Chamaka Ranasinghe on Strategic Risk Management
Chamaka Ranasinghe on Strategic Risk Management
Strategy is about where to compete and how to compete, achieving sustainable competitive
advantage.
Levels of Strategy
Chamaka Ranasinghe 1
Strategic Risk Management
Strategic Choice
[Link] controls
[Link] creativity
→ Alternative Strategies
● Logical Incrementalism
● Emergent Strategies
→ Issues when formal planning is not conducted.
[Link] drift
[Link] difficulties
Chamaka Ranasinghe 2
Strategic Risk Management
[Link] skills
The party which receives the benefits is not the party which funds these organizations.
Therefore, setting a strategic plan can be problematic. Their performance should be
measured using 3Es and this also can be considered when setting the strategy.
[Link] measures
• Cost leadership
• Differentiation
• Focus
Chamaka Ranasinghe 3
Strategic Risk Management
Allows penetration
strategy.
Barrier to entry
Differentiation Higher margins Demand Differentiation Need for
is less elastic using technology, continuous
Strengthening barriers to design, innovation.
entry performance. Smaller volumes
Superior after Marketing costs
sales service are higher
Brand strength performance in a
Augmenting the recession can be
product packaging poor.
Focus Smaller investment in Reliable segment Cost leaders and
marketing identification. other will get
Specialization Identification of attracted
Less competition consumer needs Low volumes
Entry is easier Segment to be
sufficiently large
Competition
analysis
Chamaka Ranasinghe 4
Strategic Risk Management
Differentiation may not always lead to a business being able to command higher
prices.
Ansoff’s matrix
Method Risks
Market penetration Lowest risk option
Product development Higher risk
Market development Higher risk
Diversification Highest risk Related – Less risky.
Unrelated - Riskier
Chamaka Ranasinghe 5
Strategic Risk Management
• Simplicity
• Resources
• Cost Accessibility
• Quality
Steps
Chamaka Ranasinghe 6
Strategic Risk Management
[Link]
7 Questions
[Link] customer
[Link] boundaries
[Link] commitment
[Link] uncertainties
• Cyber attacks
• Workforce strikes
Ethics
Chamaka Ranasinghe 7
Strategic Risk Management
Fundamental Principles
(a) Integrity - A professional accountant should be straightforward and honest in all
professional and business relationships.
(b) Objectivity - A professional accountant should not allow bias, conflict of interest or undue
influence of others to override professional or business judgments.
(c) Professional Competence and Due Care - A professional accountant has a continuing
duty to maintain professional knowledge and skill at the level required.
1. Information is not disclosed outside the firm unless there is proper authority, right
or duty to disclose.
There must be reasons for disclosure before confidential information is provided to a 3rd
party.
2. Required by law
(e) Professional Behaviour - A professional accountant should comply with relevant laws
and regulations and should avoid any action that discredits the profession.
Threats
(a) Self-interest threats -may occur as a result of the financial or other interests of a
professional accountant or of an immediate or close family member.
Chamaka Ranasinghe 8
Strategic Risk Management
(b) Self-review threats - may occur when a previous judgment needs to be re-evaluated by
the professional accountant responsible for that judgment.
(c) Advocacy threats - may occur when a professional accountant promotes a position or
opinion to the point that subsequent objectivity may be compromised.
(d) Familiarity threats - may occur when, because of a close relationship, a professional
accountant becomes too sympathetic to the interests of others.
(e) Intimidation threats - may occur when a professional accountant may be deterred from
acting objectively by threats, actual or perceived.
2. Ascertain ethical issues involved and identify the fundamental principles related
Chamaka Ranasinghe 9
Strategic Risk Management
Safeguards
Reputational Risk
Reputational risk is the likelihood of losses occurring due to deterioration in the belief or
opinion held about someone or something.
Chamaka Ranasinghe 10
Strategic Risk Management
Corporate social responsibility (CSR) refers to the idea that a company should be sensitive to
the needs of all stakeholders in its business operations and not just shareholders.
● Brand – is something that the organization can control to a certain extent. It’s
about what the organisation does and how it approaches its products, services and
interactions.
Chamaka Ranasinghe 11
Strategic Risk Management
● Reputation – is what people think about an organisation, and crucially what they
communicate about an organization. This is much harder to control.
Strategic alignment
Strategic alignment starts at the very top of an organisation and is about the board making
sure that the strategic goals, the company and business processes align for the reason the
organisation exists, achievement of the mission.
