SlideShare a Scribd company logo
1 of 21
Download to read offline
Incorporating
Risk Management
into BCP
What Risk Means to You
Ron Andrews
January 2013
Context
• The meaning of “risk” has expanded in definition
and understanding – well beyond financial
instruments and safeguards
• Greater numbers of risk assessment tools
• Broader multi-disciplinary application
• Renewed interest and opportunity in examining
“risk” as applied to continuity planning
• Implications for continuity practitioners
Types of Risk
• Hazard
• Natural hazards, accidents, fire, other insurable hazards
• Financial
• Interest and exchange rate volatility, loan defaults, asset-liability
mismatch
• Operational
• Systems, processes, people – succession planning, HR, IT, control
and regulatory systems
• Strategic
• Inability to adjust to environmental changes, e.g. geo-political,
market, competitor, customer, etc.
Risk Management & BCM
Risk Management
• “RM is the process which aims to help organizations
understand, evaluate and take action on all their risks
with a view to increasing the probability of their success
and reducing the likelihood of failure” (IRM)
Business Continuity Management
• “Business Continuity Management is a holistic
management process that identifies potential impacts
that threaten an organization and provides a framework
for building resilience and the capability for an effective
response that safeguards the interests of its key
stakeholders, reputation, brand and value creating
activities” (BCI)
Risk Management & BCM
ITEM RM BCM
Key Method Risk Analysis Business Impact Analysis
Key Parameters Impact and Probability Impact and Time
Incident Type All types – though usually
segmented
Events causing significant
damage to critical
functions/ capabilities
Size of Events All (costs) – though
usually segmented
Strategy planning -
incidents threatening
survival
BCI “Good Practice Guidelines” (2007)
ERM and BCM
Managing Risk
• Process Dimension (Technical)
• Systems, structures, strategies and tools
• Application of sound processes and rational logic
• Results reinvested through a learning cycle
• People Dimension (Human)
• Belief and value systems
• Knowledge, skill and competency
• Success dependent on the human element
Risk is Evolving
From To
Risk as individual hazards Risk in context of business strategy
Risk identification and assessment Risk portfolio development
All risks Critical risks
Risk mitigation Risk optimization
Risk limits Risk strategy
Risks with no owners Defined risk responsibilities
Risk quantification Risk monitoring and measurement
Risk is not my responsibility Risk is everyone’s responsibility
Sample Risk Management Frameworks
Sample Risk Management Frameworks
Sample Risk Management Frameworks
Sample Risk Management Frameworks
Risk Management Trends
• Growing numbers of “emergent” or “wicked” problems
• Greater need for comprehensive BCM and EM governance
models – tools – processes and adaptive strategies
• Greater need for awareness, understanding and acceptance of
ERM, RM and BCM risk mitigation/ management strategies
• RM profile continues to gain prominence in business and
government, e.g. ERM, but challenging with limited resources
Implications for Practitioners
Risk - Context
• Complex and multi-faceted
• Multi-disciplinary in understanding and application
• Integrally tied to innovation and resilience
• Rarely falls neatly into functional areas
• Emerging risks = emerging opportunities
• Management of risk is not technically difficult
• Embedding an RM culture is far more challenging
Implications for Practitioners
Risk - Practice
• Risk management as normal business strategy
• Holistic, inter-functional planning
• Clear, realistic and generalizable RM plans
• Understand the risk tolerance/ profile – build for resilience,
not just recovery
• Risk measures anchored to routine governance and
business processes
• Leverage current communication tools
• Consider blending RM with BIA
• Gradually increase testing complexity
• Embrace risk audits
• Build awareness, training and certification
• Accept that all RM plans are dynamic
Risk Management Exercise
Room Discussion
Your CEO believes that true enterprise resiliency is
achievable. Discuss.
Small Group Discussion
Your CEO wants to incorporate a very robust risk
management tool into either the BIA or the
Strategy component of the company BCP. You
develop one. Discuss.
References
• BCI, “Risk and Business Continuity Management”
• Canadian Centre for Management Development, “A
Foundation for Developing Risk Management Learning
Strategies in the Public Service”
• Ernst & Young, “BCM – Current Trends”
• IMA, “ERM: Frameworks, Elements and Integration”
• IRM, “A Risk Management Standard”
• IRM, “A Structured Approach to Enterprise Risk Management”
• IRM, “Risk Appetite and Tolerance: Guidance Paper”
• IRM, “Emergent Risks”
• ISO 31010, “Risk Management-Risk Assessment Techniques”
• Klein, Luc “Is Business Continuity Management a Misnomer?”
References
• KPMG, “Enterprise Risk Management”
• Lenhart, Carol “Exploring the Interrelationship between
Risk Management and Business Continuity: An Interview
with David Kaye”
• Price, Waterhouse, Coopers, “Exploring Emerging Risks”
• PRMIA.org, “Future of Risk Management and
Compliance: Global Trends and Perspectives”
• The Conference Board, “Bouncing Back: How Companies
Approach Resilience”
• UNESCO, “Risk Management Training Handbook”
Recommended Reading
• Bestoutcome, “Risk and Issue Management Workshop”
• Deloitte, “ERM Management Survey Report – 2012”
• Gartner, “BCM: Key Performance Indicator – Key Risk
Indicator Mapping”
• Hubbard, Douglas, “The Failure of Risk Management”
• IRM, “Risk Culture Under the Microscope”
• PRMIA, “Future of Risk Management and Compliance:
Global Trends and Perspectives”
Contact
Ron Andrews
34 Stonington Bay
Winnipeg, Manitoba
R3P 2K4
(204) 489-3700
bcmguyron@gmail.com
Risk Notification

