1
Chapter 5 – Risk Response
Risk Risk appetite refers to the level of risk an organization or individual is willing to accept
Appetite or tolerate in pursuit of its objectives.
Risk Appetite Vs. Risk Tolerance
Source Definition of Risk Appetite Definition of Risk Tolerance
ISO Guide Amount and type of risk that an Organization’s or stakeholder’s readiness to
73 ISO organization is willing to pursue or bear the risk after risk treatment in order
31000 retain. to achieve its objectives.
BS The amount and type of risk than an The organization’s readiness to bear the
31100:2008 organization is prepared to seek, risk after risk treatments in order to
accept or tolerate. achieve its objectives.
Institute Risk appetite is the total exposed Risk tolerance is the amount of uncertainty
of Risk amount that an organization wishes to an organization is prepared to accept in
Management undertake on the basis of risk-return total or more narrowly within a certain
trade-offs for one or more desired business unit, a particular risk category or
and expected outcomes. for a specific initiative.
Risk Appetite Vs. Risk Tolerance (Conclusion)
Risk Appetite Risk Tolerance
The Risk Appetite is the amount of risk an Risk Tolerance is the specific minimum and maximum
organisation is ready to “live” with or willing level beyond which an organisation loses
to accept while pursuing its objectives.
Risk Appetite is generally expressed in Risk tolerance is expressed in quantitative terms
qualitative /quantitative terms and can be in and hence can be monitoring relatively in an easy
relation to an individual or organisation as a manner. It can also be measured as
whole. acceptable/unacceptable range of outcomes.
Risk appetite is related to long term strategy. The Risk Tolerance may be related to shorter term and
can be changed due to change in different dynamics.
Telegram and You Tube: CA Himanshu Adlakha
2
Chapter 5 – Risk Response
Factors on which Risk Appetite of an organisation is dependent
(i) Nature of Industry: - It depends on the nature of industry to which organisation pertains. If
organisation is in the banking business of course the risk appetite is quite on higher side.
Further it also depends on the stage in which industry is because if it is new industry, it may have high
risk appetite while the industry that has been matured may have low risk appetite.
(ii) Stage of Company: - While in early stage, high potential and high risk growth start-up companies
may have higher risk appetite which has been matured and will be more focused on stable growth.
(iii) Nature of Objective of a Company: - It also matters how aggressively company pursue its objectives.
If it is pursuing its objective aggressively then may have high Risk Appetite
(iv) Financial strength and capabilities of the organisation: - Company with more resources will be willing
to accept higher risk than a company with lower resources.
Role Of Risk Appetite In Risk Management
Foundation of Risk Culture: - Since Risk Appetite are generally set up by the Board or Executive
management at helms of affair of company it lays down the foundation of Risk Culture.
Identification of New Risks: - To keep updated changing Risk landscapes frequent risk
assessment is made, which helps to identify new risks.
Focus on Risk Management and control: - Regular Quantification and aggregation helps to set
priorities helps to focus on risk management.
Monitoring of Performance: - Once the limits of Risk Appetite are set it becomes easy to monitor and
reporting of performance of individual/division/units.
Optimising of Cost/Benefit: - Since framework of controls are calibrated in line with risk appetite it
helps to optimise cost/benefit.
Value to the company: - Close monitoring of organisation’s risk profile against risk appetite helps to
identify the trends to identify key areas which are effective to the risk management.
Benefits Of Risk Appetite Statement
(i) Better Risk Management: - It helps the company to manage the risk in a better manner as it serves
as a guide to take measured risk to generate value and avoid intolerable losses.
Telegram and You Tube: CA Himanshu Adlakha
3
Chapter 5 – Risk Response
(ii) Well -informed Risk-Based Decisions: - It helps the management to make risk-based informed
decisions.
(iii) Better Risk-Return Trade Off: - It helps to allocate scared resources of organisation in a better
manner to achieve a better Risk -Return Trade off.
(iv) Improved Transparency: - It helps to improve transparency for various stakeholders including
investors, regulators and other agencies (credit Rating Agencies) etc.
(v) Alignment with stakeholders: - It also helps stakeholders (Board, shareholders, etc) to get aligned
on same page on the quantum of and type of risk organisation is willing to take.
Guiding Principles For Effective Risk Appetite Statement
OrganizationÕs strategy: - Risks identified should be in line with the organisation’s strategy. It
involves critical thinking organisation’s mission, objectives, vision and value drivers.
Engage the right stakeholder: - At early stage of development of risk appetite statement engagement
of right stakeholders such as Board, senior management, Business unit heads and head of finance
department is necessary.
