Risk Assessment: A Practical Guide to Assessing Operational Risk Chapter 20: Global Perspectives.

Slides:



Advertisements
Similar presentations
Risk Assessment. Objectives By the end of this presentation you will know: What risk assessment is; Where the need for risk assessment comes from; and.
Advertisements

The New Safety Laws – Are you being Harassed? Jamie McPherson Partner MVM Legal.
Control and Accounting Information Systems
PPRT PREVENTION DES RISQUES ET LUTTE CONTRE LES POLLUTIONS Safe Communities & a Sustainable Hazaedous Industry : Present and Future Discussion.
The Australian/New Zealand Standard on Risk Management
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
1 Risk evaluation Risk treatment. 2 Risk Management Process Risk Management Process.
Title slide PIPELINE QRA SEMINAR. PIPELINE RISK ASSESSMENT RISK ACCEPTANCE CRITERION 2.
Title slide PIPELINE QRA SEMINAR. PIPELINE RISK ASSESSMENT INTRODUCTION TO GENERAL RISK MANAGEMENT 2.
WORK HEALTH AND SAFETY ACT IMPLICATIONS FOR SMALL BUSINESS
Promoting Excellence in Family Medicine Enabling Patients to Access Electronic Health Records Guidance for Health Professionals.
Codex Guidelines for the Application of HACCP
OH&S Management System
Tom Cecich, CSP, CIH NC Chapter ASSE March 12, 2015.
Basics of OHSAS Occupational Health & Safety Management System
SMS Operation.  Internal safety (SMS) audits are used to ensure that the structure of an SMS is sound.  It is also a formal process to ensure continuous.
What is it? Why it is so important?
IAEA International Atomic Energy Agency Overview of legal framework Regional Workshop - School for Drafting Regulations 3-14 November 2014 Abdelmadjid.
Work Health and Safety (National Uniform Legislation) Act and Regulations NT WorkSafe Anna McGill.
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
© 2011 Underwriters Laboratories Inc. All rights reserved. This document may not be reproduced or distributed without authorization. ASSET Safety Management.
Essentials of Machine Safety Standards in Perspective.
Integrated Risk Management Charles Yoe, PhD Institute for Water Resources 2009.
Hazards Identification and Risk Assessment
Advanced Project Management Project Risk Management Ghazala Amin.
Risk Management Approaches to Hydrogen Safety. Risk Assessment, Limbo Dancing, and ALARP Les Shirvill.
Railway Safety Commission An Coimisiún Sábháilteachta Iarnróid The Management of Third Party Generated Risk in Ireland International Railway Safety Conference.
Jacques Vanier ICAO EUR/NAT Regional Officer Almaty, 5 to 9 September 2005 SAFETY MANAGEMENT SYSTEMS RISK VERSUS SAFETY.
Harmonization Project FAS Meeting Harmonization project and ISSAI 200 Purpose and scope of the project The purpose is to provide a conceptual basis.
Integrated Risk Management Charles Yoe, PhD Institute for Water Resources 2009.
Responsible Care® Health & Safety Task Force – 06 H&S.
Risk Estimation Two distinct categories of Risies Voluntary Risks e.g. driving or riding in an automobile, and working in an industrial facility. Involuntary.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
ISSAI 400 Compliance Audit Subcommittee
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Company LOGO. Company LOGO PE, PMP, PgMP, PME, MCT, PRINCE2 Practitioner.
Be Prepared For Change Are you Prepared?. Be Prepared For Change Are you Prepared?
The NIST Special Publications for Security Management By: Waylon Coulter.
OHSAS Occupational health and safety management system.
Principles of risk assessment Risk assessment training course Module 1 Principles of risk assessment.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
AUDIT QUALITY AND ASSURANCE 2 ND AND 3 RD OCTOBER 2014 HILTON HOTEL MATERIALITY IN PLANNING AND PERFORMING THE AUDIT (ISA 320) 1.
Organizations of all types and sizes face a range of risks that can affect the achievement of their objectives. Organization's activities Strategic initiatives.
Risk Assessment: A Practical Guide to Assessing Operational Risk
#327 – Legal and Regulatory Risk: Silent and Possibly Deadly Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
Risk Assessment: A Practical Guide to Assessing Operational Risk
AUDIT STAFF TRAINING WORKSHOP 13 TH – 14 TH NOVEMBER 2014, HILTON HOTEL NAIROBI AUDIT PLANNING 1.
Risk Assessment: A Practical Guide to Assessing Operational Risk

