0% found this document useful (0 votes)
11 views23 pages

Risk Management Course Overview

Enterprise Risk Management

Uploaded by

Kopano Jonas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views23 pages

Risk Management Course Overview

Enterprise Risk Management

Uploaded by

Kopano Jonas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

COURSE FOR MANAGERS IN

RISK MANAGEMENT

Date

c-MiRM
Introduction

• Emergency Preparedness and Response


• Team Introduction
• Course Discipline
• Material Required
• Assignments & Final Assessment

(sherisk@[Link])

c-MiRM
Evolvement of ISO & RM Systems c-MiRM
65 countries
6 continents

Interna'onal*Na'onal*Standards*
Adopt*new*SL*format*
ISO14001,*ISO19001,*ISO45001,*
ISO31000,*ISO31010*
COSO,*IRMUK*Guidance*Doc*
Cri'cal*Control*ICMM*

BSI*OHSAS*standard*in*BSI*8800*
ISO3100,*31010,*73,*14000,*19000*
G=MIRM&2008&
Principle*Hazard*Management*

Na'onal*Standards*
Australian*AS/NZS*4801*(2001)*
Singapore*(SS)*506*(2004)*
US*ANSI*Z10*(2006)*
Derik&Venir&2001&&

OSHA’s*Voluntary*S&H*
SIMRAC*Guideline*
James&Reason&Models&

Interna'onal*Safety*Ra'ng*System*(ISRS)*
Frank&Bird,&et*al.*
Heinrich&theories*
*

c-MiRM
Module 1
Session 1 - Theory Session 2 - Theory Session 3 - Practical Session 4 - Practical
Introduction to the Course Feedback from Previous day Short Recap on Theory Feedback from Previous day
Module 4B: ISO 31010 Risk Assessment
Techniques
Module 1: ERM Principles, framework, Baseline, Issue Base RA Module 7: Monitoring and Review Practical: SWOT combined with Force
principles and protocols (ISO 31000) HAZOP (Project) (ISO31000) Filed Analysis
FMECA (Technical Equipment)
FTA / ETA (Event Management)

Module 2: Risk Culture, Aspect and Module 5: H&S Leadership in context of


Strategy ISO 45001, 14001, 9001
Modelling (IRM:UK Model) Behaviour modelling & Human Error
Practical: Attendee Presentations
Module 3: ISO 73 Risk Management 1. Internal and External Context
Vocabulary 2. Risk Culture and Improvement Plan
Concepts and Terminology 3. Hazard and Event Identification
Module 4A: Multilevel risk management 4. Hazard Lifecycle Map
Module 6: Bow Tie Analysis - Integration
process 5. Selection of Risk Assessment Techniques
with Activities and Critical Control
(ISO 45001) 6. System Effectiveness Course Examination
Monitoring regimes
Baseline Risk Assessment 7. BTA and Critical Control Exercise &
Issue / Significant Based Risk Assessment Feedback
Task / Activity Risk Assessment
Continuous Risk Assessment

c-MiRM
Managing Risks: The Un-Complete Framework
Managing Risk: Rules or Dialogue? The first step in creating an effective risk-management system is to
understand the qualitative distinctions among the types of risks that organizations face. Research shows
that risks fall into one of three categories. Robert S. Kaplan and Anette Mikes; June 2012

Preventable risks.
These are internal risks, emerging from within the organization, that are controllable
and ought to be eliminated or avoided. Examples are the risks from employees’ and
managers’ unauthorized, illegal, unethical, incorrect, or inappropriate actions and the
risks from breakdowns in routine operational processes.

Strategic risks.
Willingly accepts some risk in order to generate superior returns from its strategy. Not
inherently undesirable, cannot be managed through a rules-based control model.
The organisation will seek a risk-management system designed to reduce the
likelihood and impact, and to improve the ability to manage or contain the risk events
within their risk capacity.

External risks.
Some risks arise from events outside the company and are beyond its influence or
control. Sources of these risks include natural and political disasters and major
macroeconomic shifts. The most appropriate approach is for management to focus on
identification and mitigation of event impact.

c-MiRM
Guidelines
The Course and its Guidelines is purposefully limited to the following International Standards as
they have been adopted most widely by participating, listed companies and organisations, whether
in full or in a modified version

ISO
ISO 31004:2013: Risk 45001:2018:
ISO 31000:2018: Risk ISO 73: Risk ISO 31010:2019: Risk Occupational
Management - Guidance
Management - Practices Management – Management – Risk Health and
for the implementation
and Guidelines Vocabulary Assessment Techniques Safety
of ISO 31000
Management
Systems

