0% found this document useful (0 votes)
16 views60 pages

Risk Management and Organizational Strategy

Uploaded by

dafuqdam
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views60 pages

Risk Management and Organizational Strategy

Uploaded by

dafuqdam
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

D.

Risk
Relationship between organisational strategy and
risk management strategy
Nature of risk
• Risk in business is something that is not planned for and is unexpected.
• Financial woe, globalization and issues arising from physical, operational,
brand, reputation are examples of the negative effect of risk known as
‘downside risk’.
• In contrast, positive effect of risk do happen such as a sudden demand for
a product caused by an event happening.
• Since profits are in part the reward for successful risk-taking, certain risks
are simply not able to be prevented and companies should instead work
around them by adjusting operational and capital structure.
Risk management strategy
• Risk management strategy is related to organizational strategy in several
ways, namely:

– Organisational strategy concerns with adopting actions that will shape


the long-term direction of an organization thereby enhancing its
shareholders’ value.
– The ever changing environment and the internal organization means
that the risks organisation faces are continually changing causing the
desired objectives not able to be achieved.
– To overcome the said setback, risk management strategy which is a
process by which executive management, under board supervision,
identifies the risks arising from the business and establishes the
priorities for control and particular objectives needs to be
implemented across the whole organization.
Risk management strategy
• Risk management strategy is related to organizational strategy in several
ways, namely:

– Strategic options are selected against the backdrop of the risk appetite
of the organisation’s stakeholders notably the shareholders.
– Risk management provides an insight into the sensitivity of the
assumptions used in formulating an organization’s objectives thereby
leading to making better strategic decisions.
Framework for risk management and the
establishment of risk management system
The board’s role in risk management
• Set appropriate policies on managing the risk with regards to the following
factors:
– the nature and extent of the risks facing the company;
– the extent and categories of risk which it regards as acceptable for the
company to bear;
– the likelihood of the risks concerned materializing;
– the company’s ability to reduce the incidence and impact on the
business of risks that do materialize; and
– the costs of operating particular controls relative to the benefit
thereby obtained in managing the related risks. .
• Ensure that the system of internal control is effective in managing those
risks in the manner which it has approved.
The board’s role in risk management
• Monitor on a continuous basis the effective functioning of the risk
management system by:

– regularly receive and review reports on internal control; and


– undertake an annual assessment for the purpose of making public its
statement on internal control.
The management’s role in risk management
• Implement the board policies on risk and control.
• Identify and evaluate the risks faced by the company for consideration by
the board.
• Design, operate and monitor a suitable system of internal control which
implements the policies adopted by the board.
• Report to the board a balanced assessment of the significant risks and the
effectiveness of the system of internal control in managing those risks
including the impact that they have had, or may have, on the company
and the actions being taken to rectify them.
Risk Management Processes:

1) Identification of 2) Assessment of
Risks Risks

4) Communication of 3) Managing the


the Risks’ Status Risks

5) Monitoring the
Risks
Risks that arise from strategic decision making/
1) Identification of external environment and operations are being
Risks identified by the board and operating
management respectively.

2) Assessment of Risks identified are measured in term of their


Risks likelihood of occurrence and impact on the
organisation should they occur.

3) Managing the Depending on their significance, measures under


Risks the TARA framework are implemented to mitigate
or reduce the risks to an acceptable level.
The status of the risks are compiled and
4) Communication communicated by the Risk Manager to the
of the Risks’ Status Risk Management Committee who will in turn
highlight the most significant risks faced by the
company and the measures taken to rectify
them to the board.

5) Monitoring the Risks are monitored on a continuous basis to


Risks ensure that the company is able to respond to
them promptly.
Different categories of risks
Risk are categorized broadly based on their :

Severity Nature Sources


Severity

Strategic risks
• Risks that arise from an organisation’s positioning in the
environment and the fundamental decisions made by the directors
on its objectives.
• Have the effect of threatening the going concern of the company.
• Responsibility for managing these risks lies with the board.
Operational risks
• Risks that are connected with the internal resources, systems,
processes and employees of the organisation.
• Have the effect of causing temporary hiccups in the smooth running
of an organisation’s operations.
• Responsibility for managing these risk lies with the respective line
managers.
Nature

Operational risks
Risks that threaten the smooth running of an organisation which
can arise from breakdown of machineries, high staff turnover or
interruption in the supply of raw materials.
Financial risks
Risks that have the effect of threatening a company’s cashflow
such as adverse movement in foreign exchange rate, hike in
interest rate, default in payment from credit customers or
overtrading.
Compliance risks
Risks that the company failed to comply with internal policies and
procedures or external laws and regulations.
Sources

Risks are categorised based on where they originate from.