Transfers within an international group will often be cross-border, between divisions in the
different countries. With international transfers and international transfer pricing, the issues
already described still apply. In addition, other factors need to be considered.
Changes in transfer price can redistribute the pre-tax profit between subsidiaries, but the total
pretax profit will be the same. However, if more pre-tax profit is earned in low-tax countries
and less profit is earned in high-tax countries, the total tax bill will be reduced.
There are factors that need to be considered when setting international transfer prices
Reduce the profitability of high tax countries can be done through transfer pricing
Multinationals could be required to apply “arm’s length” prices to transfer prices, they
might be required by tax laws to use market based transfer prices, to remove
opportunities for tax avoidance.
Chamaka Ranasinghe 12
Strategic Risk Management
A pyramid scheme is a business model that recruits’ members via a promise of payments or
services for enrolling others into the scheme, rather than supplying investments or sale of
products or services.
Advance Fee Fraud: When fraudsters target victims to make advance or upfront payments for
goods, services and/or financial gains that do not materialise. Types of advance fee fraud
include : Career opportunity scams. Clairvoyant or psychic scams.
3 pre-requisits :
dishonesty
→ Prerequisites for fraud opportunity
motive
As for most property-related crimes, there are three prerequisites for fraud to occur:
dishonesty on the part of the perpetrator; the opportunity for fraud to occur and a motive for
the fraud. Each can be dealt with through fraud prevention techniques:
Chamaka Ranasinghe 13
Strategic Risk Management
1. Dishonesty
● Pre-employment checks on all new staff (especially references)
● Careful scrutiny of staff by supervision and lifestyles that are not supported by
salaries.
● Severe discipline for offenders
● Effective moral leadership.
2. Opportunity
● Separation of duties where possible
● Controls over inputs (especially cash)
● Controls over processing
● Controls over outputs
● Physical security of assets.
● Motive
● Good employment condition
● Instant dismissals where necessary
● Sympathetic complaints procedure
The following warning signs may indicate the presence of fraud risk.
Chamaka Ranasinghe 14
Strategic Risk Management
Chamaka Ranasinghe 15
Strategic Risk Management
● Contracts that include specifications that only one supplier can satisfy.
● Personal relationships between staff and suppliers
● Withdrawal of a lower bid without explanation
● Acceptance of late bids
● Changes to specifications after bids have been opened.
● Poor documentation of contract award process
● Consistent favouring of one firm over another
● Unexplained changes to contract after its award
● Contract awarded to supplier with poor performance record.
● Split contracts to circumvent controls.
1. Fraud Prevention
The existence of a fraud strategy is itself a deterrent. This can be achieved through:
● Anti-fraud culture
● Risk awareness
● Whistle blowing
● Sound internal control systems
Chamaka Ranasinghe 16
Strategic Risk Management
● Not acting in a way that could bring the organisation into disrepute.
● Acting with integrity towards colleagues, customers, suppliers and the
public
● Ensuring that business objectives are clearly stated and communicated.
● Ensuring that benefits (whether to shareholders, customers or employees)
are distributed fairly and impartially.
● Safeguarding the confidentiality of personal data
● Complying with legal requirements.
Risk awareness - Fraud should never be discounted, and there should be awareness
among all staff that there is always the possibility that fraud is taking place.
Whistle blowing - Fraud may be suspected by those who are not personally involved.
People must be encouraged to raise the alarm about fraud.
Sound internal control systems - Sound systems of internal control should monitor
fraud by identifying risks and then putting into place procedures to monitor and report
on those risks.
2. Fraud Detection
Qualifying disclosures
1. Criminal offences
2. Failure to comply with legal obligation
3. Miscarriage of justice
4. Threats to health and safety
5. Damage to environment
Protected disclosure
Chamaka Ranasinghe 17
Strategic Risk Management
1. To legal advisory
2. To a government minister if you are a public sector worker
3. To a professional body or in extreme circumstance the media
3. Fraud Response
The fraud response plan sets down the arrangements for dealing with suspected cases of
fraud, theft or corruption.
Chamaka Ranasinghe 18
Strategic Risk Management
Corporate Governance
Chamaka Ranasinghe 19
Strategic Risk Management
Division of Responsibilities
Chairman
● Should be independent.
● Provide leadership to the board.
● Leading role in determining the composition and structure of the board which
will include a regular assessment on the size of the board, balance between
executive and non-executive directors and interaction, harmony, effectiveness
of the directors.
● Set board’s agenda and plan board meetings.
● Chair all board meetings, directing debate towards consensus.
