Guidance Note on Risk Management
Guidance Note on Risk Management
[Link]
PRESIDENT
THE INSTITUTE OF COST AND WORKS ACCOUNTANTS OF INDIA (Established by an Act of Parliament) 12, Sudder Street, Kolkata-700016 Phones:91-33-2252-1021/34/35.2252-1602/1492 Fax: 91-33-2252-7993/1026 E-mail: president@[Link] Website: [Link]
Foreword Across the world, Risk Management has increasingly become integral to the management of businesses. In our country, while awareness of the need for proactive risk management is growing steadily, actual progress has been limited. However our country is moving rapidly up a growth curve in an increasingly borderless and turbulent world. While competitive forces compel focus on better, faster, lower cost, steering a business in this exciting scenario requires a thorough understanding of risks and their mitigation. Members of our Institute have always played an active role in assisting managements to meet the expectations of their stakeholders. The prime demand from stakeholders is improvement in returns with minimum volatility. Effective management of risk is a prerequisite to meet this need. This Guidance Note provides a comprehensive overview of the subject and will enable our members to play a complimentary role in enabling organizations to meet their stakeholders expectations. It is heartening to note that the Professional Development Committee of our Institute has brought out this Guidance Note as our Institutes continued contribution towards enabling our Members to enrich their organizations and remain contemporary with world trends. I place on record by sincere appreciation to Shri Kunal Banerjee, Chairman of the Professional Development Committee and to all the members of the Committee for overseeing the preparation of this publication and to Shri Prodipto Banerjea, our member, who has authored it. I also thank the PD Directorate and Studies Directorate for their contribution in bringing out this publication timely. I hope the Regional Councils and Chapters will come forward to conduct programmes to enable all our members to develop the required competence in this area. With Best wishes, [Link] President 18th July, 2011
KUNAL BANERJEE
Chairman Professional Development Committee
THE INSTITUTE OF COST AND WORKS ACCOUNTANTS OF INDIA (Established by an Act of Parliament) 12, Sudder Street, Kolkata-700016 Phones:91-33-2252-1021/34/35.2252-1602/1492 Fax: 91-33-2252-7993/1026 E-mail: [Link]@[Link] Website: [Link]
Preface The process of Risk Management was formally introduced by SEBI for all listed companies by revising Clause 49 of the listing agreements with the stock exchanges. As a result, with effect from December 31, 2005, it became necessary for every listed company to meet the following requirement - The company shall lay down procedures to inform Board members about the risk assessment and minimization procedures. These procedures shall be periodically reviewed to ensure that executive management controls risk through means of a properly defined framework While management of business invariably necessitates management of risks, formal processes were absent and silo based activities was the norm. The SEBI intervention requires a comprehensive approach which has been delineated in this Guidance Note. A detailed overview has been provided to members to enable appreciation of the nuances involved and a structured approach to the risk management process has been suggested. We hope our members emerge as important resources in the risk management processes of their organization. I have the pleasure in introducing the title Risk Management. This publication shall act as a ready reference to assess the risk involved. I express my sincere thanks to Sri Prodipto Banerjea, a fellow member of our Institute, a pioneer in this field of Risk Management, who has authored the Guidance Note. I would like to thank my fellow members on the Professional Development Committee for their enthusiastic participation in the preparation of this Note I appreciate the timely efforts put in by the officials of the Secretariat in arranging for the release of the material. I hope that this publication will be a very useful reference to all the concerned. With Best wishes, Kunal Banerjee Chairman, Professional Development Committee 18th day of July, 2011
INDEX
Ch. No. I II III IV V VI VII VIII IX X XI Introduction Understanding Risk The Management Process Environmental Risks Strategic Risks Operational Risks Financial Risks Governance and Risk Internal Controls Driving Stakeholder Value Setting up the Risk Management System 1 2 5 9 11 13 19 22 24 27 29 Title Page Nos.
