GLOBAL ECONOMIC PROSPECT AND THE ROLE OF INSURANCE INDUSTRY IN SUSTAINABLE ECONOMIC AND SOCIAL DEVELOPMENT
First of all, I would like to congratulate the organizer (the Indonesia Life Insurance Association, AAJI) for hosting this very important conference. Thank you very much for inviting me to deliver my brief speech. I am very honored. I am very grateful.
In this session we will discuss two big topics. Firstly, global economic prospect. Secondly, the role of insurance industry. Please allow me to discuss the topics from the point of view of Indonesian context.
In preparing my speech, I read several reports published by prominent institutions like the World Bank, the International Monetary Fund, the Asian Development Bank, as well as private consulting companies like McKinsey, EY, PwC, Deloitte, and others. In general, they report very similar information and message on the prospect of the global economy, especially in the context of Indonesian economy. To summarize the reports, let me use the framework provided by the World Bank.
In this diagram, it is perceived that a country economic performance is shaped by global as well as domestic situations. Two global phenomena, namely the COVID19 pandemic and the war in Ukraine, are significantly influencing the global economy. The WHO has not declared the end of the pandemic yet. But in most countries, including Indonesia, we have seen good signs of the ending of the pandemic. Naturally, this will be followed by an increase in the consumers’ confidence and in turn it will significantly increase the demand for commodities.
On the other hand, China, from which many East Asian countries, including Indonesia, import important commodities, has not been completely recovered from the pandemic. As a result, the countries experience supply shortage in several important commodities at least in the next few months. This situation has been worsened by the war in Ukraine that significantly creates supply disruptions. The prices of food and energy have increased and it will certainly trigger global inflation. Financial authorities of major countries respond the inflation by increasing interest rates. The combination of the phenomena will lead to a slower global economic growth.
Most, if not all, reports on global economic outlook mentioned that Indonesia rightfully responded the global economic situations with prudent economic and financial policies. Thank to these prudent public policies, the reports forecast that the Indonesian economic growth rate will reach 5.1% for this year and the coming year. The figure is even better than the growth rate in pre-pandemic year which was 5.0% in 2019. Therefore, it is safe enough to conclude, that despite the probable global recession in the coming few years, Indonesian economy is forecasted to be able to survive with a moderate growth rate.
Let me now proceed to our second topic which is about the role of insurance industry, again, in the context of Indonesian economy. I am very fortunate that last July I attended an international conference in Lombok in which Mr. Budi Tampubolon (the Chairman of Indonesia Life Insurance Association) delivered his speech on “Market Updates & Current Issues in Indonesia Life Insurance Industry”. What I need to do now is to cite the important points of his speech and add some comments and opinion of mine, based on my own observation.
I would like to use this table as an approach to discuss the role of insurance industry. I divide the topic into two parts, one is the social and economic development aspect and the other is the sustainable development aspect. Each aspect will be discussed in two perspectives, which are the current existing condition and the expectation toward the development of insurance industry.
My main point is that the insurance industry has been very instrumental as a catalyst to economic growth of this country just like the one in advanced developed economies. It provides protection so that households and firms can better manage their risks. This role is increasingly important in the world that is full of volatilities, uncertainties, complexities, and ambiguities. The insurance industry is a vital thread in the fabric of a strong Indonesian economy.
Absolutely, insurance industry creates employment and mobilizes fund for productive investments. However, as the case in many other industries in the financial sector, the relative contribution of insurance industry to the Indonesian economy is small. The penetration rate of life insurance industry is only 1.2% of the Indonesian GDP, whereas the density is only USD 54 per capita. These figures are much less than the figures in neighboring comparable countries like Malaysia, Thailand, India, or Vietnam.
Considering the fact that the Indonesian economy grows steadily, I can predict confidently that the penetration rate and the density of life insurance industry will soon increase significantly, under certain conditions such as the improvement of insurance literacy among Indonesian people and the capability of the industry in creating innovative products.
Recent news about corruption cases in some insurance firms in Indonesia do not help the efforts to increase the contribution of insurance industry to the economy. In my quick observation, several insurance firms still need to improve their governance, risk management, and compliance (GRC) initiatives.
My last point is related with the role of insurance industry in sustainable development. This issue is important and will become increasingly important in the years to come. The Government of Indonesia, including the Ministry of National Development Planning (Bappenas), Ministry of Finance, as well as the Financial Service Authority (OJK) have prepared and issued regulations to pursue the targets of Green Economy initiatives that have been internationally established. On the other hand, in my quick observation, the signs of relevant actions taken by insurance firms have not been widely seen in the media, except those from a very small number of big international players. I would like to stress one point regarding the contribution of the Insurance Industry to sustainable development, that is, the green economy initiative, anywhere in the world, need collaboration among all parties, the government, the private sector, the people or the households within the economy. The government must lead the initiative through creating and enforcing good regulations effectively. The government must be the leader in creating green economy. In other words, it is not rational to assume that private sector alone could autonomously execute efforts to create green economy. I should not talk much about this issue, because we will exclusively discuss this topic in the next session this afternoon.
It is not easy to draw conclusion or implication from my speech. One reason for that is the high diversity of membership of AAJI. Some members are big companies, while the others are medium or small companies. Some members have long experience, while the others have only short history. The corporate cultures and the organizational maturity levels are also very diverse. As a result, the problems they are facing are also very heterogeneous.
To end my presentation, I would like to express my optimism regarding the development of insurance industry in Indonesia. The size of the economy and the steady growth rates of the GDP will sufficiently guarantee the potential rapid development of insurance industry in Indonesia. I wish you all the best. Thank you very much.
_______________________________
Bogor, 8 October 2022
Artikel ini dipaparkan oleh penulis pada acara Insurance Forum 2022 di Bali tanggal 16-18 Oktober 2022.
Prepared for Insurance Forum, hosted by the Indonesia Life Insurance Association in Bali, 17-18 October 2022.
BUMN Indonesia – Penerapan Manajemen Risiko berbasis Peraturan Menteri BUMN No: 5/MBU/09/2022
Merujuk pada Peraturan Menteri BUMN Nomor Per- 5/MBU/09/2022 tentang Manajemen Risiko pada BUMN (PerMen No:5) yang dikeluarkan pada awal September 2022, dan mencermati berbagai komentar, ulasan, analisis, serta harapan yang berpendar, penulis tergerak untuk berbagi pandangan dengan tajuk tulisan di atas.
Dalam era penuh ketidakpastian, BUMN maupun privat diharapkan dapat mengelola risiko mereka sedemikian rupa sehingga dapat secara efektif menangani dampak dari ketidakpastian terhadap pencapaian tujuan dan sasaran organisasi. Dalam hal ini, PerMen No:5 dapat membantu BUMN dalam membangun kepatuhan, kapasitas dan kapabilitas mereka dalam penerapan manajemen risiko organisasi yang sistematis, terstruktur, dan terukur serta tertelusur.
