Video summary
Teori Dasar Manajemen Risiko
Main summary
Key takeaways
Main Ideas and Lessons Conveyed
- Risk management is essential in organizations because uncertainty is unavoidable. Strong organizations are not those that avoid risk entirely—but those that manage risks well.
- The purpose of the material is to build the basic theory of risk management so that programs, policies, and activities can stay on track to achieve targets.
- After learning the material, the audience should be able to:
- Understand how risks arise
- Learn how to identify risks
- Apply risk management systematically (not reactively)
- The lecture frames risk management around four interconnected topics:
- Risk management according to ISO 31000
- The link between organizational structure (goals/vision/mission), risk governance, and business processes
- How to distinguish risks from problems
- How risk management is implemented in the Ministry of ATR BPN (ATR/BPN)
Key Concepts Explained
1) Why Risk Management Matters
- Humans cannot control everything; events can occur beyond human capability.
- Risk management is not meant to eliminate uncertainty, but to manage it:
- Prevent events from occurring when possible
- Mitigate their impact if they happen
- Everyday examples already reflect risk thinking:
- Buying tickets early
- Preparing detailed plans
- Preparing before PTSL activities
- Using an umbrella before rain (“prevention is better than cure”)
2) ISO 31000 Definition and the Components of “Risk”
-
ISO 31000 definition: Risk = the effect of uncertainty on achievement of objectives
-
Risk is always tied to objectives/goals.
- Four elements of risk:
- Incident/event (something that may happen)
- Possibility/likelihood it occurs
- Impact it would cause
- Target/objective it affects
- If an event does not affect the target, then in the organizational context it is not a risk.
Example logic:
- US election announcements are an event, but they become a risk only if they can affect a goal (e.g., timely arrival).
- Demonstrations around the airport are a risk because they combine possibility + direct impact on the target.
3) What “Risk Management” Is (Process/System, Not Random Action)
- Risk management = coordinated activity to direct and control an organization regarding risks.
- Key principles emphasized:
- Coordinated
- Structured and systematic
- Continuous (ongoing, not one-time)
4) Risk Management Benefits (Beyond Protection)
- Provides:
- Protection: shielding organizational objectives from disruptions
- Opportunity/value: enabling innovation and improved strategic decision-making
- Analogy used: driving a car to a destination
- Rearview mirror, seatbelt, speed control, checking brakes/accelerator = risk controls
- Traffic jams/bad weather = risks that can’t be eliminated, but can be anticipated
Methodology / Structured Approach Presented
A) Four-Topic Learning Structure (Lecture Roadmap)
- Understand risk management according to ISO 31000
- Understand:
- Organizational goals (vision/mission → goals → targets)
- Risk governance
- Business processes
- Distinguish between risks vs problems
- Understand implementation in Ministry of ATR BPN
- Transition logic:
- Start with basic concepts
- Move into organizational context
- Differentiate risk vs problem
- Then apply in practice
B) Aligning Risk Management With Objectives (Target Structure)
- Objectives hierarchy described:
- Vision & mission
- → strategic targets
- → program targets
- → activity targets
- Principle emphasized:
- Risk management must follow the same structure:
- Risks at the activity level must align with risks at program/strategic levels
- Risk management must follow the same structure:
- Example given (draft Renstra 2025–2029):
- Vision: quality, fair, legally certain land/spatial planning management
- Derived targets include digital-based land registration
- Each level has its own performance indicators
C) SMART Criteria for Good Targets (to Enable Risk Identification)
A “good target” should meet:
- Specific (clear and directed)
- Measurable (can be measured)
- Attainable (achievable)
- Relevant (aligned with organizational strategy)
- Time bound (has a deadline)
-
Challenging (challenging enough to encourage positive change)
-
Without clear/measurable goals, risks are harder to identify and manage.
Example target:
- Increase certified land plots by 1,000 through digital-based land registration by 2026 (Includes clarity on what is achieved, how much, how, relevance to national strategy, and timing.)
D) Embedding Risk Management Into Business Processes
- Business process definition: A series of interconnected activities producing a specific output.
- Vision/mission → programs/activities → implemented via business processes
- Each stage of a business process has potential risks.
- Emphasis:
- Risk management must be embedded in every stage, not only at the end.
Example: PTSL business process stages and risks
- Planning
- Preparation
- Counseling
- Collection of physical and legal data
- Issuing certificates
- Reporting
Example risks by stage:
- Incomplete data during collection
- Verification errors in legal research
- Delays in issuing certificates
Benefit of full process understanding:
- Identify risks systematically
- Determine appropriate mitigation actions
E) “Three Lines Concept” for Governance and Oversight (Implementation Model)
- First line: operational implementers
- Carry out daily activities
- Manage risks arising from those activities
- Second line: policy director & supervisor
- Ensure risk management is implemented according to standards/guidelines
- Third line: internal supervision (Inspectorate/Internal oversight function)
- Independently verify effectiveness of risk control
Principle:
- Lines should strengthen each other (not “monitor against” each other negatively)
F) Distinguishing Risk, Problem, and Disaster Using Timing/Sequence
- Uncertainty: incomplete information
- When uncertainty affects targets → becomes risk
- If the risk happens → becomes a problem
- If problems are not handled properly → can escalate into a disaster
Therefore:
- Earlier anticipation reduces the chance that risk escalates into crisis.
G) National and Ministry-Level Risk Management Governance Structure
- Based on Presidential Regulation No. 39 of 2023:
- Applies to national development risk management for:
- development programs
- activities
- projects
- priorities
- Includes a governance structure with:
- directors/chairman/deputy chairman and cross-ministerial members
- Meaning:
- Not one unit only; it is part of overall national development governance
- Purpose:
- Enable coordinated identification/management of cross-sector strategic risks
- Applies to national development risk management for:
Within Ministry of ATR BPN (Tiered “Lines” and Roles)
- Starts from:
- Minister/Head as highest risk owner
- Coordinated by Deputy Minister/Deputy Head
- First line (operational risks):
- Echelon 1 work units through land offices
- Second line (policy and monitoring):
- second-line unit(s) design policies and monitor implementation
- Third line (independent oversight):
- Inspectorate General performs independent supervision/quality assurance
Risk management must be formalized:
- Each structure established via unit leader’s decree
- It is not an “extra” activity but an official part of the organization system
Operational Cadence / Periodic Implementation
- January: each work unit prepares:
- performance agreement
- targets
- risk register
- Monthly: meetings to discuss and monitor mitigation action plans
- Quarterly: reports and implementation evaluation
- July–August: independent assessment of SPIP maturity, including measuring risk management maturity
Message: Risk management is ongoing throughout the year, not a one-time administrative task.
Speakers / Sources Featured
- ISO 31000 (referenced as the standard for risk definition and risk management approach)
- Presidential Regulation No. 39 of 2023 (referenced for national development risk management governance)
- Ministry of ATR BPN (ATR/BPN) (described as the institutional implementation context)
- Inspectorate General (mentioned as part of the third line / independent supervision)