Video summary
Penyusunan Risk Register
Main summary
Key takeaways
Main ideas & concepts (Risk Register Preparation)
- Risk register as a tool: Not only a document, but a systematic instrument to record, manage, and monitor risks.
- Purpose of the risk register:
- Help organizations understand risks related to achieving targets.
- Determine appropriate control measures to support target achievement.
- Enable structured, documented, and accountable risk management by each work unit.
- Focus of the material: How to compose an organization’s operational risk register according to applicable regulations/formats.
What the risk register must contain (key structural requirements)
- Prepared based on the format specified in applicable regulations.
- Key parts mentioned:
- Seat risk register (as labeled in subtitles)
- Monitoring table
- Title section
- Filling columns:
- Must be completed according to provisions (with an exception noted: when a risk is accepted).
- Validation & authority:
- Must be validated by the relevant unit leader.
- Must be determined by the risk owner.
- Emphasized: the risk register is an official document with an important governance role.
Detailed methodology / step-by-step workflow for compiling the risk register
-
Set targets
- Targets are filled based on activity performance indicators or program performance indicators in the performance agreement.
- Each work unit must fill in identity completely:
- Code and name of work unit
- Performance indicators and targets
- Clear goals form the basis for identifying relevant risks.
-
Identify risks
- Determine the business processes used to achieve targets.
- Each business process may contain multiple risks.
- Risks are defined as events that have not yet occurred, and must be tied to:
- business objectives
- business processes
- Risk identification is performed through stages:
- (1) Understand the context of the goals
- (2) Identify business processes supporting the goals
- (3) Choose the most crucial processes
- (4) Identify the inherent risks in those processes
- Example method for identifying risks: job method
- Uses four aspects:
- Networks
- Outcomes
- People
- Goods
- Each aspect is linked to an event to describe the risk more clearly.
- Example given: field measurement and mapping
- Analyze aspects such as personnel, equipment, and field conditions
- Link each aspect to events that could hinder target achievement
- Uses four aspects:
-
Group risks into categories
- Categories are defined in regulations (examples listed):
- Fraud risk
- Legal risk
- Strategic risk
- Governance risk
- Reputation risk
- Information/data risk
- Other categories also mentioned:
- Property and archive risks
- Technology risks
- Partnership risks
- Operational and compliance risks
- State financial risks
- Human resource risks
- Policy risks
- Goal: facilitate analysis and more targeted risk management.
- Categories are defined in regulations (examples listed):
-
Determine risk causes and sources
- Risk causes: factors/conditions that trigger the risk.
- Risk sources: can come from internal and external organizations.
- Guidance: focus on the most significant root causes (not just visible symptoms).
- Method mentioned: 5Y method
- Used to dig into causes gradually until finding the real root problem.
-
Determine risk impacts
- Must be the most significant impact, directly related to the target/goal.
- Impacts should be classified by impact area, such as:
- Financial
- Reputational
- Performance
- Organizational services
- Impact assessment must be:
- measurable
- based on established criteria
- Impact criteria examples mentioned:
- Financial, reputational, legal
- Occupational safety
- Organizational performance
- Impact criteria can differ by organizational level (e.g., ministerial vs operational unit) to keep assessment contextual.
-
Assign risk owner and related units
- Each risk must have a clear owner:
- described as the unit leader responsible for managing the risk.
- Also identify related units linked to the risk.
- Rationale: ensures clear responsibility.
- Each risk must have a clear owner:
-
Assess existing controls
- Controls may include:
- policies
- procedures
- monitoring mechanisms
- Assess:
- whether controls are adequate
- the extent of implementation in practice
- This assessment supports determining next risk management steps.
- Controls may include:
-
Assess risk probability (likelihood)
- Probability = how often/how likely the risk is to occur.
- Must be based on valid data, such as:
- historical data
- discussion results
- expert assessments
- Output: understanding of the organization’s risk exposure level.
-
Assess risk impact and apply impact criteria (more detail)
- A slide/table is described for legal sanctions (including):
- criminal
- civil
- administrative sanctions
- It maps indicators for different organizational levels, including:
- Ministerial and Echelon 1
- Echelon 2 and Land Office (as labeled)
- Thresholds differ by level:
- higher/lower financial loss thresholds
- different criteria for positions subject to sanctions
- Occupational safety impacts mentioned:
- from minor injuries to death
- Service disruption considered:
- affects public service quality
- A slide/table is described for legal sanctions (including):
-
Use the risk analysis matrix
- Map risk positions based on:
- likelihood (probability)
- impact level
- Use it to determine grouping into:
- areas of risk acceptance
- areas requiring mitigation
- Visualization helps make decisions easier and more focused.
- Map risk positions based on:
-
Determine risk behavior / response based on risk level
- Low/very low risks: generally accepted without mitigation.
- Moderate to very high risks: require actions to reduce the risk level.
- Must consider:
- risk appetite
- organizational priorities
-
Establish risk treatment and mitigation plans
- Risk treatment options:
- accepting
- reducing
- sharing
- avoiding
- Mitigation plans must be concrete activities that reduce:
- probability
- and/or impact
- Four types of risk treatment described:
- Accept if impact is not significant
- Reduce via mitigation measures
- Share via mechanisms like insurance or collaboration
- Avoid (noted as rare in government organization context)
- Treatment choice must match the conditions and risk level.
- Risk treatment options:
-
Set risk targets after mitigation
- Targets reflect the expected condition after mitigation actions.
- Must be realistic:
- not simply “reduce to low level” without basis
- Targets become reference points for future monitoring and evaluation.
-
Create and use a monitoring table
- Monitoring table contains:
- planned mitigation activities scheduled in a period
- recording whether activities are completed as planned at a certain time
- Also record:
- realization status of mitigation implementation
- proof of implementation
- responsible party
- Purpose: ensure risk management is implemented, not merely planned.
- Monitoring table contains:
-
Maintain the risk register as an ongoing (“living”) process
- Prepared continuously, not one-time.
- Example cycle described:
- set targets at the beginning of the year
- routine monitoring monthly
- periodic evaluation and reporting
- The risk register must be continuously updated to match organizational conditions.
Speakers / sources featured
- No specific named speakers are identified in the subtitles.
- Sources referenced (by type, not by author):
- Applicable regulations specifying the risk register format and risk categories
- Performance agreements (as the basis for targets)
- Risk register-related tables/criteria (ministerial/echelon level mappings, legal sanctions, occupational safety criteria)