Pertanyaan pertama yang kemudian timbul adalah ‘apakah bila BUMN sudah menerapkan PerMen No:5 tersebut, mereka akan lebih tangguh dan lincah dalam menghadapi ketidakpastian dan risiko yang menyertainya?’ Jawaban bisa ‘Ya’ dan juga bisa ‘Tidak’ tergantung bagaimana BUMN terkait menyikapi pelaksanaan PerMen No:5 ini, dan bagaimana BUMN tersebut mampu mengoptimalkannya.
Menurut hemat penulis yang kebetulan juga adalah ketua komite teknis 03/10 BSN (Badan Standarisasi Nasional) yang mendapat amanah untuk pengembangan standar nasional terkait Governansi, Manajemen Risiko, dan Kepatuhan di BSN yang merupakan representasi Indonesia di Technical Committe ISO dunia (TC 309, dan TC 262), perlu adanya suatu kerendahan hati dan kearifan profesional untuk melihat sejauh apa kesesuaian regulasi dengan dasar dan standar nasional serta internasional sehingga hasil yang diperoleh dapat optimal. Hal ini penting kita cermati, karena dunia persaingan – dan juga daya saing organisasi agar tangguh dan lincah – tidak terbatas dan tidak dapat dibatasi hanya pada regulasi suatu negara semata, tetapi mengarah dan mendasar pada berbagai standarisasi internasional termasuk penerapan manajemen risiko, yaitu ISO 31000 (Standar Manajemen Risiko Internasional) yang identik dengan SNI ISO 31000 (Standar Nasional Indonesia).
Pertanyaan kedua yang kemudian timbul adalah ‘sejauh apa kesesuaian PerMen No:5 dengan ISO 31000 ?’
Untuk ini, kita semua patut memberikan apresiasi karena PerMen No:5 sinkron dan memiliki dasar serta nafas sejalan dengan ISO 31000 yang dikenal dan digunakan di banyak negara dan bahkan telah menjadi standar nasional negara mereka masing-masing. Lebih jauh lagi, PerMen No:5 juga beririsan (https://crmsindonesia.org/publications/analisis-bumn-dan-iso-31000/) dengan SNI 8848 (Manajemen Risiko Sektor Publik) dan juga ISO 37000 (Standar Governansi) serta ISO 37301 (standar Manajemen Kepatuhan). Oleh karena itu, sudah saatnya bagi setiap BUMN untuk menterjemahkan penerapan PerMen No:5 ke tingkat operasionalisasi yang bersandar pada kepatuhan terhadap regulasi, dan sekaligus membangun ketangguhan dan daya saing melalui standarisasi
Beberapa hal di bawah ini dapat dijadikan pertimbangan dalam pembuatan pedoman operasionalisasi PerMen No:5 di tingkat organisasi BUMN itu sendiri:
- Memastikan dalam pedoman manajemen risiko, secara eksplisit dinyatakan bahwa berlandaskan PerMen No:5, praktik terbaik harus konsisten dengan standar nasional/internasional yang dikenal dan diakui oleh Republik Indonesia yaitu SNI ISO 31000 (yang identik dengan standar internasional ISO 31000). Hal ini diperlukan agar dapat mendorong BUMN untuk terus terikutkan dalam proses pengkinian penerapan manajemen risiko mereka seiring dan sejalan dengan kompetisi dan pergaulan dunia yang berbasis pada standarisasi.
- Memastikan terbangunnya kompetensi manajemen risiko di keseluruhan jajaran BUMN, mulai dari dewan governansi mereka yaitu direksi/pengurus dan dewan komisaris/pengawas sampai kepada tingkat pelaksana terdepan organisasi. Dalam hal ini, sebaiknya jangan hanya melalui pelatihan yang bersifat pembangunan pengetahuan (knowledge) saja – tetapi dengan pembangunan kompetensi person yang merupakan bauran terpadu dari pengembangan pengetahuan (knowledge), keterampilan (skills), dan sikap (attitude). Hal ini diperlukan agar penerapan manajemen risiko dapat terus bertumbuh-kembang menjadi budaya sadar dan tanggap risiko yang semakin pro-aktif dan inovatif.
- Memastikan dukungan teknologi dan metodologi serta sistem informasi dan manajemen data yang tepat guna dan efektif, misal kompetensi penggunaan RCSA (Risk – Control – Self Assesement) yang didukung oleh aplikasi berbasis AI (Artificial Intelligence), manajemen data yang berbasis penggunaan teknologi blockchain, ERM Dashboard yang dapat memberikan analisis KRIs (Key Risk Indicators). Hal ini diperlukan agar informasi berbasis data akan semakin tepat waktu dan akurat sehingga pengambilan keputusan dapat dibuat lebih cepat, tanggap, dan menyeluruh.
- Memastikan bahwa maturitas manajemen risiko terus terasah dan ditingkatkan dari waktu ke waktu. Hal ini diperlukan sehingga penerapan manajemen risiko bukan hanya ad-hoc tergantung kepemimpinan saat ini semata, tetapi menjadi tarikan nafas dan kebiasaan sehat seluruh insan organisasi untuk selalu waspada, tangguh, serta lincah. Hanya dengan lebih dewasa dan matang dalam pengelolaan risiko, BUMN dapat bertahan dalam era VUCA (Volatility, Uncertainty, Complexity, and Ambiguity), dan sekaligus mampu menciptakan terobosan-terobosan inovatif dalam menciptakan nilai tambah yang bermanfaat, baik bagi organisasi BUMN itu sendiri maupun masyarakat Indonesia secara berkelanjutan.
Mudah-mudahan tulisan ini bermanfaat.
Dr. Antonius Alijoyo
- Pendiri CRMS Indonesia (Center for Risk Management and Sustainability)
- Ketua Komite Teknis 03/10 BSN: Governansi, Manajemen Risiko, dan Kepatuhan.
