<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1d1 20130915//EN" "http://jats.nlm.nih.gov/publishing/1.1d1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" article-type="research-article" xml:lang="en">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">SAJEMS</journal-id>
<journal-title-group>
<journal-title>South African Journal of Economic and Management Sciences</journal-title>
</journal-title-group>
<issn pub-type="ppub">1015-8812</issn>
<issn pub-type="epub">2222-3436</issn>
<publisher>
<publisher-name>AOSIS</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">SAJEMS-20-1621</article-id>
<article-id pub-id-type="doi">10.4102/sajems.v20i1.1621</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Original Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A proposed operational risk management framework for small and medium enterprises</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<contrib-id contrib-id-type="orcid">http://orcid.org/0000-0002-0475-9474</contrib-id>
<name>
<surname>Naude</surname>
<given-names>Micheline J.</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">http://orcid.org/0000-0001-7757-211X</contrib-id>
<name>
<surname>Chiweshe</surname>
<given-names>Nigel</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<aff id="AF0001"><label>1</label>School of Management, Information Systems and Public Administration, University of KwaZulu-Natal, South Africa</aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><bold>Corresponding author:</bold> Micheline Naude, <email xlink:href="naudem@ukzn.ac.za">naudem@ukzn.ac.za</email></corresp>
</author-notes>
<pub-date pub-type="epub"><day>04</day><month>12</month><year>2017</year></pub-date>
<pub-date pub-type="collection"><year>2017</year></pub-date>
<volume>20</volume>
<issue>1</issue>
<elocation-id>1621</elocation-id>
<history>
<date date-type="received"><day>16</day><month>06</month><year>2016</year></date>
<date date-type="accepted"><day>28</day><month>08</month><year>2017</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2017. The Authors</copyright-statement>
<copyright-year>2017</copyright-year>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>Licensee: AOSIS. This work is licensed under the Creative Commons Attribution License.</license-p>
</license>
</permissions>
<abstract>
<sec id="st1">
<title>Background</title>
<p>The gap between small and medium-sized enterprises (SMEs) and large businesses that perform risk assessment is significant. SMEs continuously face many operational risks and uncertainties in their daily operations, and these risks threaten to reduce productivity, increase costs and reduce profits.</p>
</sec>
<sec id="st2">
<title>Aim</title>
<p>The purpose of this article was to develop an operational risk management framework that SMEs can use to identify and analyse risks in their operations and take corrective actions to mitigate these risks.</p>
</sec>
<sec id="st3">
<title>Setting</title>
<p>Small and medium-sized enterprises in South Africa do not view risk management as a key component of organisational success, despite evidence that businesses that adopt risk management strategies are more likely to survive and grow.</p>
</sec>
<sec id="st4">
<title>Methods</title>
<p>The article is exploratory in nature, and a conceptual analysis approach was used to formulate the framework. This study reviewed relevant literature sources on risk published between 2002 and 2017.</p>
</sec>
<sec id="st5">
<title>Results</title>
<p>The four process steps of risk management were used as a reference point and form the foundation for the operational risk management framework. The categories of operational; marketing; technical and financial risks were identified from a review of available literature on risk management.</p>
</sec>
<sec id="st6">
<title>Conclusion</title>
<p>There is a dearth of research that deals with operational risk management frameworks for SMEs. The expected contribution of this article, therefore, is twofold: firstly, it is envisaged that managers or owners of SMEs could use the proposed framework as a tool to appraise and minimise their operational risks; secondly, it will add to the current body of knowledge on risk appraisal for SMEs.</p>
</sec>
</abstract>
</article-meta>
</front>
<body>
<sec id="s0001">
<title>Introduction</title>
<p>In this current business environment, businesses are required to compete in a global, volatile and dynamic market. As more markets have opened up for products, this has created the potential to increase sales and profits (Cheng &#x0026; Kam <xref ref-type="bibr" rid="CIT0007">2008</xref>:345; Cocca &#x0026; Alberti <xref ref-type="bibr" rid="CIT0009">2010</xref>:186; Hoffmann, Schiele &#x0026; Krabbendam <xref ref-type="bibr" rid="CIT0018">2012</xref>:1; Simchi-Levi, Kaminsky &#x0026; Simchi-Levy <xref ref-type="bibr" rid="CIT0045">2008</xref>:315). Despite these advantages and opportunities, businesses face tough competition with regard to quality, cost and on-time delivery to market. Consequently, businesses are required to improve their flexibility, quality standards and innovative capacities (Islam, Tedford &#x0026; Haemmerle <xref ref-type="bibr" rid="CIT0023">2012</xref>:2). To achieve this, businesses need experienced and trained staff, reliable machines, efficient processes, good relationships with suppliers and customers, a supply of quality materials and services and other value-adding processes throughout the operations system. This is rarely achieved and many businesses, especially small and medium-sized enterprises (SMEs), face a number of business risks in their day-to-day operations that threaten to reduce productivity, increase costs and liabilities and reduce profits (Michalski <xref ref-type="bibr" rid="CIT0035">2009</xref>:213; Smit &#x0026; Watkins <xref ref-type="bibr" rid="CIT0047">2012</xref>:6327).</p>
<p>When businesses find themselves in a position where unexpected events cause disruption to normal operations, resulting in financial loss and damage to their reputation, this presents as a risk. Shareholders expect businesses to identify and mitigate risks that may cause disruption (Hopkins <xref ref-type="bibr" rid="CIT0019">2017</xref>:24). Therefore, risk assessment is a necessary tool for all businesses (Benton <xref ref-type="bibr" rid="CIT0003">2014</xref>:363; Wu &#x0026; Olson <xref ref-type="bibr" rid="CIT0057">2009</xref>:362). Even though tools for risk assessment like business scorecards are available in the market (Wu &#x0026; Olson <xref ref-type="bibr" rid="CIT0057">2009</xref>:362), findings indicate that SMEs tend not to formally assess and manage their risks, but instead respond reactively by using risk avoidance and risk transfer techniques (Islam et al. <xref ref-type="bibr" rid="CIT0023">2012</xref>:4; Smit <xref ref-type="bibr" rid="CIT0046">2012</xref>:iii).</p>
<p>The gap between SMEs and large businesses that perform risk assessment is significant. In South Africa, a component of the King III report on governance is risk management. The report states that &#x2018;it is the duty of the board of a trading enterprise to undertake a measure of risk for reward and to try to improve the economic value of a company&#x2019; (King <xref ref-type="bibr" rid="CIT0030">2012</xref>:6). However, SMEs in South Africa do not view risk management as a key component of organisational success (Smit &#x0026; Watkins <xref ref-type="bibr" rid="CIT0047">2012</xref>:4). Islam et al. (<xref ref-type="bibr" rid="CIT0023">2012</xref>:4) suggest that risk management is less developed within SMEs, despite evidence that businesses that adopt risk management strategies are more likely to survive and grow. By failing to assess the risks to which they are exposed, SMEs may find their success, reputation and credibility at stake (Dimopoulos et al. <xref ref-type="bibr" rid="CIT0013">2004</xref>:279). Some causes of failure in SMEs include poor management planning and failure to adopt risk assessment (Islam et al. <xref ref-type="bibr" rid="CIT0023">2012</xref>:4; Smit &#x0026; Watkins <xref ref-type="bibr" rid="CIT0047">2012</xref>:6325).</p>
<p>In many cases, risk can be predicted on the basis of experience, but it can be better managed through a risk management framework. This would include identifying risks, measuring their probable impact, mitigating the risks and eliminating or reducing their effect with the minimum investment of resources (Verbano &#x0026; Venturini <xref ref-type="bibr" rid="CIT0054">2013</xref>:1). The adoption of risk management is important when considering interruptions that can be caused in operational activities such as timely delivery, global competition and the strict requirements of customers (Servaes, Tamayo &#x0026; Tufano <xref ref-type="bibr" rid="CIT0043">2009</xref>:94).</p>
<p>Accordingly, the purpose of this article was to present an operational risk management framework which SMEs could use as a tool to identify risks, assess them, take corrective action to mitigate them and thereafter monitor them. For the framework to be relevant it should, according to Cocca and Alberti (<xref ref-type="bibr" rid="CIT0009">2010</xref>:187), not merely be a shortened version of a framework developed for large businesses; it should, moreover, remain simple and comprehensive; it should not be too demanding in terms of resources; finally, it must guide the owner-manager towards action or improvement.</p>
<p>The proposed operational risk management framework presented in this study is based on the four process steps of risk management, namely risk identification, risk assessment, risk response and risk monitoring and control (Sharma &#x0026; Bhat <xref ref-type="bibr" rid="CIT0044">2014</xref>:26; Waters <xref ref-type="bibr" rid="CIT0056">2009</xref>:477; Young <xref ref-type="bibr" rid="CIT0059">2008</xref>:1). These aspects were used as a reference point and formed the foundation for the framework. The various categories of operations risks were identified from academic texts and are embedded in this proposed framework.</p>
</sec>
<sec id="s0002">
<title>Research methodology</title>
<p>The article is exploratory in nature and a conceptual analysis approach was used to formulate the framework. Conceptual analysis can be defined as a technique that treats concepts as classes of objects, such as words, themes or characters. The technique involves analysing and interpreting text by coding the text into manageable content categories (Sekaran &#x0026; Bougie <xref ref-type="bibr" rid="CIT0042">2016</xref>:350). Conceptual analysis was deemed appropriate to gain better insight into the risk management processes of SMEs, steps in risk management and the various types of risks. This study reviewed relevant literature sources on risk published in the period between 2002 and 2017. These included journal articles available on Google Scholar and Science Direct, academic texts, theses and reports dealing with SMEs, risk and risk management. In this way, the study examined: (1) the nature of SMEs, (2) risk and risk management, (3) the different categories of risk and (4) the importance of risk management. When this review was completed, a risk management framework was developed, which SMEs can use as management tool.</p>
</sec>
<sec id="s0003">
<title>Ethical consideration</title>
<p>Ethical clearance through University of KwaZulu-Natal was obtained.</p>
</sec>
<sec id="s0004">
<title>Theoretical review</title>
<sec id="s20005">
<title>Small and medium enterprises in South Africa</title>