Risk Capacity: - Broadly risk capacity is based on financial constraints such available of Funds, cost
of capital, etc. It is important to note that Risk Appetite should be less than the Risk Capacity to
create a sufficient buffer.
Approval of Board: - Risk Appetite statement should be approved by Board and then get articulated
to the lower level of management .
Regulatory Requirements: - If there are any regulatory requirement regarding the appetite
statement it should be complied with.
Common Language: - The Risk Appetite statement should be expressed in common language/
taxonomy to be used throughout the organisation. This would enable all related stakeholders to
make decisions in an intelligent manner.
Monitoring and Evaluation: - After defining the Risk Appetite Statement it should be reviewed
and evaluated periodically -Annually or at the time interval required as per changed circumstances.
If required, they should be updated and adjusted accordingly.
Telegram and You Tube: CA Himanshu Adlakha
4
Chapter 5 – Risk Response
Conclusion
Subjectivity: Risk appetite is a subjective concept and can vary from one organization or individual to
another. Different entities may have different attitudes toward risk based on their goals, values,
and risk tolerance.
Risk Tolerance: While risk appetite is the overall willingness to take on risk, risk tolerance is the
specific level of risk that an entity is willing to accept for a particular activity or objective.
Alignment with Objectives: It's important to strike a balance between risk-taking and risk
avoidance to ensure that risk is managed in a way that supports the achievement of objectives.
Communication and Governance: It helps guide decision-making at all levels of the organization and
ensures that risk is managed consistently. This often involves setting up a governance structure to
oversee and enforce risk management policies.
Risk Culture: Risk appetite is closely related to an organization's risk culture—the shared values,
attitudes, and behaviours related to risk within an organization. A strong risk culture helps in promoting
responsible risk-taking and a proactive approach to risk management.
External Factors: External factors such as regulatory requirements, market conditions, and industry
standards can influence an entity's risk appetite.
Dynamic Nature: Risk appetite is not static and may change over time as the business environment
evolves, as new opportunities and challenges arise, or as the organization's risk tolerance adjusts.
Risk treatment involves the process of choosing and executing suitable control
Risk Treatment measures to address or alter the risk.
A comprehensive risk treatment system should ensure the presence of efficient
and effective internal controls.
Risk Treatment Techniques
Tolerate
The risk may be tolerable without any further action being taken. Even if it is not tolerable, ability to
do anything about some risks may be limited.
In such instances, the appropriate response might involve accepting the current level of risk.
Telegram and You Tube: CA Himanshu Adlakha
5
Chapter 5 – Risk Response
This approach could be further reinforced by developing contingency plans to manage the consequences
that may occur if the risk materializes in the future.
Transfer
This can be achieved through traditional insurance mechanisms or by outsourcing the risk to a third
party through financial arrangements.
This option is particularly good for mitigating financial risks or risks to assets.
It is important to note that some risks are not (fully) transferable in particular; it is generally not
possible to transfer reputation risk even if the delivery of a service is contracted out.
Terminate
Some risks can only be treatable, or containable to acceptable levels, by terminating the activity itself.
This option can be particularly important in project management if the cost of treating the risk does
not make the activity viable.
For example, land acquisition for a project whose feasibility is based on that particular land may be
risky and the cost of legal fees is so high, that it may be better to terminate the project.
Treat
By far, a large number of risks will be addressed in this way. The purpose of treatment is to
continue with the activity giving rise to the risk and action (internal control) is taken to contain the
risk to an acceptable level.
Controlling Risk
Risk control involves the implementation of strategies by businesses to assess potential losses and
mitigate or eradicate associated risks.
Risk control facilitates proactive adjustments to minimize risks across these domains, ultimately aiding
companies in curtailing potential losses.
Risk control holds significant importance for the vitality of an organization as it enables the company
to achieve its objectives and financial gains by safeguarding against risks that could impact its
profitability. Serving as an internal control strategy, its core focus lies in preventing losses.
Risk Management Vs. Risk Control
Although risk control is part of risk management, it is only one part; the two concepts are not the same.
Risk management is the entire, end-to-end process of identifying and handling risks.
Telegram and You Tube: CA Himanshu Adlakha
6
Chapter 5 – Risk Response
Risk control is a way for organizations to mitigate risks by implementing operational processes.
As an illustration, a company could manage the risk of equipment failure by adhering to a
predetermined maintenance schedule. However, this specific action does not encompass the
entirety of the risk management procedure, which includes recognizing equipment failure as a potential
hazard, mitigating it through regular maintenance, ensuring an adequate surplus of equipment in
case of failure, and providing reports on equipment maintenance to senior management.
