0% found this document useful (0 votes)
3 views19 pages

Module 4 Risk Management - 110157

The document provides an overview of risk management, emphasizing its importance in corporate governance and the need for organizations to have a robust risk management plan. It categorizes risks into various types, including pure, speculative, diversifiable, and non-diversifiable risks, and outlines the risk management process, which includes identifying, assessing, and prioritizing risks. Additionally, it highlights the roles of different stakeholders in managing risks and the basic principles that guide effective risk management practices.

Uploaded by

helise542
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views19 pages

Module 4 Risk Management - 110157

The document provides an overview of risk management, emphasizing its importance in corporate governance and the need for organizations to have a robust risk management plan. It categorizes risks into various types, including pure, speculative, diversifiable, and non-diversifiable risks, and outlines the risk management process, which includes identifying, assessing, and prioritizing risks. Additionally, it highlights the roles of different stakeholders in managing risks and the basic principles that guide effective risk management practices.

Uploaded by

helise542
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

4 Risk Management

CONTENTS
1.1. The Nature of Risk
1.2. Risk Management

OUTCOMES
LO2.

OBJECTIVES
1. Explain the
concepts, elements
and basic principles
of risk management.
2. Describe the steps
in risk management
process.
Recent events in the world have brought risk into
higher profile. Terrorism, extreme weather
events and the global financial crisis represent
the extreme risks that are facing society and
commerce. These extreme risks exist in addition
to the daily, somewhat more mundane, risks
mentioned above.
Evaluating the range of risk responses
available and deciding the most appropriate one
in each case is at the heart of risk management.
Responding to risks should produce benefits for
us as individuals, as well as for the organizations
where we work and/or are employed (Hopkin,
2017).
Effective corporate governance cannot be
attained without the organization mastering the
art of risk management. And risk management is
recognized as one of the most important
competencies needed by the board of directors
of modern organization, large as well as small
and medium sized business firms.

1 BALINA ‖ For Internal Use only


ABSTRACTION

Risk and Individual Behavior


Risk is the possibility of something to happen. We cannot foresee
when will it happen. What we can do is to be prepared for it to happen. That
is why every organization must have a proper risk management plan. In the
book of Rejda and Mcnamara (2014), risk is defined as uncertainty
concerning the occurrence of a loss. The term “risk” is often used in
situations where the probability of possible outcomes can be estimated with
some accuracy, while “uncertainty” is used in situations where such
probabilities cannot be estimated. As such, many authors have developed
their own concept of risk, and numerous definitions of risk exist in the
professional literature.
According to the Committee of Sponsoring Organizations of the
Treadway Commission (COSO), risk is the possibility that an event will occur
and adversely affect the achievement of enterprise objectives.”
There are many events that can affect the business. These events can
either be internal or external. Those events that occur within the company
are called internal events and those that happen outside are external events.

Examples of internal events:

Event Potential impact


1. Internal Fraud  Financial Loss
 Damage to the reputation of the
company.
2. Machine breakdown  Disruption in the production process
 Failure to deliver finished goods to
customers
3. Accident in the factory  Physical injuries, loss of lives
 Increase in medical costs
4. Violation of laws and  Fines and penalties
regulations  Potential criminal prosecution of erring
corporate officers and employees

Examples of external events:

Event Potential impact


1. Economic recession  Decline in sales revenue and operating
profit
 Possible closure of the business
2. Entry of more competitors in  Loss of market share
the market  Decline in sales revenue
3. Bankruptcy of a major  Failure to collect receivables
customer  Decline in cash balance
4. Pandemic  Disruption in business operations
 Decline in revenue and profit

2 BALINA ‖ For Internal Use only


 Possibility of closure of the business

Classification of Risk
1. Pure and speculative risk
 Pure risk is defined as a situation in which there are only the
possibilities of loss or no loss. The only possible outcomes are adverse
(loss) and neutral (no loss). Predicting the outcomes of a pure risks is
accomplished (sometimes) using the law of large numbers, a priori
data or empirical data. Examples of pure risks include premature
death, job-related accidents, catastrophic medical expenses, and
damage to property from fire, lightning, flood, or earthquake.

