1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:03,570
we will discuss Risk Management Strategies.

3
00:00:03,570 --> 00:00:05,970
Once risks are identified and assessed,

4
00:00:05,970 --> 00:00:07,470
the next step is to decide

5
00:00:07,470 --> 00:00:10,200
how to treat or manage these risks.

6
00:00:10,200 --> 00:00:12,090
There are four primary risk management strategies,

7
00:00:12,090 --> 00:00:15,960
which are transfer, accept, avoid, and mitigate.

8
00:00:15,960 --> 00:00:18,090
First, we have risk transference,

9
00:00:18,090 --> 00:00:20,280
also known as risk sharing.

10
00:00:20,280 --> 00:00:22,800
Transferring a risk involves shifting the risk

11
00:00:22,800 --> 00:00:24,810
from the organization to another party.

12
00:00:24,810 --> 00:00:26,640
This is typically done through insurance

13
00:00:26,640 --> 00:00:28,470
or contract clauses.

14
00:00:28,470 --> 00:00:31,050
By far, insurance is the most common method

15
00:00:31,050 --> 00:00:32,460
of risk transference.

16
00:00:32,460 --> 00:00:34,050
When you purchase an insurance policy,

17
00:00:34,050 --> 00:00:36,150
you're transferring the risk of a potential loss

18
00:00:36,150 --> 00:00:38,460
to the insurance company in exchange for a fee

19
00:00:38,460 --> 00:00:39,870
known as the premium.

20
00:00:39,870 --> 00:00:41,580
For example, if you own a business

21
00:00:41,580 --> 00:00:43,650
and you purchase liability insurance,

22
00:00:43,650 --> 00:00:45,810
you are transferring the risk of financial loss

23
00:00:45,810 --> 00:00:48,090
due to a lawsuit to the insurance company.

24
00:00:48,090 --> 00:00:49,350
If a lawsuit does occur,

25
00:00:49,350 --> 00:00:51,870
the insurance company will cover the financial loss

26
00:00:51,870 --> 00:00:53,970
up to the limit specified in the policy.

27
00:00:53,970 --> 00:00:56,310
Another common method of risk transfer

28
00:00:56,310 --> 00:00:59,010
is to use a contract indemnity clause.

29
00:00:59,010 --> 00:01:00,570
Contract indemnity clauses

30
00:01:00,570 --> 00:01:02,940
are another method of risk transference.

31
00:01:02,940 --> 00:01:05,580
An indemnity clause is a contractual agreement

32
00:01:05,580 --> 00:01:08,400
in which one party agrees to compensate the other

33
00:01:08,400 --> 00:01:10,950
for any harm, liability, or loss

34
00:01:10,950 --> 00:01:13,200
that arises out of the contract.

35
00:01:13,200 --> 00:01:15,450
For example, in the construction contract,

36
00:01:15,450 --> 00:01:18,750
the contract might agree to identify the property owner

37
00:01:18,750 --> 00:01:20,250
for any damages that occurred

38
00:01:20,250 --> 00:01:21,660
during the construction process.

39
00:01:21,660 --> 00:01:23,790
This means that if any damage does occur,

40
00:01:23,790 --> 00:01:26,070
the contractor rather than a property owner

41
00:01:26,070 --> 00:01:28,620
will be responsible for the financial loss.

42
00:01:28,620 --> 00:01:31,440
In both cases, the goal of risk transference

43
00:01:31,440 --> 00:01:34,140
is to shift the financial burden of a potential loss

44
00:01:34,140 --> 00:01:35,970
from one party to another.

45
00:01:35,970 --> 00:01:37,770
This can provide a sense of security

46
00:01:37,770 --> 00:01:39,900
and help to mitigate the potential impact

47
00:01:39,900 --> 00:01:41,490
of unforeseen events.

48
00:01:41,490 --> 00:01:43,110
However, it's important to note

49
00:01:43,110 --> 00:01:46,440
that risk transference does not eliminate the risk entirely,

50
00:01:46,440 --> 00:01:48,360
it simply shifts the responsibility

51
00:01:48,360 --> 00:01:51,210
for dealing with the financial consequences of the risk.