Controlling risk is a critical aspect of effective risk management. The goal is not always to
eliminate all risks, as some level of risk is inherent in any business or project, but rather to manage and
mitigate risks to an acceptable level.
Here are some key steps and strategies for controlling risk in the context of risk management:
(i) Risk Identification: Begin by identifying and understanding the risks associated with a particular
project, process, or business. This involves brainstorming, analysing historical data, and consulting with
stakeholders.
(ii) Risk Assessment: Evaluate and prioritize risks based on their potential impact and likelihood.
This helps in focusing efforts on the most critical risks that could significantly affect objectives.
(iii) Risk Mitigation Planning: Develop a risk mitigation plan for each identified risk. This might involve
implementing preventive measures, transferring risk through insurance, or developing contingency
plans.
(iv) Risk Monitoring: Establish a system for ongoing monitoring of identified risks. This involves regularly
assessing the effectiveness of risk mitigation strategies and making adjustments as needed.
(v) Risk Communication: Clearly communicate risks and risk mitigation strategies to stakeholders.
(vi) Risk Transfer: This could involve purchasing insurance, outsourcing certain activities, or entering
into contracts that allocate risks to other parties.
(vii) Diversification: Diversify resources, investments, or operations to spread risk. This is especially
relevant in financial management, where diversifying a portfolio of investments can help mitigate the
impact of a poor-performing asset.
Telegram and You Tube: CA Himanshu Adlakha
7
Chapter 5 – Risk Response
(viii) Scenario Planning: Conduct scenario planning to anticipate and prepare for different possible
future scenarios.
(ix) Continuous Improvement: Regularly review and improve risk management processes. This involves
learning from past experiences, conducting post-event evaluations, and updating risk management plans
based on new information or changes in the business environment.
(x) Crisis Management Planning: Develop a crisis management plan that outlines how the organization
will respond to and recover from a major risk event. This includes having clear communication
protocols, designated response teams, and predefined recovery strategies.
Contingency Planning
Contingency planning is a critical component of risk management, aimed at preparing an organization
for potential disruptions and ensuring that it can respond effectively to unexpected events. Here are key
elements and steps involved in contingency planning within the context of risk management:
(i) Risk Identification and Assessment: Begin by identifying and assessing potential risks that could
impact your organization. These risks can include natural disasters, technology failures, supply chain
disruptions, regulatory changes, and more.
(ii) Critical Asset Identification: Identify and prioritize critical assets and processes. These are the
elements of your organization that are essential for its operations and that, if disrupted, could have a
significant impact.
(iii) Impact Analysis: Evaluate the potential impact of identified risks on critical assets and
processes. Understand the potential consequences in terms of financial losses, operational
disruptions, reputational damage, and other relevant factors.
(iv) Risk Mitigation Strategies: Develop and implement risk mitigation strategies to reduce the likelihood
and impact of potential disruptions. This could involve redundancy, diversification of suppliers,
technology upgrades, and other measures.
(v) Contingency Planning Team: Establish a team responsible for contingency planning which include
representatives from various departments to ensure a comprehensive and well-informed approach.
Telegram and You Tube: CA Himanshu Adlakha
8
Chapter 5 – Risk Response
(vi) Developing Contingency Plans: Develop comprehensive contingency plans for every recognized
risk. These plans must detail precise steps to be executed in reaction to various potential scenarios.
(vii) Communication Plan: Develop a communication plan that outlines how information will be disseminated
during a crisis. Clearly define roles and responsibilities for communication, both internally and
externally.
(viii) Testing and Exercising: Regularly test and exercise contingency plans through simulations and drills.
This helps identify weaknesses in the plans, ensures that personnel are familiar with procedures, and
allows for adjustments and improvements.
(ix) Resource Allocation: Allocate resources, including personnel, equipment, and finances, to support the
execution of contingency plans. Ensure that there are adequate resources available to respond
effectively to potential disruptions.
(x) Training and Awareness: Provide training to relevant personnel on their roles and responsibilities
during a crisis. Ensure that employees are aware of the contingency plans and understand how to
implement them.
(xi) Continuous Improvement: Continuously review and update contingency plans to reflect changes in the
organization's operations, structure, and external environment. Learn from past experiences and
incorporate lessons learned into future planning.
(xii) Coordination with External Partners: Establish communication and coordination mechanisms with
external partners, such as suppliers, regulatory agencies, and emergency services. Collaborate with
these entities to enhance the overall resilience of the organization.
(xiii) Legal and Regulatory Compliance: Ensure that contingency plans comply with relevant legal and
regulatory requirements. This may include data protection laws, safety standards, and industry-
specific regulations.
Telegram and You Tube: CA Himanshu Adlakha