Risk Management
Risk Management involves the recognition of risks, and the development of strategies to manage them. These strategies can include risk avoidance, risk reduction, risk retention (accepting some or all of the consequences of a particular risk) or risk transfer.
Ongoing Risk Management – a part of day to day operations
Traditional approaches to risk management make it very difficult, if not impossible, to truly manage risks on an ongoing basis. Many organisations resort to manually intensive and costly approaches - maintaining Risk Registers or multiple Risk Manuals (Health & Safety and Environmental Risk Manuals being two examples).
To manage risks in a proactive and ongoing manner – the risk impact would need to be assessed for every single process change.
- Has the process change affected one of our risk mitigation strategies?
- Which risks are affected?
- Which processes are affected if a risk response changes?
- Should risk managers be notified?
The Integrated Risk Management Solution
The Promapp Risk module stores all recognised risks – then these are linked to their relevant controls within the Process Module. If a control is changed, the Risk Register is updated, and automatic notifications are sent to the appropriate Risk Manager, who can assess the risk management response.
Separate manuals (Health and Safety, Environmental...) are no longer required
Processes from multiple risk manuals can be incorporated into the Promapp Process Module - which has been designed for ease of use as part of day to day operations. Health and Safety, Environmental Risks become risk portfolios in the Risk Module – linking to the specific controls in business processes in the Process Module.
Timely, costly compliance audits significantly reduced
The good news for risk managers is that risk controls are now fully dynamic. Risk Registers are automatically updated off our business process changes – so they are not only permanently up to date, but:
- Changes are notified to the risk manager, for ongoing risk management assessments
- Change log descriptions, date and author are logged in the Audit Report
- Comments from risk assessments are logged against each control
|