© March 2018 Bureau Veritas
•Continuity and Resilience (CORE)
•ISO 22301 BCM Consulting Firm
•Presentations by speakers at the
7th
ME Business & IT Resilience Summit
March 11, 2018 at The Address Hotel, Duabi Mall, Dubai, UAE
Our Contact Details:
UAE INDIA
Continuity and Resilience
Website: www.coreconsulting.ae
Tel: +971 2 6594006
PO Box: 25722, Abu Dhabi, United Arab Emirates
Email: info@continuityandresilience.com
Continuity and Resilience
Tel: +91 11 41055534 | Direct: +91 11 6467 9380
Email: info@continuityandresilience.com
Website: www.coreconsulting.ae
Level 15, Eros Corporate Towers, Nehru Place, New Delhi
– 110019, India
IMPLEMENTING RISK MANAGEMENT
SYSTEM
(Based on ISO 31000: 2018 Risk Management – Guidelines)
3IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Managing Risk
The Challenge !!!
â–şWe live in an ever-changing world
where we are forced to deal with
uncertainty every day.
Why ?
Organizations of all types and sizes
face external and internal factors and
influences that make it uncertain
whether they will achieve their
objectives.
4IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Success
What Predicts Success ??
â–şHow an organization tackles that
uncertainty can be a key predictor of
its success
Source : ISO 31000
Managing Risk
5IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Why Risk Management ?
Preparing for and responding to negative
events, from the predictable to the unforeseen,
from the mundane to the catastrophic, has
become a fact of life for businesses and
governments around the world.
Tackling these risks requires an integrated
and holistic framework with the capability to
identify, evaluate and adequately define
responses to the circumstances
This holistic approach gives organizations a
better framework for mitigating risk while
advancing their goals and opportunities in the
face of business threats
Source : ISO 31000
6IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Why ISO 31000 ?
â–şRisk is a necessary part of doing business and in a world
where enormous amounts of data are being processed at
increasingly rapid rates, identifying and mitigating risks is a
challenge for any company.
â–şMany contracts and insurance agreements require solid
evidence of good risk management practice.
â–şISO 31000 provides direction on how companies can
integrate risk-based decision making into an organization’s
governance, planning, management,reporting, policies, values
and culture
Source : ISO 31000
7IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
ISO 31000:2018 Risk management
â–şThis provides Guidelines on Managing risk faced by
organizations.
â–şThe application of these guidelines can be
customized to any organization and its context.
â–şThis document provides a common approach to
managing any type of risk and is not industry or sector
specific.
â–şThis document can be used throughout the life of the
organization and can be applied to any
activity,including decision-making at all levels.
Source : ISO 31000
8IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Implementing Risk Management
â–şis iterative and assists organizations in setting strategy,
achieving objectives and making informed decisions.
â–şis part of governance and leadership, and is fundamental to how
the organization is managed at all levels. It contributes to the
improvement of management systems.
â–şis part of all activities associated with an organization and
includes interaction with stakeholders
â–şconsiders the external and internal context of the organization,
including human behaviour and cultural factors
â–şis based on the principles, framework and process.
â–şThese components might already exist in full or in part within the
organization, however, they might need to be adapted or improved
so that managing risk is efficient, effective and consistentSource : ISO 31000
9IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Principles, framework and process
10IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Step 1 Define Risk Management Principles
â–şThe purpose of risk management is the
creation and protection of value.
â–ş It improves performance, encourages
innovation and supports the
achievement of objectives.
Source : ISO 31000
11IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
ISO 31000
Principles for risk management
â–şRisk management creates and protects value
Contributes to the demonstrable achievement of objectives and
improvement of performance in, for example, human health and
safety, security, legal and regulatory compliance, public
acceptance, environmental protection, product quality, project
