Risk management is the continuous process of:
Risk identification – finding what can go wrong.
Risk assessment – evaluating severity, likelihood and detectability.
Risk control – introducing mitigating measures to reduce the risk.
It is applied to reduce the possibility of suffering loss, such as financial losses, production stoppages, quality failures, accidents or reputational damage.
2. What does risk management have to do with Supply Chain Management?
Supply chains face risks from suppliers, transport, production and external events. Risk management helps companies prepare for and reduce these disruptions.
3. What are the challenges in setting up effective risk management?
Complexity and limited visibility: Companies often do not know their complete supply network, especially indirect suppliers.
Knowledge requirements: Risk identification needs experts from different functions and detailed knowledge of the company and its supply chain.
Subjective assessment: Severity, likelihood and detection scores are based partly on human judgement.
Unknown unknowns: Some disruptions cannot be predicted, quantified or included in a traditional risk assessment.
Efficiency–resilience trade-off: Measures such as additional inventory, suppliers and capacity increase protection but also increase costs.
Continuous coordination: Risks change over time, so identification, assessment and control must be repeated continuously across supply-chain partners.
What basic problem creates supply chain risk?
Part 1: Why Supply Chain Risk Matters
The basic problem is a loss of control.
Companies cannot completely control all suppliers, transport routes, countries, technologies and external events.
Why do increasing global trade and longer supply chains create more risk?
Longer supply chains contain more companies, intermediaries, countries and transport steps.
This makes the supply chain more complex and harder to monitor.
What does the Suez Canal obstruction demonstrate?
One disruption at an important transport point can affect hundreds of ships, many industries and several countries at the same time.
Why are supply chains better described as networks than as chains?
Companies are connected through many suppliers, customers, transport routes and production locations. One company or location may support several value streams at the same time.
Why can one incident affect several value streams?
Different products may depend on the same supplier, factory, port, transport route or energy source. A failure at this shared point can stop several flows together.
Why do offshoring and outsourcing increase risk exposure?
They make the supply chain geographically more diverse.
The company becomes exposed to more countries, laws, political conditions, transport routes and external events.
1. Why can lean manufacturing and just-in-time increase vulnerability?
2.What can happen when a just-in-time supply is interrupted?
They reduce inventory levels.
When a disruption occurs, there may not be enough raw materials or parts to continue production.
Production lines may shut down because the company has only a small amount of inventory available.
Are lean manufacturing and just-in-time are always bad?
No.
They reduce costs and waste, but they also reduce safety buffers.
Companies must balance efficiency and risk.
What are the six types of risks (3/6)
strategic risks - Markets, competition and sabotage.
financial risks - Currencies, interest rates and stock markets.
regulatory risks - Tax laws, environmental law and employment law.
What are the six types of risks (6/6)
technical risks - New technologies, security and products.
operational risks - Transport, suppliers and quality.
economical risks - Trade restrictions, exchange rates and political boundaries.
What are the three parts of risk management?
Risk Identification - finding possible events, failures or dangers that could negatively affect the company or supply chain.
Risk Assessment - evaluating and quantifying the identified risks.
Risk Control - selecting and implementing measures that reduce the risk.
What knowledge is required for risk identification?
3A: Risk Identification
It requires:
extensive knowledge of the company and its supply chain,
practical experience with possible problems and deviations.
Which three questions support risk identification and assessment?
3A: Risk Assessment
What can happen or go wrong?
How likely is it to happen?
What are the consequences if it happens?
What is Severity, or S?
What is Likelihood, or L?
What is Detection, or D?
3B: Risk Assessment
Severity is an estimate of how serious the effect of a failure will be for the next user or final customer.
Likelihood, also called occurrence, estimates how likely the cause of a failure is to occur.
Detection estimates how effective the controls are at preventing or detecting the failure before it reaches the customer.
What is the Risk Prioritization Number?
The Risk Prioritization Number, or RPN, is a score used to rank risks.
RPN=S×L×D
What does a high RPN mean and What does a low RPN mean?
High RPN: It means the risk requires more attention because it is severe, likely, difficult to detect, or a combination of these factors.
Low RPN: It means the risk is less urgent compared with risks that have a higher RPN.
Which risks normally receive the highest priority?
Risks with high severity, high likelihood and low detectability.
What does risk control mean?
3B: Risk Control
Risk control means identifying and assessing mitigating measures that lower the RPN.
Which three questions are asked during risk control?
What can reduce the likelihood of occurrence?
What can reduce the severity?
What can increase the detectability of the problem?
What is the most important difference between risk management and resilience?
Risk management tries to prevent or reduce shocks.
Resilience prepares the supply chain to function, adapt and learn when prevention fails.
Last changed3 days ago