PerMen BUMN Nomor: Per-5/MBU/09/2022 tentang Manajemen Risiko pada BUMN
Pada awal September 2022, Kementerian BUMN menerbitkan Peraturan Menteri BUMN Nomor Per- 5/MBU/09/2022 tentang Manajemen Risiko pada BUMN. Karena kebijakan tersebut bersifat umum, organisasi memerlukan penjabaran lebih lanjut pada tataran operasional terutama kebutuhan untuk pembuatan dan/atau penyempurnaan pedoman risiko mereka. Dari sudut pandang penulis, pedoman risiko BUMN sebaiknya juga sejalan dengan standar nasional manajemen risiko SNI ISO 31000 yang identik dengan standar internasional ISO 31000 itu sendiri. Hal ini dipandang baik, karena akan membuat BUMN lebih mudah dalam menjalin protokol manajemen risiko mereka dengan mitra dan pemangku kepentingan internasional yang juga mengadopsi ISO 31000. Pertanyaan yang timbul dan kemudian menjadi bahan pemikirian penulis adalah ‘sejauhmana relevansi SNI ISO 31000:2018 (Standar Nasional Indonesia) dan turunannya untuk Sektor Publik yaitu SNI 8848:2019 dalam mendukung penerapan manajemen risiko pada BUMN sebagai penjabaran dari Peraturan Menteri tersebut’ ?. Lebih lanjut, artikel ini akan membahasnya dalam tiga kelompok besar, yaitu definisi, struktur, dan proses manajemen risiko.
Definisi
Definisi adalah hal esensial karena menentukan arah kebijakan serta implementasi manajemen risiko suatu organisasi. Kementerian BUMN secara eksplisit menempatkan manajemen risiko sebagai bagian tidak terpisahkan dari pengendalian intern dan tata kelola terintegrasi (Pasal 1 Ayat 9). Hal ini sangat relevan dengan prinsip pertama manajemen risiko SNI ISO 31000:2018 dan SNI 8848:2019 yaitu terintegrasi, dimana manajemen risiko bukanlah sistem yang berdiri sendiri, namun harus terintegrasi dengan proses dan tata kelola organisasi secara keseluruhan. Jika tidak terintegrasi, manajemen risiko akan hanya dilihat sebagai tambahan beban tugas administrasi yang tidak memberikan nilai tambah bagi organisasi tersebut. Perspektif bandingan definisi ‘risiko’ disajikan dalam tabel berikut:

Terkait definisi ‘Risiko’ di atas, beberapa hal yang perlu dipertimbangkan dan/atau diatur lebih lanjut dalam pedoman manajemen risiko adalah sebagai berikut:
- Batasan yang lebih jelas antara definisi ‘risiko’ dan ‘masalah’, karena keduanya sama-sama mempengaruhi pencapaian sasaran, namun menurut SNI ISO 31000, masalah sudah terjadi sedangkan risiko belum terjadi;
- Batasan yang lebih jelas mengenai level pencapaian tujuan/sasaran. Jika PerMen BUMN hanya membatasi pada tujuan strategis perusahaan, maka risiko yang relevan akan hanya untuk risiko strategis saja, padahal SNI ISO 31000 memberikan panduan bahwa risiko ada pada setiap level organisasi, mulai dari level strategis sampai level operasional, sejak penetapan sasaran strategis, sasaran program, sampai pada sasaran kegiatan/aktivitas;
- Batasan yang jelas antara tujuan dan sasaran. SNI ISO 31000 menekankan pada pencapaian sasaran karena lebih terukur dan SMART[1]***), sedangkan tujuan organisasi masih abstrak sehingga identifikasi risikonya cenderung tidak spesifik.
Perspektif bandingan definisi ‘manajemen risiko’ disajikan dalam tabel berikut:

Untuk definisi ‘Manajemen Risiko’, beberapa hal perlu dipertimbangkan dan/atau diatur lebih lanjut dalam pedoman manajemen risiko, sebagai berikut:
- Integrasi antara manajemen risiko dengan sistem manajemen lainnya terutama pengendalian intern dan tata kelola. Dalam hal ini, organisasi dapat mengadopsi standar berbasis ISO, antara lain SNI ISO 31000 (Manajemen Risiko), ISO 37000 (Governance), dan ISO 37301 (Compliance Management System);
- Sebelum proses manajemen risiko dijalankan (identifikasi, mengukur, mengendalikan, dan memantau), perlu disepakati terlebih dahulu adanya ‘prinsip manajemen risiko’ yang eksplisit, serta ‘kerangka kerja manajemen risiko’ yang menjadi landasan organisasi secara keseluruhan. Untuk hal ini, SNI ISO 31000 telah menyediakan arsitektur implementasi manajemen risiko yang sudah terdiri dari tiga pilar yaitu prinsip manajemen risiko, kerangka kerja manajemen risiko, dan proses manajemen risiko;
- Sebelum proses manajemen risiko, organisasi perlu memahami konteks internal dan eksternalnya, kemudian menetapkan ruang lingkup risiko yang akan dikelola, termasuk merumuskan kriteria sebelum pengukuran risiko. Untuk hal ini, SNI ISO 31000 sangat sejalan karena langkah pertama dalam proses pengelolaan risiko berbasis SNI ISO 31000 adalah penetapan lingkup, konteks, dan kriteria.
Struktur
Berkaitan dengan struktur manajemen risiko, Peraturan Menteri BUMN telah mengadopsi three lines model dari IIA dan ini merupakan hal yang baik, karena sudah sejalan dengan SNI 8848:2019 bahwa penerapan manajemen risiko dapat mengadopsi model tiga lini, yang terdiri dari lini pertama sebagai pemilik risiko, lini kedua sebagai pemantau, koordinator, dan edukasi risiko, dan lini ketiga sebagai asurans internal yang independen terhadap penerapan manajemen risiko. Perspektif bandingan ‘struktur manajemen risiko’ disajikan dalam tabel berikut:

Terkait ‘Struktur Manajemen Risiko’ di atas, beberapa hal yang perlu dipertimbangkan dan/atau diatur lebih lanjut dalam pedoman manajemen risiko adalah sebagai berikut:
- Kejelasan komite tersebut (komite audit, komite pemantau risiko, komite tata kelola terintegrasi) menjadi bagian dari lini berapa (1, 2 atau 3) dan berada dibawah Direksi atau Dekom karena SNI 8848:2019 memberikan contoh bahwa Komite Manajemen Risiko adalah komite di bawah Direksi dan Komite Pemantau Risiko adalah komite di bawah Dewan Komisaris;
- Kejelasan struktur manajemen risiko di level unit pemilik risiko, misalnya di anak perusahaan, unit bisnis, dan unit mandiri lainnya;
- Kejelasan operasionalisasi direktur yang membidangi keuangan yang dapat merangkap sebagai direktur yang membidangi pengelolaan risiko, karena SNI 8848:2019 memberikan contoh direktur pengelolaan risiko sebaiknya memiliki independensi terbatas terhadap unit pemilik risiko. Ada potensi benturan kepentingan ketika direktur keuangan harus memantau pengelolaan risiko keuangan yang menjadi tugas dan tanggungjawabnya.
