Risk is embedded in every opportunity a business faces. And poor risk management can result in large financial costs, or even failure. Risk points can emerge anywhere: small scale project delays,
misguided actions of an employee, or a fire in an inventory warehouse. This article will help any small business owner or manager better understand what risks are out there, and more importantly, how to better control them.
First, I’ll explain why a systematic analysis of risks is important and illustrate a simple risk management architecture. Then, I’ll talk about how I helped companies better identify and manage a variety of risks.
What is Risk Management? Simply, risks are threats to your business or project. They are situations or events that can affect
outcome of your decisions and actions. Therefore, risk management is
identification, evaluation, and mitigation of risks to a business or project.
Why is Risk Management Important? All businesses exist for one clear reason: To make a profit. Poorly managed risks have tangible and dramatic effects on
bottom line. Therefore, sound risk management is important to ensure that your business can overcome any problems and continue to grow profitably.
Threats to a small business or project can come from a variety of sources. In 2002, The Risk Management Standard categorized risks into four areas: Financial, Operational, Strategic, and Hazard. Strategic risks can emerge from competitors, customers, or markets of a company. For example,
technological features of a companies’ product may become obsolete. Operational risks can affect how
company operates internally. Systems such as IT, material procurement, and accounting responsibilities can be compromised by employees. Financial risks can hinge on financial market performance, such as foreign exchange fluctuations. The last type- Hazard risk- can be
most damaging. Events like natural disasters, manmade disasters, and crime can permanently disable a company.
How to Build an Effective Risk Management Strategy An effective risk management strategy must be systematic and robust. It also must be straight-forward, and simple to implement.
An effective risk management strategy will have three stages: •Identify •Evaluate •Mitigate During
Identify stage, owners and/or senior managers need to thoroughly examine
business from many different perspectives. All risks facing all areas of a company need to be identified. This should be done with as many people involved as realistically possible to give a complete picture.
During
Evaluate stage, each risk is given a probability of occurrence and a severity of occurrence ranking (This can be done with a simple 1 to 5 scale; 1 being “rarely occurring” and “minimal damage”). This allows senior management to more clearly understand
extent of potential damage.
During
Mitigate stage,
resulting risks are controlled through a variety of methods. For example, traditional insurance is one way to remove hazard risk. Financial risks can be managed through capital market hedging transactions. Operational risks are minimized by clear check and balance procedures and management oversight within
company. Strategic risks can be minimized by better documentation, such as protecting intellectual property rights.