0% found this document useful (0 votes)
23 views95 pages

Risk Management Process Mastery Guide

The document outlines a comprehensive framework for mastering the risk management process, detailing foundational concepts, the Enterprise Risk Management (ERM) framework, and the risk management process itself. It emphasizes the importance of recognizing risks not just as negatives but as potential opportunities for growth and improvement, particularly in organizational settings like healthcare. Additionally, it classifies risks into pure and speculative types and categorizes them into various domains, providing strategies for effectively managing and exploiting risks.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
23 views95 pages

Risk Management Process Mastery Guide

The document outlines a comprehensive framework for mastering the risk management process, detailing foundational concepts, the Enterprise Risk Management (ERM) framework, and the risk management process itself. It emphasizes the importance of recognizing risks not just as negatives but as potential opportunities for growth and improvement, particularly in organizational settings like healthcare. Additionally, it classifies risks into pure and speculative types and categorizes them into various domains, providing strategies for effectively managing and exploiting risks.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

2025

Mastering the Risk


Management Process
DR. GHADA SHARAF EL-DEEN
Contents

Module 1: Foundations of Risk

• What is Risk? (Definition, Types, The Difference between Risk and Opportunity).
• Risk Categories / Areas
• The Importance of Risk Management in the Modern Era. (Why do we need Risk
Management?)
• Risk Management and Strategy

Module 2: The ERM Framework

• The General Framework for Enterprise Risk Management (ERM)


o Concept of Enterprise Risk Management (ERM)
o The Difference between Traditional Risk Management and Enterprise Risk
Management (ERM vs TRM)
o Roles and Responsibilities of Risk Managers in the Organization
o Risk Management Frameworks

Module 3: Risk Management Process

• Identify and analyze loss exposures.


• Examine risk treatment techniques or methods.
• Select the best risk treatment technique/method or combination of
techniques/methods.
• Implement the selected treatment techniques/methods.
• Monitor, evaluate, and improve the risk management program to identify and analyze
loss exposures.
• Risk Appetite and Strategy

Module 4: Risk Governance and Culture

• Risk Management Governance Structure.


• The Three Lines of Defense Model
• Risk Culture

Module 5: Advanced concepts

• Success Factors for the Enterprise Risk Management Program Framework


• Risk Quantification

Page 1 of 94
Module 1: Foundations of Risk

• What is Risk? (Definition, Types, The Difference between Risk and Opportunity).
• Risk Categories / Areas
• The Importance of Risk Management in the Modern Era. (Why do we need Risk
Management?)
• Risk Management and Strategy

What is Risk? (Definition, Types, The Difference between Risk and Opportunity).

Definition of Risk:

• Risk: The most globally accepted definition, especially in the field of management and
organizations, comes from the International Organization for Standardization (ISO) in
its standard (ISO 31000): The effect of uncertainty on objectives.
• Effect: Is a deviation from the expected.
o It can be positive, which is known as an "Opportunity" (achieving higher than
expected profit, finishing a project ahead of schedule).
o Or negative (financial loss, project delay, accident occurrence).
o Or both.
o It can address, create, or result in opportunities and threats.
• Uncertainty: Is the state of lacking complete information or understanding about an
event, its consequences, and its likelihood. If you are 100% sure something bad will
happen, it is not a risk; it is a "certainty" or a "current problem." Risk lies in the
lack of certainty.
• Objectives: Are the results you seek to achieve. These objectives can be at different
levels:
o Strategic: Such as increasing the organization's market share.
o Financial: Such as achieving a certain profit margin.
o Operational: Such as delivering a project on time.
o Personal: Such as safely reaching a destination.
• Risk Management: Coordinated activities to direct and control an organization with
regard to risk.

Illustrative Example

Suppose your objective is to "reach an important meeting in another city by car within two
hours."

• State of Uncertainty: There might be a traffic jam, the car might break down, or all
roads might be clear. You do not know for certain what will happen.

1. Risks (Negative Effect):


o Being late for the meeting due to congestion.
o Missing the entire meeting due to a car breakdown.
2. Opportunities (Positive Effect):
o Arriving early and having time for good preparation because there is no traffic.

Page 2 of 94
Therefore, risk management is not just about avoiding bad things; it is a structured process for
understanding and managing "uncertainty" in order to protect your objectives and increase
your chances of success.

Risk vs. Opportunity: A Comparative View


Feature Risk (Negative Effect) Opportunity (Positive Effect)
Potential for harm, loss, or Potential for gain, growth, or desirable
Nature
undesirable outcomes. outcomes.
Often associated with fear, Often associated with hope, potential,
Perception
avoidance, and uncertainty. and growth.
Impact on Hinders achievement of objectives, Facilitates achievement of objectives,
Goals causes setbacks. creates new possibilities.
Mitigation, avoidance, transfer, Enhancement, exploitation, sharing,
Response
acceptance. acceptance.
Proactive Identifying potential problems Identifying potential advantages or
Role before they occur. benefits.
Ultimate Minimize negative impact and Maximize positive impact and create
Goal protect assets. value.
Core Idea What could go wrong? What could go right?
Key Question How can we prevent this? How can we make the most of this?

Page 3 of 94
How can Risk be an Opportunity or Positive?

Risk is not always negative; it can lead to the emergence of new opportunities, improvement
of organizational processes, service development, or enhancement of competitive advantage.
Leveraging risk positively depends on analyzing the situation and adopting innovative
solutions instead of fearing or avoiding them.

Examples of Converting Risks into Opportunities in a Hospital Setting

1. Risk of Hospital-Acquired Infections (HAIs)

The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)


Opportunity: Process Improvement and Quality
Proof. Identifying this risk and performing a root
Risk: High rates of Hospital-Acquired
cause analysis leads to developing strict new
Infections (e.g., post-surgical
infection control protocols and implementing
infections).
advanced sterilization technologies (such as
sanitizing robots or air purification systems).
Enhanced Reputation and Competitive
Advantage for the hospital as a leader in patient
Positive Outcome: safety, which attracts more patients and reduces
costs associated with prolonged treatment and
litigation.

2. Risk of Medication Errors

The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)


Opportunity: Integration of Technological
Risk: Errors in dispensing dosages or
Systems and Service Development. Investment in
administering the wrong medication to
an Electronic Medication Administration System
a patient, putting the patient's life at
(CPOE) and an Automated Barcode Scanning
risk.
system for patients and medications.
Significant increase in the efficiency of clinical
services, as medication errors are virtually
eliminated, leading to better treatment outcomes
Positive Outcome:
and empowering pharmacy and nursing staff to
focus on direct patient care instead of manual
administrative burdens.

Page 4 of 94
3. Risk of Data Loss or Cyber Attacks

The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)


Opportunity: Leadership in Technical
Innovation and Cyber Security. Immediate
Risk: A cyber-attack that disrupts the recognition of this risk drives the development of
Electronic Health Records (EHR) the strongest cyber security systems in the
system or leads to the leakage of healthcare sector, adopting encrypted cloud
sensitive patient data. backup technologies, and implementing advanced
training programs for staff on information
security.
The hospital becomes a benchmark in data
protection, strengthening trust with patients and
Positive Outcome: insurance companies and opening the door to
providing consulting services in data security to
other health facilities.

4. Risk of Specialized Human Resource Shortages

The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)


Opportunity: Internal Talent Development and
Strategic Partnership. Instead of costly
Risk: Shortage of specialized nurses
recruitment attempts, a comprehensive internal
or consultants in rare specializations,
training and specialization program (Talent
impacting the quality of care.
Development Program) is launched for existing
employees in collaboration with universities.
Building employee loyalty and improving the work
environment (employee satisfaction), and providing
Positive Outcome:
highly specialized personnel specifically tailored
to meet the hospital's future needs, leading to a

Page 5 of 94
The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)
sustainable competitive advantage in providing
specialized care.

5. Risk of High Operational Costs and Inefficiency (Operational Cost Risk)


The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)
Opportunity: Leadership in Sustainability and
Risk: Rising utility costs (electricity, Operational Efficiency. This risk is used as a
water) and poor management of driver to invest in an advanced Building
inventory and procurement, Management System (BMS) for smart energy
threatening the hospital's financial consumption control, and to implement a Just-in-
sustainability. Time (JIT) inventory management system to
reduce waste and costs.
Achieving significant long-term financial savings,
enhancing the hospital's reputation as an
environmentally friendly "Green Hospital," and
Positive Outcome:
gaining a new competitive advantage in the market
by offering services at more competitive prices
while maintaining high quality.

6. Risk of Resistance to Change and Delayed Expansion (Strategic Risk)


The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)
Opportunity: Leading the Culture of Innovation and
Risk: Resistance from senior
Corporate Transformation. Resistance is treated not
physicians and staff to adopt new
as an obstacle, but as an indicator of the need to
treatment technologies or modern
restructure governance and develop a rewards
care models (e.g., Telemedicine),
program that links financial incentives to the adoption
hindering the hospital's expansion
of innovation, and to launch "rapid change units"
and market growth plans.
(Change Agents) within each department.
Accelerating the pace of digital transformation and
successfully adopting new technologies, allowing the
Positive Outcome: hospital to offer new and innovative services (like
remote consultations), achieve faster patient base
expansion, and boost its market share.

Page 6 of 94
7. Risk of Failure in a New Infrastructure Project (Project Risk)
The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)
Opportunity: Establishing an Internal Project
Risk: Delays or cost overruns in a
Management Office (PMO) Standard. The
project to build a new specialized
challenges and errors faced in this project are used as
unit (such as an oncology center),
an opportunity to establish a formal Project
harming the timeline and expected
Management Office (PMO) that sets strict
returns.
methodologies and standards for future projects.
Developing permanent internal capabilities in
project management, avoiding the recurrence of errors
in the future, and ensuring that future large
Positive Outcome: infrastructure projects are implemented with higher
quality and within the specified budget, thereby
transforming the hospital's ability to expand into an
organized competitive advantage.

Strategies for Exploiting Opportunities within Risks

Strategies for exploiting the opportunities inherent in risks are an advanced approach in risk
management, where the focus is not limited to avoiding or reducing them, but also involves
seeking out their positive side. Risk management strategies are divided into Accept, Enhance,
Share, or Exploit. Examples include:

• Accept the positive risk if it is associated with significant growth opportunities.


• Enhance or Share the risk to maximize potential returns by cooperating with partners
or investors.
• Exploitation (or Exploit)

Page 7 of 94
Benefits of Viewing Risk as an Opportunity

• Stimulating Innovation and problem-solving in non-traditional ways.


• Enhancing Team Spirit and internal cooperation.
• Increasing Agility in the face of unexpected changes and exploiting them for the
benefit of the organization or individual.

Consequently, risk is not always a negative thing; it may harbor opportunities for growth and
development for those who know how to read and utilize it wisely.

Page 8 of 94
Risk Classification:

Risks in the fields of management and insurance are classified into two main types based on
the potential outcomes: Pure Risk and Speculative Risk. Understanding the difference
between them is essential for correctly managing each type.

1. Pure Risk:
o These are risks whose potential outcome is only one of two: loss or no loss (the
situation remains the same). There is absolutely no possibility of achieving a profit
or gain from this type of risk.
o Characteristics:
▪ Outcome: Only two possible outcomes (loss or no loss).
▪ Objective: Cannot be used to achieve gains; they are undesirable events.
▪ Insurability: This type of risk can be insured, as insurance companies can
statistically calculate the probability of loss and estimate compensation.
o Examples:
▪ Fire: Either a fire occurs (loss) or it does not (no loss). A fire cannot lead to a
profit.
▪ Theft or Damage: Either your property is stolen or damaged (loss) or nothing
happens (no loss).
▪ Natural Disasters: Such as floods and earthquakes.
2. Speculative Risk:
o These risks can lead to a loss, no loss, or a gain. There is a chance for value addition
to the organization.
o Characteristics:
▪ Outcome: Three potential outcomes (loss, break-even, profit).
▪ Objective: They are taken with a conscious decision aiming to achieve a
financial return or gain.
▪ Insurability: Generally, this type of risk cannot be insured, as insurance
companies cannot calculate the probability of profit or loss as they do with pure
risks.
o Example: Expansion into a new service, such as 'Urgent Care,' in a competitive
area. This expansion can lead to gains (an increase in the number of referrals,
improved reputation) or it may lead to losses if it does not succeed, but there is
always an opportunity to achieve gains.

Page 9 of 94
Risk Classification: Pure Risk vs. Speculative Risk
Feature Pure Risk Speculative Risk
Only two: Loss or No Loss Three: Loss, No Loss (break-
Potential Outcomes
(break-even/status quo). even/status quo), or Gain/Profit.
Absolutely no possibility of There is a definite possibility of
Possibility of Gain
profit or gain. achieving a profit or gain.
Undesirable events; not Taken with a conscious decision,
Objective/Motivation
taken to achieve gains. aiming for financial return or gain.
Generally Non-Insurable. Insurance
Insurable. Insurance
companies cannot calculate the
Insurability companies can calculate the
probability of profit or loss in the same
probability of loss.
way.
Fire, Theft, Natural Investing in the stock market,
Disasters (floods, Launching a new product/service,
Examples
earthquakes), Car Expanding into a new market,
Accidents, Illness. Gambling.

Page 10 of 94
Risk Categories / Domains

Risks are divided into 8 categories or Domains:

Risk Area Description / Example


Operational § Risks related to business operations resulting from inadequate or failed
internal processes, people, or systems.
§ Examples include risks related to:
• Handling adverse events
• Credentialing and hiring
• Documentation
• Chain of command
• Lack of internal controls
• Supply chain
• Service interruptions (electricity, water)
• Equipment failure
Clinical/Patient § Associated with the provision of care (or failure to provide) to patients
Safety and residents.
§ Clinical risks include:
• Non-adherence to evidence-based practices
• Medication errors
• Healthcare-Associated Conditions (HAC) / Hospital-Acquired
Infections
• Serious Safety Events (SSE)
• Health equity
• Opportunities for safety improvement within care environments, and
others.
Strategic § Risks associated with the organization's focus and direction.
§ Since the rapid pace of change can create uncertainty, the strategic risks
listed are related to: Branding, reputation, competition, or failure to adapt to
changing systems (e.g., changes in the healthcare system or shifts in
customer priorities).
§ Managed care relations/partnerships, conflicts of interest, marketing and
sales, media relations, mergers and acquisitions and divestitures, joint
ventures, affiliations and other agreements, contract management,
advertising, and other areas are also generally considered potential strategic
risks.
Financial § Risks that affect profitability, cash position, access to capital, or external
financial ratings through business relationships or the timing of revenue and
expense recognition.

Page 11 of 94
§ Risks may include:
• Capital, credit, interest rate, and foreign currency fluctuations
• Growth in programs, facilities, and capital equipment
• Regulatory fines and penalties
• Budget performance, billing and collection activities, accounts
receivable, and available cash
• Capitation contracts, reimbursement rates, managed care contracts,
and the revenue cycle/billing and collection.
Human Capital § Risks that relate to the organization's most valuable asset: its workforce.
§ Includes risks associated with:
• Staff selection, retention, turnover rate, recruitment, and
absenteeism
• Work-related injuries (worker's compensation), scheduling and
burnout, productivity, compensation, succession planning, and union
activity.
• Also, wrongful termination, sexual harassment, disruptive behavior,
discrimination, morale, diversity, employment practices, and breach
of contracts.
• Human capital risks may also cover the recruitment, diversity,
retention, and termination of medical and allied health staff
members.
Legal/Regulatory § Includes risks arising from licensing, accreditation, legislation, standards,
and regulations.
§ Risks in this domain include failure to identify, manage, and monitor
legal, regulatory, and legislative mandates at the local level. These risks are
generally related to fraud and abuse, licensing, accreditation, product
liability, and management liability.
Technology § Includes risks related to:
• Systems and Software: Risks related to information systems, such as
Electronic Health Records (EHR), billing systems, and social media.
• Cybersecurity: Significant risks arising from cyber threats, such as data
breaches or cyberattacks.
• Generally, technological risks include everything related to the use of
technology in the organization's operations, whether for clinical care
delivery, administration, or any other purpose.
Hazard / § This ERM domain covers assets and their value. Traditionally, insurable
Environmental environmental risks have been associated with exposure to natural disasters
and business interruption.
§ It can also include risks related to: Logistics/supply chain, facility
management, facility age, parking (lighting, location, security),
construction/renovation, earthquakes, windstorms, hurricanes, floods, fires,
and epidemics.