management, efficiency in operations, governance and reputation.
â–şRisk management is an integral part of all organizational processes
Part of the responsibilities of management and of all organizational
processes including strategic planning and project and change
management processes.
â–şRisk management is part of decision making
Helps decision makers make informed choices, prioritize actions
and distinguish among alternative courses of action.
â–şRisk management explicitly addresses uncertainty
Takes account of uncertainty, the nature of that uncertainty, and
how it can be addressed.
Source : ISO 31000
12IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Principles for risk management, continued ..
â–şRisk management is systematic, structured and timely
A systematic, timely and structured approach contributes to efficiency
and to consistent, comparable and reliable results.
â–şRisk management is based on the best available information
The Inputs to the process are based on information sources such as
historical data, experience, stakeholder feedback, observation, forecasts
and expert judgment.
â–şRisk management is tailored.
It is aligned with the organization's external and internal context and risk
profile.
â–şRisk management takes human and cultural factors into account
recognizes the capabilities, perceptions and intentions of external and
internal people that can facilitate or hinder achievement of the
organization's objectives.
Source : ISO 31000
13IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Principles for risk management, continued …
â–şRisk management is transparent and inclusive.
Appropriate and timely involvement of stakeholders and, in particular,
decision makers at all levels of the organization, ensures that risk
management remains relevant and up-to-date. Involvement also allows
stakeholders to be properly represented and to have their views taken into
account in determining risk criteria.
â–şRisk management is dynamic, iterative and responsive to change.
Risk management continually senses and responds to change. As external
and internal events occur, context and knowledge change, monitoring and
review of risks take place, new risks emerge, some change, and others
disappear.
â–şRisk management facilitates continual improvement of the
organization
Organizations should develop and implement strategies to improve their
risk management maturity alongside all other aspects of their organization.
Source : ISO 31000
14IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Step 2 Develop Risk Management Framework
•The purpose of the risk management
framework is to assist the organization in
integrating risk management into
significant activities and functions.
•The effectiveness of risk management will
depend on its integration into the
governance of the organization, including
decision-making.
•This requires support from stakeholders,
particularly top management.
•Framework development encompasses
integrating, designing, implementing,
evaluating and improving risk management
across the organization.
Components of Framework
Source : ISO 31000
15IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Step 3 Establish Risk Management process
The risk management process involves the
systematic application of policies,
procedures and practices to the activities
of :
•Communicating and consulting,
•Establishing the context and
•Assessing, treating, monitoring,
•Reviewing, recording and
•Reporting risk.
Source : ISO 31000
16IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Establish Risk Management process
•The risk management process should
be an integral part of management and
decision-making and integrated into the
structure, operations and processes of
the organization.
•It can be applied at strategic,
operational, programme or project
levels.
Source : ISO 31000
17IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Step 4 Communication and consultation
Communication and consultation aims
to:
•bring different areas of expertise
together for each step of the risk
management process;
•ensure that different views are
appropriately considered when defining
risk criteria and when evaluating risks;
• provide sufficient information to
facilitate risk oversight and decision-
making;
•build a sense of inclusiveness and
ownership among those affected by risk.
Source : ISO 31000
18IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Step 5 Establishing the context
•The purpose of establishing the scope,
the context and criteria is to customize
the risk management process, enabling
effective risk assessment and
appropriate risk treatment.
•Scope, context and criteria involve