 Speculative risk is defined as a situation in which either profit or loss


is possible. For example, if you purchase 100 shares of common stock,
you would profit if the price of the stock increases but would lose if the
price declines.

Pure vs. Speculative Risk Exposures


Pure Risk: Speculative Risk:
Potential loss but no possible gain Potential gain or loss
 Physical damage to property  Market risk which includes
from: o Interest rate fluctuation
o Fire o Foreign exchange
o Flood or volatility
o Other natural disasters o Stock price
 Liability risk such as:  Reputational risk
o Getting sued over illegal  Brand risk
and harmful products  Individual credit risk
o Employment  Regulatory changes
malpractices  Accounting risk
 Individual risk which may
include
o War
o Unemployment
 Global pandemics
 Social program failure

2. Diversifiable and non-diversifiable risk


 Diversifiable risk is a risk that affects only individuals or small
groups and not the entire economy. It is a risk that can be reduced or
eliminated by diversification. Examples include car thefts, robberies,
and dwelling fires. Only individuals and business firms that experience
such losses are affected, not the entire economy.

 Non-diversifiable risk is a risk that affects the entire economy or


large numbers of persons or groups within the economy. It is a risk
that cannot be eliminated or reduced by diversification. Examples
3 BALINA ‖ For Internal Use only
include rapid inflation, cyclical unemployment, war, hurricanes, floods,
and earthquakes because large numbers of individuals or groups are
affected. Because non-diversifiable risk affects the entire economy or
large numbers of persons in the economy, it is also called systematic
risk or fundamental risk.

Diversifiable and Non-Diversifiable Risk Exposures

Diversifiable Risks Non-Diversifiable Risks


 Strategic Risk  Political Risk
 Operational Risk  Inflation and Recession Risk
 Legal Risk  Environmental Risk
 Credit Risk  Market Risk
 Reputational Risk  Regulatory Risk
 Brand Risk  Social Security Program Risk
 Product Risk  Accounting Risk
 Physical Damage Risk  Pandemics

3. Enterprise risk is a term that encompasses all major risks faced by a


business firm. Such risks include pure risk, speculative risk, strategic risk,
operational risk, and financial risk.
a. Strategic risk refers to uncertainty regarding the firm’s
financial goals and objectives; for example, if a firm enters a
new line of business, the line may be unprofitable. It arises from
trends in the economy and society.

b. Operational risk results from the firm’s business operations. It


rises from people, processes, systems, or controls. For example,
a bank that offers online banking services may incur losses if
“hackers” break into the bank’s computer.

c. Financial risk refers to the uncertainty of loss because of


adverse changes in commodity prices, interest rates, foreign
exchange rates, and the value of money. It arises from the effect
of market forces on financial assets or liabilities. For example, a
food company that agrees to deliver cereal at a fixed price to a
supermarket chain in six months may lose money if grain prices
rise.

Types of Risk
Because of the increasing complexity of business, there are different
kinds of risk that the company may encounter. There is no single standard
manner for classifying risks. At the minimum, however, risks can be
categorized in two broad groups;

1. Financial Risk – is the likelihood that the company might incur a


financial loss or suffer a decline in profit, capital, investment, or cash
4 BALINA ‖ For Internal Use only
flows, on account of the occurrence of events or transactions. It
includes;
a. Credit risk – the risk that a counter-party such as a customer or
a borrower might fail to pay its account on the due date. This is
sometimes refereed to as default risk. Credit risk is present in all
activities where there is an expectation of returns or repayment.

b. Liquidity risk – the risk that the business will be unable to meet
its financial obligations as they fall due because of insufficient
cash, inability to liquidate assets, or obtain adequate funding
given a short period of time.

c. Market risk – is the risk of volatility in the market brought about


by factors of interest rate, foreign currency, and market process.
i. Interest rate risk – is the potential decline in earnings and
capital arising from changes in interest rates in the
market.
ii. Foreign currency risk – the risk that fluctuations in
exchange rates could affect the profit of the business.
iii. Price risk – the risk that changes in specific prices could
affect the profit or cash flow of the business.