<p>Small and medium-sized enterprises are businesses in the private sector and across all industries employing between 10 and 200 employees. The definitions of SMEs by industry sector or subsector in accordance with the Standard Industrial Classification are presented in <xref ref-type="table" rid="T0001">Table 1</xref>. These definitions are based on the <italic>National Small Business Act No. 26, 2003</italic> (South Africa <xref ref-type="bibr" rid="CIT0049">2003</xref>). SMEs are usually independently owned and operated and are closely controlled by their owners. Thus, the owners are responsible for the management of the business on a day-to-day basis, including areas such as marketing, production, human resources and finance (Nieuwenhuizen <xref ref-type="bibr" rid="CIT0037">2007</xref>:2; Smit &#x0026; Watkins <xref ref-type="bibr" rid="CIT0047">2012</xref>:6325).</p>
<table-wrap id="T0001">
<label>TABLE 1</label>
<caption><p>Schedule of size standards for the definition of small and medium-sized enterprises in South Africa.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Sector or subsector in accordance with the standard industrial classifications</th>
<th valign="top" align="left">Size of class</th>
<th valign="top" align="center">Number of employees</th>
<th valign="top" align="left">Total turnover</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td align="left" rowspan="3">Agriculture, finance and business services</td>
<td align="left">Medium</td>
<td align="center">100</td>
<td align="left">R5m</td>
</tr>
<tr>
<td align="left">Small</td>
<td align="center">50</td>
<td align="left">R3m</td>
</tr>
<tr>
<td align="left">Very small</td>
<td align="center">10</td>
<td align="left">R0.5m</td>
</tr>
<tr>
<td align="left" rowspan="3">Mining and quarrying</td>
<td align="left">Medium</td>
<td align="center">200</td>
<td align="left">R39m</td>
</tr>
<tr>
<td align="left">Small</td>
<td align="center">50</td>
<td align="left">R10m</td>
</tr>
<tr>
<td align="left">Very small</td>
<td align="center">20</td>
<td align="left">R4m</td>
</tr>
<tr>
<td align="left" rowspan="3">Manufacturing, electricity, gas and water</td>
<td align="left">Medium</td>
<td align="center">200</td>
<td align="left">R51m</td>
</tr>
<tr>
<td align="left">Small</td>
<td align="center">50</td>
<td align="left">R13m</td>
</tr>
<tr>
<td align="left">Very small</td>
<td align="center">20</td>
<td align="left">R5m</td>
</tr>
<tr>
<td align="left" rowspan="3">Construction</td>
<td align="left">Medium</td>
<td align="center">200</td>
<td align="left">R26m</td>
</tr>
<tr>
<td align="left">Small</td>
<td align="center">50</td>
<td align="left">R6m</td>
</tr>
<tr>
<td align="left">Very small</td>
<td align="center">20</td>
<td align="left">R3m</td>
</tr>
<tr>
<td align="left" rowspan="3">Retail and motor trace and repair services</td>
<td align="left">Medium</td>
<td align="center">200</td>
<td align="left">R39m</td>
</tr>
<tr>
<td align="left">Small</td>
<td align="center">50</td>
<td align="left">R19m</td>
</tr>
<tr>
<td align="left">Very small</td>
<td align="center">20</td>
<td align="left">R4</td>
</tr>
<tr>
<td align="left" rowspan="3">Wholesale trade, commercial agents and applied services<break/>Transport, storage and communications<break/>Community, social and personal services</td>
<td align="left">Medium</td>
<td align="center">200</td>
<td align="left">R64m</td>
</tr>
<tr>
<td align="left">Small</td>
<td align="center">50</td>
<td align="left">R32m</td>
</tr>
<tr>
<td align="left">Very small</td>
<td align="center">20</td>
<td align="left">R6m</td>
</tr>
<tr>
<td align="left" rowspan="3">Catering, accommodation and other trade</td>
<td align="left">Medium</td>
<td align="center">200</td>
<td align="left">R13m</td>
</tr>
<tr>
<td align="left">Small</td>
<td align="center">50</td>
<td align="left">R6m</td>
</tr>
<tr>
<td align="left">Very small</td>
<td align="center">20</td>
<td align="left">R5.1m</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p><italic>Source</italic>: Government Gazette of the Republic of South Africa 2003</p></fn>
</table-wrap-foot>
</table-wrap>
<p>Small and medium-sized enterprises play an important role in the economies of many countries and therefore governments globally focus on the development of the SME sector to promote economic growth. The contribution to most economies by SMEs is significant as they constitute the largest number of businesses and employ a significant proportion of the labour force (Islam &#x0026; Tedford <xref ref-type="bibr" rid="CIT0022">2012</xref>:2; Sousa &#x0026; Aspinwall <xref ref-type="bibr" rid="CIT0048">2010</xref>:476). The role of SMEs in South Africa is no exception. According to the National Development Plan, South Africa&#x2019;s SMEs play a key role in the creation and promotion of employment, particularly in labour-intensive industries (Davis Tax Committee <xref ref-type="bibr" rid="CIT0011">2014</xref>:5). SMEs are employers of unskilled labour and develop and nurture entrepreneurial skills (Smit &#x0026; Watkins <xref ref-type="bibr" rid="CIT0047">2012</xref>:6324). However, SMEs are perceived as high-risk enterprises as their entry and exit levels in the market are high. It is estimated that 50&#x0025; of the small businesses started in South Africa have eventually failed (Islam &#x0026; Tedford <xref ref-type="bibr" rid="CIT0022">2012</xref>:2). Despite these high failure rates, SMEs continue to be a key part of the economy as they collectively employ a large overall workforce. It is estimated that the SME sector contributes 55&#x0025; to private sector employment and accounts for approximately 40&#x0025; of the gross domestic product of the country (Radebe <xref ref-type="bibr" rid="CIT0038">2014</xref>:para. 2; Sanlam Financial Services <xref ref-type="bibr" rid="CIT0040">2014</xref>:para. 7).</p>
<p>Small and medium-sized enterprises thrive on their adaptability, their agility based on their closeness to their customers, their openness to processes that enhance their efficiency and their ability to take risks (Smit &#x0026; Watkins <xref ref-type="bibr" rid="CIT0047">2012</xref>:6324). Nevertheless, while SMEs operate in the same environment as larger organisations, they do not have the resources of these larger organisations (Sousa &#x0026; Aspinwall <xref ref-type="bibr" rid="CIT0048">2010</xref>:476). Globalisation, legislation, market expansion and the removal of trade barriers have fuelled an increase in the competition faced by SMEs. Moreover, they, in common with every business, are susceptible to unwanted internal and external setbacks in their daily operations (Islam et al. <xref ref-type="bibr" rid="CIT0023">2012</xref>:2).</p>
<p>The business environment is dynamic and highly competitive. To survive, businesses are under pressure to satisfy all their stakeholders and excel at the same time (Cocca &#x0026; Alberti <xref ref-type="bibr" rid="CIT0009">2010</xref>:186). Therefore, all enterprises including SMEs need to adopt a formal risk management strategy as a tool to survive and grow. Kagwathi et al. (<xref ref-type="bibr" rid="CIT0026">2014</xref>:9) found that, unlike the larger businesses in developing countries, there is a lack of formal risk management in SMEs which can identify and mitigate their risks. Islam and Tedford (<xref ref-type="bibr" rid="CIT0022">2012</xref>:3) suggest that risk management is less developed in SMEs. Despite the evidence that businesses that adopt a formal risk management strategy are more likely to survive and grow, SMEs are reluctant to do so as it is viewed as time consuming and entrepreneurs would rather focus their energies on running their businesses based on their known skills and experience. Paradoxically, a formal approach to risk management and risk-mitigation could alert them to the realities of some of the threats and risks.</p>
</sec>
<sec id="s20006">
<title>Risks</title>
<p>One of the first definitions of risk can be ascribed to Bernoulli, who in 1738 proposed measuring risk with a geometric mean and minimising risk by spreading it across a set of independent events (Verbano &#x0026; Venturini <xref ref-type="bibr" rid="CIT0054">2013</xref>:187). Risk is always linked to the uncertainty of the occurrence of a certain event that can cause loss or damage. It combines the probability and severity of a risk (Aven <xref ref-type="bibr" rid="CIT0002">2016</xref>:4; Islam &#x0026; Tedford <xref ref-type="bibr" rid="CIT0022">2012</xref>:258). The International Organization for Standardization (ISO) defines risk as the effect of uncertainty on objectives. An effect is described as a deviation from the expected objectives and can apply at different levels, that is, financial, health and safety, reputation, natural environment and legal. The uncertainty is related to understanding or knowledge of an event and its consequence or likelihood (ISO <xref ref-type="bibr" rid="CIT0021">2009</xref>). Li and Zeng (<xref ref-type="bibr" rid="CIT0033">2014</xref>:45) define risk as the level of exposure to uncertainties that the business must understand and effectively manage as it carries out its strategies to achieve its business objectives and create value. To refine this from an operational point of view, operational risk can be defined as the risk of loss as a direct consequence from inadequate or failed processes, people and systems from external and internal events (GARP <xref ref-type="bibr" rid="CIT0014">2014</xref>:41).</p>
<p>The business environment constantly changes. In this changing environment, risk taking is a key element of the entrepreneurial function and ultimately crucial in the creation of economic value and innovation (Dempster <xref ref-type="bibr" rid="CIT0012">2009</xref>:151). Changes in factors such as interest hikes, material price increases and strikes influence the business environment and result in uncertainty about the future path of an enterprise. Uncertainty about the future manifests itself as a risk (Hugo &#x0026; Badenhorst-Weiss <xref ref-type="bibr" rid="CIT0020">2011</xref>:97). Operational risk and uncertainties are important in the academic and practical application. The field of operational risk management materialised as a result of several catastrophes and natural disasters, globalisation, intensified competition and integrated production methods (Cheng &#x0026; Kam <xref ref-type="bibr" rid="CIT0007">2008</xref>:347). Thus, operational risk management is a developing focus area in supply chain management research (Aven <xref ref-type="bibr" rid="CIT0002">2016</xref>:3; Hoffmann, Schiele &#x0026; Krabbendam <xref ref-type="bibr" rid="CIT0018">2012</xref>:1).</p>
<p>The sources of risks in operations are many and multifaceted and include strategy misalignment, regulatory requirements, changes in consumer preferences and the impairment of key assets (Lavastre, Gunasekaran &#x0026; Spalanzani <xref ref-type="bibr" rid="CIT0032">2012</xref>:829). Other risks include skills shortages, unreliable suppliers, as well as economic, technological, social factors and information security (Blome, Schoenherr &#x0026; Eckstein <xref ref-type="bibr" rid="CIT0005">2014</xref>:309). Consequently, entrepreneurs must be able to identify and mitigate potential risks, as failure to do so could result in reduced productivity or even lead to bankruptcy. For example, an SME may find the costs of enforced responsibilities such as a product recall or a site clean-up could reduce or eliminate expected profits (Sanders <xref ref-type="bibr" rid="CIT0039">2012</xref>:394). Risk management is not well defined, which can give rise to challenges in any organisation and specifically to SMEs (Blanc-Alquier &#x0026; Lagasse-Tignol <xref ref-type="bibr" rid="CIT0004">2006</xref>:273).</p>
</sec>
<sec id="s20007">
<title>Risk management</title>