defining the scope of the process, and
understanding the external and internal
context.
Source : ISO 31000
19IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Step 6 Perform Risk assessment
•Risk assessment is the overall process
of risk identification, risk analysis and
risk evaluation.
•Risk assessment should be conducted
systematically, iteratively and
collaboratively, drawing on the
knowledge and views of stakeholders.
•It should use the best available
information, supplemented by further
enquiry as necessary.
Source : ISO 31000
20IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Step 7 Risk Treatment
•The purpose of risk treatment is to
select and implement options for
addressing risk.
•Risk treatment involves an iterative
process of:
• formulating and selecting risk treatment
options;
• planning and implementing risk treatment;
• assessing the effectiveness of that
treatment;
• deciding whether the remaining risk is
acceptable;
• if not acceptable, taking further treatment.
Source : ISO 31000
21IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Step 8 Monitor and review Risk Management Process
•The purpose of monitoring and review
is to assure and improve the quality and
effectiveness of process design,
implementation and outcomes.
•Ongoing monitoring and periodic review
of the risk management process and its
outcomes should be a planned part of
the risk management process, with
responsibilities clearly defined..
Source : ISO 31000
22IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Step 9 Recording and reporting outcomes
•The risk management process and its
outcomes should be documented and
reported through appropriate
mechanisms.
•Recording and reporting aims to:
• communicate risk management activities and
outcomes across the organization;
• provide information for decision-making;
• improve risk management activities;
• assist interaction with stakeholders, including
those with responsibility and accountability for
risk management activities.
Source : ISO 31000
23IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
ISO 31000 Relationship with other management systems
â–ş Leadership (corporate Governance) of an organisation is performed by
Top Management and high level personnel of the different departments.
â–ş To direct management and employees for common objectives and
behaviours a policy of the organisation is deployed, communicated and
implemented.
â–ş Management Systems arrange the organisations different control
mechanisms.
â–ş Management-Information-Systems measure the activities in the organization
and present the results with quantitative and financial indicators.
â–ş All activities of the organisation must comply to statutory and regulatory
requirements.
Source : ISO 31000
24IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
ISO 31000
Connection with Other Management instruments
Top Management
“Corporate Governance“
Integrated
Management-
system
Organizations
policy
Risk management
Customer, statutory, regulatory and standardized requirements
Management
information
system
(with internal
Controlling)
Source : ONR 49000
25IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Risk Management and other related standards
ISO 27001 :
INFORMATION
SECURITY
MANAGEMENT
SYSTEM
ISO 22301 :
BUSINESS
CONTINUITY
MANAGEMENT
ISO 31000 : RISK MANAGEMENT GUIDELINES
ISO27001:A.14.1
Information
security aspects of
business continuity
management
harmonize risk management processes in existing and future standards,
dealing with specific risks and/or sectors, and does not replace those
standards
preservation of confidentiality,
integrity and availability of
information
strategic and tactical capability of the
organization to plan for and respond to
incidents and business disruptions in
order to continue business operations at
an acceptable pre-defined level
Also the QMS, EMS,OHSMS,ASSET MANAGEMENT to name a few in ISO series
Requires Risk Management
26IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas
Thank You
•Process Excellence and Resilience...
• Creating Corporate Sustainability© March 2018 Bureau Veritas
Continuity and Resilience (CORE)
•ISO 22301 BCM Consulting Firm
•Presentations by our partners and extended
team of industry experts
UAE INDIA
Continuity and Resilience
Website: www.coreconsulting.ae
Tel: +971 2 6594006
PO Box: 25722, Abu Dhabi, United Arab Emirates
Email: info@continuityandresilience.com
Continuity and Resilience
Tel: +91 11 41055534 | Direct: +91 11 6467 9380
Email: info@continuityandresilience.com
Website: www.coreconsulting.ae
Level 15, Eros Corporate Towers, Nehru Place, New Delhi –
110019, India