Series of linked activities


Set of iterative steps
Coordinated
Not necessarily in a strict sequence

c-MiRM
C-MiRM: 3 – Core Subjects
Module 1, 2 & 3: Risk Module 4 & 5: Risk Module 6 & 7: Risk
Management Principles Management Process Management Framework

Integrated to all
organizational
activities. Governance / Policy Scope Context, Criteria
Integra(on*
Structured and Risk Appetite Statement
comprehensive Principal risk evaluation
Continual approach
improvement Design*
contributes to
through learning Risk Assessment
and experience. consistent and
comparable Risk Identification
results. Risk capacity statement
Total revenue expenditure: Improvement*
Risk Lifecycle
• Risk control

Dependency and supportive control monitoring regime


research
• Risk control
framework
• Risk control advice Risk Analysis
Qualitative, quantitative or a Implementa(on*

Change management strategies


combination
Human and Customised RM

Monitor and Review


Magnitude, effectiveness
cultural factors framework and Sensitivity, confidence levels Evalua(on*

Communication and Consultation


that significantly Effective risk process Scenarios
influence aspects management proportionate to
of RM at each external and
level and stage. internal context. Risk Evaluation

Risk deduce strategies


Critical control regimes
Cost benefit analysis
Risk tolerances and risk appetite

Best available
information, Inclusive,
historical and appropriate and
current, future timely Risk Response & Treatment
expectations, involvement of
limitations and Dynamic, risks stakeholders. Preventive control management
uncertainties. emerge, change, structure
disappear, Consequence control management
anticipates, structure
detects,
acknowledges
and responds. Recording and Reporting

c-MiRM
Principles, framework, principles and protocols (ISO 31000)
Dynamic, risks
Inclusive, appropriate emerge, change,
and timely involvement disappear, anticipates,
of stakeholders. detects, acknowledges
and responds.
Customised RM
framework and Best available
process proportionate information, historical
to external and internal and current, future
context. expectations,
limitations and
uncertainties.

Structured and Human and cultural


comprehensive factors that
approach contributes significantly influence
to consistent and aspects of RM at each
comparable results. level and stage.
Value
Creation &
Protection
Continual
Integrated to all improvement through
organizational
activities. learning and
experience.

c-MiRM
Framework at Upper Level

Risk management Structures Risk management Strategy Risk management Systems

• Committee structure and terms of • Risk management philosophy • Tools and techniques
reference • Arrangements for embedding risk • Risk classification system
• Roles and responsibilities management • Risk assessment procedures
• Internal reporting requirements • Risk appetite and attitude to risk • Risk control rules and procedures
• External reporting controls • Benchmark tests for significance • Responding to incidents, issues and
• Risk management assurance • Specific risk statements/policies events
arrangements • Risk assessment techniques • Documentation and record keeping
• Risk priorities for the present period • Training and communications
• Audit procedures and protocols
• Reporting/disclosures/certification

c-MiRM
Pillars of Risk Management (ISO 31001: 2018 & ISO 45001:2018)

Risk management is not strictly a serial process, where one Objective Setting
component affects only the next. It is a multidirectional, Objectives must exist before management can
iterative process in which almost any component can and does identify potential events affecting their achievement.
influence another. Enterprise risk management ensures that
Scope Context, Criteria management has in place a process to set objectives
and that the chosen objectives support and align
with the entity’s mission and are consistent with its
Risk Assessment
risk appetite.

Dependency and supportive control monitoring regime


Internal Environment
Risk Identification

Communication and Consultation


The internal environment

Change management strategies


encompasses the tone of an

Monitor and Review


Risk Analysis
organization, and sets the basis for Event Identification
how risk is viewed and addressed by Risk Evaluation Internal and external events affecting
an entity’s people, including risk achievement of an entity’s objectives must
management philosophy and risk be identified, distinguishing between risks
appetite, integrity and ethical and opportunities. Opportunities are
values, and the environment in Risk Response & Treatment channeled back to management’s strategy or
which they operate. objective-setting processes.
Recording and Reporting

c-MiRM
Pillars of Risk Management (ISO 31001: 2018 & ISO 45001:2018)

Risk Assessment Scope Context, Criteria Monitoring


Risks are analyzed, considering The entirety is monitored and
likelihood and impact, as a basis for modifications made as necessary.
Monitoring, measurement, analysis
determining how they should be Risk Assessment
and performance evaluation form the

Dependency and supportive control monitoring regime


managed. Risks are assessed on an basis of the change management
inherent and a residual basis. Risk Identification process.

