Speaker: Kelly

[Opening title slide displayed: Part Two: Building Agility and Resilience. Background music plays.]

Kia ora, koutou, and welcome back to part two of the Adapting to Change workshop. In part one, we focused on identifying pivot opportunities for your business. In part two, we are going to focus on building agility and resilience into your business plans.

Let's get into it.

Business risk assessment

[Slide displayed: Business Risk Assessment. On-screen text lists key steps for risk identification and risk management: identify potential threats and risks; categorise the type of risk; identify who or what could be harmed; put processes or strategies in place to mitigate risks; review and monitor risks regularly.]

The business environment is constantly changing. Even without large fundamental shifts in the market, there are continuous small changes that alter the context businesses operate in. Businesses have to be able to identify risks and market changes and know how to quickly respond.

They need to have plans in place to continue doing business when things go wrong. And that's exactly what part two is about.

So the first thing we are going to do is a business risk assessment. This will serve as a guide for you to build risk identification processes into your business and explore a variety of ways that you can protect your key assets.

So, how do we do this?

To conduct this risk assessment, there are a few key steps. Firstly, we want to identify potential threats and risks to our business. We then want to spend some time categorising the type of risks. Are these high, medium, or low risk to our business?

We want to identify then who and what could be harmed. We then want to focus on putting processes and strategies in place to mitigate these and review and monitor these risks regularly.

Now, please note we will not go into detail about emergency planning in this workshop. However, if you go to the back of your workbooks, you'll find a whole heap of resources to help you do this.

Now every business relies on certain people, systems, suppliers, technology and customers to operate effectively. If we can understand these dependencies, these can help us prepare for disruptions before they happen.

Step one: Identify potential business threats

[Slide displayed: Identify Potential Business Threats. On-screen text: "Identify threats, vulnerabilities, and dependencies that could disrupt your business operations." Label: "Step One".]

So step one is identifying potential business threats. Now there are numerous ways to identify these for our business. We can conduct a SWOT analysis, which we will touch on in more detail shortly. We could review financial statements or performance indicators or other things like utilising data and feedback from customers, employees, and the market.

And if you check out your workbooks, there are more examples to help your thinking here.

Dependencies and vulnerability

[Slide displayed: Dependencies & Vulnerability? On-screen bullet points list business reliance on one revenue stream, one sales channel, one key staff member, one supplier, one customer, one system or tool, and undocumented knowledge. A note states that resilience improves when businesses reduce unnecessary dependency and prepare for disruption early.]

Before we move on to identifying threats, it's important to understand the difference between a dependency and a vulnerability.

Businesses often become vulnerable when they heavily rely on things like one revenue stream, one sales channel, one key staff member with potentially all the knowledge in their head, one supplier, one large customer, or one system or tool. You can see there's a lot of ones through there.

The other key area is undocumented knowledge.

Now, remember that resilience improves when businesses reduce unnecessary dependency and prepare for disruption early. And that's exactly what we're going to do throughout the rest of this workshop.

SWOT analysis

[Slide displayed: SWOT Analysis with four sections: Strengths, Weaknesses, Opportunities, and Threats.]

Which brings us to our SWOT analysis.

Some of you may have done one of these for your business before and some not. A SWOT, which focuses on strengths, weaknesses, opportunities, and threats, is another great tool to help businesses identify their assets and strengths and also the areas of risk in the context of the market that you operate in.

[Slide changes to a detailed SWOT framework. Strengths section includes questions about what the business does well, competitive advantages, unique knowledge and key assets. Weaknesses section includes competitor advantages, business gaps, missing skill sets, shortcomings and resource limitations. Opportunities section includes emerging market trends, demand drivers and underserved markets. Threats section includes emerging competitors, regulatory changes and changing customer attitudes.]

So, let's break it down.

First, we look at strengths. You'll notice that these are internal. What does the business do well? What sets it apart from its competitors?

If we look on the flip side, internal weaknesses. What does your competition do better? And where are there gaps in your business?

If we now look externally, we can look at opportunities. What are the emerging market trends? How could these drive demand for your products or services?

And we talked a lot about that in part one, pivoting.

And finally, we look at external threats. Are there any emerging competitors out there in the market? Are customers' attitudes changing?

Now, for the purposes of the rest of this workshop, we are going to focus on weaknesses and threats to your business.

Don't worry, you'll have plenty of opportunity later on to focus on your strengths and opportunities. But it is the weaknesses and threats that we want to start to plan for.

[Exercise slide displayed. On-screen text: "Exercise #8: Note down the key internal risks (weaknesses) and the key external risks (threats) in your business. Refer to Part 3: Extra Resources (B) of the workbook for assistance. Use the strengths and opportunities columns to note down potential strengths that you could leverage to mitigate risks."]

So, to get us started here, note down the key internal risks or weaknesses and the key external risks or threats to your business. Refer to Part 3 or extra resources in the back of your workbook for assistance.

And later on, you can use the strengths and opportunities column to note down potential strengths that you could leverage to start mitigating these risks.

Now, remember when completing the SWOT analysis, there is no right or wrong answer. It's about you and your individual business.

Take a moment to complete the SWOT and I will see you back here soon.

