Risk Management Course Overview
Risk Management Course Overview
RISK MANAGEMENT
Date
c-MiRM
Introduction
(sherisk@[Link])
c-MiRM
Evolvement of ISO & RM Systems c-MiRM
65 countries
6 continents
Interna'onal*Na'onal*Standards*
Adopt*new*SL*format*
ISO14001,*ISO19001,*ISO45001,*
ISO31000,*ISO31010*
COSO,*IRMUK*Guidance*Doc*
Cri'cal*Control*ICMM*
BSI*OHSAS*standard*in*BSI*8800*
ISO3100,*31010,*73,*14000,*19000*
G=MIRM&2008&
Principle*Hazard*Management*
Na'onal*Standards*
Australian*AS/NZS*4801*(2001)*
Singapore*(SS)*506*(2004)*
US*ANSI*Z10*(2006)*
Derik&Venir&2001&&
OSHA’s*Voluntary*S&H*
SIMRAC*Guideline*
James&Reason&Models&
Interna'onal*Safety*Ra'ng*System*(ISRS)*
Frank&Bird,&et*al.*
Heinrich&theories*
*
c-MiRM
Module 1
Session 1 - Theory Session 2 - Theory Session 3 - Practical Session 4 - Practical
Introduction to the Course Feedback from Previous day Short Recap on Theory Feedback from Previous day
Module 4B: ISO 31010 Risk Assessment
Techniques
Module 1: ERM Principles, framework, Baseline, Issue Base RA Module 7: Monitoring and Review Practical: SWOT combined with Force
principles and protocols (ISO 31000) HAZOP (Project) (ISO31000) Filed Analysis
FMECA (Technical Equipment)
FTA / ETA (Event Management)
c-MiRM
Managing Risks: The Un-Complete Framework
Managing Risk: Rules or Dialogue? The first step in creating an effective risk-management system is to
understand the qualitative distinctions among the types of risks that organizations face. Research shows
that risks fall into one of three categories. Robert S. Kaplan and Anette Mikes; June 2012
Preventable risks.
These are internal risks, emerging from within the organization, that are controllable
and ought to be eliminated or avoided. Examples are the risks from employees’ and
managers’ unauthorized, illegal, unethical, incorrect, or inappropriate actions and the
risks from breakdowns in routine operational processes.
Strategic risks.
Willingly accepts some risk in order to generate superior returns from its strategy. Not
inherently undesirable, cannot be managed through a rules-based control model.
The organisation will seek a risk-management system designed to reduce the
likelihood and impact, and to improve the ability to manage or contain the risk events
within their risk capacity.
External risks.
Some risks arise from events outside the company and are beyond its influence or
control. Sources of these risks include natural and political disasters and major
macroeconomic shifts. The most appropriate approach is for management to focus on
identification and mitigation of event impact.
c-MiRM
Guidelines
The Course and its Guidelines is purposefully limited to the following International Standards as
they have been adopted most widely by participating, listed companies and organisations, whether
in full or in a modified version
ISO
ISO 31004:2013: Risk 45001:2018:
ISO 31000:2018: Risk ISO 73: Risk ISO 31010:2019: Risk Occupational
Management - Guidance
Management - Practices Management – Management – Risk Health and
for the implementation
and Guidelines Vocabulary Assessment Techniques Safety
of ISO 31000
Management
Systems
c-MiRM
C-MiRM: 3 – Core Subjects
Module 1, 2 & 3: Risk Module 4 & 5: Risk Module 6 & 7: Risk
Management Principles Management Process Management Framework
Integrated to all
organizational
activities. Governance / Policy Scope Context, Criteria
Integra(on*
Structured and Risk Appetite Statement
comprehensive Principal risk evaluation
Continual approach
improvement Design*
contributes to
through learning Risk Assessment
and experience. consistent and
comparable Risk Identification
results. Risk capacity statement
Total revenue expenditure: Improvement*
Risk Lifecycle
• Risk control
Best available
information, Inclusive,
historical and appropriate and
current, future timely Risk Response & Treatment
expectations, involvement of
limitations and Dynamic, risks stakeholders. Preventive control management
uncertainties. emerge, change, structure
disappear, Consequence control management
anticipates, structure
detects,
acknowledges
and responds. Recording and Reporting
c-MiRM
Principles, framework, principles and protocols (ISO 31000)
Dynamic, risks
Inclusive, appropriate emerge, change,
and timely involvement disappear, anticipates,
of stakeholders. detects, acknowledges
and responds.
