0% found this document useful (0 votes)
26 views6 pages

Chapter 11 Risk Management

Chapter 10 of ACCTG 3116 focuses on risk management as a crucial aspect of corporate governance, emphasizing the need for organizations to master risk management principles to create value and address uncertainties. It outlines the risk management process, including risk identification, assessment, and treatment, while also discussing various types of risks such as business, financial, and operational risks. Additionally, it highlights the importance of establishing a Board Risk Oversight Committee to ensure effective risk management practices within organizations.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
26 views6 pages

Chapter 11 Risk Management

Chapter 10 of ACCTG 3116 focuses on risk management as a crucial aspect of corporate governance, emphasizing the need for organizations to master risk management principles to create value and address uncertainties. It outlines the risk management process, including risk identification, assessment, and treatment, while also discussing various types of risks such as business, financial, and operational risks. Additionally, it highlights the importance of establishing a Board Risk Oversight Committee to ensure effective risk management practices within organizations.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ACCTG 3116: GOVERNANCE, BUSINESS ETHICS, RISK MANAGEMENT, AND INTERNAL CONTROL

CHAPTER 10: RISK MANAGEMENT


LECTURER: BAIS, P. A.Y. 2024 - 2025 SEMESTER: 1st COVERAGE: FINALS

Effective corporate governance cannot be attained BASIC PRINCIPLES OF RISK MANAGEMENT


without the organization mastering the art of risk
management. The International Organization of Standardization
(ISO) identifies the basic principles of risk
Risk Management – recognized as one of the most management.
important competencies needed by the board of
directors of modern organizations, large as well as Risk management should:
small and medium sized business firms.
1. Create value – resources spent to mitigate risk
The levels of risk faced by business firms have should be less than the consequences of
increased because of the fast-growing inaction, i.e., the benefits should exceed the
sophistication of organization, globalization, costs
modern technology and impact of corporate
scandals. 2. Address uncertainty and assumptions

In compliance with legal requirements, top 3. Be an integral part of the organizational


management should consider adequate processes and decision-making
knowledge of risk management.
4. Be dynamic, iterative, transparent, tailorable,
RISK MANAGEMENT DEFINED and responsive to change

• The process of measuring or assessing risk and 5. Create capability of continual improvement
developing strategies to manage it. and enhancement considering the best
available information and human factors
• A systematic approach in identifying, analyzing
and controlling areas or events with a potential 6. Be systematic, structured and continually or
for causing unwanted change. periodically reassessed

• The act or practice of controlling risk, it PROCESS OF RISK MANAGEMENT


includes:
According to the Standard ISO 310000 “Risk
 Risk planning management – Principles and Guidelines on
Implementation,” the process of risk management
 Assessing risk areas
consists of several steps as follows:
 Developing risk handling options
 Monitoring risks
1. Establishing the Context. This will involve:
a. Identification of risk in a selected domain
To determine how risks have changes and
of interest
documenting overall risk management
b. Planning the remainder of the process
program.
c. Mapping out the following:
i. the social scope of risk management
• The identification, assessment, and ii. the identity and objectives of
prioritization or risks followed by coordinated stakeholders
and economical application of resources to iii. the basis upon which risks will be
minimize, monitor and control the probability evaluated, constraints
and/or impact of unfortunate events and to
d. Defining a framework for the activity and
maximize the realization of opportunities an agenda for identification
(International Organization of Standardization e. Developing an analysis of risks involved in
31000) the process.
f. Mitigation or solution of risks using
It is through risk management that risks to any available technological, human and
specific program are assessed and systematically organizational resources.
managed to reduce risk to an acceptable level.
2. Identification of Potential Risks. Risk
Risks can come from uncertainty in financial identification can start with the analysis of the
market, project failure, legal liabilities, credits source of problem or with the analysis of the
risks, accident, natural causes and disasters as problem itself. Common risk identification
well as deliberate attack from adversary or events methods are:
of uncertain or unpredictable root-cause. a. Objective-based risk
b. Scenario-based risk
c. Taxanomy-based risk
d. Common-risk checking
e. Risk charting

1|P a g e
BCT, CPA
ACCTG 3116: GOVERNANCE, BUSINESS ETHICS, RISK MANAGEMENT, AND INTERNAL CONTROL
CHAPTER 10: RISK MANAGEMENT
LECTURER: BAIS, P. A.Y. 2024 - 2025 SEMESTER: 1st COVERAGE: FINALS

cause the operating income to be more volatile


3. Risk Assessment. Once risks have been than sales. Business risk is related to sales
identified, their potential severity of impact volatility as well as to the operating leverage of the
and the probability of occurrence must be firm caused by fixed operating expenses.
assessed. The assessment process is critical
to make the best educated decisions in DEFAULT RISK
prioritizing the implementation of the risk
management plan. — The probability that some or all of the initial
investment will not be returned.
ELEMENTS OF RISK MANAGEMENT
The degree of default risk is closely related to the
In practice, the process of assessing overall risks financial condition of the company issuing the
can be difficult, and balancing resources to security and the security’s rank in claims on assets
mitigate between risks with a high probability of in the event of default or bankruptcy. For example,
occurrence but lower loss versus a risk with high if a bankruptcy occurs, creditors including
loss but lower probability of occurrence can often bondholders have a claim on assets prior to the
be mishandled. claim of ordinary equity shareholders.

