202
14 Risk Assessment for the Twenty-First Century
Incidentally, we are not keen on conducting risks assessments workshops in the
way this is commonly done: unprepared people, no system definition (Chap. 8),
no success/failure criteria definition (Sect. 7.7), etc. We always propose to perform
preliminary definition and knowledge gathering actions and then enhance efficiency
by leading small groups or even one-on-one meetings and interviews.
The ICMM position statement also remarked that performance criteria should be
“… established for risk controls and their associated monitoring, internal reporting
and verification activities” (ICMM website). ICMM further suggests that “Critical
control management has been identified as an approach to managing low probability,
high impact events such as catastrophic failures of tailings storage facilities”. The
identification of those issues that will require the highest level of attention is a
necessary outcome of any risk assessment, and it cannot be the result of gut-feeling
exercises.
Regarding risk management framework, leading practice would require that a
company, working within the framework of ISO 31000, establish a corporate risk
management standard that would include statements regarding the qualifications
of audit assessment teams and require the identification of critical risks and their
controls.
14.2 Manageable-Unmanageable and Strategic Risk
Definition
Management is generally hard pressed to provide quick answers to questions about
different aspects of the risks, such as which risks are:
• tolerable;
• intolerable but manageable, thus mitigation occurs by reducing the probability of
failure;
• intolerable and unmanageable and hence require strategic shifts (altering the system).
These are obviously very different questions than the classic engineering questions: what FoS do we choose under various loading conditions? and in some cases,
what deformations do we accept in which scenario/stage?
By using any of the explicit tolerance thresholds discussed above (Chap. 13) it is
possible to provide a transparent definition of what constitutes a manageable risk: if
a risk above tolerance (probability, consequence) can be brought under the selected
tolerance threshold, before hitting the credibility limit of, say, 10
−6 , by mitigative
investments and risk transfer that still preserve the economic livelihood of a company,
then that risk is manageable (yellow bubble in Fig. 14.1).
The key element here is a corporate/government choice of what level of mitigative investment preserves the economic livelihood of an entity. If the risk cannot
be brought under the tolerance threshold as described, then it must be considered
unmanageable. Unmanageable risks cannot be mitigated; they require strategic shifts
Précédent

- 213/823

Suivant