Proses
Proses pengelolaan risiko merupakan inti dari manajemen risiko, sehingga penguatannya merupakan suatu keharusan. Perspektif bandingan proses manajemen risiko disajikan dalam tabel berikut:

Merujuk tabel di atas, beberapa hal yang perlu dipertimbangkan dan/atau diatur lebih lanjut dalam pedoman manajemen risiko adalah sebagai berikut:
- Kebijakan manajemen risiko di tingkat operasional sebaiknya tidak hanya membahas struktur manajemen risiko saja, tetapi termasuk di dalamnya prinsip, kerangka kerja, dan proses manajemen risiko, yang dapat mengacu pada SNI ISO 31000:2018;
- Perencanaan, Penerapan, Monitoring dan Evaluasi Manajemen Risiko secara lebih terperinci dapat mengacu pada kerangka kerja manajemen risiko berbasis SNI ISO 31000:2018 yang di dalamnya secara eksplisit memasukkan peran ‘kepemimpinan dan komitmen’ dalam manajemen risiko, serta integrasi manajemen risiko dengan proses bisnis organisasi;
- Siklus proses manajemen risiko dapat mengacu pada SNI ISO31000:2018 yang dimulai dari Komunikasi dan Konsultasi, Penetapan Lingkup, Konteks dan Kriteria Risiko, Penilaian Risiko, Penanganan Risiko, Pemantauan dan Evaluasi, serta Pencatatan dan Pelaporan.
Sebagai penutup, penulis menggaris bawahi pasal 32 PerMen BUMN Nomor Per- 5/MBU/09/2022 yang menyatakan bahwa masih diperlukan pedoman lebih lanjut mengenai pengukuran tingkat kematangan risiko BUMN, tata Kelola terintegrasi, kriteria ukuran kompleksitas BUMN, penempatan BUMN dalam kuadran risiko, kualifikasi organ pengelola risiko, taksonomi risiko, serta mekanisme pelaporan risiko. Untuk kesemua hal tersebut, pemenuhannya dapat didukung oleh SNI ISO 31000:2018 dan SNI 4484:2019.
Mudah-mudahan artikel singkat ini bermanfaat bagi BUMN dalam mengembangkan pedoman manajemen risiko yang berbasis PerMen BUMN Nomor Per-5/MBU/09/2022, dan sekaligus sejalan dengan SNI ISO 31000 (yang identik dengan Standar Internasional ISO 31000) sehingga BUMN Indonesia dapat lebih gesit dan tangguh untuk tidak hanya bersandar pada regulasi pokok nasional, tetapi juga fasih dan tangguh dalam pergaulan/persaingan internasional yang berbasis pada standarisasi.
________________________________
*) Manajemen Risiko – Pedoman
**) Panduan Implementasi SNI ISO 31000:2018 di Sektor Publik
***) “Specific, Measurable, Attainable, Relevant, Timebound”
ARTI PENTING PERATURAN MENTERI BUMN NOMOR PER-5/MBU/09/2022 BAGI PENINGKATAN BUDAYA PERUSAHAAN BUMN
Pada bulan September 2022, Kementerian BUMN menetapkan peraturan mengenai penerapan manajemen risiko pada Badan Usaha Milik Negara Nomor PER-5/MBU/09/2022 yang bertujuan untuk melindungi dan menciptakan nilai bagi BUMN. Apabila dilihat dari isi peraturan BUMN tersebut, aturan ini akan sangat membantu dan memudahkan para praktisi manajemen risiko yang berkarya di BUMN sebagai dasar hukum bagi peningkatan penerapan manajemen risiko yang lebih terstruktur dan sistematis di organisasinya.
Namun, agar tujuan dari diberlakukannya peraturan ini dapat benar-benar melindungi dan menciptakan nilai, BUMN kiranya jangan sampai terjebak pada arti sempit dari diberlakukannya peraturan menteri ini yaitu hanya berfokus pada tujuan pelaporan semata namun sebaiknya dalam melaksanakan aturan ini lebih fokus pada tujuan mengapa peraturan ini dibuat, yaitu melindungi dan menciptakan nilai bagi BUMN. Manajemen risiko dapat melindungi dan menciptakan nilai apabila manajemen risiko bukan dianggap sekedar prosedur dan bentuk pelaporan di atas kertas saja, tetapi sebagai budaya manajemen risiko yang mengakar di tiap insan BUMN. Oleh karena itu, untuk membangun budaya manajemen risiko dengan baik di BUMN, diperlukan peran aktif DIrektur, Komisaris, dan organ pengelola risiko lainnya yang tercantum dalam pasal 12 PER-5/MBU/09/2022.
Selain peran aktif dari pimpinan BUMN, membangun budaya manajemen risiko di suatu organisasi memerlukan komitmen secara berkesinambungan dari pimpinan serta pengalokasian sumber daya yang memadai untuk membangun dan merawat budaya manajemen risiko yang telah terbentuk. Hal ini diperlukan karena dalam teori transformasi organisasi, perilaku individu dalam organisasi hanya baru akan mulai membentuk budaya organisasi yang diharapkan ketika sekitar 5%-25% dari insan organisasi memiliki pemahaman yang sesuai. Untuk itu, bagaimana cara agar insan organisasi memiliki pemahaman yang sesuai terkait manajemen risiko? Dalam salah satu tulisannya, Organization for Economic Cooperation and Development (OECD) menggambarkan pentingnya meningkatkan kompetensi dari insan organisasi yang terdiri dari pengetahuan, keterampilan, dan sikap dalam membentuk perilaku yang akhirnya dapat membentuk budaya organisasi yang diharapkan, dalam konteks ini adalah budaya manajemen risiko.
Di dalam PER-5/MBU/09/2022 pasal 15 ayat 2, hal ini juga telah secara eksplisit disebutkan, dimana Direksi BUMN memiliki wewenang, tugas, dan tanggung jawab untuk mengembangkan budaya manajemen risiko pada seluruh jenjang organisasi (butir c) dan melaksanakan peningkatan kompetensi sumber daya manusia yang terkait dengan manajemen risiko. Hal ini diperkuat juga di pasal 19 PER-5/MBU/09/2022, bahwa direktur yang membidangi pengelolaan risiko memiliki wewenang, tugas, dan tangung jawab untuk melaksanakan penyusunan dan penetapan rencana kerja, rencana pengembangan, dan sumber daya manusia di bidang pengelolaan risiko yang menjadi tanggung jawabnya untuk kepentingan BUMN dalam mencapai maksud dan tujuan perusahaan.