Page 12 of 94
The Importance of Risk Management in the Modern Era. (Why do we need Risk
Management)

We need risk management in the modern era because it is no longer just a preventative process;
it has become a vital strategic tool to ensure business continuity and achieve objectives in an
environment characterized by complexity and uncertainty. In a volatile and rapidly changing
world—often referred to as the VUCA world (Volatile, Uncertain, Complex, Ambigous)—
any unexpected event, whether a financial crisis, natural disaster, cyber-attack, or shift in
consumer behavior, can lead to devastating losses if not properly prepared for.

How Does Enterprise Risk Management (ERM) Effectively Help Achieve Strategic
Objectives?

The primary ways ERM supports the achievement of strategic objectives include:

1. Alignment with and Focus on Strategy


o By:
▪ Linking risks directly to strategic objectives.
▪ Prioritizing risks based on their impact on strategy.
▪ Defining the risk appetite and tolerance level.
▪ Allocating resources in line with the strategy.
2. Enhancing Better, Data-Driven Strategic Decision-Making
o By:
▪ Providing a comprehensive view of all risks—both threats and opportunities—
that could affect strategic objectives.
▪ By analyzing these risks and their potential impact, leadership can make more
informed and balanced decisions.
▪ Ensuring that the risks being taken are aligned with the organization's risk
appetite.
3. Proactive Risk Management
o By anticipating potential risks in advance, the ERM program allows the
organization to develop mitigation strategies early on, reducing surprises and
disruptions that could derail strategic objectives.
4. Optimal Resource Allocation
o By prioritizing risks based on their potential impact relative to the organization's
objectives, ensuring that critical risk areas receive appropriate attention.
5. Improved Collaboration and Communication
o ERM breaks down silos by encouraging cooperation across departments, so the
entire organization maintains a unified view of risks and mitigation efforts.
6. Boosting Organizational Resilience
o By integrating risk awareness into the corporate culture and strategic planning,
ERM helps the organization better withstand uncertainties and challenges while
pursuing its mission.
7. Increasing Stakeholder Confidence
o Effective ERM assures stakeholders, including regulators and investors, that the
organization is managing risks comprehensively and strategically, which supports
sustainable growth and value creation.

Page 13 of 94
Risk Management and Strategy

The Relationship between Risk Management and Strategy

Risk management is no longer a separate preventative process but has become an integral part
of the organization's core strategy. The relationship between them is integrative and two-way,
not merely one of dependence. This means that each influences and supports the other in crucial
ways, where Risk Management acts as a supportive tool for achieving the organization's
strategic goals, while Strategy helps guide how risks are managed. This relationship has
become central in the modern business environment characterized by complexity and rapid
changes.

1. Risk Management as a Strategic Support Tool (First Direction: From Risk to Strategy)
🛡️

How does Risk Management influence Strategy?

Risk management serves the organization's strategic objectives by:

• Protecting Value and Alignment with Objectives: It helps identify, assess, and
mitigate risks that could impede the achievement of strategic goals or lead to losses. If
the strategy of a hospital is to expand its specialized surgical services, ERM would
identify risks associated with this expansion (e.g., risks of surgical complications
beyond the norm, shortage of highly-skilled surgeons, or failure to obtain
accreditation for the new service).
• Supporting Decision Making: Risk management provides data and analyses that help
senior management make more informed and aware strategic decisions. For example,
when a healthcare system considers acquiring a smaller clinic in a new region,
potential risk analysis (e.g., financial risks related to payment models, or legal risks
from patient malpractice claims in the new region) provides a clear vision of threats
and opportunities, avoiding hasty decisions.
• Capitalizing on Opportunities and Protection from Disruptions: By identifying
potential risks (e.g., shifts in healthcare policy or the emergence of a highly effective
competitor in a niche service), ERM helps ensure the continuous execution of the
strategy even under unexpected circumstances.

2. Strategy as a Guide for Risk Management (Second Direction: From Strategy to Risk)

How does Strategy influence Risk Management?

Strategy helps guide how risks are managed by:

• Guiding the Identification Process: The organization's strategic objectives determine


which risks must be focused on. For example, if a hospital's strategy is to become a
leader in digital health records and telehealth services, the risks associated with this
strategy (cyber risks, data privacy breaches, or system downtime) will become a top
priority for the risk management team.
• Determining Risk Appetite: Strategy sets the level of risk the organization is prepared
to accept to achieve its goals. This level directly impacts the growth strategy; a startup
health-tech company with a high-risk appetite might pursue aggressive, high-return

Page 14 of 94
strategies (like early adoption of experimental AI tools), while a traditional non-profit
hospital with a low-risk appetite would prefer more cautious growth strategies.
• Prioritizing Risks: Strategy helps identify the most critical risks based on objectives.
For example, if the strategy focuses on improving patient experience and outcomes,
risk management will prioritize clinical risks and patient safety events.
• Resource Allocation: Strategy directs how resources are allocated for risk
management, such as investing heavily in staff training on infection control
protocols or acquiring advanced cybersecurity technology to protect patient data.

Frameworks that Support this Relationship

• COSO ERM Framework (2017): Focuses on integrating risk management with


strategy and enhancing performance. It encourages viewing risks as part of the strategic
decision-making process.
• ISO 31000: Provides guidelines for risk management that link risks to strategic
objectives, emphasizing value creation and protection.
• ASHRM Enterprise Risk Management Framework: Specifically tailored for the
healthcare sector, this framework emphasizes applying ERM across all eight domains
of risk to protect patients, staff, and the financial/strategic success of the organization.

Page 15 of 94
Module 2: The ERM Framework

• The General Framework for Enterprise Risk Management (ERM)


o Concept of Enterprise Risk Management (ERM)
o The Difference between Traditional Risk Management and Enterprise Risk
Management (ERM vs TRM)
o Roles and Responsibilities of Risk Managers in the Organization
o Risk Management Frameworks

The Concept of Enterprise Risk Management (ERM)

Enterprise Risk Management (ERM) is a comprehensive, organization-wide, and holistic


approach to identifying, assessing, managing, and mitigating risks that may affect the
organization's ability to achieve its strategic objectives.

It involves a systematic framework of practices, policies, and procedures that allow the
organization to proactively address a wide range of risks—including operational, financial,
compliance, legal, strategic, and reputational risks—across all business units and departments.

Unlike Traditional Risk Management (TRM), which tends to be siloed within individual
departments, ERM adopts a holistic, top-down view, ensuring effective coordination and
communication about all risks throughout the entire organization.

Value Protection and Value Creation 🛡️✨

This approach enables healthcare leaders (and leaders in general) to achieve two main goals:

1. Value Protection: By reducing potential threats and losses, ERM ensures the
continuity of operations and the safety of assets.
2. Value Creation: ERM goes beyond mere protection to transform threats into
opportunities for growth. For example, instead of simply avoiding a new technology
risk, the organization might leverage that technology to develop innovative services
and gain a competitive advantage in the changing healthcare environment.

In short, ERM provides a comprehensive framework that enables organizations to effectively


deal with complex challenges while enhancing their ability to innovate and achieve
sustainable success.

Page 16 of 94
The Difference Between Traditional Risk Management (TRM) and Enterprise Risk
Management (ERM)

Traditional Risk Management (TRM):

• It is a set of practices that focuses on identifying, measuring, and treating risks


individually and typically within individual departments or business units.
• It is generally reactive, addressing risks after incidents occur, with a focus on
operational and insurable risks.
• It tends to adopt a "risk avoidance" mindset and "operates in silos" without true
integration with the overall business strategy.

Traditional Risk
Aspect Enterprise Risk Management (ERM)
Management (TRM)
Focuses on specific risks in Organization-wide, covering all types of
Scope
isolated departments (silos) risks
Proactive (before the incident), focuses on
Reactive (after the incident),
Approach the future, considers both risks and
looks to the past, avoids risks
opportunities
Risks are handled by individual Shared across the organization with
Responsibility
units or functions oversight from senior management
Fragmented and siloed, rarely Integrated into strategic planning and
Integration
aligned with business strategy operations
Value creation and protection; balances
Risk-averse, focused on
Mindset risks and rewards, seeks to optimally
minimizing negative outcomes
leverage uncertainty and opportunities
Standardized, often Dynamic, uses frameworks like COSO or
Methodology
compliance-driven ISO 31000
Types of Primarily focuses on Includes strategic, financial, operational,
Risks insurable/operational risks and reputational risks

Evolution from Siloed Management to Enterprise-Wide Management: Breaking Down


the Barriers - Transitioning to ERM

The following illustrates the maturity stages of an ERM program and how it evolves from a
basic approach to an advanced one, with increasing efficiency in resource consumption.

There are Three Levels of ERM Program Maturity:

1. Basic:
o At this stage, risk management is fragmented (separated) and focused on
protecting assets and value.
o Risks are identified "reactively" (i.e., after they occur).
o This level represents Traditional Risk Management (TRM), which focuses
on "pure risks" (loss-only risks).

Page 17 of 94
o Insurance is purchased as a means of risk management.
o Risks are seen in "silos" or isolated departments, and there is inconsistency in
risk management practices.
o The organization is "Risk Adverse."
2. Intermediate:
o The organization begins to collect and use data for decision-making.
o An understanding of Enterprise Risk Management (ERM) is developed.
o ERM strategies and tools are used for key risks at the unit or department level.
o The understanding of the relationship between different risks improves.
o A transition occurs towards "value creation" by identifying risk opportunities.
o "Micro ERM" is applied.
3. Advanced:
o The program becomes fully integrated, where "everyone is a risk manager."
o "Risk Appetite" and "Tolerance Statements" are developed.
o Risk-based decision analysis is used for making choices.
o An ERM framework and supportive governance are developed.
o ERM is a "Top-down, Bottom-up" process.
o Risks are identified "proactively."
o "Macro ERM" is applied.
o "Value is recognized."

Page 18 of 94
Roles and Responsibilities of Risk Managers in the Organization

Risk managers in organizations play a vital role in implementing the Enterprise Risk
Management (ERM) framework to ensure patient safety, regulatory compliance, and the
financial stability of the institution. Their key roles and responsibilities include:

1. Risk Identification and Assessment:


o Identifying potential risks in all aspects of healthcare (clinical, operational,
financial, technological, legal, strategic, and human risks).
o Assessing the likelihood of these risks occurring and their potential impact on
the organization and patients.
2. Developing Risk Management Strategies:
o Establishing plans and strategies to deal with identified risks, whether by
avoidance, mitigation, transfer, or acceptance.
o Developing policies and procedures to reduce medical errors, improve patient
safety, and ensure compliance with regulations.
3. Legal and Regulatory Compliance:
o Keeping pace with changing laws and regulations in the healthcare sector, such
as data privacy protection laws and other local and international regulations.
o Ensuring that the organization's practices comply with these requirements to
avoid fines and legal penalties.
4. Incident and Litigation Management:
o Overseeing and analyzing incident and adverse event reporting processes.
o Managing professional liability claims and lawsuits, and working with legal
counsel.
5. Training and Education:
o Educating employees at all levels about the importance of risk management,
how to identify risks, and how to report incidents.
o Fostering a risk-aware culture within the organization.
6. Collaboration and Coordination:
o Working closely with senior management, clinical, financial, legal, and IT
departments to ensure comprehensive implementation of risk management.
o Facilitating communication between different departments on risk issues.
7. Monitoring and Reporting:
o Continuously monitoring the effectiveness of risk management plans.
o Preparing periodic reports for senior management and the Board of Directors
on the risk status and the performance of the ERM program.
8. Value Creation:
o Identifying opportunities that may arise from potential risks, and contributing
to strategic decisions that enhance the organization's value and the quality of
care or service.

In summary, the risk manager is a strategic individual who ensures that the organization not
only avoids problems but also leverages its understanding of risks to achieve its objectives and
improve the quality of care or service provided.

Page 19 of 94
Page 20 of 94
Risk Management Frameworks

There are numerous Enterprise Risk Management (ERM) frameworks that have already been
developed and published.

The most common ERM models are (COSO), (ISO 31000), and the (RIMS) Risk Maturity
Model.

Organizations can choose to adopt one of these frameworks when implementing an ERM
program or create their own framework.

Flexibility is important because the "one-size-fits-all" approach does not apply to Enterprise
Risk Management (ERM).

There is no single rigid ERM model or program that will work perfectly for every organization.

Why is Flexibility Essential in Enterprise Risk Management?

No single rigid ERM model or program will work perfectly for every organization. Here is why
flexibility is important in ERM:

• Organizational Uniqueness: Every healthcare organization has a unique size, scope,


and complexity. What works for a small clinic will not necessarily work for a large
university hospital system.
• Influencing Factors: The ERM program needs to be customized based on various
internal factors specific to the organization, including its leadership, culture, mission,
strategy, and specific risk appetite and tolerance. These factors differ significantly from
one entity to another.
• Adaptation is Key: Risk managers must carefully consider general guidelines and
reference materials but then adapt and customize the ERM program to fit their specific
organizational context. This ensures that the ERM program is relevant, effective, and
adds tangible value.

In essence, ERM is not a rigid template but a flexible, tailored approach designed specifically
to fit the unique needs and characteristics of each organization. ERM must be dynamic and
adaptable to ensure its effectiveness in the environment in which it operates.

The healthcare sector is witnessing increasing adoption of ERM, guided primarily by the
COSO 2017 and ISO 31000 frameworks. Specifically, the ASHRM association supports
aligning ERM activities with the COSO 2017 framework because it integrates risk
management with strategy, governance, and the organization's overall performance. This
integration makes ERM more visible and acceptable to leaders, directly linking it to the
organization's mission, vision, and core values.

Page 21 of 94
Global Frameworks for Enterprise Risk Management

• COSO 2017 Enterprise Risk Management Framework – Integrating with Strategy


and Performance
• International Organization for Standardization (ISO) 31000: 2018 Framework
• American Society for Healthcare Risk Management (ASHRM) Framework and
Guiding Principles

COSO 2017 Enterprise Risk Management Framework – Integration with Strategy and
Performance

The COSO Enterprise Risk Management (COSO ERM) Framework is an integrated


system developed by the Committee of Sponsoring Organizations of the Treadway
Commission (COSO) to enhance an organization's ability to systematically and
comprehensively manage risks that may affect the achievement of its objectives. The
framework focuses on integrating risk management within the organization's strategic
objectives, enabling it to better identify, assess, and respond to risks for sustainable success.

The COSO ERM framework includes several core components or principles, such as: Internal
Environment, Objective Setting, Event Identification, Risk Assessment, and Risk Response.
These components help build an integrated risk management system that supports performance
improvement and ensures compliance with relevant standards and laws.

Furthermore, the framework provides a common language and clear guiding principles that
help organizations formulate and implement effective risk management policies and
procedures, with the possibility of linking risk management to governance and internal control
systems.

Applying the COSO framework benefits organizations by improving internal control, reducing
operational risks, supporting strategic decision-making, and enhancing risk disclosure and
management in an organized manner. Consequently, the COSO framework is a major and
globally recognized reference in ERM, helping organizations across all sectors build an
integrated and effective risk management system.

The COSO framework is divided into five core components and principles for Enterprise Risk
Management:

1. Governance and Culture


2. Strategy and Objective-Setting
3. Performance
4. Review and Revision
5. Information, Communication, and Reporting

Page 22 of 94
Core Principles Under Each Component:

1. Governance and Culture

Governance sets the organization's tone, reinforces the importance of ERM, and establishes
oversight responsibilities. Culture relates to ethical values, desired behaviors, and
understanding of risk in the entity.

• Principle 1: Exercises Board Risk Oversight: The Board ensures effective oversight
of risk management.
• Principle 2: Establishes Operating Structures: Defining how the organization is
structured to support risk management.
• Principle 3: Defines Desired Culture: Formulating values and behaviors that promote
risk awareness.
• Principle 4: Demonstrates Commitment to Core Values: Applying ethical values in
all aspects of work.
• Principle 5: Attracts, Develops, and Retains Capable Individuals: Building a team
with the necessary competencies to manage risk.

Page 23 of 94
For an organization to succeed and create value, its culture must constantly reflect the core
values set by its leadership. A risk-aware culture is crucial, as it emphasizes transparent and
timely sharing of risk information without blame, fostering understanding, accountability, and
continuous improvement.

2. Strategy and Objective-Setting

There is an integrated relationship between ERM, strategy, and objective-setting, as they are
not separate processes but work together within the strategic planning process. This is evident
in:

• Risks as Part of Strategic Planning: When setting an organization's strategy, risks are
not ignored but are considered from the outset.
• Defining "Risk Appetite": Before starting the strategy, the organization defines its
"Risk Appetite," which is the level of risk it is willing to accept to achieve its
objectives.
• Aligning Risk with Strategy: The risk appetite is then aligned with the strategy. The
chosen strategy must be compatible with the risk level defined by the organization.
• Objectives as Practical Tools: Once the strategy is set, "business objectives" are
established, which translate the strategy into practical, executable steps.
• Objectives as the Basis for Risk Management: These objectives become the
foundation upon which the entire risk management program is built.

