0% found this document useful (0 votes)
41 views5 pages

Corporate Governance and Risk Management

Chapter 2 discusses the evolution and importance of governance in corporate decision-making, emphasizing the roles of various stakeholders and the significance of risk management frameworks. It highlights key reports and principles that have shaped governance practices, the responsibilities of individuals like the Chief Risk Officer, and the processes involved in effective risk governance. The chapter concludes by noting the ongoing evolution of risk management in financial services and the necessity for clearer risk appetite integration within organizations.

Uploaded by

annie.waingankar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
41 views5 pages

Corporate Governance and Risk Management

Chapter 2 discusses the evolution and importance of governance in corporate decision-making, emphasizing the roles of various stakeholders and the significance of risk management frameworks. It highlights key reports and principles that have shaped governance practices, the responsibilities of individuals like the Chief Risk Officer, and the processes involved in effective risk governance. The chapter concludes by noting the ongoing evolution of risk management in financial services and the necessity for clearer risk appetite integration within organizations.

Uploaded by

annie.waingankar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Here's a detailed summary of Chapter 2:

**1. Governing and Governance**


Governance is defined as **the structure that specifies policies, principles, and procedures
for making decisions about corporate direc on** [2]. It distributes rights and responsibili es
among stakeholders like the board, management, employees, shareholders, and regulators
[2].
* **Ship Analogy**: The chapter uses the analogy of steering a ship to explain governance,
where se ng the des na on is key, and governance ensures the ship safely reaches it. This
includes detailed planning, course adjustments, and emergency procedures [3]. The term
"cyberne cs," coined by Norbert Wiener, originates from the Greek word for "steer" or
"navigate," further linking it to governance [4].
* **Origins of Formal Corporate Governance**: Increased a en on to organiza onal
governance in the UK and USA from the 1990s led to various reports, o en in response to
perceived failures. Notable reports include the 1992 Cadbury Report, 1995 Greenbury
Report, 1998 Hampel Report, 1999 Turnbull Report, 2001 Myners Report, 2003 Higgs Report,
and 2009 Walker Review [5, 6].
* **Turnbull Report (1999)**: This report was significant as it was the first to **require a
board to consider risks and control systems for risks**, sta ng that policies should account
for risks, risk appe te, controllability, and cost/benefit of controls [6]. It outlined that
directors must iden fy and assess significant risks, management must review internal
controls annually, and risk management is the collec ve responsibility of the whole board [7,
8].
* **OECD Principles (1999, revised 2004)**: The Organiza on for Economic Co-opera on
and Development (OECD) endorsed principles of corporate governance, emphasizing the
board's key func ons such as reviewing strategy, risk policy, and ensuring the integrity of
financial repor ng and control systems, especially for monitoring risk and compliance [9,
10]. The six core principles include ensuring an effec ve framework, protec ng shareholder
rights, equitable treatment of shareholders, recognizing stakeholder roles, disclosure and
transparency, and board responsibili es for strategic guidance and management monitoring
[11, 12].
* **Legisla on and Standards**: Governance requirements have increasingly been
incorporated into legisla on, par cularly for financial firms, such as the **Sarbanes-Oxley
Act of 2002** and the **Dodd-Frank Wall Street Reform and Consumer Protec on Act of
2010**, both enacted in response to financial scandals and crises [13]. Voluntary auditable
standards like ISO 31000 (interna onal risk management standard) also contain strong
elements of risk governance [14].
* **Risk of Non-Compliance**: This is an important category of risk, o en classified as an
opera onal risk within most risk-governance frameworks [15].
* **Risk Governance & Strategic Planning**: Risk governance is a structure for decision-
making about managing corporate risks, categorized as reac ve (keeping on course) and
preventa ve (avoiding problems ahead) [16]. The manual limits risk governance to these
two structures, although "ac ve governance" could extend to improving results [17].
Con nuous improvement approaches like Six Sigma are increasingly used in financial
opera ons to reduce defects and opera onal risk, such as reducing trade failure rates [18].
* **Risk Governance Principles**: No single universal standard exists for risk management,
leading firms to create their own frameworks [19].
* **PRMIA's 10 Principles of Good Governance**: Key competencies, resources and
processes, ongoing educa on and development, compensa on architecture, independence
of key par es, risk appe te, external valida on, clear accountability, disclosure and
transparency, and trust, honesty, and fairness of key people [20].
* **ACCA’s Corporate Governance and Risk Management Principles**: Boards, shareholders,
and stakeholders share a common understanding; boards lead by example, empower
execu ve management, ensure strategy considers risk/reward, are balanced; execu ve
remunera on is transparent; risk management is objec vely challenged; boards account to
stakeholders; and corporate governance evolves [21].
* **ICAEW's Five Overarching Principles**: Leadership, capability, accountability,
sustainability, and integrity [22].
While these principles share commonali es, their boundaries and emphases differ, and they
o en appear to be reac ve rather than grounded in a strong theore cal framework [23, 24].