Sebagai kesimpulan, pemberlakuan PER-5/MBU/09/2022 adalah suatu momentum yang sangat berharga untuk dapat meningkatkan efektifitas dan kematangan penerapan manajemen risiko di BUMN. Terkait hal tersebut, peran para praktisi bidang Governansi, Manajemen Risiko, dan Kepatuhan juga menjadi sangat penting untuk memanfaatkan momentum yang terbentuk ini dengan memastikan agar tujuan aturan untuk melindungi dan menciptakan nilai bagi BUMN tetap menjadi fokus utama dalam membangun manajemen risiko terintegrasi, dengan Bersama-sama membudayakan pentingnya manajemen risiko dalam upaya melindungi dan menciptakan nilai, karena dengan hal itulah maka penerapan peraturan ini baru dapat benar-benar bermanfaat bagi BUMN dan kesejahteraan bangsa.
–**–
Artikel ini juga terbit pada website ICoPI
Permen BUMN No. PER-5/MBU/09/2022: Langkah Strategis Kementerian BUMN Menuju Manajemen Risiko BUMN Yang Lebih Efektif
Awal bulan September 2022, Kementerian BUMN menerbitkan Peraturan Menteri (Permen) BUMN No. PER-5/MBU/09/2022 tentang Penerapan Manajemen Risiko Pada BUMN. Peraturan ini berlaku bagi BUMN konglomerasi dengan jumlah pendapatan dari anak perusahaan terkonsolidasi lebih besar atau sama dengan 20% dari pendapatan BUMN, memiliki investasi pada anak perusahaan dengan total investasi lebih besar atau sama dengan 5% dari modal BUMN, dan atau memiliki anak perusahaan dengan saham seri A, serta BUMN individu yang tidak memenuhi kriteria di atas. Dengan kata lain, Permen BUMN ini tidak hanya berlaku bagi BUMN melainkan juga bagi anak perusahaan BUMN, khususnya perseroan terbatas yang dikendalikan oleh BUMN. Berkaitan dengan hal ini, Permen BUMN mewajibkan BUMN untuk menerapkan model tata kelola risiko yang terdiri atas model 3 lini dan tata kelola terintegrasi.
Permen BUMN ini mengatur klasifikasi BUMN dan anak perusahaan berdasarkan intensitas risiko yang mengacu pada ukuran dan kompleksitas BUMN dan anak perusahaan menjadi empat kategori: Sistemik A, untuk BUMN dan anak perusahaan yang memiliki ukuran besar dan kompleksitas tinggi; Sistemik B, untuk BUMN dan anak perusahaan yang memiliki ukuran tidak besar namun dengan kompleksitas tinggi; Signifikan, untuk BUMN dan anak perusahaan yang memiliki ukuran besar namun dengan kompleksitas tidak tinggi; dan Netral, untuk BUMN dan anak perusahaan yang memiliki ukuran tidak besar dan kompleksitas tidak tinggi. Kategorisasi ini menjadi penentu bagi BUMN dan anak perusahaan dalam hal organ pengelola risiko yang harus dimiliki serta pelaporan risiko yang harus dijalankan. Permen BUMN di atas juga mensyaratkan agar BUMN, dan anak perusahaannya, mengadopsi taksonomi risiko sesuai arahan Kementerian BUMN, memenuhi kecukupan kebijakan manajemen risiko, proses manajemen risiko, dan sistem pengendalian internal, serta melakukan perencanaan, penerapan, monitoring, dan evaluasi manajemen risiko, berikut pelaporannya.
IRMAPA menyambut positif Permen BUMN tentang manajemen risiko ini dan mengajak profesional bidang manajemen risiko di BUMN dan anak perusahaan BUMN untuk meresponsnya dengan melakukan kajian kesesuaian praktik penerapan manajemen risiko yang dijalankan dengan ketentuan-ketentuan yang ada di dalam Permen BUMN tersebut sehingga kesenjangan dapat segera teridentifikasi dan rencana pemenuhannya dapat segera diusulkan kepada manajemen puncak. Pada rapat sosialisasi Permen BUMN yang dilaksanakan oleh Kementerian BUMN pada hari Jumat, 7 Oktober 2022 lalu, tiap BUMN diarahkan untuk melaksanakan self-assessment intensitas risiko untuk mengidentifikasi pada kategori apa entitas berada. Walaupun Kementerian BUMN akan menerbitkan Keputusan Menteri sebagai petunjuk pelaksanaan Permen BUMN di atas, masing-masing BUMN dan anak perusahaan hendaknya mengantisipasi kebutuhan untuk mengembangkan struktur organisasi, kebijakan, serta prosedur manajemen risiko sesuai Permen BUMN.
Berkaitan dengan hal tersebut, SNI ISO 31000 sebagai standar praktik terbaik nasional penerapan manajemen risiko yang diadopsi dari standar praktik terbaik dunia, tidak bertentangan, bahkan mendukung, isi ketentuan Permen BUMN di atas. Baik perancangan desain kerangka kerja manajemen risiko berbasis SNI ISO 31000, yang dalam istilah yang digunakan dalam Permen BUMN yaitu tata kelola risiko, maupun proses manajemen risiko berbasis SNI ISO 31000, mengarahkan organisasi, dalam hal ini BUMN dan anak perusahaannya, untuk menyesuaikannya manajemen risikonya dengan konteks internal dan eksternalnya masing-masing, di mana Permen BUMN merupakan salah satu konteks eksternal yang harus ditaati. Selain itu, BUMN dan atau anak perusahaan BUMN yang telah mengadopsi SNI ISO 31000 dalam penerapan manajemen risikonya juga akan lebih cepat beradaptasi dalam melaksanakan isi ketentuan Permen BUMN di atas karena telah terbiasa dengan prinsip “Perbaikan Sinambung” dalam SNI ISO 31000 yang dijalankan melalui pelaksanaan komponen ‘Evaluasi’ dan ‘Perbaikan’ pada kerangka kerja manajemen risiko serta aktivitas ‘Pemantauan dan Tinjauan’ dalam proses manajemen risiko SNI ISO 31000. Lebih jauh lagi, SNI ISO 31000 bahkan mengarahkan rangkaian praktik manajemen risiko spesifik berdasarkan regulasi dan standar industri ke dalam suatu sistematika manajemen risiko yang holistik bagi organisasi (enterprise risk management).
Sebagai penutup, IRMAPA berpesan kepada para profesional bidang manajemen risiko di BUMN maupun anak-anak perusahaannya untuk melihat keberadaan Permen BUMN tentang penerapan manajemen risiko sebagai kesempatan untuk meningkatkan efektivitas praktik pengendalian dan pengelolaan risiko yang dijalankan perusahaan.
Teruslah semangat mengelola risiko, dan amankan kiprah BUMN bagi kemajuan negeri..!