<p>Risk management can be described as the process of identifying potential risks, assessing the likelihood of their occurrence, mitigating these risks before they occur or reducing the risk probability and putting contingency plans in place to mitigate the consequences if they do arise (Monczka et al. <xref ref-type="bibr" rid="CIT0036">2016</xref>:259; Waters <xref ref-type="bibr" rid="CIT0056">2009</xref>:277). The four concepts of risk management are illustrated in <xref ref-type="fig" rid="F0001">Figure 1</xref>.</p>
<fig id="F0001">
<label>FIGURE 1</label>
<caption><p>Four process steps of risk management.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJEMS-20-1621-g001.tif"/>
</fig>
<sec id="s30008">
<title>Identification of risks</title>
<p>This is the first step in the risk management process, with the aim of identifying future potential risks so that they can be proactively mitigated. Risk identification can be defined as the process of systematically identifying all potential internal and external risks which can cause loss or damage to the business (Hallikas &#x0026; Lintukangas <xref ref-type="bibr" rid="CIT0015">2016</xref>:57; Kodithuwakku &#x0026; Wickramarachchi <xref ref-type="bibr" rid="CIT0031">2015</xref>:122). It is about recognising and understanding possible risk sources (Hoffmann et al. <xref ref-type="bibr" rid="CIT0018">2012</xref>:4). However, these risks might be difficult to identify, as they have not yet happened, but might happen sometime in the future (Turner &#x0026; Keetelaar <xref ref-type="bibr" rid="CIT0051">2005</xref>:29). Key to the process is that, when they are identified, they should be recorded and monitored (Scarborough, Wilson &#x0026; Zimmerer <xref ref-type="bibr" rid="CIT0041">2009</xref>:730; Van Weele <xref ref-type="bibr" rid="CIT0052">2010</xref>:175). The methods suggested for identifying risks are through brainstorming with staff and external stakeholders and through researching the political, economic, legislative and operating environment. It must, however, be noted that the identification of risks can be limited by the experiences and perspectives of the person(s) conducting the risk analysis (Islam &#x0026; Tedford <xref ref-type="bibr" rid="CIT0022">2012</xref>:262; Turner &#x0026; Keetelaar <xref ref-type="bibr" rid="CIT0051">2005</xref>:29).</p>
</sec>
<sec id="s30009">
<title>Risk assessment</title>
<p>This is the second step in the risk management process and can be described as evaluating or calculating the probability of occurrence of a possible risk and predicting its impact. Risk assessment includes evaluating two variables, namely the likelihood that a risk will occur and the extent of its impact if the risk actually occurs (Ho et al. <xref ref-type="bibr" rid="CIT0017">2015</xref>:132). The impacts can be on the finances, on health and safety, the natural environment or the reputation of the business and may have legal implications (Ho et al. <xref ref-type="bibr" rid="CIT0017">2015</xref>:44; Hoffmann et al. <xref ref-type="bibr" rid="CIT0018">2012</xref>:4; Kannan &#x0026; Martin <xref ref-type="bibr" rid="CIT0027">2016</xref>:33).</p>
</sec>
<sec id="s30010">
<title>Risk response</title>
<p>The third step in the risk management process is the use of mitigation strategies to eliminate, reduce or counteract risks (Hoffmann et al. <xref ref-type="bibr" rid="CIT0018">2012</xref>:4). There are three commonly used strategies to mitigate risk. These are: (1) risk informed &#x2013; treatment of risk, avoidance, reduction, transfer and retention; (2) cautionary or precautionary &#x2013; highlights features like containment, the development of substitutes, safety factors; and (3) discursive strategies &#x2013; uses measures to build confidence and trustworthiness, through reduction of uncertainties. In most cases the appropriate strategy would be a hybrid of these three strategies (Aven <xref ref-type="bibr" rid="CIT0002">2016</xref>:6; Cucchiella &#x0026; Gastaldi <xref ref-type="bibr" rid="CIT0010">2006</xref>:4). A business may select and implement a risk response strategy depending on the type of risk it faces (Yoon &#x0026; Lee <xref ref-type="bibr" rid="CIT0058">2012</xref>:32).</p>
</sec>
<sec id="s30011">
<title>Risk monitoring and control</title>
<p>The last step in the risk management process is regular risk monitoring. For example, indictors can be used to identify risk levels that are within limits but rising. This indicates future problems (Hoffmann et al. <xref ref-type="bibr" rid="CIT0018">2012</xref>:4). Risk management is a dynamic process as the probability of risks can change over time. Therefore, the monitoring of risks is vital as it can provide as an early warning when risk levels are increasing, giving businesses time to react to these changes and to formulate mitigation strategies (Chang et al. <xref ref-type="bibr" rid="CIT0006">2015</xref>:55; Wagner &#x0026; Bode <xref ref-type="bibr" rid="CIT0055">2008</xref>:311).</p>
</sec>
<sec id="s30012">
<title>Categories of risk</title>
<p>There are many categories of risks that businesses will come across. Some risks may have little impact on the business and can be managed easily, whereas other risks may threaten the survival of the business. Therefore, understanding what the potential risks are and how to effectively manage these risks will help small and medium business owner-managers make the necessary decisions to ensure the best possible outcome for their businesses.</p>
<p>There are various sources of risks in the operations of a business that have been identified by various authors and these can be grouped into various categories as presented in <xref ref-type="table" rid="T0002">Table 2</xref>.</p>
<table-wrap id="T0002">
<label>TABLE 2</label>
<caption><p>Categories of risks.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Authors</th>
<th valign="top" align="center">Operational risks</th>
<th valign="top" align="center">Market risks</th>
<th valign="top" align="center">Technological risks</th>
<th valign="top" align="center">Financial risk</th>
<th valign="top" align="center">Political risks</th>
<th valign="top" align="center">Environmental risks</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Keizer, Halman and Song (<xref ref-type="bibr" rid="CIT0028">2002</xref>)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Harland, Brenchley and Walker (<xref ref-type="bibr" rid="CIT0016">2003</xref>: 55)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="left"></td>
<td align="center">X</td>
</tr>
<tr>
<td align="left">Van Wyk, Dahmer and Custy (<xref ref-type="bibr" rid="CIT0053">2004</xref>:262)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">-</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Young (<xref ref-type="bibr" rid="CIT0059">2008</xref>:3)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Waters (<xref ref-type="bibr" rid="CIT0056">2009</xref>:475)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
</tr>
<tr>
<td align="left">Tang and Musa (<xref ref-type="bibr" rid="CIT0050">2011</xref>:32)</td>
<td align="center">X</td>
<td align="center">-</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Islam et al. (<xref ref-type="bibr" rid="CIT0023">2012</xref>)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
</tr>
<tr>
<td align="left">Islam and Tedford (<xref ref-type="bibr" rid="CIT0022">2012</xref>:258)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
</tr>
<tr>
<td align="left">Johnson and Flynn (<xref ref-type="bibr" rid="CIT0024">2015</xref>:29)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">-</td>
<td align="center">X</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Chopra and Meindl (<xref ref-type="bibr" rid="CIT0008">2013</xref>:160)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Kim and Vonortas (<xref ref-type="bibr" rid="CIT0029">2014</xref>:457)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Lysons and Farrington (<xref ref-type="bibr" rid="CIT0034">2016</xref>:94)</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
<td align="center">X</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Because the majority of the authors listed in <xref ref-type="table" rid="T0002">Table 2</xref> categorised the risks into operational, market, technological and financial risks and the proposed framework concerns operational risk management, it is around these four categories of risks that the proposed operational risk management framework is built (<xref ref-type="fig" rid="F0002">Figure 2</xref>). Furthermore, to be effective, a risk assessment method needs to help identify potential risks in these four domains (Keizer et al. <xref ref-type="bibr" rid="CIT0028">2002</xref>:214), and these four domains can be adapted for SMEs (Kim &#x0026; Vonortas <xref ref-type="bibr" rid="CIT0029">2014</xref>:456). Each of these is briefly explained below.</p>
<fig id="F0002">
<label>FIGURE 2</label>
<caption><p>Operational risk management framework.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJEMS-20-1621-g002.tif"/>
</fig>
</sec>
<sec id="s30013">
<title>Operational risk</title>
<p>The operational risk deals with the internal organisation and management of the operations team for development, production, supply and distribution. Operational risk encompasses the production, warehousing, distribution, staff challenges, systems and the processes that the company uses (Islam &#x0026; Tedford <xref ref-type="bibr" rid="CIT0022">2012</xref>:258; Keizer et al. <xref ref-type="bibr" rid="CIT0028">2002</xref>:214; Young <xref ref-type="bibr" rid="CIT0059">2008</xref>:5). It is the uncertainty associated with supplier activities and relationships, poor quality, inventory risks and product demand among others (J&#x00FC;ttner <xref ref-type="bibr" rid="CIT0025">2005</xref>:123; Waters <xref ref-type="bibr" rid="CIT0056">2009</xref>:475).</p>
</sec>
<sec id="s30014">
<title>Market risk</title>
<p>The market risk refers to the market acceptance of the product, the potential actions of competitors and general market conditions. For example, understanding customer needs, who competitors are, the products they offer, their advantages and any potential and future competitors, the inability to identify future market needs, failure to design new products and retention of market share (Keizer et al. <xref ref-type="bibr" rid="CIT0028">2002</xref>:214; Kim &#x0026; Vonortas <xref ref-type="bibr" rid="CIT0029">2014</xref>:456; Waters <xref ref-type="bibr" rid="CIT0056">2009</xref>:478).</p>
</sec>
<sec id="s30015">
<title>Technical risk</title>
<p>This type of risk refers to product design, production technology and intellectual property. Under technical risks, the framework includes risks such as failure to identify, launch and design new products, which will result in a lack of growth and possible loss of market share (Keizer et al. <xref ref-type="bibr" rid="CIT0028">2002</xref>:214; Kim &#x0026; Vonortas <xref ref-type="bibr" rid="CIT0029">2014</xref>:456).</p>
</sec>
<sec id="s30016">
<title>Financial risk</title>
<p>This kind of risk refers to the tangible value investors lose if the business fails and to the financial aspects of a business (Kim &#x0026; Vonortas <xref ref-type="bibr" rid="CIT0029">2014</xref>:456). It is considered to be the risk associated with commercial and business performance (Islam &#x0026; Tedford <xref ref-type="bibr" rid="CIT0022">2012</xref>:259). It comprises all financial transactions, including payments, costs, prices, sourcing of funds, profit and loss to the company should legal claims be lodged and when a customer declares insolvency resulting in irrecoverable sales. It should also cover the customers&#x2019; debtors&#x2019; book (Waters <xref ref-type="bibr" rid="CIT0056">2009</xref>:478).</p>
</sec>
</sec>
<sec id="s20017">
<title>Importance of risk management</title>
