1
Chapter 17
Managing Risk
Chamantha Ubewarna
MBA – University of West London (UK), ACIM (UK), BBA - Edith Cowan
University (AUS)
• Explain how and why organisational risk is subjective and
Learning subject to change
• Discuss strategies for engaging with risk, and where this is
Objectives linked to a real-life example, providing recommendations
• Explain the relationship between ethics, risk, and reputation
in the context of business management
❖ In business, risk means that a company’s or an
organization’s plans may not turn out as originally
planned or that it may not meet its target or achieve its
goals.
❖ Risk management attempts to balance threats and
opportunities that organisations face:
• Threats are the risks that an organisation will not prosper
and survive in the long term
Risk • Opportunities need to be exploited in order to remain
competitive. The risks of missed opportunities need to be
taken seriously.
Management ❖ The International Standards Organisation (ISO, 31000)
links Risk Management with ability to thrive:
• Organizations that manage risks effectively are more likely
to protect themselves and succeed in growing their
business.
❖ Risk management processes can be conceptualised to
include context, risk identification, assessment and risk
treatment
❖ Risk management relates to reducing negative
events and grasping opportunities to enable the company
to thrive in the long-term.
Why worry ❖ In relation to start-up companies, Eisenmann (HBR, May-June
2021) suggests that two-thirds never deliver positive returns to
investors and that these failures also take a toll on the economy
about Risk and society.
Management in ❖ These figures illustrate how frequently organisations fail,
and risk management aims to reduce the likelihood of business
closure.
Organisations? ❖ Data from National Center on Charitable Statistics reveals that
approximately 30% of non-profits fail to exist after 10 years, so
this problem is not confined to profit making organisations.
Many charities and government organisations have also adopted
business risk management approaches.
❖ Risk identification requires:
❖ intimate knowledge of the organisation
❖ understanding of the market in which it operates
PESTEL ❖ the legal, social, political and cultural
analysis environment
❖ an understanding of strategic and operational
objectives
❖ This usually focusses on threat reduction, because
opportunities will be managed within strategic
activities. (Whilst the risk of not seizing an
opportunity is important from the perspective of
fully understanding risk, risk practices in
companies tend to focus on negative aspects of
risk, i.e., the threats).
Assessing Risk ❖ Traditionally risks are assessed as a multiple of
severity and likelihood
❖ Scales are typically 1 to 5 (with 1 being low and 5
being high)
❖ Some organisations use words (low, medium, high)
instead of numbers
Scoring
grid of Risk
This approach enables organisations to focus
action on those activities expected to
deliver the most value to the organisation.
❖ Risk Assessment: Data and the type of risk
❖ Risk assessment requires the ability to analyse threats and
How to Assess
opportunities to see how likely or severe they may be. There is often
a trade-off here, severe storms happen less often, for example.
Risk ❖ In the business context, interest rate rises of more than 10% have
been extremely rare, but 3% is more likely to occur.
❖ The nature of business risk prevents easy calculation of known
probabilities, so much of the analysis relies on estimation by
managers (which may be affected by biases).
❖ Some types of risk can make use of historical
data to enable quantitative analysis:
Risk • Health & Safety assessments may make
use of accident data
Assessment: • Actuarial assessments; insurance
Data and the premiums calculated using historical data
Financial measures e.g. Internal Rate of
type of risk
•
Return (IRR), Value at Risk (VAR)
• Statistical analysis requires knowledge of
the data distribution to be valid
❖ Insert diagram normal distribution
❖ For other types of risk there is a lack of statistical data to analyse,
so the manager's opinion and interpretation are even more
important:
Reputation: Secondary risk linked to other risk sources (a
How to Assess
❖
secondary risk, since the primary risk was the cost of replacing
the devices with compliant ones, but damage to reputation was of
Risk ❖
greater concern)
Personnel change: New management approaches can be
identified as a threat to some parts of the organisation or to
particular products and services
Risk Appetite: Which threats to focus on?
❖ Scoring risks enables managers to select those that
are assessed as posing a significant threat in terms
of the combination of likelihood and severity.
❖ To enable managers to treat the identified risks using
Managing Risk 'management by exception' (Drury, 2013) the
organisation can decide on its 'risk appetite’.
❖ What magnitude of risks are they prepared to accept,
and which are they very keen to avoid? What is the
tolerable risk score for impact x likelihood?
Risk Appetite
❖ The diagram shows how risk appetite can be set in
relation to how likely it is or the scale of the impact the
potential risk may have.
❖ This can be set at different levels for example, in
relation to financial risks and Health & Safety (H&S)
Risk Appetite risks.
❖ The firm and its managers may be willing to speculate
on a potential high gains investments, but very
unwilling to risk the death of any employees or
customers.
HSBC bank outlines this concern about reputational risk
in their 2016 annual report:
Reputation and ❖ Reputational risk is the risk of failure to meet
stakeholder expectations as a result of any event,
risk: social behaviour, action or inaction, either by HSBC itself, our
employees or those with whom we are associated,
responsibility that might cause stakeholders to form a negative view
of the Group.
❖ This may have financial or non-financial effects,
resulting in a loss of confidence or have other
consequences.
❖ When making business decisions, profit is usually evaluated.
In the case of not-for-profit organisations, it may be a case of
evaluating 'Value-for-Money' and improvements to
performance.
Ethical decision ❖ But, is this enough? As a minimum, business managers need
to think about:
making ❖ Consequences of the decision:
▪ Is it profitable? A key factor in analysis of future
investments – but can only be fully assessed by looking
at more than the financial data. This is often where
decision making has stopped in the past.
▪ Does it align with corporate values?
❖ Impact on rights
• Legal: All assessments need to consider whether the
decision is legal, and whether higher standards will be
applied in areas that do not have, for example, strong
consumer rights legislation.
Fair: does the decision treat stakeholders fairly. Link
Ethical decision •
to fair operating practices, for example, are customers
being charged more than they should for services and
making are labour practices delivering equal pay and
encouraging diversity
❖ However, an ethical decision framework suggests
decision makers also need to employ 'sniff tests’.
❖ Sniff tests are informal reality checks of an idea (in this
case, perhaps a project) which uses common sense.
The framework suggests we should think about a wider
range of inputs, for example:
a. Has anything important been overlooked? Have we
forgotten to think about the impact on the community
around the planned warehouse development?
Sniff test b. Is information available to support the decision? Take
the outside view could be useful here – what
information should be available – have legal issues
been considered?
c. Is there evidence that stakeholders have been
considered? Have we focussed too much on
shareholder interests?