0% found this document useful (0 votes)
21 views40 pages

Liquidity Analysis for Investors in Able Inc.

Thank you

Uploaded by

aspirantuscma
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
21 views40 pages

Liquidity Analysis for Investors in Able Inc.

Thank you

Uploaded by

aspirantuscma
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

PART 2

PART 2 UNIT 4

4
2D. Enterprise Risk Management

Module

1 D.1. Enterprise Risk Management: Part 1 3

2 D.1. Enterprise Risk Management: Part 2 17


NOTES

4–2 © Becker Professional Education Corporation. All rights reserved.


1
MODULE
PART 2 UNIT 4

D.1. Enterprise Risk


Management: Part 1
Part 2
Unit 4

This module covers the following content from the IMA Learning Outcome Statements.

CMA LOS Reference: Part 2—Section D.1. Enterprise Risk Management: Part 1

The candidate should be able to:


a. identify and explain the different types of risk, including business risk, hazard risks,
financial risks, operational risks, and strategic risks
b. demonstrate an understanding of operational risk
c. define legal risk, compliance risk, and political risk
d. demonstrate an understanding of how volatility and time impact risk
e. define the concept of capital adequacy; i.e., solvency, liquidity, reserves, sufficient
capital, etc.
f. explain the use of probabilities in determining exposure to risk and calculate expected
loss given a set of probabilities
g. define the concepts of unexpected loss and maximum possible loss (extreme or
catastrophic loss)
j. demonstrate an understanding of the concept of residual risk and distinguish it from
inherent risk
q. identify and explain qualitative risk assessment tools including risk identification, risk
ranking, and risk maps
r. identify and explain quantitative risk assessment tools including cash flow at risk,
earnings at risk, earnings distributions, and earnings per share (EPS) distributions
s. identify and explain Value at Risk (VaR) (calculations not required)
x. prepare a cost-benefit analysis and demonstrate an understanding of its uses in risk
assessment and decision making

1 Types of Risk

"Risk" is uncertainty and generally refers to exposure to possible negative events, possible
negative outcomes, or possible missed opportunities. Risk is discussed in terms of how risk is
evaluated and managed. Risk categorization may be broad at the strategic level, or narrow at the
operational or transactional level.

© Becker Professional Education Corporation. All rights reserved. Module 1 4–3 D.1. Enterp
1 D.1. Enterprise Risk Management: Part 1 PART 2 UNIT 4

LOS 2D1a 1.1 Business Risk


Business risk is the exposure of an organization to lost profits or failure stemming from both
internal weaknesses and external threats. Business risk is a broad, strategic level of risk.
Inefficient operations or unethical or dysfunctional leadership are risks within an organization.
Regulatory burdens, pandemics, extreme acts of nature, or competition represent external risks.
Organizations employ risk management strategies to manage business risk.

1.2 Hazard Risk


Exposure to a hazard may produce negative results. If there is no exposure to the hazard, a
hazard will not present a risk. Akin to this concept is the idea that risks that are unrelated to
business objectives are not relevant to risk management decisions.

Illustration 1 Risk vs. Hazard

Freezing temperatures seldom occur in southern Florida. While prolonged freezing


temperatures represent a hazard to citrus production, prolonged freezing does not
represent a significant risk in southern Florida.

1.3 Financial Risk


The concept of financial risk includes broad, strategic risks associated with business
capitalization (involving both overall leverage and liquidity) and operational risks associated with
transaction execution and settlement (involving credit risk, default risk, and hedging).

1.4 Strategic Risk


Strategic risk is the risk that external threats could prevent an organization from executing
its strategy. Strategic goals could be disrupted by economic and industry threats such as
competition or general economic slowdowns; regulatory risks that add layers of compliance;
technological or process changes that threaten or disrupt the business model; and political
events, pandemics, and extreme weather conditions or scenarios that might disrupt the
economy or an industry.

LOS 2D1b 1.5 Operational Risk


Operational risk represents the exposure organizations have in their day-to-day operations
separate from the risks presented by the economy or by participation in an industry.
Operational risk comes from internal failures, inefficiencies, flawed processes, human error,
and/or poorly designed systems that produce losses. Operational risk is characterized by
inefficiency (e.g., increased cost) and ineffective delivery of value (e.g., lower production)
resulting from management decisions or human error. These scenarios adversely impact client
satisfaction, business reputation, and shareholder wealth.

4–4 Module 1 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 1
PART 2 UNIT
1 4 D.1. Enterprise Risk Management: Part 1

Illustration 2 Operational Risk in Business

A manufacturing firm may operate at capacity and fail to implement and execute
appropriate maintenance programs. Poor maintenance practices ultimately result in
defective products and decreased production from breakdowns.
A delivery company operating at capacity may fail to properly maintain its fleet of vehicles.
Poor maintenance practices ultimately result in breakdowns, late deliveries, and a damaged
reputation.
A nursing home may fail to install appropriate generator capacity or fail to properly
maintain the generator. This situation could result in interrupted power in the wake of a
disaster with catastrophic results for residents and their families.

Pass Key

Operational risk is the uncertainty that management confronts while conducting the
company's daily business activities, procedures, and systems.
Operational risk is significantly impacted by human error. Mistakes or failures due
to the actions or decisions of company employees are often the reason for adverse
operating results.
Operational risk is a component of overall business risk, distinct from systematic risk and
financial risk.

1.6 Legal Risk LOS 2D1c

Legal risk is broadly defined as the risk of loss due to management's actions that include
defective products, services, and/or transactions, failures to take steps to protect assets (such as
intellectual property), breach of contract or related claims, and failure to adapt to changes in law.
Legal risk is often traced to ethical lapses and the lack of proper communications channels or
undefined institutional objectives that would mitigate this risk. Legal risk is quantified by costs of
litigation and financial and reputational losses that come from either lack of awareness of legal
requirements or negligent, reckless, or intentional disregard for legal requirements.

1.7 Compliance Risk


Compliance risk is the risk of sanctions, fines, or other judgments imposed by a regulatory body
that could create financial or economic harm to an organization. A government agency or other
regulatory body may fine a company for noncompliance with the law while a court may order a
company to cease its business practices, thereby causing economic damage.

© Becker Professional Education Corporation. All rights reserved. Module 1 4–5 D.1. Enterp
1 D.1. Enterprise Risk Management: Part 1 PART 2 UNIT 4

1.8 Political Risk


Political risk is the risk that a political change will increase or decrease the probability of
achieving a business or strategic objective, favorably or unfavorably alter expected outcomes,
or increase or decrease the value of an economic action. Political risk is faced by investors,
corporations, and governments alike. For example, increased corporate taxes decrease the
profitability of businesses while increasing the resources available to the government.

LOS 2D1j 1.9 Inherent Risk and Residual Risk


Inherent risk is the risk to an entity in the absence of any direct or focused actions by management
to alter the risk's severity. Residual risk represents the risk that remains even after management
has fully implemented a response to inherent risks.

Example 1 Risk Mitigation and Residual Risk

A company seeks to mitigate exposure to storm damage to the windows of a factory


located in a hurricane zone. The company debates the merits of storm shutters and impact-
resistant glass and, based on both cost and perceived risk, elects for impact-resistant
glass. Properly installed, impact-resistant glass provides protection from wind and most
flying debris. However, direct impact by flying debris will damage the glass and will require
replacement of the windows. The risk that the company will have to replace the windows
after installing the impact-resistant glass is the residual risk.

2 Risk Assessment

LOS 2D1d 2.1 Factors That Impact Risk


Investors are compensated for risk by rates of return. Risk may be quantified as a rate of
return and expressed as a rate of return or with a volatility calculation. Volatility is a measure
of the likely effect of a change in the expected rate of return on the value of an underlying
security. By extension, the longer an investment's "duration," the greater its volatility and the
greater the risk.

Pass Key

The greater the time a security is outstanding, the greater the chance that the expected
rate of return will change, thereby changing the value of the security.

4–6 Module 1 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 1
PART 2 UNIT
1 4 D.1. Enterprise Risk Management: Part 1

Longer-term investments may decline in value because of changes in interest rates, default, or
from erosion of purchasing power from inflation. Longer-time horizons increase exposure to
changes in interest rates, the impact of inflation, and the risk of default. More broadly, volatility
represents the variability in trading values over time. The longer the time horizon, the greater
the potential for unfavorable changes in value. Shorter time horizons are identified with lower-
risk exposures due to less opportunity for price and interest rate volatility and default.

2.2 Probability and Expected Loss LOS 2D1f

Expected loss due to risk can be computed as the weighted average of a range of outcomes and
their associated probability of occurrence.