OH&S Management System
UNDERSTANDING ISO 9001:2008.
An Overview on Risk Management
Project Quality Management
Risk Assessment OSHA 21/09/ WHAT IS RISK ASSESMENT? Risk Assessment is the process of determining the possibility of short and long term unfavorable.
Jamie McPherson Partner – MVM Legal
MODELOS DE GESTIÓN DE CALIDAD
Nuclear and Treaty Law Section Office of Legal Affairs
Assurance, Related Services and Internal Auditing
COSO and ERM Committee of Sponsoring Organizations (COSO) is an organization dedicated to providing thought leadership and guidance on internal control,
Nuclear and Treaty Law Section Office of Legal Affairs
OH&S Management System
Risk management - HIRAC awareness presentation
Air Carrier Continuing Analysis and Surveillance System (CASS)
HSE Case: Risk Based Approach.
INTRODUCTION TO Compliance audit METHODOLGY and CAM
BSBWHS304 Participate effectively in WHS communication and consultation processes.
QRA Guideline - update Marcello Oliverio February 6, 2018
Communication and Consultation with Interested Parties by the RB
RISK ASSESSMENT AND METHOD STATEMENT
H A C C P HAZARD ANALYSIS CRITICAL CONTROL POINTS 1 December 2018
Presentation transcript:

Risk Assessment: A Practical Guide to Assessing Operational Risk Chapter 20: Global Perspectives

Risk Assessments: Global Perspectives Objectives Using ISO for Maturity Assurance and Conformity Global Uptake of ISO International Risk Management Standard Global Comparison of Risk Tolerability Criteria Tolerability Criteria for Planning New Industries / Locations Investment to Prevent a Fatality Shifting the Paradigm from Absolute Safety to Risk Management – ALARP & Reasonably Practicable Changing Traditional Language to Risk Based Language for more Effective Safety Risk Conversations

Introduction In these days of business globalization, professional safety, health & environmental (SH&E) practitioners often need to be aware of what are the international practices and standards around the world. Global organizations need assurance of the uniformity, consistency and harmonization of their risk management standards, policies and processes, in general, and their SH&E standards in particular.

Introduction ISO 31000:2009 was nationally adopted in the United States as an American National Standard, ANSI/ASSE Z , Risk Management Principles and Guidelines, and is identical to the ISO standard. The International Risk Management (RM) Standard consists of: 1.Principles, a Framework and a structured Process for effective RM shown in Figure Consistent defined RM vocabulary and language 3.A set of performance criteria 4.One, common overarching RM process shown in Figure Guidance on how that process should be integrated into the decision- making processes of any organization

Using ISO for Maturity Assurance and Conformity ISO 31000:2009 is being applied world-wide and now allows an organization of any size and business activity to assess the maturity and adequacy of its risk management system RMS. Many organizations currently have at least informal risk management practices and processes which include a number of fundamental components of an RMS as detailed in ISO 31000/ANSI Z690.2, ANSI Z , ANSI Z Prevention through Design, and even the Occupational Safety and Health Administration’s (OSHA) Process Safety Management standard, (briefly described in Chapter 6 - What if Analysis). However, the means of gaining confidence and assurance that those practices and processes are adequate, mature and effective are often lacking.

Using ISO for Maturity Assurance and Conformity Many organizations have made the extra step to integrate their risk management systems for consistency in handling all risk domains. ISO becomes the over-arching envelope that provides uniform management processes for all types of risks.

Using ISO for Maturity Assurance and Conformity A process called a Conformity Assessment consists of tools constructed and used to review, assess, and even audit how well the organization conforms and complies with the standard and hence provides a measure of maturity and adequacy of the organization’s own system. A practical conformity assessment tool [Whiting 2012] consists of 3 sets of comprehensive evidence-seeking questions designed for each detailed “should” expectation of the standard in its Principles, Framework, and Process. It can be used internally or externally as a first or second or even third party audit tool. It can be tailored to any activity and risk domain. According the answers to these questions an overall rating of Maturity Level 1  5 can be determined as in Figure 20.4.

Global Uptake of ISO International Risk Management Standard

Global Comparison of Risk Tolerance Criteria A critical stage in the RM Process is Evaluation. At that stage in the process, the risk manager needs to evaluate the sizes of the risks calculated or estimated in the preceding Analysis stage by comparing them with pre-determined criteria developed in the initial Establish Context and Scope stages. The criteria of most importance are the prior agreed risk acceptability levels and whether the risk level is being continually managed down So Far As Is Reasonably Practicable (SOFAIRP).

