Risk Management Process Mastery Guide
Risk Management Process Mastery Guide
• What is Risk? (Definition, Types, The Difference between Risk and Opportunity).
• Risk Categories / Areas
• The Importance of Risk Management in the Modern Era. (Why do we need Risk
Management?)
• Risk Management and Strategy
Page 1 of 94
Module 1: Foundations of Risk
• What is Risk? (Definition, Types, The Difference between Risk and Opportunity).
• Risk Categories / Areas
• The Importance of Risk Management in the Modern Era. (Why do we need Risk
Management?)
• Risk Management and Strategy
What is Risk? (Definition, Types, The Difference between Risk and Opportunity).
Definition of Risk:
• Risk: The most globally accepted definition, especially in the field of management and
organizations, comes from the International Organization for Standardization (ISO) in
its standard (ISO 31000): The effect of uncertainty on objectives.
• Effect: Is a deviation from the expected.
o It can be positive, which is known as an "Opportunity" (achieving higher than
expected profit, finishing a project ahead of schedule).
o Or negative (financial loss, project delay, accident occurrence).
o Or both.
o It can address, create, or result in opportunities and threats.
• Uncertainty: Is the state of lacking complete information or understanding about an
event, its consequences, and its likelihood. If you are 100% sure something bad will
happen, it is not a risk; it is a "certainty" or a "current problem." Risk lies in the
lack of certainty.
• Objectives: Are the results you seek to achieve. These objectives can be at different
levels:
o Strategic: Such as increasing the organization's market share.
o Financial: Such as achieving a certain profit margin.
o Operational: Such as delivering a project on time.
o Personal: Such as safely reaching a destination.
• Risk Management: Coordinated activities to direct and control an organization with
regard to risk.
Illustrative Example
Suppose your objective is to "reach an important meeting in another city by car within two
hours."
• State of Uncertainty: There might be a traffic jam, the car might break down, or all
roads might be clear. You do not know for certain what will happen.
Page 2 of 94
Therefore, risk management is not just about avoiding bad things; it is a structured process for
understanding and managing "uncertainty" in order to protect your objectives and increase
your chances of success.
Page 3 of 94
How can Risk be an Opportunity or Positive?
Risk is not always negative; it can lead to the emergence of new opportunities, improvement
of organizational processes, service development, or enhancement of competitive advantage.
Leveraging risk positively depends on analyzing the situation and adopting innovative
solutions instead of fearing or avoiding them.
Page 4 of 94
3. Risk of Data Loss or Cyber Attacks
Page 5 of 94
The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)
sustainable competitive advantage in providing
specialized care.
Page 6 of 94
7. Risk of Failure in a New Infrastructure Project (Project Risk)
The Risk (Negative Effect) Conversion to Opportunity (Positive Effect)
Opportunity: Establishing an Internal Project
Risk: Delays or cost overruns in a
Management Office (PMO) Standard. The
project to build a new specialized
challenges and errors faced in this project are used as
unit (such as an oncology center),
an opportunity to establish a formal Project
harming the timeline and expected
Management Office (PMO) that sets strict
returns.
methodologies and standards for future projects.
Developing permanent internal capabilities in
project management, avoiding the recurrence of errors
in the future, and ensuring that future large
Positive Outcome: infrastructure projects are implemented with higher
quality and within the specified budget, thereby
transforming the hospital's ability to expand into an
organized competitive advantage.
Strategies for exploiting the opportunities inherent in risks are an advanced approach in risk
management, where the focus is not limited to avoiding or reducing them, but also involves
seeking out their positive side. Risk management strategies are divided into Accept, Enhance,
Share, or Exploit. Examples include:
Page 7 of 94
Benefits of Viewing Risk as an Opportunity
Consequently, risk is not always a negative thing; it may harbor opportunities for growth and
development for those who know how to read and utilize it wisely.
Page 8 of 94
Risk Classification:
Risks in the fields of management and insurance are classified into two main types based on
the potential outcomes: Pure Risk and Speculative Risk. Understanding the difference
between them is essential for correctly managing each type.
1. Pure Risk:
o These are risks whose potential outcome is only one of two: loss or no loss (the
situation remains the same). There is absolutely no possibility of achieving a profit
or gain from this type of risk.
o Characteristics:
▪ Outcome: Only two possible outcomes (loss or no loss).
▪ Objective: Cannot be used to achieve gains; they are undesirable events.
▪ Insurability: This type of risk can be insured, as insurance companies can
statistically calculate the probability of loss and estimate compensation.
o Examples:
▪ Fire: Either a fire occurs (loss) or it does not (no loss). A fire cannot lead to a
profit.
▪ Theft or Damage: Either your property is stolen or damaged (loss) or nothing
happens (no loss).
▪ Natural Disasters: Such as floods and earthquakes.