More Related Content

PDF
Enterprise Risk Management - Aligning Risk with Strategy and Performance
PDF
How to Build an Enterprise Risk Management Framework
PPTX
Risk culture presentation
PPTX
Operational Risk Management - A Gateway to managing the risk profile of your...
PPTX
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
PPTX
Implementing Enterprise Risk Management with ISO 31000:2009
PPTX
Key risk indicators shareslide
PPTX
Integrating Risk Appetite With Strategy Feb 14 2011
Enterprise Risk Management - Aligning Risk with Strategy and Performance
How to Build an Enterprise Risk Management Framework
Risk culture presentation
Operational Risk Management - A Gateway to managing the risk profile of your...
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
Implementing Enterprise Risk Management with ISO 31000:2009
Key risk indicators shareslide
Integrating Risk Appetite With Strategy Feb 14 2011

What's hot (20)

PDF
Embedding RCSA into Strategic Planning and Business Strategy
PDF
ISO 31000:2018 Risk Management System, Framework and Implementation
PPTX
Risk management
PDF
Riskpro - Operational Risk Management
PDF
Business Risk Management Overview PowerPoint Presentation Slides
PDF
Risk Overview & Risk management
PPTX
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
PDF
Enterprise Risk Management Framework
PDF
Enterprise Risk Management PowerPoint Presentation Slides
PDF
Risk Management Lifecycle PowerPoint Presentation Slides
PPTX
Integrating Strategy and Risk Management
PPTX
Governance, risk and compliance framework
 
PDF
Operational risk management and measurement
PPTX
Enterprise Risk Management and Sustainability
 
PDF
Iso 31000 Risk management Principles and guidelines
PPT
Introduction to risk management
PPTX
Operational risk ppt
PDF
Governance Culture & Incentives- Fundamentals of Operational Risk
PPTX
Governance, Risk & Compliance Management Solution
PPTX
Risk management
Embedding RCSA into Strategic Planning and Business Strategy
ISO 31000:2018 Risk Management System, Framework and Implementation
Risk management
Riskpro - Operational Risk Management
Business Risk Management Overview PowerPoint Presentation Slides
Risk Overview & Risk management
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Enterprise Risk Management Framework
Enterprise Risk Management PowerPoint Presentation Slides
Risk Management Lifecycle PowerPoint Presentation Slides
Integrating Strategy and Risk Management
Governance, risk and compliance framework
 
Operational risk management and measurement
Enterprise Risk Management and Sustainability
 
Iso 31000 Risk management Principles and guidelines
Introduction to risk management
Operational risk ppt
Governance Culture & Incentives- Fundamentals of Operational Risk
Governance, Risk & Compliance Management Solution
Risk management
Ad

Similar to Implementing a Risk Management System based on the ISO 31000 (20)

PDF
Five lines of assurance a new paradigm in internal audit & erm
PPTX
Five Lines of Assurance A New ERM and IA Paradigm
PPTX
ISO 31000 2018 PRESENTATION.pptrisk management principles and frameworkx
PPTX
1-.Teklay-EFFORT (PPT) -April-2025- Risk Mgnt Top Mgmnt -Breifing.PPTX
PDF
Risk management erm
PDF
A structured approach to Enterprise Risk Management (ERM) and the requirement...
PDF
Descriptor MetisGRC
PDF
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...
PPTX
Relevance of ISO 31000 for risk professionals.pptx
PDF
Essay On Risk Management
PPT
Risk Management Presentation to Doyle Property Club
PPTX
Super Strategies 2014 Risk Strategy Presentation
DOCX
I need response to the discussion post in 200 words.docx
PPT
FERMA presentation at the IIA Belgium Conference
 
PPTX
Iso 31000
PPT
Risk Management Fundamentals
PPTX
Management of risk introduction
PDF
The IRM India- A Risk Management Standard
PDF
Management of Risk M_o_R Dubai - Syzygal
PDF
Riskpro iso 31000 services 2013
Five lines of assurance a new paradigm in internal audit & erm
Five Lines of Assurance A New ERM and IA Paradigm
ISO 31000 2018 PRESENTATION.pptrisk management principles and frameworkx
1-.Teklay-EFFORT (PPT) -April-2025- Risk Mgnt Top Mgmnt -Breifing.PPTX
Risk management erm
A structured approach to Enterprise Risk Management (ERM) and the requirement...
Descriptor MetisGRC
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...
Relevance of ISO 31000 for risk professionals.pptx
Essay On Risk Management
Risk Management Presentation to Doyle Property Club
Super Strategies 2014 Risk Strategy Presentation
I need response to the discussion post in 200 words.docx
FERMA presentation at the IIA Belgium Conference
 
Iso 31000
Risk Management Fundamentals
Management of risk introduction
The IRM India- A Risk Management Standard
Management of Risk M_o_R Dubai - Syzygal
Riskpro iso 31000 services 2013
Ad

More from Continuity and Resilience (20)

PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - AWS
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - John Davison
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Sunil Mehta
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Murphy -Dat...
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Shakti Moha...
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Dr.Carlotta...
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Megan James...
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Vijay - 4 B...
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Zhanar Tuke...
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE Paul Gant - A...
PDF
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Abdelmoaty Ali
PDF
🌟 Join Resilience Expert Dhiraj Lal in this FREE Career Upgrade Session! 🌟
PDF
Celebrating Success: Transformative BCM Specialist Training for the Water & P...
PPTX
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
PPTX
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
PPTX
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul Gant
PPTX
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
PPTX
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
PDF
DEFLUFFING RESILIENCE
PDF
CREATING AND MAINTAINING A BCM PROGRAM
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - AWS
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - John Davison
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Sunil Mehta
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Murphy -Dat...
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Shakti Moha...
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Dr.Carlotta...
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Megan James...
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Vijay - 4 B...
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Zhanar Tuke...
The Business Conference and IT Resilience Summit Abu Dhabi, UAE Paul Gant - A...
The Business Conference and IT Resilience Summit Abu Dhabi, UAE - Abdelmoaty Ali
🌟 Join Resilience Expert Dhiraj Lal in this FREE Career Upgrade Session! 🌟
Celebrating Success: Transformative BCM Specialist Training for the Water & P...
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul Gant
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
DEFLUFFING RESILIENCE
CREATING AND MAINTAINING A BCM PROGRAM

Recently uploaded (20)

PDF
Tortilla Mexican Grill 发射点犯得上发射点发生发射点犯得上发生
PPTX
df0ee68f89e1a869be4bff9b80a7 business 79f0.pptx
PPTX
basic introduction to research chapter 1.pptx
PPTX
IMM.pptx marketing communication givguhfh thfyu
PDF
income tax laws notes important pakistan
DOCX
Handbook of Entrepreneurship- Chapter 5: Identifying business opportunity.docx
PDF
Satish NS: Fostering Innovation and Sustainability: Haier India’s Customer-Ce...
PDF
Consumer Behavior in the Digital Age (www.kiu.ac.ug)
PDF
Highest-Paid CEO in 2025_ You Won’t Believe Who Tops the List.pdf
PDF
Cross-Cultural Leadership Practices in Education (www.kiu.ac.ug)
DOCX
Center Enamel A Strategic Partner for the Modernization of Georgia's Chemical...
PPTX
Portfolio Example- Market & Consumer Insights – Strategic Entry for BYD UK.pptx
PDF
Engaging Stakeholders in Policy Discussions: A Legal Framework (www.kiu.ac.ug)
PDF
Value-based IP Management at Siemens: A Cross-Divisional Analysis
 
PDF
Middle East's Most Impactful Business Leaders to Follow in 2025
PPTX
chapter 2 entrepreneurship full lecture ppt
PDF
Immigration Law and Communication: Challenges and Solutions {www.kiu.ac.ug)
PDF
Vinod Bhatt - Most Inspiring Supply Chain Leader in India 2025.pdf
DOCX
80 DE ÔN VÀO 10 NĂM 2023vhkkkjjhhhhjjjj
PDF
#1 Safe and Secure Verified Cash App Accounts for Purchase.pdf
Tortilla Mexican Grill 发射点犯得上发射点发生发射点犯得上发生
df0ee68f89e1a869be4bff9b80a7 business 79f0.pptx
basic introduction to research chapter 1.pptx
IMM.pptx marketing communication givguhfh thfyu
income tax laws notes important pakistan
Handbook of Entrepreneurship- Chapter 5: Identifying business opportunity.docx
Satish NS: Fostering Innovation and Sustainability: Haier India’s Customer-Ce...
Consumer Behavior in the Digital Age (www.kiu.ac.ug)
Highest-Paid CEO in 2025_ You Won’t Believe Who Tops the List.pdf
Cross-Cultural Leadership Practices in Education (www.kiu.ac.ug)
Center Enamel A Strategic Partner for the Modernization of Georgia's Chemical...
Portfolio Example- Market & Consumer Insights – Strategic Entry for BYD UK.pptx
Engaging Stakeholders in Policy Discussions: A Legal Framework (www.kiu.ac.ug)
Value-based IP Management at Siemens: A Cross-Divisional Analysis
 
