Actions

Difference between revisions of "Risk Mitigation"

 
(2 intermediate revisions by the same user not shown)
Line 1: Line 1:
The process by which an organization introduces specific measures to minimize or eliminate unacceptable risks associated with its operations. Risk mitigation measures can be directed towards reducing the severity of risk consequences, reducing the probability of the risk materializing, or reducing the organizations exposure to the risk.<ref>Definition - What is Risk Mitigation? [http://www.investorwords.com/19332/risk_mitigation.html InvestorWords]</ref>
+
== What is Risk Mitigation? ==
 +
The process by which an organization introduces specific measures to minimize or eliminate unacceptable risks associated with its operations. Risk mitigation measures can be directed towards reducing the severity of risk consequences, the probability of the risk materializing, or reducing the organization's exposure to the risk.<ref>[http://www.investorwords.com/19332/risk_mitigation.html Definition - What is Risk Mitigation?]</ref>
  
  
 
+
== Types of Risk Mitigation<ref>[https://www.mha-it.com/2013/05/17/four-types-of-risk-mitigation/ What are the The Four Types of Risk Mitigation?]</ref> ==
== Types of Risk Mitigation ==
+
Four types of risk mitigation strategies hold unique to Business Continuity and Disaster Recovery. It’s important to develop a strategy that closely relates to and matches your company’s profile.
'''The Four Types of Risk Mitigation'''<ref>What are the The Four Types of Risk Mitigation? [https://www.mha-it.com/2013/05/17/four-types-of-risk-mitigation/ MHA-IT]</ref><br />
+
*Risk Acceptance: Risk acceptance does not reduce effects but is still considered a strategy. This strategy is a common option when the cost of other risk management options such as avoidance or limitation, may outweigh the cost of the risk itself. A company that doesn’t want to spend a lot of money on avoiding risks that do not have a high possibility of occurring will use the risk acceptance strategy.
There are four types of risk mitigation strategies that hold unique to Business Continuity and Disaster Recovery. It’s important to develop a strategy that closely relates to and matches your company’s profile.
 
*Risk Acceptance: Risk acceptance does not reduce any effects however it is still considered a strategy. This strategy is a common option when the cost of other risk management options such as avoidance or limitation may outweigh the cost of the risk itself. A company that doesn’t want to spend a lot of money on avoiding risks that do not have a high possibility of occurring will use the risk acceptance strategy.
 
 
*Risk Avoidance: Risk avoidance is the opposite of risk acceptance. It is the action that avoids any exposure to the risk whatsoever. It’s important to note that risk avoidance is usually the most expensive of all risk mitigation options.
 
*Risk Avoidance: Risk avoidance is the opposite of risk acceptance. It is the action that avoids any exposure to the risk whatsoever. It’s important to note that risk avoidance is usually the most expensive of all risk mitigation options.
*Risk Limitation Risk limitation is the most common risk management strategy used by businesses. This strategy limits a company’s exposure by taking some action. It is a strategy employing a bit of risk acceptance along with a bit of risk avoidance or an average of both. An example of risk limitation would be a company accepting that a disk drive may fail and avoiding a long period of failure by having backups.
+
*Risk Limitation: Risk limitation is the most common risk management strategy businesses use. This strategy limits a company’s exposure by taking some action. It is a strategy employing a bit of risk acceptance along with a bit of risk avoidance or an average of both. An example of risk limitation would be a company accepting that a disk drive may fail and avoiding a long period of failure by having backups.
*Risk Transference: Risk transference is the involvement of handing risk off to a willing third party. For example, numerous companies [[Outsourcing|outsource]] certain operations such as customer service, payroll services, etc. This can be beneficial for a company if a transferred risk is not a core competency of that company. It can also be used so a company can focus more on their core competencies.
+
*Risk Transference: Risk transference involves handing risk off to a willing third party. For example, numerous companies outsource operations such as customer service, payroll services, etc. This can be beneficial for a company if a transferred risk is not a core competency of that company. It can also be used so a company can focus more on its core competencies.
  
  
== Risk Mitigation Planning ==
+
== Risk Mitigation Planning<ref>[https://www.nap.edu/read/11183/chapter/7 Risk Mitigation Planning]</ref> ==
 
 
'''Risk Mitigation Action Plans'''<ref>Risk Mitigation Planning [https://www.nap.edu/read/11183/chapter/7 Nap.edu]</ref><br />
 
 
Risk mitigation action plans should be incorporated in the project execution plan, or risk analyses are just so much wallpaper. Risk mitigation plans should:
 
Risk mitigation action plans should be incorporated in the project execution plan, or risk analyses are just so much wallpaper. Risk mitigation plans should:
 
*Characterize the root causes of risks that have been identified and quantified in earlier phases of the risk management process.
 