Illustration 3 Expected Loss

The X Co. is evaluating its overall expected loss based upon the risks associated with its
international operations. The company faces the risk of loss of business value from a
variety of sources including overall strategic risk, legal risks of operating internationally,
compliance risk associated with the Foreign Corrupt Practices Act, and ongoing political
risks from both domestic and international policies of governments that interface with
the business. Global participation also increases strategic risk from natural disasters and
exposure to technological obsolescence.
Management developed the following loss amounts and probabilities for each risk to arrive
at the total of expected loss to be included in the business plan:

Expected Loss
Risk Type Risk Exposure Probability Losses (Probability × Loss)
Strategic risk Natural disasters 15.0% 100,000 $ 15,000
Technological
obsolescence 5.0% 3,000,000 150,000
Political risk Expropriation of assets 0.1% 50,000,000 50,000
Tariffs 5.0% 1,500,000 75,000
Legal risk Theft of intellectual
property 5.0% 600,000 30,000
Failure to adapt to
foreign laws 4.0% 50,000 2,000
Compliance risk Fines levied 2.0% 25,000 500
Court-ordered cease
and desist 0.1% 50,000,000 50,000
Total expected loss $372,500

© Becker Professional Education Corporation. All rights reserved. Module 1 4–7 D.1. Enterp
1 D.1. Enterprise Risk Management: Part 1 PART 2 UNIT 4

LOS 2D1g 2.3 Unexpected Loss and Maximum Possible Loss


Maximum possible loss is the worst loss that could occur from a single event. The maximum
possible loss is the sum of expected losses, unexpected losses, and catastrophic losses, where
catastrophic losses (as a component of unexpected losses) are financed by insurance. The most
relevant losses are the unexpected losses retained (self-insured) by the business.
Expected losses for financial assets are the average credit loss anticipated from an exposure
over a given period. The total expected loss of a portfolio is the sum of expected losses for
each asset. The concept of expected losses can be expanded to the components of risks that
management confronts. The average loss from exposure to operational risks, for example, may
be the sum of expected losses from fraud, employment practices, or process management. The
expected losses for property would be the amount normally paid for repairs and maintenance
associated with usual and customary (expected) wear and tear. Businesses will generally budget
for expected business losses as part of normal operating cash flows.
An unexpected loss is the average total loss over and above the mean (average) loss. An
unexpected loss is calculated as a standard deviation from the mean at a certain confidence
level and is also referred to as Value at Risk (VaR) for financial assets. Businesses allocate capital
as a protection from unexpected losses. Unexpected losses, by their nature, are highly variable.
Unexpected loss for financial assets is computed as the difference between value at risk and
expected loss.

LOS 2D1s 2.3.1 Value at Risk (VaR)


VaR is used to quantify the worst-case scenario for losses that could be incurred as a result of
market volatility. Value at Risk (VaR) is used to quantify the probability of losses in a portfolio by
focusing the user on three variables:
— Confidence level
— Period
— Amount
A typical VaR assertion focuses on downside risk (losses) and states that there is a high
percentage confidence (95%–99%) that over the next period (year, quarter, month, day, etc.),
a portfolio will lose no more than a calculated dollar amount.
Computations of VaR can be complex and organized in one of three ways: historical method,
variance-covariance method, and Monte Carlo simulation method.
— Historical Method
The historical method organizes past returns in order from worst to best and assumes that
the frequency and severity of losses will repeat themselves.
— Variance-Covariance Method
The variance-covariance method is a statistical approach that assumes that investment
returns are normally distributed around an average. Estimation of an expected or average
return and standard deviation provide a means for quantifying the confidence level for a
maximum loss for a period.
— Monte Carlo Simulation
Monte Carlo simulations involve the development of a model for projecting future outcomes
(such as stock values) and executing multiple hypothetical trials through the model.
The term Monte Carlo simulation refers to any method that randomly generates projections.
The worst outcomes from the model represent the worst-case scenario.

4–8 Module 1 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 1
PART 2 UNIT
1 4 D.1. Enterprise Risk Management: Part 1

2.4 Qualitative Risk Assessment Tools LOS 2D1q

Entities use a variety of techniques to assess the likelihood and impact of risks to the
achievement of strategic and business objectives. Qualitative risk assessment processes include
risk identification, risk ranking, and risk maps. Qualitative assessment approaches may be used
to supplement quantitative assessment approaches. They can also be used when it is neither
practicable nor cost-effective to obtain enough data for quantification. Qualitative assessments
are more efficient to complete but are not effective in identifying correlations or performing a
cost-benefit analysis.

2.4.1 Risk Identification


Risk identification includes techniques that identify the events that expose an organization to
risk. Common techniques include qualitative approaches such as risk inventories, facilitated
workshops, interviews, questionnaires, surveys, and process flow analyses.
— Risk Inventories
Risk or event inventories identify the risks that are commonly encountered in a particular
circumstance whether it is a project or a functional area. Lists may be generic and taken
from industry groups or developed by staff. Risk inventories are used as part of enterprise
risk management (ERM).
— Facilitated Workshops
Workshops assemble cross-functional groups to draw on the collective knowledge of an
organization to develop an inventory of risks that may threaten the accomplishment of an
objective.
— Interviews
Interviews typically occur in a one-on-one setting where the interviewer seeks the candid
views of various subjects on the risk in achieving objectives.
— Questionnaires and Surveys
Questionnaires ask participants to reflect on the risks to which an organization may be
exposed. Participants may be internal with a possible focus on processes or external
(customers) with a possible focus on satisfaction and demand for new products.
— Process Flow Analysis
Flowcharting, or processes flow analysis, diagrams the inputs, tasks, and outputs associated
with an activity. Similar to internal control flowcharting, process flow analysis seeks to
identify weaknesses in the activity and, by extension, the risks in accomplishing an objective.

2.4.2 Risk Ranking


Risk ranking, or prioritizing, is used to order risks by probability and potential impact.
Probability is a measure of how likely it is that a risk event will occur. In evaluating risks to
technology systems, for example, a terrorist attack on the system might be assigned a very low
level of probability, while the presence of hackers might be viewed as moderately likely, and the
use of company technology for personal use might be viewed as highly likely.
Potential impact can be categorized as insignificant, moderately threatening, significant, or
catastrophic. Events viewed as insignificant will generate minimal loss of production, while
catastrophic events could result in substantial loss of production capability.

© Becker Professional Education Corporation. All rights reserved. Module 1 4–9 D.1. Enterp
1 D.1. Enterprise Risk Management: Part 1 PART 2 UNIT 4

2.4.3 Risk Maps


A risk map is a graphic representation of the ranking or importance of various risks in terms of
both the likelihood and impact of each risk on the achievement of objectives.
Risk maps may take the form of a heat map or matrix that plots qualitative estimates of
risk likelihood and impact. Risks are depicted in a manner highlighting which risks are more
significant (higher likelihood and/or impact) and which are less significant (lower likelihood
and/or impact). Risk maps can present the overall expected likelihood and/or impact or
incorporate an element of variability of likelihood and/or impact. The illustration below
demonstrates the overall expected likelihood and impact of risks.

Illustration 4 Risk Mapping

The following heat map presents risk levels (likelihood and impact) by type and color:

The XYZ Corp. seeks to increase market share while maintaining profitability and
appropriate returns for investors.
Index Risk Description of Risk Likelihood Impact
A Shifts in lifestyle Changing habits and needs of Moderate Moderate
customers reduce product demand
B Emerging Advances in technology that change High High
technology the relevance of product offerings
C Labor shortages Increased competition for skilled Unlikely Moderate
labor and costs of employee
turnover
D Political Changing regulatory and Unlikely Moderate
environment international trade barriers
E Market The ability of market competitors to High High
competitiveness consistently meet price offering
F Expanding role Inability to efficiently and effectively Unlikely Low
of Big Data use data sources

These same risks can be depicted in a matrix risk map with likelihood on the horizontal
axis and impact on the vertical axis. The strong visual presentation allows for more rapid
analysis and prioritization of risks.

Risks: Likelihood and Impact

A. Shifts in lifestyle
B
B. Emerging technology
E
Impact

A C. Labor shortages
D. Political environment
C
E. Market competitiveness
F D F. Expanding role of Big Data
Likelihood

4–10 Module 1 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 1
PART 2 UNIT
1 4 D.1. Enterprise Risk Management: Part 1

2.5 Quantitative Risk Assessment Tools LOS 2D1r

Quantitative approaches are typically used in more complex and sophisticated activities to
supplement qualitative techniques. Quantitative approaches include probabilistic models such
as cash flow at risk, earnings at risk, and earnings distributions.

2.5.1 Cash Flow at Risk


Cash flow at risk is used to estimate an organization's or business unit's change in cash flows
relative to a targeted cash flow expectation over a defined time horizon with a given level of
confidence. Cash flow at risk is used for businesses whose results are sensitive to changes
in cash flows related to nonindustry-specific factors such as foreign currency exchange rate
fluctuations, changes in GDP, supply and demand for components, and corporate investments.
While cash flow at risk is a financial risk, it is driven by multiple factors, including the
implementation of tariffs (political risk, with exchange rate risk) and changes in GDP (business
risk that shifts the supply and demand curves). Understanding how each risk factor varies with
its impact on cash flow allows management to measure and manage risk better.

Illustration 5 Cash Flow at Risk

Hi Tech Computer Co. is a computer manufacturer that uses a cash-flow-at-risk technique


to evaluate the impact of foreign currency rates to assess the foreign currency exchange
rate risk in relation to cash flows. Similar to value at risk, probabilities are assigned
to changes in the company's cash flow associated with favorable and unfavorable
developments in foreign currency rates over a period of time. The company computes the
worst-case scenario and notes that the probability of loss of negative cash flow of $1,000 or
more on any given day is less than five percent. Measurements provide a confidence level
of the company's maximum cash requirements.

Hi Tech Computer Co.


Cash Flow at Risk
Daily Risk of Negative Cash Flow From Exchange Rate Risk

About 5% of the curve


represents the likelihood
of a $1,000 negative cash
flow in a day

(1,500) (1,250) (1,000) (750) (500) (250) 250 500 750 1,000 1,250 1,500

Cash flow at risk

2D_Cash Flow at Risk

© Becker Professional Education Corporation. All rights reserved. Module 1 4–11 D.1. Enterp
1 D.1. Enterprise Risk Management: Part 1 PART 2 UNIT 4

2.5.2 Earnings at Risk


Earnings at risk is the amount that accounting income may change due to a change in interest
rates or other risk factors over a specified period. As with value at risk and cash flow at risk,
earnings at risk estimates the changes in accounting earnings over a specific period of time to
determine the amount of loss that will not be exceeded within a given confidence level.
Earnings-at-risk calculations isolate interest rate risks by computing the expected earnings
deviation due to changes in interest rates for sensitive balance sheet items.