Global Comparison of Risk Tolerance Criteria Risks to people can be represented in two ways. Both are a combination of the likelihood of an event happening (e.g. an accident at a major hazard installation), and the possible consequences - in terms of harm to people: Individual Risk Societal Risk

Global Comparison of Risk Tolerance Criteria 1. Individual risk is the likelihood or probability or chance that a particular individual at a particular location under specific exposure circumstances will be harmed. It is usually described in numerical terms such as “a 1 in 20,000,000 chance of being killed by lightning per annum (p.a.)”.

Global Comparison of Risk Tolerance Criteria 2. Societal risk is a way to estimate the chances of numbers of people being harmed from an incident. The likelihood of the primary event (an accident at a major hazard plant) is still a factor, but the consequences are assessed in terms of level of harm and numbers affected, to provide an idea of the scale of an accident in terms of numbers killed or harmed.

Tolerability Criterion for Individual Risk In the UK and the Netherlands, many decades ago, public safety risk criteria for new industrial hazardous activities have been set by government regulation. The starting point for determining these criteria was the statement ‘that any additional risk from exposure to a new hazardous activity to a member of the public should not be significant when compared with risk in everyday life.’

Tolerability Criteria for Planning New Operations The foundation for choosing quantitative risk tolerability criteria is the principles: 1)that the exposed persons such as nearby residents, should not be involuntarily subject to a risk from a new exposure that is significant compared to the ‘background’ risk associated with existing hazards. 2)that individual and societal risk should be considered separately.

Tolerability Criteria for Planning New Operations Fatality Risk Criteria for Land Use Planning and Locations of New Exposures

Investment to Prevent a Fatality An interesting global perspective in Risk Management is how different countries use measures related to human life values when calculating cost-benefit analysis (CBA) for deciding to commit to spending on proposed new or changed risk controls for a particular risk, e.g. should all school buses be fitted with seat belts? The standard approach to CBA of risks to life is to convert them into equivalent costs. The monetary valuation of risks to life is often described as a “value of life”.

Shifting the Paradigm from Absolute Safety to Risk Management Internationally, more and more countries have shifted, and are shifting their safety philosophies and practices from unrealistic absolute safety or even zero risk beliefs to more appropriate models of managing risk to as low as reasonably practicable (ALARP). Safety regulators in many countries have been traditionally prescriptive in describing absolute obligations to detail how safety risks were to be eliminated or prevented or stopped. In recent decades, legal and regulatory safety obligations are being described in ALARP/performance based frameworks rather than prescriptive, unconditional ensure without risk models. National and International safety standards are now more and more written in terms of ALARP or the equivalent.

What is reasonably practicable? A risk-informed performance based regulatory approach to safety laws defines reasonably practicable, in relation to a duty to ensure health and safety, as meaning that what was reasonably able to be done in relation to ensuring health and safety

What is reasonably practicable? Weighing all relevant matters including: (a) the likelihood of the hazard or the risk occurring; and (b) the degree of harm that might result; and (c) what the person concerned knows, or ought reasonably to know, about— (i) the hazard/risk; and (ii) ways of eliminating/minimizing the risk; and (d) the availability/suitability of ways to eliminate/minimize the risk; and (e) after assessing the extent of the risk and the available ways of eliminating or minimizing the risk, the cost associated including whether the cost is grossly disproportionate to the risk.

Societal or Group Risk Tolerability Framework In terms of Societal or Group Risk, ALARP principles are described in Figure with a common expression of the “intolerable” frequency of Incidents involving more than 1,000 fatalities per incident (e.g. Bhopal or 2 X 500 passenger planes colliding in mid-air).

Moving Towards Risk Based Language for more Effective Risk Conversations The transition from compliance-based safety to risk-based safety in large part has occurred in many parts of the world, and is beginning to take place in the United States. This requires risk-centric organizations and progressive risk professionals to use better terminology and language for risk based conversations. For example, outdated terms such as loss control and loss prevention are now being replaced with safety risk management and risk control.

Conclusion Risk Management is fundamentally about how to make risk-informed decisions when life and business circumstances are uncertain. Risk Management is not about more risk taking, rather better risk understanding of the exposures we are currently not managing as well as we need to, or could. Safety is managing risk to ALARP, not zero risk. The risk makers and the risk takers need to be the risk managers.