2. Speculative Risk:
o These risks can lead to a loss, no loss, or a gain. There is a chance for value addition
to the organization.
o Characteristics:
▪ Outcome: Three potential outcomes (loss, break-even, profit).
▪ Objective: They are taken with a conscious decision aiming to achieve a
financial return or gain.
▪ Insurability: Generally, this type of risk cannot be insured, as insurance
companies cannot calculate the probability of profit or loss as they do with pure
risks.
o Example: Expansion into a new service, such as 'Urgent Care,' in a competitive
area. This expansion can lead to gains (an increase in the number of referrals,
improved reputation) or it may lead to losses if it does not succeed, but there is
always an opportunity to achieve gains.
Page 9 of 94
Risk Classification: Pure Risk vs. Speculative Risk
Feature Pure Risk Speculative Risk
Only two: Loss or No Loss Three: Loss, No Loss (break-
Potential Outcomes
(break-even/status quo). even/status quo), or Gain/Profit.
Absolutely no possibility of There is a definite possibility of
Possibility of Gain
profit or gain. achieving a profit or gain.
Undesirable events; not Taken with a conscious decision,
Objective/Motivation
taken to achieve gains. aiming for financial return or gain.
Generally Non-Insurable. Insurance
Insurable. Insurance
companies cannot calculate the
Insurability companies can calculate the
probability of profit or loss in the same
probability of loss.
way.
Fire, Theft, Natural Investing in the stock market,
Disasters (floods, Launching a new product/service,
Examples
earthquakes), Car Expanding into a new market,
Accidents, Illness. Gambling.
Page 10 of 94
Risk Categories / Domains
Page 11 of 94
§ Risks may include:
• Capital, credit, interest rate, and foreign currency fluctuations
• Growth in programs, facilities, and capital equipment
• Regulatory fines and penalties
• Budget performance, billing and collection activities, accounts
receivable, and available cash
• Capitation contracts, reimbursement rates, managed care contracts,
and the revenue cycle/billing and collection.
Human Capital § Risks that relate to the organization's most valuable asset: its workforce.
§ Includes risks associated with:
• Staff selection, retention, turnover rate, recruitment, and
absenteeism
• Work-related injuries (worker's compensation), scheduling and
burnout, productivity, compensation, succession planning, and union
activity.
• Also, wrongful termination, sexual harassment, disruptive behavior,
discrimination, morale, diversity, employment practices, and breach
of contracts.
• Human capital risks may also cover the recruitment, diversity,
retention, and termination of medical and allied health staff
members.
Legal/Regulatory § Includes risks arising from licensing, accreditation, legislation, standards,
and regulations.
§ Risks in this domain include failure to identify, manage, and monitor
legal, regulatory, and legislative mandates at the local level. These risks are
generally related to fraud and abuse, licensing, accreditation, product
liability, and management liability.
Technology § Includes risks related to:
• Systems and Software: Risks related to information systems, such as
Electronic Health Records (EHR), billing systems, and social media.
• Cybersecurity: Significant risks arising from cyber threats, such as data
breaches or cyberattacks.
• Generally, technological risks include everything related to the use of
technology in the organization's operations, whether for clinical care
delivery, administration, or any other purpose.
Hazard / § This ERM domain covers assets and their value. Traditionally, insurable
Environmental environmental risks have been associated with exposure to natural disasters
and business interruption.
§ It can also include risks related to: Logistics/supply chain, facility
management, facility age, parking (lighting, location, security),
construction/renovation, earthquakes, windstorms, hurricanes, floods, fires,
and epidemics.
Page 12 of 94
The Importance of Risk Management in the Modern Era. (Why do we need Risk
Management)
We need risk management in the modern era because it is no longer just a preventative process;
it has become a vital strategic tool to ensure business continuity and achieve objectives in an
environment characterized by complexity and uncertainty. In a volatile and rapidly changing
world—often referred to as the VUCA world (Volatile, Uncertain, Complex, Ambigous)—
any unexpected event, whether a financial crisis, natural disaster, cyber-attack, or shift in
consumer behavior, can lead to devastating losses if not properly prepared for.
How Does Enterprise Risk Management (ERM) Effectively Help Achieve Strategic
Objectives?
The primary ways ERM supports the achievement of strategic objectives include:
Page 13 of 94
Risk Management and Strategy
Risk management is no longer a separate preventative process but has become an integral part
of the organization's core strategy. The relationship between them is integrative and two-way,
not merely one of dependence. This means that each influences and supports the other in crucial
ways, where Risk Management acts as a supportive tool for achieving the organization's
strategic goals, while Strategy helps guide how risks are managed. This relationship has
become central in the modern business environment characterized by complexity and rapid
changes.