Middle East's Most Impactful Business Leaders to Follow in 2025
chapter 2 entrepreneurship full lecture ppt
Immigration Law and Communication: Challenges and Solutions {www.kiu.ac.ug)
Vinod Bhatt - Most Inspiring Supply Chain Leader in India 2025.pdf
80 DE ÔN VÀO 10 NĂM 2023vhkkkjjhhhhjjjj
#1 Safe and Secure Verified Cash App Accounts for Purchase.pdf

Implementing a Risk Management System based on the ISO 31000

  • 1. © March 2018 Bureau Veritas •Continuity and Resilience (CORE) •ISO 22301 BCM Consulting Firm •Presentations by speakers at the 7th ME Business & IT Resilience Summit March 11, 2018 at The Address Hotel, Duabi Mall, Dubai, UAE Our Contact Details: UAE INDIA Continuity and Resilience Website: www.coreconsulting.ae Tel: +971 2 6594006 PO Box: 25722, Abu Dhabi, United Arab Emirates Email: info@continuityandresilience.com Continuity and Resilience Tel: +91 11 41055534 | Direct: +91 11 6467 9380 Email: info@continuityandresilience.com Website: www.coreconsulting.ae Level 15, Eros Corporate Towers, Nehru Place, New Delhi – 110019, India
  • 2. IMPLEMENTING RISK MANAGEMENT SYSTEM (Based on ISO 31000: 2018 Risk Management – Guidelines)
  • 3. 3IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Managing Risk The Challenge !!! â–şWe live in an ever-changing world where we are forced to deal with uncertainty every day. Why ? Organizations of all types and sizes face external and internal factors and influences that make it uncertain whether they will achieve their objectives.
  • 4. 4IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Success What Predicts Success ?? â–şHow an organization tackles that uncertainty can be a key predictor of its success Source : ISO 31000 Managing Risk
  • 5. 5IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Why Risk Management ? Preparing for and responding to negative events, from the predictable to the unforeseen, from the mundane to the catastrophic, has become a fact of life for businesses and governments around the world. Tackling these risks requires an integrated and holistic framework with the capability to identify, evaluate and adequately define responses to the circumstances This holistic approach gives organizations a better framework for mitigating risk while advancing their goals and opportunities in the face of business threats Source : ISO 31000
  • 6. 6IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Why ISO 31000 ? â–şRisk is a necessary part of doing business and in a world where enormous amounts of data are being processed at increasingly rapid rates, identifying and mitigating risks is a challenge for any company. â–şMany contracts and insurance agreements require solid evidence of good risk management practice. â–şISO 31000 provides direction on how companies can integrate risk-based decision making into an organization’s governance, planning, management,reporting, policies, values and culture Source : ISO 31000
  • 7. 7IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas ISO 31000:2018 Risk management â–şThis provides Guidelines on Managing risk faced by organizations. â–şThe application of these guidelines can be customized to any organization and its context. â–şThis document provides a common approach to managing any type of risk and is not industry or sector specific. â–şThis document can be used throughout the life of the organization and can be applied to any activity,including decision-making at all levels. Source : ISO 31000
  • 8. 8IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Implementing Risk Management â–şis iterative and assists organizations in setting strategy, achieving objectives and making informed decisions. â–şis part of governance and leadership, and is fundamental to how the organization is managed at all levels. It contributes to the improvement of management systems. â–şis part of all activities associated with an organization and includes interaction with stakeholders â–şconsiders the external and internal context of the organization, including human behaviour and cultural factors â–şis based on the principles, framework and process. â–şThese components might already exist in full or in part within the organization, however, they might need to be adapted or improved so that managing risk is efficient, effective and consistentSource : ISO 31000
  • 9. 9IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Principles, framework and process
  • 10. 10IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Step 1 Define Risk Management Principles â–şThe purpose of risk management is the creation and protection of value. â–ş It improves performance, encourages innovation and supports the achievement of objectives. Source : ISO 31000