iii)
II
Risks can be categorized into two groups viz., 1) Pure Risks These are cases where there are chances of loss with no possibilities of gain. Typically these relate to losses from perils such as fire, earthquake, floods or losses from automobile accidents and the like. Pure risks can generally be classified as a) Personal risks comprising possibilities of loss of income or assets as a result of loss of earning ability. Instances include i) ii) iii) iv) premature death dependant old age chronic sickness or disability unemployment
b) Property risks comprising direct and indirect losses arising out of ownership of property. While direct losses relate to losses arising directly from the destruction of the property, indirect losses refer to losses such as the additional costs an owner would incur living somewhere when the property is destroyed. This is also referred to as consequential loss and is very important for businesses c) Liability Risks These refer to losses incurred by others due to our actions. The losses could be injury to the persons, or damage to their assets and may be unintentional, or due to negligence or carelessness d) Risks arising from the failure of others - These arise when others fail to meet their agreed obligations, say when a debtor fails to pay debts on due dates. 2) Speculative Risks - These refer to risks where there are possibilities of gains as well as losses. Most risks are in this category though the classic case is that of gambling, where risk is deliberately created in the hope of gain. Similarly an entrepreneur makes his investment in the hope of gain. The risk he runs is expected to be met by his reward, or the profit expected from his venture. His management of risk becomes key to his business success.
Page 3
b)
c)
The activity of Risk Management deals with the risks retained and will be discussed in more details in the subsequent chapters.
Page 4
The goal of every business is to meet target objectives. Since Risk is a key factor in achieving the objectives, effective management of Risk is a critical goal for every business. Well-managed businesses have historically managed risks successfully, however that has generally been on a silo-based approach. The production team would manage technology, treasury would manage currency, legal teams would manage compliance. In todays complex world it has been found that such a fractured approach often leads to sub-optimal solutions, impairing the organizations overall returns. Consequently, an integrated approach is recommended. Risk is an uncertainty that can be understood, measured, monitored, mitigated and ultimately leveraged. For every business, the risks involved need to be understood clearly. Specific risks need to be identified and assessed. Mitigation methods need to be instituted and their success in controlling the risks monitored. This information needs to be shared across the organization, as relevant, ensuring a continuous process. Risk Management Process
Understanding Risks
Communicating Results
Identifying Risks
Monitoring Control
Assessing Risks
Mitigation Methods
1.
Understanding the Risks In order to understand the risks for any business it is necessary to know its purpose or mission, the objectives it has set for itself and the strategies it has chosen towards achieving those objectives.
Page 5
c.
d.
3.
Assessing the Risks All identified risks need to be assessed since this assessment will ultimately determine the priority of management. One simple qualitative method of such assessment would be to first classify the risks on the basis on frequency viz., a. b. c. d. e. Frequent : Occurring very often or continuously Likely : Occurs several times over the considered time period Occasionally : Occurs sporadically during the considered time period Seldom : Possible, but recurs rarely Unlikely : As the term signifies, will probably not occur
This is then combined with the financial impact when the risk occurs Catastrophic : critical financial loss in terms of severity and magnitude (could lead to bankruptcy) Critical : serious financial loss which would drastically reduce returns
Page 6
Such a qualitative basis is useful where no data is available either on the probability of frequency or the financial impact. However, if such data is available, then a more quantitative analysis is possible. The risks can be plotted on a Risk Map as given below : Risk Map
High High Impact Low Likelihood Value of Impact High Impact High Likelihood Low Impact High Likelihood
High
The four quadrants clearly delineate the relative importance of each risk and provide an immediate basis for action. The management of the organization can take cognizance of the risks depending on their position on the map and the resources available.
Page 7
ii)
Monitoring The success of any management process is dependent on the quality of monitoring and review. It is essential that the organization monitor the mitigation activities and i) ii) review the performance of the mitigation methods review the effectiveness of the processes being used for arriving at the mitigation methods
6.
Communication Finally, it is imperative that the progress in the area of risk management get communicated effectively across different levels in the organization. It is necessary that at each relevant level it should be known that i) ii) iii) the assessment process was appropriate the measures adopted resulted in the intended output where the performance was below expectations, the fresh assessment and new measures required have been instituted.