<p>Turner and Keetelaar (<xref ref-type="bibr" rid="CIT0051">2005</xref>:13) remark that risk management should be viewed from three perspectives: (1) why businesses would want to implement risk management; (2) why businesses should implement risk management; and (3) why businesses have to implement risk management. Small businesses can expect many benefits from managing their risks such as: an improved understanding of the impact that management practices have on a business; increased competitive advantage; and increased efficiency and productivity (Scarborough et al. <xref ref-type="bibr" rid="CIT0041">2009</xref>:730; Smit <xref ref-type="bibr" rid="CIT0046">2012</xref>:20). Likewise, there are many reasons why a small business should implement risk management, such as protection of assets and the longer-term viability of the small business (Hoffmann et al. <xref ref-type="bibr" rid="CIT0018">2012</xref>:2; Sanders <xref ref-type="bibr" rid="CIT0039">2012</xref>:394). Lastly, there are legislative and regulatory requirements relating to risk management, for example, occupational health and safety legislation and fair-trading legislation (Scarborough et al. <xref ref-type="bibr" rid="CIT0041">2009</xref>:736; Turner &#x0026; Keetelaar <xref ref-type="bibr" rid="CIT0051">2005</xref>:13).</p>
<p>The responsibility of managing risk requires the development of a framework which is not too cautious or too reckless and which guides the owner-manager towards action or improvement (Cocca &#x0026; Alberti 2009:187). The framework must focus on the control of risk, the minimising of loss through prevention and avoidance and the exploitation of opportunities (Kim &#x0026; Vonortas <xref ref-type="bibr" rid="CIT0029">2014</xref>:456). The management of risk offers businesses a sustainable competitive advantage by optimising the risk and return (Andersen <xref ref-type="bibr" rid="CIT0001">2008</xref>:156; Kim &#x0026; Vonortas <xref ref-type="bibr" rid="CIT0029">2014</xref>:456; Smit &#x0026; Watkins <xref ref-type="bibr" rid="CIT0047">2012</xref>:6324; Verbano &#x0026; Venturini <xref ref-type="bibr" rid="CIT0054">2013</xref>:186). Though there are some existing frameworks on risk management, such as the risk management framework, the conceptualisation of risk management must be driven by the values and goals of the business (Kim &#x0026; Vonortas <xref ref-type="bibr" rid="CIT0029">2014</xref>:455). Dimopoulos et al. (<xref ref-type="bibr" rid="CIT0013">2004</xref>) acknowledge that there are tools available to assess risk. However, SMEs generally do not assess risk or, if they do, they do not assess the risks they are exposed to properly, leaving them in a vulnerable position (Islam &#x0026; Tedford <xref ref-type="bibr" rid="CIT0022">2012</xref>:3; Kagwathi et al. <xref ref-type="bibr" rid="CIT0026">2014</xref>:9).</p>
<p>Small and medium-sized enterprise owner-managers need a good understanding of risk identification and analysis in order to successfully manage risks. The adaption of a risk management framework for SMEs is key as by using this they will be better suited to assess and manage their risks, thus benefiting from their resources and yielding a positive return (Smit &#x0026; Watkins <xref ref-type="bibr" rid="CIT0047">2012</xref>:6324).</p>
</sec>
<sec id="s20018">
<title>Operational risk management framework</title>
<p><xref ref-type="fig" rid="F0002">Figure 2</xref> shows the proposed operational risk management framework that SMEs could use. This proposed framework is underpinned by and analysed into the four process steps of risk, namely <italic>risk identification, risk assessment, risk response-mitigation strategy</italic> and <italic>risk monitoring and control</italic>. These terms head the four main columns across the top of the proposed framework, and the rows down the left side of the framework detail the four broad risk categories of <italic>operational risks, market risks, technical risks</italic> and <italic>financial risks</italic>. The columns listing the four process steps are further analysed into subcategories as are the four risk categories down the left side of the model. The details of the risk process steps, covering the various risk categories, are outlined below, to explain the construct of <xref ref-type="fig" rid="F0002">Figure 2</xref>.</p>
</sec>
<sec id="s20019">
<title>Risk identification</title>
<p>This is the first key step for identifying and understanding the possible risk sources. To add depth to this process stage, the <italic>risk identification column</italic> has been split into three sub-columns of <italic>objective, description of risk</italic> and <italic>responsible person</italic>. The objective column will assist in identifying the broad business issue, the description column defines the specific risk and the responsible person column defines the responsibility for managing and mitigating the risk. This feature will be explained in more detail later.</p>
<p>As can be seen in the rows of the framework, each potential risk area of the business, namely operational, market, technical and financial risks, is listed.</p>
<p>The first broad category of risk is <italic>operational risks</italic>. Operational risks encompass the various operational activities within the SME, including production, warehousing and distribution. The second risk category, after operational risks, is <italic>market risks</italic>. This includes risks such as understanding customer needs, future market needs, new opportunities and market share. The third risk category is <italic>technical risks</italic> and includes risks such as the current product range design, which can result in loss of position in the market and failure to identify, launch and design new products, which will result in a lack of growth and possible loss of market share. Finally, the fourth risk category is <italic>financial risks</italic>. These risks may have legal and other implications for the SME. For example, legal risks could include loss to the company should legal claims be lodged and/or, if a customer declares insolvency, it could result in irrecoverable sales and financial losses.</p>
<p>It must be pointed out that these risk categories are suggestions and that they would differ from SME to SME depending on the size and type of business. It is suggested that a cross-functional team be formed within the SME to discuss the objectives of the SME&#x2019;s operations and identify potential operational risks. It is for this reason that in this proposed framework some generic risks are presented as examples that SMEs could use.</p>
<p>By way of explaining <xref ref-type="fig" rid="F0002">Figure 2</xref>, the category of <italic>operational risk</italic> has been split into the key operational activities of <italic>production, warehousing</italic> and <italic>distribution</italic>. Production risks consist of risks that will impact on the production of the SME. These include supplier risks regarding quality and pricing, inventory risks, process risks, downtime risks and quality risks. Even though the list of production risks is not exhaustive, these risks have the possibility of reducing competitiveness and may have financial implications for the SME. The risks that come under <italic>warehousing</italic> include sending products from the site to warehouse, holding slow-moving stock and protecting and safeguarding stock. Under <italic>distribution</italic> are included risks such as accurate stock picking, effective control of stock and the transport of goods.</p>
<p>In order to explain the risk management process and the use shown in <xref ref-type="fig" rid="F0002">Figure 2</xref>, let us assume that a cross-functional team of key employees within the SME is undertaking this risk assessment or identification process. Under the heading of <italic>production risk</italic>, the team would note the key potential business or operational issues that could negatively affect the production environment. The team would look at these issues from an objective or desired outcome perspective and create a positive statement that the SME would want to achieve in the production area. The idea here is that, if the SME achieved this objective or outcome, then any risk that could negatively impact on the outcome would have been eliminated or at least mitigated against. This becomes the measure against which the risk is gauged. In the example shown above of the operational category of <italic>production</italic> risk, a positive outcome or objective of s<italic>ource quality materials at competitive prices</italic> could be listed. The question to be asked of the cross-functional team is what the likelihood of this objective being achieved is and, if it cannot be achieved, what the issues are leading to its non-achievement. The identification of these issues results in a listing of the negative risks to be detailed under the <italic>description of risk</italic> column. An example of this risk could be the naming of a particular key raw material which is vital for the SME to produce a quality finished product. If the quality of this raw material from a supplier has in the past been variable, then this is a key risk to the business or, if the supplier has proven to be one that is unreliable from an on-time delivery basis, then again this is a risk. If the supplier is in the habit of increasing his prices based on, for example, a fluctuating exchange rate, meaning that he does not take forward cover for his inputs, then again, the SME could face risk exposure, this time from a cost basis.</p>
<p>For explanatory purposes, let us assume that the issue of risk that will detract from the SME achieving the objective or positive outcome of s<italic>ource quality materials at competitive prices</italic> is a key raw material supplier RM Steel who provides a raw material of variable quality 30&#x0025; of the time. In this example, the actual risk to be listed in column 2, alongside the objective of s<italic>ource quality materials at competitive prices</italic> would be &#x2018;variable raw material quality from RM Steel&#x2019;.</p>
<p>The next and final step in the <italic>identification</italic> process is the nomination of the <italic>responsible person</italic> and this detail would be inserted in the third column. As the problem is related to the supply of raw materials, the buyer&#x2019;s name would be placed in this third column.</p>
<p>In this way, we have the objective or desired outcome listed in column one, the actual risk detailed in column two (there could be a number of risks related to the one objective) and, finally, the name of the individual who is responsible for managing and monitoring the particular risk. In the example of <italic>source quality materials at competitive prices</italic>, this could be the buyer. This is a key issue as it is important that someone within the SME takes ownership of achieving the positive outcome or objective, and of managing and mitigating the risks, or the risk management exercise will be futile.</p>
<p>The three subheadings of <italic>objective, description of risk</italic> and <italic>responsible person</italic> represent the first step of the risk process, namely <italic>risk identification</italic>. The cross-functional team will now move to the next section, which is <italic>risk assessment</italic>, or risk priority.</p>
</sec>
<sec id="s20020">
<title>Risk assessment</title>