Customised RM
framework and Best available
process proportionate information, historical
to external and internal and current, future
context. expectations,
limitations and
uncertainties.
c-MiRM
Framework at Upper Level
• Committee structure and terms of • Risk management philosophy • Tools and techniques
reference • Arrangements for embedding risk • Risk classification system
• Roles and responsibilities management • Risk assessment procedures
• Internal reporting requirements • Risk appetite and attitude to risk • Risk control rules and procedures
• External reporting controls • Benchmark tests for significance • Responding to incidents, issues and
• Risk management assurance • Specific risk statements/policies events
arrangements • Risk assessment techniques • Documentation and record keeping
• Risk priorities for the present period • Training and communications
• Audit procedures and protocols
• Reporting/disclosures/certification
c-MiRM
Pillars of Risk Management (ISO 31001: 2018 & ISO 45001:2018)
Risk management is not strictly a serial process, where one Objective Setting
component affects only the next. It is a multidirectional, Objectives must exist before management can
iterative process in which almost any component can and does identify potential events affecting their achievement.
influence another. Enterprise risk management ensures that
Scope Context, Criteria management has in place a process to set objectives
and that the chosen objectives support and align
with the entity’s mission and are consistent with its
Risk Assessment
risk appetite.
c-MiRM
Pillars of Risk Management (ISO 31001: 2018 & ISO 45001:2018)
Risk Evaluation
Control Activities
Relevant information is identified, captured,
Risk Response
Risk Response & Treatment
and communicated in a form and timeframe
Management selects risk responses
that enable people to carry out their
– avoiding, accepting, reducing, or
responsibilities. Effective communication
sharing risk – developing a set of
Recording and Reporting also occurs in a broader sense, flowing
actions to align risks with the entity’s down, across, and up the entity.
risk tolerances and risk appetite.
c-MiRM
Risk Management Maturity Focus Points
c-MiRM 12
Understanding Risk Appetite
How
hungry are
you for
Risk Appetite risk?
Risk Tolerance The ISO 31000 does not directly refer to risk
appetite but instead uses the terms “risk
attitude” and “risk criteria”:
c-MiRM
The components of Risk Appetite
Definition:
Risk appetite is the types, amount Risk capacity provides a threshold for the company to
ensure it remain viable.
and level of risk that a company or
individual is prepared to undertake
in pursuit of its objectives before
action is deemed necessary. Between risk capacity and risk appetite is a mitigation
GAP. Upper limits and lower limits used for standard
deviation from the target – produce KPIs
Important Factors One difficult aspect is to determine how big this GAP
• A level of risk-taking management between appetite and capacity should be.
deems acceptable The capacity of the GAP should account for every
• A conscious risk-based decision possible scenario set by extreme outcomes and errors
• Value of objectives in assumptions, analysis, and modelling
• Trigger point for risk response
This GAP is link to risk tolerance - what exposure a
company can actually cope and survive with.
c-MiRM
Benefits of Articulating Risk Appetite
A well-developed risk appetite statement and process can:
• Help a company better manage and understand its risk exposure
• Help management make informed risk-based decisions
• Help management allocate resources and understand risk and opportunities
• Help improve transparency for investors, stakeholders, regulators and credit rating agencies
Risk limit determines the thresholds (capacity) to monitor for the risk exposure or performance
deviating from the target (tolerance).
Exceeding a risk limit will typically act as a trigger for corrective action at the process level,
immediate notification at management level, and reporting at a governance level (Trigger
Action Response Plans).
Risk Strategy No Appetite for… KPIs Reporting & Limits
People Our employees contribute with a Capability performance falling outside following Employee satisfaction rating of 75%
sense of purpose and risk parameters: Total voluntary staff turnover of 8%
accomplishment: Deviations > 15% from staff satisfaction target Staff turnover of total employees with <12
• Attract and retain the skills and Short term period of staff turnover > 12% months service 18%
capability required to manage annualised monthly turnover 100% of identified key roles having an
risk exposure to meet strategic Cultural measures falling below previous year on approved succession plan
objectives year average IRM results
• Develop and maintain our Loss of incumbents of key roles without formal
Matt Mueller: EY Advisory
leadership succession plan in place
[Link] • Maintain a world class risk
culture
c-MiRM
ERM
Strategy - Horizontal approach (CADE3) Liq
gic
uid
ate
i ty
Str
Asset Capital Markets
How do we share and communicate Lifecycle Debt Financing
risk throughout the company?
g
rin
Pl a
l
M
a
nt
ee
ion
in
in
gi n
How do we measure efficiency of a
rat
g
En
e
multidimensional system?