Page 8
These are the external influences on the business and constitute the environment within which it operates. Normally this is an ever-changing scenario which provides opportunities as well as constraints within which the business has to function. Some major components are i) Economic Risk - This is the impact of the general economy on the business. Usually, the most critical impact is that of inflation since that affects the purchasing power of customers. However, in case of a recession there may be a drop in the aggregate demand which can also have a very adverse impact. An understanding of the taxation regime is always useful and for some businesses specific policies of the Government may be useful for instance where they are affected by subsidies or grants. Environmental / Ecological Risk Occasionally the Environmental Risk is taken to mean the Ecological Risk only. While this is a narrow perspective, it does not in any way reduce the criticality of the Ecological Risk for any business. Every business needs to understand the impact of its activities, products and services on its environment. Specific importance needs to be given to energy usage, waste, effluents, emissions, and sound pollution if any, including the problems of accidental spills. Prevention of pollution, minimization of global warming and environmental sustainability are important ecological targets for all businesses. When considering ecological risks, it is advisable for businesses to consider the impact of natural catastrophe such as earthquakes and floods on their installations and business cycles. Shareholder Expectations Risk Any business listed on the stock exchange needs to cognize for this risk. While these expectations exercise a stress on the business demanding constantly high levels of performance, the rewards for meeting the expectations or bettering them are generally handsome. This is a good example of a risk which can lead to gain, if mitigated successfully. Political Risk These are the risks arising from the power exercised by the government or sometimes even some non-governmental bodies. Political Risk may also arise due to governmental inaction, say failure to enforce the law. An extreme example of political risk is when there is a sudden change of government in a country, with the new government refusing to honour the agreements entered into by its predecessor. Comparatively less severe, though serious risks in this area would include risks of sudden changes in governmental policies, taxation laws, or even just bureaucratic incompetence or corruption.
ii)
iii)
iv)
Page 9
b)
c)
vi)
Social Risk These are the risks businesses face of challenges to their business practices by their stakeholders. These can also be classified as societys impact on business. A typical example is the popular movement that often arises in many developed countries on the use of clothes manufactured in third-world sweatshops. Another case is the move to ban carpets produced in countries where child labour is endemic or for instance the move to ban the use of paper or board produced through unsustainable forestry practices. Thanks to the variety and forms of media prevalent around the world, the notice and broadcast of a perceived social risk happens very, very quickly creating threats to the reputations of brands and corporates. Consequently it is very necessary for every business to a) b) identify the empowered stakeholders and their key issues work with the stakeholders in determining the appropriate level of engagement to address their concerns share the necessary information establishing improved accountability.
c)
Page 10
Strategy is the path a business follows to achieve a goal or an objective. When formulating strategy, alternatives are analysed. At this stage, the risks for each strategy may be identified, assessed and a risk map prepared. This enables the selection of strategies in line with the risk appetite of the business. Major topics in Strategic Risks include 1) Market Risks These reflect the level of uncertainty in the markets the business deals in. The markets considered here are not financial as those are discussed under financial risk. Market risk has to do with market structure, the strategies adopted for market growth and price behaviour. The social / political / cultural / economic forces impacting the industry, the legal and regulatory pressures and the demographic profile of the customers are all critical components of market risk. Competition Risk In any industry, competition works to drive down the rate of return on invested capital. It is therefore very necessary to actively monitor this risk and develop effective mitigation methods. There must be a clear understanding of the number of competitors and their business profiles as these are intrinsically linked to the business profitability. To any existing firm, new entrants are threats, as are substitute products since these tend to impact the industry economics. Similarly if suppliers are too powerful, input costs are difficult to control. On the other hand, if buyers are too powerful, output pricing gets restricted. Balancing between these opposing forces requires a careful study of competition, identifying and assessing all risks from this sector. Business Model Risk The business model of the enterprise needs to be understood in the context of its industry and competition. A dispersed manufacturing strategy could create risks of quality, uniformity and standardization. On the other hand a single manufacturing facility would create distribution and reach risks. A direct marketing model may result in ease of customer contact but fragmented distribution may inflate delivery costs. Similarly in service businesses, centralization may result in greater control, but the risk would be in higher turnaround times resulting in delays for customers. The strengths and weaknesses of each model need to be evaluated and the corresponding risks mitigated. Technology - Technology is a critical business requirement in todays world. However, the impact of technology has to be clearly understood in the context of the quality and volume, demand and price of the product or service, as the case may be. While technology in services is as important as in the manufacturing sector, its appropriateness is also essential. This area needs to be managed by