Illustration 6 Calculating Earnings at Risk

An organization purchased one available-for-sale security investment with a $1,000,000


face value and original cost (assume no brokerage fees), a 10 percent coupon rate, and a
term to maturity of three years. The organization has evaluated the probability of changes
in interest rates over the next year and arrived at a distribution of likely changes. The
likelihood of an occurrence can be computed with a specific confidence level.
If the organization is 95 percent confident that interest rates will only increase by 1.0
percent over the course of the next year, what is the earnings at risk?

Discounted Value Coupon 10% Market 11% Difference


Year 1 90,909 90,090
Year 2 82,645 81,162
Year 3 75,131 73,119
Principal (Year 3) 751,315 731,191
Total 1,000,000 975,562 (24,438)

The earnings at risk is computed as the $24,438 difference due to the potential market
adjustment of a 1.0 percent increase in interest rates.

2.5.3 Earnings Distributions


An earnings distribution is a tool used in risk management that plots a probability distribution
of earnings outcomes. From this distribution, an entity can estimate the probability of obtaining
a certain level of earnings. Earnings per share (EPS) can similarly be plotted as a probability
distribution for estimating earnings per share outcomes. This estimation becomes a critical
exercise because EPS is one of the most important financial ratios that a company reports to the
investment community. Meeting or exceeding EPS targets significantly impacts the stock price of
the company.

4–12 Module 1 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 1
PART 2 UNIT
1 4 D.1. Enterprise Risk Management: Part 1

Example 2 Probability Distribution

Facts: The Bleam Co. will issue its third quarter earnings at the end of the week.
The consensus is that EPS will be $1.55. Market analysts at Jacobs Brokerage forecast the
following earnings per share amounts and associated probabilities:
——$1.30 (15% probability)
——$1.50 (25% probability)
——$1.65 (40% probability)
——$1.80 (15% probability)
——$2.00 (5% probability)
Required: Calculate the weighted average EPS, the most likely EPS, and interpret the
probability distribution relative to the market consensus.
Solution: The weighted average EPS is equal to $1.30 (0.15) + $1.50 (0.25) + $1.65 (0.40) +
$1.80 (0.15) + $2.00 (0.05) = $1.60.
The most likely EPS is associated with highest probability in the table (40%), which is $1.65.
Based on the probability distribution, both the weighted average EPS and the most likely
EPS is above the market consensus of $1.55 per share. If Jacobs is correct in their estimates,
then the company will come in higher than expected and the stock price should respond
favorably. There is still a 40 percent chance that earnings will come in below $1.55; if this
happens, the stock price will likely fall.

2.6 Cost-Benefit Analysis LOS 2D1x

Cost-benefit analysis is used to support resource allocation decisions such as equipment


acquisitions, technology enhancements, and employee hiring. Managers compare the costs of
a decision against its benefits and generally proceed if the benefits exceed the cost. Not every
benefit or cost is fully quantifiable, making cost-benefit analysis a technique that also requires
judgment.

Illustration 7 Analyzing Costs and Benefits

The XYZ Corp. is considering an investment in equipment that will be used to digitize its
records and to provide digitization services to other entities resulting in annual income of
$50,000. Employees will need to be trained annually on the digitization process. The need
for maintenance on the equipment will escalate over the life of the project.

(continued)

© Becker Professional Education Corporation. All rights reserved. Module 1 4–13 D.1. Enterp
1 D.1. Enterprise Risk Management: Part 1 PART 2 UNIT 4

(continued)

Benefits and costs of the project are listed below by year:

Time Year 0 Year 1 Year 2 Year 3


Investment $(100,000)
Fees $50,000 $50,000 $50,000
Efficiency 2,000 6,000 6,000
Training (10,000) (5,000) (6,000)
Maintenance (2,000) (4,000) (6,000)

Because management anticipates that some costs and benefits are more certain than
others, management utilizes various discount rates to value each of the costs and benefits
of the project. The less certain management is that it will realize a benefit, the higher the
assigned discount rate.
——Training and maintenance costs are discounted at 8 percent.
——Year 1 fees and efficiency gains and Year 2 fees are discounted at the company's hurdle
rate of 10 percent.
——Year 2 efficiency gains are discounted at 11 percent to reflect risk.
——Year 3 fees and efficiency gains are discounted at 15 percent to reflect risk.
The following discounted cash flows are set forth below:

Time Year 0 Year 1 Year 2 Year 3 Total Project


Investment $(100,000)
Fees $45,455 $41,322 $32,876 119,653
Efficiency 1,818 4,870 3,945 10,633
Training (9,259) (4,287) (4,763) (18,309)
Maintenance (1,852) (3,429) (4,763) (10,044)
Total $(100,000) $36,162 $38,476 $27,295 $101,933

Total present value of net benefits for Years 1–3 = $36,162 + $38,476 + $27,295 = $101,933.
Comparison of costs vs. benefits:

Costs $(100,000)
Present value of benefits 101,933
Benefits > Costs $ 1,933

The risk-adjusted benefits exceed the risk-adjusted costs by $1,933; therefore, the digitizing
project should go forward.

4–14 Module 1 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 1
PART 2 UNIT
1 4 D.1. Enterprise Risk Management: Part 1

3 Capital Adequacy and Risk LOS 2D1e

Sufficient capital and capital adequacy are terms used specifically in the banking industry but may
be generally applied to most entities as entities seek to sustain the financial resources required to
operate and grow the business. Capital adequacy is similar to the concept of long-term solvency.
A company with adequate capital is positioned to grow and can better withstand risk.

3.1 Sufficient Capital


Sufficient capital is closely aligned with the concept of liquidity. The short-term operational goal
of liquidity is to maintain sufficient resources to meet obligations as those obligations come
due. To the extent a company has set aside financial reserves not utilized for normal ongoing
operations, the company will be able to absorb short-term liquidity issues.
Short-term liquidity issues can be addressed with lines of credit, short-term financing, or
reserves. Long-term solvency issues may result in reorganization or merger. Reserves can take
many forms and will include the funds earmarked for future uses, such as funding bad debts,
bond covenant requirements, or other contingencies.

3.2 Capital Adequacy


The term capital adequacy used in conjunction with bank regulations references a capital
adequacy ratio (CAR) used to measure the risk that reasonable losses are so high as to make the
bank insolvent and endanger depositor funds. The ratio measures the degree to which asset
values would need to fall for reserves to be overwhelmed by liabilities. CAR is computed as the
ratio of capital and various reserves to outstanding loans weighted by risk factors. The higher
the CAR, the lower the risk of potential insolvency.
While the capital adequacy ratio specifically targets the solvency of banks, a more general
measurement for all industries is the solvency ratio. The solvency ratio presumes less risk
aversion and measures the extent to which cash inflows equal or exceed liabilities. The higher
the solvency ratio, the less likely that income will be inadequate to meet debt requirements as
they come due.
The capital adequacy ratio adapts easily to the defensive posture of risk-averse financial
institutions that must be unquestionably solvent and able to conduct business on behalf of
depositors. The solvency ratio adapts more compatibly with businesses that are more willing to
take on risk to provide higher returns and increase the value of the firm.

© Becker Professional Education Corporation. All rights reserved. Module 1 4–15 D.1. Enterp
1 D.1. Enterprise Risk Management: Part 1 PART 2 UNIT 4

Question 1 MCQ-12672

The Quik Growth Manufacturing Corp. has expanded rapidly over the last year. In the
company's efforts to keep up with production requirements, management has ignored
employee training, shop and equipment maintenance, and supervisory span of control
issues. In the last week, the company has incurred losses from separate incidents in which
four employees were injured in slip and fall, machine operation, and machine malfunction
accidents. Quik Growth Manufacturing Corp.'s losses come from its failure to address
which type of risk?
a. Hazard risk
b. Operational risk
c. Compliance risk
d. Financial risk

Question 2 MCQ-12673

The management team of Barnacle Corp. is evaluating various risks to the corporation's
fleet of cargo vessels. The accounting division has estimated that ongoing maintenance of
the fleet will cost approximately $500,000 per year. The replacement cost of each cargo
vessel is $20,000,000. The company insures the vessels for 90 percent of their replacement
cost. Management is attempting to quantify the corporation's risk of loss if one of the ships
sinks. What would be the company's unexpected loss?
a. $20,000,000
b. $18,000,000
c. $2,050,000
d. $2,000,000

Question 3 MCQ-12674

Management of the Able Corp. is assessing and prioritizing the risks to the achievement
of return-on-investment objectives. Management would most likely use the following
technique to evaluate potential risks, such as declining profitability, unexpected losses
from asset destruction, and fraud, thwarting the achievement of the return-on-investment
objectives:
a. Develop a risk inventory.
b. Conduct a facilitated workshop.
c. Develop a heat map.
d. Develop a process flow analysis.

4–16 Module 1 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 1
2
MODULE
PART 2 UNIT 4

D.1. Enterprise Risk


Management: Part 2
Part 2
Unit 4

This module covers the following content from the IMA Learning Outcome Statements.