2. Non-financial Risks – do not have an immediate direct financial


impact to the business. However, their consequences may be serious
and can later affect the financial well-being of the business if not
properly mitigated. Examples includes;
a. Operational risk – the risk that business operations will be
disrupted due to inadequate or failed systems, processes,
people, breaches in internal controls, or other unforeseen
catastrophes.

b. Legal or compliance risk – the risk that the company might fail to
comply with applicable laws and regulations such as tax laws,
labor laws, corporation law, anti-money laundering law, and
environment laws among others.

c. Health and safety risk – the risk that unforeseen events could
result to injuries, illness, or even loss of lives.

d. Environmental risk – the risk that the company may fail to


control or minimize factory wastes, emissions, and other
pollutants arising from its business activities.

e. Strategic risk – the risk of selecting an inappropriate strategy or


the failure of implementing an appropriate one.

f. Reputation risk – the risk that reputation or image of the


company will be damaged due to reasons such as improper acts
of corporate officers, poor financial performance, and bad news
about the company among others.

5 BALINA ‖ For Internal Use only


The two important risks that are related to the work of professional
accountants are;
1. Financial reporting risk – is the possibility that the financial statements
of the company will be incorrect due to errors, lapses, or failure to
apply accounting standards such as Internation Reporting Standards
(IFRS)

2. Fraud risk – is the risk arising from deceptive and intentional acts that
results to loss of company assets, resources and reputation.

Risk Management
As defined by the International Organization of Standardization (ISO
31000), risk management is the identification, assessment, and prioritization
of risks followed by coordinated and economical application or resources to
minimize, monitor and control the probability and/or impact of unfortunate
events and to maximize the realization of opportunities.
As stated in the book of Hopkins (2017), there are several definitions of
risk management.
1. Co-ordinated activities to direct and control an organization with
regard to risk. (ISO Guide 73 BS 31100)
2. Process which aims to help organizations understand, evaluate and
take action on all their risks with a view to increasing the probability of
success and reducing the likelihood of failure. (Institute of Risk
Management IRM)
3. All the processes involved in identifying, assessing and judging risks,
assigning ownership, taking actions to mitigate or anticipate them, and
monitoring and reviewing progress. (HM Treasury)
4. Selection of those risks a business should take and those which should
be avoided or mitigated, followed by action to avoid or reduce risk.
(London School of Economics)
5. A process, effected by an entity’s board of directors, management, and
other personnel, applied in strategy setting and across the enterprise,
designed to identify potential events that may affect the entity, and
manage risks to be within its risk appetite, to provide reasonable
assurance regarding the achievement of entity objectives. (COSO)

Risk management is not about controlling/mitigating risk out of


existence. If business is to perform, management must learn to take more
risk and to accept failure. To perform better than the rest, you must take
greater risk, but it should be a calculated risk (the risk accepted is known, as
is the likelihood and impact). It is not acceptable to take risks unwittingly –
the past practice of silo-based approaches for managing pockets of risk, leads
to unclear responsibilities and a lack of visibility, thereby exposing the
organization to unnecessary risk.

Basic Principles of Risk Management


The main principle of risk management is that it delivers value to the
organization. In other words, risk management activities are designed to
achieve the best possible outcome and reduce volatility or uncertainty of

6 BALINA ‖ For Internal Use only


outcomes. However, risk management operates on a broader set of
principles, and there have been several attempts to define these principles.
Risk management should:
1. Create value – resources spent to mitigate risk should be less than
the consequence of inaction.
2. Address uncertainty and assumptions
3. Be an integral part of the organizational processes and decision-
making
4. Be dynamic, iterative, transparent, tailorable, and responsive to
change
5. Create capability of continual improvement and enhancement
considering the best available information and human factors
6. Be systematic, structured and continually or periodically reassessed.

The objectives for risk management provide the acronym MADE2 and this
confirms that outputs from risk management will lead to less disruption to
normal efficient operations, a reduction of uncertainty in relation to tactics
and improved decisions in relation to evaluation and selection of alternative
strategies. In other words, a key part of risk management is improved
organizational decision making.
The resources available for managing risk are finite and so the aim is
to achieve an optimum response to risk, prioritized in accordance with an
evaluation of the risks. Risk is unavoidable and every organization needs to
take action to manage it in a way that it can justify to a level that is
acceptable. The appropriate range of responses will depend on the nature,
size and complexity of the organization and the risks it faces .