3. Performance

The third component of the COSO framework, "Performance," focuses on the actual
application of the risk management process.

• Identify and Assess Risks: The organization must first identify and assess all risks that
could affect the achievement of its strategic and business objectives.
• Prioritize: After assessment, risks are ranked by their severity, considering the
organization's "Risk Appetite."
• Risk Response: The organization then selects appropriate actions to deal with each risk
(Avoid, Mitigate, Transfer, or Accept).
• Portfolio View: It is important for the organization to view all its risks as an integrated
whole, known as the "Portfolio View," which helps understand the organization's total
risk exposure.

4. Review and Revision

By reviewing organizational performance, the organization can consider the efficiency of the
ERM components over time and in light of significant changes, and what revisions are needed.
ERM must be integrated into business practices with formal performance reviews. The Board
should oversee the continuous improvement of ERM's efficiency and utility.

5. Information, Communication, and Reporting

ERM requires the continuous acquisition and sharing of necessary information, from both
internal and external sources, flowing up, down, and across the organization. Strategic

Page 24 of 94
decision-making relies on the deliberate transformation of valuable data into timely and well-
structured insights.

International Organization for Standardization (ISO) 31000: 2018


The ISO 31000: 2018 framework is a major global reference for risk management.

What is the ISO 31000 Framework?

The ISO 31000 framework is a set of guidelines and instructions for risk management, not a
mandatory standard that requires certification. Its goal is to provide guidance to help
organizations integrate risk management into their operations and decision-making effectively.
It is general and comprehensive, meaning it can be applied to any type of organization,
regardless of its size, nature, or sector.

Key Components of the Framework

The ISO 31000 framework consists of three main interconnected components:

1. Principles: The foundation upon which effective and efficient risk management must
be built. Key principles include that risk management must be integrated into all
organizational activities, dynamic and adaptable, and based on the best available
information.
2. Framework: This component defines how risk management is integrated into the
organization's governance and leadership structures. It involves establishing, designing,
implementing, evaluating, and continually improving the risk management framework.
3. Process: This component describes the practical steps for managing any type of risk.
The process includes:
o Communication & Consultation: Exchanging information about risks with
concerned parties.
o Establishing the Context: Understanding the organization's internal and
external environment.
o Risk Assessment: Risk Identification, analysis, and evaluation.
o Risk Treatment: Making the necessary decisions and taking actions to respond
to risks.
o Monitoring & Review: Continuously tracking and reviewing risks and the
actions taken.

Page 25 of 94
Definitions (ISO 31000)

• Risk: The effect of uncertainty on objectives. The effect of risk is a deviation from
what is expected. This deviation can be positive, negative, or both, and can address,
create, or lead to opportunities and threats.
• Risks are expressed in terms of risk sources (an element with the potential, alone or in
combination, to cause risk), potential events, their consequences (outcomes of an
event affecting objectives), and their likelihood (the chance of something happening).
• Risk Management: Coordinated activities to direct and control an organization with
regard to risk.

Principles (ISO 31000)

The purpose of risk management is to create and protect value. It improves performance,
encourages innovation, and supports the achievement of objectives.

1. Integrated: Risk management is an integral part of all organizational activities.


2. Structured and comprehensive: A structured and comprehensive approach
contributes to consistent and comparable results.
3. Customized: The risk management framework and process are customized and adapted
to suit the organization's external and internal context related to its objectives.
4. Inclusive: Appropriate and timely involvement of stakeholders allows their knowledge,
views, and perceptions to be considered.
5. Dynamic: Risks can emerge, change, or disappear as the organization's external and
internal context changes. Risk management is dynamic, continuous, vigilant, and
adaptive.

Page 26 of 94
6. Best available information: Inputs to risk management are based on historical and
current information, as well as future expectations.
7. Human and cultural factors: Human behavior and culture significantly influence all
aspects of risk management at every level and stage.
8. Continual improvement: Risk management is continually improved through learning
and experience.

Page 27 of 94
Framework (ISO 31000)

The purpose of the risk management framework is to help the organization integrate risk
management into critical activities and functions. The effectiveness of risk management
depends on its integration into the organization's governance, including the decision-making
process. This requires support from stakeholders, especially senior management, as leadership
support is the foundation of success.

The framework development includes integrating, designing, implementing, evaluating, and


improving risk management throughout the organization.

Page 28 of 94
The Risk Management Process:

The risk management process involves the systematic application of policies, procedures,
and practices to the activities of: communication and consultation, establishing the
context, risk assessment, risk treatment, monitoring and review, recording, and
reporting. This process is illustrated in Figure 4.

Page 29 of 94
Comparison of ISO 31000-2018 and COSO Framework 2017
Element ISO 31000-2018 COSO Framework 2017
Committee of Sponsoring Organizations of
International Organization
Developer the Treadway Commission (COSO), primarily
for Standardization (ISO)
accounting and financial organizations
Global and flexible
Detailed framework focused more on
Scope framework applicable
governance and internal control
across all sectors
Approach Principle-Based Component-Based
On value creation and Integrating risk management with strategy and
Focus
organizational protection performance
Flexible and adaptable to More systematic and detailed with specific
Inclusiveness
the organization's needs components
Culture & Emphasizes leadership and Focuses on governance culture and the "tone
Behavior risk culture from the top"

Ultimately, the ERM framework (or set of frameworks) adopted by the organization must
include an integrated and holistic approach to identifying and managing risks, recognizing that
daily decision-making must include consideration of risks in relation to strategy, and that the
process must ultimately be about value creation and recognition.

Pure Risk vs. Speculative Risk (ASHRM Context)

• Pure Risk:
o Characteristics: Only two potential outcomes: loss or no loss. No potential for
gain.
o Example: Natural disasters like hurricanes. If a hurricane occurs, there is either
loss (property damage) or no loss, but the hurricane cannot lead to any financial
gain.
• Speculative Risk:
o Characteristics: Can lead to loss, no loss, or gain. There is an opportunity for
value addition to the organization.
o Example: Expansion into a new service like "Urgent Care" in a competitive
area. This expansion can lead to gains (increased referrals, improved reputation)
or losses if unsuccessful, but there is always a chance for gain.

Importance in ERM: ERM differs from traditional risk approaches by:

• Acknowledging Gain: ERM doesn't just focus on protecting the organization from
losses but recognizes that some risks (Speculative) can create opportunities for gain
and value.
• Proactivity: Focuses on identifying risks proactively, not just responding to them after
they occur.
• Understanding Interconnectedness: Recognizes that risks do not exist in isolation but
are interconnected and affect the organization as a whole.

Page 30 of 94
Aligning Risk Appetite and Strategy

• Risk Appetite: Refers to the broad description of the desired level of risk the
organization will bear in pursuit of its mission.
• Risk Tolerance: Reflects the qualitative limit or range of risk to be endured in
pursuit of the strategy or to accept variations in outcomes.

Both are determined by the Board and Senior Management, integral to the strategic plan and
the ERM program, and vary significantly between organizations. They are usually articulated
through statements that include qualitative and quantitative metrics and require continuous
review and adjustment as the organization's strategy evolves.

Page 31 of 94
ASHRM ERM Framework & Guiding Principles

Guiding Principles

The following guiding principles were developed in collaboration with the mission and vision
of the American Society for Healthcare Risk Management (ASHRM) to serve as the
building blocks that support the Enterprise Risk Management (ERM) framework in
healthcare:

1. Promote the safety and reliability of healthcare.


2. Manage uncertainty.
3. Maximize value protection and creation.
4. Enhance accountability across all departments.
5. Improve organizational readiness.
6. Foster a positive organizational culture, which will impact readiness and success.
7. Use data/metrics to prioritize risks.
8. Align risk appetite with strategy.

The ASHRM guiding principles form the logical basis for all decisions and actions of risk
managers in the health sector. Although strategies and objectives may change over time, the
philosophy of ERM in healthcare remains rooted in these fundamental principles.

Page 32 of 94
Promoting the Safety and Reliability of Healthcare

ASHRM's core purpose is to promote safe and reliable healthcare, aligning with the Institute
of Medicine's (IOM) report, "Crossing the Quality Chasm," which identified six aims for
improving healthcare delivery (STEEEP):

• Safe
• Timely
• Effective
• Equitable
• Efficient
• Patient-centered

Maximizing Value Protection and Creation: The Role of Risk Managers in Empowering
Leadership

The role of risk managers is to effectively empower leadership to engage actively in


Enterprise Risk Management (ERM). This is achieved by integrating ERM principles and
knowledge deep into the organization's culture.

This sustainable approach helps leadership understand interconnected risks, enabling them to
effectively assess both risks and opportunities at the operational levels. Ultimately, this
integration ensures the overall success and sustainability of the ERM program.

Fostering Ethical and Transparent Decision-Making

Integrity, honesty, and transparency are fundamental principles that must guide all
organizational levels and ERM leaders. These values ensure that ethical and trustworthy
strategic decisions are made, support the well-being of staff and patients, and enhance a
culture of readiness and success by building trust and engaging stakeholders.

Fair and Just Culture ⚖️ Traditional healthcare often blamed individuals for all errors. A
Fair and Just Culture, however, is different: it recognizes that individuals should not be

Page 33 of 94
blamed for system problems they cannot control. It also acknowledges that even skilled
professionals sometimes make mistakes and breach rules to facilitate. But a Fair and Just
Culture never tolerates reckless behavior or the deliberate disregard of obvious risks to
patients. It's about understanding and accountability, not merely assigning blame.

Improving Strategic Decision-Making

When any organization strives to achieve its strategic objectives, risks inevitably emerge. This
is where Enterprise Risk Management (ERM) plays its role as a tool for improving strategic
decision-making.

ERM enables the organization to:

• Systematically identify and analyze risks.


• Leverage uncertainty to transform it into opportunities and create value.

In summary, although the adoption of ERM is not yet complete in all healthcare organizations,
effective risk management is considered essential and crucial for sustainable success.

Governance and Organizational Culture

Risk Culture is the shared attitudes, behaviors, and understanding of risks—both positive and
negative—that influence management and employee decisions and reflect the organization's
mission, vision, and core values.

Governance and Culture are the cornerstones of effective ERM, ensuring its alignment with
the organization's mission and vision. A risk-valuing organizational culture promotes
transparency, accountability, and integrity, which is especially vital in the rapidly changing
healthcare environment, where governance helps discover new risks and opportunities.

To ensure effective oversight, it is essential that the governing body receives formal training
on ERM concepts and principles. This training aims to enable them to understand and define
the organization's risk profile and appetite, integrate risks with strategy, ensure clear
reporting and accountability, and evaluate the risk culture.

Strategically, Governance is responsible for guiding the organization towards success in a


dynamic environment. Strategy involves taking calculated risks, built upon a deep
understanding of strengths and weaknesses through SWOT analysis. A culture that embraces
change is a crucial factor in the success of these strategies.

Today, strategic planning in healthcare has become a continuous process, with department
heads participating to evaluate performance, new projects, and their risks, while senior
leadership takes responsibility for setting priorities. In this context, the role of risk
professionals is increasing to become strategic partners, providing insights on emerging risks
and supporting the decision-making process.

Page 34 of 94
Module 3: Risk Management Process

• Identify and analyze loss exposures.


• Examine risk treatment techniques or methods.
• Select the best risk treatment technique/method or combination of
techniques/methods.
• Implement the selected treatment techniques/methods.
• Monitor, evaluate, and improve the risk management program to identify and analyze
loss exposures.

The Risk Management Process (Five Steps)

The risk management process involves a systematic approach to identifying, assessing, and
managing risks across the enterprise. It is an integral part of Enterprise Risk Management
(ERM).

The five steps of the ERM process are:

1. Identify and analyze loss exposures.


2. Examine risk treatment techniques or methods.
3. Select the best risk treatment technique/method or combination of techniques/methods.
4. Implement the selected treatment techniques/methods.
5. Monitor, evaluate, and improve the risk management program to identify and analyze
loss exposures.

1. Identify and Analyze Loss Exposures (What could happen?)

Risk Identification/Recognition: A critical responsibility of senior leadership is the ongoing


process of identifying risks and opportunities for creating and sustaining value for the
organization. Identifying risks that could negatively affect the achievement of the
organization's mission, strategy, objectives, and goals is paramount. Risks must be identified
in specific units or departments and across the organization as a whole. The organization's
Board of Directors is ultimately responsible for ensuring that management is competent in its
duties and that best practices, protocols, and procedures are used to help identify, assess,
manage, and monitor enterprise risks.

A variety of methodologies, tools, and resources are available to aid in identifying risks and
opportunities. Risk managers must focus on existing, identified risks as well as new and
emerging risks. Given the changing nature of healthcare, not all risks can be defined. Risks
can also evolve and change. Therefore, it is good practice to identify, review, and analyze risks
continuously and consistently.

Risk identification methods can be formal or informal, internal or external to the organization,
and retrospective or concurrent. This involves actively searching for, recognizing, and
describing risks. Methods can include interviewing key individuals, using questionnaires or

Page 35 of 94
surveys, brainstorming sessions, and engaging both internal and external stakeholders through
Focus Groups. Data analysis, trend identification, and research are also crucial for this step.

Sources of Risk Identification

Enterprise risks can be identified using various methods categorized based on their nature
(formal or informal), source (internal or external), and timing (retrospective or proactive).

§ Formal and Informal Sources

• Formal Systems: These are structured, documented methodologies that the


organization systematically follows. These methods are used to ensure comprehensive
risk coverage and facilitate the process of review and accountability.
o Examples:
▪ Risk Identification Workshops: Structured sessions gathering key
stakeholders to discuss potential risks.
▪ Scenario Analysis: Building specific hypothetical scenarios (e.g., a
natural disaster or economic collapse) and assessing their impact.
▪ Checklists: Using pre-made lists of common risks in a specific sector.
▪ Risk Registers: Systematically documenting all risks in a centralized
database.
• Informal Systems: These are undocumented daily practices that rely on experience
and professional judgment. Although less structured, they are essential for rapidly
detecting emerging risks.
o Examples:
▪ Daily Observation: Managers and employees notice potential risks
during their daily tasks.
▪ Side Conversations: Risks are sometimes discovered through casual
conversations between colleagues.
▪ Personal Experience: Managers rely on their past experience to
identify risks.

§ Internal and External Sources

• Internal Sources: Focus on risks that arise from within the organization and can be
controlled.
o Examples:
▪ SWOT Analysis: Analyzing Strengths and Weaknesses.
▪ Operational Process Review: Analyzing errors in production lines or
customer service procedures.
▪ Financial Reports: Studying financial data to identify liquidity or debt
risks.
▪ Employee Interviews: Gathering opinions from staff about the
challenges and risks they face in their work.
▪ Historical Data Analysis: Reviewing records of past incidents, such as
system failures or workplace accidents.
• External Sources: Focus on risks that arise from the surrounding environment and
cannot be directly controlled by the organization.
o Examples:
▪ SWOT Analysis: Analyzing Threats and Opportunities.

Page 36 of 94
▪ Environmental Analysis (PESTEL)
▪ Market and Competitor Analysis: Monitoring competitor movements,
consumer trends, and market changes.
▪ Tracking Political and Legal Changes: Monitoring new laws,
environmental regulations, and trade policies.
▪ Economic Analysis: Studying inflation rates, interest rates, and their
impact on the organization's investments.

§ Retrospective and Proactive Sources

• Retrospective (Reactive) Sources: Rely on analyzing events that have already


occurred to learn from them and prevent recurrence.
o Examples:
▪ Root Cause Analysis: After an incident (e.g., a data breach), analyzing
all the causes that led to it.
▪ Review of Near-misses: Studying situations that nearly caused a
disaster to ensure they do not happen in the future.
▪ Review of Audit Findings: Analyzing internal and external audit
results to identify weaknesses that led to risks.
• Proactive Sources: Used to identify risks before they happen. This approach is
proactive and aims to avoid losses from the outset.
o Examples:
▪ Horizon Scanning: Searching for emerging trends, new technologies,
and potential risks in the distant future.
▪ Risk Forecasting: Using statistical models and data to analyze the
probability of specific events occurring in the future.
▪ Contingency Planning: Developing proactive plans to deal with
unexpected scenarios (e.g., power outage or cyberattack).
▪ FMEA.

Brainstorming
Brainstorming is a very common risk identification technique.

1. Formal vs. Informal System

Brainstorming is typically a Formal System.

While it can be done casually, in a risk management context, it's almost always a planned,
structured meeting (like the "Risk Identification Workshops" you listed). It involves key
stakeholders, has a set agenda, and the results (the identified risks) are documented in a
formal output, such as a risk register.