Op
Network and Contract
Human
Infrastructure Management
Rights
Sa
t
f
He ety &
ial
en
k s
Ris orie
nc
So
Le
Scope Context, Criteria alt
on
a
g
ga
cia
h
Fin
te
vir
l
Ca
l
En
Risk Assessment
Dependency and supportive control monitoring regime
Risk Identification
Compliance Assurance Decisions
Communication and Consultation
Risk Evaluation
E 3 E 2
E 1
c-MiRM 16
Strategy - Vertical approach (PACED)
Risk Taxonomy
Risk Area - Level 3
Water Stress
Do we have a dynamic system for risk Biodiversity and Land Use
Human Rights
Carbon Emissions
embedded at all levels of the “cube”? 1,2 Market and Demand for Products Supply, Demand and Commodity Prices
Asset Portfolio
Capital Allocation
Align
Risk Identification Aligned with other
Communication and Consultation
business activities
Change management strategies
Comprehensive
Monitor and Review
Risk Analysis
Comprehensive, systematic
and structured
Risk Evaluation
Embedded
Embedded within
business processes
Dynamic
Dynamic, iterative and
Risk Response & Treatment responsive to change
c-MiRM 17
Internal & External Context (ISO 45001:2018)
The internal issues among which are: the Operational NGOs: which focus on development projects.
organizational structure, responsibilities and Rural Community Initiative
Consider what distribution, personal knowledge, middle Association of Round Tables in Southern Africa (ARTSA)
surrounds the management, technology, information flows,
organization and Centre for Conflict Resolution (CCR)
processes of decision making, etc.
evaluate how it may Advocacy NGOs: which are organized to promote particular
affect your OH&S causes.
Management External issues including: the cultural environment, Art for Humanity (AFH)
System market competition, new and old suppliers, new Lawyers for Human Rights (LHR)
technology, new legislation, etc.
Socio-Economic Rights Institute of South Africa (SERI)
c-MiRM
Internal & External Context
SocioGorganisa9onal!! !!!!!!!! !!!!!!!! External!!
Context! !!!!!Economic! !!!!!Safety!! Environment!
Environment! !!!!!!!legisla9on!
!!!!!!!!
!!!!!Organisa9onal!! !!!!!!!!!!!!!!&!!!
!!!!Structure!&!Systems! !!!!!!!!!!!!!!!regula9ons!
c-MiRM
External Environment
ECONOMIC)ENVIRONMENT)) )SAFETY)LEGISLATION)&)REGULATIONS))
) )
Unemployment)levels/)industry)job)crea@on)) Risk)Based)vs)prescrip@ve)
Levels)of)employee)indebtedness) Complexity)of)stakeholder) ))rela@onships)
Perceived/)real)wage)gaps) Over/)under)regula@on/)enforcement))
Family)Structures)(Dual/)distance)) Regulator)role)and)competence)in)execu@on)
Industry)GDP)contribu@on) (Statutory)consistency)and)clarity))
Stakeholder)expecta@ons)(shared)value))) Mechanism)for)development))and)review)of)
Transforma@on)&)ownership) legisla@on)
Illegal)mining/)theO)
External))
Environment)
DEMOGRAHIC)CONTEXT) INDUSTRY)STANDARDS))
) )
Social)diversity)(race,)gender,)genera@onal,) Industry)benchmark)for)H&S)performance))
language,)educa@on))) Management)and)focus)on)indicators)(leading)
Risk)Percep@on)and)tolerance) vs)lagging))
Ability)to)collaborate/)self)regulate))
Measurement)and)accepted)criteria)for)
performance)(local)vs)global))))
c-MiRM
Internal Environment
PERFORMS TASKS
c-MiRM
Drivers of Context
INFRASTRUCTURE RISKS
FINANCIAL RISKS
Communications
Accounting standards
Transport links
Interest rates
Supply chain
Foreign exchange
Terrorism
Funds and credit
Natural disasters
Internal control
Pandemic
Recruitment
Fraud
People skills
Historical liabilities
Health and safety
External Driven
External Driven
Investments
Premises
Capex decisions
Liquidity and cash flow IT systems
Internal Driven
Mergers and acquisitions activity Product extensions
Research & development Board composition
activities Control environment
Intellectual property
Contracts
Economic environment
Technology developments Product recall
Competition Public perception
Customer demand Regulator enforcement
Regulatory requirements Competitor behaviour
c-MiRM
Combined Assurance for Effective RM
Governing Body / Board / Audit Committee
Senior Management
External Audit
Internal
Management Risk Management Internal
Regulator
Control
Controls Quality Audit
Measures
Inspection
Compliance
Management Functions Assurance
c-MiRM