Page 11
2)
3)
4)
b)
c)
d)
Page 12
Operational Risk is the risk associated with business operations. Running a business requires the employment of people, working through certain processes and systems towards the pursuit of specific objectives. Consequently Risks associated with these areas are Operational Risks. 1) People - The people in a business comprise both the supervisors and the supervised and the processes and systems need to cover both, those managing and those being managed. This is consequently a complex area requiring careful attention. People are our greatest asset is a statement regularly heard from businesses today, but the manifestation of this belief in routine business operations needs to remain a key focus area. To quote from Peter Drucker in fact, organizations have to market membership as much as they market products and services and perhaps more. They have to attract people, hold people, recognize and reward people, motivate people, and serve and satisfy people. The major aspects are a) Human Resource Management practices viz., i) ii) iii) iv) v) vi) recruitment training and development job roles working conditions performance evaluation industrial relations Recruitment - The recruitment process is the first contact a future employee has with a business. A favourable first impression is always a good basis for a lasting relationship. A clear job description and a fair selection process implemented by a personable, enthusiastic and competent recruiter mitigates the risks in this process. Training & Development Having recruited the right persons, it becomes necessary for the organization to ensure proper fitment. A comprehensive induction programme ensures that the new entrants get integrated into the working environment and become productive quickly, with an understanding of the organisations and the specific business units goals, policies and procedures. Appropriate continued professional development processes for employees ensure that the people in the organization remain contemporary.
The Institute of Cost and Works Accountants of India Page 13
c)
Page 14
b)
c)
ii)
Knowledge Management the knowledge an organization possesses is often key to the success of the enterprise, being its major source of competitive advantage. However, this knowledge is often restricted to a few key persons with no structured process for its dissemination and updation. This can become a major drawback in case for any reason those individuals become unavailable. Further if the knowledge is unique and can be registered as an intellectual property, it is imperative that such registration be completed as soon as possible, failing which registration by another party may limit its use or even render it unusable. Information Technology (IT) As information technology becomes more and more necessary to operate businesses, the risk from IT failure becomes an increasing concern. The areas to be considered include a) Business Alignment The IT in use should be aligned with the business processes, ensuring smooth operations. A typical problem occurs when the physical process in use is not in line with the IT process, requiring additional effort for alignment. Data Security Globally, the security of electronic data is recognized as a risk and hacking, or illegal or unauthorised access has been identified
Page 15
iii)
b)
d)
e)
iv)
Supply Chain In a manufacturing system, the process of sourcing raw material, its conversion to finished product and delivering to the ultimate customer is called the supply chain process. Any uncertainty at any step of this process leads to a supply chain risk impacting the ultimate business objective of delivery to the customer. Consequently, these risks need to be identified, assessed and mitigated. Compliance All businesses need to follow laws and regulations, which cover all aspects of an enterprise. This is an area of pure risk since the mitigation only ensures that there is no downside i.e. no penalty. However, even though no benefit can accrue to the business, it is absolutely necessary for its successful existence to ensure that all its operations comply fully with the laws and regulations in place. One simple method is to have a Compliance Register or a checklist containing all the legal and regulatory issues that need to be complied with. A regular set of checks with this register can ensure that this risk is being mitigated on an ongoing basis. Project Any activity using specific resources towards a set goal is a project. Two specific characteristics of a project are a set schedule or time period within which it has to be completed and an estimated budget, which limits
Page 16
v)
vi)
c)
d)
e)
f)
g)
h)
i)
j)
vii)
Other Risks The list of operations risks enumerated is illustrative and not comprehensive. Two further risks relevant in the twenty-first century also merit special mention viz.,
Page 17
b)
Page 18
Management of the finances of a business is an integral part of the operations. Consequently, Financial Risk is a part of the Operations Risks of a business. However, these risks have unique structures and their management often involves special expertise. That is why these risks have been considered separately. Financial Risk arises when the values of assets, liabilities, cash flows and operating incomes vary due to changes in financial parameters. Some essential financial risks that need to be considered include:1. Liquidity Risk This refers to the risk that a business will not have sufficient funds to meet its obligations when they fall due. This could arise due to two reasons a) Funding Risk The inability to raise funds or borrow at normal rates. This happens when a business is not doing well and lenders are apprehensive of a default Asset Liquidity Risk - The lack of demand for the assets available. Liquid assets refer to assets that can be converted to cash easily such as bank deposits or government bonds. Usually other than businesses in the financial sector, such assets are not available. A manufacturing company would ordinarily need to sell its inventory and collect the dues from its customers to meet its liquidity needs. Consequently, control of the working capital cycle is an essential aspect of liquidity management.
b)
2.
