Operational Risk Management Guide
Total Page:16
File Type:pdf, Size:1020Kb
OPERATIONAL RISK MANAGEMENT GUIDE U.S. DEPARTMENT OF AGRICULTURE FOREST SERVICE 2020 Last Updated 02/26/2020 RISK MANAGEMENT COUNCIL IN COOPERATION WITH THE OFFICE OF SAFETY & OCCUPATIONAL HEALTH and THE NATIONAL AVIATION SAFETY COUNCIL Contents Contents ....................................................................................................................................................................................... 2 Executive Summary .................................................................................................................................................................. i Introduction ............................................................................................................................................................................... 1 What is Operational Risk Management? ................................................................................................................... 1 The Terminology of ORM ................................................................................................................................................ 1 Principles of ORM Application ........................................................................................................................................... 6 The Five-Step ORM Process ................................................................................................................................................ 7 Step 1: Identify Hazards ................................................................................................................................................... 7 Step 2: Assess Hazards ..................................................................................................................................................... 8 Risk Assessment Matrix .............................................................................................................................................. 8 Risk Assessment Tool ................................................................................................................................................. 13 Step 3: Make Risk Decisions ......................................................................................................................................... 15 Identifying Risk Management Strategies ........................................................................................................... 15 Evaluate Risk vs. Gain ................................................................................................................................................ 16 Risk Decision Authority Chart ................................................................................................................................ 17 Step 4: Implement Controls .......................................................................................................................................... 17 Step 5: Supervise ............................................................................................................................................................... 20 Communicate, Evaluate, Validate ............................................................................................................................... 20 ORM Process Examples ....................................................................................................................................................... 21 References ................................................................................................................................................................................ 23 Appendix 1: Risk Assessment Worksheet ................................................................................................................ 244 Appendix 2: Risk Assessment Matrix ............................................................................................................................ 24 Appendix 3: Risk Assessment Codes ............................................................................................................................. 27 Appendix 4: Risk Assessment Tool ................................................................................................................................ 29 Appendix 4: Risk Decision Authority Chart ................................................................................................................ 29 Executive Summary To accomplish the mission of the U.S. Department of Agriculture Forest Service, we expose employees, volunteers, and contractors to a wide variety of environments ranging from secure office settings to extremes of weather, terrain, fires, and floods. All these workplace situations have hazards that present some degree of risk of harm to employees. Fortunately, most of the risk our employees face is manageable through deliberate, collaborative, and thoughtful risk management. This guide exists to help managers and employees identify and communicate value and objectives, identify risks, evaluate how to mitigate them to the lowest practicable level, and then decide if the value or attempting to achieve the objectives is worth accepting the residual risks. The Operational Risk Management (ORM) process can be used to assist agency leaders, supervisors, and employees with identifying and mitigating risk associated with the work we perform. This guide provides a format for employees to conduct a thorough discussion of the various levels where ORM can be applied, illustrates uses of the tools, and contains reproducible forms in the Appendix. Essentially, all Forest Service actions seek to meet multiple objectives, not just safety-related objectives. This guide is written to be inclusive of managing the risks associated with meeting any objective, especially the objective of no harm to employees. The ORM process and the newly developed risk assessment worksheet, when signed by a line officer or other approved authority, can replace the Job Hazard Analysis (JHA) form. i | Page Send comments to Branch Chief Risk Management [email protected] ii | Page Introduction The U.S. Department of Agriculture Forest Service is embracing development of an Operational Risk Management (ORM) process to better plan for and address the inherent risks that our employees face. Adoption and implementation of ORM will allow the Forest Service to enhance employee capacity to identify, evaluate, and mitigate risks across the full spectrum of work activities and improve the ability to make risk informed decisions and ultimately accomplish objectives as safely and efficiently as possible. The ORM Guide has been developed to describe and clarify an ORM process to be used in project, incident, and work activity decision making. (This guide will use the term “project” to represent all incidents, projects, or work activities from here on out.) The intent of this guide is to: • Clearly define four principles that guide a five-step ORM process. • Describe how to apply ORM in all Forest Service activities. • Provide a sound foundation for creating a greater understanding of the importance of ORM through education, training, and application. • Guide the incorporation of ORM into the full spectrum of Forest Service project/incident/work activities. What is Operational Risk Management? ORM is a continuous, systematic process of identifying and controlling hazards to increase the certainty of outcomes. This process includes detecting hazards, assessing risks, implementing controls, and monitoring risk controls to support effective risk-based decision making. “Risk management is essentially decision making under uncertainty” (Thompson et al, 2016). ORM involves identifying, assessing, decision making, implementing controls, and supervising. Furthermore, ORM seeks to harness feedback and input from all organizational levels to make the most informed decisions possible while reducing unintended outcomes. ORM has a specific goal: Enhance employee’s ability to anticipate hazards and reduce the potential for loss, thereby increasing the probability of a successful outcome. The Terminology of ORM A clear understanding of ORM terminology is a prerequisite to effective communication of risk, decisions, and controls. Risk: Risk is “the effect of uncertainty on objectives” as defined by the International Organization for Standardization (ISO 31000). It is typically expressed as an estimate of the probability and severity of consequence of uncertain future events. In situations where outcomes and consequences are known, calculations of risk are possible. For example, the probability of the dealer winning a single hand of blackjack is approximately 51%. The consequence is the win or the loss. 1 | Page This ORM guide is designed for use where absolute calculations are not possible, such as the risks of working in the wildland environment. Here the odds of various outcomes are estimated based on experience and the context of the situation, using tools discussed later in the guide. Risk is characterized by different types. These are: • Identified risk: Risk that has been determined to exist. Simply stated, identified risk is the risk that we recognize as existing that could reduce the likelihood of achieving our objective. • Unidentified risk: Risk that has not been identified but has some effect on the likelihood of achieving our objective. Some risk is not identifiable or measurable but is no less important. • Total risk: Total risk