下載本文檔
版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進(jìn)行舉報或認(rèn)領(lǐng)
文檔簡介
Contents?CHAPTER1:INTRODUCTION?CHAPTER2:PRINCIPLES?CHAPTER3:HOWRISKSAREMANAGED?CHAPTER4:MANAGINGRISKATTHESTRATEGICLEVEL?CHAPTER5:MANAGINGRISKATTHEPROGRAMMELEVEL?CHAPTER6:MANAGINGRISKSATTHEPROJECTLEVEL?CHAPTER7:MANAGINGRISKATTHEOPERATIONALLEVEL?CHAPTER8:TECHNIQUES?ANNEXA:EXAMPLESOFBENEFITSOFRISKMANAGEMENT?ANNEXB:HEALTHCHECK:HOWWELLISYOURORGANISATIONMANAGINGRISK??ANNEXC:CATEGORISINGRISK?ANNEXD:SETTINGASTANDARDFOREVALUATIONOFRISK?ANNEXE:PROCUREMENT,CONTRACTUALANDLEGALCONSIDERATIONS?ANNEXF:BUSINESSCONTINUITYMANAGEMENT?ANNEXG:MANAGINGORGANISATIONALSAFETYANDSECURITY?ANNEXH:INFORMATIONONFURTHERTECHNIQUESTOSUPPORTMANAGEMENTOFRISK?ANNEXJ:LESSONSLEARNEDFROMOTHERS?ANNEXK:ASSESSINGTHESUITABILITYOFTOOLS?ANNEXL:DOCUMENTATIONOUTLINESCHAPTER1:INTRODUCTIONPurposeofthisguideWhatismanagementofrisk?WhymanagementofriskisimportantWhoisinvolvedinriskmanagementHowtousethisguideTheresearchforthisguidancePurposeofthisguideThisguideisintendedtohelporganisationstoputinplaceeffectiveframeworksfortakinginformeddecisionsaboutrisk.Theguidanceprovidesaroutemapforriskmanagement,bringingtogetherrecommendedapproaches,checklistsandpointerstomoredetailedsourcesofadviceontoolsandtechniques.ItexpandsontheOGCGuidelinesforManagingRisk.Theprocessofinvestmentappraisal,inwhichassessmentsaremadeofcosts,benefitsandrisks,isoutsidethescopeofthisguide.However,manyoftheprinciplesandtechniquesdescribedherecanbeusedwhendevelopingthebusinesscase.TheapproachdescribedinthisguidecomplementsOGC'sguidanceonprogrammeandprojectmanagementandiscontinuallyupdatedtoreflectcurrentthinking.Thisapproach,brandedbyOGCasM_o_R(ManagementofRisk),issupportedbytrainingandqualifications.Whatismanagementofrisk?Inthisguideriskisdefinedasuncertaintyofoutcome,whetherpositiveopportunityornegativethreat.Theterm'managementofrisk7incorporatesalltheactivitiesrequiredtoidentifyandcontroltheexposuretoriskwhichmayhaveanimpactontheachievementofanorganisation'sbusinessobjectives.Everyorganisationmanagesitsrisk,butnotalwaysinawaythatisvisible,repeatableandconsistentlyappliedtosupportdecisionmaking.Thetaskofmanagementofriskistoensurethattheorganisationmakescosteffectiveuseofariskprocessthathasaseriesofwelldefinedsteps.Theaimistosupportbetterdecisionmakingthroughagoodunderstandingofrisksandtheirlikelyimpact.Therearetwodistinctphases:riskanalysisandriskmanagement.Riskanalysisisconcernedwithgatheringinformationaboutexposuretorisksothattheorganisationcanmakeappropriatedecisionsandmanageriskappropriately.Managementofriskinvolveshavingprocessesinplacetomonitorrisks,accesstoreliableanduptodateinformationaboutrisks,therightbalanceofcontrolinplacetodealwiththoserisks,anddecisionmakingprocessessupportedbyaframeworkofriskanalysisandevaluation.Managementofriskcoversawiderangeoftopics,includingbusinesscontinuitymanagement,security,programme/projectriskmanagementandoperationalservicemanagement.Thesetopicsneedtobeplacedinthecontextofanorganisationalframeworkforthemanagementofrisk.Somerisk-relatedtopics,suchassecurity,arehighlyspecialisedandthisguidanceprovidesonlyanoverviewofsuchaspects.WhymanagementofriskisimportantAcertainamountofrisktakingisinevitableifyourorganisationistoachieveitsobjectives.Effectivemanagementofriskhelpsyoutoimproveperformancebycontributingto:?increasedcertaintyandfewersurprises?betterservicedelivery?moreeffectivemanagementofchange?moreefficientuseofresources?bettermanagementatalllevelsthroughimproveddecisionmaking?reducedwasteandfraud,andbettervalueformoney?innovation?managementofcontingentandmaintenanceactivities.SeeAnnexAforexamplesofthebenefitsofmoreeffectivemanagementofrisk.WhoisinvolvedinriskmanagementInpractice,everyoneinanorganisationisinvolvedinriskmanagementtosomeextentandshouldbeawareoftheirresponsibilitiesinidentifyingandmanagingrisk.However,therearesomeaspectsforwhichresponsibilitymustbeassignedtoindividuals.Withoutclearresponsibility(andtheauthoritytosupportthatresponsibility)someriskswillbemissedoroverlooked.Inthepublicsector,therearetwomajorroleswithaclearresponsibilitytoensurerisksaremanaged(therewillbeequivalentstotheserolesinprivatesectororganisations).Theserolesare:?anAccountingOfficer(orequivalentseniormanager),whoisresponsiblefortheorganisation'soverallexposuretorisk.TypicallythispersonwillbetheChiefExecutiveOfficer(CEO);theseniormanagerintheorganisation.Theymaydelegatesomeoftheactionsbutcannotforgotheresponsibility?aseniormanageractingasaproject'owner;whoisresponsibleforriskrelatingtoaspecificprogrammeorprojectandfortherealisationofassociatedbusinessbenefits.AudienceforthisguidanceBusinessmanagers,processowners,strategicplanners,projectandprocurementteams,businesscontinuityplannersandsecurityteamsaretheprimaryaudienceforthisguidance,togetherwiththeirserviceproviders.Itwillalsobeofinteresttoauditors,withtheirresponsibilityforensuringeffectivecorporategovernance.Howtousethisguideintroducesthestructure,processandcultureofmanagementofrisk,explainingwhyorganisationsneedtodeviseandimplementeffectivestrategiesinordertomaximiseopportunitiesandminimisethreatstotheachievementoftheirbusinessobjectives.Itidentifieskeypersonnelinthemanagementofriskandthetargetaudiencefortheguidance.outlinesthekeyprinciplesunderpinningmanagementofrisk:establishingariskmanagementframework,riskownership,whererisksoccur,thedecisionmakingprocess,theimportanceofembeddingtheriskmanagementculture,andallocatingrealisticbudgets.describesthemainactivitiesofmanagementofrisk.Itcontainspracticalexamples,pointersandchecklistsforidentifyingandrespondingtorisk,andmonitoringriskresponses.Chapters4-7explainwhenandhowmanagementofriskshouldbeappliedthroughoutanorganisation,atthestrategic,programme,projectandoperationallevels.Chapter8discussestherangeoftechniquesavailabletosupporttheriskmanagementprocess.TheAnnexesprovidesupportingdetail:A:ExamplesofbenefitsofriskmanagementB:Healthcheck:howwellisyourorganisationmanagingrisk?C:CategorisingriskD:SettingastandardforevaluationofriskE:Procurement,contractualandlegalconsiderationsF:BusinesscontinuitymanagementG:ManagingorganisationalsafetyandsecurityH:InformationonfurthertechniquestosupportmanagementofriskJ:LessonslearnedfromothersK:AssessingthesuitabilityoftoolsL:Documentationoutlines.1.6TheresearchforthisguidancePreparedbyOGCsITDirectorate,thisguidancehasbeendevelopedfromextensiveresearchintocurrentthinkingandpracticeinboththepublicandprivatesectors,drawingonpublishedpapersandinterviews/studieswithanumberofleadingorganisationsinvolvedinmajorchangeandwithspecialistexpertsinthemanagementofrisk.ItbuildsontherecentworkoftheNationalAuditOffice(NAO),HMTreasuryandCabinetOffice,togetherwithOGCspublishedguidanceonbestpracticeinriskmanagement;italsoaimstoaddressissuesrelatingtocorporategovernance.Thisguidancerespondstolessonslearnedandtheexperiencesofreal-worldpracticalissues,asreportedbyconsultantsinOGC'sStrategicAssignmentsConsultancyServiceandtheirclients.Inaddition,itincorporatesfeedbackfromcontributorstoOGCworkshopsandotherreviewchannels.Thesecontributionsareacknowledgedwiththanks.CriticalsuccessfactorsformanagementofriskWhatisatriskandwhy?DecisionsaboutriskWhererisksoccurAframeworkformanagingriskRiskownershipEmbeddingtheriskmanagementcultureBudgetsThischapteroutlinesthekeyprinciplesunderpinningtheeffectivemanagementofrisk.CriticalsuccessfactorsformanagementofriskThekeyelementsthatneedtobeinplaceifriskmanagementistobeeffective,andinnovationencouraged,include:clearlyidentifiedseniormanagementtosupport,ownandleadonriskmanagementriskmanagementpoliciesandthebenefitsofeffectivemanagementclearlycommunicatedtoallstaffexistenceandadoptionofaframeworkformanagementofriskthatistransparentandrepeatableexistenceofanorganisationalculturewhichsupportswellthought-throughrisktakingandinnovationmanagementofriskfullyembeddedinmanagementprocessesandconsistentlyappliedmanagementofriskcloselylinkedtoachievementofobjectivesrisksassociatedwithworkingwithotherorganisationsexplicitlyassessedandmanagedrisksactivelymonitoredandregularlyreviewedonaconstructive'no-blame'basis.Jointworkingandpartnershipsofteninvolvemorecomplextypesofriskthatcanadverselyaffectthedeliveryofbusinessservices.Forexample,ifpartoftheserviceprovidedbyoneorganisationisdelayedorofpoorquality,thesuccessofthewholecollaborationcanbeputatrisk.Youmustmakesurethatyourorganisationknowsabouttheriskmanagementapproachesofyourpartners.Sharinginformationaboutriskmanagementmeansthatrisksincollaborativeprogrammescanbeidentifiedandmanagedinaproactiveway.PublicsectorconcernsTheModernisingGovernmentinitiativeseekstoencouragethepublicsectortoadoptwellmanagedrisktakingwhereitislikelytoleadtosustainableimprovementsinservicedelivery.Moreeffectiveriskmanagementwillimprovethepublicsector'sabilitytoundertaketheincreasinglycomplexandcross-cuttingprojectsthataredemandedbytheModernisationagenda.Publicsectororganisationsneedtohaveinplacetheskills,managementstructuresandorganisationalstructurestotakeadvantageofpotentialopportunitiestoperformbetterandtoreducethepossibilityoffailure.Thekeyareasthathavetobeaddressedare:therequirementsofcorporategovernance-includingmorefocusedandopenwaysofmanagingrisk(seethesectiononcorporategovernancebelow)theneedfora'riskowner'atseniorlevel,foranactivity(strategy,programmeorproject).Heorsheissupportedbyriskownersateverydayworkinglevelsasappropriatefortheactivityandriskexposuretheneedforimprovedreportingandupwardreferralofmajorproblemsopportunitiesandthepotentialresolutionapproachestheneedforsharedunderstandingofriskmanagementatalllevelsintheorganisationandwithpartners,combinedwithconsistenttreatmentofriskmanagingprojectriskinthewidercontextofprogrammesofchangeandthebusiness.TheNAOstudyofriskmanagement{SupportingInnovation:ManagingRiskinGovernmentDepartments),theCabinetOffice'sreportSuccessfulYT:ModernisingGovernmentinAction,andHMTreasury'sOrangeBookprovidevaluablemessagesthatareincorporatedinthisguidance.MeetingtheneedsofcorporategovernanceCorporategovernanceistheongoingactivityofmaintainingasoundsystemofinternalcontroltosafeguardshareholders/investmentandthecompany'sassets.TheTurnbullReportstatesthat:'acompany'sobjectives,itsinternalorganisationandtheenvironmentwhichitoperatesinarecontinuallyevolvingandasaresulttherisksitfacesarecontinuallychanging.Asoundsystemofcontrolthereforedependsonathoroughandregularevaluationofthenatureandextentoftheriskstowhichthecompanyisexposed.Sinceprofits[orbusinessresults]areinparttherewardforsuccessfulrisktakinginbusiness,thepurposeofinternalcontrolistohelpmanageandcontrolriskratherthaneliminateit/Corporategovernanceframeworksmustensurethatmanagementisheldaccountableforacorporation'sperformanceandthatownersareabletomonitorandinterveneintheoperationsofmanagement.Theseprinciplesapplyequallytothepublicandprivatesectors.Whereascorporationsfocusmainlyonshareholderreturnsandthepreservationofshareholders'value,thepublicsector'sroleistoimplementprogrammescosteffectivelyinaccordancewithGovernmentlegislationandpolicies.TheBritishStandardsInstitute(BSI)hasproducedaguidancenoteonCorporateGovernance-PD6668:2000-relatingtothemanagementofstrategicrisks.Itoutlinesamanagementframeworkforidentifyingthethreats,determiningtherisks,implementationandmaintainingcontrolmeasuresandfinallyreportingannuallyontheorganisation'scommitmenttothisprocess.PolicyonmanagementofrisktosupportcorporategovernanceTosupportcorporategovernance,thereneedstobeariskmanagementpolicyinplace.Thispolicyshould:beappropriateforthesizeandnatureofyourorganisation,itsbusinessandoperatingenvironmentbeclearabouttheroles(and,ifpossible,individuals)thatareresponsibleforriskbeclearaboutescalationcriteriainrelationtoriskmanagement(i.e.,whentoreferdecisionmakingupwards)ensurethatprocesses,andthecuIture/infrastructure,toidentifyandmanageriskareputinplace;theseprocessesmustberepeatablesetupthemechanismformonitoringthesuccessoftheapplicationofthepolicy(includingreportstomanagement,atleastannually)ensurethatinternalcontrolmechanismsareinplaceforindependentassessmentthatthepolicyisimplemented(andchecked).Whatisatriskandwhy?Therearemanydiversefactorsthatcouldplaceanorganisationatrisk.Figure1outlinesthemainreasonswhythereshouldbearobustriskmanagementprocessinplace.Yourorganisationwillhaveasetofkeyobjectives.Risksshouldbeidentifiedagainsttheseobjectives,ideallynotmorethan10-15athighlevel.Thesehigh-levelriskswillthenbeconsideredandmanagedbyseniormanagement,increasingtheorganisation'sabilitytomeetitsobjectives.AnnexBprovidesa'healthcheck'toseeifanorganisationisadoptinganeffectiveframeworkformanagementofriskandriskmanagementprocess.AnnexCexpandsonpossiblecategoriesofrisk.Relatingmanagementofrisktosafety,securityandbusinesscontinuityManagementofriskshouldbecarriedoutinthewidercontextofsafetyconcerns,securityandbusinesscontinuity.Healthandsafetypolicyandpracticeisconcernedwithensuringthattheworkplaceisasafeenvironment.Securityisconcernedwithprotectingtheorganisation'sassets,includinginformation,buildingsandsoon.Businesscontinuityisconcernedwithensuringthattheorganisationcouldcontinuetooperateintheeventofadisaster;suchaslossofaservice,floodorfiredamage.Figure1:ReasonsforariskmanagementprocessReducingriskinlargescaleprojectsExperiencehasshownthatprogrammesandprojectsattemptingalargescale,comprehensivebusinesschangearelesslikelytobesuccessfulthanthosetakingalessambitious,step-by-stepapproach.Althoughthelatterincreasesmanagementactivity,witheachoftheelementsneedingtobecontrolledandcoordinated,theadvantagesarethatactivitiesare:easiertomanagesimplertoimplementwithinthebusinessenvironmenteasiertoacceptformallyas,typically,thespecificationiseasiertodocumentandthussimplertoverifythatithasbeenmetabletooffermoreoptionsforcontingencymorelikelytoaccommodatefastmovingchangesintechnology,orinthepoliticalorfinancialenvironmentabletooffermoredecisionpoints,allowinggreatercontroloftheproject.2.3DecisionsaboutriskDecisionsaboutriskneedtobebalancedsothatthepotentialbenefitsareworthmoretotheorganisationthanitcoststoaddresstherisk.Forexample,innovationisinherentlyriskybutcouldachievemajorbenefitsinimprovingservices.Theabilityoftheorganisationtolimititsexposuretoriskwillalsobeofrelevance.Youshouldaimtomakeanaccurateassessmentoftherisksinagivensituationandanalysethepotentialbenefits.Therisksandopportunitiespresentedbyeachcourseofactionshouldbedefinedinordertoidentifyappropriateresponse.ScopeofdecisionsDecisionsaboutriskwillvarydependingonwhethertheriskrelatestolong,mediumorshort-termgoals.Strategicdecisionsareprimarilyconcernedwithlong-termgoals;thesesetthecontextfordecisionsatotherlevelsoftheorganisation.Therisksassociatedwithstrategicdecisionsmaynotbecomeapparentuntilwellintothefuture.Thusitisessentialtoreviewthesedecisions,andassociatedrisks,onaregularbasis.Medium-termgoalsareusuallyaddressedthroughprogrammesandprojectstobringaboutbusinesschange.Decisionsrelatingtomedium-termgoalsarenarrowerinscopethanstrategicones,particularlyintermsoftimeframeandfinancialresponsibilities.Attheoperationalleveltheemphasisisonshort-termgoalstoensureongoingcontinuityofbusinessservices;however,decisionsaboutriskatthislevelmustalsosupporttheachievementoflong-andmedium-termgoals.TheseorganisationallevelsarediscussedinmoredetailinChapters4,5,6and7.Therearealsoconsiderationsaboutwhatcanrealisticallybeachievedinonechangeinitiative.Deliveryofeachofthecomponentsofachangeinitiative(whetheraprogramme,projectorstage)mustprovidesomedirectbenefittotheorganisationasaresultofitsdelivery.Thiscouldbebydelivering:?amajorcomponenttosupport/buildtowardstheintendedoutcome-forexample,providingatelephonehelplinefirstaspartofanewinformationserviceandthenaddingwebsiteservicestoexpandthefacilitiesavailabletothepublic?theproducttopartoftheendusercommunityandthen'rollingouttotherestofthatcommunity-forexample,introducinganewinformationserviceintheNorth-Eastandgraduallymakingitavailablenationwide.Thisisamodularand/orincrementalapproachthatisfurtherdiscussedinChapters5and6andinAnnexE.Whenmanaginganyprojectitisessentialtoensuremajordecisionsaremadeappropriately.Aprojectwillsupportsomebusinesschangeandsorequiresomethingtobeproducedandthenputintouse.Figure2showsthemainstagesoftheprocurementprocessandthedecisionstobetakenaboutbreakingprojectsdownintomanageable'packages*.Formajorprojects,therewillbeformalGatewayReviewsinadditiontothenormalprojectdecisionpoints;thesereviewsestablishwhethertheprojectisreadytoproceedtothenextstage.Figure2:Mainstagesoftheprocurementprocess2.4WhererisksoccurTheriskmanagementprocessshouldbemostrigorouslyappliedwherecriticaldecisionsarebeingmade.Figure3showswhereriskcanoccurinanorganisation.Forconvenience,theselevelsaredescribedas:strategicorcorporateprogrammeprojectoperational.Inpractice,thelevelsoverlap;however,itishelpfultoclarifytheoccurrenceofrisksattheselevelstoinformthekindofdecisionsyouarelikelytomake.Figure3:OrganisationalmanagementhierarchyItisimportanttonotethatariskmaymaterialiseinitiallyatonelevelbutsubsequentlyhaveamajorimpactatadifferentlevel.ArecentexampleisaHighStreetbankfacingtechnicalfaultsattheoperationallevel;ultimatelycustomers/confidenceinthebank'sonlineservicebecameastrategicrisk.Thishighlightstheneedforrelevantinformationaboutriskstobesharedthroughouttheorganisation.Table1showsexamplesoftypicalrisksoccurringateachorganisationallevel.Table1:RiskrelatedtoorganisationallevelsLevel