risks of your objectives! Risk Evaluation Risk Analysis Risk Identification Risk Assessment Risk Treatment Scope, Context, Criteria COMMUNICATION& CONSULTATION MONITORING&REVIEW RECORDING & REPORTING
  • 20. © Operational Excellence Consulting. All rights reserved. 20 Risk Management Process § Risk evaluation ‱ Its purpose is to support decisions ‱ It involves comparing the results of risk analysis with the established risk criteria to determine where action is required. Decisions might be to: Ø Do nothing further Ø Consider risk treatment options Ø Undertake further analysis Ø Maintain existing controls Ø Reconsider objectives Risk Evaluation Risk Analysis Risk Identification Risk Assessment Risk Treatment Scope, Context, Criteria COMMUNICATION& CONSULTATION MONITORING&REVIEW RECORDING & REPORTING
  • 21. © Operational Excellence Consulting. All rights reserved. 21 ISO 31000 Key Clause Structure (4-6) 4. Principles 5. Framework 6. Process Value creation and protection § Integrated § Structured and comprehensive § Customized § Inclusive § Dynamic § Best available information § Human and cultural factors § Continual improvement 5.1 General 5.2 Leadership and commitment 5.3 Integration 5.4 Design 5.4.1 Understanding the organization and its context 5.4.2 Articulating risk management commitment 5.4.3 Assigning organizational roles, authorities, responsibilities and accountabilities 5.4.4 Allocating resources 5.4.5 Establishing communication and consultation 5.5 Implementation 5.6 Evaluation 5.7 Improvement 5.7.1 Adapting 5.7.2 Continually improving 6.1 General 6.2 Communication and consultation 6.3 Scope, context and criteria 6.3.1 General 6.3.2 Defining the scope 6.3.3 External and internal context 6.3.4 Defining risk criteria 6.4 Risk management 6.4.1 General 6.4.2 Risk identification 6.4.3 Risk analysis 6.4.4 Risk evaluation 6.5 Risk treatment 6.5.1 General 6.5.2 Selection of risk treatment options 6.5.3 Preparing and implementing risk treatment plans 6.6 Monitoring and review 6.7 Recording and reporting
  • 22. © Operational Excellence Consulting. All rights reserved. 22 Your Risk Management Checklist 1. Do you have a risk management plan (it does not have to be lengthy or complicated)? 2. Have you identified and captured your risks in a risk register? 3. How have you evaluated and prioritized your risks? 4. Have you engaged the appropriate stakeholders in the risk identification and evaluation processes? 5. What about risk owners? Does each risk have a risk owner? 6. Have the risk owners developed risk response plans for the highest risks? 7. Are you facilitating a review of your risks periodically, resulting in updates to the risk register and effective risk responses?
  • 23. © Operational Excellence Consulting. All rights reserved. About Operational Excellence Consulting
  • 24. © Operational Excellence Consulting. All rights reserved. 24 About Operational Excellence Consulting § Operational Excellence Consulting is a management training and consulting firm that assists organizations in improving business performance and effectiveness. § The firm’s mission is to create business value for organizations through innovative operational excellence management training and consulting solutions. § OEC takes a unique “beyond the tools” approach to enable clients develop internal capabilities and cultural transformation to achieve sustainable world-class excellence and competitive advantage. For more information, please visit www.oeconsulting.com.sg
  • 25. © Operational Excellence Consulting. All rights reserved. END OF PREVIEW To download this presentation, please visit: www.oeconsulting.com.sg