<p>The first column under the risk framework of <italic>risk assessment</italic> deals with the <italic>severity rating</italic> of the identified risk. Here the risks are subcategorised according to the impact that the risk may have on the various aspects of the business, such as finances, health and safety, the natural environment and the reputation of the SME or the possible legal consequences (Ho et al. <xref ref-type="bibr" rid="CIT0017">2015</xref>:44; Hoffmann et al. <xref ref-type="bibr" rid="CIT0018">2012</xref>:4; Kannan &#x0026; Martin <xref ref-type="bibr" rid="CIT0027">2016</xref>:33). The risks are then ranked on a <italic>severity rating</italic> scale from 1 to 10, with a 10 being of the highest severity. There could be many risks attached to any one objective. Examples are &#x2018;delayed supply&#x2019;, &#x2018;current supplier is unable to supply&#x2019;, &#x2018;quality of materials&#x2019;, &#x2018;uncompetitive price&#x2019; among others. In the example being explained under the first objective, <italic>source quality materials at competitive prices</italic>, the issue of &#x2018;variable raw material quality from RM&#x2019; has been listed. This could have severe financial implications for the SME, as the final product produced by the SME using the materials from RM could be sub-standard, resulting in returns to the SME and financial loss. This issue could also negatively impact on the reputation of the company, which could in turn have financial and legal implications. Further, it could impact on health and safety and the natural environment. However, because the severity rating may not be equally severe on all the business aspects, in our example the following ratings are assigned: <italic>financial</italic> (8), <italic>health and safety</italic> (1), <italic>natural environment</italic> (1), <italic>reputation</italic> (8) and <italic>legal</italic> (4). These ratings are then combined as follows:</p>
<p>8 + 1 + 1 + 8 + 4 = 22.</p>
<p>The third column under <italic>risk assessment</italic> deals with the probability rating given to each risk. The SMEs must determine, on a scale from 1 to 10, the likelihood of this risk occurring. A score of 10 will be relative to a risk being probable. So, with regard to our previous example, what is the risk probability of receiving poor quality materials? It would depend on the supplier, but, for the sake of this example, the probability of this risk occurring might not be that severe. Let us say that the cross-functional team decides that 30&#x0025; of the time the quality of the raw material receipts is below standard; they could assess that there is a probability of 3 out of 10 chances of it happening.</p>
<p>The last column under <italic>risk assessment</italic> scores the risk. In our example, the total of the severity risk rating is 22 and the probability of the risk occurring is 3. The severity risk rating is then multiplied by the probability rating as follows:</p>
<p>22 &#x00D7; 3 = 66</p>
<p>Sixty-six is the total score. The higher the score, the higher the perception that the risk is likely to happen and impact on the business. Each risk must be scored accordingly. The scores will highlight the more severe risks. This completes the risk assessment portion of the process.</p>
</sec>
<sec id="s20021">
<title>Risk response (mitigation)</title>
<p>The third step in the risk process framework presents the <italic>risk response-mitigation strategy</italic>. Once each potential risk is scored, these should be sorted and ranked from top to bottom. The cross-functional team of the SME can then work their way down the list from more severe to less severe risks. It will be the responsibility of the cross-functional team to score all the risks identified and to deal with the highest scoring or most severe risks first.</p>
<p>In our example, let us assume a score of 66 would lift this risk to the top of the value scale, meaning it would be viewed as a key risk requiring attention. The goal of the cross-functional team is to then look at what existing controls are in place and the additional measures needed to be implemented in order to mitigate the more severe risks. In our example, the buyer has been assigned the responsibility for managing the risk. In the open forum of the cross-functional team meeting, a discussion should take place and the buyer would be asked for his input or what his risk-mitigation strategy will actually be.</p>
<p>An obvious point would be for the buyer to contact RM and to raise the SME&#x2019;s concern with this supplier. This would be risk-mitigation step one. Step two of the risk-mitigation strategy would be for the buyer to visit the RM with the SME&#x2019;s quality controller to undertake a quality process audit on the production process to ensure that RM&#x2019;s processes and procedures are under control and to check for consistency and repeatability, which is obviously lacking as problems arise 30&#x0025; of the time. Such an audit could identify system or process weaknesses, which the SME would insist that RM addresses. Step three could be for the buyer to instruct the quality controller to conduct incoming quality checks of the incoming raw material from the supplier RM and to reject any product that does not conform. Key to the success of the process is for the cross-functional team to be satisfied that the steps identified by the buyer will mitigate against the identified risks.</p>
</sec>
<sec id="s20022">
<title>Risk monitoring and control</title>
<p>Using this process in relation to various production objectives, identifying risk types and scoring these risks will complete the final column of the risk framework. This is the fourth and final step. Chang et al. (<xref ref-type="bibr" rid="CIT0006">2015</xref>:55) and Wagner and Bode (<xref ref-type="bibr" rid="CIT0055">2008</xref>:311) maintain that the monitoring of risks is important, because it can provide an early warning of increasing risk levels, thus giving the SME time to react to these changes and to formulate and/or adapt mitigation strategies.</p>
<p>In the example shown in <xref ref-type="fig" rid="F0002">Figure 2</xref>, the results of the actions taken against risk-mitigation strategy steps 1 to 3 as identified above would be written up in this column. This is done once the various actions have been completed and provides feedback to the cross-functional team, evidence that positive mitigating action steps have been taken. It is recommended that the risk management cross-functional team meets at least twice a year, which gives the various responsible individuals time to complete the mitigating action steps. At the next meeting of this team, a follow-up review of the risks should take place, and the team will be asked to re-evaluate the revised risk and rescore each identified risk, overwriting the original rating values. In our example, the original score of 66 will also be noted in the <italic>risk monitoring and control</italic> column, in order that the progress on the risk strategies can be monitored and progress confirmed. This may be compared with the new revised risk assessment score. This process is key to closing the risk management &#x2018;loop&#x2019; and to ensure forward progress and momentum.</p>
<p>It should be noted that the example outlined to explain <xref ref-type="fig" rid="F0002">Figure 2</xref> has assumed an SME with a number of employees and functional responsibilities, hence the possibility of a cross-functional team. The model could equally apply to a smaller operation with, for example, the cross-functional team comprising the owner and just one or two employees, such as the production supervisor and the bookkeeper. The benefit of the process of using cross-functionality is not relative to there being highly skilled functional department heads but is rather about individuals who know the SME and its functioning and who understand the risks that such an operation actually faces.</p>
<p><xref ref-type="fig" rid="F0002">Figure 2</xref> presents the proposed operataional risk management framework.</p>
<p>It is suggested that the proposed framework complies with the requirements of scholars who specify that a risk management framework must focus on identifying risks, measuring the probability of the impact of risks, mitigating the risks and monitoring and controlling the risks (Chang et al. <xref ref-type="bibr" rid="CIT0006">2015</xref>:55; Sharma and Bhat <xref ref-type="bibr" rid="CIT0044">2014</xref>:26; Wagner and Bode <xref ref-type="bibr" rid="CIT0055">2008</xref>:311; Waters <xref ref-type="bibr" rid="CIT0056">2009</xref>:477). The proposed framework differs from the standard risk management process in that it includes the categories of risks and also includes the responsible person and a severity and probability rating to score each risk.</p>
</sec>
</sec>
<sec id="s0023">
<title>Conclusion</title>
<p>Operational risk can be defined as the risk of loss as a direct consequence of inadequate or failed processes, people and systems because of external events (GARP <xref ref-type="bibr" rid="CIT0014">2014</xref>:41). The business environment is dynamic and competitive, and businesses face a number of risks that threaten to reduce productivity and to increase costs and liabilities, thus negatively impacting the bottom line. Therefore, risk assessment is necessary for all businesses, including SMEs. It is vital that entrepreneurs can identify and mitigate potential risks as failure to do so could result in reduced productivity or even bankruptcy. Within this context, the aim of this article has been to present an operational risk management framework that SMEs can use to assess and manage their risks. The various types of operational risks were explored and are embedded in this proposed framework.</p>
<p>The limitation of this study is that even though the proposed framework can be used as a tool to identify, assess, mitigate and manage or control the risks of SMEs, the framework has not been tested. It is proposed that it be tested in a future study to determine whether the model is valuable and useful for SMEs.</p>
<p>There is a lack of research dealing with operational risk frameworks for SMEs (Verbano &#x0026; Venturine <xref ref-type="bibr" rid="CIT0054">2013</xref>:8); therefore, the expected contribution of this article is twofold. Firstly, it is envisaged that managers or owners of SMEs could use the proposed framework as a tool to appraise and minimise their operational risks. Secondly, it adds to the current body of knowledge of risk appraisal for SMEs. As stated by Theodore Roosevelt, &#x2018;Risk is like fire: if controlled it will help you; if uncontrolled it will rise up and destroy you&#x2019;.</p>
</sec>
</body>
<back>
<ack>
<title>Acknowledgements</title>
<p>We acknowledge that this is our own work and all sources we have used or quoted have been indicated and acknowledged by means of complete references.</p>
<sec id="s20024" sec-type="COI-statement">
<title>Competing interests</title>
<p>The authors declare that they have no financial or personal relationship(s) which may have inappropriately influenced them in writing this article.</p>
</sec>
<sec id="s20025">
<title>Authors&#x2019; contributions</title>
<p>M.J.N. was the project leader, made conceptual contributions and finalised the article. N.C. collected and analysed the secondary data and wrote up the literature review.</p>
</sec>
</ack>
<ref-list id="references">
<title>References</title>
<ref id="CIT0001"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Andersen</surname>, <given-names>T.J</given-names></string-name></person-group>., <year>2008</year>, &#x2018;<article-title>The performance relationship of effective risk management: Exploring the firm-specific investment rationale</article-title>&#x2019;, <source><italic>Long Range Plan</italic></source> <volume>41</volume>(<issue>2</issue>), <fpage>155</fpage>&#x2013;<lpage>176</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.lrp.2008.01.002">https://doi.org/10.1016/j.lrp.2008.01.002</ext-link></comment></mixed-citation></ref>