Ideal risk management should minimize spending FINANCIAL RISK


of manpower or other resources and at the same
time minimizing the negative effect of risks. — It is determined b the firm’s capital structure or
sources of financing. If the firm is all equity
For the most part, the performance of assessment financed, then any variability in operating
methods should consist of the following elements: income is passed directly to net income on an
equal percentage basis.
1. Identification, characterization and
assessment of threats If the firm is partially financed by debt that requires
2. Assessment of the vulnerability of critical fixed interest payments or by preferred share the
assets to specific threats requires fixed preferred dividend payments, then
3. Determination of the risk (i.e., the expected these fixed charges introduce financial leverage.
likelihood and consequences of specific types This leverage causes net income to vary more than
of attacks on specific assets) operating income.
4. Identification of ways to reduce those risks
5. Prioritization or risk reduction measures based The introduction of financial leverage causes the
on a strategy firm’s lenders and its stockholders to view their
income streams as having additional uncertainty.
RELEVEANT RISK TERMINOLOGIES As a result of financial leverage. Both investment
groups would increase the risk premiums that they
I. RISKS ASSOCIATED WITH INVESTMENTS require for investing in the firm.

Although a single risk premium must compensate INTEREST RATE RISK


the investor for all the uncertainty associated with
the investment, numerous factors may contribute Because money has time value, fluctuations in
to investment uncertainty. The factors usually interest rates will cause the value of an investment
considered with respect to investments are to fluctuate also.

BUSINESS RISK Although interest rate risk is most commonly


associated with bond price movements, rising
— The uncertainty about the rate of return caused interest rates cause bond prices to decline and
by the nature of the business. declining interest rates cause bond prices to rise.

The most frequently discussed causes of business Movements in interest rates affect almost all
risk are uncertainty about the firm’s sales and investment alternatives. For example, as a change
operating expenses. Clearly, the firm’s sales are in interest rates will impact the discount rate used
not guaranteed and will fluctuate as the economy to estimate the present value of future cash
fluctuates or the nature of the industry changes. dividends from ordinary shares. This change in the
discount rate will materially impact the analyst’s
A firm’s income is also related to its operating estimate of the value of a share of ordinary share.
expenses. If all operating expenses are variable,
then sales volatility will be passed directly to LIQUIDITY RISK
operating income. Most firms, however, have some
fixed operating expenses (for example: — Associated with uncertainty created by the
depreciation, rent, salaries). These fixed expenses inability to sell the investment quickly for cash.

2|P a g e
BCT, CPA
ACCTG 3116: GOVERNANCE, BUSINESS ETHICS, RISK MANAGEMENT, AND INTERNAL CONTROL
CHAPTER 10: RISK MANAGEMENT
LECTURER: BAIS, P. A.Y. 2024 - 2025 SEMESTER: 1st COVERAGE: FINALS