CMA LOS Reference: Part 2—Section D.1. Enterprise Risk Management: Part 2

The candidate should be able to:


h. identify strategies for risk response (or treatment), including actions to avoid, retain,
reduce (mitigate), transfer (share), and exploit (accept) risks
i. define risk transfer (e.g., purchasing insurance, issuing debt)
k. identify and explain the benefits of risk management
l. identify and describe the key steps in the risk management process
m. explain how attitude toward risk might affect the management of risk
n. demonstrate a general understanding of the use of liability/hazard insurance to
mitigate risk (detailed knowledge not required)
o. identify methods of managing operational risk
p. identify and explain financial risk management methods
t. define enterprise risk management (ERM) and identify and describe key objectives,
components, and benefits of an ERM program
u. identify event identification techniques and provide examples of event identification
within the context of an ERM approach
v. explain how ERM practices are integrated with corporate governance, risk analytics,
portfolio management, performance management, and internal control practices
w. evaluate scenarios and recommend risk mitigation strategies
y. demonstrate an understanding of the COSO Enterprise Risk Management—Integrated
Framework (2017)

1 Managing Risk

Organizations must establish objectives and develop strategies and tactics to achieve those
objectives. Objectives and the methods by which those objectives will be achieved should be
aligned with the risk appetite of the organization.

© Becker Professional Education Corporation. All rights reserved. Module 2 4–17 D.1. Enterp
2 D.1. Enterprise Risk Management: Part 2 PART 2 UNIT 4

LOS 2D1l 1.1 Risk Management Process


The risk management process is a top-down process that is primarily driven by management
attitudes toward risk and is revised through ongoing communication and review.
1. Management begins with articulating its willingness to assume risk to produce value
and achieve returns. Strategies and related objectives are set based on management's
willingness to assume risk.
2. Identification of risks that would prevent achievement of objectives or the implementation
of strategy follow the establishment of objectives. Risks outside the context of objectives are
not fully relevant to an organization.
3. Development of responses to identified risks follows logically after risk identification.
Risk management requires both judgment and consensus on both the priority and
significance of the identified risk and the appropriate response to that risk.
4. The final step in the risk management process is reporting the results of risk management
and ultimately using those results to reevaluate objectives and strategies.

LOS 2D1m 1.2 Attitude Toward Risk


Management's response to risk is shaped by its attitude toward risk. Risk attitudes and
behaviors can be categorized as risk indifferent, risk seeking, and risk averse.
— A risk indifferent, or risk neutral, approach does not focus on risk as a factor when making
decisions.
— A risk seeker is willing to accept higher risk in exchange for higher returns. Risk-seeking
behavior may not seem rational; this behavior goes beyond what more conservative
investors would view as prudent. Individuals who speculate or companies that expand
rapidly into highly competitive markets in search of higher returns are risk seekers.
— The risk-averse are generally not willing to accept high risk and therefore are willing to
accept lower returns. Risk-averse behaviors are the most frequently observed attitude
toward risk. Managers seek to balance the assumption of risk with return. Achieving return
while minimizing risk characterizes the risk-averse investor.

LOS 2D1h 1.3 Risk Response Strategies


LOS 2D1w Strategic responses to risk include avoiding, retaining, reducing, transferring, and exploiting risk.

1.3.1 Risk Avoidance


Companies that avoid risk do not engage in an activity that has unacceptably high risk.

Illustration 1 Risk Avoidance

A highly risk-averse company reviews the implications of global warming. The company
elects to eliminate its business interests in coastal areas.

4–18 Module 2 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 2
PART 2 UNIT
2 4 D.1. Enterprise Risk Management: Part 2

1.3.2 Risk Retention


Risk retention is a form of risk acceptance and is similar to residual risk but usually implies that
management has made a decision to transfer some risk and retain some risk. While residual risk
represents the amount of risk exposure that cannot be eliminated, risk retention represents the
amount of risk that management has consciously decided to absorb. A company might purchase
insurance to share or transfer its losses with an insurance policy but may also elect a large
deductible to help reduce the premium. The amount of the deductible that the company must
pay in the event of a loss is the company's risk retention.

1.3.3 Risk Reduction or Mitigation


Companies that seek to reduce or mitigate risk take measures to counter the impact of the risk.

Illustration 2 Risk Mitigation

A risk-averse company reviews the implications of global warming. The company elects to
stormproof its facilities with impact-resistant windows and protective shuttering systems
along with the installation of metal, wind-resistant roofs. In addition, company policy
requires that all company-owned buildings in hurricane, cyclone, and tornado zones be
constructed from brick or concrete block.

1.3.4 Risk Transfer or Sharing LOS 2D1i


Companies can transfer or share risk with outside entities or individuals. Insurance is a
mechanism for transferring or sharing risk. Outsourcing is another example of risk sharing.
From a financing perspective, borrowing money through the issuance of debt is a means of
obtaining cash to finance operations and growth. Debt allows an entity to share its risks with its
debtholders, for which they will expect to be compensated with returns in line with that risk.

Illustration 3 Risk Transfer

A risk-averse company reviews the implications of global warming. The company elects
to purchase property insurance for all its facilities and to augment its wind damage and
flood insurance by paying higher premiums for extremely low deductibles to ensure that
catastrophic damages will be entirely covered by insurance.

© Becker Professional Education Corporation. All rights reserved. Module 2 4–19 D.1. Enterp
2 D.1. Enterprise Risk Management: Part 2 PART 2 UNIT 4

1.3.5 Risk Exploitation or Acceptance


Companies that exploit and retain or accept risk make little or no attempt to reduce risk and
may seek out risks that other companies avoid.

Illustration 4 Risk Exploitation

A company that is not risk-averse reviews the implications of global warming and sees
opportunities for increased market share. With no additional investment in risk mitigation
techniques or insurance, the company elects to engage fully in businesses in coastal
and storm-prone areas. The company plans to offset any catastrophic losses with higher
margins and higher market shares in areas abandoned or forgone by their competitors.

LOS 2D1n 1.4 Liability/Hazard Insurance


As stated above, insurance can be used to share or transfer risk. An insurance policy identifies
the risks covered by the insurance, describes hazards that increase the likelihood of loss,
and offers terms and conditions under which those losses will be reimbursed to the insured.
The amount of risk retained by the insured can be adjusted by expanding or contracting the
insurance coverage or changing the insurance deductible, which is the amount of the loss the
insured must pay before the insurance can be used to cover losses.
The coverage grouped under liability/hazard insurance includes coverage for losses of property
value and losses from an insured's liability to individuals harmed because of the actions or
inactions of the insured. Commercial property insurance insures buildings and personal property
as well as lost business income. General liability insurance will cover a range of injuries occurring
on property owned by the insured or as part of the operation of the insured's business.

Illustration 5 Use of Hazard Insurance

The management of ABC Groceries is concerned about the potential damage to property
from various calamities including natural disasters, such as storms, fire, and accidents.
Management is also concerned about lawsuits resulting from slips and falls by customers in
the store and from foodborne illnesses attributable to the foods prepared in the stores' deli
and bakery. While management believes the likelihood of any of these risks resulting in actual
losses is relatively low, management recognizes the financial impact could be enormous in
repair costs, lost income, or legal fees and settlements. The company elects to share these
risks and does so by purchasing appropriate amounts of liability/hazard insurance.

LOS 2D1o 1.5 Managing Operational Risk


Specific operational risks and risk management methods include the following:
— Human Error: Human error resulting from individual carelessness or ineffective training
can increase operational risk. Human error is mitigated by supervision, including both
general training initiatives and specific quality control.

4–20 Module 2 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 2
PART 2 UNIT
2 4 D.1. Enterprise Risk Management: Part 2

— Information Technology Failures: IT failures such as disrupted communications and


interrupted or slow processing contribute to operational risk. Continuous maintenance of
systems and ongoing review of system effectiveness are appropriate responses to the risk
of information technology failures.
— Quality Risk: Total quality management programs addressing continuous improvement can
be effective in mitigating quality risk by focusing organizations on customer satisfaction and
effective value delivery.
— Process Failures: Continuous process improvement programs and defect analysis are
appropriate and effective responses to mitigate the risk of process failure.

1.6 Financial Risk Management LOS 2D1p

Financial risk management methods are designed to mitigate the risk of loss related to asset
valuation or cash flows. Valuation risks include interest rate risk, market (systematic) risk,
nonmarket (unsystematic) risk, default risk, and price risk. Cash flow risks include credit risk and
liquidity risk.

1.6.1 Interest Rate Risk


Interest rate risk represents the exposure of an asset to fluctuations in value in response
to changes in interest rates. Interest-bearing securities that carry a fixed rate of interest will
increase in value as interest rates fall and will decrease in value as interest rates rise. Responses
to interest rate risks may include investment in floating rate securities that will track market
rates or the use of derivative instruments, such as interest rate swaps. In an interest rate swap,
an investor who has an adjustable rate agrees to pay a third party a fixed interest rate and will
receive (earn) a floating rate in return.

1.6.2 Market (Systematic) Risk


Market, or systematic, risk represents exposure to loss from investing in the market as a whole.
An example of market risk is the loss in value of the S&P 500 if a severe economic depression
grips the country. Responses to market or systematic risks include investments in derivatives.
Options to sell securities at a specific market price will insulate the owner against risk of loss of
value over the period of the option.

1.6.3 Nonmarket (Unsystematic) Risk


Nonmarket, unsystematic, or price risk represent exposure to losses in investments in specific
companies or industries. An example of nonmarket risk is the risk of the adverse impact on the
value of a major technology company's stock if the chief executive were to become gravely ill.
Nonmarket risks can be effectively mitigated through portfolio diversification.

