0% found this document useful (0 votes)
3 views3 pages

Chapter 5 Risk Management Processes

Chapter 5 discusses risk management processes, emphasizing the systematic identification, assessment, and response to risks while aligning with organizational objectives. It highlights the COSO ERM framework and the essential components for effective risk management, including the role of internal audit and the use of risk matrices and registers. The chapter also addresses challenges in risk management, such as concealed risks and excessive risk aversion, while providing strategic lessons from the Marconi case.

Uploaded by

Aiah Lampitoc
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views3 pages

Chapter 5 Risk Management Processes

Chapter 5 discusses risk management processes, emphasizing the systematic identification, assessment, and response to risks while aligning with organizational objectives. It highlights the COSO ERM framework and the essential components for effective risk management, including the role of internal audit and the use of risk matrices and registers. The chapter also addresses challenges in risk management, such as concealed risks and excessive risk aversion, while providing strategic lessons from the Marconi case.

Uploaded by

Aiah Lampitoc
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 5 – Risk Management Processes

1. Meaning and Objectives of Risk Management


- Risk management is the systematic process of:
• Identifying risks
• Assessing their likelihood and impact
• Selecting appropriate responses
• Monitoring and communicating risks

The main objective is not to eliminate all risks, but to ensure risks remain within the organization’s risk appetite
(acceptable level of risk).

Core Objectives of Risk Management


Objective Explanation
Alignment with mission Organizational goals must support the organization’s mission
Identification of risks Significant internal and external risks must be recognized
Appropriate responses Risk responses should match the organization’s risk appetite
Communication Risk information should be shared promptly across the organization

2. COSO Enterprise Risk Management (ERM) Framework


- The chapter heavily references the Committee of Sponsoring Organizations of the Treadway Commission
Enterprise Risk Management framework.

COSO defines ERM as a process used by boards, management, and employees to identify and manage risks affecting
organizational objectives.

Four COSO Risk Management Objectives


Objective Category Description
Strategic High-level goals aligned with mission
Operations Effective and efficient use of resources
Reporting Reliable reporting and information
Compliance Compliance with laws and regulations

3. Essential Components of Effective Risk Management


- COSO identifies eight components necessary for effective ERM.
Component Purpose
Internal Environment Organizational culture and ethical tone
Objective Setting Establishing goals aligned with mission
Event Identification Recognizing possible risk events
Risk Assessment Evaluating likelihood and impact
Risk Response Choosing how to address risks
Control Activities Policies and procedures to reduce risks
Information & Communication Sharing risk information effectively
Monitoring Continuous review and improvement

These components show that risk management is not only about avoiding losses but also about integrating risk
thinking into strategic decision-making.

4. Internal Audit’s Role in Risk Management


- Internal audit has both:

Assurance roles — evaluating risk management effectiveness


Consulting roles — advising management on risk-related matters

However, internal auditors must not take management responsibility for risks.
Internal Audit Activities:
Appropriate Roles Inappropriate Roles
Evaluating risk management processes Setting risk appetite
Reviewing key risks Taking risk decisions
Providing assurance Managing risks directly
Facilitating risk identification Implementing controls for management

This separation preserves the independence and objectivity of internal auditors.

5. Risk Matrix: A Key Risk Management Tool


- A risk matrix measures risk based on:

• Likelihood of occurrence
• Impact if the event occurs

Types of Risk
Type Meaning
Inherent Risk Risk without controls
Gross Risk Risk before additional mitigation
Residual Risk Remaining risk after controls

Residual risk should ideally remain within the organization’s risk appetite.

6. Risk Response Strategies


- The chapter explains four major responses depending on the seriousness of the risk.

Risk Quadrant Characteristics Appropriate Response


A. High likelihood, high impact Continuous top management attention
B. Low likelihood, high impact Contingency planning or risk termination
C. High likelihood, low impact Strong control procedures
D. Low likelihood, low impact Monitoring

This framework helps organizations allocate resources effectively.

7. Risk Registers
= A risk register is a structured document used to record and monitor risks.

Typical contents include:


1. Risk description
2. Likelihood and impact
3. Controls in place
4. Risk owner
5. Residual risk
6. Action plans

Importance of Risk Registers:


• Centralizes risk information
• Clarifies accountability
• Helps monitor mitigation activities
• Supports audit and governance functions
8. Important Challenges in Risk Management
- The chapter emphasizes several limitations and challenges.

A. Concealed Risks
- Some major risks may remain hidden because:
• Management focuses only on visible goals
• Employees fear reporting problems
• Organizational culture discourages openness

Example:

The nuclear company case showed how falsified quality data caused massive financial and reputational damage
because risks were hidden from top management.

B. Multiple Simultaneous Risks


- Organizations often fail not because of one risk, but because several risks occur at the same time.
Example:
The home loans company collapsed due to:
• Economic crisis
• High interest rates
• Rising unemployment
• Banking instability

This demonstrates the importance of scenario planning and crisis preparedness.

C. Missing Opportunities
- Risk management should also identify opportunities, not only threats.
Organizations that fail to respond quickly to opportunities may lose:
• Market share
• Competitive advantage
• Innovation potential

D. Excessive Risk Aversion


- The text warns against avoiding all risks.

“Profit is the reward for taking risk.”

Organizations must balance:


• Caution
• Innovation
• Growth opportunities

9. Strategic Lessons from the Marconi Case


- The Marconi case illustrates the dangers of poor strategic risk management.

You might also like