0% found this document useful (0 votes)
4 views79 pages

Chapter 2 - Risk Management Process

Uploaded by

davidkeddar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views79 pages

Chapter 2 - Risk Management Process

Uploaded by

davidkeddar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CHAPTER

FINANCIAL RISK MANAGEMENT PROCESS


Definition
• Financial risk management is a process to deal with the
uncertainties resulting from financial markets.
• It involves assessing the financial risks facing an organization
and developing management strategies consistent with
internal priorities and policies.
• Therefore, financial risk management can be defined as the
process of identification, analysis, and acceptance or
mitigation of uncertainty in investment decisions.
• Essentially, risk management occurs when an investor or
fund manager analyzes and attempts to quantify the
potential for losses in an investment and then takes the
appropriate action given the fund's investment objectives
and risk tolerance.
• Risk is inseparable from return in the investment world.
• A variety of tactics exist to ascertain risk; one of the most
common is standard deviation, a statistical measure of
dispersion around a central tendency.
• Beta, also known as market risk, is a measure of the
volatility, or systematic risk, of an individual stock in
comparison to the entire market.
• Alpha is a measure of excess return; money managers who
employ active strategies to beat the market are subject to
alpha risk.
Objectives of Risk Management
• Risk managements objective is to identify and evaluate risk
• Find out which risks a business faces
• Find ways to quantify and measure those risks
• To create methods to monitor risks and finally come up with
treatment methods which mitigate or eliminate risk.
• The overall objective to create a business that is less
susceptible to risks and therefore enhance the safety of
investors in the business.
• Reduce and eliminate harmful threats
• Supports Efficient use of Resources
• Better Communication of Risk within Organisation
• Reassures Stakeholders
• Support Continuity of Organisation
Sources of Risk
There are three main sources of financial risk:
1. Financial risks arising from an organization’s exposure to
changes in market prices, such as interest rates, exchange
rates, and commodity prices.
2. Financial risks arising from the actions of, and transactions
with, other organizations such as vendors, customers, and
counterparties in derivatives transactions.
3. Financial risks resulting from internal actions or failures of
the organization, particularly people, processes, and
systems.
Risk Management Approach
• Addressing financial risks proactively may provide an
organization with a competitive advantage.
• It also ensures that management, operational staff,
stakeholders, and the board of directors are in agreement on
key issues of risk.
• Managing financial risk necessitates making organizational
decisions about risks that are acceptable versus those that
are not.
• The passive strategy of taking no action is the acceptance of
all risks by default.
• Organizations manage financial risk using a variety of
strategies and products.
• It is important to understand how these products and
strategies work to reduce risk within the context of the
organization’s risk tolerance and objectives.
• Strategies for risk management often involve derivatives.
Derivatives are traded widely among financial institutions
and on organized exchanges.
• The value of derivatives contracts, such as futures, forwards,
options, and swaps, is derived from the price of the
underlying asset.
• Derivatives trade on interest rates, exchange rates,
commodities, equity and fixed income securities, credit, and
even weather.
A Risk Management Framework
• Organizations face many different types of risks, but they can
all be managed using a common framework.
• The framework used in this discussion therefore directly
applies to financial risk management, and provides a context
for subsequent sections that
a) outline the different types of financial risks, and
b) explain how financial risks may be identified and
assessed before implementing appropriate strategies
and control systems.
The Risk Management Cycle
• The above diagram shows that risk management starts with
defining risks by reference to organizational goals, then
progressing through a series of stages to a reassessment of
risk exposures following the implementation of controls.
• At the organizational level, the stages of the risk cycle are set
against the background of a clearly articulated risk policy.
• The policy indicates the types of risks management wants
the organization to take or avoid, and establishes the
organization’s overall appetite for risk taking.
• The starting point is therefore a general understanding of
a) the range and type of risks that an organization may face
in pursuing its specific strategic objectives, and
b) the scale and nature of any interdependencies between
these risks.
• This overview can then be used as the basis for constructing
a more detailed financial risk management strategy.
• Based on the CIMA risk management cycle diagram, the core
elements of a financial risk management system are:
 Risk identification and assessment
 Development of a risk response
 Implementation of a risk control strategy and the
associated control mechanisms.
 Review of risk exposures (via internal reports) and
repetition of the cycle.
1. Risk Identification and Assessment
• The first stage is to identify the risks to which the
organization is exposed.
• Risk identification needs to be methodical, and to address
the organization’s main activities and their associated
risks.
• Risk identification may be carried out via questionnaires,
surveys, brainstorming sessions, or a range of other
techniques such as incident investigation, auditing, root
cause analysis, or interviews.
• The aim is to use staff expertise to identify and describe
all the potential financial risks to which the organization
may be exposed.
• The scale of each identified risk is then estimated, using a
mix of qualitative and quantitative techniques.
• Then risks are ranked in order of priority and the resulting
risk ranking should relate directly back to overall
corporate objectives.
• A commonly used approach is to map the estimated risks
against a likelihood/impact matrix.
• Both likelihood and impact would be classified into high,
medium, or low.
• The more likely the outcome, and the bigger the impact,
the more significant the risk would become.