1.6.4 Default Risk


Default risk exposes creditors to the risk that debtors may not pay, or may not timely pay, the
principal and/or interest due on indebtedness, reducing the realizable value of the receivable.
Default risk can be mitigated by choosing to lend only to borrowers with low risk of default or by
adjusting the interest rate charged to reflect the risk of the borrower.

1.6.5 Price Risk


Price risk drives market risk. Market risk represents losses from adverse price behavior. Price
risk is quantified by the same decreases in value that are described as market risk, however,
price risk itself is a composite risk comprised of many different features, including earnings
volatility, operational risk, etc.

© Becker Professional Education Corporation. All rights reserved. Module 2 4–21 D.1. Enterp
2 D.1. Enterprise Risk Management: Part 2 PART 2 UNIT 4

1.6.6 Credit Risk


Credit risk exposes borrowers to an inability to secure financing or secure favorable credit terms
as a result of poor credit ratings. Credit risk may be mitigated by drawing down on unused
lines of credit if management foresees poor financial results or periods of reduced cash flow.
In addition, borrowers might consider increasing credit lines when credit is available to have
access to financing when credit terms subsequently tighten.

1.6.7 Liquidity Risk


Liquidity risk represents the exposure associated with being unable to sell securities or other
assets in a timely matter without needing to make material price concessions. Effective methods
of maintaining liquidity include allocating a greater percent of capital to investments that trade
on active markets and/or maintaining cash reserves adequate to meet liquidity requirements.

LOS 2D1t 2 Enterprise Risk Management (ERM) Framework

The Committee of Sponsoring Organizations (COSO), an independent private sector initiative,


was initially established in the mid-1980s to study the factors that lead to fraudulent financial
reporting. The private "sponsoring organizations" include the five major financial professional
associations in the United States: the American Accounting Association (AAA), the American
Institute of Certified Public Accountants (AICPA), the Financial Executives Institute (FEI), the
Institute of Internal Auditors (IIA), and the Institute of Management Accountants (IMA).
In 2004, COSO issued Enterprise Risk Management (ERM)—Integrated Framework ("the framework")
to assist organizations in developing a comprehensive response to risk management.
In recognition of the changing complexity of risk, the emergence of new risks, and the enhanced
awareness of risk management by both boards and executive oversight bodies, COSO published
Enterprise Risk Management—Integrating With Strategy and Performance in 2017.
According to COSO, "Risk is the possibility that events will occur and affect the achievement of
strategy and business objectives."
As defined by COSO:
Enterprise risk management is the culture, capabilities, and practices, integrated with
strategy-setting and performance, that organizations rely on to manage risk in creating,
preserving, and realizing value.

2.1 Components of Enterprise Risk Management


Enterprise risk management is depicted as a series of sequential yet intertwined components
that drive an organization toward enhanced value.
The tone at the top and communication are linked, and weave into the similarly linked efforts
to develop overall strategy, specific business objectives, and manage performance to the
achievement of value.
Mission, vision, and values drive the process but are also affected by performance, as
management constantly reviews its risks and its ability to create value.

4–22 Module 2 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 2
PART 2 UNIT
2 4 D.1. Enterprise Risk Management: Part 2

Enterprise Risk Management—Integrating With Strategy and Performance, © 2017 Committee of Sponsoring Organizations
of the Treadway Commission (COSO). Used with permission.

2.1.1 Governance and Culture


Governance and culture together form a base for all other components of enterprise risk
management. Governance sets the entity's tone, reinforcing the importance of enterprise
risk management and establishing oversight responsibilities for it. Culture is reflected in
decision making.

2.1.2 Strategy and Objective Setting


Enterprise risk management is integrated into the entity's strategic plan through the process
of setting strategy and business objectives. With an understanding of business context,
the organization can gain insight into internal and external factors and their effects on risk.
An organization sets its risk appetite in conjunction with strategy-setting. The business objectives
allow strategy to be put into practice and elevate the entity's day-to-day operations and priorities.

2.1.3 Performance
To drive performance, an organization identifies and assesses risks that may affect its ability
to achieve its strategy and business objectives. It prioritizes risks according to severity and the
entity's risk appetite. The organization then selects risk responses and monitors performance for
change. In this way, it develops a portfolio view of the amount of risk the entity has assumed in
the pursuit of its strategy and entity-level business objectives.

2.1.4 Review and Revision


By reviewing enterprise risk management capabilities and practices and the entity's
performance relative to its targets, an organization can consider how well the enterprise risk
management capabilities and practices have increased value over time and will continue to drive
value in light of substantial changes.

2.1.5 Information, Communication, and Reporting


Communication is the continual, iterative process of obtaining information and sharing it
throughout the entity. Management uses relevant information from both internal and external
sources to support enterprise risk management. The organization leverages information
systems to capture, process, and manage data and information. By using information that
applies to all components, the organization reports on risk, culture, and performance.

© Becker Professional Education Corporation. All rights reserved. Module 2 4–23 D.1. Enterp
2 D.1. Enterprise Risk Management: Part 2 PART 2 UNIT 4

LOS 2D1k 2.2 Benefits of Enterprise Risk Management


Benefits of ERM include the ability for management to do the following:
— Increase the Range of Opportunities: Assessing the positive and negative elements of risk
focuses management on opportunities for profit realization as well as loss avoidance.
— Increase Positive Outcomes and Advantages While Reducing Negative Surprises:
Identifying risk and responding in a timely manner reduces surprises and ensures
reasonable preparation for addressing risks.
— Identify and Manage Entity-Wide Risks: Individual risks may aggregate or interrelate
with entity-wide and strategic risks. Identification of the implications of individual risks to
strategic risks gives the organization greater focus in managing entity-wide exposures.
— Reduce Performance Variability: ERM allows managers to focus on the risks that impede
consistent performance over time rather than focusing on extreme or infrequent risks.
— Improve Resource Deployment: Risk data and risk management give managers the ability
to assess overall resource needs and to optimize resource allocation.

LOS 2D1u 2.3 Event Identification Under ERM


Under ERM, management identifies new and emerging risks and, using various risk identification
approaches, reevaluates currently assessed risks. Risk identification is a focused evaluation of
events that might negatively impact the achievement of objectives. Risk identification begins
with establishing an inventory or list of risks that either currently exist or are new, emerging, or
related to change. A significant step in risk identification is establishing that current risks are still
applicable, relevant, and require a response. Risk identification processes are governed by the
speed with which risks develop. Rapidly developing or changing risk environments require more
rigorous attention than risk environments where risks are developed or changing more slowly.

2.3.1 Risk Profile


From the inventory of risks that threaten the achievement of strategic and business objectives,
management identifies the level of risks assumed. The level of risks assumed is the risk profile
of the organization at the organization's chosen level of activity or performance. The COSO
defines risk profile as "a composite view of the risk assumed at a particular level of the entity,
or aspect of the business that positions management to consider the types, severity, and
interdependencies of risks, and how they may affect performance relative to the strategy and
business objectives."

2.3.2 Risk Identification Approaches


Management needs to identify risks that are likely to disrupt operations and affect the reasonable
expectation of the achievement of strategic and business objectives. Risks of this type represent
significant changes in the risk profile and may be specific events or evolving circumstances that
may lead to various responses, including changes to strategy. Risks are defined as existing, new,
or emerging. Existing risks are those present in the current environment. New or changing risks
arise from circumstances that include changes in business objectives. Emerging risks arise when
the economy, markets, competition, etc. (sometimes referred to as business context) changes.

4–24 Module 2 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 2
PART 2 UNIT
2 4 D.1. Enterprise Risk Management: Part 2

Risk identification approaches relating to existing, new, and emerging risks include the following:
Cognitive Computations. Cognitive computing allows organizations to collect and analyze
large volumes of data to detect future trends and meaningful insights into new and
emerging risks as well as changes in existing risks.
Data Capture. Capturing (tracking) data from past events can help predict future
occurrences. Databases developed and maintained by third-party service providers or
through industry consortiums that collect information on incidents and losses incurred by
industry or region may inform the organization of potential risks.
Interviews. Interviews seek knowledge from individuals of past and potential events.
Interviewing includes surveying large groups of people.
Key Indicators. Key indicators are qualitative measures or quantitative measures that assist
in identifying changes to existing risks. Risk indicators are prospective and should not be
confused with performance measures, which are typically retrospective in nature.
Process Analysis: Process analysis involves developing a diagram of a process to
understand better the interrelationships of its inputs, tasks, outputs, and responsibilities.
Once management has developed the process diagram, management can identify risks and
weigh them against relevant business objectives.
Workshops. Workshops bring together individuals from different functions and levels to
draw on the group's collective knowledge for the purpose of developing a list of risks as they
relate to the organization's strategy and business objectives.
Techniques most effective for different types of risks are generally distributed as follows:

Types Cognitive Data Interviews Key Process Workshops


Computing Tracking Indicators Analysis
Existing X X X X X X
New X X X X
Emerging X X X X

2.3.3 Risk Severity Assessment


The severity of risk is evaluated after it has been identified. Resources and capabilities are
deployed to keep the risk within the entity's risk appetite based on the assessment.
The severity of a risk is assessed at multiple levels (across divisions, functions, and operating
units) in line with the business objectives it may affect. Risks deemed severe at the operating
level may be less of a concern at the division or entity level.
Severity measures relate to impact (result or effect of the risk) and likelihood (possibility of the
risk occurring). Likelihood may be expressed qualitatively or quantitatively.
Risk assessment includes the concepts of inherent risk, target residual risk, and actual residual risk.
Inherent risk is the risk to an entity in the absence of any direct or focused actions by
management to alter its severity.
Target residual risk is the amount of risk that an entity prefers to assume in the pursuit
of its strategy and business objectives knowing that management will implement or has
implemented direct or focused actions to alter the severity of the risk.
Actual residual risk is the risk remaining after management has taken action.
The organization strives to identify triggers that will prompt a reassessment of severity when required.