Currency Risk If a business transacts with customers or suppliers in another country, then it is exposed to the fluctuations in value between the currencies of the two countries. These fluctuations arise due to two reasons, viz., the actual differences in demand and supply and the expected or projected differences on future dates of the two currencies involved. There are three components to this risk. a) Transaction Risk This arises due to the differences on the date of the transactions and the date of the cash flow. For instance in an export transaction if the sellers currency loses value between the date of sale and the date of cash inflows the actual amount received in the exporters currency will be higher than the amount recorded on the sale date. Translation Risk This arises due to the fact that the accounts of the business may need to be completed at a time when an overseas transaction has not been settled. Consequently the value of that asset or liability would need to be recorded on a date which is neither the date of
Page 19
b)
3. Credit Risk this is the risk that the counter-party to a transaction may not meet its obligations. In the case of a bank this would mean default by a borrower, while in a manufacturing business it would be a refusal or inability of a customer to pay its debts on the due dates. Traditionally, each business was required to complete its own diligence analysis of customers before dealing with them. However, nowadays credit rating agencies have come into being providing specific ratings of the capabilities of each business to pay its debts. 4. Interest Rate Risk Businesses borrow funds from the banks or the financial markets, which are intermediaries obtaining the funds from investors. The cost of the funds to the borrower is a mark up on the returns paid to the investor. Consequently, if such returns vary, the cost of funds or the interest rates for the borrowings would vary. It is therefore necessary for each business to ensure that the mix of funds borrowed is appropriate for its own returns profile ensuring that this risk is within manageable proportions. There are three issues that need to be considered in the context of Financial Risks viz :a) Commodity Risk The price behaviour of commodities is similar to that of currencies. Consequently, the mode of risk management of commodities is similar to the way in which currencies are managed. Quantity or size of exposure, current price and price volatility are the parameters to be mapped. Common Denominators The three basic factors of financial risks are price, volatility and liquidity. Most markets provide a current price and one into the future. The relationship is linear as the change in value is equal to the product of the change on price and the number of units held. Volatility is a measure of the changes in price of an item over a given period of time. Accurate predictions of volatility are required to determine the degree of risk at a given price level. Liquidity is a measure of market inefficiency as it provides a constraint on the size of transactions. It is a typical feature of each market segment. Theoretical calculations in measurement of risk usually assume
b)
Page 20
iv. c)
Derivatives These are financial products derived from some other financial instruments. For instance, an interest rate future is derived from a bond or treasury bill or deposit, while a currency future is derived from the spot market in that currency. Derivates are used for the redistribution of risk and customers fall primarily into two categories viz., one group which is guarding against a risk they need to mitigate in the normal course of business and another seeking a large reward for taking on a high risk. Some common derivatives are i. Futures An agreement to give or take delivery of a specific quantity of a currency or a commodity of a particular grade at a definite location on a future date is called a future. The contracts are standardized to ensure adequate liquidity. While currency futures contracts are standardized to quantity, commodity futures are standardized with respect to quantity, grade, delivery month and place of delivery. Options This is a contract in which the buyer has the right but not the obligation to purchase or sell an underlying asset at a specified price (strike price). In return, the option seller (writer) receives a fee referred to as the option premium. Options are available for interest-rate exposures as well as currency exposures. Swaps A swap is when an exposure in one currency is converted into an exposure in another currency, or when a loan with a fixed rate of interest is converted into one with a floating rate of interest.
ii.
iii.
A large variety of derivative instruments are available, however it is very necessary to understand each instrument as often the downside risks may be extremely high. The rules of accounting have also become stricter as a result of which any mistakes in this area are likely to surface immediately. Consequently although derivatives are excellent risk mitigation tools, their adoption needs complete understanding of all aspects.