<ref id="CIT0002"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Aven</surname>, <given-names>T</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Risk assessment and risk management: Review of recent advances on their foundation</article-title>&#x2019;, <source><italic>European Journal of Operational Research</italic></source> <volume>253</volume>, <fpage>1</fpage>&#x2013;<lpage>13</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ejor.2015.12.023">https://doi.org/10.1016/j.ejor.2015.12.023</ext-link></comment></mixed-citation></ref>
<ref id="CIT0003"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Benton</surname>, <given-names>W.C</given-names></string-name></person-group>., <year>2014</year>, <source><italic>Supply chain focused manufacturing planning and control</italic></source>, <publisher-name>Cengage Learning</publisher-name>, <publisher-loc>Melbourne</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0004"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Blanc-Alquier</surname>, <given-names>A.M</given-names></string-name>. &#x0026; <string-name><surname>Lagasse-Tignol</surname>, <given-names>M.H</given-names></string-name></person-group>., <year>2006</year>, &#x2018;<article-title>Risk management in small- and medium-sized enterprises</article-title>&#x2019;, <source><italic>Production Planning and Control: The Management of Operations</italic></source> <volume>17</volume>(<issue>3</issue>), <fpage>273</fpage>&#x2013;<lpage>282</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/09537280500285334">https://doi.org/10.1080/09537280500285334</ext-link></comment></mixed-citation></ref>
<ref id="CIT0005"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Blome</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Schoenherr</surname>, <given-names>T</given-names></string-name>. &#x0026; <string-name><surname>Eckstein</surname>, <given-names>D</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>The impact of knowledge transfer and complexity on supply chain flexibility: A knowledge-based view</article-title>&#x2019;, <source><italic>International Journal of Production Economics</italic></source> <volume>147</volume>, <fpage>307</fpage>&#x2013;<lpage>316</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ijpe.2013.02.028">https://doi.org/10.1016/j.ijpe.2013.02.028</ext-link></comment></mixed-citation></ref>
<ref id="CIT0006"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chang</surname>, <given-names>C.H</given-names></string-name>., <string-name><surname>Jingjing Xu</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Song</surname>, <given-names>D.P</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Risk analysis for container shipping: From a logistics perspective</article-title>&#x2019;, <source><italic>The International Journal of Logistics Management</italic></source> <volume>26</volume>(<issue>1</issue>), <fpage>147</fpage>&#x2013;<lpage>171</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/IJLM-07-2012-0068">https://doi.org/10.1108/IJLM-07-2012-0068</ext-link></comment></mixed-citation></ref>
<ref id="CIT0007"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cheng</surname>, <given-names>S.K</given-names></string-name>. &#x0026; <string-name><surname>Kam</surname>, <given-names>B.H</given-names></string-name></person-group>., <year>2008</year>, &#x2018;<article-title>A conceptual framework for analysing risk in supply networks</article-title>&#x2019;, <source><italic>Journal of Enterprise Information</italic></source> <volume>22</volume>(<issue>4</issue>), <fpage>345</fpage>&#x2013;<lpage>360</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/17410390810888642">https://doi.org/10.1108/17410390810888642</ext-link></comment></mixed-citation></ref>
<ref id="CIT0008"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Chopra</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Meindl</surname>, <given-names>P</given-names></string-name></person-group>., <year>2013</year>, <source><italic>Supply chain management: Strategy planning and operation</italic></source>, <edition>5th edn</edition>., <publisher-name>Pearson</publisher-name>, <publisher-loc>Boston, MA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0009"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cocca</surname>, <given-names>P</given-names></string-name>. &#x0026; <string-name><surname>Alberti</surname>, <given-names>M</given-names></string-name></person-group>., <year>2010</year>, &#x2018;<article-title>A framework to assess performance measurements systems in SMEs</article-title>&#x2019;, <source><italic>International Journal of Productivity and Performance Management</italic></source> <volume>59</volume>(<issue>2</issue>), <fpage>186</fpage>&#x2013;<lpage>200</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/17410401011014258">https://doi.org/10.1108/17410401011014258</ext-link></comment></mixed-citation></ref>
<ref id="CIT0010"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cucchiell</surname>, <given-names>A.F</given-names></string-name>. &#x0026; <string-name><surname>Gastaldi</surname>, <given-names>M</given-names></string-name></person-group>., <year>2006</year>, &#x2018;<article-title>Risk management in supply chain: A real option approach</article-title>&#x2019;, <source><italic>Journal of Manufacturing Technology Management</italic></source> <volume>17</volume>(<issue>6</issue>), <fpage>700</fpage>&#x2013;<lpage>720</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/17410380610678756">https://doi.org/10.1108/17410380610678756</ext-link></comment></mixed-citation></ref>
<ref id="CIT0011"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>Davis Tax Committee</collab></person-group>, <year>2014</year>, <source><italic>Small and medium enterprises: Taxation considerations</italic></source>, <comment>Interim report, viewed 27 October 2014, from <ext-link ext-link-type="uri" xlink:href="http://www.taxcom.org.za/docs/DTC&#x0025;20SME&#x0025;20Report&#x0025;20for&#x0025;20Public&#x0025;20Comment&#x0025;20by&#x0025;2011&#x0025;20July&#x0025;202014.pdf">http://www.taxcom.org.za/docs/DTC&#x0025;20SME&#x0025;20Report&#x0025;20for&#x0025;20Public&#x0025;20Comment&#x0025;20by&#x0025;2011&#x0025;20July&#x0025;202014.pdf</ext-link></comment></mixed-citation></ref>
<ref id="CIT0012"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dempster</surname>, <given-names>A.M</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>An operational risk framework for the performing arts and creative industries</article-title>&#x2019;, <source><italic>Creative Industries Journal</italic></source> <volume>12</volume>, <fpage>151</fpage>&#x2013;<lpage>170</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1386/cij.1.2.151_1">https://doi.org/10.1386/cij.1.2.151_1</ext-link></comment></mixed-citation></ref>
<ref id="CIT0013"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Dimopoulos</surname>, <given-names>V</given-names></string-name>., <string-name><surname>Furnell</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Barlow</surname>, <given-names>I</given-names></string-name>. &#x0026; <string-name><surname>Lines</surname>, <given-names>B</given-names></string-name></person-group>., <year>2004</year>, &#x2018;<article-title>Factors affecting the adoption of IT risk analysis</article-title>&#x2019;, in <conf-name>Proceedings of the 3rd European Conference on Information Warfare and Security</conf-name>, <conf-loc>University of London, London</conf-loc>, <conf-date>June 28&#x2013;29, 2004</conf-date>, pp. <fpage>267</fpage>&#x2013;<lpage>283</lpage>.</mixed-citation></ref>
<ref id="CIT0014"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>Global Association of Risk Professionals (GARP)</collab></person-group>, <year>2014</year>, &#x2018;<article-title>Chapter 12 &#x2013; Operational risk</article-title>&#x2019;, in <source><italic>The GARP risk series operational risk management</italic></source>, <comment>viewed 05 September 2014, from <ext-link ext-link-type="uri" xlink:href="http://www.garp.org/media/673303/operational&#x0025;20risk&#x0025;20slides.pdf">http://www.garp.org/media/673303/operational&#x0025;20risk&#x0025;20slides.pdf</ext-link></comment></mixed-citation></ref>
<ref id="CIT0015"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hallikas</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Lintukangas</surname>, <given-names>K</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Purchasing and supply: An investigation of risk management performance</article-title>&#x2019;, <source><italic>International Journal of Production Economics</italic></source> <volume>171</volume>, <fpage>487</fpage>&#x2013;<lpage>494</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ijpe.2015.09.013">https://doi.org/10.1016/j.ijpe.2015.09.013</ext-link></comment></mixed-citation></ref>
<ref id="CIT0016"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Harland</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Brenchely</surname>, <given-names>R</given-names></string-name>. &#x0026; <string-name><surname>Walker</surname>, <given-names>H</given-names></string-name></person-group>., <year>2003</year>, &#x2018;<article-title>Risk in supply networks</article-title>&#x2019;, <source><italic>Journal of Purchasing &#x0026; Supply Management</italic></source> <volume>9</volume>, <fpage>51</fpage>&#x2013;<lpage>62</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/S1478-4092(03)00004-9">https://doi.org/10.1016/S1478-4092(03)00004-9</ext-link></comment></mixed-citation></ref>
<ref id="CIT0017"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ho</surname>, <given-names>W</given-names></string-name>., <string-name><surname>Zheng</surname>, <given-names>T</given-names></string-name>., <string-name><surname>Yildiz</surname>, <given-names>H</given-names></string-name>. &#x0026; <string-name><surname>Talluri</surname>, <given-names>S</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Supply chain risk management: A literature review</article-title>&#x2019;, <source><italic>International Journal of Production Research</italic></source> <volume>53</volume>, <fpage>5031</fpage>&#x2013;<lpage>5069</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/00207543.2015.1030467">https://doi.org/10.1080/00207543.2015.1030467</ext-link></comment></mixed-citation></ref>
<ref id="CIT0018"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Hoffmann</surname>, <given-names>P</given-names></string-name>., <string-name><surname>Schiele</surname>, <given-names>H</given-names></string-name>. &#x0026; <string-name><surname>Krabbendam</surname>, <given-names>K.J</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>Uncertainty, supply risk management principles and the impact on performance</article-title>&#x2019;, in <conf-name>21st Annual IPSERA Conference</conf-name>, <conf-loc>Naples, Italy</conf-loc>, <conf-date>April 1&#x2013;4</conf-date>, pp. <fpage>1</fpage>&#x2013;<lpage>16</lpage>.</mixed-citation></ref>
<ref id="CIT0019"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Hopkins</surname>, <given-names>P</given-names></string-name></person-group>., <year>2017</year>, <source><italic>The fundamentals of risk management</italic></source>, <edition>4th edn</edition>., <publisher-name>Logan Page</publisher-name>, <publisher-loc>London</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0020"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Hugo</surname>, <given-names>W.M.J</given-names></string-name>. &#x0026; <string-name><surname>Badenhorst-Weiss</surname>, <given-names>J.A</given-names></string-name></person-group>., <year>2011</year>, <source><italic>Purchasing and supply management</italic></source>, <edition>6th edn</edition>., <publisher-name>Van Schaik</publisher-name>, <publisher-loc>Pretoria</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0021"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>International Organization for Standardization (ISO)</collab></person-group>, <year>2009</year>. <source><italic>Risk management &#x2013; Vocabulary</italic></source>, <comment>Guide 73-2009, viewed 04 August 2017, from <ext-link ext-link-type="uri" xlink:href="https://www.iso.org/standard/44651.html">https://www.iso.org/standard/44651.html</ext-link></comment></mixed-citation></ref>