*Characterize the root causes of risks that have been identified and quantified in earlier phases of the risk management process.
Line 27: Line 24:
  
 
== Risk Mitigation Strategies ==
 
== Risk Mitigation Strategies ==
 
+
Several risk mitigation strategies can be used to assess risks, as demonstrated in the image below.
There are several risk mitigation strategies that can be used to assess risks, as demonstrated in the image below.
 
  
  
Line 35: Line 31:
  
  
*Accept: Make a deliberate decision to accept the risk and not develop any further plans to control it.
+
*Accept: Make a deliberate decision to accept the risk and not develop further plans to control it.
 
*Monitor: Review the risk universe for any changes that may influence the impact of the risk.
 
*Monitor: Review the risk universe for any changes that may influence the impact of the risk.
 
*Avoid: Change the risk processes and requirements to eliminate or reduce the risk.
 
*Avoid: Change the risk processes and requirements to eliminate or reduce the risk.
 
*Control: Develop further risk mitigation plans to minimize the impact and/or likelihood of the risk.
 
*Control: Develop further risk mitigation plans to minimize the impact and/or likelihood of the risk.
*Transfer: Reassign responsibility of the risk to another department or stakeholder in the organization for acceptance.
+
*Transfer: Reassign responsibility for the risk to another department or organizational stakeholder for acceptance.
  
  
== Risk Mitigation Approach ==
+
== Risk Mitigation Approach<ref>[https://www.jasadvisors.com/professional-services/risk-management/ Managing Internal and External Risk through Rik Mitigation]</ref> ==
 
+
Risk mitigation strategies must match the degree of control within the enterprise. Where the enterprise has significant control, the strategy should call for prevention measures; where there is limited control, mitigation, and resiliency are the keys to reducing risk.
'''Managing Internal and External Risk'''<ref>Managing Internal and Extrnal Risk through Rik Mitigation [https://www.jasadvisors.com/professional-services/risk-management/ JAS]</ref><br />
 
Risk mitigation strategies must match the degree of control within the enterprise. Where the enterprise has significant control, the strategy should call for prevention measures; where there is limited control, mitigation and resiliency are the keys to the reduction of risk.
 
  
  
Line 53: Line 47:
  
 
== See Also ==
 
== See Also ==
 +
*[[Risk Management]]
 +
*[[Risk Assessment]]
  
[[Risk Assessment|Assessment of Risk]]
 
[[Risk Assessment Framework (RAF)|Framework for Risk Assessment]]
 
[[Risk Based Testing|Risk Based Testing]]<br />
 
[[Risk IT Framework|Risk IT Framework]]<br />
 
[[Risk Management]]<br />
 
[[Risk Management Framework (RMF)|Risk Management Framework (RMF)]]<br />
 
[[Risk Matrix|Risk Matrix]]<br />
 
[[Risk Maturity|Risk Maturity]]<br />
 
[[Risk Maturity Model (RMM)|Risk Maturity Model (RMM)]]<br />
 
[[Compliance]]<br />
 
[[IT Governance|Corporate Governance of Information Technology (IT Governance)]]<br />
 
[[Key_Risk_Indicator_(KRI)|Key Risk Indicator (KRI)]]<br />
 
[[Business_Continuity|Business Continuity]]<br />
 
[[Business_Continuity_Planning_(BCP)|Business Continuity Planning (BCP)]]<br />
 
[[Disaster_Recovery_Planning|Disaster Recovery Planning]]<br />
 
[[Enterprise_Risk_Management_(ERM)|Enterprise Risk Management (ERM)]]<br />
 
[[Crisis_Management|Crisis Management]]<br />
 
[[Risk Analysis]]<br />
 
[[Risk-Adjusted Return on Capital (RAROC)]]<br />
 
[[Risk-Adjusted Return]]<br />
 
[[Own Risk and Solvency Assessment (ORSA)]]
 
  
 
== References ==
 
== References ==
 
 
<references/>
 
<references/>
  
  
 