52
00:01:51,210 --> 00:01:53,400
While the material risk may shift,

53
00:01:53,400 --> 00:01:56,850
risk to the original party's reputation still remains.

54
00:01:56,850 --> 00:01:59,130
Second, we have risk acceptance.

55
00:01:59,130 --> 00:02:01,140
Accepting a risk means acknowledging the risk

56
00:02:01,140 --> 00:02:03,960
and deciding to deal with it if and when it occurs.

57
00:02:03,960 --> 00:02:05,520
This strategy is often used

58
00:02:05,520 --> 00:02:07,170
when the cost of managing the risk

59
00:02:07,170 --> 00:02:08,699
outweighs the potential loss

60
00:02:08,699 --> 00:02:12,480
or when the risk unlikely to have a significant impact.

61
00:02:12,480 --> 00:02:15,030
Risk acceptance is a risk management strategy

62
00:02:15,030 --> 00:02:16,440
where a business or individual

63
00:02:16,440 --> 00:02:18,690
acknowledges that a certain risk exists

64
00:02:18,690 --> 00:02:19,860
and decides to accept it

65
00:02:19,860 --> 00:02:22,170
without taking any measures to mitigate it.

66
00:02:22,170 --> 00:02:24,300
This strategy is often used again

67
00:02:24,300 --> 00:02:25,650
when the cost of preventing the risk

68
00:02:25,650 --> 00:02:27,510
is greater than the potential loss

69
00:02:27,510 --> 00:02:30,900
or when the potential gain outweighs the potential laws.

70
00:02:30,900 --> 00:02:33,000
One method of conducting risk acceptance

71
00:02:33,000 --> 00:02:34,650
is through exemption.

72
00:02:34,650 --> 00:02:37,470
An exemption is a provision that excludes a party

73
00:02:37,470 --> 00:02:39,870
from a particular rule or requirement.

74
00:02:39,870 --> 00:02:41,130
This means that the party

75
00:02:41,130 --> 00:02:43,230
is not subject to the rule or requirement,

76
00:02:43,230 --> 00:02:44,730
and therefore does not bear the risk

77
00:02:44,730 --> 00:02:46,503
associated non-compliant.

78
00:02:47,370 --> 00:02:50,730
For example, in the context of financial regulation,

79
00:02:50,730 --> 00:02:52,710
certain small businesses might be exempt

80
00:02:52,710 --> 00:02:54,660
from certain reporting requirements.

81
00:02:54,660 --> 00:02:56,190
This means that these businesses

82
00:02:56,190 --> 00:02:57,930
accept the risk of operating

83
00:02:57,930 --> 00:02:59,670
without the protection offered

84
00:02:59,670 --> 00:03:01,080
by these reporting requirements,

85
00:03:01,080 --> 00:03:02,250
but they also are free

86
00:03:02,250 --> 00:03:05,010
from the administrative burden of compliance.

87
00:03:05,010 --> 00:03:07,140
Another method of conducting risk acceptance

88
00:03:07,140 --> 00:03:08,850
is through exception.

89
00:03:08,850 --> 00:03:11,520
An exception is a provision that allows a party

90
00:03:11,520 --> 00:03:14,010
to avoid a particular rule or requirement

91
00:03:14,010 --> 00:03:16,140
under specific circumstances.

92
00:03:16,140 --> 00:03:17,130
This means that the party

93
00:03:17,130 --> 00:03:19,350
is generally subject to the rule or requirement,

94
00:03:19,350 --> 00:03:20,910
but under certain conditions

95
00:03:20,910 --> 00:03:22,830
they can avoid the associated risk.

96
00:03:22,830 --> 00:03:23,790
Another example,

97
00:03:23,790 --> 00:03:26,130
in the context of data protection regulation,

98
00:03:26,130 --> 00:03:28,110
there might be exceptions that allow businesses

99
00:03:28,110 --> 00:03:29,430
to process personal data

100
00:03:29,430 --> 00:03:32,010
without consent under specific circumstances.

101
00:03:32,010 --> 00:03:33,360
This means that these businesses

102
00:03:33,360 --> 00:03:35,610
accept the general risk of non-compliance

103
00:03:35,610 --> 00:03:37,230
with data protection regulations,

104
00:03:37,230 --> 00:03:40,380
but they can avoid the risk under specific conditions.