● Ensure the board receives appropriate, accurate, timely and clear information.
● Facilitate effective contribution from NEDs.
● Hold meetings with NEDs, without executive directors’ presence.
● Chair the AGM and other shareholder meetings, using these to provide effective
dialog with shareholders.
● Discuss governance and major strategy with major shareholders.
● Ensure views of shareholders are communicated to the board as a whole.
CEO
Chamaka Ranasinghe 20
Strategic Risk Management
The role of chairman and CEO should not be held by the same individual.
→ Non-Executive Directors
● Strategy Role - Contribute to strategy development.
● Scrutinizing Role - Review performance of management in meeting objectives
● Risk Role - Ensure the risk management process is robust and financial systems
are accurate.
● People Role- Decide fair remuneration of BOD and succession planning.
Independence
● The code states the board should include a balance of NEDs and executive
directors. The board should consist of half of NEDs excluding the chair.
● One NED should be the senior independent director who is directly
available to shareholders if they have concerns.
● The primary fiduciary duty of NEDs is that they owe to the company’s
shareholders.
● They should not allow themselves to be captured or unduly influenced by
the vested interests of other members of the company such as executive
directors, trade unions or middle management.
● There are also concerns over the recruitment of NEDs and the challenge
that this may bring to independence.
● Recruiting NEDs with prior industry knowledge is good, but it can make
them less independent as it may reduce their ability to be objective, so it is
sometimes easy to be independent when they are from outside the
industry.
Chamaka Ranasinghe 21
Strategic Risk Management
The board should establish a transparent arrangement for considering how they should apply
the corporate reporting and risk management and internal control principles and for
maintaining an appropriate relationship with the company’s auditor.
→ Audit committee
Audit committees were first required under the Cadbury Code in response to criticisms of the
relationship between the directors and auditors
The board should establish an audit committee of at least 3 (for small companies 2)
independent NEDs. In smaller companies the chairman may be a member, but will not chair in
addition to the independent NEDs provided he or she was considered independent on
appointment as chairman. The board should satisfy itself that at least one member should
have recent financial experience.
Chamaka Ranasinghe 22
Strategic Risk Management
1. Significant accounting policies that have been used, and whether these are
appropriate
2. Any significant estimates or judgments that have been made and whether these
are reasonable
3. The methods used to account for any significant or unusual transactions, where
alternative accounting treatments are possible
4. The clarity and completeness of the disclosures in financial statements
Chamaka Ranasinghe 23
Strategic Risk Management
Remuneration
→ Remuneration committee
● Judge where to position the company relative to other companies
● Sensitive to pay and employment conditions elsewhere in the group, specially
when determining annual salary increments
● Decide what compensation commitments the director would entail in early
termination, should avoid rewarding poor performance
Chamaka Ranasinghe 24
Strategic Risk Management
Chairman should arrange for the chairmen of audit, remuneration and nomination
committees to be available to answer the questions at the AGM and for all directors to attend.
→ Summary on Committees
No of members - Min 3 3 3
Small companies - No 2 2 2
of members - Min
International Developments
→ Sarbanes Oxley Act – US
● Came into being after financial scandals of Enron & WorldCom
● SOX is extremely detailed and carries the full force of Law
● Includes requirements for the SEC to issue certain rules on CG
● Relevant to US companies, directors of subsidiaries of US listed businesses and
auditors who are working on US listed businesses
SOX vs UK code
Chamaka Ranasinghe 25
Strategic Risk Management
● Enforcement
● UK Code is “Principles-based” (a series of voluntary codes)
● SOX is “Rules-based”
● Documentation
● SOX includes rigorous provisions for evidencing IC and having them audited
● Auditors are restricted in the additional services they can provide to an audit
client
● Company MUST have audit committee-if not it will be disallowed from trading
● Senior partner of Audit partners must be changed every five years
● Directors are prohibited from dealing in shares at “sensitive times”
● Financial reports to detail off balance sheet financing
● Annual reports must include statements concerning the IC system
● Accuracy of financial statements must be vouched for by CEO & CFO
→ UK Code vs SOX
UK Code SOX
Certification of accuracy in financial More disclosures required in SOX Eg: Details on off
statements balance sheet transactions
Increased financial disclosures More disclosures required in SOX Eg: Details on off
balance sheet transactions
Both codes are similar SOX has more restrictions on auditors providing
non audit services
Chamaka Ranasinghe 26
Strategic Risk Management
→ CSR Report
Chamaka Ranasinghe 27