### 统计代写|决策与风险作业代写decision and risk代考|International Standard ISO 31,000

International Organization for Standardization (ISO) is a non-governmental, international, and independent association that develops international standards designed to ensure the quality, safety, and efficiency of activities, operations or organizational processes. These developed standards are published, and organizations can implement them if they meet the criteria set out in the standard (ISO – The International Organization for Standardization 2009).

When we talk about risk management, we approach ISO 31,000 , Risk management-Guidelines, provides principles, a framework, and a process for managing risk. This standard can be implemented by any organization, regardless of location, size or field of activity. This standard contributes to the achievement of organizational objectives and helps to identify opportunities and reduce the severity of the consequences. Provides directions for internal or external audit. If an organization wants to apply the directions of this standard, it can be ensured that it has an internationalreference point with which to compare its situation. This reference provides consistent principles for developing sound and consistent strategies. The whole approach is sustainable and can contribute to increasing organizational competitiveness (ISO – The International Organization for Standardization 2009). The benefits of adopting ISO 31,000 are presented in Table 1.2.

## 统计代写|决策与风险作业代写decision and risk代考|Risk Management Process

Risk management is an organized process for identifying what may be wrong, quantifying and assessing the associated risks, implementing measures related to actions to prevent or treat each identified risk (Van Der Walt 2003; Wohl and Harvey 2005; Eaton 2015). Risk Management is the process that plans, identifies, evaluates, controls, and communicates aspects related to potential risks in order to minimize the negative impact it can have on the organization. These stages can be structured as follows:
(1) Risk Planning – it is the stage in which each organization plans its activity for the risk management process. Before risks can be identified, assessed, and addressed, a plan or strategy must be developed. Planning is part of the basic risk management process, including: (1) developing and documenting an organized, comprehensive, and interactive risk management strategy; (2) determining the methods to be used in the risk management strategy; (3) planning adequate resources. Risk planning is iterative and includes the scheduling of assessment, management, and monitoring activities and processes. The result of this action is called the risk management plan.
(2) Risk Identification-it is the stage in which the risks that could affect the achievement of organizational objectives, the fulfillment of the mission, and the achievement of the vision are determined. At the same time, a correct identification of risks can contribute to the realization of investments and of the activities and organizational processes. Within this stage a number of methods can be used, for example: Delphi method, brainstorming, documentation reviews, interviews, SWOT analysis (Strengths, Weakness, Opportunities and Threats), historical evaluation of the organization, and use of checklist analysis and others.
(3) Risk Assessment-it is in this stage are analyzed and evaluates the risks associated with a hazard or a source of danger. Qualitative risk analysis is the process of conducting a qualitative assessment of the risks identified within the enterprise. This stage sets a risk priority, depending on their potential effect on the company’s objectives. Within this method, a series of methods can be used, for example, what-if analysis, fault tree analysis, failure mode event analysis, hazard operability analysis, Bow-Tie incident, event-tree, and others.
(4) Risk Controlling-it is the stage in which a series of risk control methods are applied. There are a number of possibilities for risk control, such as avoidance, loss prevention, loss reduction, separation, isolation, du-plication, or diversification. Associated with these control methods are the attitudes of managers that are corroborated with temperament, biological component, and attitude toward risks.
(5) Risk Communication-it is the stage in which the communication between the parties involved in risk management is carried out in order to increase the level of information and to better understand the risks and to apply the most efficient management methods.

## 统计代写|决策与风险作业代写decision and risk代考|Organizational Methods

The purpose of risk assessment is to assess and describe the risks associated with an organizational decision-making problem. As presented in the previous chapter, risk assessment can be performed qualitatively and quantitatively. Qualitative methods use qualitative terms of appreciation, being a non-numerical method. Quantitative methods use numbers to express the level of risk. In continuation, Table $1.3$, a selection of quantitative and qualitative methods that can be used is presented (Aloini et al. 2012; Theoharidou et al. 2012; Rausand 2013; Lefèvre et al. 2014; Abd Rashid and Yusoff 2015; Rivero et al. 2015; SheikAllavudeen and Sankar 2015; Chander and Cavatorta 2017).

## 统计代写|决策与风险作业代写decision and risk代考|Risk Management Process

(1) 风险规划——这是每个组织为风险管理过程规划其活动的阶段。在识别、评估和解决风险之前，必须制定计划或策略。规划是基本风险管理过程的一部分，包括： (1) 制定和记录有组织、全面和互动的风险管理战略；(2) 确定在风险管理策略中使用的方法；(3)规划充足的资源。风险规划是迭代的，包括评估、管理和监控活动和过程的调度。这一行动的结果称为风险管理计划。
(2)风险识别——确定可能影响组织目标的实现、使命的完成和愿景的实现的风险的阶段。同时，正确识别风险有助于实现投资以及活动和组织流程。在此阶段可以使用多种方法，例如：德尔菲法、头脑风暴法、文档审查、访谈、SWOT 分析（优势、劣势、机会和威胁）、组织的历史评估以及使用清单分析等。
(3) 风险评估——在这个阶段分析和评估与危险或危险源相关的风险。定性风险分析是对企业内识别的风险进行定性评估的过程。此阶段根据风险对公司目标的潜在影响设置风险优先级。在该方法中，可以使用一系列方法，例如假设分析、故障树分析、故障模式事件分析、危害可操作性分析、Bow-Tie 事件、事件树等。
(4)风险控制——应用一系列风险控制方法的阶段。风险控制有多种可能性，例如规避、防损、减损、分离、隔离、重复或多样化。与这些控制方法相关的是管理人员的态度，这些态度与气质、生物成分和对风险的态度有关。
(5) 风险沟通——风险管理各方之间进行沟通的阶段，以提高信息水平，更好地了解风险，并应用最有效的管理方法。