2. Internal vs. External Source

Brainstorming is an Internal Source.

The identification process relies on the knowledge, experience, and creativity of people inside
your organization (managers, employees, subject matter experts). Even if you are
brainstorming external risks (like new regulations or competitor actions), the source of the
information is your internal team.

Page 37 of 94
3. Retrospective vs. Proactive Source

Brainstorming is a Proactive Source.

Its entire purpose is to look forward and think about what might happen in the future. You are
trying to identify potential risks before they occur, which is the definition of a proactive
approach.

Triggering Questions:

Strategic and objective-based questions

These questions focus on how risks can affect your organization's highest-level goals.

• What are our main business objectives for the next year, and what could prevent us
from achieving them?
• What are our most valuable assets (e.g., intellectual property, data, reputation) and
what could happen to them that would result in a significant loss?
• What major assumptions are we making about our market, competition, or resources?
What happens if these assumptions are wrong?
• What keeps you up at night regarding this project or business unit?
• How do we know if we are achieving our objectives? What information are we most
reliant on?

Financial and contractual questions

These questions focus on risks related to money and obligations.

• Which contracts represent a meaningful portion of our revenue or operations? What


would happen if we breached one?
• Where are we experiencing financial losses today, and what could be causing them?
• What changes in market prices or interest rates could affect our budget or revenue?
• How could a cash flow problem or unexpected expense affect our operations?
• How could a vendor's or partner's financial distress impact us?

Operational and process-based questions

These questions target day-to-day activities and the potential for process failures.

• What are the most complex or difficult activities we perform? What could go wrong
with them?
• What steps in our core processes rely on a single person or a small group of people?
• Where are the handovers between departments or teams? Is there a risk of
miscommunication or failure at these points?
• What must go right for us to succeed, and how could these things fail?
• What are the most common workarounds or manual fixes in our processes? Are these
a sign of a larger, underlying risk?

Page 38 of 94
Human resources and people-related questions

These questions address risks related to your employees and organization's culture.

• What happens if a key team member leaves or is unavailable?


• Are there any skills gaps or resource shortages that could impact our work?
• Are workloads and responsibilities distributed fairly, or are certain employees
experiencing burnout?
• Are there any interpersonal conflicts or employee complaints that could escalate into a
larger issue?
• How do we ensure that new employees receive adequate training and are not a source
of risk?

Technology and data questions

These questions focus on risks related to information systems and cybersecurity.

• What IT practices could create a risk of a cyber-attack or data breach?


• What applications or databases store our most valuable data? How could that data be
compromised?
• What are the most probable scenarios for our systems failing (e.g., power outage,
network failure)?
• How could unauthorized users gain access to our systems or sensitive data?
• How could the failure of a key software vendor or platform impact our operations?

Regulatory and external questions

These questions address risks that originate outside the organization.

• What recent changes in regulatory policy have occurred in our industry? Do any of
them apply to us?
• Are there any legal or licensing requirements that apply to our products or services?
• What emerging external threats (e.g., new competitors, economic downturns) could
impact our business?
• What are the environmental or social risks associated with our operations?
• How might public perception or a social media incident affect our reputation?

Questions about potential failures

• What could go wrong?


• How could we fail to achieve our objectives?
• What must go right for us to succeed?
• What are the most probable ways our most valuable assets could be impacted?

Page 39 of 94
Questions about vulnerabilities and dependencies

• Where are we most vulnerable?


• What assets do we need to protect?
• On what information do we most rely?
• What activities are most complex?
• What assumptions are we making that, if proven false, would create a risk?

Questions about processes and impact

• What business process accounts for the largest amount of revenue?


• How do we bill and collect our revenue?
• How could someone disrupt our operations?
• What are the most probable ways our data could be compromised?
• What decisions require the most judgment?
• Under what conditions could we be exposed to regulatory fines or punitive damages?

Questions about change and monitoring

• What has changed in previously identified risks?


• Have project assumptions changed?
• Are workarounds increasing, and why?
• Are there common causes that are increasing multiple risks?

Risk Identification – Outcomes:

• So we have identified a bunch of risks. What do we do with them? We begin a risk


registry.
• A short title / Statement for the risk event
• A description of the risk with its consequences
• Causes of this risk.
• The Risk Category / Domain
• The organizational objective that the risk relates to.

Page 40 of 94
The key to writing a good risk statement

Writing a clear and effective risk statement is one of the most critical steps in the entire risk
management process. A poor statement leads to confusion, while a good one makes analysis
and response planning much easier.

The standard best practice for writing a risk statement follows a

Cause → Risk → Impact (or Cause → Event → Consequence) format.

A weak risk statement just names a topic (etc."Server Failure"). A strong risk statement
explains why it might happen and what the "so what" is.

The 3-Part Formula for a Good Risk Statement

Here is the most common and effective structure. Think of it as a single sentence with three
parts:

1. [THE CAUSE] The definite event or existing condition why the risk might happen.
2. [THE RISK] The uncertain event that may or may not occur.
3. [THE IMPACT] The consequence or effect on your objectives (e.g., on cost,
schedule, safety, or quality) if the risk happens.

You can often structure this as:

"Due to... [Cause], there is a risk of... [Risk Event], which could result in...
[Impact/Consequence]."

Indicators of a good, quality risk statement are that it can answer the following
questions:

• What could happen?


• Why could it happen?
• Why should an enterprise care?

Page 41 of 94
Examples: Bad vs. Good Risk Statements

Let's look at how this formula transforms vague problems into actionable risk statements.

Here are examples of good vs. bad risk statements across the main healthcare risk domains.

The key difference is that bad statements are often vague, broad topics, or issues that have
already happened. Good statements are specific and actionable, following the Cause → Risk
→ Impact formula.

Page 42 of 94
Clinical & Patient Safety Risk

This domain relates to harm or potential harm to patients during the delivery of care.

👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement

Due to inconsistent use of the hourly rounding protocol on the night


shift (Cause), there is a risk that a high-risk patient will attempt to
Patient falls get up unassisted (Risk Event), which could result in a fall with
fracture, leading to increased length of stay and potential litigation
(Impact).

Due to the storage of look-alike, sound-alike (LASA) drugs


hydralazine and hydroxyzine in the same automated dispensing cabinet
Medication
drawer (Cause), there is a risk that a nurse will select the wrong
errors
medication (Risk Event), which could result in a patient experiencing
a severe hypotensive event and requiring ICU transfer (Impact).

Due to staff rushing the pre-operative "time-out" process for emergent


cases (Cause), there is a risk that the surgical site marking is
Wrong-site
overlooked (Risk Event), which could result in the team performing
surgery
surgery on the wrong limb, leading to catastrophic patient harm and
immediate loss of accreditation (Impact).

Operational Risk

This domain relates to failures in the day-to-day internal processes, people, and systems.

👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement

Due to the new electronic health record (EHR) system's complex


Patient registration interface (Cause), there is a risk that patient check-in
waiting times will be delayed by an average of 15 minutes (Risk Event),
times which could result in decreased patient satisfaction scores and
patients leaving without being seen (Impact).

Due to the hospital's reliance on a single, aging sterilization unit


(autoclave) (Cause), there is a risk that the unit will have critical
Equipment
downtime (Risk Event), which could result in the cancellation of all
failure
elective surgeries for the day, leading to significant revenue loss and
surgeon complaints (Impact).

Page 43 of 94
Financial Risk

This domain relates to the financial health and stability of the organization.

👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement

Due to recent complex changes in insurance coding for outpatient


procedures (Cause), there is a risk that our billing department
Billing
will submit incorrect codes (Risk Event), which could result in a
problems
20% increase in claim denials, negatively impacting cash flow by
$2M per quarter (Impact).

Due to the hospital's high rate of hospital-acquired infections


(HAIs) (Cause), there is a risk that the hospital will receive a
Low
penalty from CMS (Risk Event), which could result in a 1%
reimbursement
reduction in all Medicare reimbursements for the next fiscal year
(Impact).

Human Capital (HR) Risk

This domain relates to the workforce (recruitment, retention, training, and well-being).

👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement

Due to mandatory overtime and high patient-to-staff ratios in the ICU


(Cause), there is a risk that experienced critical care nurses will resign
Nurse
for jobs at a competing hospital (Risk Event), which could result in
turnover
increased costs from using expensive agency staff and a decline in
patient care quality (Impact).

Due to the lack of a formal staff debriefing process after traumatic


patient events (Cause), there is a risk that clinical staff will experience
Staff
severe burnout and compassion fatigue (Risk Event), which could
burnout
result in increased sick leave, higher medication errors, and poor
patient interactions (Impact).

Page 44 of 94
Technological (IT) Risk

This domain relates to technology, data, and cybersecurity.

👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement

Due to a lack of a redundant power supply for the main data center
(Cause), there is a risk that a city-wide power outage will cause a total
EHR
EHR system failure (Risk Event), which could result in staff reverting
downtime
to paper charts, leading to lost billing, medication errors, and an
inability to access patient histories (Impact).

Due to medical staff using personal, unencrypted USB drives to


transfer patient data (Cause), there is a risk that a drive will be lost or
Data
stolen (Risk Event), which could result in a major breach of patient
breach
health information (PHI), leading to millions in regulatory fines and
severe reputational damage (Impact).

Legal & Regulatory Risk

This domain relates to non-compliance with laws, regulations, and accreditation standards.

👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement

Due to new staff being unaware of infection control policies


(Cause), there is a risk that an accreditation surveyor will observe
Accreditation
improper hand hygiene or sterile processing (Risk Event), which
failure
could result in the hospital receiving a "Condition of Participation"
warning, threatening its ability to bill for services (Impact).

Due to physicians failing to consistently document informed


consent for high-risk procedures (Cause), there is a risk that a
patient will sue the hospital after a poor outcome, claiming they
Malpractice
were not aware of the risks (Risk Event), which could result in a
costly legal settlement and damage to the physician's reputation
(Impact).

Page 45 of 94
Strategic Risk

This domain relates to high-level decisions that affect the organization's long-term goals and
viability.

👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement

Due to a new competing specialty clinic opening in our primary


service area (Cause), there is a risk that our hospital will lose 30%
Competition of its profitable orthopedic surgery market share (Risk Event), which
could result in an inability to fund other essential, loss-leading
services like the emergency department (Impact).

Due to multiple negative news stories about long ER wait times


(Cause), there is a risk that the community will develop a perception
Bad
of the hospital as low-quality (Risk Event), which could result in
reputation
patients and top physicians choosing our competitor, making future
growth impossible (Impact).

Environmental (Hazard) Risk

This domain relates to the physical environment and external hazards (e.g., fire, flood,
utilities).

👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement

Due to improper storage of flammable chemicals in a non-compliant


cabinet in the main laboratory (Cause), there is a risk that a fire could
Fire start and spread rapidly (Risk Event), which could result in a full unit
evacuation, patient injuries from smoke inhalation, and catastrophic
damage to the building (Impact).

Due to construction on a nearby city water main (Cause), there is a


risk that the hospital's water supply could be cut off for 8+ hours (Risk
Utility
Event), which could result in an inability to sterilize equipment or
failure
perform hand hygiene, forcing a full hospital evacuation and diversion
of all patients (Impact).

Page 46 of 94
🔑 Key Tips for Writing Risk Statements

• Be Specific, Not Vague. "Supplier delay" is vague. "XYZ Corp. delaying the server
shipment by 6 weeks" is specific.
• Focus on One Risk. Don't bundle multiple risks into one statement (e.g., "fire, flood,
or theft"). Write a separate statement for each.
• It Must Be Uncertain. If it has already happened or is 100% certain to happen, it is
an issue, not a risk.
• Connect to Objectives. The impact should always relate to what your organization or
project is trying to achieve (e.g., patient safety, budget, timeline, reputation).

Once you have a well-written risk statement, you can then properly analyze its probability
and impact, which is the necessary next step before you can select a response.

Page 47 of 94
Risk Analysis (What is the probability of it happening and what is the magnitude of its
impact?)

• Analysis: Is determining the potential severity of loss associated with specific risks, the
probability/frequency of that loss occurring, and the severity/impact of that loss.
• Risk Assessment and Modeling: Once risks are identified, they are analyzed to understand
their characteristics, such as correlations and interdependencies. This involves assessing
the probability of the risk occurring and the potential severity/impact if it does happen.
Various tools can be used for this assessment, such as risk scales, risk curves, and risk
matrices. The process also distinguishes between Inherent Risk (risk before controls are
applied) and Residual Risk (risk remaining after controls).
• Risk Scoring / Ranking:
o Formula: Probability times (×) Severity/Impact} = Risk Ranking/Score
o Probability Scale: 1 (Lowest) to 5 (Highest)
o Severity/Impact Scale: 1 (Lowest) to 5 (Highest)
• Risk Map/Risk Matrix:
o The Risk Map/Heat Map/Risk Matrix graphically displays the assessed risks according
to the risk ranking, as shown in the figure.
o This visual representation is especially useful in meetings and status reports because it
provides a quick snapshot of the organization's risks according to probability and/or
likelihood and impact.

Page 48 of 94
Risk Scales

Examples of Risk Probability, Severity, and Control


Effectiveness Ratings
Risk Probability Rating:
1. Very Low: Less than 5% probability of the risk event occurring within one year.
2. Low: 5-20% probability of the risk event occurring within one year.
3. Medium: 20-50% probability of the risk event occurring within one year.
4. High: 50-95% probability of the risk event occurring within one year.
More than 95% probability of the risk event occurring within one
5. Very High:
year.
Risk Severity Rating:
Non-material impact on the company's reputation and/or annual
1. Very Low:
profits, or on its ability to achieve business objectives.
Low impact on the company's reputation and/or annual profits, or on
2. Low:
its ability to achieve business objectives.
Moderate impact on the company's reputation and/or annual profits,
3. Medium:
or on its ability to achieve business objectives.
Significant impact on the company's reputation and/or annual profits,
4. High:
or on its ability to achieve business objectives.
5. Very High Very significant impact on the company's reputation and/or annual
(Critical): profits, or on its ability to achieve business objectives.
Control Effectiveness Rating:
Risk exposures are within defined tolerance levels, controls are tested
1. Highly Effective: and working effectively, a clear link exists between risks and returns,
and comprehensive metrics and dashboard reports are in place.
Risk exposures are within defined tolerance levels, controls are tested
and working effectively, an implicit link exists between risks and
2. Effective:
returns, and some metrics and dashboard reports are in place but with
specific development plans.
Risk exposures are generally within defined tolerance levels with
3. Moderately
some exceptions, controls are functioning at an acceptable level but
Effective:
not fully tested, and some metrics and dashboard reports are in place.
There are some or material exceptions to defined tolerance levels,
4. Needs
controls are present but not fully tested, and minimal metrics or
Improvement:
dashboard reports are in place.
There are significant exceptions to defined tolerance levels (or
5. Needs
tolerance levels have not been defined), controls are non-existent or
Significant
not working effectively, and minimal or no metrics or dashboard
Improvement:
reports are in place.
Source: Lam, J. Risk Management – The ERM Guide from Association for Financial
Professionals (AFP) Used with permission

Page 49 of 94
Factors Influencing Probability

1. Historical Data: Previous incidents or near-misses.


2. Procedure Complexity: Interventional procedures, high-risk surgical operations.
3. Staff Experience: Training, competency, and staffing ratios.
4. Equipment Reliability: Maintenance and calibration of medical devices.
5. Environmental Factors: Hospital design and infection control.
6. Regulatory Compliance: Adherence to standards and guidelines.

Risk Probability Matrix:

1: Rare 2: 5: Almost
3: Possible 4: Likely
Factor (Very Unlikely Certain (Very
(Moderate) (High)
Low) (Low) High)

At least
one
No
similar
known No
incident
incidents incidents 1-2 near- Multiple similar
or
Historical or near- or near- misses in the incidents have
multiple
Data misses at misses in last 12-24 occurred in the
near-
this the last 2- months. last 12 months.
misses in
facility in 5 years.
the last
> 5 years.
12
months.

Standard, High-
Simple,
non- Standard risk,
non-
invasive, invasive or complex A novel,
invasive,
multi- complex interventi emergent, or
Procedure single-
step multi-step onal or extremely high-
Complexit step
procedur procedure surgical risk procedure
y procedur
e (e.g., (e.g., central operation being performed
e (e.g.,
dispensin line (e.g., under pressure.
taking
g oral insertion). cardiac
vitals).
meds). bypass).