© Becker Professional Education Corporation. All rights reserved. Module 2 4–25 D.1. Enterp
2 D.1. Enterprise Risk Management: Part 2 PART 2 UNIT 4

2.3.4 Risk Prioritization


Prioritization of risk as a basis for determining risk response is a principle underlying the
performance component. Risks that result in the entity approaching the risk appetite for specific
business objectives are typically given higher priority.

2.3.5 Risk Appetite


ERM practices are intended to provide the management and the board with a reasonable
expectation that the organization's overall strategy and business objectives can be achieved.
Reasonable expectation means the amount of risk of achieving strategy and business objectives
is appropriate for that entity.
An organization must continually review and manage the types and amounts of risk it is willing
to accept in its pursuit of value.
Risk appetite represents the types and amounts of risk, on a broad level, that an organization
is willing to accept in pursuit of value. Risk appetite is a range rather than a specific limit and
provides guidance on the practices an organization is encouraged to pursue or not pursue.
— Risk appetite is expressed first in mission and vision.
— Risk appetite varies between products, business units, or over time in line with changing
capabilities for managing risk and must be flexible enough to adapt to changing business
conditions without approvals.

2.3.6 Relationship of Value and Risk Appetite


Managing risk within risk appetite enhances an organization's ability to create, preserve, and
realize value. ERM seeks to align anticipated value creation with risk appetite and capabilities for
managing risk over time.

LOS 2D1v 3 ERM Integration

Enterprise risk management (ERM) is put into practice by the application of its framework to
both the structure of the organization and the processes of the organization.

3.1 Corporate Governance


The assignment of roles and responsibilities for ERM begins with those charged with governance
and permeates each level of management and operations. The engagement of the board of
directors, chief executive officer, chief risk officer, management, and internal auditor through
a "lines of accountability model" offer an organization a balanced approach to manage risk as
well as seize opportunities. Use of risk management throughout the organization allows for
integration of different disciplines that enable risk-based decision making that is free of bias.

4–26 Module 2 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 2
PART 2 UNIT
2 4 D.1. Enterprise Risk Management: Part 2

Overlaying the responsibilities of those charged with governance with each component of ERM
results in the integration practices shown below:

ERM Component Risk Oversight Practices of the Board of Directors


Governance and culture ——Assesses the strategies of the entity in relation to the mission,
vision, and values of the entity
——Develops governance subcommittees
——Engages management in defining suitability of ERM
——Promotes a risk awareness mindset and oversees the alignment
of business performance, risk taking, and achievement of
objectives
Strategy and objective ——Sets expectations for the integration of ERM into the strategic
setting management process
——Discusses and understands risk appetite and its alignment with
expectations
——Engages management with changes in business context/
environment that may impact strategy with new or emerging
risks
——Requires management to demonstrate an understanding of risk
capacity
Performance ——Compares the entity's strategy and underlying assumptions to
the risk portfolio
——Sets expectations for risk reporting and risk metrics
——Understands how management identifies and communicates
the most severe risks as depicted by the entity's portfolio
Review and revision ——Asks management about financial reporting risks
——Asks management about the performance and suitability of ERM
Information, ——Identifies information and underlying data required for board
communication, and oversight
reporting
——Obtains internal and external audit feedback regarding
management perceptions and assumptions

© Becker Professional Education Corporation. All rights reserved. Module 2 4–27 D.1. Enterp
2 D.1. Enterprise Risk Management: Part 2 PART 2 UNIT 4

3.1.1 Board-Level Committees


Board-level committees that manage risk oversight responsibilities may include the following:
— Audit Committee: Reinforces the importance of risk oversight. The role and scope of the
authority of an audit committee can vary depending on the entity's regulatory requirements,
industry, or other variables.
— Risk Committee: Establishes direct oversight of ERM. Risk committees look at the
nonfinancial areas of an organization's operations that go beyond the scope of the audit
committee.
— Compensation Committee: Reviews executive compensation arrangements to ensure
executives are motivated to achieve objectives without undue risk.
— Nomination and Governance Committee: Provides input and oversight of the selection
of candidates for directors and management, including executive succession planning that
serves to reduce variability and risk.

3.1.2 Management
Management has three lines of accountability that serve as the basis for integration of ERM.
The lines of accountability represent those who perform day-to-day operations, those who
supervise and monitor the effectiveness of operations, and internal audit functions that provide
additional independent assurance.
1. Core Business, Day-to-Day Operations: Management is responsible for managing
performance and risks taken to achieve strategic and business objectives.
2. Managing Support Functions: Support functions include management and personnel
responsible for overseeing performance and enterprise risk management independent of
core business functions in an unbiased way. Support functions may be embedded in the
core business or may be a separate oversight group.
3. Assurance Functions: Internal audit provides a final line of accountability. Internal audit is
the least biased and the most effective when it reports to the board of directors rather than
management. External auditors may also provide an additional level of assurance, although
the scope of their review is usually narrower.
Each component of the organization's structure contributes to the implementation of enterprise
risk management from direction to implementation and further, to oversight and verification.

LOS 2D1y 3.2 Risk Analytics


Planning and monitoring are based on the selection of appropriate risk analytics that correlate
risk with strategic objectives. Common analytics used in ERM include earnings at risk or value
at risk associated with different strategic alternatives or degrees of strategic implementation
(sometimes referred to as performance levels).
Risk analytics provide a composite view of risks related to different levels of performance and
are collectively known as a risk profile. Organizations use the relationship between the level of
performance for a strategy or business objective and the expected amount of risk (risk profile)
to gauge the change in risk as performance increases.

4–28 Module 2 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 2
PART 2 UNIT
2 4 D.1. Enterprise Risk Management: Part 2

Illustration 6 Risk Analytics: Initial Assessment

The graph below illustrates the use of risk analytics by a retail operation. Management has
determined the worst-case scenario for losses (value at risk) as performance increases
(additional stores are added). The potential relationship between value at risk and
increased performance (addition of store outlets) is illustrated below:

Enterprise Risk Management


Risk, Strategy, and Performance
$100,000

$90,000

$80,000

$70,000

$60,000
Value at risk

$50,000
Risk profile
$40,000

$30,000

$20,000

$10,000

$-
1 2 3 4 5 6 7 8 9 10
Performance (addition of store outlets)

Risk profiles allow for assessment of risk in comparison to performance. Generally, risk is
assessed and compared to an entity's risk2D_Risk
appetite. Value at risk quantifies both the amount of
Analytics
escalating risk and maximum or tolerable losses.
Prioritization criteria are incorporated into risk profiles by considering the adaptability of an
organization to changes, the complexity of risk, and the speed of change. Risk profiles are
adjusted by selecting risk responses that relate to the priority of risk. The risk remaining after
implementation of responses is known as residual risk.

© Becker Professional Education Corporation. All rights reserved. Module 2 4–29 D.1. Enterp
2 D.1. Enterprise Risk Management: Part 2 PART 2 UNIT 4

3.3 Risk Portfolio Management


Residual risk is the entity-wide portfolio view of risk that the entity faces after responding to
known risks. The chief financial officer may view risk from a financial perspective while operating
officers may look at operational performance.

Illustration 7 Risk Portfolio

In this portfolio view, the relationship among the entity objectives and supporting business
objectives and the risks to each are shown:

Strategy Overall Strategy


Entity objectives Entity No. 1 objective Entity No. 2 objective Entity No. 3 objective

Business Business Business Business


Business objectives
objective No. 1 objective No. 2 objective No. 3 objective No. 4

Risk Risk Risk Risk Risk Risk Risk


Risks
No. 1 No. 2 No. 3 No. 4 No. 5 No. 6 No. 7

Illustration 8 Risk Analytics: Change in Assessment

A change in risk may cause the associated risk profile to shift. After the initial risk analysis,
management now expects that competition to the retail operation may be more significant
than originally evaluated, thereby causing the risk profile to shift upward.

Enterprise Risk Management


Risk, Strategy, and Performance

$180,000
Original
risk
$160,000
profile
$140,000
Revised
$120,000 risk
Value at risk

profile
$100,000

$80,000

$60,000

$40,000

$20,000

$-
1 2 3 4 5 6 7 8 9 10

Performance (addition of store outlets)

4–30 Module 2 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 2
2D_Residual Risk
PART 2 UNIT
2 4 D.1. Enterprise Risk Management: Part 2

3.4 Performance Management


Performance management requires risk identification, assessment of risk severity, prioritization
of risk, implementation of risk responses, and development of a portfolio view. Performance
management is put into practice by organizational units. A risk assessment officer may be hired
to oversee the implementation and monitoring of ERM.

3.5 Internal Control


Management designs controls to ensure that enterprise risk management principles are applied
and objectives are achieved within the limits of the entity's risk appetite.
Graphical representations may be used to understand performance and risk management.
Graphical presentation allows management to evaluate the effects of a change in a risk profile in
relation to risk appetite and risk capacity.
Periodic reviews of the organization's risk profile allow for regular assessments of whether
the organization performed as expected and achieved its target, what risks have impact
performance, and whether the estimate of risk was accurate.