1. Risk Management as a Strategic Support Tool (First Direction: From Risk to Strategy)
🛡️
• Protecting Value and Alignment with Objectives: It helps identify, assess, and
mitigate risks that could impede the achievement of strategic goals or lead to losses. If
the strategy of a hospital is to expand its specialized surgical services, ERM would
identify risks associated with this expansion (e.g., risks of surgical complications
beyond the norm, shortage of highly-skilled surgeons, or failure to obtain
accreditation for the new service).
• Supporting Decision Making: Risk management provides data and analyses that help
senior management make more informed and aware strategic decisions. For example,
when a healthcare system considers acquiring a smaller clinic in a new region,
potential risk analysis (e.g., financial risks related to payment models, or legal risks
from patient malpractice claims in the new region) provides a clear vision of threats
and opportunities, avoiding hasty decisions.
• Capitalizing on Opportunities and Protection from Disruptions: By identifying
potential risks (e.g., shifts in healthcare policy or the emergence of a highly effective
competitor in a niche service), ERM helps ensure the continuous execution of the
strategy even under unexpected circumstances.
2. Strategy as a Guide for Risk Management (Second Direction: From Strategy to Risk)
Page 14 of 94
strategies (like early adoption of experimental AI tools), while a traditional non-profit
hospital with a low-risk appetite would prefer more cautious growth strategies.
• Prioritizing Risks: Strategy helps identify the most critical risks based on objectives.
For example, if the strategy focuses on improving patient experience and outcomes,
risk management will prioritize clinical risks and patient safety events.
• Resource Allocation: Strategy directs how resources are allocated for risk
management, such as investing heavily in staff training on infection control
protocols or acquiring advanced cybersecurity technology to protect patient data.
Page 15 of 94
Module 2: The ERM Framework
It involves a systematic framework of practices, policies, and procedures that allow the
organization to proactively address a wide range of risks—including operational, financial,
compliance, legal, strategic, and reputational risks—across all business units and departments.
Unlike Traditional Risk Management (TRM), which tends to be siloed within individual
departments, ERM adopts a holistic, top-down view, ensuring effective coordination and
communication about all risks throughout the entire organization.
This approach enables healthcare leaders (and leaders in general) to achieve two main goals:
1. Value Protection: By reducing potential threats and losses, ERM ensures the
continuity of operations and the safety of assets.
2. Value Creation: ERM goes beyond mere protection to transform threats into
opportunities for growth. For example, instead of simply avoiding a new technology
risk, the organization might leverage that technology to develop innovative services
and gain a competitive advantage in the changing healthcare environment.
Page 16 of 94
The Difference Between Traditional Risk Management (TRM) and Enterprise Risk
Management (ERM)
Traditional Risk
Aspect Enterprise Risk Management (ERM)
Management (TRM)
Focuses on specific risks in Organization-wide, covering all types of
Scope
isolated departments (silos) risks
Proactive (before the incident), focuses on
Reactive (after the incident),
Approach the future, considers both risks and
looks to the past, avoids risks
opportunities
Risks are handled by individual Shared across the organization with
Responsibility
units or functions oversight from senior management
Fragmented and siloed, rarely Integrated into strategic planning and
Integration
aligned with business strategy operations
Value creation and protection; balances
Risk-averse, focused on
Mindset risks and rewards, seeks to optimally
minimizing negative outcomes
leverage uncertainty and opportunities
Standardized, often Dynamic, uses frameworks like COSO or
Methodology
compliance-driven ISO 31000
Types of Primarily focuses on Includes strategic, financial, operational,
Risks insurable/operational risks and reputational risks
The following illustrates the maturity stages of an ERM program and how it evolves from a
basic approach to an advanced one, with increasing efficiency in resource consumption.
1. Basic:
o At this stage, risk management is fragmented (separated) and focused on
protecting assets and value.
o Risks are identified "reactively" (i.e., after they occur).
o This level represents Traditional Risk Management (TRM), which focuses
on "pure risks" (loss-only risks).
Page 17 of 94
o Insurance is purchased as a means of risk management.
o Risks are seen in "silos" or isolated departments, and there is inconsistency in
risk management practices.
o The organization is "Risk Adverse."
2. Intermediate:
o The organization begins to collect and use data for decision-making.
o An understanding of Enterprise Risk Management (ERM) is developed.
o ERM strategies and tools are used for key risks at the unit or department level.
o The understanding of the relationship between different risks improves.
o A transition occurs towards "value creation" by identifying risk opportunities.
o "Micro ERM" is applied.
3. Advanced:
o The program becomes fully integrated, where "everyone is a risk manager."
o "Risk Appetite" and "Tolerance Statements" are developed.
o Risk-based decision analysis is used for making choices.
o An ERM framework and supportive governance are developed.
o ERM is a "Top-down, Bottom-up" process.
o Risks are identified "proactively."
o "Macro ERM" is applied.
o "Value is recognized."