Unit is
Unit is Meets Staffed
fully
fully minimum below
staffed
staffed staffing minimum Critically
with a
with ratios, but ratios; understaffed;
Staff mix of
experienc has some high staff are floated
Experienc new and
ed, senior new/float reliance from other units
e senior
staff. All staff or on with known
staff. All
competen minor agency or competency gaps.
competen
cies are competency float
cies are
met. gaps. staff.
met.

Page 50 of 94
1: Rare 2: 5: Almost
3: Possible 4: Likely
Factor (Very Unlikely Certain (Very
(Moderate) (High)
Low) (Low) High)

New,
fully
Mid- Mid- Older
maintaine
lifecycle lifecycle equipmen
d
equipmen equipment, t with Equipment is old,
equipmen
t, >95% >90% known known to be
Equipmen t with
maintena maintenance minor faulty, or has
t built-in
nce compliance, faults or critical overdue
Reliability redundan
complian but has some maintenance/cali
cy. 100%
ce. No known overdue bration.
calibratio
known single points maintena
n
issues. of failure. nce.
complian
ce.

Good
Cramped,
Modern, design,
high-
well- managea Older unit,
traffic
designed ble some Poorly designed,
unit,
unit, low workflow workflow/sp chaotic unit with
Environm known
noise, , meets ace known,
ental workflow
good all challenges, unaddressed
Factors issues,
workflow infection but meets workflow and IC
minor/rep
, exceeds control minimum IC violations.
eat IC
standards (IC) standards.
deviation
. standards
s.
.

Known
Full Full
General non-
complian complian
compliance, complian
ce, ce with Known major
Regulator with only ce in
considere all non-compliance;
y minor some
d a "best required currently under a
Complianc recommenda areas;
practice" standards corrective action
e tions for repeat
in all and plan or cited.
improvemen minor
recent guideline
t. findings
audits. s.
in audits.

Page 51 of 94
Risk Severity and Impact Matrix:

Rati Patient Operations / Legal /


Impac
ng Financial Safety Process Reputation Regulatory
t-
(‫التقييم‬ (‫)مالية‬ ( ‫سالمة‬ ( / ‫العمليات‬ al (‫)سمعة‬ ( / ‫قانوني‬
‫التأثير‬
) ‫)المرضى‬ ‫)اإلجراءات‬ ‫)تنظيمي‬

- Significant
- Cash - Death /
deterioratio
Liquidity: Permane
- Major labor n of brand - Loss of
Leads to 20 nt
relations event and major License
days of disabilit
market
available cash y
share loss

- Event: - Workplace
-
Suicide / Safety: Multiple -
- Property Continuous
Rape / time-loss Government
damage: negative
Child injuries / al/Federal
Critic $250,000 media
abductio Recordable Investigation
5 al coverage
n incidents
(‫)حرج‬
- Breach of
Personal Health
Information - Customer
- Loss of a key
(PHI) / Private Satisfaction:
contract
Information for < 85%
more than 100
people

- Loss of
business

-
Docume
nted
incident - Temporary -
of but Government
- Cash - Significant
boundar significant al/Federal
Liquidity: loss/turnover of
y negative Inquiry (not
$150,000 key personnel
violation media investigation
Major
4 or code coverage )
(‫)عالية‬
of
conduct
breach

- Property
- Major - Customer
damage: - IT system
or Satisfaction:
$100,000 to failure
critical 85-88%
$250,000

Page 52 of 94
Rati Patient Operations / Legal /
Impac
ng Financial Safety Process Reputation Regulatory
t-
(‫التقييم‬ (‫)مالية‬ ( ‫سالمة‬ ( / ‫العمليات‬ al (‫)سمعة‬ ( / ‫قانوني‬
‫التأثير‬
) ‫)المرضى‬ ‫)اإلجراءات‬ ‫)تنظيمي‬

health
incident

- Non-
- Workplace
- Need for complia
Safety: Time-
unexpected nce with
loss and
additional the
recordable
capital standard
incidents
of care

- Breach of
Personal Health
Information
(PHI) / Private
Information for
up to 100
people

- - Corporate
- Negative
Increasi - Loss or non-
- Cash mention in
ng trend increased compliance
Liquidity: media
in minor turnover in key with
$50,000 (state/region
health positions financial
Mode al level)
incidents impact
rate
3
(‫متوسط‬
- Operational
‫)ة‬ - Lack -
- Property disruption or
of - Customer Ramification
damage: increased cost
clinical Satisfaction: s for
$10,000 to due to
continuit 88-90% insurance
$100,000 regulatory
y access
change

- Minor
health
incidents - Minor
- Cash - Customer
(patient - Staff base violations
Liquidity: Satisfaction:
is distraction (e.g., auto
Minor $10,000 90-94%
unaware incidents)
2 (‫منخف‬
of the
‫)ضة‬
error)

- Property
damage:
$10,000

Page 53 of 94
Rati Patient Operations / Legal /
Impac
ng Financial Safety Process Reputation Regulatory
t-
(‫التقييم‬ (‫)مالية‬ ( ‫سالمة‬ ( / ‫العمليات‬ al (‫)سمعة‬ ( / ‫قانوني‬
‫التأثير‬
) ‫)المرضى‬ ‫)اإلجراءات‬ ‫)تنظيمي‬

Insign
ificant - Minor
- No
(‫منخف‬ property - Customer
impact
1 ‫ضة جدا‬ damage or - Satisfaction: -
on care
‫ غير‬/ impact on > 95%
delivery
‫جوهرية‬ cash liquidity
)

Source: Aon/Barbara McCarthy

Factors Influencing Impact / Severity:

1. Patient Outcomes: Complications (morbidity), mortality, quality of life.


2. Financial Consequences: Costs, lawsuits, reputational harm.
3. Regulatory Compliance: Penalties, fines, loss of accreditation.
4. Reputational Impact: Media attention, public perception.
5. Operational Disruption: Staffing, resource allocation.

Page 54 of 94
Inherent Risks and Residual Risks

Inherent Risk is the baseline level of risk without any mitigation efforts.

Target Residual Risk is the desired level of risk that the organization wants to have after
implementing risk management measures.

Actual Residual Risk is the risk that remains after those measures have been taken.

Ideally, the Actual Residual Risk should be at or below the Target Residual Level. If it is higher,
the organization needs to define additional risk reduction strategies. Healthcare organizations
use various proactive processes to reduce inherent risks, such as network vulnerability
assessments, risk assessments for new services or equipment, electronic controls, auditing,
system backups, structured communication, disaster plans, engineering controls, and
equipment maintenance schedules.

Risk
Risk Evaluation Suggested Action
Rating
1-3 Low Risk Accept Risk, Maintain Existing Control
4-6 Medium Risk Accept Risk, Review Existing Control
Management Action Required: Improve existing
8-12 High Risk
Control
Immediate Senior management action required,
15-25 Critical Risk
stop activity, Improve existing control measures.

Page 55 of 94
2. Examining Risk Treatment Techniques / Methods

Avoidance (Avoid):

Risk avoidance is a strategy where the organization takes decisive action to completely
eliminate a risk by stopping the activity that causes it. It is the only risk control technique that
can reduce the probability of a specific loss to zero. This strategy is typically chosen when no
other response can reduce the risk to an acceptable level.

Primary Indication: Used for "Extreme" or "Critical" risks, typically those with both a
high likelihood and a catastrophic impact.

When to Use It:

• When the risk's potential negative consequences are so severe (e.g., mass patient harm,
total business failure, massive legal penalties) that no other treatment is acceptable.
• When the cost of mitigating the risk to an acceptable level is prohibitively expensive or
complex, and the activity is not essential.
• When the risk falls completely outside the organization's strategic goals and risk appetite.

Healthcare Example: A hospital's leadership team is considering opening a new, highly


specialized neurosurgery unit. After analysis, they discover the malpractice insurance is
unavailable, the specialized equipment is unreliable, and they cannot recruit qualified staff.
The risk of catastrophic patient harm and financial failure is "Extreme."

Treatment: They choose Avoidance by deciding not to open the new unit.

Page 56 of 94
Acceptance or Retention:

This is a conscious, documented decision to take no action to treat the risk, accepting the
potential consequences.

• Primary Indication: Used for "Low" risks, where both the likelihood and impact
are small.
• When to Use It:
o When the risk is within the organization's defined "risk appetite."
o When the cost of implementing a control (cost, time, resources) is greater than
the potential loss from the risk.
o When the risk is so insignificant that it is not worth the effort to treat.
• Healthcare Example: A hospital's risk register notes that the paint in a rarely used
basement storage closet is chipped. The impact is "Insignificant" (minor aesthetic
issue) and the likelihood of anyone being harmed is "Rare."
• Treatment: They choose Acceptance. They formally document the risk and the
decision, and agree to simply monitor it, as the cost of repainting is not justified by
the tiny risk.

Risk Acceptance: Involves acknowledging and accepting the potential consequences of a risk
without taking any additional action to mitigate or transfer it.

Risk Retention: Involves bearing the potential losses associated with a specific risk and
establishing plans to cover any financial consequences of those losses. This response is
appropriate when the risk already falls within the organization's defined "risk appetite." If
management wishes to accept a risk that exceeds this appetite, approval from a higher authority,
such as the Board of Directors, is usually required. When an organization accepts or retains a
risk, it agrees to cover any resulting financial losses with its own internal funds, meaning the
financial exposure is not transferred to another party, such as an insurance company.

The Four Key Principles of Risk Retention:

• Avoiding retaining a large-sum risk to save a small amount.


• Understanding the organization's financial capacity to cover the potential loss.
• Having a clear and comprehensive understanding of the risk itself.
• Using self-insurance for expected losses while transferring unexpected or catastrophic
losses.

Transfer or Share:

Risk Transfer: Is a strategy to reduce the severity of a risk by shifting a portion of its financial
obligation to a third party. This action reduces the residual risk to a level aligned with the
organization's "risk appetite."

This strategy involves shifting the financial burden or liability of a risk to a third party. It
does not eliminate the risk itself, but it protects the organization from its financial impact.

Page 57 of 94
• Primary Indication: Used for risks with a low probability but a very high financial
impact, or for risks that require highly specialized management.
• When to Use It:
o When the risk's potential financial cost is catastrophic but manageable for a larger
entity (like an insurer).
o When a third party has more expertise in managing the risk (e.g., outsourcing
cybersecurity).
o When it is more cost-effective to pay a premium (for insurance or an outsourced
service) than to manage the risk internally.
• Healthcare Example: A hospital faces a low-likelihood risk of its main building
being destroyed by an earthquake. The financial impact would be catastrophic.
• Treatment: They cannot avoid or mitigate the earthquake. They choose Transfer by
purchasing a comprehensive property insurance policy. If the event occurs, the
financial loss is transferred to the insurance company.

There are two distinct forms of risk transfer:

• Insurance Contracts: This involves purchasing insurance to cover financial losses.


The insured organization pays a premium, and in return, the insurance company agrees
to pay for covered losses, its own operating expenses, and achieve a profit.
• Non-Insurance Agreements: This technique transfers the financial obligation of loss
to another party through legal contracts, such as "hold harmless" and "indemnification"
agreements. This can also include exculpatory clauses in leases and contracts that shift
the legal obligation for loss. When considering risk transfer, the organization must
evaluate criteria such as the financial stability provided by the technique, its long-term
cost, the organization's understanding of the risk, and its general risk-bearing
philosophy.

Risk Mitigation:

Risk mitigation is a strategy that focuses on preparing for and reducing the negative effects
of potential threats and disasters on the organization. It is comparable to "risk reduction" and
involves taking active steps to lessen the impact of a risk.

This is the most common strategy. It involves implementing controls or actions to reduce the
risk's likelihood or impact (or both) to an acceptable level.

• Primary Indication: Used for "High" or "Medium" risks that are central to the
organization's objectives and cannot be avoided.
• When to Use It:
o When the risk is a core part of your operations (e.g., you can't avoid performing
surgery, but you can mitigate the risks involved).
o When the risk is at an unacceptable level, but a cost-effective control exists to
reduce it.
o When required by law or regulation (e.g., patient safety standards, infection
control protocols).
• Healthcare Example: A hospital identifies a "High" risk of patient falls on a specific
ward.

Page 58 of 94
• Treatment: They cannot avoid admitting patients. Instead, they choose Mitigation.
They implement a new fall-prevention bundle: new non-slip flooring, hourly patient
rounding, bed-exit alarms, and staff training. This reduces the likelihood of falls.

Key Techniques used in Risk Mitigation: Risk prevention, reduction, and segregation. After
implementing these measures, some risks may still remain, which the organization may
formally accept.

• Risk Prevention: Risk prevention techniques affect the frequency or number of times
an event will occur. They do not eliminate the probability, but they reduce the
likelihood of the risk occurring.
• Risk Reduction: Risk reduction techniques reduce or lessen the loss once the event has
actually occurred. For example, having emergency preparedness plans is a risk
reduction technique because once a disaster occurs, the preparedness plans will help
minimize any further losses and mitigate the impact of those that have already occurred.
• Risk Segregation: Segregating exposure units reduces loss uncertainty by increasing
the predictability of both loss frequency and severity. Segregation of exposure units can
take one of two forms:
1. Separation: Dividing an asset or process that could be stored or performed in
one location among two or more separate locations. An example is having a
travel policy that states the maximum number of Board members or senior
leaders allowed to travel together to avoid a catastrophic event involving
multiple Board members, senior leadership, or clinical staff.
2. Duplication: Involves replicating an asset or facility. Examples include backup
disks, cloud storage, duplicate keys, and double-checking of medication
administration.

Risk Indicated for Risk


Key Question to Ask
Treatment Level

Extreme / Critical
"Is this risk so catastrophic that we should
Avoidance ↑ High Probability + ↑ not do this activity at all?"
High Impact

High / Medium "What controls can we implement to


Mitigation ↑ High Probability + reduce the likelihood or impact of this
↓ Low Impact risk?"

↓ Low Likelihood + "Can we (and should we) pay someone


Transfer
↑ High Impact else to bear the financial cost of this risk?"

Low
"Is the cost of treating this risk more than
Acceptance ↓ Low Probability +
the cost of the risk itself?"
↓ Low Impact

Page 59 of 94
HIERARCHY OF RISK CONTROLS:

• Elimination: Removing the hazard (the potential source of harm) or the target (the
person or entity exposed to the risk) is the most robust response. If the hazard is entirely
eliminated, there is no chance for it to cause harm. An example is closing a low-volume
surgical program that does not provide sufficient practice for surgeons to maintain
competency. This essentially transfers the risk to another organization. This example
can also be considered target elimination, as patients at risk of harm from that surgery
will not be seen by this institution.
• Engineering Controls: Anything other than elimination that does not rely on people
doing the right thing. These include strategies such as physical barriers, isolation,
forcing functions, human factors/ergonomics engineering, and fail-safe design.
Examples might include placing a second set of locked doors between a locked
psychiatric unit and the rest of the hospital, or computerized physician order entry
systems that include a "hard stop" to prevent a ten-fold overdose of high-risk
medications.
• Administrative Controls: Motivate people to improve safety by doing the right thing.
These include policies, procedures, training, signage, alarms, and other controls that
rely on people taking the intended action. Although they are the least robust category
of risk response, healthcare organizations have historically focused most of their risk
response efforts on administrative controls.

3. Selecting the Best Risk Management Technique or Combination of Techniques

First, predict the effects that the available risk management options are likely to have on the
organization's ability to achieve its objectives. Second, identify and apply criteria that measure
how well each alternative risk ranking technique contributes to each organizational objective
in cost-effective ways.

Evaluation Criteria:

• Effectiveness: The ability to reduce risk probability or impact.


• Cost-Benefit Ratio: Comparing treatment costs to potential benefits.
• Feasibility: Practicality of implementation.
• Residual Risk: The remaining risk after treatment.
• Regulatory Compliance: Alignment with laws, regulations, and standards.
• Operational Impact: Effects on business operations, resources, and stakeholders.
• Reputation and Brand: Potential impact on the organization's reputation.
Page 60 of 94
From
Matrix Primary
Risk Level Key Question & Rationale
(Prob × Strategy
Impact)

"This is unacceptable."

EXTREME This activity must be stopped


15-25 AVOID or redesigned from the ground
(High Prob + up. If avoidance is impossible,
High Impact) you must apply maximum
Mitigation and Transfer.

"How do we control this?"

HIGH This is the main "control" zone.


The risk is too frequent or too
8-12 MITIGATE
(e.g., High Prob severe to ignore. We must
+ Med Impact apply active controls (redesign,
or Med Prob + new policies, checklists) to
High Impact) reduce its score.

"What is the best


combination?"

