Simply, to know your risks you need to know your business and how it fits into the broader environment. Consider using the PEST Wheel as a way to bring out the key aspects that impact your business.

Political
Economical
Social
Technology

Brainstorm your business risks

Use simple techniques to work through your risks such as brainstorming and mind mapping. Make this part of running your business.

Analyse and understand business risks

The brainstorm should generate some "risk ideas" but these need futher understanding and analysis to best determine the risk. Consider asking about who, what, when, how and why, and also using the "5-Whys" technique.

Quantify your business risks

Utilise formulaic approaches to quantify risks wherever possible such as historical instances in and outside your organisation, and leveraging data on processes. Plot the results on a visual that provides a simple view of the high/medium/low risk levels.

E-Extreme risk requiring immediate action
H-High risk issue requiring additional controls
M-Moderate risk issues that are likely to be acceptable should they happen
L-Low risk issues that can be dealt with

Control your business risks

Develop process flow documentation and then establish appropriate controls to manage against the risk. Consider the possible different risk treatment strategies in the control process:
- Avoid
- Reduce
- Transfer
- Replace controls
- Offset

Educate and communicate your business risks

Effective risk management does not end with this process, it is ever changing and evolving. Therefore, develop learning modules for staff and continually communicate on the importance of escalation.

Develop required action plans

Risks are not always adequately covered and therefore where the business does not accept the current level of control, then action plans should be established, monitored and reviewed.

Determine and monitor risk indicators

Risk indicators are indicators that provide a barometer of tolerable levels of risk, give early warning signs and show measures of change in risks. Measures should include operational events, compliance events, and control failures.

shared by innovaterisk on Aug 23
An infographic from Riskographics providing a visual guide for "knowing your risks". Leveraging the AS/NZS ISO 31000:2009 Risk Management – Principles and Guidelines, this infographic provides