Roles in the Risk Management Process


Everyone has a role to play in the company’s risk management
process. the following summarizes the duties of key people pertaining to the
management of risks:
1. Board of directors – conducts an oversight of the effectiveness of the
company’s risk management process.

2. Management – implements specific risk mitigation and control


procedures in managing the various types of risks affecting the
company.

3. Internal auditors – conduct examination of the risk management process


for the purpose of determining its effectiveness over time.

4. Other personnel – implement specific tasks and duties pertaining to the


processes within their departments.

Risk Management: Basic Ideologies


1. Manage risk where risk occurs. This includes:
a. Across the entire organization when needed
b. All of its endeavors whether internal or external
c. Administration and management level
d. Assets and resources

7 BALINA ‖ For Internal Use only


e. Marketing
f. Public Relations
g. Financial Management

2. Prioritization. Know which ones require the most attention and


immediate action. Risk listing and ranking may cover the following areas
of concern:
a. Grievance to injury and casualty aftermaths
b. Damage to persona, reputation, and integrity
c. Damage to private property
d. Damage to structural resources
e. Environmental damage

3. Resource allocation and loading. This refers to the priority given to


risk management program beyond just the usual attention. Conscious
efforts should be pursued in ensuring that funding is made available to
run the program.

Steps in the Risks Management Process

1. Setting of business objectives.


The risk management process starts with the setting of business
objectives. In this regard, the COSO Risk Management framework
categories business objectives into strategic, operational, reporting,
and compliance.
Descriptions of the four business objectives are shown below:
a. Strategic objectives – are high-level goals aligned with and support
the organization’s mission and long-term vision.

b. Operational objectives – are goals that are related to the effective


and efficient use of corporate resources.

c. Reporting objectives – are goals relating to the reliability and


transparency of corporate reports such as financial and non-
financial reports.

d. Compliance objectives – are goals relating to compliance and


conformity with applicable laws and regulatory requirements.

2. Identify the risks.


After setting the various objectives of the business, the risks or
threats to the achievement of those objectives are identified. This is
the process called risk identification. To be able to identify risks, risk
managers must possess a comprehensive understanding of the
company, the way it operates and corporates mission and vision, major
transactions, products and services, suppliers and customers, and
regulatory environment among others.

3. Asses the risks.

8 BALINA ‖ For Internal Use only


Any risk has dimensions: (1) the probability that something can
go wrong and (2) the negative consequence or impact if that event
occurs. Hence, identified risks should be assessed in terms of (1)
likelihood of occurrence and (2) impact. “Likelihood” pertains to the
probability that the event will occur. In other words, likelihood means
the chance of occurrence. It is often classified into high, moderate, or
low.
On the other hand, “impact” refers to the significance or
magnitude of the negative effect of the risk to the company. The
“impact” of a risk is also classified into high, moderate, or low.
Analyzing risk in terms of likelihood and impact is known as risk
assessment.

4. Respond to the assessed risks.


Management will select the appropriate risk response depending
on the result of the risk assessment which can be high, moderate, or
low. Possible responses to assessed risk are listed as follows:
a. Accept – Tolerating or accepting the risk is permissible only if it
is of minor effect to the business or if its likelihood is “remote”
such that it is not worth the money or effort to do anything
about it.

b. Reduce – Risks that are likely to happen or those that are


expected to have a significant impact to the business cannot be
simply accepted. These risks should be mitigated or reduced to
tolerable levels. Reducing risks can be done through
implementing controls or specific risk mitigation plans.
c. Share – In some situations, the appropriate response might be to
share or transfer the risks to some other entity such as an
insurance [Link] insurance company manages other
people’s risks.

d. Avoid – Avoiding a risk may be the right response when


management thinks that mere reducing it is not enough. For
instance, the company may terminate one of its product lines if
it assesses the operating it has become too risky.

5. Implement the risk response.


Implementing the risk response is done through deploying
specific risk mitigating plans or management action plans to control
the risks.

6. Monitor the risk management process.


The risk management process must be continuously monitored
to determine if it remains to be effective and efficient over time. A risk
management process that is effective today may no longer be effective
for the next period. Therefore, there must be a periodic evaluation of
the risk management process. this is usually done through internal
audit process.

