0% found this document useful (0 votes)
3 views4 pages

9. Risk

The document provides an overview of risk and risk management, defining risk as the possibility of negative outcomes that vary by company and industry. It categorizes different types of risks, such as market, liquidity, and reputation risks, and discusses the importance of managing these risks through a structured process involving risk appetite and the ALARP principle. Additionally, it introduces practical tools like the Risk Register, TARA framework, and Risk Heat Map to help organizations effectively identify, assess, and prioritize risks.

Uploaded by

mbilper784
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views4 pages

9. Risk

The document provides an overview of risk and risk management, defining risk as the possibility of negative outcomes that vary by company and industry. It categorizes different types of risks, such as market, liquidity, and reputation risks, and discusses the importance of managing these risks through a structured process involving risk appetite and the ALARP principle. Additionally, it introduces practical tools like the Risk Register, TARA framework, and Risk Heat Map to help organizations effectively identify, assess, and prioritize risks.

Uploaded by

mbilper784
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Hello everyone. Let's take a look at these documents together.

Think of me as your guide,


walking you through the fundamental concepts of risk and risk management. We'll break this
down step-by-step, just like we would in a classroom.

Lecture 1: What is Risk and the Different Types?

Let's start with the most basic question: What is risk?

In simple terms, risk is the possibility that things might not go according to plan and that the
outcome could be negative. It's the uncertainty we face when we look to the future.

Now, here's a crucial point: risk is not the same for every company. It varies depending
on several internal and external factors. Think of two different businesses:
 A small, local bakery versus a large, multinational technology corporation.
 A new start-up versus a well-established manufacturer.

Their risks are completely different because of factors like their size, where they operate,
what stage of growth they're in, and how they are financed.

Similarly, risk varies by industry. A bank faces different risks than an oil company. An
online retailer faces different risks than a physical store. This is because of the nature of their
products, the technology they use, the regulations they must follow, and the amount of
investment required.

Now, let's look at the specific types of risks a company might face. The document
categorizes them neatly. I'll explain them one by one.
1. Market Risk: This is the risk of financial loss from changes in market prices. For
example, the price of raw materials a company needs, or the value of its investments.
If a company imports goods, a change in foreign exchange rates could suddenly make
those goods much more expensive.

2. Liquidity Risk: This is a very serious risk. It's the risk that a company won't have
enough cash to pay its bills when they are due. Imagine a business that has lots of
assets, like property, but no cash in the bank. If a large payment is due today and they
can't sell their property quickly enough, they face a liquidity crisis.

3. Technological Risk: This is a risk from changes in technology. Companies constantly


have to decide whether to adopt new tech. Adopting too early can be expensive and
risky if the technology fails. Adopting too late can mean losing a competitive edge to a
rival who is more efficient or innovative.

4. Legal Risk: This is the risk of losses from failing to comply with laws. This could be
from getting sued, being fined by the government, or having contracts voided.

5. Health & Safety Risk: This is the risk of injury or illness to employees, customers, or
the public. Companies have a legal duty to provide a safe environment. If they fail,
they can face huge fines, lawsuits, and significant damage to their reputation.

6. Reputation Risk: This is the risk of damage to a company's brand or public image.
This is a difficult risk to measure, but it can be devastating. A single scandal, data
breach, or product failure can destroy customer trust and loyalty, leading to lost sales.
Companies often hire public relations experts to help monitor and protect their
reputation.
7. Business Probity Risk (Honesty & Integrity): This is the risk from acting
dishonestly. Examples include paying bribes to secure contracts or dealing with
smugglers. This exposes the company to serious legal and regulatory action and
destroys trust.

8. Credit Risk: This is the risk of loss because a customer fails to pay their debts or pays
very late. This is a major risk for banks and lenders, but also for any company that
sells goods or services on credit.

9. Environmental Risk: This is the risk of losses from damage to the environment, such
as pollution. A company could be fined for breaking environmental regulations or lose
customers who are concerned about environmental issues.

Finally, the document introduces derivatives. Don't get bogged down by the jargon. Simply
put, derivatives are financial contracts whose value is based on something else. They can be
used to speculate (bet on price changes) or, more importantly, to hedge (protect against)
market risks. A hedging strategy is like buying insurance against a price change.

Lecture 2: Managing Risk: Appetite and the ALARP Principle

Now that we know what risk is and what types exist, how do we manage it? This is the core
of Risk Management. It's the process of reducing the negative impact of bad events. We do
this by trying to reduce how likely an event is to happen or how bad the consequences will
be if it does.

A key concept here is Risk Appetite.

Imagine you're an investor. Some people are willing to take big risks for a chance at high
returns. Others want a safe, steady return, even if it's smaller. Companies are the same. Risk
appetite is the amount of risk an organization is willing to take in pursuit of its
objectives. This attitude is often decided by the shareholders and the board of directors. A
company with a high risk appetite might invest in a risky new market. A conservative
company with a low risk appetite might stick to safer, more established areas. This appetite
then shapes the company's risk policy and the controls they put in place.

Now, let's discuss a fundamental principle: ALARP (As Low As Reasonably Practicable).