Communication and Consultation

Change management strategies

Monitor and Review


Risk Analysis

Risk Evaluation

Control Activities
Relevant information is identified, captured,
Risk Response
Risk Response & Treatment
and communicated in a form and timeframe
Management selects risk responses
that enable people to carry out their
– avoiding, accepting, reducing, or
responsibilities. Effective communication
sharing risk – developing a set of
Recording and Reporting also occurs in a broader sense, flowing
actions to align risks with the entity’s down, across, and up the entity.
risk tolerances and risk appetite.

c-MiRM
Risk Management Maturity Focus Points

Scope Context, Criteria

Addresses Deviations in a Timely Manner – Risk Assessment

Dependency and supportive control monitoring regime


Deviations from the entity’s expected
standards of conduct are identified and Risk Identification

Communication and Consultation


remedied in a timely and consistent

Change management strategies


manner.

Monitor and Review


Risk Analysis
Evaluates Adherence to Standards of Conduct –
Processes are in place to evaluate the
performance of individuals and teams against the Risk Evaluation

entity’s expected standards of conduct.

Establishes Standards of Conduct – The expectations of the board of directors


and senior management concerning integrity and ethical values are defined in Risk Response & Treatment
the entity’s standards of conduct and understood at all levels of the organization
and by outsourced service providers and business partners.
Recording and Reporting
Sets the “Tone at the Top” – The board of directors and management at all levels of
the entity demonstrate through their directives, actions and behaviors the
importance of integrity and ethical values to support the functioning of the system
of internal control.

c-MiRM 12
Understanding Risk Appetite
How
hungry are
you for
Risk Appetite risk?

Risk Tolerance The ISO 31000 does not directly refer to risk
appetite but instead uses the terms “risk
attitude” and “risk criteria”:

Risk attitude reflects the organization's


Risk Profile approach to assess and eventually pursue,
retain, take or turn away from risk.

Risk criteria is a terms of reference against which


Residual risk the significance of a risk is evaluated.

c-MiRM
The components of Risk Appetite
Definition:
Risk appetite is the types, amount Risk capacity provides a threshold for the company to
ensure it remain viable.
and level of risk that a company or
individual is prepared to undertake
in pursuit of its objectives before
action is deemed necessary. Between risk capacity and risk appetite is a mitigation
GAP. Upper limits and lower limits used for standard
deviation from the target – produce KPIs
Important Factors One difficult aspect is to determine how big this GAP
• A level of risk-taking management between appetite and capacity should be.
deems acceptable The capacity of the GAP should account for every
• A conscious risk-based decision possible scenario set by extreme outcomes and errors
• Value of objectives in assumptions, analysis, and modelling
• Trigger point for risk response
This GAP is link to risk tolerance - what exposure a
company can actually cope and survive with.

c-MiRM
Benefits of Articulating Risk Appetite
A well-developed risk appetite statement and process can:
• Help a company better manage and understand its risk exposure
• Help management make informed risk-based decisions
• Help management allocate resources and understand risk and opportunities
• Help improve transparency for investors, stakeholders, regulators and credit rating agencies

Risk limit determines the thresholds (capacity) to monitor for the risk exposure or performance
deviating from the target (tolerance).

Exceeding a risk limit will typically act as a trigger for corrective action at the process level,
immediate notification at management level, and reporting at a governance level (Trigger
Action Response Plans).
Risk Strategy No Appetite for… KPIs Reporting & Limits

People Our employees contribute with a Capability performance falling outside following Employee satisfaction rating of 75%
sense of purpose and risk parameters: Total voluntary staff turnover of 8%
accomplishment: Deviations > 15% from staff satisfaction target Staff turnover of total employees with <12
• Attract and retain the skills and Short term period of staff turnover > 12% months service 18%
capability required to manage annualised monthly turnover 100% of identified key roles having an
risk exposure to meet strategic Cultural measures falling below previous year on approved succession plan
objectives year average IRM results
• Develop and maintain our Loss of incumbents of key roles without formal
Matt Mueller: EY Advisory
leadership succession plan in place
[Link] • Maintain a world class risk
culture

c-MiRM
ERM
Strategy - Horizontal approach (CADE3) Liq

gic
uid

ate
i ty

Str
Asset Capital Markets
How do we share and communicate Lifecycle Debt Financing
risk throughout the company?

g
rin
Pl a

l
M

a
nt

ee

ion
in
in
gi n
How do we measure efficiency of a

rat
g
En

e
multidimensional system?