9 BALINA ‖ For Internal Use only


Assessment of Risks and Selection of Risk Strategies
The 2004 COSO Enterprise Risk Management framework can be
illustrated through a diagram known as the COSO Cube.

The top portion of the cube highlights the four objectives of risk
management. The front section of the cube identifies the eight components
of risk management. These are the elements that make up the risk
management process.

1. Internal environment. This component reflects the company’s risk


management philosophy, risk appetite, board oversight, commitment
to ethical values and competence of the human resource, and the
assignment of authority and responsibility. It encompasses the “tone
at the top: and it influences the governance process as well as the risk
and control consciousness of people in the company.

Internal Environment
Risk Management – Risk Appetite – Board of Directors – Integrity and
Ethical Values – Commitment to Competence – Organizational Structure
– Assignment of Authority and Responsibility – Human Resource
Standards
2. Objective setting. Objective setting is a precondition to event
identification, risk assessment, and risk response. It follows, therefore,
that without the setting of clear objectives, it will not be possible to
identify risks. Management sets strategic objectives which provide a
context for operational, reporting, and compliance objectives. Strategic
and other objectives are formulated within the company’s risk appetite
or the level of risk that the company can accept.

Objective Setting
Strategic Objectives – Related Objectives – Selected Objectives – Risk
Appetite – Risk Tolerances

10 BALINA ‖ For Internal Use only


3. Event identification – Management identifies potential events that
may affect the company’s ability to achieve its strategic, operational,
reporting, and compliance objectives. These potential events can be
internal or external. The events may also be categorized as potentially
or potentially negative events. Potentially negative events are risks.
Potentially positive events represent opportunities, which management
channels back into the objective-setting process. In identifying risks,
management applies various event identification techniques such as
facilitated workshops, technical sessions, and brainstorming among
others.

Event Identification
Events – Influencing Factors – Event Identification Techniques – Event
Interdependencies – Event Categories – Distinguishing Risks and
Opportunities

4. Risk Assessment – Management considers different assessment


techniques and uses various data sources to evaluate the likelihood
and impact of the identified potential events. likelihood and impact
assessments may be high, moderate, or low. In addition, inherent and
residual risks will also be assessed.
a. Inherent risks – is the susceptibility of the company to risk in the
absence of any actions management might take to alter the
risk’s likelihood or impact.
b. Residual risks – is the risk that remains after applying
management’s response to the risk. Management must evaluate
whether this residual risk is within the company’s risk appetite.
Risk Assessment
Inherent and Residual Risk – Establishing Likelihood and Impact – Data
Sources – Assessment Techniques – Event relationships

5. Risk Response. Management considers alternative risk response


options and their effect on risk likelihood and impact with the goal of
reducing residual risk to within desired risk tolerances. Risk response
planning determines the development of risk mitigation policies and
controls.

Risk Response
Evaluating Possible Responses – Selected Responses – Portfolio View

6. Control Activities. Management implements specific risk mitigation


policies and procedures throughout the organization, at all levels and
in all functions, to help ensure that risk responses are properly
executed. Control activities to be developed must be integrated with
risk response. The risk response, on the other hand, must be also
integrated with the result of the risk assessment.
Control Activities
11Integration
BALINA ‖with Risk Response
For Internal Use only – Types of Control Activities – Policies
and Procedure – Controls over Information Systems – Entity Specific
7. Information and Communication – The company identifies, captures,
and communicates pertinent information from internal and external
sources to enable personnel in carrying out their responsibilities.
Conversely, without information and communication, people in the
company will not be able to perform their functions in an appropriate
manner.

Information and Communication


Information - Communication

8. Monitoring – Ongoing activities and separate evaluations assess both


the existence and effective functioning of the risk management
components and the quality of their performance over time. For anu
given objective, management must evaluate the eight risk
management components Erm at the appropriate level, such as the
entity or business unit-level.
Monitoring
Ongoing Monitoring Activities – Separate Evaluations – Reporting
Deficiencies

Risk Assessment

Assigning Risk Ratings


Risks identified should be assessed in terms of likelihood and impact.
Assessment of likelihood and impact involves assigning a qualitative risk
rating such as “high”. “moderate”, or “low”. It may also be done
quantitatively such as assigning specific risk scores (0 to 5) to each identified
risk. Management is most concerned with risks that have “high” likelihood
and “high” potential impact.