ExamplesoftypicalrisksconsideredatthislevelStrategic/corporateCommercial,financial,political,environmental,directional,cultural,acquisitionandqualityrisks.Thereisafocusonbusinesssurvival,continuityandgrowthforthefuture.Whenprogramme,projectandoperationalrisksexceedsetcriteria-e.g.notacceptable,outsideagreedlimits,couldaffectstrategicobjectives,informationneedstobeescalatedtothislevelsothatappropriatedecisionscanbetaken.ProgrammeProcurement/acquisition,funding,organisational,projects,security,safety,qualityandbusinesscontinuityrisks.Whenprojectandoperationalrisksexceedsetcriteria-e.g.notacceptable,outsideagreedlimits,couldaffectprogrammeobjectives,informationneedstobeescalatedtothislevelsothatappropriatedecisionscanbetaken.Project Personal,technical,cost,schedule,resource,operationalsupport,qualityandproviderfailure.Operationalissues/risksshouldbeconsideredatthislevelastheyaffecttheprojectandhowitneedstoberun.Informationonstrategicandprogrammerelatedrisksshouldbecommunicatedtothislevelwheretheycouldaffectprojectobjectives.Projectmanagersshouldcommunicateinformationonriskstootherprojectsandoperationsasappropriate.OperationsPersonal,technical,cost,schedule,resource,operationalsupport,quality,providerfailure,environmentalandinfrastructurefailure.AIIthehigherlevelshaveinputtothislevel;specificconcernsincludebusinesscontinuitymanagement/contingencyplanning,supportforbusinessprocessesandcustomerrelations.AdditionalfactorsAdditionalfactorsmayincreasethecomplexityofassessingoverallexposuretorisk.Theseinclude:interdependencies,orlinksbetweenprojectsand/orrelatedissues,wheretheimpactofoneormoreriskscouldaffectothers,possiblycreatinga'domino'effect.Youshouldensurethatanyknowninterdependenciesareidentifiedandassessedsothatappropriateactioncanbeplannedtherelationshipbetweenbusinessbenefitsandriskstodelivery,whereachievementofbenefitsisdependentonsuccessfuldeliveryofaproject.Youshouldcontinuallycheckwhetherchangingplansaffecttheachievementofbenefits.AframeworkformanagingriskAframeworkformanagementofrisksetsthecontextinwhichriskswillbeidentified,analysed,controlled,monitoredandreviewed.Itmustbeconsistentwithprocessesthatareembeddedineverydaymanagementandoperationalpractices.Itaddresses:howrisksareidentifiedhowinformationabouttheirprobabilityandpotentialimpactisobtainedhowrisksarequantifiedhowoptionstodealwiththemareidentifiedhowdecisionsonriskmanagementaremade,suchasfurtherriskreductionhowthesedecisionsareimplementedhowactionsareevaluatedfortheireffectivenesshowappropriatecommunicationmechanismsaresetupandsupportedhowstakeholdersareengagedthroughouttheprocess.(SeeChapter3formoreinformationaboutthemanagementofriskframeworkandsupportingprocesses.)RiskownershipFortheorganisation,ownershipoftheriskmanagementframeworklieswiththeAccountingOfficer(orequivalentseniormanageratBoardlevel).Individualseniormanagersowntheprogrammeorprojectandareresponsibleforthemanagementoftheoverallriskofthatactivity.However,theserolesdonotownalltheindividualrisks.Riskownershipmustbeclearlydefined,documentedandagreedwiththeindividualownersatalllevels,sothattheyunderstandtheirvariousroles,responsibilitiesandultimateaccountabilitywithregardtothemanagementofrisk.Theownerofariskmaynotbethepersontaskedwiththeassessmentormanagementoftherisk,butheorsheisresponsibleforensuringthemanagementofriskprocessisapplied-theremaybeseparateownerstoactuallydealwiththerisks.Itisimportanttoidentifywhoowns:thesettingpolicyandtheorganisation'swillingnesstotakeriskthemanagementofriskprocessatthedifferentlevels-thatis,strategic,programme,project,operationallevelsdifferentelementsofthemanagementofriskprocess,suchasidentifyingthreats,throughtoproducingriskresponsesandreportingondecisionsimplementationoftheactualmeasurestakeninresponsetotherisksinterdependentrisksthatcrossorganisationalboundaries,whethertheyarebusinessprocesses,operationalservicesorprojects.Forexample,foraseniormanagerwithresponsibilityforaproject,ownershipofriskcouldbedefinedasfollows:Seniormanagersresponsibleforprojectsmustassurethemselvesthatanumberoftypesofriskarebeingtrackedanddealtwithaseffectivelyaspossible.Themechanismsinplaceformonitoringandreportingriskwillvaryaccordingtothesizeandcomplexityoftheprojectorprogramme,rangingfromtheuseofasimpleriskregistertotheappointmentofariskmanagerreportingdirectlytotheseniormanager.Clearly,thedegreeofdelegationadoptedbytheseniormanagerwillvary,butheorshemustbesurethatthecriticalissuesarebeingaddressed;forexample,throughchairingtheprojectboardorbydevelopingstrongmechanismsforreportingproblems.Checklist:ownershipofriskandtheprocessHaveownersbeenallocatedforallthevariouspartsofthecompletemanagementofriskprocess?Arethevariousrolesandresponsibilitiesassociatedwithownershipwelldefined?Dotheindividualswhohavebeenallocatedownershipactuallyhavetheauthorityandcapabilitytofulfiltheirresponsibilities?Forexample,suppliersmaybetaskedwithriskownership.Havethevariousrolesandresponsibilitiesbeencommunicatedandunderstood?Arethenominatedownersappropriateandawareoftheirnomination?Isownershipreassessedonaperiodicbasis,orintheeventofachangeinthesituation;andifnecessary,canitbequicklyandeffectivelyreallocated?Doallrisks,andwhereappropriatetheirmitigationactions,haveclearlyidentifiedowners?Aretheseownersappropriate?EmbeddingtheriskmanagementcultureIdentifyingappropriatepolicies,standardsandpracticesisthefirststageofcreatingariskmanagementculture.Oncetheseareinplacetheyneedtobetotallyembeddedinindividualsthroughtheenactmentoftheirrolesandassociatedresponsibilities.Awarenessofandresponsibilityforriskissuesmustbelinkedexplicitlytokeyobjectives,inordertobuildasustainableriskmanagementculture.Thereshouldbedelegatedresponsibilityforrisksateverylevelofobjectivesintheorganisation.Thisisthemajorsupporttoembeddingriskmanagementintotheorganisationanditsculture,withriskmanagementseenasanintrinsicpartofthewayanorganisationworks.Asthepeopleinanorganisationchange,itisessentialtoensureacontinuingunderstandingofrolesandresponsibilitiesrelatedtomanagingrisk.Theriskenvironmentisconstant
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 心靈涂鴉繪畫課程設(shè)計
- 織毛衣的手工課程設(shè)計
- 食物的消化與一吸收復(fù)習(xí)測試附答案
- 人教版九年級上冊數(shù)學(xué)期中考試試卷帶答案-2022年
- 2024年短期建筑施工協(xié)議
- 二零二五年度環(huán)保材料生產(chǎn)合伙創(chuàng)業(yè)合同
- 2025年小區(qū)電梯廣告品牌形象合作合同
- 2025版子女教育及撫養(yǎng)綜合性協(xié)議書模板3篇
- 二零二五年度個人住房貸款合同糾紛代理服務(wù)合同
- 2025年電壓力煲合作協(xié)議書
- 2024年時事政治試題【有答案】
- 全套教學(xué)課件《工程倫理學(xué)》
- 人音版六年級上冊全冊音樂教案(新教材)
- 2024年認(rèn)證行業(yè)法律法規(guī)及認(rèn)證基礎(chǔ)知識
- 機(jī)械原理課程設(shè)計鎖梁自動成型機(jī)床切削機(jī)構(gòu)
- 病理生理學(xué)試題及復(fù)習(xí)資料
- 國電南自遠(yuǎn)動服務(wù)器作業(yè)指導(dǎo)書1介紹
- WXZ196系列微機(jī)消諧裝置說明書
- 卡特彼勒生產(chǎn)體系手冊(PDF62頁)
- 四川省煤礦探放水基準(zhǔn)線“兩把鎖”管理規(guī)定
- 消防安全重點單位檔案(參考)
評論
0/150
提交評論