Monday, March 19, 2018

Risk Analysis


In a previous post, we discussed Risk Identification.  We discussed seven areas in an operation where foreseeable risk can exist, and we outlined four methodologies that can be used to identify foreseeable risk.  Next, we need to determine the probability that each risk event will occur and a measurement of the impact the event will have on operations.  
In this post, we will look at:
  • the probability of an event occurring
  • the measured impact the event could have on operations.
  • an assessment to determine if the level of risk is acceptable based on appetite and tolerance.
  • finally, prioritization based on the level of impact to operations. 

Probability

Oh no, here comes that nervous twitch and the flashbacks to college statistics!  Not to worry we are not about to start calculating the standard deviation from the mean of anything. 

For the purposes of this post, we are going to define probability as the likelihood that an event will occur. In its basic form, probability assumes that all possibilities must be equally likely to occur. Since we know this is not likely, we factor in a frequency variable which means that over time, a risk event has the likelihood of occurring x number of times (where x is the frequency of the event).  This is based on the collection of historic data and experience and is not an absolute. Although you cannot know the exact value of a probability, you can estimate it by observing how often similar events have occurred in the past. A common example that uses frequency interpretation is weather forecasting. If the forecast calls for a 60 percent chance of rain, it means that under the same weather conditions, it will rain in 60 percent of cases. This approach can be difficult and requires some individual judgment and credible historic data.

If credible historic data is not available, we can determine probability through subjective interpretation.    This approach is often used in situations where there is very little direct evidence. There may only be indirect information, educated guesses, or intuition, to consider. The probability of an event occurring is based on what an individual believes in the likelihood of occurrence. Different people assess probabilities differently, based on opinion or evaluation. One disadvantage of this approach is that it is often hard for people to estimate the probability, and the same person can end up estimating different probabilities for the same event using different techniques.  If this occurs, review the steps in each of the techniques and try to determine what caused the differences.  If you are unable to, in my opinion, take an average of the probabilities and use that. 

Measured Impact

After determining the probability of a risk event, we need to assign a value to the impact this will have on operations.   Knowing the probability of the event occurring, we multiply this by the amount it will cost operations if it happens.  With historical data, the probability and cost projections easier to determine. Without historical information, the estimates must be based on experience. 

This gives you a value for the risk:

Risk Value = Probability of Event x Cost of Event

As a simple example, imagine that you've identified a risk that when the water in a nearby retention pond rises to five feet, the basement of your business floods.
You think that there's an 80 percent chance of this happening because it has been an unusually wet winter and in past winters with similar amounts of rain and snow, you have experienced the flooding nearly every time. If this happens, it will cost your business an extra $25,000 in clean-up costs and lost income.
So the risk value of the flooded basement is:
0.80 (Probability of Event) x $25,000 (Cost of Event) = $20,000 (Risk Value)

Applying this analysis to each event allows you to rank the risk based on a value.  If the value data is not available, another option is to use an impact/probability chart. 

A risk probability/impact chart is a tool I have used often as it is a quick and easy way to visually plot the probability of an event occurring and the impact that event will have on operations.  This chart is most useful when subjectively determining the probability and impact of risk. 




To most effectively use this chart
  1. Assess the probability of each risk occurring and assign it a rating from 1-10. Assign a score of 1 when a risk is extremely unlikely to occur and use a score of 10 when the risk is extremely likely to occur. In the example above, there is an 80% probability of flooding occurring, therefore you would assign a value of 8 to the risk.
  2. Estimate the impact of the risk occurring. Again, using a 1-10 scale, assign it a 1 for little impact and a 10 for a huge, catastrophic impact. In the above case maybe a flooded basement is a nuisance, but it does not significantly impact operations so you assign it a “5”
  3. Map out the ratings on the Risk Impact/Probability Chart.
  4. Develop a response to each risk, according to its position in the chart. Remember, risks in the bottom left corner can often be ignored, while you will want to focus your attention on the risks in the upper right quadrant.

Assessment of the risk

Recalling the post about Risk Appetite and tolerance, we now evaluate the identified risk as falling inside or outside of tolerance based on your risk appetite statement.  This will allow you to determine a target risk value to review or on the Risk Impact/Risk Probability chart, a point above which you will review and rank the risk.    

Using the flooded basement example again.  Assume your company’s risk tolerance statement was something to the effect “XYZ Company cannot afford the cost associated with a single flooded basement event”.  Since you estimated an 80% probability of a flood event occurring based on the weather patterns this winter, this would rank pretty high for risk to review.

Prioritization of risk

Finally, you will want to prioritize the list.  This can be done based on the importance of the risk to operations, or (if you can determine at this point) you can prioritize the list based on the amount of resources it will take to manage risk.  In either event, this allows you to break down the list into manageable pieces.  This also will help to determine a strategy or how you will manage each of the risk. Here is an example of three risks identified by XYZ Company:
  1. There is a proposal from an engineer that says in order to solve for the flooded basement, you need to enlarge the retention pond and redirect the run-off.  The cost of this project is $60,000 but will potentially save $20,000+ if there is a wet winter. Additionally, the flooded basement impacts production as some of the production equipment has to be shut down every time the basement floods to protect the equipment.
  2. You have a proposal from a web-design firm to expand and enhance your online presence.  The cost of the project is $25,000. This new design will not only allow you to interact with customers through a customer service portal and social media, you will now have the ability for online retail sales.  This webpage can really broaden your market presence and potentially boost sales and revenue significantly.  You will need to hire a full-time employee to manage the webpage, and if sales go as projected, you will need to expand your production and shipping capabilities.
  3. The equipment used in your production process is getting old and showing signs of wear.  You have a proposal to update your equipment. It is a two-year upgrade process that will allow you to continue current production pace, but there is no room for increased production until after the updates are completed. The cost of the upgrades is $40,000 each year for a total of $80,000. 

So here are three risk scenarios, how would you prioritize them?

While we can't avoid risk altogether, there are often steps we can take to better cope with risk.  Risk analysis helps us determine the right steps to take, in the right order. 

Until next time, say safe and be kind to one another.

No comments:

Post a Comment