Risk Management
每个已识别风险之处理方案的纪录 风险缓解计划 紧急应变计划 负责追踪及解决每个风险的人员清单
SG2 Risks are identified and analyzed to determine their relative importance.
识别风险并分析决定他们的相关重要 性。
分析风险需要从内外部来源识别风险,而 后评估每一风险,以决定可能性和发生结 果。风险分类提供处理风险所需的信息, 它是依据已建立的风险类别,以及风险管 理策略所发展的准则来进行评估。为了有 效率的处理和有效的应用风险管理资源, 可把相关风险组成不同的群组。
从SP1.1到SP1.3,要求逐步深化。SP1.1 只要求确定风险来源及分类。SP1.2就要求 定义清晰的风险属性,一般来说,风险会 有原因、后果、严重级别、发生机率、类 别等属性,每个企业可以根据自己需要定 义属性。SP1.3所谓的风险管理策略,指得 就是风险如何存储、记录、跟踪、采取什 么缓解措施等所有关于风险管理的组织级 别的要求。
风险管理(Risk Management, RSKM)的 目的是在风险发生前,识别出潜在的问题, 以便在产品或项目的生命周期中规划风险 处理活动,并于必要时启动风险管理,如 此可将不利于完成目标的影响降低。
SG1主要就是讲述组织级的要求,而SG2、 SG3重点讲数, 评估已识别的风险
ACCA笔记 SBL笔记9 Risk management
ACCA笔记 | SBL笔记9 | Risk management今日的笔记是Risk management的第一篇笔记,下一篇笔记会集中讲述Risk management process这个大知识点~Organisational Control and Audit部分知识点传送门:SBL笔记7SBL笔记81. Risk- Risks are the opportunities and dangers associated with uncertain future events.- Risks can have an adverse (‘downside exposure’) or favourable impact (‘upside potential’) on the organisation’s objectives.【注意:有好也有坏】- Risk management:增强好的影响减少坏的影响2. Roles and responsibilities of board of directors on risk management.- It considers risk at the strategic level and defines the organisation's appetite and approach to risk. - The board is responsible for driving the risk management process and ensuring that managers responsible for implementing risk management have adequate resources. - The board ensures that the risk management strategy iscommunicated to the rest of the organisation and integrated with all the other activities. - The board will determine which risks will be accepted, which cannot be managed, or which it is not cost-effective to manage.3. Risk appetite - Risk appetite describes the willingness of an entity to become exposed to an unrealised risk. - There are usually two preference: risk seeking and risk aversion.- Risk appetite is determined by: Risk capacity and Risk attitude4. Risk manager - Member of risk committee. - Supported and monitored by the risk management committee. - Policy is set by the board and the risk management committee and implemented by the risk manager.- The role is more operational than strategic.5. Risk awareness - A lack of risk awareness means that an organisation has an inappropriate risk management strategy. - Risks affecting the organisation may not have been identified meaning there will be a lack of control over that risk. - Risks may occur and the control over that risk is not active due to lack of monitoring and awareness.- 3 levels: Strategic level, Tactical level, and Operational level6. ERM framework 1) Internal environment - including the risk management philosophy and risk appetite2) Objective setting3) Event identification4) Risk assessment - Risks are analysed to consider their likelihood and impact 5) Risk response - avoid, accept, reduce or share risk 6) Control activities - Policies and procedures7) Information and communication8) Monitoring。