Should the risk relate to reputation damaged, it will be
termed reputation risk or research and development risk if it
relates to failure to invest in research and development.
Sources and impacts of common business risks
• Market
– Arises from any of the markets that a company operates in. Most
common examples are those risks from resource markets (inputs),
product markets (outputs) or capital markets (finance).

• Credit
– The risk of financial losses resulting from one of the parties to a
contract not performing on its contractual obligations.

• Liquidity
– Risks which arise from the way a business is financially structured, its
management of working capital and its management of short and
long-term debt financing.
Sources and impacts of common business risks
• Technological
– Technological risk concerns the potential losses and damage
incurred by the failure of any technology including the loss of
highly sensitive financial data in some financial systems.

• Legal
– Arises from the possibility that an entity may not be able to
enforce a contract against another party.

• Environmental
– Unrealised loss or liability arising from the effects on an
organisation from the natural environment or the actions of that
organisation upon the natural environment such as the effects of
climate change, adverse weather, resource depletion, and threats
to water or energy supplies
Sources and impacts of common business risks
• Reputation
– A threat or danger to the good name or standing of a business or
entity as a result of the actions of the company itself; its employee
or through other peripheral parties, such as joint venture partners
or suppliers.

• Business probity
– Risk related to the governance and ethics of the organization
arising from unethical behaviour by one or more participants in a
particular process.

• Derivatives
– Risks arising from the use of financial instruments involving assets
such as stocks, bonds, commodities, currencies, interest rates and
market indexes whose value has fluctuated.
Risk appetite and their effect on the risk policy
Risk appetite
• Defined as the amount of risk, on a broad level, that an organisation is
willing to take in pursuit of value.

• Vary from organisation to organisation depending on circumstances


unique to each such as the external environment, people, business
systems and policies.
• The two notional preferences usually taken by organisations are risk
aversion and risk seeking which are associated with different levels of
returns.
• Risk seeker favours higher risks and higher returns while risk-averse
entities tend to be cautious about accepting risk, preferring to avoid
risk, to share it or to reduce it even though the level of return will be
lower accordingly.
Dynamic nature of risk and its variability by sector
Dynamic nature of risk
• Changes in the environment such as PEST (political, economic, social,
and technological) or any industry level change such as a change in the
competitive behaviour of suppliers, buyers or competitors will render
new risks to be introduced, existing ones to become more likely or
have a higher impact, or the opposite may occur.
• Given the dynamic nature of risk, the risk management process must
be ongoing and the initial risk assessment results being periodically
updated.
• Helps management to quickly recognize potential adverse events, be
more proactive and forward-looking, and establish appropriate risk
responses, thereby reducing surprises and the costs or losses
associated with business disruptions.
• The more real-time and forward looking the analysis of potential risks,
the more controllable the achievement of objectives becomes.
Variability of risk
• Business risks vary by sector because of the different environments,
and the business models, strategies and financial structures adopted
by companies in different industries.

• Environment
– Industries that are mainly located within a certain geographical do
not face exchange rate risk unlike others that are international.
– Some businesses exist in relatively simple and stable environments
whilst others are in more turbulent and changeable environments
characterised by greater levels of regulation, changing consumer
patterns and higher technology.
Variability of risk
• Business models
– A manufacturing company will have risks associated with inventory
management which a service industry will not be exposed to.
Conversely, a company in a service industry such as insurance or
banking is more likely to be exposed to certain technical skill
shortages and fraud risks.

• Strategies and financial structures


– Different financial structures give rise to different costs of capital
and exposure to such external factors as monetary pressure.
– Companies with high operational gearing, such as those having
very high fixed costs compared to variable costs, have more volatile
returns simply because of the structure of their cost base.
Assessment of the severity and probability of risk
events
Risk assessment
• The objectives are to separate the minor acceptable risks from the
major risks and to provide data to assist in the evaluation and
treatment of risks.

• Risk assessment involves consideration of the sources of risk, their


consequences and the likelihood that those consequences may occur
in the context of existing control measures.

• Consequences and likelihood determined using statistical analysis and


calculations are combined to produce a level of risk.
Risk assessment
• To avoid subjective biasness, the best available information sources
and techniques should be used when analyzing consequences and
likelihood. Sources of information may include the following:
– past records
– relevant experience
– industry practice and experience
– relevant published literature
– test marketing and market research
– experiments and prototypes
– economic, engineering or other models
– specialist and expert judgment.
Risk assessment
• To avoid subjective biasness, the best available information sources
and techniques should be used when analyzing consequences and
likelihood. Techniques that may be used include:
– structured interviews with experts in the area of interest
– use of multi-disciplinary groups of experts
– individual evaluations using questionnaires
– use of computer and other modeling
Types of Analysis

1) Qualitative

Word form or descriptive scales are used to describe the


magnitude of potential consequences and the likelihood that
those consequences will occur.