-o0o-
GRC (Governance, Risk Management, Compliance) – A Set of Capabilities for Embracing ESG Towards SDG
Driven by SDGs (Sustainable Development Goals), organizations around the world and across industries are pursuing their credentials of implementing ESG (Environmental, Social, & Governance). SDGs are global goals set out by the United Nations, whereas ESG is a rating system used by companies to measure their environmental, social, and governance credentials (https://crmsindonesia.org/publications/sdgs-and-esg-overcoming-the-sustainability-risks/) The goal of organizations to implement ESG is to be an organization of integrity to ensure that the values, ethics, statements, commitments, relationships, and transactions are a reality in practice.
However, understanding ESG is complex. Some focus on the E for the environment, others are focused on the S, and others on the G. Despite this, all three are critical and intersect with each other, whereby:
- Environment: It covers and addresses the organization’s credentials of environmental performance, such as climate change, natural resource utilization, pollution and waste, biodiversity, carbon footprint, or emissions.
- Social, it covers and addresses the organization’s credentials of social performance such as child labor, forced labor, socio-economic inequality, privacy, personal data use, diversity and inclusion, working conditions, health and safety, and product liability.
- Governance covers and addresses the organization’s credentials of governance performance and practices, such as anti-fraud, anti-bribery and corruption, anti-money laundering, internal controls over financial reporting, security, corporate conduct and behavior, anti-competitive practices, tax transparency, ownership, and structure.
Although there is no single global standard for ESG, some reporting guidelines could help the organization provide more visibility of their ESG performance and credential to their stakeholders. The most popular is the Global Reporting Initiative (GRI) which was introduced at an early stage, and what is now widely used, the Value Reporting Foundation ((the merger of the International Integrated Reporting Council (IIRC) and the Sustainability Accounting Standards Board (SASB)). Despite their best efforts, however, nothing is complete as they each have their different perspectives.
Therefore, organizations must develop a strategy and process that delivers what they need to report to their respective and/or interested stakeholder groups. In that situation, organizations need more structured guidance on delivering on ESG strategy and processes across the diverse areas of ESG. As such, they need capabilities to perform ESG, hence to gain the credentials accordingly. As such, taking the capabilities, GRC comes up to the surface.
As originally introduced by OCEG, the definition of GRC is the integrated collection of capabilities that enable an organization to achieve objectives reliably, address uncertainty, and act with integrity (https://www.oceg.org/about/what-is-grc/). We start with the objectives (Governance) of the organization, which could be an entity, division, department, process, project, or asset level objectives, and from there, we have the context to manage the risks as the effect of uncertainties (Risk Management), and then acting with integrity (Compliance).
Organizations must set objectives for ESG overall, each component or area of ESG, and varying sub-elements. Once objectives are established, the organization can assess, monitor, and manage uncertainty to those ESG objectives. From there, the organization can provide assurance and report that it is operating with integrity in the context of stated ESG statements, commitments, and obligations.
In short, ESG is a rating system used by companies to measure their environmental, social, and governance credentials, whereas GRC is a set of capabilities to bring about such credentials into reality as the base of measurement and reporting.
Talking about capabilities, we could use the two most widely used references, i.e., the OCEG GRC Capability Model ( https://go.oceg.org/grc-capability-model-red-book) and the Integrated GRC using ISO-based series of standards and/or guidelines (http://theigrca.org/2021/08/05/integrated-grc-using-iso-based-series-of-standards-and-or-guidelines/).
The GRC Capability Model has four components: Learn, Align, Perform, Review, explicitly applied to ESG:
- LEARN: To understand the context and map the reporting requirements and relationships
- ALIGN: To document ESG objectives and related risks and design the overall program with appropriate policies, processes, monitoring, issue reporting, and assurance.
- PERFORM: To perform the designed program into operational, communicate and educate the stakeholder groups on their role and responsibilities in ESG.
- REVIEW: conduct ongoing monitoring and reporting on ESG to various stakeholders and continuously improve ESG in the organizations context and its broader objectives and operations.
Whilst the GRC Capability Model above emphasizes the fundamental cycle and logic of Learn-Align-Perform-Review in the ESG process, ISO-based GRC refers to a more practical reference and traceable process encapsulated into a standard-form alike. Both are worth considering, as OCEG GRC Capability Model refers to a more generic and fundamental approach, whereas the ISO Standards refer to more traceable and consistent practices. In short, both will help the organization accomplish their credentials of ESG performance.
GRC is something organizations do and not something they purchase. No one technology solution does everything needed for GRC, and there is certainly none that does everything for ESG. Performance and objectives did through actions, behaviors, and transactions of the organization. There can be a core reporting and monitoring platform, but it requires integration with other business systems internally and content providers externally
Hope this short article is useful.
Dr. Antonius Alijoyo, founder of Center for Risk Management and Sustainability (CRMS Indonesia) and Chair of supervisory board of Indonesia Risk Management Professionals Association (IRMAPA)
SDGs and ESG – Overcoming The Sustainability Risks
The topic of SDGs (Sustainable Development Goals) and ESG (Environmental, Social, Governance) are rising trends and have become the agenda of generations. In short, SDGs are global goals set out by the United Nations, whereas ESG is a rating system used by companies to measure their environmental, social, and governance credentials (www.safety4sea.com), which matters to their stakeholders, particularly the investors.
The Sustainable Development Goals (SDGs), also known as the Global Goals, were adopted by the United Nations in 2015 as a universal call to action to end poverty, protect the planet, and ensure that by 2030 all people enjoy peace and prosperity (www.undp.org). The 17 goals that have been defined address the root causes of poverty and pledge to leave no one behind, including vulnerable and minority groups. They also emphasize the need to tackle climate change urgently and protect the environment through a shift to sustainable consumption and production (source: world economic forum).
The 17 SDGs are intended to be universal, applying to all countries, organizations, and every human being rather than just the particular ones. The Sustainable Development Goals (SDGs) are the fundamental cornerstone to secure future economic and business growth by inclusively eradicating poverty while protecting the environment. They recognize the private sector’s key role in pursuing and financing sustainable development in partnership with governments and civil society. The business has the unique opportunity to embrace the SDG agenda and recognize it as a driver of business strategies, innovation, and investment decisions since it is impossible to have a strong, functioning business in a world of increasing inequality, poverty, and climate change. Sustainability risk will eventually become a sustainability crisis for the company if they don’t take part or make efforts to embrace the SDGs agenda.
A question is arising: “How does the private sector and/or business play their role in taking participation and then place a contribution towards SDGs? Further, how doing so makes business sense and will give them an edge over their competitors?”
To answer the question, the followings are worth considering:
- Addressing sustainability risk properly
Companies may be unable to continue to create capital over the long term if natural, social, financial, and capital are at risk and being eroded elsewhere. Each SDG represents a risk area already presenting challenges to businesses and society, and these risks are likely only to continue and grow if not well and effectively addressed. For example, supply chains are particularly exposed to the effects of climate change and depletion of natural resources (SDG No: 12, 13, 14, and 15), geopolitical instability (SDG No. 16), inequality (SDG No. 10), and lack of development in some regions (SDG Nos. 1, 2, 3 and 4) that limit the potential of emerging markets.