风险管理 Risk Management目的:在发生前识别潜在的问题,以便在整个产品或者项目生命周期中,按需策划和激活风险应对活动,缓解对实现目标的不利影响Identify potential problems before they occur so that risk handling activities can be planned and invoked as needed across the life of the product or project to mitigate adverse impacts on achieving objectivesMitigate 减轻;adverse:不利的,相反的特定目标:– SG 1 准备风险管理 Prepare for Risk Management– SG 2 识别和分析风险 Identify and Analyze Risks– SG 3 缓解风险 Mitigate RisksSG1 准备风险管理Prepare for Risk Management 目标陈述:进行风险管理准备Preparation for risk management is conducted.特定实践:– SP1.1 确定风险来源和类别 Determine Risk Sources and Categories– SP1.2 定义风险参数 Define Risk Parameters– SP1.3 制订风险管理策略 Establish a Risk Management StrategySP1.1 确定风险来源和类别 Determine Risk Sources and Categories•确定风险的来源和类别*Risk Management Sampling of Work Products——Plans典型工作产品1.风险(内部和外部)来源一览表2.风险类别一览表子实践1. 确定风险来源2. 确定风险类别SP1.2 定义风险参数 Define Risk Parameters•定义参数用于分析和归类风险并用于控制风险管理的努力*Risk Management Sampling of Work Products——Plans典型工作产品1. 风险评价、分类和排序准则2.风险管理需求(如,控制和批准的级别,重新评估的间隔)子实践1. 为评价和量化风险的可能性和严重等级,定义一致的准则2. 规定每类风险的阈值3. 把界限定义在风险阈值的适用范围上或定义在某个风险类别中SP1.3 建立风险管理策略Establish a Risk Management Strategy•建立和维护用于风险管理的策略*Risk Management Sampling of Work Products——Plans典型工作产品1. 项目风险管理策略SG2 识别和分析风险Identify and Analyze Risks目标陈述:识别和分析风险来确定风险的相对重要性Risk are identified and analyzed to determine their relative importance.特定实践:– SP2.1 识别风险 Identify Risks– SP2.2 对风险进行评价、分类和排序 Evaluate, Categorize, and Prioritize Risks SP2.1 识别风险 Identify Risks•识别风险并文档化典型工作产品1. 已识别的风险的一览表,包括上下文、条件和风险发生的后果*Risk Management Sampling of Work Products——Risk Repository(仓库)*Risk Management Sampling of PA and GP Relationships——PP SP 2.2 Identify Project Risks子实践1. 识别与成本、进度和性能相关联的风险2. 评审可能影响项目的环境元素3. 作为风险识别活动的一个部分,对工作分解结构的所有元素进行评审,以便有助于确保工作的所有各个方面都得到考虑4. 作为风险识别活动的一个部分,对项目计划的所有元素进行评审,以便有助于确保项目的所有各个方面都得到考虑5. 把风险的上下文、条件和潜在的后果形成文件6. 识别风险有关的干系人SP 2.2 对风险进行评价、分类和排序Evaluate, Categorize, and Prioritize Risks•运用风险类别和参数对每个风险进行评价和分类,并确定其相对优先级*Risk Management Sampling of Work Products——Risk Repository(仓库)典型工作产品1. 风险一览表和优先级子实践1. 运用规定的风险参数对所识别的风险进行评价2. 根据规定的风险类别对风险进行分类和分组3. 为缓解风险排列优先顺序SG3 缓解风险Mitigate Risks目标陈述:在适当时处理和缓解风险,从而降低对实现项目目标的不利影响Risks are handled and mitigated as appropriate to reduce adverse impacts on achieving objectives.特定实践:– SP3.1 制定风险缓解计划 Develop Risk Mitigation Plans– SP3.2 实施风险缓解计划 Implement Risk Mitigation PlansSP3.1 制定风险缓解计划 Develop Risk Mitigation Plans•按照风险管理策略的规定,制定风险缓解计划*Risk Management Sampling of Work Products——Risk Repository(仓库)典型工作产品1.文档化的已识别风险的应对选项2.风险缓解计划3.应急计划4.负责跟踪和处理风险的责任人一览表子实践1. 确定风险级别和阈值;它们指出风险在什么情况下将变得不可接受并且将触发风险风险或应急计划2. 确定负责处理每个风险的人或组3. 确定实施风险缓解计划的成本/效益比4. 拟订本项目的总体风险缓解计划,用以指导单个风险的缓解计划和应急计划的实施5. 针对所选择的关键风险拟订应急计划,以备影响发生SP 3.2 实施风险缓解计Implement Risk Mitigation Plans•定期监督每个风险的状态并且在适当时实施风险缓解计划*Risk Management Sampling of Work Products——Risk Repository(仓库)*Risk Management Sampling of PA and GP Relationships——PMC SP 1.3 Monitor Project Risks典型工作产品1.经过更新的风险状态表2.风险可能性、后果、等级和阈值的新的评估结果3.更新的风险处理意见汇总4.更新的风险处理行动汇总5.风险处理选项的风险缓解计划子实践1. 监督风险状态2. 提供跟踪方法,用以从开始到结束对风险处理行动进行跟踪3. 当所监督的风险超过规定阈值时,调用所选择的风险处理选项4. 针对每个风险处理活动制订进度,其中包括开始日期和预计完成日期5. 为每个计划提供持续的资源承诺,以保证风险处理策略的成功执行6. 收集关于风险处理活动的性能度量。
风险管理risk management:是指通过识别风险、衡量风险、分析风险,从⽽有效的控制风险,⽤最经济的⽅法来综合处理风险,以实现最佳安全⽣产保障的科学管理⽅法。
⽬标管理management by objective:是由组织中的管理者和被管理者共同参与⽬标制定,在⼯作中由员⼯实⾏⾃我控制并努⼒完成⼯作⽬标的管理⽅法。
正式组织(Formal organization)是指为了实现某⼀共同⽬标,对其内部成员的职责范围和相互关系,以政策、章程、组织结构等加以明⽂规定所形成的组织体系。