Video summary

Penyusunan Risk Register

Main summary

Key takeaways

Educational

Main ideas & concepts (Risk Register Preparation)

  • Risk register as a tool: Not only a document, but a systematic instrument to record, manage, and monitor risks.
  • Purpose of the risk register:
    • Help organizations understand risks related to achieving targets.
    • Determine appropriate control measures to support target achievement.
    • Enable structured, documented, and accountable risk management by each work unit.
  • Focus of the material: How to compose an organization’s operational risk register according to applicable regulations/formats.

What the risk register must contain (key structural requirements)

  • Prepared based on the format specified in applicable regulations.
  • Key parts mentioned:
    • Seat risk register (as labeled in subtitles)
    • Monitoring table
    • Title section
  • Filling columns:
    • Must be completed according to provisions (with an exception noted: when a risk is accepted).
  • Validation & authority:
    • Must be validated by the relevant unit leader.
    • Must be determined by the risk owner.
  • Emphasized: the risk register is an official document with an important governance role.

Detailed methodology / step-by-step workflow for compiling the risk register

  1. Set targets

    • Targets are filled based on activity performance indicators or program performance indicators in the performance agreement.
    • Each work unit must fill in identity completely:
      • Code and name of work unit
      • Performance indicators and targets
    • Clear goals form the basis for identifying relevant risks.
  2. Identify risks

    • Determine the business processes used to achieve targets.
    • Each business process may contain multiple risks.
    • Risks are defined as events that have not yet occurred, and must be tied to:
      • business objectives
      • business processes
    • Risk identification is performed through stages:
      • (1) Understand the context of the goals
      • (2) Identify business processes supporting the goals
      • (3) Choose the most crucial processes
      • (4) Identify the inherent risks in those processes
    • Example method for identifying risks: job method
      • Uses four aspects:
        • Networks
        • Outcomes
        • People
        • Goods
      • Each aspect is linked to an event to describe the risk more clearly.
      • Example given: field measurement and mapping
        • Analyze aspects such as personnel, equipment, and field conditions
        • Link each aspect to events that could hinder target achievement
  3. Group risks into categories

    • Categories are defined in regulations (examples listed):
      • Fraud risk
      • Legal risk
      • Strategic risk
      • Governance risk
      • Reputation risk
      • Information/data risk
    • Other categories also mentioned:
      • Property and archive risks
      • Technology risks
      • Partnership risks
      • Operational and compliance risks
      • State financial risks
      • Human resource risks
      • Policy risks
    • Goal: facilitate analysis and more targeted risk management.
  4. Determine risk causes and sources

    • Risk causes: factors/conditions that trigger the risk.
    • Risk sources: can come from internal and external organizations.
    • Guidance: focus on the most significant root causes (not just visible symptoms).
    • Method mentioned: 5Y method
      • Used to dig into causes gradually until finding the real root problem.
  5. Determine risk impacts

    • Must be the most significant impact, directly related to the target/goal.
    • Impacts should be classified by impact area, such as:
      • Financial
      • Reputational
      • Performance
      • Organizational services
    • Impact assessment must be:
      • measurable
      • based on established criteria
    • Impact criteria examples mentioned:
      • Financial, reputational, legal
      • Occupational safety
      • Organizational performance
    • Impact criteria can differ by organizational level (e.g., ministerial vs operational unit) to keep assessment contextual.
  6. Assign risk owner and related units

    • Each risk must have a clear owner:
      • described as the unit leader responsible for managing the risk.
    • Also identify related units linked to the risk.
    • Rationale: ensures clear responsibility.
  7. Assess existing controls

    • Controls may include:
      • policies
      • procedures
      • monitoring mechanisms
    • Assess:
      • whether controls are adequate
      • the extent of implementation in practice
    • This assessment supports determining next risk management steps.
  8. Assess risk probability (likelihood)

    • Probability = how often/how likely the risk is to occur.
    • Must be based on valid data, such as:
      • historical data
      • discussion results
      • expert assessments
    • Output: understanding of the organization’s risk exposure level.
  9. Assess risk impact and apply impact criteria (more detail)

    • A slide/table is described for legal sanctions (including):
      • criminal
      • civil
      • administrative sanctions
    • It maps indicators for different organizational levels, including:
      • Ministerial and Echelon 1
      • Echelon 2 and Land Office (as labeled)
    • Thresholds differ by level:
      • higher/lower financial loss thresholds
      • different criteria for positions subject to sanctions
    • Occupational safety impacts mentioned:
      • from minor injuries to death
    • Service disruption considered:
      • affects public service quality
  10. Use the risk analysis matrix

    • Map risk positions based on:
      • likelihood (probability)
      • impact level
    • Use it to determine grouping into:
      • areas of risk acceptance
      • areas requiring mitigation
    • Visualization helps make decisions easier and more focused.
  11. Determine risk behavior / response based on risk level

    • Low/very low risks: generally accepted without mitigation.
    • Moderate to very high risks: require actions to reduce the risk level.
    • Must consider:
      • risk appetite
      • organizational priorities
  12. Establish risk treatment and mitigation plans

    • Risk treatment options:
      • accepting
      • reducing
      • sharing
      • avoiding
    • Mitigation plans must be concrete activities that reduce:
      • probability
      • and/or impact
    • Four types of risk treatment described:
      1. Accept if impact is not significant
      2. Reduce via mitigation measures
      3. Share via mechanisms like insurance or collaboration
      4. Avoid (noted as rare in government organization context)
    • Treatment choice must match the conditions and risk level.
  13. Set risk targets after mitigation

    • Targets reflect the expected condition after mitigation actions.
    • Must be realistic:
      • not simply “reduce to low level” without basis
    • Targets become reference points for future monitoring and evaluation.
  14. Create and use a monitoring table

    • Monitoring table contains:
      • planned mitigation activities scheduled in a period
      • recording whether activities are completed as planned at a certain time
    • Also record:
      • realization status of mitigation implementation
      • proof of implementation
      • responsible party
    • Purpose: ensure risk management is implemented, not merely planned.
  15. Maintain the risk register as an ongoing (“living”) process

    • Prepared continuously, not one-time.
    • Example cycle described:
      • set targets at the beginning of the year
      • routine monitoring monthly
      • periodic evaluation and reporting
    • The risk register must be continuously updated to match organizational conditions.

Speakers / sources featured

  • No specific named speakers are identified in the subtitles.
  • Sources referenced (by type, not by author):
    • Applicable regulations specifying the risk register format and risk categories
    • Performance agreements (as the basis for targets)
    • Risk register-related tables/criteria (ministerial/echelon level mappings, legal sanctions, occupational safety criteria)

Original video