**2. People**
This sec on focuses on the roles of individuals in suppor ng risk governance [25].
* **Board**: The board holds full responsibility for risk, confirming strategic risks, ensuring
effec ve management and control, deciding on appropriate controls, reviewing the CRO's
annual report, and ensuring outcomes from risk management inform audit plans [26, 27].
With increased criminaliza on of corporate malfeasance, boards are highly sensi ve to their
responsibili es [27].
* **Chief Risk Officer (CRO)**: The CRO is a pivotal role, o en placed on the board, and
should par cipate in enterprise-wide risk management and oversight [27].
* **Repor ng Lines**: The CRO should report to the board risk commi ee, with direct
access to the chairman, especially if there's a difference of view with the CEO or CFO. Their
status and remunera on should reflect the importance of the role, and removal from office
requires board agreement [28].
* **Responsibili es**: Key responsibili es include providing a risk strategy, informing the
board of cri cal and emerging risks, establishing risk analysis and repor ng, ensuring
compliance, business con nuity, cross-organiza onal links on risk issues, and embedding a
firm-wide culture of risk awareness [29]. The CRO's span of control can include compliance,
financial risk, opera onal risk, data integrity, internal audit, reputa onal risk, insurance,
actuary, legal, and IT/physical security [30, 31].
* **Boundaries**: Principal discussions on boundaries occur with the CFO (who has
separate control and statutory repor ng func ons), the head of internal audit (who needs
independence and separate repor ng to the audit commi ee), and the chief counsel and
head of compliance [32].
* **Wider Repor ng**: The risk management framework must link with strategic planning,
budge ng, audits, health and safety, ethics, and legal requirements [33]. CROs typically
manage some risk func ons directly and coordinate others through commi ees, o en
responsible for Enterprise Risk Management (ERM) [33]. They also deal with regulators and
other external stakeholders [34].
* **The Risk Func on**: Under the CRO and board's sponsorship, the risk func on
documents its ac vi es, typically via a risk management manual and policies. Its
responsibili es include: se ng basic stages in risk management, owning risk categoriza on
and taxonomy, outlining assessment methodologies, maintaining a risk register,
recommending risk appe te, communica ng policies, advising/challenging management,
reviewing mi ga on ini a ves, monitoring risks, and preparing annual reports [35-38].

**3. Process**
This sec on considers how risk governance processes should work effec vely [39].
* **Theory**: Stafford Beer’s **Viable System Model (VSM)**, from organiza onal
cyberne cs, proposes seven fundamental elements for an organiza onal system to be
viable: input, process, output (implementa on elements), feedforward, feedback
(intelligence elements), and monitoring and governance (management elements) [40, 41].
* **Risk vs. Uncertainty**: The chapter discusses the dis nc on between "frequen st"
(history predicts future probability) and "Bayesian" (combines subjec ve and historic data)
views of risk [42, 43]. It also differen ates between **risk** (known likelihood from
sufficient data) and **Knigh an uncertainty** (known poten al events but unable to
evaluate likelihood) [44]. However, it notes that pure uncertainty is rare, as people tend to
assign probabili es once aware of an event [45].
* **Defini on of Risk Management**: The chapter offers a simplis c defini on: "the
applica on of risk analysis to financial, strategic, systems, human, and organiza onal
problems to improve performance" [46].
* **Risk Management Process**: It explores six elements before focusing on governance:
1. **Input**: Awareness of poten al risks ("perceived" vs. "actual"). The quality of
informa on is crucial, as market condi ons are o en unique, and past data may not be
directly applicable [47, 48]. Risks are categorized by severity and likelihood (e.g., low
severity/high likelihood like computer failures, high severity/low likelihood like terrorist
a acks, high severity/high likelihood like new technology by compe tors, and low
severity/low likelihood which might be ignored) [49-51].
2. **Process**: A er iden fica on, four generic ac ons exist: accept, mi gate, transfer, or
eliminate the risk [52].
3. **Output**: Objec ves should be SMART (Specific, Measurable, Achievable, Realis c, and
with a specified Timescale) and communicated throughout the organiza on to ensure buy-in
[53].
4. **Feedforward**: Forward-looking processes aimed at predic ng risk and mi ga on
ac vi es, such as budge ng and assessing risks for new businesses [54].
5. **Feedback**: Regular assessment of outputs (economy, efficiency, effec veness) [55].
Risk professionals play an important challenge role in both feedforward and feedback [55].
6. **Monitoring**: The risk func on monitors exposure against risk and mi ga on
strategies, outlining repor ng obliga ons and transparency. It needs to make its value
proposi on clear [56, 57].
7. **Governance**: Considers numerous outside factors (e.g., Porter's five forces, PEST
analysis) [58]. Risk management should be involved in cra ing decisions, both flowing down
from strategy and escala ng problems up [58].