Assessment of Likelihood

Qualitative Ratings for Likelihood

Qualitative rating Description


Low There is a small chance that the event will happen.
Moderate There is a moderate possibility that the event will
happen.
High There is a big probability that the event will

12 BALINA ‖ For Internal Use only


happen.

Quantitative Ratings for Likelihood

Qualitative rating Description


1 There is only REMOTE chance that the event will
happen.
2 It is LESS LIKELY that the event will happen.
3 It is LIKELY that the event will happen.
4 It is VERY LIKELY that the event will happen.
5 It is VIRTUALLY CERTAIN to happen.

Assessment of Impact
By its very nature, a risk always has a negative impact. However, the
impact of risks varies in terms of its potential consequence to profit,
reputation, health, environment, or some other critical factor. Impact pertains
to the magnitude or consequence of the event of risk to the company.
Impact can be assessed either qualitatively or quantitively. The
following tables show possible risk ratings for impact assessment:

Qualitative Ratings for Impact

Qualitative rating Description


Low Minor effect to the company
Moderate Medium impact to the company
High Significant impact to the company

Quantitative Ratings for Impact

Qualitative rating Description


1 Insignificant or negligible impact
2 Minor impact
3 Moderate impact
4 Major impact
5 Catastrophic effect

Risk Maps
Assessment of likelihood and impact can be shown on a risk map. A
risk map is a graphic or visual representation of the likelihood and impact of
one or more risks. Risk ratings can be plotted on the plot. To provide better
visuals, color coding is often applied depending on risk levels where
significant risks are colored red. Moderate risks and minor risks are colored
green and yellow, respectively.

13 BALINA ‖ For Internal Use only


Combined Assessments and Risk Response
Risks on a risk map can be interpreted as:
1. Low likelihood / Low impact – these are the risks on the bottom left
corner of the risk map. Since the combined risk assessment is only
“low”, management can ordinarily accept these risks. Hence, risk
response would be to “accept the risk.”
2. High likelihood / High impact – these are the risks on the top right
corner of the risk map. These risks cannot be accepted for they are
significant risks. Therefore, management gives top priority to these
risks. Available responses for these risks are to “mitigate”, “share”, or
“avoid.” Management should make sure that these risks are addressed
through implementing risk mitigation plans and specific control
activities.
3. High likelihood / Low Impact and High impact / low likelihood – these
are moderate risks. Management may not simply ignore these risks as
they can still affect the company. Because they are not minor risks,
management should exert efforts in reducing these moderate risks.

High
LIKELIHOOD

Reduce Avoid
Occurrenc
e Accept Share
Frequency
Amount of High
Low Damage
IMPACT

14 BALINA ‖ For Internal Use only


Risk Response
Priority significant risks facing an organization are those that have:
 high or very high impact in relation to the benchmark test for
significance;
 high or very high likelihood of materializing at or above the benchmark
level;
 high or very high scope for cost-effective improvement in control.

ISO 31000 also suggest that once risks have been identified and
assessed, techniques to manage the risk should be applied. These techniques
can fall into one or more of these four categories:
1. Risk Avoidance. This includes performing an activity that could carry
risk. Avoiding risks, however, also means losing out on the potential
gain that accepting (retaining) the risk may have allowed. Not entering
a business to avoid the risk of loss also avoids the possibility of earning
profits.
2. Risk Reduction. Involves reducing the severity of the loss or the
likelihood of the loss from occurring. Optimizing risks means finding a
balance between the negative risk and the benefit of the operation or
activity; and between risk reduction and effort applied.
3. Risk Sharing. It means sharing with another party the burden of loss or
the benefit of gain, from a risk, and the measures to reduce a risk.
4. Risk Retention. It involves accepting the loss or benefit of gain from a
risk when it occurs.

The benchmark test for significance should be set at a level that


represents a significant impact for the organization. Having identified the
priority significant risks, the organization then needs to review the controls in
place and decide whether further actions are required. For hazard risks, the
range of responses available is often described as the 4Ts.