This is where you combine


MITIGATE +
MEDIUM techniques.
TRANSFER
4-6
(e.g., Low Prob 1. Mitigate to reduce the risk
(Cost-Benefit
+ High Impact (e.g., add fire sprinklers).
Analysis)
or High Prob +
Low Impact) 2. Transfer the remaining
financial risk (e.g., buy fire
insurance).

"Is this worth our time?"

The risk is tolerable. The cost


LOW to apply controls would be
1-3 ACCEPT
more than the risk itself.
(Low Prob + Formally accept it and monitor
Low Impact) it, but dedicate resources to the
higher-level risks.

Page 61 of 94
4. Implementing the Selected Treatment Techniques/Methods

Implementing the selected techniques requires attention to the technical risk management
decisions that the risk professional must make and the administrative decisions that must be
made in collaboration with other managers across the organization to execute the chosen
techniques.

5. Monitoring, Evaluating, and Improving the Risk Management Program to Identify


and Analyze Loss Exposures

The risk management program is monitored, evaluated, and improved to measure and assess
the effectiveness of the techniques used to identify, analyze, and treat risks.

• a) Reducing and controlling the number and size of claim payments.


• b) Identifying the most economic methods of risk financing.
• c) Improving quality and safety.
• d) Quantifying the cost of risk.
• e) Quantifying risk tolerance.

This involves continuous tracking of identified risks, the effectiveness of risk responses, and
the organization's overall risk profile. Metrics, measures, and targets are established to gauge
performance. This ensures that risk is managed within the organization's defined "risk
appetite" and tolerance levels.

The risk management process is iterative and dynamic, requiring regular review and
adjustment. As the organization's strategy, objectives, and environment change, the risk profile
evolves, necessitating continuous learning and adaptation of risk management practices. This
systematic approach, which goes beyond traditional reactive methods, allows healthcare
organizations to proactively manage risks, seize opportunities, and align risk management with
strategic objectives to protect and create value.

Risk Register

What is a Risk Register?

The Risk Register is an essential and critical document in the Enterprise Risk Management
(ERM) program. It is a centralized record of all potential risks that may affect the
organization's objectives. The Risk Register is not just a list; it is a dynamic tool used to
systematically document, analyze, track, and monitor risks.

Components of a Risk Register

A Risk Register typically includes the following information for each identified risk:

• Risk Name: A brief and clear description of the risk (e.g., "Loss of sensitive data due
to a cyber-attack").
• Risk Description: A more detailed explanation of the risk, clarifying its nature,
potential causes, and potential effects on the organization.

Page 62 of 94
• Risk Category: Classification of the risk within defined categories (e.g., Financial,
Operational, Strategic, Legal, Technology).
• Risk Owner: The person or department responsible for managing and following up on
this risk.
• Likelihood: Assessment of the probability of the risk occurring.
• Impact: Assessment of the magnitude of harm or effect that will occur if the risk
materializes (Financial, Reputational, Operational).
• Risk Score: The result of calculating the Likelihood multiplied by the Impact. This
helps in prioritizing risks.
• Current Response: The actions currently being taken by the organization to control
this risk.
• Mitigation Plan: Additional planned actions to reduce the probability or impact of the
risk.
• Review Date: The last time this risk was reviewed and assessed.

The Importance of the Risk Register in the ERM Program

The Risk Register is the backbone of the ERM program for the following reasons:

1. Proactive Management: Helps in early detection of risks and taking preventative


measures before they escalate.
2. Prioritization: Helps in identifying risks that require immediate attention, based on the
Risk Score (Likelihood and Impact).
3. Decision Making: Provides managers and executive leadership with a comprehensive
picture of the risks facing the organization, enabling them to make informed decisions.
4. Accountability: Clearly defines the owner of each risk, ensuring clear responsibility
for managing and tracking each risk.
5. Increased Stakeholder Confidence: Demonstrates the organization's commitment to
transparency and professional risk management.
6. Enhanced Communication: Promotes transparency and communication among
departments and stakeholders regarding risks and coping strategies.
7. Continuous Monitoring and Improvement: Allows for tracking the evolution of risks
and the effectiveness of response plans, helping to continuously improve the risk
management process.
8. Improved Monitoring and Reporting: Enables tracking of risk mitigation progress
and preparation of periodic reports.
9. Compliance: Ensures the organization adheres to regulatory requirements related to
risk management.

In summary, the Risk Register is a practical tool that helps transform risk management from a
reactive process into a proactive and systematic one.

Date of
Risk Impact Overal Rank
Risk Likelihoo
Ris Descriptio Risk Severit l risk (Critical -
Risk identifie Affected ‫االرتباط‬ d
k n& Categor y Rating High -
identifie d Departme Cause ‫االحتمالية باألهداف‬
ID / Impact y ‫ التصنيف التأثير‬Medium –
d ‫تاريخ‬ nt s ‫االستراتيج‬ (L)
Ref ‫وصف‬ ‫فئة‬ (S) ‫اإلجمالي‬ Low -
‫المخاطر‬ ‫التعرف‬ ‫القسم‬ ‫ية‬ Score (1-
: ‫المخاطر‬ ‫المخاطر‬ Score R=L Insignifican
‫على‬ 5)
‫واألثر‬ (1-5) S t)
‫المخاطر‬

Page 63 of 94
Risk Appetite and Strategy

Definition of Risk Appetite

The concept of "Risk Appetite" can be confusing for healthcare risk managers who have
traditionally been trained to consider all risks undesirable and to be avoided. However, in the
context of Enterprise Risk Management (ERM), Risk Appetite is defined as the total
amount and type of risk that an organization is willing to accept in the pursuit of value.

It acknowledges that taking calculated risks is essential for growth, adding new services,
adopting modern technologies, and ultimately, progressing toward the organization's mission.
An organization's risk appetite is shaped by factors such as its history, culture, and financial
stability. It reflects a strategic agreement between senior leadership and the Board of Directors
on the acceptable level of risk, considering the entity's resources and capabilities.

The Relationship between Risk Appetite, Risk Capacity, and Risk Tolerance

Organizations constantly balance the risks they undertake with the potential rewards of their
strategic goals. This balance is heavily influenced by the organization's culture, whether it is
"risk-averse" or "risk-seeking." The following interconnected concepts distinguish between
three fundamental notions in ERM:

• Risk Capacity: This is the maximum amount of risk an organization can absorb
without compromising its ability to meet its obligations or sustain itself. It is influenced
by tangible factors such as financial size, cash position, and asset liquidity.
• Risk Appetite: Refers to the amount of risk the organization is willing to accept to
protect and create value under uncertainty in achieving its objectives. The
organization's appetite is usually set below its total capacity to maintain a safety margin.
• Risk Tolerance: Defined as the amount of risk exposure or potential adverse events
that the organization is willing to endure while pursuing its objectives.

The primary goal of ERM is to maintain strategic alignment among these three elements,
ensuring that current risks (Risk Profile) plus the desired additional risks (Appetite) do not
exceed the organization's maximum ability to absorb loss (Capacity).

Page 64 of 94
Defining and Formulating Risk Appetite

Defining Risk Appetite 🎯

• There is no single universal approach to defining risk appetite. The process begins by
analyzing the organization's current risk profile in relation to its risk capacity.
• Process: This should involve high-level discussions between senior leadership and
the Board of Directors, taking into consideration past and current objectives and the
potential impact on key stakeholders.

Formulating Risk Appetite 📝

• Formulation: Formulating the risk appetite statement is a flexible process, but the most
important characteristic is that the statement must be linked to the organization's
overall strategy, mission, and values.

What is a Risk Appetite Statement (RAS)?

A Risk Appetite Statement is a structured framework that articulates an organization's acceptable


level of risk exposure across different domains, balancing growth opportunities with risk
mitigation strategies.

The RAS provides a clear boundary for risk-taking, serving as a guide for decision-making at all
levels of the organization. It includes qualitative and quantitative measures to define acceptable

Page 65 of 94
risk levels, ensuring consistency and transparency in managing risk across various departments
and functions.

How to Formulate a Risk Appetite Framework

Formulating risk appetite is a top-down process that links your strategy to your daily
operations. Here are the key steps.

Step 1: Link to Strategic Objectives

You cannot define your risk appetite in a vacuum. It must be directly tied to what you are
trying to achieve.

• Ask: "To achieve our goal (e.g., 'become the #1 cardiac center'), what risks must we
take, and what risks must we avoid?"
• Example: To be #1, we have a high appetite for investing in new, unproven surgical
technology (Technological Risk) but an extremely low appetite for any harm to
patients (Clinical Risk).

Step 2: Define Risk Categories

You don't have one "risk appetite." You have multiple appetites for different types of risk.
Use your risk domains to break it down.

• Clinical / Patient Safety


• Operational
• Financial
• Human Capital
• Technological
• Legal & Regulatory
• Strategic & Reputational

Step 3: Develop the Risk Appetite Statement (Qualitative)

For each category, assign a qualitative statement. This is the core of the "Appetite
Statement." Most organizations use a simple scale.

Page 66 of 94
Adapted from Quail (2012)

Step 4: Set Risk Tolerances (Quantitative)

This is where you make the qualitative appetite measurable. The risk tolerance puts hard
numbers on your appetite statement.

Setting quantitative risk tolerances is the most critical step to make a risk appetite actionable.

It translates the high-level, qualitative philosophy (e.g., "We are Averse," "We are Cautious")
into specific, measurable, and non-negotiable boundaries.

• Appetite is the statement: "We have an Averse appetite for patient harm."

Tolerance is the number: "Therefore, we will tolerate zero (0) sentinel events."

• Appetite is the statement: "We have a Cautious appetite for operational downtime."

Tolerance is the number: "Therefore, we will tolerate no more than 4 hours of


unscheduled EHR downtime per quarter."

Tolerances are the triggers. When a tolerance is breached, it signals to management that the
organization is operating outside its desired appetite, requiring an immediate response.

Page 67 of 94
Here is one example of a Risk Appetite Statement for a hospital, which integrates this entire
framework.

Risk Appetite Statement

1. Overall Risk Appetite Statement

Our mission at [Example Hospital] is to provide safe, innovative, and high-quality care to our
community. To achieve this, we must thoughtfully balance risk and opportunity. This
statement defines the amount and type of risk we are willing to accept (our Appetite) to
achieve our strategic objectives.

We empower our staff to innovate and improve, but we will not pursue any opportunity that
compromises our commitment to patient safety, regulatory compliance, or community trust.
This statement serves as a guide for all management in strategic planning and daily decision-
making.

2. Risk Appetite Philosophy & Definitions

We define our appetite for risk across five levels, which are applied to our major risk
domains.

Rating Philosophy Guiding Principle


"Sacred" avoidance of risk is the core
Averse We will not accept this risk. Tolerance is zero.
objective.
We will accept risk only if essential and
Minimalist Extremely conservative.
unavoidable.
We will accept limited risk if heavily
Cautious Preference for safe delivery.
outweighed by benefits.
We will choose to put risk at, but will actively
Flexible Will take well-justified risks.
manage the impact.
We will choose the option with the highest
Open Will take justified risks for high returns.
return, accepting some possibility of failure.

Page 68 of 94
3. Risk Appetite & Tolerances by Domain

The following table maps our philosophy to measurable tolerances (Key Risk Indicators -
KRIs).

Appetite Level Quantitative Risk Tolerances


Risk Domain Guiding Rationale
(Philosophy) (The Measurable Limit)
• Zero Tolerance (0) for all
Sentinel Events (e.g., wrong-
site surgery, unexpected patient
Patient safety is non-
Clinical & death).
Averse negotiable. Our goal is Zero
Patient Safety
Harm.
• < 1.0 Severe Hospital-
Acquired Infections (CLABSI,
CAUTI) per 1,000 patient days.
• Zero Tolerance (0) for major
non-compliance findings from
JCI, CBAHI, or Ministry of
Legal & We must protect our license to Health.
Minimalist
Regulatory operate and our public trust.
• All "High Risk" audit
findings must be remediated
within 30 days.
• Unscheduled EHR downtime
must not exceed 4 hours per
We prioritize safety and
quarter.
reliability over pure speed, but
Operational Cautious
we must be efficient to serve
• Patient wait times (ER, Door-
our patients.
to-Doctor) must not exceed a
60-minute average.
• Must maintain a minimum of
100 "Days Cash on Hand" at
We must ensure long-term
all times.
Financial Cautious financial sustainability to serve
our mission.
• Operating Margin must
remain positive ( > 2.0%).
• Overall clinical staff turnover
Our staff are our most critical rate must not exceed 15%
Human
Cautious asset. We must maintain a safe, annually. <S> • Staff injury rate
Capital
stable, and engaged workforce. (Lost Time Injury) must remain
below 1.2.
• We will allocate up to 10% of
the capital budget to new,
To be a leader in healthcare,
unproven technologies.
Strategic & we must innovate. We accept
Flexible
Innovation well-managed risks to pioneer
• We will tolerate a negative
new services and technologies.
operating margin on a new
service line for the first 24

Page 69 of 94
Appetite Level Quantitative Risk Tolerances
Risk Domain Guiding Rationale
(Philosophy) (The Measurable Limit)
months if strategically
approved.

Step 5: Communicate and Review

The final Risk Appetite Statement (a document combining the qualitative statements and
quantitative tolerances) must be approved by the board. It should then be communicated to all
managers so they can make decisions.

This is not a "set it and forget it" document. It must be reviewed annually, or whenever the
organization's strategic objectives change.

Page 70 of 94
Module 4: Risk Governance and Culture

• Risk Management Governance Structure.


• The Three Lines of Defense Model
• Risk Culture

Risk Management Governance Structure

The Enterprise Risk Management (ERM) Governance Structure is the organizational


framework that defines the roles, responsibilities, processes, and policies to ensure effective
and coordinated risk management across the enterprise. This structure aims to link risk
management to strategic objectives, improve decision-making, and ensure compliance with
regulatory requirements.

Below is a breakdown of the Risk Management Governance Structure:

Components of the Risk Management Governance Structure

1. Board of Directors 👨‍⚖️

The Board of Directors holds the ultimate responsibility for risk management. Its role is not
limited to approving strategies but includes:

• Setting the Vision: Establishing the organization's Risk Appetite, defining the level
of risk the organization accepts to achieve its objectives.
• Oversight: Supervising executive management to ensure the risk management system's
effectiveness and monitoring performance through periodic reports.
• Integration: Ensuring that risk management is an integral part of the strategic
decision-making process.
• Ensuring that risk management strategies align with the organization's strategic
objectives.
• Approving the ERM framework.
• Forming subcommittees such as the Risk Committee or Audit Committee.

2. Senior Executive Management

Senior leadership bears the responsibility for designing, implementing, and maintaining the
ERM program. They set the "tone from the top" and ensure risk management is integrated into
the organization's strategy and daily operations.

• Key Tasks and Responsibilities:


o Developing risk management strategies and policies.
o Risk Identification: Ensuring that risks in all departments and units are
properly identified and assessed.
o Reporting: Providing periodic risk reports to the Risk Committee and the
Board.
o Integrating risk management into strategic planning and decision-making
processes.
o Allocating the necessary resources for risk management.
o Communicating with the Board about key risks and the measures taken.

Page 71 of 94
3. ERM Committee (Risk Management Committee) 🤝

This committee is usually composed of Board members and is a specialized subcommittee of


the Board focused on overseeing the implementation of risk management.

• Key Tasks and Responsibilities:


o Advising: Providing advice to the Board on key risk strategies.
o Review: Reviewing periodic risk reports and assessing the adequacy and
effectiveness of controls.
o Recommendations: Providing recommendations to the Board on policies, risk
tolerance context, and recommendations for improving risk management
performance.
o Validating and prioritizing identified risks.
o Confirming risk mitigation strategies.
o Coordinating risk management activities across different departments.
o Reviewing the status of risk mitigation plans.

4. Chief Risk Officer (CRO) 📈

• Role: Leading and coordinating enterprise-wide risk management efforts.


• Key Tasks and Responsibilities:
o Designing and implementing the ERM framework.
o Overseeing risk identification, assessment, and measurement.
o Preparing periodic risk reports for senior management and the Board.
o Fostering a risk management culture within the organization.

5. Risk Owners 💼

• Role: These are the individuals or groups within the organization directly responsible
for managing specific risks within their area of expertise or department. They are the
First Line of Defense in risk management.
• Key Tasks and Responsibilities:
o Identifying, assessing, and monitoring risks in their daily operations.
o Developing and implementing risk mitigation and management plans.
o Providing regular updates on risk status to the ERM Committee.

6. Business Units and Operational Departments ⚙️

• Role: Identifying and managing risks at the daily operational level.


• Key Tasks and Responsibilities:
o Implementing risk management policies and procedures in their activities.
o Reporting potential risks to the Risk Manager.
o Contributing to data collection and risk analysis.