• It is important to identify and assess those risks that have
the potential to severely jeopardize the organization’s
ability to achieve its objectives, or even to threaten its
very survival.
• The estimated risks can then be prioritized using a
likelihood/impact matrix, such as that illustrated in Figure
below.
A Likelihood/Impact Matrix
• The numbers relate to individually identified risks, and risk
impact may be expressed in either financial (quantitative)
or nonfinancial (qualitative) terms.
• A private sector business may express impact in terms of
forecast income, profit, or cash flow.
• On the other hand a public sector organization may
measure impact in terms of its ability to provide services
to a prescribed level.
• Let us suppose that risk number five in the grid relates to the
likelihood and risk of the impact on bad debts of a rise in
interest rates.
• For a company retailing small-ticket consumer goods, the
anticipated likelihood is shown as high – probably because of
prevailing economic conditions – but the impact is relatively
low.
• In the case of a mortgage provider operating under the same
economic conditions, this same risk may be identified as
having a much higher impact because of the size of the
potential defaults and the fact that lending is its core
business.
• In other words, the component risks and also the resulting
matrix of likelihood and consequences will vary from
business to business, and are subject to a degree of
subjective judgment.
• Many firms find it useful to record their risk information in a
risk register.
• Such a register would include information on the type of risk,
its likelihood of occurrence, its likely consequence, its
potential monetary impact, and its relationship (if any) with
other identified risks.
2. Risk Response
• The organization then needs to respond to the risks it has
identified.
• An example would include setting out a policy defining
the organization’s response to a particular risk, and
explain how that policy fits in with its broader objectives.
It would also
a) set out the management processes to be used to
manage that risk,
a) assign responsibility for handling it, and
b) set out the key performance measures that would
enable senior management to monitor it.
• In more serious cases, it might also include contingency
plans to be implemented if a projected event actually
occurred.
• The organization should take account of the effectiveness
of alternative possible responses.
• The organization should also take account of the costs and
prospective benefits of alternative responses, as well as
take account of how any response would relate to its risk
appetite and its ability to achieve its strategic objectives.
• The possible responses can be categorized into three
categories, as illustrated in the figure below.
Risk Strategies and Tools
i. Internal strategies imply a willingness to accept the risk
and manage it internally within the framework of normal
business operations.
An example would be a decision to use the customer’s
currency for pricing of all exports, and using internal
netting processes to manage currency exposures.
ii. Risk sharing strategies relate to strategies that mitigate or
share risks with an outside party.
An example would be a forward contract, which ‘locks
in’ a particular future price or rate. This prevents losses
from unfavourable currency movements, but locks the
buyer into a fixed future exchange rate. Another
example is a joint venture.
iii. Risk transfer involves paying a third party to take over
the downside risk, while retaining the possibility of
taking advantage of the upside risk.
An option, for example, creates the opportunity to
exchange currency at a pre-agreed rate, known as the
strike price. If the subsequent exchange rate turns out
to be favorable, the holder will exercise the option, but
if the subsequent exchange rate is unfavourable, the
holder will let it lapse.
Thus, the option protects the holder from downside
risk while retaining the possible benefits of upside risk.
Note that the greater flexibility of risk transfer tools is
usually accompanied by greater cost.
3. Risk Control Implementation
• Having selected a risk response, the next stage is to
implement it and monitor its effectiveness in relation to
the specified objectives.
• Implementation includes allocating responsibility for
managing specific risks and, underlying that, creating a
risk-aware culture in which risk management becomes
embedded within the organizational language and
methods of working.
4. Review of Risk Exposures
• The control loop is closed when the effectiveness of the
risk controls is evaluated through a reporting and review
process. This then leads to a new risk identification and
evaluation process.
• This process itself has three main components:
i. Review process
 This should include a regular review of risk forecasts,
a review of the management responses to significant
risks, and a review of the organization’s risk strategy.
 It should also include the establishment of an early
warning system to indicate material changes to the
risks faced by the organization.
II. Internal reporting to management
 This might include a
a) review of the organization’s overall risk
management strategy, and
b) reviews of the processes used to identify and
respond to risks, and of the methods used to
manage them.
 It should also include an assessment of the costs and
benefits of the organization’s risk responses, and an
assessment of the impact of the organization’s risk
management strategy on the risks it faces.
III. External reporting
 External stakeholders should be informed of the
organization’s risk management strategy, and be
given some indication of how well it is
performing.
• This basic framework for risk management can now be
applied to each of the different categories of financial risk,
namely: market, credit, financing, liquidity, and cash flow
risks.
Quantifying Financial Risk
• Three commonly used approaches to quantifying financial
risks are regression analysis, Value-at-Risk analysis, and
scenario analysis.
1. Regression Analysis
• Regression analysis involves trying to understand how one
variable – such as cash flow – is affected by changes in a
number of other factors (or variables) that are believed to
influence it.
• For example, the cash flow for a Zambian-based
engineering business may be affected by changes in
interest rates (INT), the Kwacha/Dollar exchange rate
(EXCH), and the price of gas (GAS). The relationship
between the variables can be expressed as follows:

Change in cash flow = 𝜕 + β1 INT + β2 EXCH + β3 GAS + ε


• Where
INT = represents the change in interest rates
EXCH = represents changes in the euro/sterling exchange
rate,
GAS = represents changes in the commodity price
ε = represents the random error in the equation. The
random error reflects the extent to which cash flows
may change as a result of factors not included in the
equation.
• The coefficients β1 , β2 , and β3 reflect the sensitivity of the
firm’s cash flows to each of the three factors.
• To continue the example, suppose β2 is negative, implying
that the firm’s cash flow would fall if the exchange rate
went up.
• If the firm wished to hedge its cash flow against such an
event, then it might do so by taking out a forward
contract.
• If the exchange rate rose, the resulting drop in cash flow
would be countered by an equivalent rise in thevalue of
the forward contract.
2. Value-at-Risk
• Another popular approach to risk measurement is
Valueat- Risk (VaR) analysis.
• The VaR can be defined as the maximum likely loss on a
position or portfolio at a specified probability level
(known as the confidence level) over a specified horizon
or holding period.
• For example, a company may own an investment portfolio
on which the risk manager estimates the VaR to be $14
million, at a 95% confidence level over a ten-day holding
period.
• This means that if no investments are bought or sold over a
ten-day period, then there is a 95% chance of the portfolio
falling by no more than $14 million.
• VaR is therefore an estimate of the likely maximum loss, but
actual losses may be either above or below VaR.
• However, VaR also has a serious drawback: it tells us nothing
about what to expect when we experience a loss that exceeds
the VaR.
• If the VaR at a particular confidence level is $10m, we have no
idea whether to expect a loss of $11m or $111m when losses
occur that are greater than the VaR.
For example, a board of directors might set an earnings target of,
say, 80 pence per share, but also be conscious that if the earnings
per share (EPS) fell below 70 pence then there would be strong
adverse reaction from the market, causing the share price to fall.
The board may therefore wish to ensure that there is only, say, a
5% likelihood of earnings falling to 70 pence per share. It is
possible for organizations to construct a model that measures the
sensitivity of earnings to changes in the market prices of financial
assets or liabilities, and use this model to estimate a VaR to assess
their potential exposure if such risks are left partially or wholly
unhedged.
• Besides this application of VaR methods to estimate
Earnings-at-Risk, other applications include:
Liquidity-at-Risk: VaR taking account of changes in
market liquidity.
Cash-flow-at-Risk: VaR analysis applied to a firm’s cash
flows rather than P&L.
Credit-at-Risk: VaR analysis applied to a firm’s credit
exposure.
Default-Value-at-Risk: VaR analysis applied to estimate
a firm’s losses in the event of default.
• Thus, VaR-type analysis is very flexible and can be applied
to any type of quantifiable risk.