== Further Reading ==
 
== Further Reading ==
*Risk Mitigation Planning, Implementation, and Progress Monitoring [https://www.mitre.org/publications/systems-engineering-guide/acquisition-systems-engineering/risk-management/risk-mitigation-planning-implementation-and-progress-monitoring Mitre]
+
*[https://www.mitre.org/publications/systems-engineering-guide/acquisition-systems-engineering/risk-management/risk-mitigation-planning-implementation-and-progress-monitoring Risk Mitigation Planning, Implementation, and Progress Monitoring]
*7 Ways To Mitigate Risk on Projects [https://www.strategyex.co.uk/blog/pmoperspectives/7-ways-to-mitigate-risk-on-projects/ StrategyEx]
+
*[https://www.strategyex.co.uk/blog/pmoperspectives/7-ways-to-mitigate-risk-on-projects/ 7 Ways To Mitigate Risk on Projects]
*Risk Mitigation And Management Scheme Based On Risk Priority [https://globaljournals.org/GJCST_Volume10/gjcst_vol10_issue4_25.pdf Basit Shahzad, Sara Afzal Safvi]
+
*[https://globaljournals.org/GJCST_Volume10/gjcst_vol10_issue4_25.pdf Risk Mitigation And Management Scheme Based On Risk Priority]
*Risk Mitigation, Monitoring and Management Plan [http://www.mhhe.com/engcs/compsci/pressman/graphics/Pressman5sepa/common/cs2/rmmm.pdf MHHE]
+
*[http://www.mhhe.com/engcs/compsci/pressman/graphics/Pressman5sepa/common/cs2/rmmm.pdf Risk Mitigation, Monitoring, and Management Plan]
 +
__NOTOC__

Latest revision as of 17:52, 13 April 2023

What is Risk Mitigation?

The process by which an organization introduces specific measures to minimize or eliminate unacceptable risks associated with its operations. Risk mitigation measures can be directed towards reducing the severity of risk consequences, the probability of the risk materializing, or reducing the organization's exposure to the risk.[1]


Types of Risk Mitigation[2]

Four types of risk mitigation strategies hold unique to Business Continuity and Disaster Recovery. It’s important to develop a strategy that closely relates to and matches your company’s profile.

  • Risk Acceptance: Risk acceptance does not reduce effects but is still considered a strategy. This strategy is a common option when the cost of other risk management options such as avoidance or limitation, may outweigh the cost of the risk itself. A company that doesn’t want to spend a lot of money on avoiding risks that do not have a high possibility of occurring will use the risk acceptance strategy.
  • Risk Avoidance: Risk avoidance is the opposite of risk acceptance. It is the action that avoids any exposure to the risk whatsoever. It’s important to note that risk avoidance is usually the most expensive of all risk mitigation options.
  • Risk Limitation: Risk limitation is the most common risk management strategy businesses use. This strategy limits a company’s exposure by taking some action. It is a strategy employing a bit of risk acceptance along with a bit of risk avoidance or an average of both. An example of risk limitation would be a company accepting that a disk drive may fail and avoiding a long period of failure by having backups.
  • Risk Transference: Risk transference involves handing risk off to a willing third party. For example, numerous companies outsource operations such as customer service, payroll services, etc. This can be beneficial for a company if a transferred risk is not a core competency of that company. It can also be used so a company can focus more on its core competencies.


Risk Mitigation Planning[3]

Risk mitigation action plans should be incorporated in the project execution plan, or risk analyses are just so much wallpaper. Risk mitigation plans should:

  • Characterize the root causes of risks that have been identified and quantified in earlier phases of the risk management process.
  • Evaluate risk interactions and common causes.
  • Identify alternative mitigation strategies, methods, and tools for each major risk.
  • Assess and prioritize mitigation alternatives.
  • Select and commit the resources required for specific risk mitigation alternatives.
  • Communicate planning results to all project participants for implementation.

Although risk mitigation plans may be developed in detail and executed by contractors, the owner’s program and project management should develop standards for a consistent risk mitigation planning process. Owners should have independent, unbiased outside experts review the project’s risk mitigation plans before final approval. This should be done prior to completing the project design or allocating funds for construction. Risk mitigation planning should continue beyond the end of the project by capturing data and lessons learned that can benefit future projects.


Risk Mitigation Strategies

Several risk mitigation strategies can be used to assess risks, as demonstrated in the image below.


Risk Mitigation Strategies
source: Workiva


  • Accept: Make a deliberate decision to accept the risk and not develop further plans to control it.
  • Monitor: Review the risk universe for any changes that may influence the impact of the risk.
  • Avoid: Change the risk processes and requirements to eliminate or reduce the risk.
  • Control: Develop further risk mitigation plans to minimize the impact and/or likelihood of the risk.
  • Transfer: Reassign responsibility for the risk to another department or organizational stakeholder for acceptance.


Risk Mitigation Approach[4]

Risk mitigation strategies must match the degree of control within the enterprise. Where the enterprise has significant control, the strategy should call for prevention measures; where there is limited control, mitigation, and resiliency are the keys to reducing risk.


Risk Mitigation Approach
source: JAS Global Advisors


See Also


References


Further Reading