It is almost impossible to eliminate every single risk. So, the goal of risk management is not
to create a zero-risk environment, but to reduce risk to a tolerable level.

The ALARP principle is about balancing risk against the cost of reducing it.
 On one side, you have the impact and likelihood of a risk happening.
 On the other side, you have the cost to mitigate it (to put controls in place to make
it safer).

You can't spend a million dollars to protect against a risk that might only cause a thousand
dollars of damage. That's not reasonable. The 'tolerable level' is where the cost of further risk
reduction is grossly disproportionate to the benefit you would get. It's the Board's role to
decide what this ALARP level is for the company. And remember, even the remaining risk (the
residual risk) must be constantly monitored because the world changes.

The Risk Management Process:


Managing risk is not a one-off activity; it's a continuous cycle. Here's a simplified version of
the steps in the document:
1. Commitment from the Top: Risk management must start at the very top. The Board
of Directors and senior management must be fully committed and set the tone for the
whole organization.
2. Create a Risk Committee: A formal committee at the board level should be
established to oversee risk management.
3. Risk Assessment: This is the core process of figuring out what risks you face. It's
broken down into:
o Identify: What are all the risks we face?
o Assess: What is their potential impact, and how likely are they to occur?
o Prioritize: Which risks are the most serious and need our immediate attention?
4. Plan Mitigating Strategies: For each major risk, develop a plan to manage it.
5. Prepare a Risk Register: Document everything formally in this crucial document.
6. Regular Monitoring: Risks are not static. They change. You must constantly monitor
their impact, likelihood, and the effectiveness of your controls.
7. Staff Training and Audit: Everyone in the company should be aware of risks, and
internal audits can check if your controls are working.

Lecture 3: The Tools of Risk Management

In this final section, we'll look at the practical tools mentioned in the documents: The Risk
Register, the TARA Framework, and the Risk Heat Map.

1. The Risk Register

Think of the Risk Register as the master document, or the "risk database," for the entire
company. It's a formal document that lists all the risks a company faces, along with key
information for managing them. It's structured like a table, with columns for:
 [Link].: A serial number for each risk.
 Description: A clear description of the risk.
 Impact: How severe the consequences would be if the risk happened.
 Likelihood: The probability of the risk happening.
 Priority: A ranking based on the impact and likelihood (this is where the heat map
comes in).
 Owner: The person or department responsible for managing this specific risk.
 Mitigating Action: The strategy in place to deal with the risk (this is where the TARA
framework comes in).
 Frequency of Review: How often the risk's status should be checked.

The Risk Register helps us prioritize risks, allocate resources effectively, and get a complete,
holistic view of how the company is managing its risks.

2. The TARA Framework

The TARA framework gives us a menu of options for how to deal with a specific risk once
we've identified it. TARA stands for four possible strategies:
 Transference (or Sharing): This means shifting the risk to a third party. The most
common example is buying insurance. You pay a premium, and the insurance
company takes on the financial risk.

 Acceptance: Sometimes, the best option is to do nothing special and just accept the
risk. This is usually done when the potential impact of the risk is very small or
minimal. You understand the risk and are prepared to deal with it if it happens.
 Avoidance: This means taking the risk down to zero by avoiding the risky activity
altogether. For example, a company might withdraw from a specific volatile market or
decide not to launch a controversial new product. The limitation is that sometimes,
risks are unavoidable in business.

 Reduction: This is the most common strategy. It means taking action to limit the
risk. You can't eliminate it, but you can try to reduce its likelihood or its impact. For
example, implementing safety training reduces the likelihood of workplace accidents.
Putting in place backup generators reduces the impact of a power outage.

3. The Risk Heat Map

A heat map is a powerful visual tool, usually a 3x3 grid. It helps you prioritize risks based on
their impact and probability.
 The X-axis (horizontal) represents Probability/Likelihood (Low, Medium, High).
 The Y-axis (vertical) represents Impact (Low, Medium, High).

Each risk you've identified is plotted on the grid.


 Risks in the top-right corner (High Impact, High Probability) are the most critical.
They are the "red zone" and need immediate and significant management attention.
 Risks in the bottom-left corner (Low Impact, Low Probability) are the least
concerning. They are the "green zone" and might just need to be accepted or
monitored.
 Risks in the middle areas require moderate attention.

The Heat Map provides an instant, visual snapshot of the company's risk profile, making it
very easy for the Board and management to see where to focus their efforts.

Summary & Final Word

To bring it all together:


 Risk is the possibility of a negative outcome.
 Different companies and industries face different types of risk, which can be
categorized, such as Market, Liquidity, and Reputation risk.
 The goal of Risk Management is to reduce risk to a tolerable level, guided by the
company's Risk Appetite and the ALARP Principle.
 We manage risks through a continuous process that includes identifying, assessing,
planning, and monitoring.
 We document all risks in a Risk Register, decide on a strategy using the TARA
framework (Transfer, Accept, Reduce, Avoid), and visualize priorities with a Risk
Heat Map.

Risk is an inherent part of business. The goal is not to avoid it entirely, but to understand it,
manage it intelligently, and ensure the company can navigate uncertainty to achieve its
objectives. These documents provide the fundamental tools and concepts to do just that.

You might also like