Example: Consequences – insignificant, moderate, catastrophic


Likelihood – almost certain, likely, rare
LEVEL DESCRIPTOR EXAMPLE OF DETAIL DESCRIPTION

1 Insignificant No injuries, low financial loss

2 Minor First aid treatment, on-site release of toxic immediately


contained, medium financial loss

3 Moderate Medical treatment required, on-site release of toxic


contained with outside assistance, high financial loss

4 Major Extensive injuries, loss of production capability, off-site


release of toxic with no detrimental effects, major financial
loss

5 Catastrophic Death, toxic release off-site with detrimental effect, huge


financial loss

Qualitative measures of consequence or impact


LEVEL DESCRIPTOR EXAMPLE OF DETAIL DESCRIPTION

1 Almost certain It is being expected to occur in most circumstances

2 Likely Will probably occur in most circumstances

3 Possible Might occur at some time

4 Unlikely Could occur at some time

5 Rare May occur only in exceptional circumstances

Qualitative measures of likelihood


Types of Analysis

2) Semi-quantitative

Qualitative scales such as those described are given values.


However, they do not have to bear an accurate relationship to
the actual magnitude of consequences or likelihood

3) Quantitative

Numerical values rather than the descriptive scales are used for
both consequences and likelihood using data from a variety of
sources
The use of ALARP principles in risk assessment
ALARP principle
• It is financially and operationally impracticable to completely eliminate
all the risks, and so we must live with the ever-present possibility that
they can happen.

• The management of risk should never be confused with the refusal or


the inability to actually take a risk as enterprise which sets out to
deliver profits and returns to shareholders can only do so by risk-
taking.

• Directors should therefore observe the clear distinction between


managing and avoiding so as to avoid managing risk out of the
business.

• As such, the adverse impact of risks should only be made as low as


reasonably practicable (ALARP), irrespective of any absolute criteria
because we can never say that a risk has a zero value.
The concepts of related and correlated risk
factors
Related and correlated risks
• Corporations need to develop a holistic approach to risk management
by identifying and managing critical risk interdependencies.
Companies that suffer the greatest losses do so because of exposure
to more than one type of risk.

• Unforeseen interdependence of risk can turn a small event into a


company or industry-wide threat.

• Related risks are those that often present at the same time in the
same organisation because they have a common cause or that one
type of risk can give rise to another.

• Correlated risks are those that vary together which can be negatively
correlated (one goes up as the other declines) or positively correlated
(both go up or down together).
The role of a risk Manager
Risk Manager
• Primarily he/she is responsible for developing and implementing an
enterprise-wide strategy as agreed by the board, which encompasses
all aspects of organizational risk.

• Work closely with the CEO, the board and its sub-committees to
achieve an enterprise-wide perspective of risk and their associated
controls, looking across all business units to anticipate all the risks
that threaten the organization.

• Provide overall leadership, vision and direction for risk and assurance
activity by promoting a truly enterprise-wide appreciation of risk
across all operations and functions.

• Liaise with other corporate functions to facilitate an improvement in


the quality of discussion on risk and assurance issues at the senior
corporate level.
Risk Manager
• In certain specific industries such as bank, oil and mining, risk
manager plays the role of ensuring compliance with relevant codes,
regulations, statutes, etc.

• To sort, standardize and merge the substantial amount of risk


management information gathered from the risk management
process into a risk register so as to provide the stakeholders with a
clear view of the current status of each risk, at any point in time.
The use of risk register and heat maps to identify
and monitor risk
Risk register
• A tool that plays an important part in risk management plan by
helping organisations to track issues and address problems as they
arise.

• The risk register addresses risk management in four key steps:


– identifying the risk
– evaluating the severity of any identified risks
– applying possible solutions to those risks
– monitoring and analysing the effectiveness of any subsequent
steps taken.

• The information in the register are shared between stakeholders to


keep them informed of issues and providing a means of tracking the
response to issues.
Heat map
• A way of representing the resulting qualitative and quantitative
evaluations of the probability of risk occurrence and the impact on
the organisation in the event that a particular risk is experienced.

• The development of an effective heat map requires several critical


elements:
– a common understanding of the risk appetite of the company
– the level of impact that would be material to the company
– a common language for assigning probabilities and potential
impacts.