Page 72 of 94
Essential Elements of a Governance Structure

Any governance structure must contain a set of elements that ensure its effectiveness and
transparency. The most important of these elements are:

• Leadership 👨‍💼: There must be clear and accountable leadership, typically the Board
of Directors, which sets the strategy and oversees implementation. Leadership sets the
organization's overall direction.
• Accountability ⚖️: Every individual in the organization must be accountable for their
role and duties. Accountability ensures there is a party responsible for outcomes,
whether positive or negative.
• Transparency 🔍: Decisions, processes, and procedures must be clear and
communicated to relevant parties. Transparency builds trust and prevents
misunderstandings.
• Oversight: Oversight includes monitoring and review processes to ensure adherence
to policies and procedures. Oversight helps in detecting and addressing problems early.
• Policies and Procedures 📜: There must be a set of rules and controls governing
internal operations. These rules ensure that work is performed consistently and
systematically.
• Ethics and Values ✨: Governance must be based on a set of ethical values that guide
the behavior of individuals and ensure that decisions are made fairly and honestly.
• Supportive Corporate Culture: Promoting integrity and ethical values within the
organization through staff training and dedicating a culture of transparency and
accountability.

Best Practices in Governance Structure

• Building a Specialized and Balanced Board: Recruiting diverse competencies in


terms of experience and knowledge, providing continuous training for members, and
periodic evaluation of the Board's performance. The Board must be independent of
executive management to ensure objective decision-making.
• Defining Roles and Responsibilities Accurately: Establishing clear organizational
structures that describe the role of each party (Board, committees, executive
management) and clarify their authorities and powers to prevent overlap and conflict.
• Transparency and Disclosure: Ensuring the accurate and timely disclosure of
financial and non-financial information to all stakeholders, with clear channels for
reporting violations and conflicts of interest.
• Accountability and Continuous Review: Establishing effective internal and external
control mechanisms, providing periodic performance reports, in addition to
mechanisms for receiving complaints and grievances.
• Effective Risk Management: Establishing clear policies for risk analysis and
management and continuously updating them to face changes in the business
environment.
• Aligning Strategies with Objectives: Linking organizational strategies to the entity's
objectives through regular review and update processes.

Page 73 of 94
• Adherence to Ethical Values: Instilling integrity and commitment to the highest
standards of professional conduct among all employees, and activating corporate codes
of conduct and ethics.
• Establishing a Governance Culture: Governance must become an integral part of the
company's culture, adhered to by all employees from the top to the bottom of the
pyramid.
• Focusing on Stakeholder Value: The primary goal of governance must be maximizing
stakeholder value, while considering the rights of all concerned parties.
• Using Technology: Technology can enhance the efficiency and effectiveness of
governance systems, such as using information systems to monitor performance and
manage data.
• Seeking Advice: Organizations can hire experts and consultants to evaluate governance
systems and provide recommendations for improvement.
• Independence: Ensuring the independence of units such as Internal Audit and Risk
Management to avoid conflicts of interest.
• Continuous Training: Raising the competency of employees in understanding and
managing risks.
• Flexibility: Designing a structure that is adaptable to environmental and regulatory
changes.

These practices help in enhancing corporate trust and reputation, ensuring sustainability, and
achieving the organization's objectives efficiently and fairly.

Conclusion

The Risk Management Governance Structure is a hierarchical system that ensures effective
coordination among all levels of the organization to identify, assess, and manage risks. Its
success depends on clear roles, integration with strategy, and the use of technological tools.
Through a strong governance structure, organizations can transform risks into opportunities
and achieve their goals sustainably.

Page 74 of 94
The Three Lines Model

The "Three Lines Model" (The Three Lines Model) was developed by the Institute of Internal
Auditors (IIA) to become a practical and vital framework for enhancing governance and risk
management within organizations. The model aims to clarify the different roles and
responsibilities in oversight and risk management, and it emphasizes the importance of
coordination and cooperation among the concerned parties.

What is this Model?

It is a framework that helps organizations manage risks and achieve their objectives by
defining roles and responsibilities.

Why do we need it?

Because organizations operate in a complex and risk-filled world. This model ensures the
existence of strong governance and effective risk management. It clarifies who does what,
and how everyone works together.

The model consists of three main lines of defense, in addition to the Board of Directors, which
oversees them:

Page 75 of 94
1. The First Line: Operational Management (Risk Owners) 👷‍♀️

• Role: This line represents the employees and managers directly responsible for
achieving the organization's operational objectives. They are the "Risk Owners,"
meaning they are responsible for identifying the risks that could affect their daily work
and applying the necessary controls to manage them.
• Responsibilities:
o Leading and directing actions to achieve the organization's objectives.
o Applying daily control checks.
o Ensuring compliance with internal and external regulations in daily activities.
• Value: First Line personnel possess deep knowledge of operational processes, making
them the most capable of identifying and immediately addressing potential risks.

2. The Second Line: Risk Management and Compliance Functions (Oversight Functions)
⚖️

• Role: This line represents specialized functions such as Risk Management,


Compliance, and Cybersecurity, which provide expertise, support, and challenge to
the First Line. This line works to assist the First Line in developing and applying
effective risk management practices.
• Responsibilities:
o Developing risk management methodologies and policies.
o Monitoring and evaluating the effectiveness of controls applied by the First
Line.
o Reporting to senior management on the adequacy and effectiveness of risk
management.
• Value: This line provides a specialized and objective view that ensures risk
management is correctly and consistently executed throughout the organization.

3. The Third Line: Internal Audit (Assurance Function) 🔎

• Role: This line represents the Internal Audit function, which is completely
independent of management and operational activities. Its core role is to provide
"Objective Assurance" to the Board and senior management that the First and Second
Lines of Defense are working effectively.
• Responsibilities:
o Evaluating the effectiveness of governance, risk management, and internal
controls.
o Operating with complete independence, reporting directly to the Board of
Directors or the Audit Committee.
o Ensuring that risks are properly managed and that internal controls are adequate.
• Value: The independence of this line is essential to its credibility, as it gives the Board
confidence that the organization is managing its risks efficiently.

Page 76 of 94
The Role of the Governing Body (Board of Directors):

The Board of Directors and Senior Management are above these lines, responsible for setting
strategic objectives and defining the risk appetite. They also have the overall oversight
responsibility for the entire risk management system to ensure its effectiveness.

Importance of the Model:

• This model enhances internal control and reduces instances of fraud and resource
misuse.
• It improves transparency and accountability, contributing to good governance.
• It helps ensure that risk management is effectively managed, especially in large and
complex organizations.
• It encourages cooperation and coordination among all lines to ensure the flow of
information and work effectively to achieve common goals.

Principles of the Three Lines Model

Principle 1: Governance Organizational governance requires the presence of appropriate


structures and processes that allow for:

• The Board's accountability to stakeholders for organizational oversight through


integrity, leadership, and transparency.
• Actions (including risk management) taken by management to achieve the entity's
objectives by making risk-based decisions and utilizing resources.
• Assurance and advice from an independent internal audit function to provide clarity
and confidence and to enhance and facilitate continuous improvement through
meticulous inquiry and insight-rich reporting.

Principle 2: Board Roles The Board ensures the existence of:

• Appropriate structures and processes for effective governance.


• Organizational objectives and activities that align with the priority interests of
stakeholders.

The Board undertakes:

• Delegating responsibilities and providing resources to management to achieve the


entity's objectives while ensuring legal, regulatory, and ethical expectations are met.
• Establishing and overseeing an objective and competent internal audit function to
provide clarity and confidence regarding progress toward achieving objectives.

Key Terms:

• Risk-Based Decision-Making: A thoughtful process that includes analysis, planning,


action, monitoring, and review, considering the potential effects of uncertainty
surrounding objectives.
• Assurance: Independent confirmation and confidence.

Page 77 of 94
Principle 3: Management Roles and the First- and Second-Lines Management, in achieving
organizational objectives, assumes responsibility that includes the roles of the First and Second
Lines.

• First Line roles are directly associated with delivering products or services to the
entity's clients, and they include the roles of support functions.
• Second Line roles provide assistance in risk management.

First and Second Line roles can be integrated or separated. Some Second Line roles may be
assigned to specialists to provide complementary expertise, support, monitoring, and challenge
to those assigned First Line roles. Second Line roles may focus on specific risk management
objectives, such as adherence to laws and regulations, acceptable ethical conduct, internal
control, information security and technology, sustainability, and quality assurance. In contrast,
Second Line roles may include broader risk management responsibility such as Enterprise Risk
Management. However, the responsibility for risk management remains part of the First Line
roles and within the scope of management.

Principle 4: Third Line Roles Internal Audit provides independent and objective assurance
and advice on the adequacy and effectiveness of governance and risk management. Internal
Audit achieves this through the specialized application of systematic, disciplined processes,
expertise, and deep insight. Internal Audit communicates its findings to management and the
Board to enhance and facilitate continuous improvement. In doing so, it may take into account
assurance from other internal and external service providers.

Principle 5: Third Line Independence The independence of Internal Audit from management
responsibilities is crucial for its objectivity, authority, and credibility, and is established
through: Accountability to the Board, unrestricted access to the people, resources, and data
necessary to complete its work, and freedom from bias or interference in the planning and
execution of audit services.

Principle 6: Creating and Sustaining Value All roles working together collectively
contribute to creating and sustaining value when they are aligned with each other and consistent
with the priority interests of stakeholders. This alignment is achieved through communication,
synergy, and cooperation, which will ensure the reliability, interconnectedness, and
transparency of information necessary for risk-based decision-making.

• Keep using the terms "First Line," "Second Line," and "Third Line" from the
original model due to their common usage.
• The word "Lines" is not intended to denote structural elements but a useful distinction
between roles.
• Some view support functions like Human Resources, Administrative Affairs, and
building services as Second Line roles.
• The Three Lines Model considers First Line roles to include both direct customer
activities and administrative support activities, and Second Line roles include
complementary activities focused on risk-related matters.
• In some entities, other Third Line roles are defined, such as oversight, inspection,
investigation, and evaluation, which may be part of the Internal Audit function or
operate separately.

Page 78 of 94
Key Roles in the Three Lines Model

Entities vary significantly in their distribution of responsibilities; however, the following high-
level roles strengthen the principles of the Three Lines Model.

Board of Directors 🏛️

• Accepting accountability to stakeholders for the oversight and supervision of the entity.
• Working with stakeholders to monitor their interests and being transparent when
reporting on the achievement of objectives.
• Establishing a culture that promotes ethical behavior and accountability.
• Establishing governance structures and processes, including forming auxiliary
committees as needed.
• Delegating responsibilities and providing resources to management to achieve the
entity's objectives.
• Determining the organizational risk-taking level and exercising oversight and
supervision over risk management (including internal control).
• Ensuring oversight of compliance with legal, regulatory, and ethical expectations.
• Establishing and overseeing an independent, objective, and competent internal audit
function.

Management 💼

• First Line Roles: Managing and directing actions (including risk management) and
using resources to achieve the entity's objectives.
• Second Line Roles: Providing complementary expertise, support, monitoring, and
challenge related to risk management.
• Shared Management Tasks:
o Maintaining continuous dialogue with the Board and reporting on planned,
actual, and expected outcomes related to the entity's objectives and risks.
o Establishing and managing appropriate structures and processes for managing
business operations and risks (including internal control).
o Ensuring compliance with legal, regulatory, and ethical expectations.
o Establishing and implementing risk management practices and continuously
improving them, including internal control at the process, system, and entity
levels.
o Achieving risk management objectives, such as adherence to laws and
regulations, acceptable ethical conduct, internal control, information security
and technology, sustainability, and quality assurance.
o Providing analysis and reporting on the adequacy and effectiveness of risk
management (including internal control).

Page 79 of 94
Internal Audit 🛡️

• Ensuring fundamental accountability to the Board and independence from management


responsibilities.
• Communicating independent and objective assurance and providing advice to
management and the Board on the adequacy and effectiveness of governance and risk
management (including internal control) to support the achievement of organizational
objectives and to enhance and facilitate continuous improvement.
• Informing the Board of barriers to independence and objectivity and implementing
measures to ensure them.

External Assurance Providers 🌐

• Providing additional assurance regarding compliance with legal and regulatory


expectations that serve to protect the interests of stakeholders.
• Meeting management and Board requests necessary to complement internal assurance
sources.

Relationships Between Key Roles

Between the Board and Management (First- and Second-Line Roles)

The Board typically charts the entity's course by defining the vision, mission, values, and
organizational risk-taking level. The Board then assigns responsibility for achieving the entity's
objectives to management and provides the necessary resources. The Board receives reports
from management on planned, actual, and expected outcomes, as well as reports on risks and
risk management.

• Entities vary in the degree of overlap and separation between the roles of the Board and
management.
• There must be strong communication between management and the Board, typically
with the CEO acting as the link.
• Some Second Line leaders, such as the Chief Risk Officer, may have a direct reporting
line to the Board, which is entirely consistent with the model's principles.

Between Management (First- and Second-Line Roles) and Internal Audit

The independence of Internal Audit from management ensures that its planning and execution
of work are not hindered or biased, and that it has unrestricted access to the people, resources,
and information it needs.

• Internal Audit is accountable to the Board.


• There must be regular communication between Internal Audit and management to
ensure its work is relevant to the entity's strategic and operational needs.
• Internal Audit contributes assurance and advice as a trusted advisor and strategic
partner.

Page 80 of 94
• Cooperation and communication between the First- and Second-Line roles of
management and Internal Audit are necessary to avoid unnecessary duplication,
overlap, or gaps.

Between Internal Audit and the Board

Internal Audit is accountable to the Board, sometimes described as the Board's "eyes and ears."
The Board is responsible for overseeing Internal Audit, which requires:

• Establishing an Internal Audit function.


• Serving as the primary reporting line for the Chief Audit Executive.
• Approving the audit plan and providing it with the necessary resources.
• Receiving and studying reports from the Chief Audit Executive.
• Allowing the Chief Audit Executive, the freedom to communicate with the Board,
including private meetings without management present.

Among All Roles

The Board, management, and Internal Audit each have different responsibilities, but all
activities should be aligned with the entity's objectives. The foundation of successful
interconnectedness is coordination, synergy, and regular, meaningful communication.

• Chief Audit Executive (CAE): The individual holding the highest position in the entity
and assuming responsibility for Internal Audit services.

Applying the Model

Structure, Roles, and Responsibilities

• The Three Lines Model achieves optimal effectiveness when adapted and tailored to
align with the entity's objectives and circumstances.
• The Board may form committees to provide additional oversight on certain aspects of
its responsibilities, such as audit and risk.
• Functions, teams, and even individuals may be entrusted with responsibilities
encompassing both First- and Second-Line roles.
• Second Line roles remain part of management's responsibilities and are not completely
independent of it.
• A distinguishing feature of Third Line roles is their independence from management,
which is the basis for the distinct value of the assurance and advice they provide.
• The independence of Internal Audit is only achieved by refraining from making any
decisions or taking any actions that fall within the scope of management's
responsibilities. In case the Chief Audit Executive assumes additional responsibilities
(such as compliance aspects), a qualified external party must be engaged to provide
independent and objective assurance.

Page 81 of 94
Oversight and Assurance

• The Board relies on reports submitted by management, those assigned First and Second
Line roles, Internal Audit, and others to exercise oversight.
• Management provides valuable assurance, also referred to as affirmations, regarding
outcomes, risks, and risk management.
• Those assigned Second Line roles provide additional assurance on risk-related matters.
• The assurance provided by Internal Audit is characterized by the highest degree of
objectivity and confidence because it is independent of management.

Coordination and Alignment

• Effective governance calls for the appropriate assignment of responsibilities and the
strong alignment of activities through synergy, cooperation, and communication.
• The Board seeks assurance from Internal Audit that governance structures and
processes are designed for their purpose and operate as intended.

Page 82 of 94
Risk Culture
What is Risk Culture?

Risk Culture is a fundamental concept in ERM, defining how individuals and the organization
as a whole approach and manage risk. Simply put, it is "how we think and act toward risks
here."

Risk culture is not limited to written policies and procedures but extends to include informal
behaviors, daily decisions, and how employees interact with each other and with leadership
regarding risk.

Why is Risk Culture Important?

• Influences Decisions: Determines whether employees will report risks, ignore them,
or even take excessive risks.
• Enhances Effectiveness: When the risk culture is strong, risk management becomes
more effective because it is part of the daily operational fabric.
• Supports Objectives: Helps the organization achieve its strategic goals by consciously
managing risks and opportunities.
• Prevents Disasters: Many major corporate crises were the result of a weak or toxic
risk culture.