3. Scenario Analyses
• Scenario analyses involve a financial model of the firm
and a set of specified scenarios.
• Questions such as ‘what if’ one or more scenarios
should occur are asked, and the model is used to
determine the impact of these scenarios on the firm’s
financial position.
• The scenarios chosen include any that are believed
might be relevant to the organization.
• For example, the firm might ask:
“What if the stock market crashed by 20%?”
“What if interest rates were to rise by 300 basis
points?”
“What if the exchange rate were to fall 10%?”
“What if a firm were to lose a key client or key
market?”
And so forth.
• Scenario analyses are particularly helpful for quantifying
what we might lose in crisis situations where ‘normal’
market relationships break down.
• Scenario analyses can identify our vulnerability to a
number of different crisis-phenomena:
i. Changes in the cost and availability of credit
 Scenario analyses are ideal for evaluating our
exposure to an
a) increase in the cost, and
b) decrease in the availability, of credit.
ii. Sudden decreases in liquidity
 Markets can suddenly lose liquidity in crisis
situation, and risk management strategies can
easily become unhinged, leading to much bigger
losses than anticipated.
iii. Concentration risks
 Scenario analyses can sometimes reveal that we
might have a much larger exposure to a single
counterparty or risk factor than we had realized,
taking into account the unusual conditions of a
crisis.
 Probability-based measures such as VaR can
overlook such concentration, because they tend
not to pay much attention to crisis conditions.
iv. Macroeconomic risks
 Scenario analyses are well suited for gauging a firm’s
exposure to macroeconomic factors such as the state
of the business cycle, sudden exchange rate changes,
and the economic condition of a particular country.
Loss Exposure
• A loss exposure is any situation or circumstance in which a
loss is possible, regardless of whether a loss occurs. For
example, a plant that may be damaged by an earthquake, or
an automobile that may be damaged in a collision.
• New forms of risk management consider both pure and
speculative loss exposures.
• Risk management has objectives before and after a loss
occurs.
1. Pre-loss objectives
• Prepare for potential losses in the most economical way.
• Reduce anxiety.
• Meet any legal obligations.
2. Post-loss objectives
• Ensure survival of the firm.
• Continue operations.
• Stabilize earnings.
• Maintain growth.
• Minimize the effects that a loss will have on other persons
and on society.
Steps in the Risk Management Process
1. Identifying Loss Exposures
• Property loss exposures
• Liability loss exposures
• Business income loss exposures
• Human resources loss exposures
• Crime loss exposures
• Employee benefit loss exposures
• Foreign loss exposures
• Intangible property loss exposures
• Failure to comply with government rules and regulations
• Risk Managers have several sources of information to
identify loss exposures:
 Questionnaires
 Physical inspection
 Flowcharts
 Financial statements
 Historical loss data
• Industry trends and market changes can create new loss
exposures.
 e.g., exposure to acts of terrorism
2. Measure and Analyze Loss Exposures
• Estimate the frequency and severity of loss for each type
of loss exposure:
 Loss frequency refers to the probable number of losses
that may occur during some given time period.
 Loss severity refers to the probable size of the losses
that may occur.
• Once loss exposures are analyzed, they can be ranked
according to their relative importance.
• Loss severity is more important than loss frequency:
 The maximum possible loss is the worst loss that could
happen to the firm during its lifetime.
 The probable maximum loss is the worst loss that is
likely to happen.
3. Select the Appropriate Combination of Techniques for
Treating the Loss Exposures
• Risk control refers to techniques that reduce the
frequency and severity of losses.
• Methods of risk control include:
 Avoidance
 Loss prevention
 Loss reduction
• Avoidance means a certain loss exposure is never
acquired, or an existing loss exposure is abandoned.
• The chance of loss is reduced to zero.
• It is not always possible, or practical, to avoid all
losses.
• Loss prevention refers to measures that reduce the
frequency of a particular loss.
 e.g., installing safety features on hazardous
products.
• Loss reduction refers to measures that reduce the
severity of a loss after is occurs.
 e.g., installing an automatic sprinkler system.
4. Select the Appropriate Risk Management Technique
• Risk financing refers to techniques that provide for the
funding of losses
• Methods of risk financing include:
 Retention
 Non-insurance Transfers
 Commercial Insurance
1. Risk Financing Methods: Retention
• Retention means that the firm retains part or all of the
losses that can result from a given loss.
• Retention is effectively used when:
 No other method of treatment is available
 The worst possible loss is not serious
 Losses are highly predictable
• The retention level is the kwacha amount of losses that the
firm will retain.
 A financially strong firm can have a higher retention
level than a financially weak firm.
 The maximum retention may be calculated as a
percentage of the firm’s net working capital.
• A risk manager has several methods for paying retained
losses:
 Current net income: losses are treated as current
expenses.
 Unfunded reserve: losses are deducted from a
bookkeeping account.
 Funded reserve: losses are deducted from a liquid
fund.