• Risks are mapped on a heat map on a ‘residual risk’ basis that


considers the extent to which risks are mitigated or reduced by
internal controls or other risk response strategies.
Heat map
• A visual, big picture, holistic view to share while making strategic
decisions
The concept of embedding risk in an
organisation’s culture and value
Embedding risk management
• Risk awareness is the knowledge of the nature, hazards and
probabilities of risk in given situations. To reduce the costs of risk to
an organisation and its members (which might be measured in
financial or non-financial terms), it is important to embed awareness
at all levels.

• To embed means introducing a taken-for-grantedness of risk


awareness into the culture of an organisation and its internal
systems.

• In such organisational cultures, risk management is unquestioned,


taken for granted, built into the corporate mission and culture and
may be used as part of the reward system.
Embedding risk management
• The methods by which risk awareness and management can be
embedded in organisations include:

– Risk management training by the risk manager for all the levels of
staff
– Alignment of reward system with risk responsibilities
– Establishment of metrics and performance indicators to monitor
and feedback of information on risks to management. This would
ensure that accurate information is always available to the risk
committee and/or board.
The importance of risk transfer, avoidance,
reduction and acceptance (TARA)
TARA Framework:

Transfer the Risk

Avoid the Risk

Reduce the Risk

Accept the Risk


Avoid the risk
• Risk is avoided by not proceeding with the activity likely to
generate the risk.
• Applicable for risks that have high chances of occurrence and the
impacts are significant.
• Risk may also be inappropriately avoided because of an attitude of
risk aversion

Accept the risk

• Risk is accepted if both the chances of its occurrence and the


impact are insignificant.
• Risk can also be retained by default, when there is a failure to
identify and/or appropriately transfer otherwise treat risk.
Reduce the risk
• Risk can be reduced via the reduction in the likelihood of
occurrence or the impact.
• Measures taken include preventative maintenance, contract
conditions, supervision etc. depending on the circumstances.

Transfer the risk (also know as


sharing of risk)
• Risk is transferred if the impact is regarded as too significant
beyond the company’s ability to tolerate.
• Mechanisms include insurance arrangement, organisational
structures such as partnership and joint ventures, outsourcing.
• The organisation to which the risk has been transferred, may not
manage the risk effectively.
The concept of assurance mapping using the
‘four lines of defence’
Four lines of defence model

• Provides a simple and effective way to communicate risk


management and control by clarifying essential roles and duties
thereby improving the effectiveness of risk management systems.
Four lines of defence model
• More efficient and effective to build more controls at the earlier lines
of defence because there is likely to be:

➢ less mistakes, with closer to real-time monitoring;


➢ easier rectification of any mistakes, as they should be detected
more promptly;
➢ lower costs of compliance and internal auditors; and
➢ better information for external assurers.
Four lines of defence model
First line of defence

• Management establishes structures to manage risks which include


the top level policies of the organisation, control frameworks and
controls and management supervisory processes.

• Nevertheless, they are operated by staff and therefore the assurance


offered is not objective.

Second line of defence

• Comprises of control risk self-assessment, risk and compliance


reviews and board supervisory processes.

• These exercises are operated or overseen by specialists who are more


separate from line management, which increases the level of
confidence in the assurance.
Four lines of defence model
Third line of defence

• Only comprises the internal auditors.

• Most separate internal line of defence from line management, which


further increases the level of confidence in the assurance.

Fourth line of defence

• Comprises external assurers, the most significant of which is often


the external auditor who provides assessment of internal controls in
the first three lines of defence.

• Independent of the organisation itself, and having to comply with the


Code of Ethics. Accordingly, the level of assurance is the highest.
Assurance mapping

• A structured means of identifying and mapping the main sources and


types of assurance in an organisation across the four lines of defence.

• Provides decision-makers (boards, senior management and audit


committees) great insights and comfort from the assurance provided.
Assurance mapping
• An assurance map shows:
➢ the key elements over which assurance is required which can vary
depending on the type and size of organisation.
➢ the 'four lines of defence’ with details of what had been provided.
➢ any gaps where no assurance is provided.

• The benefits of assurance mapping:


➢ enable the board to make more reliable and robust reports to its
stakeholders about the organisation’s state of internal control.
➢ the well-structured analysis or assurance enable audit and risk
committee to evidence their satisfaction with the current state of
internal control and to focus on those specific areas that remain a
concern.
➢ the assurance-related work of the individuals operating within
the four lines of defence can be best directed with the map to
avoid overlaps.
Assurance mapping
• Maintenance and reassessment:
➢ An assurance map is a live document that should be constantly
reassessed and updated to reflect new or changed elements,
assurance providers or assurance activities.
➢ The desired or required amounts of assurance may also change
for a variety of reasons, which would also lead to a new
assessment of the map and updated action plan.
➢ Failure to embed the maintenance process in the organisation will
waste much of the effort committed in creating the map for the
first time.

You might also like