- Understanding the expectation of stakeholders
The capital provisions are made by the investors seeking sustainability of the organizations. Addressing these and other risks can make good business sense as stakeholders hold companies accountable for their role in creating or exacerbating these risks and, therefore, are able to maintain their social license to operate. As such, Investors are increasingly paying attention to environmental, social, and governance (ESG) risks when making investment decisions into particular businesses or companies and trying to see the organization’s credentials in dealing with them effectively.
According to the third EY Investor Survey (2017), weak corporate governance, poor environmental performance, resource scarcity, climate change, and human rights risks are likely indicators that could alter investors’ decisions.
- Building a strong and meaningful ESG program
An ESG program creates a valuable impact on our organization, our community, and the planet for years to come. A strong and meaningful ESG program can set a vision for an organization’s environmental and societal influence, providing value both internally and externally. Establishing environmental goals can help reduce our carbon footprint, determine our sourcing strategy, and set a foundation for eliminating unnecessary waste. From a social impact lens, we can build a meaningful diversity program, enhance employee health and make lasting changes in our community. And by building a strong governance foundation, we can diversify our board, enhance business ethics, increase stakeholder transparency and protect privacy.
To ensure the adoption and success of an ESG program, it’s critical to align an ESG vision to our organization’s existing strategy and purpose. Establishing and communicating this foundation will allow our organization to be authentic in its actions, avoid “greenwashing,” and align the roadmap to core business objectives. As such, ESG has emerged as an opportunity (rather than just a responsibility) to build a more sustainable business and a key differentiator to enhance relevancy and trust with the organization’s stakeholders, now and in the future.
Hope this short article is useful.
Dr. Antonius Alijoyo, founder of Center for Risk Management and Sustainability (CRMS Indonesia) and Chair of supervisory board of Indonesia Risk Management Professionals Association (IRMAPA).
Lagging Indicators and Leading Indicators – in Use of Risk-based Decision Making
Managing risk is managing the effect of uncertainties on our objectives. It could be related to the objectives of our strategy, financials, operations, compliance, etc. As it starts from the decision-making, we need some indicators at that stage. As such, we need to consider both relevant lagging and leading indicators. The following questions are then asked to risk professionals: ‘what exactly are the differences, and why does it matter?
Leading indicators are described as inputs. They define actions necessary to achieve the goals and objectives with measurable outcomes, hence they lead to successfully meeting the organization’s goals and objectives. Whereas a lagging indicator is sometimes described as output that’s already occurred to gain insight into an organization’s future success.
In essence, leading indicators are about trying to predict the future, and lagging indicators are about understanding what has already happened. Both are important for a risk-based decision-making purpose related to measuring an organization’s performance. As such, both indicators are equally needed for an organization to understand its performance and identify proper ways to improve them in the future.
Another thing worth considering for risk professionals is to be aware of the challenges of using the leading indicators and the downsides of using the lagging indicators. Such awareness is important to help organizations not be trapped into one indicator due to one-sided preference or limitations, especially those that might lead to an organization’s focus and leniency.
What are the challenges of using leading indicators?
They are important for building a broad understanding of performance because they provide information on likely future outcomes. Some examples are the increased portion of younger generations that consume our product or services, the increased portion of new products or services of a new market segment that contribute to our sales portfolio, and the more productive innovation cycle of an organization or the index of future-fit of people competencies. Hence, leading indicators are much more likely to be unique to the organization, making them harder to build, measure and benchmark. In such a situation, many organizations could be tempted not consciously and cautiously develop their leading indicators due to many reasons. As a result, they might gradually lose the foresight and horizon of the future relevant contextualization, which disables organizations from making quality risk-based decisions.
What is the downside of using lagging indicators?
They’re typically easy to identify, measure and compare against elsewhere in our industry, such as actual revenue, profit, etc., which makes lagging indicators very useful. However, the obvious downside of backward-looking indicators is they may provide insights too late to do anything about it. Even if it’s not too late, the lagging indicator is probably not telling us why this trend is happening and what you can do to stop it. Another downside is that lagging indicators encourage a focus on outputs (a number-based measure of what has happened) rather than outcomes (what we wanted to achieve).
Hope this short article is useful.
Dr. Antonius Alijoyo, founder of Center for Risk Management and Sustainability (CRMS Indonesia) and Chair of supervisory board of Indonesia Risk Management Professionals Association (IRMAPA).
Sustainability and Natural Capital – Relationship with Triple Bottom Line
The topic above is the rising trends and become the agenda of generations. Whilst no question about the importance of those agendas, what do we need to know in this respect? And what considerations need to be taken into account when we are making decisions and actions in the firm’s best interest? Such questions are critical, especially to the risk professional who must consider the aspect of sustainability in the organization’s decision-making process.
Let us start with some concepts and fundamentals that underlie the importance of sustainability. In this regard, United Nations (UN) say that sustainability meets the needs of the present without compromising the ability of future generations to meet their own needs. While so many other definitions and/or sayings about sustainability, they all converged on the understanding that sustainability deals with how to ‘avoid the depletion of our natural resources to maintain a balanced ecosystem and preserve natural capital.’
One word is underlined here “natural capital.” What does it mean? And why does it matter to us? Natural capital, in short, can be defined as the world’s stocks of natural assets, which include geology, soil, air, water, and all living things. From this natural capital, humans derive a wide range of services, often called ecosystem services, which make human life possible.
The most obvious ecosystem services include the food we eat, the water we drink, and the plant materials we use for fuel, building materials, and medicines. There are also many less visible ecosystem services such as the climate regulation and natural flood defenses provided by forests, the billions of tonnes of carbon stored by peatlands, or the pollination of crops by insects. Even less visible are cultural ecosystem services, such as the inspiration we take from wildlife and the natural environment
Nevertheless, if we talk about sustainability, it is about the interdependencies between the three things: environment, society, and economy. Talking about the environment takes place when we use to grow our food, the air we breathe, the water we drink, the soil we use, and the energy we consume. Talking about society takes place when it comes to making decisions amongst individuals and the interaction amongst individuals and groups in towns, villages, and particular organizations. And when we think about the economy, we think about the efficient allocation of scarce resources in response to our unlimited wants.