 Credit line: funds are borrowed to pay losses as they
occur.
• A captive insurer is an insurer owned by a parent firm
for the purpose of insuring the parent firm’s loss
exposures.
 A single-parent captive is owned by only one parent.
 An association or group captive is an insurer owned
by several parents.
 Many captives are located in the Caribbean because
the regulatory environment is favourable.
• Captives are formed for several reasons, including:
 The parent firm may have difficulty obtaining
insurance.
 To take advantage of a favourable regulatory
environment.
 Costs may be lower than purchasing commercial
insurance.
 A captive insurer has easier access to a reinsurer.
 A captive insurer can become a source of profit.
• Premiums paid to a captive may be tax-deductible
under certain conditions.
• Self-insurance is a special form of planned retention
 Part or all of a given loss exposure is retained by the
firm
 Another name for self-insurance is self-funding
 Widely used for workers compensation and group
health benefits
• A risk retention group is a group captive that can write
any type of liability coverage except employer liability,
workers compensation, and personal lines.
 In certain countries government regulations allows
employers, trade groups, governmental units, and
other parties to form risk retention groups.
 In the US risk retention groups are exempt from
many state insurance laws.
• Advantages of Retention Risk Financing
 Save on loss costs
 Save on expenses
 Encourage loss prevention
 Increase cash flow
• Disadvantages of Retention Risk Financing
 Possible higher losses
 Possible higher expenses
 Possible higher taxes
2. Risk Financing Methods: Non-insurance Transfers
• A non-insurance transfer is a method other than
insurance by which a pure risk and its potential
financial consequences are transferred to another
party. For example Contracts, leases, hold-harmless
agreements.
• Advantages of Non-Insurance Transfers
 Can transfer some losses that are not insurable.
 Save money
 Can transfer loss to someone who is in a better
position to control losses.
• Dis-advantages of Non-Insurance Transfers
 Contract language may be ambiguous, so transfer
may fail.
 If the other party fails to pay, firm is still responsible
for the loss.
 Insurers may not give credit for transfers.
3. Risk Financing Methods: Insurance
• Insurance is appropriate for loss exposures that have a
low probability of loss but for which the severity of loss
is high.
 The risk manager selects the coverages needed, and
policy provisions:
A deductible is a provision by which a specified
amount is subtracted from the loss payment
otherwise payable to the insured.
An excess insurance policy is one in which the
insurer does not participate in the loss until the
actual loss exceeds the amount a firm has
decided to retain.
• The risk manager selects the insurer, or insurers, to
provide the coverages.
• The risk manager negotiates the terms of the insurance
contract.
 A manuscript policy is a policy specially tailored for
the firm.
Language in the policy must be clear to both
parties.
 The parties must agree on the contract provisions,
endorsements, forms, and premiums.
• The risk manager must periodically review the
insurance program.
• Advantages of Insurance
• Firm is indemnified for losses
• Uncertainty is reduced
• Insurers may provide other risk management
services
• Premiums are tax-deductible
• Dis-advantages of Insurance
• Premiums may be costly. Opportunity cost should
also be considered.
• Negotiation of contracts takes time and effort
• The risk manager may become lax in exercising loss
control.
Risk Management Matrix
Market Conditions and the Selection of Risk Management
Techniques
• Risk managers may have to modify their choice of techniques
depending on market conditions in the insurance markets.
• The insurance market experiences an underwriting cycle.
 In a “hard” market, when profitability is declining,
underwriting standards are tightened, premiums increase,
and insurance becomes more difficult to obtain.
 In a “soft” market, when profitability is improving,
standards are loosened, premiums decline, and insurance
become easier to obtain.
5. Implement and Monitor the Risk Management Program
• Implementation of a risk management program begins
with a risk management policy statement that:
 Outlines the firm’s risk management objectives.
 Outlines the firm’s policy on loss control.
 Educates top-level executives in regard to the risk
management process.
 Gives the risk manager greater authority.
 Provides standards for judging the risk manager’s
performance.
• A risk management manual may be used to:
 Describe the risk management program
 Train new employees
• A successful risk management program requires active
cooperation from other departments in the firm.
• The risk management program should be periodically
reviewed and evaluated to determine whether the
objectives are being attained.
 The risk manager should compare the costs and benefits of
all risk management activities.
Benefits of Risk Management
• Pre-loss and post-loss objectives are attainable.
• A risk management program can reduce a firm’s cost of risk.
• The cost of risk includes premiums paid, retained losses,
outside risk management services, financial guarantees,
internal administrative costs, taxes, fees, and other
expenses.
• Reduction in pure loss exposures allows a firm to enact an
enterprise risk management program to treat both pure and
speculative loss exposures.
• Society benefits because both direct and indirect losses are
reduced.
END OF CHAPTER

You might also like