An investor assumes that the investment can PURCHASING POWER RISK


be sold at the expected price when future
consumption is planned. — More difficult to recognized than the other
types of risk. It is easy to observe the decline in
As the investors considered the sale of the the price of a stock or bond, but it is often more
investment, he or she faces two uncertainties: difficult to recognize that the purchasing
1. What price will be received? power of the return you have earned on an
2. How long will it take to sell the asset? investment has declined (risen) as a result of
inflation (deflation).
An example of an illiquid asset is a house in a
market with an abundance of homes relative to the It is important to remember that an investor
number of potential buyers. This investment may expects to be compensated for forgoing
not sell for several months or even years. Of consumption today. If an individual is invested in
course, if the price is reduced sufficiently, the real peso- denominated assets such as bonds,
estate will sell, but the investor must make a selling treasury bills, or savings accounts during the
price concession in order for the transaction to period of inflation, the real or inflation adjusted rate
occur. of return will be less than the nominal or stated rate
of return.
In contract, a government treasury bill can be sold
almost immediately with very little concession on Thus, inflation erodes the purchasing power of the
selling price. Such an investment can be converted peso and increases investor risk.
to cash almost at will and for a price very close to
the price the investor expected. II. RISKS ASSOCIATED WITH
MANUFACTURING, TRADING AND SERVICE
The liquidity risk for ordinary equity shares is more CONCERNS
complex.
MARKET RISK
They are traded on organized and active markets;
ordinary equity shares can be sold quickly. Some • Product Risk
ordinary equity shares however, have greater  Complexity
liquidity risk than others due to a think market.  Obsolescence
 Research and Development
Thin market – occurs when there are relatively few  Packaging
shares outstanding and investor trading interest is  Delivery of Warranties
limited.
• Competitor Risk
The thin market results in a large price spread (the
 Pricing Strategy
difference between the bid price buyers are willing
 Market Share
to pay and the ask price sellers are willing to
 Market Strategy
accept.)
OPERATIONS RISK
A large spread increases the cost of trading to the
investor and thus represents liquidity risk.
Investors considering the purchase of illiquid • Process Stoppage
investments – ones that have no ready market or • Health and Safety
require price concessions – will demand a rate of • After Sales Service Failure
return that compensates for the liquidity risk. • Environmental
• Technological Obsolescence
MANAGEMENT RISK • Integrity
 Management Fraud
Decisions made by a firm’s management and  Employee Fraud
board of directors materially affect the risk faced  Illegal Acts
by investors. Areas affected by these decisions
range from product innovation and production FINANCIAL RISK
methods (business risk) and financial (financial
risk) to acquisitions. • Interest Rates Volatility
• Foreign Currency Liquidity
For example, acquisition or acquisition-defense • Derivative
decisions made by the management of such firms • Viability
materially affected the risk of the holders of their
companies’ securities.

3|P a g e
BCT, CPA
ACCTG 3116: GOVERNANCE, BUSINESS ETHICS, RISK MANAGEMENT, AND INTERNAL CONTROL
CHAPTER 10: RISK MANAGEMENT
LECTURER: BAIS, P. A.Y. 2024 - 2025 SEMESTER: 1st COVERAGE: FINALS

BUSINESS RISK RISK REDUCTION

• Regulatory Change Risk reduction or optimization involves reducing


• Reputation the severity of the loss or the likelihood of the loss
Political from occurring. Optimizing risks means finding a
• Regulatory and Legal balance between the negative risk and the benefit
• Shareholder Relations of the operation or activity; and between risk
• Credit Rating reduction and effort applied.
• Capital Availability
• Business Interruptions Outsourcing could be an example of risk reduction
if the outsourcer can demonstrate higher capability
III. RISKS ASSOCIATED WITH FINANCIAL of managing or reducing risks.
INSTITUTIONS
RISK SHARING

Risk sharing means sharing with another party the


burden of loss of the benefit of gain, from a risk and
the measures to reduce a risk.

RISK RETENTION

Risk retention involves accepting the loss or


benefit of gain from a risk when it occurs. Self-
insurance falls in this category. All risks that are not
avoided are transferred or retained by default. Also,
any amount of potential loss over the amount
insured is retained risk. This is acceptable if the
chance of a very large loss is small or if the cost to
insure for greater coverage involves a substantial
amount that could hinder the goals of the
organizations.

AREAS OF RISK MANAGEMENT

As applied to corporate finance, risk management


is the technique for measuring, monitoring and
controlling the financial or operational risk on a
firm’s balance sheet.
POTENTIAL RISK TREATMENTS
The Basel II framework breaks risks intro market
ISO 31000 also suggests that once risks have been risk (price risk), credit risk and operational risk and
identified and assess, techniques to manage the also specifies methos for calculating capital
risks should be applied. These techniques can fall requirements for each of these components.
into one or more of these four categories:
The most commonly encountered areas of risk
• Avoidance management include:
• Reduction
• Sharing 1. Enterprise risk management
2. Risk management activities as applied to
• Retention
project management
3. Risk management for megaprojects
RISK AVOIDANCE
4. Risk management of information technology
5. Risk management techniques in petroleum
This includes performing an activity that could
and natural gas
carry risk. An example would be not buying a
property or business in order not to take on the
legal liability that comes with it. Avoiding risks,
however, also means losing out on the potential
gain that accepting (retaining) the risk may have
allowed. Not entering a business to avoid the risk
of loss also avoids the possibility of earning profits.

4|P a g e
BCT, CPA
ACCTG 3116: GOVERNANCE, BUSINESS ETHICS, RISK MANAGEMENT, AND INTERNAL CONTROL
CHAPTER 10: RISK MANAGEMENT
LECTURER: BAIS, P. A.Y. 2024 - 2025 SEMESTER: 1st COVERAGE: FINALS

Subject to a corporation’s size, risk profile and


complexity of operations, the Board should
establish a separate Board Risk Oversight
Committee (BROC) that should be responsible for
the oversight of a company’s Enterprise Risk
Management system to ensure its functionality and
effectiveness.

The BROC should be composed of at least three


members, the majority of whom should be
independent directors, including the Chairman.