105
00:03:40,380 --> 00:03:42,690
In both cases, the party is accepting

106
00:03:42,690 --> 00:03:43,920
a certain level of risk,

107
00:03:43,920 --> 00:03:45,900
either by operating outside of the protections

108
00:03:45,900 --> 00:03:48,180
offered by a particular rule or requirement

109
00:03:48,180 --> 00:03:49,620
in the case of exemption,

110
00:03:49,620 --> 00:03:51,660
or by operating under conditions

111
00:03:51,660 --> 00:03:52,920
that allow them to avoid the risk

112
00:03:52,920 --> 00:03:55,140
in the case of an exception.

113
00:03:55,140 --> 00:03:57,300
Third, we have risk avoidance.

114
00:03:57,300 --> 00:04:00,240
Avoiding a risk involves changing plans or strategies

115
00:04:00,240 --> 00:04:02,310
to eliminate the risk entirely.

116
00:04:02,310 --> 00:04:03,960
This is often the chosen strategy

117
00:04:03,960 --> 00:04:06,780
when the risk is too great to accept or transfer.

118
00:04:06,780 --> 00:04:08,910
For example, a company might avoid the risk

119
00:04:08,910 --> 00:04:11,160
of a lawsuit by deciding not to launch a product

120
00:04:11,160 --> 00:04:14,310
that could potentially infringe on another company's patent.

121
00:04:14,310 --> 00:04:16,620
Alternatively, a company might avoid the risk

122
00:04:16,620 --> 00:04:19,050
of operating in a political unstable country

123
00:04:19,050 --> 00:04:21,690
by choosing to operate in a different market.

124
00:04:21,690 --> 00:04:24,270
And fourth, we have risk mitigation.

125
00:04:24,270 --> 00:04:26,730
Mitigating a risk involves taking steps

126
00:04:26,730 --> 00:04:29,820
to reduce the likelihood or impact of that risk.

127
00:04:29,820 --> 00:04:32,010
This is the most common risk management strategy.

128
00:04:32,010 --> 00:04:34,560
It can involve a wide range of activities.

129
00:04:34,560 --> 00:04:36,630
For instance, a manufacturing company

130
00:04:36,630 --> 00:04:39,390
might mitigate the risk of workplace accidents

131
00:04:39,390 --> 00:04:42,780
by implementing rigorous safety training for all employees.

132
00:04:42,780 --> 00:04:45,660
A tech company might mitigate the risk of data breaches

133
00:04:45,660 --> 00:04:48,780
by investing in robust cybersecurity measures.

134
00:04:48,780 --> 00:04:51,930
So, remember, risk transference is a strategy

135
00:04:51,930 --> 00:04:53,310
that involves shifting the risk

136
00:04:53,310 --> 00:04:55,620
of lost from one party to another,

137
00:04:55,620 --> 00:04:59,250
such as through insurance or contract indemnity clauses.

138
00:04:59,250 --> 00:05:01,650
Risk acceptance is a strategy where businesses

139
00:05:01,650 --> 00:05:03,540
or individuals acknowledge their risk

140
00:05:03,540 --> 00:05:04,590
and decides to accept it

141
00:05:04,590 --> 00:05:07,170
without taking any measures to mitigate it.

142
00:05:07,170 --> 00:05:10,200
Risk avoidance is a strategy that involves taking actions

143
00:05:10,200 --> 00:05:11,940
to completely avoid the risk.

144
00:05:11,940 --> 00:05:14,040
This could mean not engaging in certain activities

145
00:05:14,040 --> 00:05:17,160
or operations that could potentially lead to the risk.

146
00:05:17,160 --> 00:05:19,170
Risk mitigation involves taking steps

147
00:05:19,170 --> 00:05:22,470
to reduce the potential impact or likelihood of a risk,

148
00:05:22,470 --> 00:05:24,750
and this could involve implementing controls,

149
00:05:24,750 --> 00:05:26,790
safety measures, or other actions

150
00:05:26,790 --> 00:05:29,640
that would lessen the impact of the risk should it occur.