Op
Network and Contract
Human
Infrastructure Management
Rights
Sa

t
f
He ety &

ial

en
k s
Ris orie

nc

So

Le
Scope Context, Criteria alt

on
a
g

ga
cia
h

Fin
te

vir

l
Ca

l
En
Risk Assessment
Dependency and supportive control monitoring regime

Risk Identification
Compliance Assurance Decisions
Communication and Consultation

Compliance with laws Assurance regarding Decisions that pay full


Change management strategies

and regulations the management of regard to risk


Monitor and Review

Risk Analysis significant risks considerations

Risk Evaluation

E 3 E 2
E 1

Efficacy in operations, Effectiveness in Efficiency in


projects and strategy operations, projects operations, projects
Risk Response & Treatment
and strategy and strategy

Recording and Reporting

c-MiRM 16
Strategy - Vertical approach (PACED)
Risk Taxonomy
Risk Area - Level 3

When is a risk management Risk_Area_-_Level_1 Risk Area - Level 2


(included as examples only (to help verify the
completeness of Level 2) - departments / assets can
define their own Taxonomies below Level 2 as required)
comprehensive?
1 Strategic 1,1 ESG / Reputation Labour Management

Water Stress
Do we have a dynamic system for risk Biodiversity and Land Use

assessment, change and control Toxic Emissions and Waste

response? Health and Safety

Human Rights

Carbon Emissions

How do we determine that the system is Corporate Governance

embedded at all levels of the “cube”? 1,2 Market and Demand for Products Supply, Demand and Commodity Prices

Asset Portfolio

Capital Allocation

Scope Context, Criteria


Proportionate
Proportionate to the level of
risk within the organization
Risk Assessment
Dependency and supportive control monitoring regime

Align
Risk Identification Aligned with other
Communication and Consultation

business activities
Change management strategies

Comprehensive
Monitor and Review

Risk Analysis
Comprehensive, systematic
and structured
Risk Evaluation
Embedded
Embedded within
business processes
Dynamic
Dynamic, iterative and
Risk Response & Treatment responsive to change

Recording and Reporting

c-MiRM 17
Internal & External Context (ISO 45001:2018)

The internal issues among which are: the Operational NGOs: which focus on development projects.
organizational structure, responsibilities and Rural Community Initiative
Consider what distribution, personal knowledge, middle Association of Round Tables in Southern Africa (ARTSA)
surrounds the management, technology, information flows,
organization and Centre for Conflict Resolution (CCR)
processes of decision making, etc.
evaluate how it may Advocacy NGOs: which are organized to promote particular
affect your OH&S causes.
Management External issues including: the cultural environment, Art for Humanity (AFH)
System market competition, new and old suppliers, new Lawyers for Human Rights (LHR)
technology, new legislation, etc.
Socio-Economic Rights Institute of South Africa (SERI)

Evaluate impact when choosing suppliers and


contractors, also need to consider, for • The nature of your relationship with each Stakeholder
example, how their activities can have an • The relative powers of each Stakeholder
impact on neighbours – next to mine and • Each group’s concern/ risk appetite
adjacent to service provider, roads, etc.
• How aligned/ unaligned are you currently with each stakeholder
• How to ensure maximum alignment (nature of communication, format,
Consider all positive (opportunities) or negative risk frequency etc.)
that may affect directly or indirectly the achievement of • What communication media you use to engage with each stakeholder
expected results, or achieve clear progress towards
planned objectives

c-MiRM
Internal & External Context
SocioGorganisa9onal!! !!!!!!!! !!!!!!!! External!!
Context! !!!!!Economic! !!!!!Safety!! Environment!
Environment! !!!!!!!legisla9on!
!!!!!!!!
!!!!!Organisa9onal!! !!!!!!!!!!!!!!&!!!
!!!!Structure!&!Systems! !!!!!!!!!!!!!!!regula9ons!

SAFETY-CULTURE-AND-CLIMATE-- -ORGANISATIONAL-STRUCTURE-AND- !!!!!!!!