1. Tolerate The exposure may be tolerable without any further


Accept/retain action being taken. Even if it is not tolerable, the
ability to do anything about some risks may be
Detective limited, or the cost of taking any action may be
disproportionate to the potential benefit gained.

Detective controls are those procedures that


identify when the hazard has materialized.
Detecting that a hazard has materialized sometime
after the event is not entirely satisfactory, but can
be justified in certain circumstances. Sometimes,
other controls may be unable to completely
eliminate the chances of a risk materializing. The
advantage of detective controls is that they are
often simple to administer. In any case, they are
essential in many circumstances where the
organization will require early warning that other

15 BALINA ‖ For Internal Use only


risk control measures have broken down. The
disadvantage of the detective controls is that the
risk will already have materialized before it is
detected. It could be argued, of course, that the fact
that detective controls are in place will deter certain
individuals from attempting to circumvent other risk
controls.

2. Treat By far the greater number of risks will be addressed


Control /reduce in this way. The purpose of treatment is that, whilst
continuing within the organization with the activity
Corrective giving rise to the risk, action (control) is taken to
constrain the risk to an acceptable level.

Corrective controls are the next option after it


has been decided that preventive controls are not
technically feasible, operationally desirable or cost-
effective. Corrective controls are capable of
producing an entirely satisfactory result, whereby
the current level of risk is reduced to within the risk
appetite of the organization. The advantage of
many corrective controls is that they can be simple
and cost effective. Also, they do not require that
existing practices and procedures are eliminated or
replaced with alternative methods of work. The
controls can be implemented within the framework
of existing activities. The disadvantage of some
corrective controls is that the marginal benefits that
are achieved may be difficult to quantify or confirm
as cost-effective.

3. Transfer For some risks the best response may be to transfer


Insurance/contract them. This might be done by conventional
insurance, or it might be done by paying a third
Directive party to take the risk in another way. This option is
particularly good for mitigating financial risks or
risks to assets.

Organizations will be familiar with the directive


controls, because staff will need to be advised of
the correct way of undertaking specific tasks.
Where tasks involve a level of risk, documented
procedures, together with information, training and
instruction, can be seen as directive controls.
Therefore, directive controls are likely to be in place
for most risks, regardless of whether other types of
controls also exist.

4. Terminate Some risks will only be treatable, or containable to


Avoid/eliminate acceptable levels, by terminating the activity. It
should be noted that the option of termination of

16 BALINA ‖ For Internal Use only


Preventive activities may be severely limited in government
when compared to the private sector.

These are the most important type of risk


controls, and all organizations will use preventive
controls to treat certain types of risks. Prevention or
elimination of all risks is not possible on a cost-
effective basis, nor may it be desirable for the
future of the organization and the continuation of
certain activities. The advantage of preventive
controls is that they eliminate the hazard, so that no
further consideration of it is required. In reality, this
may not be a cost-effective option and may not be
possible for operational reasons. The disadvantages
of preventive controls are that beneficial activities
may be eliminated and either outsourced or
replaced with something less effective and efficient.

Enterprise Risk Management


In the past few years, there have been important developments in the
practice of risk management. Firstly, there has been the development of
specialist branches of risk management, including project, energy, finance,
operational risk and clinical risk management. Secondly, organizations have
embraced the desire to take a broader approach to the practice of risk
management.
ERM takes a unifying, broader and more integrated approach. The ERM
approach means that an organization looks at all the risks that it faces across
all of the operations that it undertakes. ERM is concerned with the
management of the risks that can impact the objectives, key dependencies or
core processes of the organization. Also, ERM is concerned with the
management of opportunities, as well as the management of control and
hazard risks.
There has also been consideration of the fact that many risks are
interrelated and that traditional risk management fails to address the
relationship between risks. With the ERM approach, the relationship between
risks is identified by the fact that two or more risks can have an impact on
the same activity or objective. The ERM approach is based on looking at the
objective, key dependency or core process and evaluating all of the risks that
could impact the item being evaluated. Enterprise risk management has
become the established means of undertaking risk management activities
within most organizations. This allows the organization to gain an overview of
all the risks that it faces so that it can take coordinated actions to manage
these risks. Nevertheless, the specialist risk management functions, such as
health and safety and business continuity continue to make a valuable
contribution.