  • 11. 11IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas ISO 31000 Principles for risk management â–şRisk management creates and protects value Contributes to the demonstrable achievement of objectives and improvement of performance in, for example, human health and safety, security, legal and regulatory compliance, public acceptance, environmental protection, product quality, project management, efficiency in operations, governance and reputation. â–şRisk management is an integral part of all organizational processes Part of the responsibilities of management and of all organizational processes including strategic planning and project and change management processes. â–şRisk management is part of decision making Helps decision makers make informed choices, prioritize actions and distinguish among alternative courses of action. â–şRisk management explicitly addresses uncertainty Takes account of uncertainty, the nature of that uncertainty, and how it can be addressed. Source : ISO 31000
  • 12. 12IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Principles for risk management, continued .. â–şRisk management is systematic, structured and timely A systematic, timely and structured approach contributes to efficiency and to consistent, comparable and reliable results. â–şRisk management is based on the best available information The Inputs to the process are based on information sources such as historical data, experience, stakeholder feedback, observation, forecasts and expert judgment. â–şRisk management is tailored. It is aligned with the organization's external and internal context and risk profile. â–şRisk management takes human and cultural factors into account recognizes the capabilities, perceptions and intentions of external and internal people that can facilitate or hinder achievement of the organization's objectives. Source : ISO 31000
  • 13. 13IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Principles for risk management, continued … â–şRisk management is transparent and inclusive. Appropriate and timely involvement of stakeholders and, in particular, decision makers at all levels of the organization, ensures that risk management remains relevant and up-to-date. Involvement also allows stakeholders to be properly represented and to have their views taken into account in determining risk criteria. â–şRisk management is dynamic, iterative and responsive to change. Risk management continually senses and responds to change. As external and internal events occur, context and knowledge change, monitoring and review of risks take place, new risks emerge, some change, and others disappear. â–şRisk management facilitates continual improvement of the organization Organizations should develop and implement strategies to improve their risk management maturity alongside all other aspects of their organization. Source : ISO 31000
  • 14. 14IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Step 2 Develop Risk Management Framework •The purpose of the risk management framework is to assist the organization in integrating risk management into significant activities and functions. •The effectiveness of risk management will depend on its integration into the governance of the organization, including decision-making. •This requires support from stakeholders, particularly top management. •Framework development encompasses integrating, designing, implementing, evaluating and improving risk management across the organization. Components of Framework Source : ISO 31000
  • 15. 15IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Step 3 Establish Risk Management process The risk management process involves the systematic application of policies, procedures and practices to the activities of : •Communicating and consulting, •Establishing the context and •Assessing, treating, monitoring, •Reviewing, recording and •Reporting risk. Source : ISO 31000
  • 16. 16IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Establish Risk Management process •The risk management process should be an integral part of management and decision-making and integrated into the structure, operations and processes of the organization. •It can be applied at strategic, operational, programme or project levels. Source : ISO 31000
  • 17. 17IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Step 4 Communication and consultation Communication and consultation aims to: •bring different areas of expertise together for each step of the risk management process; •ensure that different views are appropriately considered when defining risk criteria and when evaluating risks; • provide sufficient information to facilitate risk oversight and decision- making; •build a sense of inclusiveness and ownership among those affected by risk. Source : ISO 31000
  • 18. 18IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Step 5 Establishing the context •The purpose of establishing the scope, the context and criteria is to customize the risk management process, enabling effective risk assessment and appropriate risk treatment. •Scope, context and criteria involve defining the scope of the process, and understanding the external and internal context. Source : ISO 31000
  • 19. 19IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Step 6 Perform Risk assessment •Risk assessment is the overall process of risk identification, risk analysis and risk evaluation. •Risk assessment should be conducted systematically, iteratively and collaboratively, drawing on the knowledge and views of stakeholders. •It should use the best available information, supplemented by further enquiry as necessary. Source : ISO 31000