<ref id="CIT0022"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Islam</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Tedford</surname>, <given-names>D</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>Risk determinants of small and medium-sized manufacturing enterprises (SMEs) &#x2013; An exploratory study in New Zealand</article-title>&#x2019;, <source><italic>Journal of Industrial Engineering International</italic></source> <volume>8</volume>, <fpage>12</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1186/2251-712X-8-12">https://doi.org/10.1186/2251-712X-8-12</ext-link></comment></mixed-citation></ref>
<ref id="CIT0023"><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><surname>Islam</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Tedford</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Haemmerle</surname>, <given-names>E</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>Risk determinants of small and medium-sized manufacturing enterprises (SMEs) &#x2013; An empirical investigation in New Zealand</article-title>&#x2019;, <comment>viewed 03 August 2017, from <ext-link ext-link-type="uri" xlink:href="http://www.anzam.org/wp-content/uploads/pdf-manager/1874_ISLAMMD_235.PDF">http://www.anzam.org/wp-content/uploads/pdf-manager/1874_ISLAMMD_235.PDF</ext-link></comment></mixed-citation></ref>
<ref id="CIT0024"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Johnson</surname>, <given-names>P.F</given-names></string-name> &#x0026; <string-name><surname>Flynn</surname>, <given-names>A.E</given-names></string-name></person-group>., <year>2015</year>, <source><italic>Purchasing and supply management</italic></source>, <edition>15th edn</edition>., <publisher-name>McGraw-Hill</publisher-name>, <publisher-loc>Boston, MA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0025"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>J&#x00FC;ttner</surname>, <given-names>U</given-names></string-name></person-group>., <year>2005</year>, &#x2018;<article-title>Supply chain risk management: Understanding the business requirements from a practitioner perspective</article-title>&#x2019;, <source><italic>The International Journal of Logistics Management</italic></source> <volume>16</volume>(<issue>1</issue>), <fpage>120</fpage>&#x2013;<lpage>141</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/09574090510617385">https://doi.org/10.1108/09574090510617385</ext-link></comment></mixed-citation></ref>
<ref id="CIT0026"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kagwathi</surname>, <given-names>G.S</given-names></string-name>., <string-name><surname>Kamau</surname>, <given-names>J.N</given-names></string-name>., <string-name><surname>Njau</surname>, <given-names>M.M</given-names></string-name>. &#x0026; <string-name><surname>Kamau</surname>, <given-names>S.M</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>Risks faced and mitigation strategies employed by small and medium enterprises in Nairobi, Kenya</article-title>&#x2019;, <source><italic>Journal of Business and Management</italic></source> <volume>16</volume>(<issue>4</issue>), <fpage>1</fpage>&#x2013;<lpage>11</lpage>.</mixed-citation></ref>
<ref id="CIT0027"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kannan</surname>, <given-names>G</given-names></string-name>. &#x0026; <string-name><surname>Martin</surname>, <given-names>B.J</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Supplier risk assessment based on trapezoidal intuitionistic fuzzy numbers and Electre Tri-C: A case illustration involving service suppliers</article-title>&#x2019;, <source><italic>Journal of the Operational Research Society</italic></source> <volume>67</volume>, <fpage>339</fpage>&#x2013;<lpage>376</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1057/jors.2015.51">https://doi.org/10.1057/jors.2015.51</ext-link></comment></mixed-citation></ref>
<ref id="CIT0028"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Keizer</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Halman</surname>, <given-names>J.I.M</given-names></string-name>. &#x0026; <string-name><surname>Song</surname>, <given-names>M</given-names></string-name></person-group>., <year>2002</year>, &#x2018;<article-title>From experience: Applying the risk diagnosing methodology</article-title>&#x2019;, <source><italic>Journal of Product Innovation Management</italic></source> <volume>19</volume>, <fpage>213</fpage>&#x2013;<lpage>232</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1111/1540-5885.1930213">https://doi.org/10.1111/1540-5885.1930213</ext-link></comment></mixed-citation></ref>
<ref id="CIT0029"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kim</surname>, <given-names>Y</given-names></string-name>. &#x0026; <string-name><surname>Vonortas</surname>, <given-names>N.S</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>Managing risk in the formative years: Evidence in the formative years: Evidence from young enterprises in Europe</article-title>&#x2019;, <source><italic>Technovation</italic></source> <volume>34</volume>, <fpage>454</fpage>&#x2013;<lpage>465</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.technovation.2014.05.004">https://doi.org/10.1016/j.technovation.2014.05.004</ext-link></comment></mixed-citation></ref>
<ref id="CIT0030"><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><surname>King</surname>, <given-names>K</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>Institute of directors Southern Africa</article-title>&#x2019;, <comment>viewed 03 August 2017, from <ext-link ext-link-type="uri" xlink:href="http://c.ymcdn.com/sites/www.iodsa.co.za/resource/resmgr/king_iii/King_Report_on_Governance_fo.pdf">http://c.ymcdn.com/sites/www.iodsa.co.za/resource/resmgr/king_iii/King_Report_on_Governance_fo.pdf</ext-link></comment></mixed-citation></ref>
<ref id="CIT0031"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kodithuwakku</surname>, <given-names>C.E</given-names></string-name>. &#x0026; <string-name><surname>Wickramarachchi</surname>, <given-names>D.N</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Identifying the risk dynamics of supply chain operations in large scale apparel industry in Sri Lanka</article-title>&#x2019;, <source><italic>International Journal of Innovation, Management and Technology</italic></source> <volume>6</volume>, <fpage>272</fpage>&#x2013;<lpage>277</lpage>.</mixed-citation></ref>
<ref id="CIT0032"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lavastre</surname>, <given-names>O</given-names></string-name>., <string-name><surname>Gunasekaran</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Spalanzani</surname>, <given-names>A</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>Supply chain risk management in French companies</article-title>&#x2019;, <source><italic>Decision Support Systems</italic></source> <volume>52</volume>(<issue>4</issue>), <fpage>828</fpage>&#x2013;<lpage>838</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.dss.2011.11.017">https://doi.org/10.1016/j.dss.2011.11.017</ext-link></comment></mixed-citation></ref>
<ref id="CIT0033"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Zeng</surname>, <given-names>W</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>Risk analysis for the supplier selection problem using failure modes and effects analysis (FMEA)</article-title>&#x2019;, <source><italic>Journal of Intelligent Manufacturing</italic></source> <volume>27</volume>(<issue>6</issue>), <fpage>1309</fpage>&#x2013;<lpage>1321</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s10845-014-0953-0">https://doi.org/10.1007/s10845-014-0953-0</ext-link></comment></mixed-citation></ref>
<ref id="CIT0034"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Lysons</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Farrington</surname>, <given-names>B</given-names></string-name></person-group>., <year>2016</year>, <source><italic>Procurement and supply chain management</italic></source>, <edition>9th edn</edition>., <publisher-name>Pearson</publisher-name>, <publisher-loc>Boston, MA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0035"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Michalski</surname>, <given-names>G</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>Inventory management optimisation as part of operational risk management</article-title>&#x2019;, <source><italic>Economic Computation and Economic Cybernetics Studies and Research</italic></source> <volume>43</volume>(<issue>4</issue>), <fpage>213</fpage>&#x2013;<lpage>222</lpage>.</mixed-citation></ref>
<ref id="CIT0036"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Monczka</surname>, <given-names>R.M</given-names></string-name>., <string-name><surname>Handfield</surname>, <given-names>R.B</given-names></string-name>, <string-name><surname>Giunipero</surname>, <given-names>L.C</given-names></string-name>. &#x0026; <string-name><surname>Patterson</surname>, <given-names>J.L</given-names></string-name></person-group>., <year>2016</year>, <source><italic>Purchasing &#x0026; supply chain management</italic></source>, <edition>6th edn</edition>., <publisher-name>Cengage Learning</publisher-name>, <publisher-loc>Melbourne</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0037"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Nieuwenhuizen</surname>, <given-names>C</given-names></string-name></person-group>., <year>2007</year>, <source><italic>Business management for entrepreneurs</italic></source>, <publisher-name>Juta</publisher-name>, <publisher-loc>Cape Town</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0038"><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><surname>Radebe</surname>, <given-names>P</given-names></string-name></person-group>., <year>2014</year>, <source><italic>Small business is the missing middle in banks&#x2019; service target</italic></source>, <comment>viewed 27 October 2014, from <ext-link ext-link-type="uri" xlink:href="http://www.finmark.org.za/finscope/publication/small-business-is-the-missing-middle-in-banks-service-target">http://www.finmark.org.za/finscope/publication/small-business-is-the-missing-middle-in-banks-service-target</ext-link></comment></mixed-citation></ref>
<ref id="CIT0039"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Sanders</surname>, <given-names>N.R</given-names></string-name></person-group>., <year>2012</year>, <source><italic>Supply chain management: A global perspective</italic></source>, <publisher-name>John Wiley &#x0026; Sons</publisher-name>, <publisher-loc>Hoboken, NJ</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0040"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>Sanlam Financial Services</collab></person-group>, <year>2014</year>, <source><italic>Economic overview April 2014: Pravin Gordhan promotes SME development</italic></source>, <comment>viewed 27 October 2014, from <ext-link ext-link-type="uri" xlink:href="http://southafrica.smetoolkit.org/sa/en/content/en/56030/Economic-Overview-April-2014-&#x0025;E2&#x0025;94&#x0025;80-Pravin-Gordhan-promotes-SME-development">http://southafrica.smetoolkit.org/sa/en/content/en/56030/Economic-Overview-April-2014-&#x0025;E2&#x0025;94&#x0025;80-Pravin-Gordhan-promotes-SME-development</ext-link></comment></mixed-citation></ref>