!!!!!!!! !!!!!Uses!tools!!
- SYSTEMS- !!!!!Performs!! !!!!!!!!!!!and!!
Culture-shared-values-and-beliefs-of-people- - !tasks! !!!!!!!!
!!!!!!!!!technology!
Safety!! Human!!
in-organisa+on.- Hierarchy,-centre-of-power-(corporate--vs- !!!!!!!!
Culture!&!! Resources!!
Climate!!!!!!Works!in!a!! !!!!!!!!
Organisa+onal-“Safety- mine,-JV)- !!!!!!physical!! !!!!!Works!under!!
personality”-(observable-elements-of- Management-styles-(Instruc+ve-vs- !!!!!!!!environment!! organisa9onal!
condi9ons!
culture)- par+cipa+ve)- !
Just-Culture-- Management-system-incl-Safety,-change-
management,-control-management-&- !!!!!!!! !!!!!!!!
Work!System!!
!!!!!Labour!&!Management! !!!!!Industry!!
associated-systems)-- !!!!!!!! Standards!
(ac9vity)!
Rela9ons!
!!!!!Demographic!
!!!!!!!!!!!!!Context!!
LABOUR-&-MANAGEMENT-RELATIONS-- Socio%organisa+onal--
- Context- HUMAN-RESOURCES--
Trust-rela+onship-and-stakeholder- -
alignment- Line-vs-support-func+ons-
Stakeholder-preferences-on-execu+ng- Quality-of-Leadership-(i.e.-Transac+onal-vs-
objec+ves- -transforma+onal)--
Complex-structures-and-mandate- Quality-of-empowerment-
Inter%union-rela+ons- Recruitment-policy,-diversity,-succession,-
Engagement-strategy-and-communica+on- and-talent-management--
plaXorm- Quality-of-Communica+on--
Pascale Carayon, Peter Hancock, Nancy Leveson, Ian
Noy, Laerte Sznelwar & Geert van Hootegem

c-MiRM
External Environment
ECONOMIC)ENVIRONMENT)) )SAFETY)LEGISLATION)&)REGULATIONS))
) )
Unemployment)levels/)industry)job)crea@on)) Risk)Based)vs)prescrip@ve)
Levels)of)employee)indebtedness) Complexity)of)stakeholder) ))rela@onships)
Perceived/)real)wage)gaps) Over/)under)regula@on/)enforcement))
Family)Structures)(Dual/)distance)) Regulator)role)and)competence)in)execu@on)
Industry)GDP)contribu@on) (Statutory)consistency)and)clarity))
Stakeholder)expecta@ons)(shared)value))) Mechanism)for)development))and)review)of)
Transforma@on)&)ownership) legisla@on)
Illegal)mining/)theO)
External))
Environment)
DEMOGRAHIC)CONTEXT) INDUSTRY)STANDARDS))
) )
Social)diversity)(race,)gender,)genera@onal,) Industry)benchmark)for)H&S)performance))
language,)educa@on))) Management)and)focus)on)indicators)(leading)
Risk)Percep@on)and)tolerance) vs)lagging))
Ability)to)collaborate/)self)regulate))
Measurement)and)accepted)criteria)for)
performance)(local)vs)global))))

c-MiRM
Internal Environment
PERFORMS TASKS

Conflicting demands (safety/ production/ time


pressure) USES TOOLS AND TECHNOLOGY
Quality of supervision/task direction
Job/ task execution Availability and use of the right equipment & tools
Standards/ Operating procedures/ control
management
Capability (Skill, competence, knowledge,
experience, physical capability and fitness)

Work System WORKS UNDER ORGANISATIONAL CONDITIONS


(activity)
Culture (norms, values, priorities)
WORKS IN A PHYSICAL ENVIRONMENT Profitability & incentives
State of Certainty/ Uncertainty
Workplace design, Ergonomics Individual and team engagement
Hazards & Risks (health, safety, environmental).

c-MiRM
Drivers of Context
INFRASTRUCTURE RISKS
FINANCIAL RISKS
Communications
Accounting standards
Transport links
Interest rates
Supply chain
Foreign exchange
Terrorism
Funds and credit
Natural disasters
Internal control
Pandemic
Recruitment
Fraud
People skills
Historical liabilities
Health and safety

External Driven
External Driven

Investments
Premises
Capex decisions
Liquidity and cash flow IT systems

Internal Driven
Mergers and acquisitions activity Product extensions
Research & development Board composition
activities Control environment
Intellectual property
Contracts

Economic environment
Technology developments Product recall
Competition Public perception
Customer demand Regulator enforcement
Regulatory requirements Competitor behaviour

MARKETPLACE RISKS REPUTATIONAL RISKS

c-MiRM
Combined Assurance for Effective RM
Governing Body / Board / Audit Committee

Senior Management

1st Line of Defense 2nd Line of Defense 3rd Line of Defense


Financial Control
Security

External Audit
Internal
Management Risk Management Internal

Regulator
Control
Controls Quality Audit
Measures
Inspection
Compliance
Management Functions Assurance

Operating Management Limited Independence Internal Audit


Reports Primarily to Greater Independence
Management Reports to Governing Body

c-MiRM

You might also like