More Related Content

What's hot

Enterprise Risk Management Erm
Enterprise Risk Management ErmEnterprise Risk Management Erm
Enterprise Risk Management ErmNexus Aid
 
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksC-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksAronson LLC
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk managementAndre Knipe
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk ManagementGAURAV SHARMA
 
Advanced Risk Management - Elsam Management Consultants
Advanced Risk Management - Elsam Management ConsultantsAdvanced Risk Management - Elsam Management Consultants
Advanced Risk Management - Elsam Management ConsultantsEMAC Consulting Group
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...PECB
 
BCM vs ERM: The Business Case for Integration..
BCM vs ERM: The Business Case for Integration..BCM vs ERM: The Business Case for Integration..
BCM vs ERM: The Business Case for Integration..Marc Ronez
 
Enterprise Risk Management as a Core Management Process
Enterprise Risk Management as a Core Management ProcessEnterprise Risk Management as a Core Management Process
Enterprise Risk Management as a Core Management Processregio12
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Diane Christina
 
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB
 
The importance of risk management in business
The importance of risk management in businessThe importance of risk management in business
The importance of risk management in businessr2financial
 
Enterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy JacobusEnterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy JacobusDeddy Jacobus
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkColleen Beck-Domanico
 
Coso Erm(2)
Coso Erm(2)Coso Erm(2)
Coso Erm(2)deeptica
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk ManagementAnu Damodaran
 
Achieving integrated mandatory compliance with ISO 31000
Achieving integrated mandatory compliance with ISO 31000Achieving integrated mandatory compliance with ISO 31000
Achieving integrated mandatory compliance with ISO 31000PECB
 
GRI ERM Roadmap - Program Overview
GRI ERM Roadmap - Program OverviewGRI ERM Roadmap - Program Overview
GRI ERM Roadmap - Program OverviewDenise Robinson
 

What's hot (20)

Enterprise Risk Management Erm
Enterprise Risk Management ErmEnterprise Risk Management Erm
Enterprise Risk Management Erm
 
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksC-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk management
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Advanced Risk Management - Elsam Management Consultants
Advanced Risk Management - Elsam Management ConsultantsAdvanced Risk Management - Elsam Management Consultants
Advanced Risk Management - Elsam Management Consultants
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
 
BCM vs ERM: The Business Case for Integration..
BCM vs ERM: The Business Case for Integration..BCM vs ERM: The Business Case for Integration..
BCM vs ERM: The Business Case for Integration..
 