**4. Result**
This sec on applies strategic ques ons to risk governance and discusses measuring
effec veness [59].
* **Strategic Ques ons**: Risk governance applies the same five strategic ques ons as
general management: Where were we? How did we get here? Where are we now? Where
are we going? How are we going to get there? [59].
* **Purpose of Risk Management**: To set direc on, gain commitment, keep control, and
resolve uncertainty [60].
* **Measuring Effec veness**: The most objec ve way is to monitor against external
norms, benchmarks, or quality standards [61]. Measures can be absolute, condi onal, or
expected outcomes [61].
* **Unrealis c Measurement**: Predic ve measures are contrived when applied to process
or audience, focusing solely on success or output. "Success measures" suffer from the
complexity of determining "what degree of success should have been achieved" [62].
* **Complex Measurement**: "Standard-based measures" are limited by standard selec on
(e.g., regulatory audits). "Compara ve measures" are limited by informa on gathering and
analysis challenges among comparable organiza ons [63, 64].
* **Feasible Measurement**: **Audience sa sfac on** with the risk func on's fulfillment
of its purpose is the most feasible [65]. This depends on their percep on of best prac ce,
comparators, and the linkage of strategic planning to overall success [65].

**5. Horizons of Risk Governance**


This sec on looks at future enhancements in risk governance [66].
* **Learning from Other Industries**: Financial ins tu ons can learn from industrial and
government sectors about longer-term thinking in strategic and business risk management.
Banks o en have a shorter investment horizon (1-3 years) despite long-term products [67].
Opera onal risk is in mately related to quality of execu on and outcomes [68]. Industries
like mobile telephony or airlines use higher Sigma confidence levels than financial services,
indica ng a need for fundamental change [69]. Measuring variance in costs and quality is a
key metric in leading industrial organiza ons, correla ng high-risk processes with high cost
variances and low quality outputs [70].
* **Specialist Risk Roles**: Risk management involves a clash of op mists, pessimists, and
probabili es [71]. Different func ons (e.g., human resources, legal) may operate under
different paradigms (regulatory/rules vs. probabilis c), crea ng tensions [72].
* **Confidence Accoun ng**: This approach aims to unite risk and finance by using
**ranges rather than discrete numbers for major accoun ng entries**, providing a fairer
representa on of financial results and addressing uncertainty [73, 74].
* **The Human Factor in Risk**: Individual personality and cultural affini es are increasingly
important. Research is exploring how psychological and ins tu onal factors influence
regulatory decision-makers [75, 76]. Understanding human ins ncts (tribalism, herding, fear,
greed, trust, turf, ownership, anchoring) is crucial for understanding the risk profile in
financial ins tu ons [76].
* **Risk Data and Analy cs**: Risk management is a heavy user of data, aiming to iden fy
pa erns and trends for a predic ve view of risk [77]. Automated systems can flag anomalies,
and autonomous decisions based on historic data are becoming more common [78]. The
financial ins tu on of the future will likely automate compliance tasks for a compe ve
edge [79].

**Summary of Chapter 2**


The chapter concludes that financial services regula on and governance structures have
become more prescrip ve, but risk management is s ll evolving [80]. It emphasizes the need
for clearer risk appe te and its embedding throughout the firm in decisions, monitoring, and
escala on, acknowledging that perfect risk management is not achievable [80].

You might also like