Step two: Categorise the type of risk

[Slide displayed: Categorise the Type of Risk. On-screen text: "Assess which risks are temporary, ongoing, or likely to increase over time." Label: "Step Two".]

Welcome back.

So you've now identified the key risks and threats to your business. Now we want to categorise these by type of risk.

In this case, the type of risk includes severity of risk and the function or area of the business that it would impact.

Why do we want to do this? Because not all risks carry the same level of urgency or impact. And this is going to help you prioritise which deserves your attention first.

Example: Local retail and online clothing business

[Slide displayed showing weaknesses: one staff member manages all online orders, limited cash reserves, no documented processes. Threats: consumer spending declines, major supplier delays, shipping costs increase.]

Let's look at an example of a local retail and online clothing business.

They have identified their weaknesses as being one staff member manages all the online orders. They have limited cash reserves and no documented processes.

Some of the external threats: consumer spending could decline, major supply delays, or shipping costs increase.

What we want to do is categorise these into high, medium, or low. This is going to help you understand where you need to prioritise your efforts in terms of mitigating these risks.

[Slides illustrate risk-ranking categories. High risks are described as business threatening, operationally serious and disruptive. Medium risks are manageable but important and require monitoring or planning. Low risks are inconvenient rather than critical, less urgent and lower impact.]

If we look at high, high risks feel business threatening, operationally serious, and really disruptive.

If we're looking at medium, it's a little bit more manageable, but still important. It may need monitoring or planning.

And low feels inconvenient rather than critical. It's a little less urgent and has a lower business impact.

[Example ranking slide displayed. High: one staff member manages all online orders, limited cash reserves, consumer spending declines. Medium: major supplier delays. Low: no documented processes, shipping costs increase.]

Now if we were to categorise the weaknesses and threats for this business, in high: one staff member manages all the online orders, they have limited cash reserves, and a really key threat is if consumer spending declines.

Major supply delays could be medium, and for low they have no documented processes and shipping costs increase.

Now I will note here that the severity of risk can be different for every business.

For example, shipping costs increase is ranked as low. For some businesses, this could be really disruptive and really high risk.

There is no right or wrong here. It is about your individual business.

[Exercise slide displayed: "Exercise #9: For the internal and external risks you identified in Exercise #8 (weaknesses & threats), rank them as high, medium or low."]

It's time now to focus on your business.

For the internal and external risks that you identified in exercise 8, otherwise known as weaknesses and threats, rank them as high, medium, and low for your business.

Now feel free to pause this video and I will see you back here soon.

Area of impact

[Slide displayed: Area of Impact. Categories shown: Strategic, Financial, Regulatory, Operational, and Reputational, with definitions for each category.]

Welcome back.

Now we have identified the severity of risk. We want to look at the area of business that the risk you have identified sits in.

Why do we want to do this? Well, understanding where the risk has impact helps businesses identify vulnerabilities and plan more effectively.

How we can do this is break down the area of impact into strategic, financial, regulatory, operational and reputational.

So for example, strategic areas of impact could be changes in the market, customer behaviour, competition, technology.

If we look down the bottom, reputational could be damage to trust, credibility, or public perception.

[Example slide displayed showing risks mapped to impact areas. Consumer spending declines appears in both Strategic and Financial categories. Financial also includes limited cash reserves and shipping costs increase. Operational includes no documented processes, one staff member managing all online orders, and major supplier delays.]

Now if we go back to the local retail and online clothing business as an example, you can see we have categorised these risks into area.

Of important note, consumer spending decline sits across strategic and financial.

Why is it important to understand this? Well, this can really help us understand the magnitude of the risk and where we should be focusing our time.

[Exercise slide displayed: "Exercise #10: Categorise 3-4 key risks. Discuss in pairs."]

Now, it's time to think about your business.

Categorise three to four key risks that you have identified.

Are there any risks that impact multiple areas of your business?

I'll give you a moment to complete this exercise. Feel free to pause this video now and I will see you soon.

Step three: Identify who and what could be harmed

[Slide displayed: Identify Who & What Could Be Harmed. Label: "Step Three".]

Welcome back.

Now we've categorised the risks. We want to identify who may be implicated as a result or what equipment or processes may be impacted.

Pay particular attention to the key assets that may be impacted.

[Slide displayed listing who may be affected: employees, supply chain, manufacturers, customers or clients, and other key people. Also lists what may be affected: reputation, infrastructure, equipment, buildings, IT systems, stock, intellectual property and other key assets.]

Now when we look at these implications, we want to consider who in terms of employees, supply chain, manufacturers, customers or clients, or other key people involved in the business.

We can also consider what in terms of reputation, infrastructure, equipment, buildings, IT systems, stock, IP or other key assets.

Now why is it really important to break it down to this level? Well, this helps us understand the follow-on implications should this risk come to fruition.

[Exercise slide displayed: "Exercise #11: Discuss who and what are impacted the most by these risks. Note down the greatest impacts for your business in your workbook."]

Again, now it's time to think about your individual business.

Who and what are impacted the most by the risks you have identified for your business?

Join us back here soon for step four where we focus on mitigation strategies.

[Closing music plays. End of video.]

[Visual: Video ends on workshop branding slide.]