Page 21
Governance is the process of exercise of authority and use of resources. In an organizational context it describes the method or approach by which an organization is directed and its activities controlled. Governance methods ensure that critical management information is complete and accurate and reaches the executive team on time. Governance also prescribes the mechanisms by which directions are given and instructions carried out. Risk Management, as has been explained in this Note refers to the processes through which an organization identifies, analyses and responds to the risks that may adversely impact the attainment of its business objectives. While responses to specific risks may vary the management of a portfolio of risks is routine. Governance activities cover the entire process of Risk Management which can be broken into several steps :i) Risks need to be identified, researched and understood, which includes the assessment process. Risks include all regulations, laws and in todays context even the impact of various guidelines and recommendations issued by international organizations (NGOs), especially on social and environmental issues. The next step involves the development and implementation of policies and procedures towards management of the risks and ensuring appropriate communication across the organization to ensure awareness and understanding Then it is necessary to execute the processes, track events, monitor changes, identify gaps and implement remedies. This step also requires documentation of audits and assessments so that assurance is available of effective management. Finally, it is necessary to report the progress in this area and make appropriate disclosures to the satisfaction of regulators and stakeholders.
ii)
iii)
iv)
In todays world, organizations face a range of risks and regulations in a variety of areas including safety, health, environment, security and public welfare, in addition to the laws and regulations relating to their respective products and services. Compliance with all these requirements is a complex task and has assumed critical proportions because of the severe impacts of non-compliance. Assessing the state of compliance, the risks and impact of discovery of non-compliance and the costs of corrective action have become necessary and important governance activities.
Page 22
Page 23
Internal Controls are processes within an organization designed to provide assurance regarding i) ii) iii) Efficiency and effectiveness of the operations Reliability of financial reporting Compliance with applicable laws and regulations
The Internal Controls Process comprises of five components, viz. i) Control Environment This is the atmosphere within the organization in which people conduct their activities. Integrity, competence and ethical values are the hallmarks of an effective control environment Risk Assessment Every organization works towards achieving certain objectives. Risk assessment is the identification and analysis of risks relevant to that achievement and the determination of the basis for their management. The organizational goals include a) Operations Objectives These comprise the mission of the organization i.e. the reasons for its existence including enhancement of the efficacy of its operations Financial Reporting Objectives These relate to the preparation of reliable financial reports Compliance Objectives These relate adherence to the laws and regulations applicable to the organization
ii)
b)
c)
iii)
Control Activities These are the specific policies and procedures in use within the organization towards achieving its objectives. The principal control activities are a) Segregation of Duties This requires that different persons be assigned responsibilities for different elements of related activities, especially sanctions, custody and record keeping, thus creating a system of checks and balances Authorisations This ensures that every activity is carried out by responsible persons entrusted for that purpose.
b)
Page 24
d)
e)
f)
iv)
Information and Communication Relevant information needs to be identified, processed and reported in an appropriate form and within an agreed time frame to enable the effective use of the information for the purposes of the business. The communication may be both internal and external, as required. Monitoring The assessment of the performance of the internal control process over time is an essential component of the process itself. The purpose is to ensure that the process is adequately designed, properly executed and effective in enabling the organization to achieve its objectives. Salient aspects of controls a) b) Controls need to be capable of responding quickly to changes Costs of control must be balanced against the benefits, including the impact of the risks that are being managed Control failures must be reported immediately with corrective action processes incorporated into the system The system of controls must be built into the operations of the organization as an integral part of its culture
v)
c)
d)
Note: Information Systems With the growing prevalence of Information Technology, it has become necessary to focus on controls especially relevant for this area. There are basically two categories of controls that are required for information systems i) general controls application controls General Controls include
Page 25
These controls are designed to maintain the integrity and availability of the information processing systems and networks. The controls focus on ensuring that correct data files are processed according to established protocols and relevant diagnostics monitored. ii) Application Controls include programmed procedures within application software Input controls ensure the complete and accurate recording of authorized transactions by only authorized users, ensuring identification of rejected and suspended items. These may be resubmitted after due validation, with various checks ensuring matching and completeness. Complete and accurate processing is ensured through processing controls, while output controls generate the audit trail, simultaneously reporting the results to authorized persons for review. Extensive end-user computing has necessitated focus on application controls.