Risk Culture Maturity Stages

Risk culture typically evolves through several stages within an organization, from being almost
non-existent to becoming an integral part of the organization's DNA:

1. Initial / Ad Hoc:
o Characteristics: No real risk awareness or understanding. Risks are handled
individually and randomly after they occur. No clear policies or procedures.
Employees fear reporting errors or risks for fear of blame.
o Common Phrase: "We deal with problems when they happen."
2. Emerging:
o Characteristics: The organization begins to realize the existence of risks and the
importance of managing them, often after a significant adverse event or due to
regulatory requirements. Some basic policies and procedures are set, but the focus
is still on responding to risks rather than preventing them.
o Common Phrase: "We follow the rules to avoid problems."
3. Managed / Conforming:
o Characteristics: Risk management roles and responsibilities are clearly defined.
Risk management is integrated into some key processes. There is a better
understanding of the organization's risk appetite.
o Common Phrase: "We integrate risk management into how we operate."
4. Integrated / Advancing:
o Characteristics: Risk management becomes an essential part of strategic planning
and decision-making. Risks are identified proactively and continuously analyzed.
Innovation is encouraged within risk appetite limits.
o Common Phrase: "We use our understanding of risk to create value."
5. Optimized / Leading:

Page 83 of 94
o Characteristics: The organization is a leader in risk management. Risk culture is
deeply rooted and constantly adapts to changes. All employees are empowered to
be "risk managers." Risks are used as opportunities for continuous growth and
innovation.
o Common Phrase: "Smart risk-taking is part of our identity, and we learn and adapt
continuously."

Seven Key Attributes of Risk Culture (Based on RIMS Risk Maturity Model)
Attribute Translation and Meaning
1. Adoption of Measures the organization's risk culture and the support of executive
ERM-Based Process management and the Board for the ERM program.
Measures the organization's adoption of a unified methodology for
2. ERM Process risk management across its culture and decision-making processes,
Management and the efficiency of following the steps of identifying, assessing,
treating, and monitoring risks.
Evaluates the level of awareness of risk-return trade-offs, setting risk
3. Risk Appetite
tolerance limits, and the effectiveness in closing the gap between
Management
actual and potential risks.
Evaluates the extent to which the organization focuses on identifying
4. Root Cause
risks through their source or root cause instead of merely dealing
Discipline
with symptoms and outcomes.
Measures the quality and coverage of risk assessments, the method of
5. Uncovering Risks information gathering, and the ability to uncover enterprise-wide
trends and correlations.
Determines the organization's ability to execute its vision and
6. Performance strategy, and evaluates the strength of planning, communication, and
Management measurement of core organizational objectives using a risk-based
process.
7. Business Evaluates the extent to which a risk-based methodology is used in
Resiliency and business continuity planning, operational processes, and other
Sustainability sustainability activities.

Page 84 of 94
Module 5: Advanced concepts

• Success Factors for the Enterprise Risk Management Program Framework


• Risk Quantification

Success Factors for the Enterprise Risk Management Program Framework

To ensure the success of an Enterprise Risk Management (ERM) program, a set of essential
factors must be present to support the overall framework and guarantee its effectiveness. These
factors work together to create an environment capable of dealing with risks proactively and
systematically.

1. Commitment and Support from Senior Management

Explicit and clear commitment from senior management is the cornerstone of any successful
risk management program. When leadership believes in the program's importance and supports
its implementation, it sends a strong message to the rest of the staff that this is a top priority.
This support includes providing necessary resources, allocating budgets, assigning a
specialized team, and integrating risk management into business strategies.

2. Risk-Aware Corporate Culture

The program's success heavily relies on having a corporate culture that understands and
embraces collective responsibility for risk management. All employees, at different levels,
must recognize their role in identifying and reporting risks. This culture requires continuous
training and workshops to raise awareness, along with encouraging open communication about
risks.

3. Clear and Integrated Framework

The framework must be carefully designed to suit the organization's nature and size, covering
all types of risks it may face (financial, operational, strategic, compliance risks). The
framework must be integrated into daily operations and activities, not just a formal addition.
This framework includes defining the Risk Appetite, which is the level of risk the organization
accepts to achieve its objectives.

4. Continuous Risk Identification and Assessment

The risk management program is not a one-time process; it is a continuous cycle of identifying,
assessing, analyzing, and treating risks. There must be clear mechanisms for regularly
identifying new and emerging risks, and assessing their impact and probability of occurrence
using standardized tools and techniques. This continuous assessment ensures the organization
is aware of current and potential risks.

5. Effective Communication and Periodic Reporting

Effective communication is the lifeline of the risk management program. There must be clear
communication channels for disseminating risk-related information and providing periodic
reports to senior management and stakeholders. These reports must be accurate, transparent,

Page 85 of 94
and offer actionable insights into the organization's risk status and the effectiveness of
treatment plans.

6. Integration of Technology and Appropriate Tools

Using appropriate technology such as GRC (Governance, Risk, and Compliance) software
can make a significant difference. These tools facilitate data collection, analysis, report
generation, and systematic and effective risk tracking, which reduces human error and saves
time and effort.

In conclusion, the success of an ERM program lies in its nature as not just a set of procedures,
but an integral part of the organization's culture and daily operations, supported by the
commitment of senior management and the interaction of all employees.

Page 86 of 94
Risk Quantification

Risk Quantification is the process of converting identified risks into numerical values or
measurable quantities, instead of merely describing them qualitatively (such as "high" or
"low").

This analysis relies on available data, such as historical records, or on statistical estimates, to
estimate two key factors:

1. Probability: What is the likelihood of the risk occurring? (Example: 5%, 20%).
2. Financial Impact: What is the potential financial cost or loss if the risk occurs?
(Example: $50,000, $10 million).

Why is Risk Quantification Important?

• Objective Decision Making: It moves risk management from subjective assessment to


data-driven analysis. This allows leaders to make more rational and logical decisions.
• Risk Prioritization: It enables the organization to determine which risks deserve the
most attention and resources, based on their expected financial value, not just a general
feeling of their severity.
• Efficient Resource Allocation: It helps direct budgets and efforts toward the most
threatening risks, preventing the waste of resources on less impactful risks.

Risk Quantification Methods

1. Expected Monetary Value (EMV)

This is the most common method, used to estimate the total cost of the risk. It is
calculated by multiplying the value of the potential impact by its probability.

$$\text{EMV} = \text{Probability} \times \text{Impact}$$

Example:

o Risk: Probability of a production line breakdown.


o Probability: 10% (0.10)
o Impact (Financial Loss): $500,000
o Quantification (EMV): $0.10 \times \$500,000 = \$50,000$.

This means the expected cost of this risk is $50,000.

2. Sensitivity Analysis

Used to determine which project variables (e.g., raw material price, labor cost) have the
greatest impact on project objectives if they change.

Page 87 of 94
3. Monte Carlo Simulation

Considered one of the most complex and accurate methods. It uses mathematical
models to generate thousands of possible scenarios for a project or process, based on
random variables, providing a wide range of potential outcomes (such as minimum cost,
maximum cost, and the most likely average cost).

4. Decision Tree Analysis

This method represents possible decisions and their potential outcomes in a tree
diagram, helping to calculate the expected value of each course of action and determine
the optimal decision.

How is Loss Cost Calculated?

The potential cost of loss is calculated by analyzing all the direct and indirect financial
components that might result from the risk occurring. This analysis requires expertise in the
field and includes several factors:

1. Direct Costs:

These are clear and straightforward costs that can be easily tracked.

o Repair/Replacement Costs: Cost of spare parts and labor needed to repair or


replace a machine.
o Fines and Penalties: Any financial penalties that may be imposed due to
project delay.
o Additional Costs: Costs for urgent shipping of spare parts, or renting a
replacement machine.
2. Indirect Costs:

These are costs that are not immediately obvious but can be significantly larger than
direct costs.

o Lost Revenue: Revenue that was not generated due to the production line
stoppage or project delay.
o Idle Labor Costs: Wages of employees and workers whose work stopped due
to the machine breakdown.
o Loss of Company Reputation: Costs associated with losing customers or
damage to the company's reputation due to delays or failure to meet
commitments.
o Administrative Costs: Time and resources spent by management to resolve the
problem.

To estimate this value, the risk management team sits with experts from the relevant
departments (such as the maintenance team, finance team, and project manager) to estimate
each of these potential cost components, which are then summed to reach the total amount.

Page 88 of 94
What is the Difference Between Qualitative and Quantitative Risk Analysis?

Qualitative Risk Analysis (Risk Qualification)

Is the process of evaluating risks subjectively and classifying them into categories based on an
analysis of their likelihood and severity of impact. Precise financial figures are not used;
instead, it relies on the project team's experience and personal judgment.

• Methodology: A simple Risk Matrix is used to assess each risk on a scale of Low,
Medium, or High.
• Output: A descriptive classification of risks (e.g., High Risk, Medium Risk, Low
Risk).
• Goal: Quick prioritization of risks that warrant further attention.

Example: A project manager might qualitatively assess the risk of raw material delivery delay
as "High" because its likelihood is "Medium" and its impact on the schedule is "Severe."

Quantitative Risk Analysis (Risk Quantification)

Is the process of converting risks into numerical and objective values using statistical and
financial methods. It aims to estimate the potential financial impact of the risk with greater
precision.

• Methodology: Methods such as Expected Monetary Value (EMV) or Monte Carlo


Simulation are used.
• Output: A numerical value for the risk (e.g., $50,000, 10% loss).
• Goal: Providing a clear financial basis for decision-making and allocating budgets for
managing the most costly risks.

Example: Instead of saying the risk of raw material delay is "High," it can be quantified as
"10% probability of a loss of $50,000."

Qualitative Risk Analysis Quantitative Risk Analysis


Aspect
(Qualification) (Quantification)
Subjective, descriptive, relies on
Methodology Objective, computational, relies on data
experience
Classifications Numerical values (monetary amount,
Output
(High/Medium/Low) percentage)
Quick assessment and Accurate financial decision-making and
Goal
prioritization resource allocation

Page 89 of 94
References:
• Overview of Enterprise Risk Management The CAS Enterprise Risk Management
Committee.
[Link]
• Betty J. Simkins. Enterprise Risk Management John Fraser, 2009.
[Link]
• Enterprise risk management (ERM): An overview.
[Link]
• Enterprise risk management.
[Link]
• Enterprise Risk Management: Its Origins and Conceptual Foundation.
[Link]
• The Seven Deadly Sins of Enterprise Risk Management and How to Avoid Them.
[Link]
[Link]
• Enterprise Risk Management (ERM) Fundamentals.
[Link]
• Enterprise Risk Management for Health Care Boards Leveraging the Value.
[Link]
20Boards%20and%20Trustees_2022-[Link]
• Health Care Enterprise Risk Management Playbook, Second Edition.
[Link]
• ASRMS Enterprise Risk Management: Implementing ERM.
[Link]
for-Sucecess-White-Paper_FINAL.pdf
• ERM Quick Reference Tool.
[Link]
• Health Care Enterprise Risk Management Playbook, Second Edition.
[Link]
• COSO: Integrating with Strategy and Performance: Compendium of Examples.
[Link]
• David A. Hillson: A prominent figure in risk management who has developed a four-
level risk maturity model. [Link]
[Link]
• Risk Management Maturity Level Development, April 2002.
[Link]
[Link]/sites/785/uploads/6985/R
M_Maturity_Level_Development_200220150902-[Link]
• Risk Management: A Maturity Model Based on ISO 31000.
[Link]
_Model_Based_on_ISO_31000

Page 90 of 94
• Business Wargaming - Chris Paton. [Link]
wargaming-chris-paton/
• How should risk leaders of the future work with Artificial Intelligence (AI)?.
[Link]
with-ai__compressed.pdf
• IRM's risk management standard.
[Link]
• Cyber risk. [Link]
[Link].
• [Link]
• International risk management standards. From the cube to the rainbow double helix:
a risk practitioner’s guide to the COSO ERM Frameworks.
[Link]
[Link]
• Standard Deviations A Risk Practitioners Guide to ISO 31000.
[Link]
• From the cube to the rainbow double helix: a risk practitioner’s guide to the COSO
ERM Frameworks. [Link]
[Link]
• Fit for the future?. [Link]
report-25-10-16_final.pdf
• Risk management and the business model. [Link]
[Link]
• Risk Appetite Statements. [Link]
[Link]
• Risk appetite and tolerance (Executive Summary). [Link]
say/thought-leadership/risk-appetite-and-tolerance/
• Managing Cost Risk & Uncertainty In Infrastructure Projects.
[Link]
• Short Guide to Contract Risk Management.
[Link]
[Link]
• Short Guide to the Risk Management Process.
[Link]
• Short Guide to RAID. [Link]
• Short Guide to Artificial Intelligence (AI) in Risk Management.
[Link]
[Link]
• Short Guide to Effective Facilitation. [Link]
[Link]
• Short Guide to Risk Management Plans. [Link]
[Link]
• Short Guide to Assumptions Analysis (ABCD Technique).
[Link]

Page 91 of 94
• Sustainability in Infrastructure Short Guide to using the UN SDGs.
[Link]
• Guide To Overcoming Bias. [Link]
[Link]
• Risk culture Resources for Practitioners. [Link]
[Link]
• Competition law risk. [Link]
[Link]
• Risks in the extended enterprise. [Link]
[Link]
• Risk management for charities. [Link]
[Link]
• How to embed Emerging Risk identification and management.
[Link]
[Link]
• How to Assess and Treat Emerging Risks.
[Link]
[Link]
• An Introduction to Emerging Risks and how to Identify them.
[Link]
[Link]
• Technology and cyber security: Tackling the risks.
[Link]
[Link]
• Tools for stakeholder mapping. [Link]
[Link]
• Tools for providing assurance on regulatory compliance.
[Link]
[Link]
• An introduction to understanding and managing regulatory risk.
[Link]
• Risk governance for charities Risk management structures and accountabilities.
[Link]
• Setting your risk appetite: supplementary guidance.
[Link]
[Link]
• Establishing risk appetite. [Link]
[Link]
• IRM Charities SIG Risk Management Maturity Framework.
[Link]
[Link]
• Risk management for charities Getting started: supplementary guidance.
[Link]
• An introduction to understanding and managing regulatory risk.
[Link]

Page 92 of 94
• Risk culture Under the Microscope Guidance for Boards.
[Link]
• Risk management for charities Getting started: supplementary guidance.
[Link]
• RISK MANAGEMENT PERSPECTIVES OF GLOBAL CORPORATIONS.
[Link]
corporations_correct-covers_final.pdf
• Fuelling the debate Latest risk management trends in the energy sector 2019.
[Link]
• Professional Standards in Risk Management. [Link]
psrm-brochure_web.pdf
• How to hire a great Chief Risk Officer. [Link]
[Link]
• RISK MANAGEMENT FOR THE CONSUMER SECTORS.
[Link]
sectors_compressed.pdf
• SCENARIO APPLICATIONS: STRESS TESTING COMPANIES IN THE
ENERGY VALUE CHAIN. [Link]
companies-in-the-energy-value-chain_compressed.pdf
• Disruption, uncertainty and the role of risk management.
[Link]
[Link]
• COSO Enterprise Risk Management Framework
• Committee of Sponsoring Organizations of the Treadway Commission (COSO).
[Link]
• ISO 31000: Risk Management – Guidelines
• International Organization for Standardization (ISO) [Link]
[Link]
• OECD Corporate Governance and Risk Management Principles
• Organisation for Economic Co-operation and Development (OECD)
• 🔗 [Link]
• World Economic Forum – Global Risks Report
• Annual analysis of global strategic and operational risks
• 🔗 [Link]
• Institute of Risk Management (IRM) – Risk Management Standards and Insights
[Link]
• Harvard Business Review – Managing Risks: A New Framework
[Link]
• Deloitte Insights – Enterprise Risk Management
[Link]
• McKinsey & Company – Risk and Resilience Research
[Link]
• Business Wargaming, Chris Paton. [Link]
wargaming-chris-paton/

Page 93 of 94
• [Link]
process/#:~:text=The%204%20essential%20steps%20of,and%20Report%20on%20th
e%20risk.
• Benjamin Power, August, 2022. The Key(s) to Writing Good Risk Statements.
[Link]
writing-good-risk-statements
• 3 Components of an Effective Risk Statement.
[Link]
• Guide to Risk Statements. [Link]
secretariat/corporate/risk-management/[Link]
• Risk appetite and tolerance. Institute of Risk Management.
[Link]
• James Vesper, Ph.D., MPH, ValSource, LLC. What Are Risk Appetite & Risk
Tolerance In Pharma & Medical Devices?. February 23, 2022.
[Link]
pharma-medical-devices-0001

Page 94 of 94

You might also like