1 PURPOSE
- To determine adverse threats affecting organisational assets and provide a risk treatment strategy to them.
- To identify external and internal threats to the organisational assets.
- To identify existing and potential disaster-mitigating systems/procedures.
2 SCOPE
- This procedure is applied to the Organization BCM Coordinator and Business Unit BCM Coordinators.
3 RESPONSIBILITY
- The Organization BCM Coordinator is responsible for knowing how much the potential threats can affect the organization and to provide a risk treatment.
- The BCM Steering Committee is responsible for reviewing findings and recommendations of risk analysis efforts. For each identified risk, the committee shall deliberate and select appropriate cost-effective risk treatment(s).
4 PROCEDURE (FOR RISK IDENTIFICATION)
Note: The risk identification procedure is made in accordance with ISO 31000.
4.1 List of Threats
Each business unit should identify the Risks it faces from the List of Threats which is applicable to the organisation, especially those occurring in the following categories: policies, processes, people and infrastructure. The impact of these risks on each of the primary and support activities of the organisation should then be deliberated upon and determined. This is the list which has been identified:
- Flood
- Pandemic Outbreak
- Theft (Physical, Data)
- Absence of Key Staff
- Loss of Key Personnel
- Loss of Key Suppliers
- Regulatory or Legal; Violation (WSH/MOM)
- Fire (Building)
- Workplace Injury
- Power Failure (Building)
- Equipment Failure
- Facilities Failure (air-con, HVAC, UPS, generator)
- Water Leakage (data centre, toilet, chilled water)
- Human Error (IT & non-IT)
- Physical Security Breaches
- Telecommunications Failure
- IT Failure (hardware, software, data, the web)
4.2 Risk Treatment
- It is important to identify the risk as different risk have a different impact of the people/process/infrastructure which will give different methods of Risk Treatment.
4.3 Risk Likelihood of the event
- The likelihood of the event will show how serious the risk is in some locations/area/country.
4.4 Risk Impact on people/ process/ infrastructure (APPENDIX I)
- How a risk can impact the people/ process/ infrastructure is severe as it will affect how the business still the process.
4.5 Estimated disruption period
- By estimating the process, one will be able to identify how long should we reacted on the outcome.
4.6 Scaling
- Scaling is used to identify the danger level of the risk which will affect the organisation.
4.7 Risk Rating
- The Risk Rating is the result of the multiplication of the assigned value for Risk Likelihood against the assigned value of Risk Impact.
5 PROCEDURE (FOR RISK APPETITE)
5.1 Risk Appetite
- The Risk Appetite is the willingness of an organisation to accept a defined level of risk to conduct its business cost-effectively.
- The Risk Appetite for BCM Institute is described as the description and financial values found in the Impact Rating scale of “3” and impact descriptor as “Medium.”
- The risk that is deemed not acceptable by not acceptable are as follows:
- Financial:
- For example, the loss of more than SGD 100,000
- Processes (Business Operations):
- For example, the inability to resume the scheduled course within one working day or 3 calendar day; the provision for a candidate to undertake his online examination within 24 hours (as he or she is not a residence of Singapore)
- Legal and Regulatory:
- For example, being investigated by IDA for CITREP funding process inadequacy; being investigated by WDA for WSQ process funding inadequacy, and being sanction by MOM for inadequate workplace safety enforcement and manpower violation.
- Reputation and Image:
- For example, being highlighted on Channel News Asia or local newspaper for misappropriating actions.
- People:
- The injury was resulting in being hospitalised during duty.
- Assets/ ICT Systems/ Information:
- For example, Website not available for more than one working day; vTiger CRM not available for more than three working days; and online examination not available on the day of the scheduled examination (should there be a foreigner attending the course).
6 DEFINITIONS
- Risk Likelihood
- Risk Impact
- Risk Rating
- Organization BCM Coordinator
- Business Unit BCM Coordinator
- Risk
- Risk Treatment
7 RELATED DOCUMENT
- Explanatory Notes for Part 1 Threats and Impact
- Explanatory Notes for Part 2 Risks and Controls
- Explanatory Notes for Part 3 Disruption Due to Threats
- Guidance Notes
8 RECORDS
- Record of Risk Analysis and Review
9 APPENDICES
- Descriptor: List of Threats
- Descriptor: Impact Rating
- Descriptor: Risk Treatment
- Descriptor: Risk Likelihood
- Descriptor: Risk Ratings and Levels