ERM-Enterprise Risk Management
ERM-Enterprise Risk ManagementERM-Enterprise Risk Management
ERM-Enterprise Risk Management
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Enterprise Risk Management as a Core Management Process
Enterprise Risk Management as a Core Management ProcessEnterprise Risk Management as a Core Management Process
Enterprise Risk Management as a Core Management Process
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
 
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
 
The importance of risk management in business
The importance of risk management in businessThe importance of risk management in business
The importance of risk management in business
 
Enterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy JacobusEnterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy Jacobus
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
Coso Erm(2)
Coso Erm(2)Coso Erm(2)
Coso Erm(2)
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Achieving integrated mandatory compliance with ISO 31000
Achieving integrated mandatory compliance with ISO 31000Achieving integrated mandatory compliance with ISO 31000
Achieving integrated mandatory compliance with ISO 31000
 
GRI ERM Roadmap - Program Overview
GRI ERM Roadmap - Program OverviewGRI ERM Roadmap - Program Overview
GRI ERM Roadmap - Program Overview
 

Similar to Incorporating Risk Management into BCP

DiSerafino - ORSA_insurance_conference
DiSerafino - ORSA_insurance_conferenceDiSerafino - ORSA_insurance_conference
DiSerafino - ORSA_insurance_conferenceLou DiSerafino
 
Critical risk and control frameworks - James Ritchie
Critical risk and control frameworks - James RitchieCritical risk and control frameworks - James Ritchie
Critical risk and control frameworks - James RitchieNSW Environment and Planning
 
ThinkGRC justifying the transition to an Enterprise Risk Management (ERM) model
ThinkGRC justifying the transition to an Enterprise Risk Management (ERM) modelThinkGRC justifying the transition to an Enterprise Risk Management (ERM) model
ThinkGRC justifying the transition to an Enterprise Risk Management (ERM) modelThinkGRC
 
Mastering Information Technology Risk Management
Mastering Information Technology Risk ManagementMastering Information Technology Risk Management
Mastering Information Technology Risk ManagementGoutama Bachtiar
 
Understanding and Managing Risk
Understanding and Managing RiskUnderstanding and Managing Risk
Understanding and Managing RiskThe Pathway Group
 
Risk management ppt 111p (training module)
Risk management ppt 111p (training module)Risk management ppt 111p (training module)
Risk management ppt 111p (training module)Sadia Razzaq
 
Value creation through optimising risk
Value creation through optimising riskValue creation through optimising risk
Value creation through optimising riskDavid Berkelmans
 
Ken Kurdziel: Enterprise Risk Management
Ken Kurdziel: Enterprise Risk ManagementKen Kurdziel: Enterprise Risk Management
Ken Kurdziel: Enterprise Risk ManagementJamesMooreCo
 
Risk Management - A Journey
Risk Management - A JourneyRisk Management - A Journey
Risk Management - A JourneyDebashis Gupta
 
Module 15 - Risk Management.pptx
Module 15 - Risk Management.pptxModule 15 - Risk Management.pptx
Module 15 - Risk Management.pptxcaniceconsulting
 
Risk assessment and compliance 151119
Risk assessment and compliance 151119Risk assessment and compliance 151119
Risk assessment and compliance 151119KAYODE ADEBIYI
 
Leading risk culture change webinar
Leading risk culture change webinarLeading risk culture change webinar
Leading risk culture change webinarFERMA
 
Risk Management in 2015
Risk Management in 2015Risk Management in 2015
Risk Management in 2015C Louiza
 
Risk Management and Risk Transfer
Risk Management and Risk TransferRisk Management and Risk Transfer
Risk Management and Risk TransferCBIZ, Inc.
 
Management of Risk M_o_R Dubai - Syzygal
Management of Risk M_o_R Dubai - SyzygalManagement of Risk M_o_R Dubai - Syzygal
Management of Risk M_o_R Dubai - SyzygalSyzygal
 
Implementing an Enterprise Risk Management program (2022 updates).pdf
Implementing an Enterprise Risk Management program (2022 updates).pdfImplementing an Enterprise Risk Management program (2022 updates).pdf
Implementing an Enterprise Risk Management program (2022 updates).pdfRobert Serena, FSA, CFA, CPCU
 

Similar to Incorporating Risk Management into BCP (20)

