Genesis Management Services Pty Ltd
CUSTOMER TYPES
Business
Government
Property
Education
RISK & OPPORTUNITY ANALYSIS WORKSHEETThe business risk and opportunity analysis process relates to the 3 components of business processes
INPUT >>>>>> ACTIVITY >>>>>>>>> OUTPUT
Note: Output relates to objectives.
3 STEPS
Step 1 – Issue Identification
“Possible Issue” column
“Possible Consequences” column - Are there adverse consequences in the event of failure?
Step 2 – Issue Evaluation
“Measurement” column - Are the consequences significant and likely to occur? Source the root causes of risk associated with the activity
What are the root causes that can result in failure? | |
What is the relative importance and likelihood of these
causes? “Possible Response”
column. List “right” response and “wrong” response
|
1. EXTERNAL ENVIRONMENT
1.1 Stakeholder Analysis: eg Relationships with/to stakeholders of the business or proposed project.
R=Risk
O=Opportunity
No
Possible Issue
Possible Consequences
Measurement
Possible Response (right & wrong)
1.2 Sensitivity Analysis:
eg. The volatility of environment to change, recent occurrences and trends
impacting the stability of the environment etc.
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
1.3 Capital Availability Risk: eg. Availability of funds for the business or project, effect of short-term loans.
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
1.4 Political Risk: eg. The stability of the government, impact of whole of government initiatives, etc.
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
1.5 Legal & Regulatory Risk: eg. The likelihood of new legislation or regulations that could impair the business etc.
R=Risk O=Opportunity |
No. |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
1.6 Industry Risk: eg. The volatility of the specific market, the level of competition, its phase of development (emerging, growth, mature), etc.
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
1.7 Market Risk: eg. Trend of business in general, is it in an upward or downward cycle, what are the likely impacts on business or project, etc.
R=Risk O=Opportunity |
No. |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2. PROCESS
In each area listed below ensure that the business process is clearly defined, aligned with business or project strategy, performing effectively and efficiently and not exposing significant assets to unacceptable losses, risk taking, misappropriation or misuse.
2.1 Operational Risk :
2.1.1 Customer Satisfaction
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.1.2 People quality
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.1.3 Product / Service Development
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.1.4 Capacity
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.1.5 Performance Gap
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.1.6 Sourcing of Resources
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.1.7 Compliance
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
2.1.8 Business Interruption (eg. Fire, flood, labour etc.)
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.1.9 Product / Service Failure
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.1.10 Health and Safety
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
2.2 Empowerment Risk
2.2.1 Leadership
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.2.2 Authority
R=Risk O=Opportunity |
No. |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.2.3 Monetary limits
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
2.2.4 Performance incentives
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
2.2.5 Communications
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.3 Integrity Risk
2.3.1 Management fraud
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.3.2 Employee fraud
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
2.3.3 lllegal Acts
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2..3.4 Unauthorised use
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
2.3.5 Reputational
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
2.4 Financial Risk
2.4.1 Interest Rate
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.4.2 Liquidity
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.4.3 Credit
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2.5 Information and Data Integrity Risk
eg. The integrity of the systems to store information and data, the adequacy of the processes to support them, the experience of the people accessing them, etc.
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
2.6 Information and Data Security Risk
eg. The nature of the communications network, the ability to restrict access to authorised people only, etc.
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
3. INFORMATION TECHNOLOGY
3.1 Applications Systems Risk
eg. the integrity of specific programs, the adequacy of processes to maintain them, the experience of the people that manage them, etc.
Ensure that the information technologies used in the business are operating as intended or are not compromising the integrity and reliability of information and other assets.
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
4. INFORMATION INTEGRITY
Ensure that information used to support important business decisions is not incomplete, out-of-date, inaccurate, or irrelevant to the decision.
4.1 Operational Risk
4.1.1 Pricing
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.1.2 Contract commitment
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.1.3 Measurement
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.1.4 Alignment with Business Strategy
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.1.5 Completeness and Accuracy
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
4.1.6 Regulatory Reporting
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
4.2 Financial Risk
4.2.1 Effective Budgeting and Planning
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.2.2 Completeness and
Accuracy
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
4.2.3 Financial Reporting
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.2.4 Regulatory Reporting
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
4.2.5 Investment Evaluation
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
4.3 Strategic Risk
4.3.1 Business Focus
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.3.2 Valuation
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.3.3 Performance Measurement
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.3.4 Organisational Structures
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.3.5 Resource Allocations
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4.3.6 Planning Process
R=Risk O=Opportunity |
No |
Possible Issue |
Possible Consequences |
Measurement |
Possible Response |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|