The Chairman should not be the Chairman of the


Board or of any committee. At least one member of
the committee must have relevant thorough
knowledge and experience on risk and risk
management.

SEC REQUIREMENT RELATIVE TO Subject to its size, risk profile and complexity of
ENTERPRISE RISK MANAGEMENT OF operations, the company should have a separate
PUBLICLY LISTED CORPORATION risk management function to identify, assess and
monitor key risk exposures.
SEC Code of Governance Recommendations 2.11
and corresponding explanation provide the STEPS IN THE RISK MANAGEMENT PROCESS
following:
To enhance management’s competence in their
“The Board should oversee that a sound enterprise oversight role on risk management the following
risk management (ERM) framework is in place to steps may be followed:
effectively identify, monitor, assess and manage
key business risks. The risk management 1. Set up a separate risk management committee
framework should guide the Board in identifying chaired by a board member
units/business lines and enterprise-level risk
exposures, as well as the effectiveness of risk  Creation of a risk management committee
management strategies. as board level will demonstrate the firm’s
commitment to adopt an integrated
Risk management policy is part and parcel of a company-wide risk management system.
corporation’s corporate strategy. The Board is
responsible for defining the company’s level of risk 2. Ensure that a formal comprehensive risk
tolerance and providing oversight over its risk management system is in place.
management policies and procedures.”
 This fully documented formal system will
Principle 12 which deals with strengthening the provide a clear vision of the board’s desire
internal control system and enterprise risk for an effective company-wide risk
management framework states that management as well as awareness of the
risks, internal and external, that the
“To ensure integrity, transparency and proper company faces.
governance in the conduct of its affairs, the
company should have a strong and effective 3. Assess whether the formal system possesses
internal control system and enterprise risk the necessary elements.
management framework.”
 The key elements that the company-wide
RISK MANAGEMENT FRAMEWORK risk management system should possess
are:
The Board should oversee that a sound enterprise
risk management (ERM) framework is in place to a) Goals and objectives
effectively identify, monitor, assess and manage b) Risk language identification
key business risks. The risk management c) Organization structure
framework should guide the Board in identifying d) The risk Management process
units/ business lines and enterprise-level risk documentation
exposures, as well as the effectiveness of risk
management strategies.  The risk organizational structure should
include formal charters, levels of

5|P a g e
BCT, CPA
ACCTG 3116: GOVERNANCE, BUSINESS ETHICS, RISK MANAGEMENT, AND INTERNAL CONTROL
CHAPTER 10: RISK MANAGEMENT
LECTURER: BAIS, P. A.Y. 2024 - 2025 SEMESTER: 1st COVERAGE: FINALS

authorization reporting lines and job These components should be complete


descriptions. and aligned for the risk management
structure to function effectively.
 The risk management process shall
include the following steps: 7. Assess management’s efforts to monitor
overall company risk management
a) Assessment risks: identification, performance and to improve continuously the
determination of their source firm’s capabilities.
b) Development action plans: reduce,
avoid, retain, transfer or exploit  Risk management performance must be
c) Implementation of action plans monitored on a continuing basis and
d) Monitoring and reporting risk organization must be ready to innovate
management performance their approaches to be in line with the
e) Continuous improvement risk changing lines.
management capabilities.
 Monitoring is done by all concerned
4. Evaluate the effectiveness of the various steps parties such as senior managers, process
in the assessment of the comprehensive risk owners and risk owners.
faced by the business firm.
 An independent reviewer can also be
 Risk assessment step which includes risks appointed to validate results.
identification and determination of their
sources and measurement, represents 8. See to it that best practices as well as mistakes
the foundation for the rest of the are shared by all.
procedures. This step is performed by
responsible managers, i.e., finance  These should be an open communication
officers, production managers, marketing channel to ensure that all risk
managers and human resource managers. management participant particularly
senior management are informed of risk
 This process culminates in the incidents or threat of risk incident/ This will
presentation of the risk profile or risk map go a long way toward attaining the
to the board of directors. company’s risk management vision.

5. Assess if management have developed and 9. Assess regularly the level of sophistication of
implemented the suitable risk management the firm’s risk management system.
strategies and evaluate their effectiveness.
10. Hire experts when needed.
 The risk profile highlights all the significant
possible risks identified, prioritized and
measured by the risk management
system.

 Strategies are developed to manage and


resolve these identified risks. These will
include the process, people, management
feedback methodologies and systems.

 Strategies may include avoidance,


reduction, transfer, exploitation and
retention of risks.

6. Evaluate if management has designed and


implemented risk management capabilities.

 Directors must continue to monitor and


assess if management has been
implementing designed risk management
capabilities.

 Risk management capabilities include


processes, people, reports,
methodologies and technologies needed.

6|P a g e
BCT, CPA

You might also like