Illustration 9 Risk Analytics: Assessment With Risk Appetite Overlay

A retail operation sets a target of opening five additional stores when the retailer's risk
profile is safely below its risk appetite. The risk appetite was established at the maximum
amount of value at risk the company was willing to sustain. After the initial assessment was
made, a subsequent assessment showed an overall increase in risk, as shown below. Now,
opening five stores challenges the limits of the firm's risk appetite. Management should
reevaluate the target of opening five stores or perhaps even the strategic or business goals
that drive the target.

Enterprise Risk Management


Risk, Strategy, and Performance

$180,000 Original risk


Target profile
$160,000 Revised risk
profile
$140,000 Risk appetite

$120,000
Value at risk

Risk capacity

$100,000

$80,000

$60,000

$40,000

$20,000

$-
1 2 3 4 5 6 7 8 9 10

Performance (addition of store outlets)

2D_Effect of change in risk profile_risk appetite_risk capacity


© Becker Professional Education Corporation. All rights reserved. Module 2 4–31 D.1. Enterp
2 D.1. Enterprise Risk Management: Part 2 PART 2 UNIT 4

4 Applying ERM

Applying ERM to a specific organization would overlay the five components identified in the
framework and related risk management techniques to specific circumstances.

Illustration 10 ERM Application

The Do-Good Pharmaceutical Co. was founded to produce groundbreaking discoveries


to ensure effective medications are available to the widest population possible while
providing a return to investors.
To apply ERM, the company begins with articulating a mission statement that fully
embraces both its business and altruistic goals. The mission statement is supported by a
vision statement, anchoring the mission in shared values.
To apply the governance component of ERM, the company establishes an appropriate
organizational structure, applying board oversight to ensure achievement of objectives.
The board sets appropriate objectives consistent with the entity's mission (e.g., market
share, profitability, research and development commitments, numbers of drug trials, etc.).
As part of the performance component, management identifies the risks associated with
achieving the entity's objectives, its risk appetite, and its responses to risk.
As part of the internal control component, the company establishes appropriate monitoring
and feedback to determine if risk is being adequately controlled or if estimates require
revision. Results are communicated throughout the organization and the company's
strategy is reviewed and refined.

Question 1 MCQ-12675

Risk management is normally accomplished in the following sequence:


a. Determine risk appetite, identify risk, establish objectives, develop responses,
implement responses, and report results of risk management effort.
b. Set strategy, identify risks, determine risk appetite, develop risk responses,
implement responses, and report risk management effort.
c. Establish risk appetite, set strategy, identify risk, develop and implement risk
responses, and report on risk management effort.
d. Identify risks, establish objectives, develop responses, implement responses, and
report results of risk management effort.

4–32 Module 2 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 2
PART 2 UNIT
2 4 D.1. Enterprise Risk Management: Part 2

Question 2 MCQ-12676

Able Investor has become completely enamored with the possibility of securing gains on
stock market investments and ignores market volatility. Able chases stock performance
and, although Able has done no formal analysis of Able's portfolio, Able believes Able is
slightly ahead. Able's attitude toward risk would be characterized as:
a. Risk indifferent.
b. Risk seeking.
c. Risk averse.
d. Risk sharing.

Question 3 MCQ-12677

The CEO of Mega Stores Inc. has asked the COO to propose a plan to expand operations
in a manner that prudently increases profitability while staying with the company's risk
tolerance. The COO has evaluated the possibility of opening between one and ten stores
and, with the assistance of the controller, has developed a risk profile for each level of
performance (store openings). The controller developed measurements of risk appetite
and risk capacity based on cash-flow-at-risk computations and then developed the
following depiction of risk in comparison to risk tolerance and capacity.

Enterprise Risk Management


Risk, Strategy, and Performance
Risk profile
Risk capacity
$100,000 Risk appetite

$90,000
Target
$80,000
Risk

$70,000
$60,000
$50,000

$40,000
$30,000
$20,000
$10,000
$-
1 2 3 4 5 6 7 8 9 10

Performance

The COO has proposed opening eight stores. How should the COO's proposal be received
based on the study of risk?
a. Accept the proposal.
b. Reject the proposal.
c. Accept the proposal if the risk appetite can be decreased.
d. Accept the proposal if the risk profile can be increased.

© Becker Professional Education Corporation. All rights reserved. Module 2 4–33 D.1. Enterp
2 D.1. Enterprise Risk Management: Part 2 PART 2 UNIT 4

Question 4 MCQ-12678

The objective of enterprise risk management is to provide:


a. Reasonable assurance that risks will be handled in accordance with company policy.
b. Negative assurance that confidence levels used in Value at Risk computations are
appropriate.
c. Absolute assurance that unexpected losses will be avoided.
d. Reasonable expectation that assumed risks will be within a risk appetite while
achieving strategic and business objectives.

4–34 Module 2 D.1. Enterprise


© Becker Professional Education RiskAllManagement:
Corporation. rights [Link] 2
Class Question Explanations Part 2

UNIT 4

Unit 4, Module 1

1. MCQ-12672
Choice "b" is correct. Operational risk represents the exposure organizations have in their
day‑to‑day operations separate from the risks presented by the economy or by participation
in an industry. Operational risk comes from internal failures, inefficiencies, flawed processes,
human error, and/or poorly designed systems that produce losses. Operational risk is
characterized by inefficiency (e.g., increased costs) and ineffective delivery of value (e.g., lower
production) resulting from management decisions or human error.
Quik Growth Manufacturing Corp. suffered losses that were the consequence of operational risk.
Management has poorly supervised and poorly trained employees operating poorly maintained
equipment resulting in injuries that likely produced inefficiencies. Management's decision to
expand production to meet requirements without fully addressing the operational issues of
adequate supervision, training, and plant and equipment maintenance have resulted in losses.
Choice "a" is incorrect. Quik Growth Manufacturing Corp. suffered losses that were the
consequence of operational risk, not hazard risk. Hazard risk is the risk that exposure to a
condition or hazard will produce negative results.
Choice "c" is incorrect. Quik Growth Manufacturing Corp. suffered losses that were the
consequence of operational risk, not compliance risk. Compliance risk is the risk of financial
or economic harm from sanctions, fines, or other judgments imposed by a regulatory body
on account of a business' failure to follow laws and regulations. While the situation implies
workplace safety issues that could result in fines, the risk presented by poorly executed
procedures, poor maintenance, and inadequately trained employees is an operational risk
whose subsequent consequence may be compliance risk.
Choice "d" is incorrect. Quik Growth Manufacturing Corp. suffered losses that were the
consequence of operational risk, not financial risk. Financial risk includes broad, strategic risks
associated with either, or both, business capitalization (involving both overall leverage and
liquidity) or transaction, execution, and settlement events (involving credit and default risk, as
well as hedging).

© Becker Professional Education Corporation. All rights reserved. CQ–35


Part 2 Class Question Explanations

2. MCQ-12673
Choice "d" is correct. The maximum possible loss is the worst loss that could occur because of
a single event. The maximum possible loss is the sum of expected losses, unexpected losses,
and catastrophic losses, where catastrophic losses (as a component of unexpected losses)
are financed by insurance. The most relevant losses are the unexpected losses retained
(self‑insured) by the business.
In the event of a total loss of a cargo vessel, the loss exposures would be computed as follows:

Value of cargo vessel $ 20,000,000


Periodic maintenance per vessel ($500,000 ÷ 10) 50,000
Maximum possible loss $ 20,050,000
Catastrophic loss (insured: 20,000,000 × 90%) (18,000,000)
Expected loss (periodic maintenance from routine losses) (50,000)
Unexpected loss $ 2,000,000

The company's unexpected loss is $2,000,000: the maximum $20,050,000 possible loss less
$18,000,000 catastrophic loss shared with insurers and less $50,000 expected losses. The
$2,000,000 unexpected loss is the amount retained by the company.
Choice "a" is incorrect. The $20,000,000 loss of the value of the cargo vessel is a component of
maximum possible loss but is not the unexpected loss.
Choice "b" is incorrect. The $18,000,000 insured amount of the vessel is the catastrophic loss
shared with the insurance company but is not the unexpected loss.
Choice "c" is incorrect. The $2,050,000 sum of the $2,000,000 loss exposure retained by the
company and the $50,000 expected loss from routine losses and maintenance is the total
amount retained on the loss of the vessel but is not the unexpected loss.

CQ–36 © Becker Professional Education Corporation. All rights reserved.


Class Question Explanations Part 2

3. MCQ-12674
Choice "c" is correct. Risk ranking or prioritizing assesses risk by the likelihood (probability) and
impact (severity) of risk events.
Likelihood (probability) anticipates whether a risk event is highly likely to occur, moderately likely
to occur, or not likely to occur (low probability).
Impact (severity) of risk anticipates whether the results of a risk event are insignificant,
moderately threatening, or catastrophic.
A risk map is a graphic representation of the ranking or importance of various risks in terms of
both the likelihood and impact of each risk on the achievement of operating, reporting, and/or
compliance objectives.
Risk maps may take the form of a heat map or matrix that plots qualitative estimates of both
risk likelihood and risk impact. Risks are depicted in a manner highlighting which risks are more
significant (higher likelihood and/or impact) and which are less significant (lower likelihood and/
or impact). The illustration, below, shows the heat map quadrants representing the likelihood
and impact of risks occurring. Each risk would be plotted on the map for easy visual evaluation
of the likelihood and impact of each risk and, by extension, the priority that management should
assign to each risk.