<ref id="CIT0041"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Scarborough</surname>, <given-names>N.M</given-names></string-name>., <string-name><surname>Wilson</surname>, <given-names>D.L</given-names></string-name>. &#x0026; <string-name><surname>Zimmerer</surname>, <given-names>T.W</given-names></string-name></person-group>., <year>2009</year>, <source><italic>Effective small business management: An entrepreneurial approach</italic></source>, <edition>9th edn</edition>., <publisher-name>Pearson Education</publisher-name>, <publisher-loc>London</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0042"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Sekaran</surname>, <given-names>U</given-names></string-name>. &#x0026; <string-name><surname>Bougie</surname>, <given-names>P</given-names></string-name></person-group>., <year>2016</year>, <source><italic>Research methods for business: A skill building approach</italic></source>, <edition>7th edn</edition>., <publisher-name>Wiley</publisher-name>, <publisher-loc>Chichester</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0043"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Servaes</surname>, <given-names>H</given-names></string-name>., <string-name><surname>Tamayo</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Tufano</surname>, <given-names>P</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>The theory and practice of corporate risk management</article-title>&#x2019;, <source><italic>Journal of Applied Corporate Finance</italic></source> <volume>21</volume>(<issue>4</issue>), <fpage>60</fpage>&#x2013;<lpage>78</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1111/j.1745-6622.2009.00250.x">https://doi.org/10.1111/j.1745-6622.2009.00250.x</ext-link></comment></mixed-citation></ref>
<ref id="CIT0044"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sharma</surname>, <given-names>S.K</given-names></string-name>. &#x0026; <string-name><surname>Bhat</surname>, <given-names>A</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>Supply chain risk management dimensions in Indian automobile industry</article-title>&#x2019;, <source><italic>Benchmarking: An International Journal</italic></source> <volume>21</volume>(<issue>6</issue>), <fpage>1023</fpage>&#x2013;<lpage>1040</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/BIJ-02-2013-0023">https://doi.org/10.1108/BIJ-02-2013-0023</ext-link></comment></mixed-citation></ref>
<ref id="CIT0045"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Simchi-Levi</surname>, <given-names>D</given-names></string-name>., <string-name><surname>Kaminsky</surname>, <given-names>P</given-names></string-name>. &#x0026; <string-name><surname>Simchi-Levi</surname>, <given-names>E</given-names></string-name></person-group>., <year>2008</year>, <source><italic>Designing and managing the supply chain: Concepts, strategies and case studies</italic></source>, <edition>3rd edn</edition>., <publisher-name>McGraw-Hill</publisher-name>, <publisher-loc>Boston, MA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0046"><mixed-citation publication-type="thesis"><person-group person-group-type="author"><string-name><surname>Smit</surname>, <given-names>Y</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>A structured approach to risk management for South African SMEs</article-title>&#x2019;, <comment>Doctoral thesis</comment>, <publisher-name>Cape Peninsula University of Technology</publisher-name>.</mixed-citation></ref>
<ref id="CIT0047"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Smit</surname>, <given-names>Y</given-names></string-name>. &#x0026; <string-name><surname>Watkins</surname>, <given-names>J.A</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>A literature review of small and medium enterprises (SME) risk management practices in South Africa</article-title>&#x2019;, <source><italic>African Journal of Business Management</italic></source> <volume>6</volume>(<issue>21</issue>), <fpage>6324</fpage>&#x2013;<lpage>6330</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.5897/AJBM11.2709">https://doi.org/10.5897/AJBM11.2709</ext-link></comment></mixed-citation></ref>
<ref id="CIT0048"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sousa</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Aspinwall</surname>, <given-names>E</given-names></string-name></person-group>., <year>2010</year>, &#x2018;<article-title>Development of a performance measurement framework for SMEs</article-title>&#x2019;, <source><italic>Total Quality Management &#x0026; Business Excellence</italic></source> <volume>21</volume>(<issue>5</issue>), <fpage>475</fpage>&#x2013;<lpage>501</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/14783363.2010.481510">https://doi.org/10.1080/14783363.2010.481510</ext-link></comment></mixed-citation></ref>
<ref id="CIT0049"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>South Africa</collab></person-group>, <year>2003</year>, <source><italic>National Small Business Act 26, 2003</italic></source>, <comment>Government Gazette No. 25763, 26 November 2003</comment>.</mixed-citation></ref>
<ref id="CIT0050"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tang</surname>, <given-names>O</given-names></string-name>. &#x0026; <string-name><surname>Musa</surname>, <given-names>N</given-names></string-name></person-group>., <year>2011</year> &#x2018;<article-title>Identifying risk issues and research advancements in supply chain risk management</article-title>&#x2019;, <source><italic>International Journal of Production Economics</italic></source> <volume>133</volume>(<issue>1</issue>), <fpage>25</fpage>&#x2013;<lpage>34</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ijpe.2010.06.013">https://doi.org/10.1016/j.ijpe.2010.06.013</ext-link></comment></mixed-citation></ref>
<ref id="CIT0051"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Turner</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Keetelaar</surname>, <given-names>D</given-names></string-name></person-group>., <year>2005</year>, <source><italic>Risk management guide for small businesses</italic></source>, <publisher-name>Risk Management Institute of Australia</publisher-name>, <publisher-loc>Australia</publisher-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>68</lpage>, <comment>viewed 06 September 2014, from <ext-link ext-link-type="uri" xlink:href="http://www.significanceinternational.com/Portals/0/Documents/2005-sme-risk-management-guide-global-risk-alliance-nsw-dsrd.pdf">http://www.significanceinternational.com/Portals/0/Documents/2005-sme-risk-management-guide-global-risk-alliance-nsw-dsrd.pdf</ext-link></comment></mixed-citation></ref>
<ref id="CIT0052"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Van Weele</surname>, <given-names>A.J</given-names></string-name></person-group>., <year>2010</year>, <source><italic>Purchasing and supply chain management</italic></source>, <edition>5th edn</edition>., <publisher-name>Cengage Learning South-Western</publisher-name>, <publisher-loc>Melbourne</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0053"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Van Wyk</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Dahmer</surname>, <given-names>W</given-names></string-name>. &#x0026; <string-name><surname>Custy</surname>, <given-names>M.C</given-names></string-name></person-group>., <year>2004</year>, &#x2018;<article-title>Risk management and the business environment in South Africa</article-title>&#x2019;, <source><italic>Long Range Planning</italic></source> <volume>37</volume>, <fpage>269</fpage>&#x2013;<lpage>276</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.lrp.2004.03.001">https://doi.org/10.1016/j.lrp.2004.03.001</ext-link></comment></mixed-citation></ref>
<ref id="CIT0054"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Verbano</surname>, <given-names>C</given-names></string-name>. &#x0026; <string-name><surname>Venturini</surname>, <given-names>K</given-names></string-name></person-group>., <year>2013</year>, &#x2018;<article-title>Managing risk in SMEs: A literature review and research agenda</article-title>&#x2019;, <source><italic>Journal of Technology Management and Innovation</italic></source> <volume>8</volume>(<issue>3</issue>), <fpage>186</fpage>&#x2013;<lpage>197</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4067/S0718-27242013000400017">https://doi.org/10.4067/S0718-27242013000400017</ext-link></comment></mixed-citation></ref>
<ref id="CIT0055"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wagner</surname>, <given-names>S.M</given-names></string-name>. &#x0026; <string-name><surname>Bode</surname>, <given-names>C</given-names></string-name></person-group>., <year>2008</year>, &#x2018;<article-title>An empirical examination of supply chain performance along several dimensions of risk</article-title>&#x2019;, <source><italic>Journal of Business Logistics</italic></source> <volume>29</volume>, <fpage>307</fpage>&#x2013;<lpage>325</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1002/j.2158-1592.2008.tb00081.x">https://doi.org/10.1002/j.2158-1592.2008.tb00081.x</ext-link></comment></mixed-citation></ref>
<ref id="CIT0056"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Waters</surname>, <given-names>D</given-names></string-name></person-group>., <year>2009</year>, <source><italic>Supply chain management: An introduction to logistics</italic></source>, <edition>2nd edn</edition>., <publisher-name>Palgrave MacMillan</publisher-name>, <publisher-loc>London</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0057"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wu</surname>, <given-names>D.D</given-names></string-name>. &#x0026; <string-name><surname>Olson</surname>, <given-names>D.L</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>Enterprise risk management: Small business scorecard analysis</article-title>&#x2019;, <source><italic>Production Planning and Control: The Management of Operations</italic></source> <volume>20</volume>(<issue>4</issue>), <fpage>362</fpage>&#x2013;<lpage>369</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/09537280902843706">https://doi.org/10.1080/09537280902843706</ext-link></comment></mixed-citation></ref>
<ref id="CIT0058"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yoon</surname>, <given-names>S.O</given-names></string-name>. &#x0026; <string-name><surname>Lee</surname>, <given-names>C.H</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>A study on paradigm shift of supply chain risk management for SMEs</article-title>&#x2019;, <source><italic>Journal of the Korea Safety Management and Science</italic></source> <volume>14</volume>, <fpage>71</fpage>&#x2013;<lpage>77</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.12812/ksms.2012.14.4.071">https://doi.org/10.12812/ksms.2012.14.4.071</ext-link></comment></mixed-citation></ref>
<ref id="CIT0059"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Young</surname>, <given-names>J</given-names></string-name></person-group>., <year>2008</year>, <source><italic>Operational risk management: The practical application of a qualitative approach</italic></source>, <publisher-name>Van Schaik</publisher-name>, <publisher-loc>Pretoria</publisher-loc>.</mixed-citation></ref>
</ref-list>
<fn-group>
<fn><p><bold>How to cite this article:</bold> Naude, M.J. &#x0026; Chiweshe, N., 2017, &#x2018;A proposed operational risk management framework for small and medium enterprises&#x2019;, <italic>South African Journal of Economic and Management Sciences</italic> 20(1), a1621. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajems.v20i1.1621">https://doi.org/10.4102/sajems.v20i1.1621</ext-link></p></fn>
</fn-group>
</back>
</article>