Risk management system implementation requires a deep and documented process analysis, concerning the whole organization: it must increasingly involve all activities while distinguishing among the core and cross-cutting ones, down to detailed operational activities. Process mapping should allow an organization to carry out ‘risk identification’ (see Ch. 3), describing objectives, staff, activities, responsibilities, organizational units, outputs, deadlines, sequencing and linkages/interactions among the sub-processes and related documented procedures.
Consequently, ‘risk analysis’ (see Ch. 3), is effective when including identification of all key processes containing potential exposure to some consequence. It should involve process analysis, directing special attention to key cross-organizational dependencies and significant control nodes, for example: where data originate, where they are stored, how they are converted to useful information and who uses such information.
The process mapping activity entails a number of steps:
To ensure process maps accurately reflect what actually happens, organizations may combine different methods (see appendix), so an organization should choose the kind of ‘Process Modelling and Mapping’ suitable for its specific goals. The map can be a simple macro-flowchart, showing only enough information to understand the general process flow, or it might be detailed enough to show every single action and decision point.
What follows is a description of different mappings.
The process owner should be in charge of process mapping, while process analysis should be made by other roles (either within or without the organization), in order not to be influenced by one’s own working method.
Lastly, references to the maps, procedural information, and the maps themselves need to be stored in a consistent structure called a process library. Responsibility for the process library needs to be clear, just like any process itself needs an owner.
Q1. In your organization, are identified risks a result of a previous process mapping? R. “A proxy, i.e. a list of the activities that appear in the planning and control information system, has been utilized”. Source: Italy, Survey on risk management practices Q2. Process mapping in your Organization has involved: R1. “For all business areas (pure statistical or support), integrating the IT specific (sub)processes, a list of generic activities was defined (starting with early 2000s), linking objectives, processes, organizational units, accountabilities, deadlines and outputs. In principle, for each process with underlying activities, an operational (for vertical processes) and a system (for transversal processes) procedure should be described and documented, according to a standard template”. Source: Romania, In-depth survey on risk management practices R2. “The business process model of Statistics Austria was implemented in 2000 and covers 32 statistical core processes and approx. 35 cross-cutting processes. For all these processes detailed descriptions of operational activities are provided and regularly used”. Source: Austria, In-depth survey on risk management practices Q3. The risk management training program involves: R. “A set of statistical quality training modules has just been developed that supports process mapping and the application of the various statistical controls into business areas” Source: Australia, In-depth survey on risk management practices |