Page 26
The management of risk has been established as a critical component in the operations of every organization. However, the risk- maturity level can vary across a wide spectrum ranging from merely complying with regulations, the minimum level of a GRC initiative as explained in Ch VIII, to a proactive function seeking to enhance the value of the enterprise. Value can be measured in a number of ways, not necessarily through financial measures alone, though economic profit is the parameter generally used. When the benefits derived from the use of resources are greater than the resources used, sustainable value creation takes place. Effective management of risk enables protection of value and creates sustainable value for the enterprise. A framework for a value creating risk management strategy would include Step 1 When setting objectives, performance goals and risks need to be optimized. Strategic alternatives need to be evaluated to determine whether the potential returns are commensurate with the associated risks. Therefore at the planning stage itself, the risk impact is incorporated into the objectives. Step 2 Once risk has been included into the objectives, the metrics and parameters for measurement need to be determined. These help the business to decide the current level of risk and the acceptable extent. Step 3 Then after the overall level has been decided, the granular targets for each risk are agreed as well as the key performance indicators. Step 4 All risks are analysed to identify the gaps between the existing state of affairs and the desired targets. These may arise in methodology, frameworks, tools, people or just levels of performance. Step 5 Finally, the implementation programme is made integrating the strategy into the daily operations resulting in the creation of a road map. The milestones are identified and strategy execution can commence. In this context it is relevant to refer to Michael Porters description of Risk in his book Competitive Strategy, where he states that Risk is a function of how poorly a strategy will perform if the wrong scenario occurs. Since the framework focuses on creation of value, the basic building blocks are the value drivers i.e. the measures that create sustainable value. For most commercial organization there are four basic value drivers.
Page 27
ii)
iii)
iv)
Once these value drivers have been identified in detail, the objectives for each value driver and the concomitant risks are arrived at. For instance geographic expansion may require knowledge of new regulations, new tax exposures and the like. On the other hand new products may mean a new customer base and a new competitor profile. The risks associated with each action plan are linked automatically, in this process to the performance and growth goals, ensuring continuous focus on value creation.
Page 28
Guidance Note on Risk Management Chapter XI Setting up the Risk Management System
A Risk Management Workshop is an effective means of introducing, developing and promoting the risk management process in an enterprise and setting up the systems. Such a workshop often starts with a brainstorming session where participants are encouraged to discuss the various business risks that they perceive. Identified risks need to be recorded in a Risk Register. There needs to be an understanding of the level of exposure that the enterprise must manage in order to achieve its objectives. Single point estimates are generally of little use as the range of the upside and the downside must be known. The degree of uncertainty at each level of exposure within the agreed time frame needs to be identified. Where a business plan is being prepared, the complete environmental scan and the analysis of internal capabilities needs to be completed and the risks listed. It is important to re-iterate the points that risks are a fact of life; todays environment requires quick identification of risks with immediate responses
Often when some activities get structured and defined, due to lack of clarity others are left out, leaving the enterprise vulnerable to unexpected and often unpleasant surprises. It is therefore necessary for each risk to have an identified owner, responsible for its mitigation. The risk owner can report the progress in risk management and this information can then be collated and communicated to the relevant levels, so that the impact on the organisations performance is understood and remedial action initiated, if and when necessary. An important perspective states that all management is essentially risk management. Sometimes it is useful for known risks to be revisited and re-examined to confirm relevance. The top risks need to be prioritized and the impacts assessed. Risk maps or priority lists need to be prepared taking into account significance and impact of each risk to the organization. Once the risks have been assessed, the mitigation strategies need to be implemented.
Page 29
2 3
4 5
Once the maturity levels are clear, a gap analysis may be completed for the key business risks. Based on this gap analysis, the mitigation strategy may be finalised. At the end of the workshop, the complete list of priority risks and the agreed mitigation strategies is available enabling immediate implementation. Performance in this area may be evaluated against the agreed milestones. While a detailed workshop may not be necessary ever year, revisiting the basic process with every business plan becomes an effectively control system for managing risks. A clearly enunciated Risk Management Policy, a comprehensive Risk Register recording the identified risks with ownership and regular monitoring and reporting of the progress in mitigation ensures smooth performance and growth for every organization.
Page 30