Enterprise Risk Management is said to be;

17 BALINA ‖ For Internal Use only


1. a strategic business discipline that supports the achievement of an
organization’s objectives by addressing the full spectrum of its risks
and managing the combined impact of those risks as an interrelated
risk portfolio.
2. a process, effected by an entity’s board of directors, management and
other personnel, applied in a strategy setting and across the
enterprise, designed to identify potential events that may affect the
entity, manage risk to be within its risk appetite and to provide
reasonable assurance regarding the achievement of entity objectives.
3. A rigorous and coordinated approach to assessing and responding to
all risks that affect the achievement of an organization’s strategic and
financial objectives
4. All the processes involved in identifying, assessing and judging risks,
assigning ownership, taking actions to mitigate or anticipate them and
monitoring and reviewing progress.
5. ERM involves the identification and evaluation of significant risks,
assignment of ownership, implementation and monitoring of actions to
manage these risks within the risk appetite of the organization.
6. The output is the provision of information to management to improve
business decisions, reduce uncertainty and provide reasonable
assurance regarding the achievement of the objectives of the
organization.
7. The impact of ERM is to improve efficiency and the delivery of services,
improve allocation of resources (capital) to business improvement,
create shareholder value and enhance risk reporting to stakeholders.

Here are some of the list of the benefits of the ERM;


Financial  Reduced cost of funding and capital
 Better control of CapEx approvals
 Increased profitability for organization
 Accurate financial risk reporting
 Enhanced corporate governance
Infrastructure  Efficiency and competitive advantage
 Achievement of the state of no
disruption
 Improved supplier and staff morale
 Targeted risk and cost reduction
 Reduced operating costs
Reputational  Regulators satisfied
 Improved utilization of company brand
 Enhanced shareholder value
 Good reputation and publicity
 Improved perception of organization
Marketplace  Commercial opportunities maximized
 Better marketplace presence
 Increased customer spend (and
satisfaction)
 Higher ratio of business successes
 Lower ratio of business disasters

18 BALINA ‖ For Internal Use only


Future of Risk Management
The development of international risk management standard ISO
31000 is undoubtedly an important step forward for risk management
practitioners. The emergence of enhanced corporate governance codes has
also added profile to the
practice of risk management in many countries. The effects of the global
financial crisis are still being felt and questions are still being asked of risk
management and why it did not contribute more to the avoidance of this
crisis.
management.
The emergence of ‘governance, risk and compliance’ (GRC) has been
mentioned and it represents a major step forward in the structure of risk
management activities. The emergence of GRC, together with a better
understanding of the benefits of the three lines of defense, has put
organizations in a better position to practice risk management. Risk
management practitioners realize that their discipline makes a major
contribution and they are also aware that risk management activity should be
integrated with other management activities. In some cases, there is every
danger that risk management activities will become integrated with audit
activities, and these three lines of defense then become the two lines of
defense.
In summary, the challenge for risk managers and risk management is
to keep risk management activities proportionate, aligned, comprehensive,
embedded and dynamic (PACED). However, the challenges of doing this are
becoming greater as boards, executive management, managers and staff
become more familiar with the theory and application of risk management.
The challenge is to ensure integration of these activities, without them
becoming so routine that the importance of risk management is lost. Risk
management activities need to be linked to discussion of strategy, tactics
and operations, as well as being linked to discussion of business delivery,
budgets and the business development model.
Every day, managers and employees practise risk management by making
decisions on what to do, and how and when to do it. Decisions have to be
based on factors like does the organization have the capacity, has the
organization set aside the funds and will this impact other business units.
ERM is not just a passing trend. It is here to stay and is being driven by both
governance issues and the demands of society. Companies, charities and
public-sector organizations have successfully embraced ERM. Risk
management does not have to be complex or a heavy resource user. It can
be tailored to meet the needs of the organization in its early stages and
modified as the level of sophistication and comfort with the process grows. It
is a systematic and proactive approach to managing risk. This means that
high-risk exposure areas are understood, managed and controlled to an
acceptable level of exposure so that the organization is properly protected to
minimize negative consequences. It allows the organization to focus on what
is important to control versus what is easy to control.

19 BALINA ‖ For Internal Use only

You might also like