DiSerafino - ORSA_insurance_conference
DiSerafino - ORSA_insurance_conferenceDiSerafino - ORSA_insurance_conference
DiSerafino - ORSA_insurance_conference
 
Critical risk and control frameworks - James Ritchie
Critical risk and control frameworks - James RitchieCritical risk and control frameworks - James Ritchie
Critical risk and control frameworks - James Ritchie
 
MAA_Riskmanagement
MAA_RiskmanagementMAA_Riskmanagement
MAA_Riskmanagement
 
ThinkGRC justifying the transition to an Enterprise Risk Management (ERM) model
ThinkGRC justifying the transition to an Enterprise Risk Management (ERM) modelThinkGRC justifying the transition to an Enterprise Risk Management (ERM) model
ThinkGRC justifying the transition to an Enterprise Risk Management (ERM) model
 
Mastering Information Technology Risk Management
Mastering Information Technology Risk ManagementMastering Information Technology Risk Management
Mastering Information Technology Risk Management
 
Risk Health Check
Risk Health CheckRisk Health Check
Risk Health Check
 
Understanding and Managing Risk
Understanding and Managing RiskUnderstanding and Managing Risk
Understanding and Managing Risk
 
Risk management ppt 111p (training module)
Risk management ppt 111p (training module)Risk management ppt 111p (training module)
Risk management ppt 111p (training module)
 
HIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINALHIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINAL
 
Value creation through optimising risk
Value creation through optimising riskValue creation through optimising risk
Value creation through optimising risk
 
Ken Kurdziel: Enterprise Risk Management
Ken Kurdziel: Enterprise Risk ManagementKen Kurdziel: Enterprise Risk Management
Ken Kurdziel: Enterprise Risk Management
 
Risk Management - A Journey
Risk Management - A JourneyRisk Management - A Journey
Risk Management - A Journey
 
Module 15 - Risk Management.pptx
Module 15 - Risk Management.pptxModule 15 - Risk Management.pptx
Module 15 - Risk Management.pptx
 
Risk assessment and compliance 151119
Risk assessment and compliance 151119Risk assessment and compliance 151119
Risk assessment and compliance 151119
 
Leading risk culture change webinar
Leading risk culture change webinarLeading risk culture change webinar
Leading risk culture change webinar
 
Risk Management in 2015
Risk Management in 2015Risk Management in 2015
Risk Management in 2015
 
Risk Management and Risk Transfer
Risk Management and Risk TransferRisk Management and Risk Transfer
Risk Management and Risk Transfer
 
Management of Risk M_o_R Dubai - Syzygal
Management of Risk M_o_R Dubai - SyzygalManagement of Risk M_o_R Dubai - Syzygal
Management of Risk M_o_R Dubai - Syzygal
 
Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management
 
Implementing an Enterprise Risk Management program (2022 updates).pdf
Implementing an Enterprise Risk Management program (2022 updates).pdfImplementing an Enterprise Risk Management program (2022 updates).pdf
Implementing an Enterprise Risk Management program (2022 updates).pdf
 

