Video summary

Proses Manajemen Risiko

Main summary

Key takeaways

Business

Summary of Risk Management Process (ISO 31000 + Ministry Governance)

Core idea

The video explains that organizations must use a systematic, ongoing risk management process so that organizational goals remain achievable. This makes risk management more than administrative compliance—it becomes a measurable work system integrated into governance.


Risk management as an end-to-end playbook (3 interrelated process blocks)

  1. Operational topics
    • Context determination
    • Risk identification
    • Risk analysis
  2. Risk treatment/handling
  3. Risk governance activities
    • Communication & consultation
    • Monitoring & review
    • Recording & reporting

Frameworks / methods explicitly mentioned

  • ISO 31000-based process (including “provisions applicable within the Ministry of ATR/BPN”)
  • Risk classification
    • Operational risk: failures in business processes/systems/individual safety-related factors
    • Strategic risk: failures at the policy/strategy level (e.g., unclear strategy, inaccurate data, inability to support strategic targets)
  • 5W + 1H for context setting: What, When, Where, Who, Why, How
  • Risk concepts used to guide decisions
    • Risk appetite: how much risk the organization is willing to take
    • Risk tolerance: the maximum level of risk still acceptable
    • Risk capacity: the maximum risk the organization can bear (beyond this creates “serious impacts”)
  • JOP / “JU” method for structured risk identification (Networks/Outcomes/People/Goods)
    • Networks: infrastructure + communication systems
    • Outcomes: results/value vs standards
    • People: competence/roles of officers and stakeholders
    • Goods: assets/equipment/facilities quality
  • Risk matrix / risk map
    • Classifies risks by probability and impact (from very low to very high)
  • Risk profiles
    • A holistic view of strategic-impact risks across multiple categories

Step-by-step process (operational details)

1) Determine scope, context, and criteria

  • Use 5W + 1H to define:
    • activity boundaries, time period, location, responsible parties, rationale, and mechanism
  • Include internal and external context that can influence goal achievement
  • Define risk criteria in the organization’s risk policy

2) Identify risks

  • Identification should not be limited by a fixed number; the goal is to find as many relevant risks as possible.
  • Each risk should be described by:
    • risk event
    • causes
    • indicators of emergence
    • possible consequences/impacts
  • Identification flow:
    1. Understand activity context (goals, indicators, targets)
    2. Map business processes/stages to reach targets
    3. Select the most crucial processes for target achievement
    4. Identify inherent risks within those processes
  • Use JOP method (Networks/Outcomes/People/Goods) to link aspects → possible risk events.

Concrete example (case-like illustration): Land office mapping targets

  • Target: map a number of land plots via measurement & mapping in a given year.
  • JOP application:
    • Networks: condition of supporting infrastructure/systems
    • Outcomes: whether results meet established standards
    • People: competence of officers
    • Goods: condition of equipment
  • These are linked to events that can hinder target achievement.

3) Analyze risks

  • Risk analysis determines magnitude using:
    • probability of occurrence
    • impact if it occurs
  • Use valid data and appropriate methods, such as:
    • benchmarking
    • loss event databases
    • organizational information system data
    • expert assessments
  • Distinguish:
    • Inherent risk (risk before controls)
    • Residual risk (remaining risk after controls)

Illustrative example (umbrella scenario)

Inherent risk: going to office in rain without an umbrella → clothes get wet. With controls (umbrella/raincoat): impact is reduced but not eliminated → risk management aims for tolerable levels, not total elimination.

  • Output format:
    • risk rating for inherent vs residual
    • presented as risk map/matrix

4) Evaluate risks (prioritization)

  • Compare analysis results to pre-set risk criteria
  • Determine whether additional action is required and prioritize risks
  • Use a risk matrix (probability × impact) to classify acceptability

Strategic risk profile categories mentioned

  • policy risk, operational risk, partnership risk, reputation risk, legal risk, human resource risk (used to set strategic-risk priorities)

Risk treatment options (what to do)

Risk treatment must satisfy three selection principles:

  1. Optimally reduce risk level
  2. Realistic/implementable with available resources
  3. Compliant with norms/regulations/standards

Also consider:

  • stakeholder interests
  • long-term impacts

Treatment options

  • Accept: for very low risk with no significant impact
  • Reduce: mitigation measures (e.g., policy formulation, outreach, stronger supervision)
  • Share/transfer: insurance or delegation
  • Avoid: don’t perform risk-causing activities (especially when risks are very large and threaten continuity)

Decision guidance by risk level

  • Very low / low → accept without major mitigation
  • Moderate to high → reduce and/or transfer
  • Include:
    • capacity and organizational development stage
    • cost–benefit analysis of actions

Monitoring, review, recording, reporting (governance mechanics)

Monitoring & review

  • Ensures risk management stays effective and improves continuously
  • Checks:
    • risks correctly identified
    • new risks emerging
    • mitigation effectiveness
  • Suggested cadence: routine, e.g., monthly or based on organizational needs

Monitoring table (operational tool)

  • Periodic recording (typically monthly or quarterly)
  • For each mitigation activity:
    • implemented/not implemented
    • evidence of implementation
    • accountable responsible party Purpose: mitigation plans are actually executed and auditable.

Recording & reporting

  • Occurs periodically:
    • target setting/registration at beginning of year
    • monthly monitoring
    • quarterly reporting
    • annual evaluation
  • Reporting should cover the full risk management process, backed by adequate data
  • Formats can be:
    • concise for management
    • detailed for operational teams

Communication & consultation

  • Communication: one-way (reports/info dissemination)
  • Consultation: two-way (meetings/discussions to obtain input)
  • Purpose:
    • integrate perspectives
    • ensure adequate information availability
    • increase stakeholder involvement Outcome: risk management runs more integrated and effective.

Key metrics / KPIs mentioned

No business KPIs (e.g., revenue, CAC, LTV, churn) are stated. However, the process uses risk measurement outputs:

  • Probability and impact scores (for risk matrix)
  • Risk ratings: inherent risk vs residual risk
  • Cadence-based discipline metrics implied via:
    • monthly monitoring
    • quarterly reporting
    • annual evaluation
  • Completeness/traceability implied via monitoring tables:
    • evidence of mitigation implementation

Presenter / sources

  • No individual presenter is named in the subtitles.
  • Standards / governing sources referenced:
    • ISO 31000
    • Ministry of ATR/BPN (mentioned as having applicable provisions)

Original video