Page 206
www.rsisinternational.org
management. This standard is applicable to any organisation, regardless of its size, activity, or sector.
Implementing ISO 31000 can enhance an organisation’s likelihood of achieving its objectives, improve the
identification of opportunities and threats, and facilitate the effective allocation and utilisation of resources for
risk treatment. The integration of ISO 31000, AS/NZS 4360, and OHSAS 18000 into a risk management system
is demonstrated in the proposed model, which aims to validate that an integrated risk management system can
enhance the organizational performance of the Malaysian airline industry. Consequently, a robust risk
management system can assist an organization in successfully improving its performance while mitigating risks
or threats to the company.
ACKNOWLEDGEMENT
The authors would like to express their heartfelt gratitude to Ministry of Higher Education and UTeM for the
financial support provided through the FRGS grant secured under grant number FRGS/1/ 2024/ SS01/UTEM/
02/11 (NO UTEM: FRGS-EC/1/2024/FPTT/F00603).
REFERENCES
1. Ahmed, H., & Khan, T. (2007). Risk management in Islamic banking. In M. Kabir Hassan & M. K. Lewis
(Eds.), Handbook of Islamic Banking (pp. 144–158). Edward Elgar.
2. Boehm, B. W. (1991). Software risk management: Principles and practices. IEEE Software, 8(1), 32–41.
https://doi.org/10.1109/52.62930
3. Borghesi, A., & Gaudenzi, B. (2013). Risk management: How to assess, transfer and communicate critical
risks. Springer-Verlag Italia.
4. Certification Europe. (n.d.). OHSAS 18001 occupational health and safety management. Retrieved from
https://www.certificationeurope.com
5. Chapman, C. (1997). Project risk analysis and management—PRAM the generic process. International
Journal of Project Management, 15(5), 273–281. https://doi.org/10.1016/S0263-7863(96)00071-1
6. Clutterbuck, D., & Hirst, S. (2002). Talking business: Making communication work. Butterworth-
Heinemann.
7. DAS Certification USA. (n.d.). OHSAS 18001 occupational health and safety management systems.
Retrieved from https://www.dascertificationusa.com
8. Elkington, P., Smallman, C., et al. (2002). Managing project risks: A case study. International Journal of
Project Management, 20(1), 49–57.
9. Finniston, M. (1975). Information and communication in industry.
10. George, A. Z., & Ritchie, B. (2009). Supply chain risk: A handbook of assessment, management, and
performance. Springer.
11. Grabowski, M., & Roberts, K. (1999). Risk mitigation in virtual organizations. Organization Science,
10(6), 704–721.
12. Halliday, S., Badenhorst, K., & Solms, R. von. (1996). A business approach to effective information
technology risk analysis and management. Information Management & Computer Security, 4(1), 19–31.
13. Hasanali, F. (2002). Critical success factors of knowledge management. Retrieved from
https://www.kmworld.com
14. Henriksen, P., & Uhlenfeldt, A. (2006). Contemporary risk management in project-based environments.
Project Management Journal, 37(3), 36–46.
15. Herbert, R., & Irene, W. (1995). Qualitative interviewing in education research.
16. Hofstede, G. (2001). Culture's consequences: Comparing values, behaviors, institutions, and organizations
across nations (2nd ed.). Sage.
17. Hughey, A. W., & Mussnug, K. J. (1997). Designing effective employee training programmes. Training
for Quality, 5(2), 52–57.
18. Hunter, J. (2002). Improving organizational structure and workflow.
19. Ifinedo, P. (2008). Impacts of business vision, top management support, and external expertise on ERP
success. Business Process Management Journal, 14(4), 551–568.
20. International Organization for Standardization (ISO). (2009). ISO 31000: Risk management — Principles
and guidelines. ISO.