Risks: Likelihood and Impact


Moderate exposure: High exposure:
High impact High impact
Low likelihood High likelihood
Impact

Low exposure: Moderate exposure:


Low impact Low impact
Low likelihood High likelihood
Likelihood

Risk evaluation would include prioritization of risks by their likelihood and impact. Depiction
on a heat map provides a visual image allowing management to quickly identify the most
important risks.
Choice "a" is incorrect. Risk inventories identify common risks but do not serve as an
evaluation tool.
Choice "b" is incorrect. Facilitated workshops identify risks but do not serve as an
evaluation tool.
Choice "d" is incorrect. Process flow analysis identifies risks but does not serve as an
evaluation tool.

© Becker Professional Education Corporation. All rights reserved. CQ–37


Part 2 Class Question Explanations

Unit 4, Module 2

1. MCQ-12675
Choice "c" is correct. Risk management is a top-down process primarily driven by management
attitudes toward risk. It is revised through ongoing communication and review and follows the
steps described below:
1. Establish management's willingness to assume risk (risk appetite) to produce value and
achieve returns.
2. Set strategies and related objectives to conform to management's willingness to assume risk.
3. Identify risks.
4. Develop responses to identified risks.
5. Implement risk responses.
6. Report the results of risk management and use those results to reevaluate objectives
and strategies.
Risk management begins with the determination of risk appetite followed by establishment of
objectives, identification of risks, and development of responses to those risks. Implementation
of risk responses and reporting on the effectiveness of those responses are the final steps.
Choice "a" is incorrect. Risks are not identified before the establishment of objectives.
Choice "b" is incorrect. Strategy is not set before the determination of risk appetite.
Choice "d" is incorrect. Determination of risk appetite is a crucial step in risk management and is
missing from the listing in this solution.

2. MCQ-12676
Choice "a" is correct. Risk attitudes and behaviors can be categorized as risk indifferent, risk
seeking, and risk averse.
yyAn investor who is risk indifferent (risk neutral) does not focus on risk as a factor when
the investor makes investment decisions. Risk-indifferent behavior is often emotional or
situational. An individual who invests solely based on hoped-for gains regardless of potential
losses is risk indifferent.
yyA risk-seeking behavior describes those individuals aggressively seeking higher returns in
exchange for understanding and accepting higher risk. While risk-seeking behavior may
not seem rational, this behavior simply is more aggressive than behavior which what more
conservative investors would view as prudent.
yyRisk-averse behaviors are the most frequently observed attitude toward risk. Individuals who
are risk averse seek to balance the assumption of risk with return. Achieving return while
minimizing risk characterizes the risk-averse investor.
Able is risk indifferent and seeks returns without respect to risk of loss.
Choice "b" is incorrect. Able is not seeking returns in exchange for risk; rather, Able is simply
seeking returns. Able is not a risk seeker; Able is risk indifferent.
Choice "c" is incorrect. Able is not risk averse. Able is not trying to avoid risk or even correlate
risk with return. Able is not risk averse; Able is risk indifferent.
Choice "d" is incorrect. Risk sharing describes response to risk. Risk sharing is not a risk behavior.

CQ–38 © Becker Professional Education Corporation. All rights reserved.


Class Question Explanations Part 2

3. MCQ-12677
Choice "b" is correct. The risk profile is a composite illustration of the composite risks that an
organization confronts. Risk of loss correlates performance with associated risk. In the case of
Mega Stores Inc., performance is measured by new stores opened while risk is measured by cash
flow at risk, which is the maximum amount of cash the company could lose in the worst-case
scenario. Risk appetite represents management's judgement regarding the amount of risk that
management is willing to assume, while risk capacity represents the limits of company resources.
Graphic presentation of the risk profile in comparison to the risk appetite and risk capacity depicts
the performance points at which risk either is within or exceeds established risk tolerance.
The company should reject the proposal. The proposed performance target exceeds the
company's risk tolerance.
Choice "a" is incorrect. The company should not accept the proposal to open eight stores. The
proposed performance target exceeds the company's risk tolerance.
Choice "c" is incorrect. Decreasing the risk appetite negatively widens the gap between the risk
profile at the proposed performance level. Reduction of the risk appetite makes rejection of the
proposal more certain.
Choice "d" is incorrect. Increasing (shifting up and/or to the left) the risk profile negatively widens
the gap between the risk profile at the proposed performance level. Increasing the risk profile
makes rejection of the proposal more certain.

4. MCQ-12678
Choice "d" is correct. Enterprise risk management (ERM) has the overall objective of improving
decision making in governance, strategy, objective setting, and day-to-day operations. ERM
seeks to provide the reasonable expectation that an organization will assume risks, within a risk
appetite appropriate for that organization, to achieve the organization's strategic and business
objectives. ERM achieves this objective by linking strategy and business objectives to risk.
The overall objective of ERM is to provide the reasonable expectation that an organization will
achieve its goals and objectives within its risk appetite.
Choice "a" is incorrect. Reasonable assurance is an internal control and audit concept that does
not apply to the overall objective of ERM.
Choice "b" is incorrect. Negative assurance is an audit concept that does not apply to the overall
objective of ERM.
Choice "c" is incorrect. Few, if any, measures provide absolute assurance of achievement of
objectives, particularly unexpected losses and the financial impact of those losses.

© Becker Professional Education Corporation. All rights reserved. CQ–39


Part 2 Class Question Explanations

NOTES

CQ–40 © Becker Professional Education Corporation. All rights reserved.

Common questions

Powered by AI

Governance, risk appetite, and information systems are pivotal for the integration of Enterprise Risk Management (ERM) throughout an organization. Governance frameworks assign roles and responsibilities that ensure ERM practices permeate all levels of management, fostering a culture of risk awareness and strategic alignment . Risk appetite guides decision-making by outlining acceptable risk levels in pursuit of objectives, aligning with value creation strategies . Concurrently, information systems support ERM by managing data and ensuring effective communication, helping to monitor and report risk, culture, and performance across the entity .

Implementing Enterprise Risk Management (ERM) in an organization offers several key benefits, including reducing performance variability by allowing managers to focus on risks that impede consistent performance over time rather than on extreme or infrequent risks . Additionally, ERM improves resource deployment by providing risk data and management insights that help assess overall resource needs and optimize resource allocation effectively .

The time horizon of an investment significantly impacts its risk exposure and volatility, with longer-term investments exhibiting greater susceptibility to changes in interest rates, default risk, and inflation. This is because a longer duration increases the chances that the expected rate of return on the underlying security will change, thereby affecting its value . Longer-term investments face increased exposure to interest rate changes, the impact of inflation, and risk of default, leading to a higher probability of unfavorable changes in value, whereas shorter-term investments have lower risk exposures due to limited opportunity for such volatility .

Risk ranking or prioritization plays a fundamental role in risk management by assessing risks based on their likelihood and impact, which informs strategic decision-making on risk response prioritization . This process is typically represented visually using risk maps, such as heat maps, that plot risks according to their likelihood and impact, allowing for easy evaluation and prioritization by management .

Risk severity assessment is critical in enterprise risk management as it determines the potential impact and likelihood of a risk, guiding the deployment of resources to manage the risk within the entity's risk appetite . By assessing the severity of risks at multiple levels and understanding their potential effects on business objectives, organizations can prioritize risk responses effectively and ensure that significant risks are addressed in alignment with strategic goals .

Performance review and revision processes in Enterprise Risk Management can enhance an organization's value and risk handling by facilitating continuous improvement of ERM capabilities and practices. By evaluating the entity's performance relative to targets, organizations can identify how well these practices have contributed to creating value and adapt to ongoing changes. This active review allows for the alignment of risk management strategies with evolving business objectives, increasing risk resilience and optimizing the organization's risk-return profile over time .

The 'unexpected loss' is the portion of possible losses that exceed the expected loss and do not reach the catastrophic loss threshold, typically retained by the company . It differs from the 'maximum possible loss,' which is the worst that could occur from a single event, comprising expected, unexpected, and catastrophic losses . In calculation, the maximum possible loss sums expected losses, unexpected losses, and catastrophic losses, while unexpected loss is the maximum possible loss minus insured catastrophic losses and routine expected losses .

A company like X Co. can calculate its expected losses from global operations by assessing the probability and potential impact of various strategic, legal, and compliance risks. This involves identifying different risk types, estimating the risk exposure, multiplying it by their probability of occurrence, and summing up these results to obtain a total expected loss. For example, calculating the expected loss involves multiplying the probability of technological obsolescence by its potential loss amount, and similarly for strategic risks like natural disasters, legal risks like theft of intellectual property, and compliance risks like court-ordered cease and desist .

The use of 'cash flow at risk' techniques benefits companies like Hi Tech Computer Co. by allowing them to evaluate the impact of foreign currency exchange rate fluctuations on cash flows. This approach assigns probabilities to changes in cash flows associated with foreign currency rate movements, similar to value at risk, enabling the company to assess the likelihood and impact of unfavorable developments. Such assessments provide a confidence level regarding maximum cash requirements under worst-case scenarios, thereby aiding in better financial risk management .

Aligning risk appetite with value creation within Enterprise Risk Management frameworks is crucial because managing risks within the risk appetite enhances an organization's ability to create, preserve, and realize value . This alignment ensures that the anticipated value creation is in line with the organization's risk appetite, promoting strategic risk management and effective decision-making for sustainable growth .

You might also like