All of the above concepts and thrusts are then encapsulated into a calling about the new concept founded in 1994 by social entrepreneur John Elkington to measure and evaluate a business’ increasing interest in climate and social justice. Put simply, the triple bottom line (TBL) uses the power of three – people, planet, and profit – to measure the health and quality of a business impact. Twenty-five years on, it has given rise to a plethora of responsible business models, frameworks, and operational methodologies from Social Return on Investment (SRoI) to Environmental, Social and Corporate Governance (ESG), as well as proving an early inspiration for the rise of the sharing and circular economies.
How do triple bottom lines work, and what are the business benefits?
A business that operates using the TBL philosophy, therefore, not only measures the worth of its output using these ‘3 Ps’ but also – crucially – constructs and executes its short-and long-term business goals around them. It’s commitment, for sure, but the benefits of implementing a triple bottom line are threefold:
- Firstly from a ‘people’ perspective, companies that place equal importance on all three categories enjoy stronger, more cohesive teams, improved recruitment, higher employee morale, and increased brand loyalty than those run from a profit-first one.
- Secondly, when you treat the environment as an equal stakeholder, the planetary benefits are clear for all to see; the rewards are evidenced in the long-term sustainability of both our natural and business ecosystems.
- And finally, a business that practices what they preach and embeds the TBL framework into every aspect of its models enjoys a range of financial boosts – and often significant cost savings, too. The World Wildlife Fund’s 2013 report ‘The 3% Solution’ put the potential monetary gain of curbing US carbon emissions by 3% at $780 billion a year. In many countries, government and state financial incentives exist for implementing environmentally-friendly business practices.
It is important to remember that because of the co-dependence between the three ‘bottom-lines,’ making improvements in one area will nearly always positively impact your efforts in another – and is why the TBL is often referred to as a ‘win-win-win’ business strategy. And with that in mind, TBL thinking should be applied to strategic decision-making in every aspect of your business. As such, it requires both buy-in and action from stakeholders at all levels — from suppliers to the shop floor. Practically, departmental heads and executives will need to ensure that all measures of success are tied to the overarching people-planet-profit objectives. On a truly granular level, personal performance and employee development goals must also be reassessed in confluence with the new sustainability criteria.
To summarize, using the language of tech: a triple bottom line framework works best when embraced as a new operating system rather than a patch add-on.
Dr. Antonius Alijoyo
Founder of Center for Risk Management and Sustainability Indonesia
Lisensi BNSP bagi LSP GRK: Pentingnya Kompetensi SDM tentang GRC bagi Organisasi
Terminologi “integrated GRC” dewasa ini kian populer baik di Indonesia maupun di seluruh dunia. Jika hari ini Anda ketik istilah ini sebagai kata kunci pada mesin pencari Google maka Anda bisa mendapatkan lebih dari 8 juta entry. Memang hasil pencarian ini masih jauh lebih sedikit dibandingkan misalnya dengan hasil pencarian istilah “risk management” yang menampilkan 3,6 milyar entry. Namun, hasil yang sangat berbeda mungkin akan Anda dapatkan tahun depan sampai dengan 5 tahun lagi dari sekarang. Istilah “manajemen risiko” butuh 100 tahun untuk menjadi terkenal seperti sekarang ini sejak pertama kali dikenal sekitar tahun 1920-an, dibandingkan istilah “GRC” yang kini populer sejak tercetus pertama kali 20 tahun lalu.
Popularitas GRC terintegrasi ini didorong oleh meluasnya keyakinan para pengelola organisasi di dunia akan perlu dan pentingnya untuk mengubah penerapan G, R, dan C yang tadinya berjalan sendiri-sendiri menjadi suatu penerapan yang terintegrasi guna mengurangi aktivitas yang mubazir (redundant) dalam mendukung pencapaian sasaran organisasi. Sehubungan dengan hal ini, berbagai pendekatan dan metode diupayakan oleh organisasi untuk mewujudkan praktik GRC terintegrasi, salah satunya dengan memanfaatkan perkembangan teknologi informasi agar integrasi antara G, R, dan C dapat berlangsung secara mulus (seamless).
Meski demikian, efektivitas praktik GRC terintegrasi tetap bergantung pada seperti apa kualitas dari keterlibatan tiap individu organisasi yang menjalankannya. Walau didukung dengan alat bantu yang paling canggih sekalipun, praktik GRC tetap belum tentu akan memberikan hasil yang optimal bagi organisasi jika para personil tidak melaksanakannya dengan sungguh-sungguh dan serius. Di sini kita melihat pentingnya peran kompetensi SDM organisasi yang menyeluruh tentang G, R, dan C, serta bagaimana mengintegrasikannya menjadi GRC terintegrasi untuk mewujudkan manfaat penerapan bagi organisasi. Bahkan tanpa kompetensi yang memadai, rasanya sulit bagi penerapan apapun untuk bisa membudaya, termasuk penerapan GRC terintegrasi ini. Dan yang paling tidak kita harapkan adalah tanpa membudaya, besar kemungkinan penerapan GRC terjebak dalam serangkaian praktik administratif belaka yang dijalankan oleh para personil sebatas untuk mengugurkan kewajiban dari peraturan internal atau eksternal yang berlaku.
Sehubungan dengan hal ini, IRMAPA menyambut dengan sangat positif lisensi Badan nasional Sertifikasi Profesi (BNSP) yang berhasil didapat oleh Lembaga Sertifikasi Profesi Governansi Risiko Kepatuhan (LSP GRK) untuk skema-skema sertifikasi profesi di bidang GRC, Certified GRC Oversight Professional (CGRCOP), Certified GRC Executive Professional (CGRCEP), dan Certified GRC Professional (CGRCP). Dengan skema-skema sertifikasi ini, para praktisi dan profesional didorong untuk mendapatkan pengakuan atas kompetensi yang holistik di bidang G, R, dan C dalam satu kesatuan GRC, dan bukan pemahaman silo pada salah satu atau sebagian dari komponen GRC. Bagi organisasi yang memiliki para personil dengan sertifikasi profesi bidang GRC tidak hanya berarti bahwa organisasi tersebut memiliki SDM yang kompetensinya di bidang GRC diakui secara nasional, melainkan juga organisasi ini sekaligus memiliki kapasitas yang memadai untuk mempraktikkan GRC secara utuh dan menyeluruh serta untuk mengintegrasikan ketiganya sesuai konteks karakteristik dan kebutuhan organisasi.
Besar harapan IRMAPA dan seluruh anggota komunitas profesional manajemen risiko di Indonesia bahwa LSP GRK akan terus meningkatkan mutu pelayanan serta inovasi sehingga keberadaan LSP GRK di tanah air ikut berkontribusi dalam akselerasi peningkatan kesadaran nasional akan praktik GRC terintegrasi yang efektif. Selamat bagi LSP GRK atas lisensi BNSP yang telah diperoleh, teruslah berkiprah bagi negeri..!
-o0o-