  • 20. 20IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Step 7 Risk Treatment •The purpose of risk treatment is to select and implement options for addressing risk. •Risk treatment involves an iterative process of: • formulating and selecting risk treatment options; • planning and implementing risk treatment; • assessing the effectiveness of that treatment; • deciding whether the remaining risk is acceptable; • if not acceptable, taking further treatment. Source : ISO 31000
  • 21. 21IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Step 8 Monitor and review Risk Management Process •The purpose of monitoring and review is to assure and improve the quality and effectiveness of process design, implementation and outcomes. •Ongoing monitoring and periodic review of the risk management process and its outcomes should be a planned part of the risk management process, with responsibilities clearly defined.. Source : ISO 31000
  • 22. 22IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Step 9 Recording and reporting outcomes •The risk management process and its outcomes should be documented and reported through appropriate mechanisms. •Recording and reporting aims to: • communicate risk management activities and outcomes across the organization; • provide information for decision-making; • improve risk management activities; • assist interaction with stakeholders, including those with responsibility and accountability for risk management activities. Source : ISO 31000
  • 23. 23IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas ISO 31000 Relationship with other management systems â–ş Leadership (corporate Governance) of an organisation is performed by Top Management and high level personnel of the different departments. â–ş To direct management and employees for common objectives and behaviours a policy of the organisation is deployed, communicated and implemented. â–ş Management Systems arrange the organisations different control mechanisms. â–ş Management-Information-Systems measure the activities in the organization and present the results with quantitative and financial indicators. â–ş All activities of the organisation must comply to statutory and regulatory requirements. Source : ISO 31000
  • 24. 24IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas ISO 31000 Connection with Other Management instruments Top Management “Corporate Governance“ Integrated Management- system Organizations policy Risk management Customer, statutory, regulatory and standardized requirements Management information system (with internal Controlling) Source : ONR 49000
  • 25. 25IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Risk Management and other related standards ISO 27001 : INFORMATION SECURITY MANAGEMENT SYSTEM ISO 22301 : BUSINESS CONTINUITY MANAGEMENT ISO 31000 : RISK MANAGEMENT GUIDELINES ISO27001:A.14.1 Information security aspects of business continuity management harmonize risk management processes in existing and future standards, dealing with specific risks and/or sectors, and does not replace those standards preservation of confidentiality, integrity and availability of information strategic and tactical capability of the organization to plan for and respond to incidents and business disruptions in order to continue business operations at an acceptable pre-defined level Also the QMS, EMS,OHSMS,ASSET MANAGEMENT to name a few in ISO series Requires Risk Management
  • 26. 26IMPLEMENTING RISK MANAGEMENT SYSTEM© March 2018 Bureau Veritas Thank You
  • 27. •Process Excellence and Resilience... • Creating Corporate Sustainability© March 2018 Bureau Veritas Continuity and Resilience (CORE) •ISO 22301 BCM Consulting Firm •Presentations by our partners and extended team of industry experts UAE INDIA Continuity and Resilience Website: www.coreconsulting.ae Tel: +971 2 6594006 PO Box: 25722, Abu Dhabi, United Arab Emirates Email: info@continuityandresilience.com Continuity and Resilience Tel: +91 11 41055534 | Direct: +91 11 6467 9380 Email: info@continuityandresilience.com Website: www.coreconsulting.ae Level 15, Eros Corporate Towers, Nehru Place, New Delhi – 110019, India

Editor's Notes

  • #4: Discuss with the delegates the principles. Describe the connection to policy.
  • #5: Discuss with the delegates the principles. Describe the connection to policy.
  • #6: Discuss with the delegates the principles. Describe the connection to policy.
  • #7: Discuss with the delegates the principles. Describe the connection to policy.
  • #8: Discuss with the delegates the principles. Describe the connection to policy.
  • #9: Discuss with the delegates the principles. Describe the connection to policy.
  • #12: Discuss with the delegates the principles. Describe the connection to policy.
  • #13: Discuss with the delegates the principles. Describe the connection to policy.
  • #14: Discuss with the delegates the principles. Describe the connection to policy.
  • #24: See graphical description on the following slide.