Incorporating Risk Management into BCP

  • 1. Incorporating Risk Management into BCP What Risk Means to You Ron Andrews January 2013
  • 2. Context • The meaning of “risk” has expanded in definition and understanding – well beyond financial instruments and safeguards • Greater numbers of risk assessment tools • Broader multi-disciplinary application • Renewed interest and opportunity in examining “risk” as applied to continuity planning • Implications for continuity practitioners
  • 3. Types of Risk • Hazard • Natural hazards, accidents, fire, other insurable hazards • Financial • Interest and exchange rate volatility, loan defaults, asset-liability mismatch • Operational • Systems, processes, people – succession planning, HR, IT, control and regulatory systems • Strategic • Inability to adjust to environmental changes, e.g. geo-political, market, competitor, customer, etc.
  • 4. Risk Management & BCM Risk Management • “RM is the process which aims to help organizations understand, evaluate and take action on all their risks with a view to increasing the probability of their success and reducing the likelihood of failure” (IRM) Business Continuity Management • “Business Continuity Management is a holistic management process that identifies potential impacts that threaten an organization and provides a framework for building resilience and the capability for an effective response that safeguards the interests of its key stakeholders, reputation, brand and value creating activities” (BCI)
  • 5. Risk Management & BCM ITEM RM BCM Key Method Risk Analysis Business Impact Analysis Key Parameters Impact and Probability Impact and Time Incident Type All types – though usually segmented Events causing significant damage to critical functions/ capabilities Size of Events All (costs) – though usually segmented Strategy planning - incidents threatening survival BCI “Good Practice Guidelines” (2007)
  • 7. Managing Risk • Process Dimension (Technical) • Systems, structures, strategies and tools • Application of sound processes and rational logic • Results reinvested through a learning cycle • People Dimension (Human) • Belief and value systems • Knowledge, skill and competency • Success dependent on the human element
  • 8. Risk is Evolving From To Risk as individual hazards Risk in context of business strategy Risk identification and assessment Risk portfolio development All risks Critical risks Risk mitigation Risk optimization Risk limits Risk strategy Risks with no owners Defined risk responsibilities Risk quantification Risk monitoring and measurement Risk is not my responsibility Risk is everyone’s responsibility
  • 13. Risk Management Trends • Growing numbers of “emergent” or “wicked” problems • Greater need for comprehensive BCM and EM governance models – tools – processes and adaptive strategies • Greater need for awareness, understanding and acceptance of ERM, RM and BCM risk mitigation/ management strategies • RM profile continues to gain prominence in business and government, e.g. ERM, but challenging with limited resources
  • 14. Implications for Practitioners Risk - Context • Complex and multi-faceted • Multi-disciplinary in understanding and application • Integrally tied to innovation and resilience • Rarely falls neatly into functional areas • Emerging risks = emerging opportunities • Management of risk is not technically difficult • Embedding an RM culture is far more challenging
  • 15. Implications for Practitioners Risk - Practice • Risk management as normal business strategy • Holistic, inter-functional planning • Clear, realistic and generalizable RM plans • Understand the risk tolerance/ profile – build for resilience, not just recovery • Risk measures anchored to routine governance and business processes • Leverage current communication tools • Consider blending RM with BIA • Gradually increase testing complexity • Embrace risk audits • Build awareness, training and certification • Accept that all RM plans are dynamic
  • 16. Risk Management Exercise Room Discussion Your CEO believes that true enterprise resiliency is achievable. Discuss. Small Group Discussion Your CEO wants to incorporate a very robust risk management tool into either the BIA or the Strategy component of the company BCP. You develop one. Discuss.
  • 17. References • BCI, “Risk and Business Continuity Management” • Canadian Centre for Management Development, “A Foundation for Developing Risk Management Learning Strategies in the Public Service” • Ernst & Young, “BCM – Current Trends” • IMA, “ERM: Frameworks, Elements and Integration” • IRM, “A Risk Management Standard” • IRM, “A Structured Approach to Enterprise Risk Management” • IRM, “Risk Appetite and Tolerance: Guidance Paper” • IRM, “Emergent Risks” • ISO 31010, “Risk Management-Risk Assessment Techniques” • Klein, Luc “Is Business Continuity Management a Misnomer?”
  • 18. References • KPMG, “Enterprise Risk Management” • Lenhart, Carol “Exploring the Interrelationship between Risk Management and Business Continuity: An Interview with David Kaye” • Price, Waterhouse, Coopers, “Exploring Emerging Risks” • PRMIA.org, “Future of Risk Management and Compliance: Global Trends and Perspectives” • The Conference Board, “Bouncing Back: How Companies Approach Resilience” • UNESCO, “Risk Management Training Handbook”
  • 19. Recommended Reading • Bestoutcome, “Risk and Issue Management Workshop” • Deloitte, “ERM Management Survey Report – 2012” • Gartner, “BCM: Key Performance Indicator – Key Risk Indicator Mapping” • Hubbard, Douglas, “The Failure of Risk Management” • IRM, “Risk Culture Under the Microscope” • PRMIA, “Future of Risk Management and Compliance: Global Trends and Perspectives”
  • 20. Contact Ron Andrews 34 Stonington Bay Winnipeg, Manitoba R3P 2K4 (204) 489-3700 bcmguyron@gmail.com