Page 18 of 94
Roles and Responsibilities of Risk Managers in the Organization
Risk managers in organizations play a vital role in implementing the Enterprise Risk
Management (ERM) framework to ensure patient safety, regulatory compliance, and the
financial stability of the institution. Their key roles and responsibilities include:
In summary, the risk manager is a strategic individual who ensures that the organization not
only avoids problems but also leverages its understanding of risks to achieve its objectives and
improve the quality of care or service provided.
Page 19 of 94
Page 20 of 94
Risk Management Frameworks
There are numerous Enterprise Risk Management (ERM) frameworks that have already been
developed and published.
The most common ERM models are (COSO), (ISO 31000), and the (RIMS) Risk Maturity
Model.
Organizations can choose to adopt one of these frameworks when implementing an ERM
program or create their own framework.
Flexibility is important because the "one-size-fits-all" approach does not apply to Enterprise
Risk Management (ERM).
There is no single rigid ERM model or program that will work perfectly for every organization.
No single rigid ERM model or program will work perfectly for every organization. Here is why
flexibility is important in ERM:
In essence, ERM is not a rigid template but a flexible, tailored approach designed specifically
to fit the unique needs and characteristics of each organization. ERM must be dynamic and
adaptable to ensure its effectiveness in the environment in which it operates.
The healthcare sector is witnessing increasing adoption of ERM, guided primarily by the
COSO 2017 and ISO 31000 frameworks. Specifically, the ASHRM association supports
aligning ERM activities with the COSO 2017 framework because it integrates risk
management with strategy, governance, and the organization's overall performance. This
integration makes ERM more visible and acceptable to leaders, directly linking it to the
organization's mission, vision, and core values.
Page 21 of 94
Global Frameworks for Enterprise Risk Management
COSO 2017 Enterprise Risk Management Framework – Integration with Strategy and
Performance
The COSO ERM framework includes several core components or principles, such as: Internal
Environment, Objective Setting, Event Identification, Risk Assessment, and Risk Response.
These components help build an integrated risk management system that supports performance
improvement and ensures compliance with relevant standards and laws.
Furthermore, the framework provides a common language and clear guiding principles that
help organizations formulate and implement effective risk management policies and
procedures, with the possibility of linking risk management to governance and internal control
systems.
Applying the COSO framework benefits organizations by improving internal control, reducing
operational risks, supporting strategic decision-making, and enhancing risk disclosure and
management in an organized manner. Consequently, the COSO framework is a major and
globally recognized reference in ERM, helping organizations across all sectors build an
integrated and effective risk management system.
The COSO framework is divided into five core components and principles for Enterprise Risk
Management:
Page 22 of 94
Core Principles Under Each Component:
Governance sets the organization's tone, reinforces the importance of ERM, and establishes
oversight responsibilities. Culture relates to ethical values, desired behaviors, and
understanding of risk in the entity.
• Principle 1: Exercises Board Risk Oversight: The Board ensures effective oversight
of risk management.
• Principle 2: Establishes Operating Structures: Defining how the organization is
structured to support risk management.
• Principle 3: Defines Desired Culture: Formulating values and behaviors that promote
risk awareness.
• Principle 4: Demonstrates Commitment to Core Values: Applying ethical values in
all aspects of work.
• Principle 5: Attracts, Develops, and Retains Capable Individuals: Building a team
with the necessary competencies to manage risk.
Page 23 of 94
For an organization to succeed and create value, its culture must constantly reflect the core
values set by its leadership. A risk-aware culture is crucial, as it emphasizes transparent and
timely sharing of risk information without blame, fostering understanding, accountability, and
continuous improvement.
There is an integrated relationship between ERM, strategy, and objective-setting, as they are
not separate processes but work together within the strategic planning process. This is evident
in:
• Risks as Part of Strategic Planning: When setting an organization's strategy, risks are
not ignored but are considered from the outset.
• Defining "Risk Appetite": Before starting the strategy, the organization defines its
"Risk Appetite," which is the level of risk it is willing to accept to achieve its
objectives.
• Aligning Risk with Strategy: The risk appetite is then aligned with the strategy. The
chosen strategy must be compatible with the risk level defined by the organization.
• Objectives as Practical Tools: Once the strategy is set, "business objectives" are
established, which translate the strategy into practical, executable steps.
• Objectives as the Basis for Risk Management: These objectives become the
foundation upon which the entire risk management program is built.
3. Performance
The third component of the COSO framework, "Performance," focuses on the actual
application of the risk management process.
• Identify and Assess Risks: The organization must first identify and assess all risks that
could affect the achievement of its strategic and business objectives.
• Prioritize: After assessment, risks are ranked by their severity, considering the
organization's "Risk Appetite."
• Risk Response: The organization then selects appropriate actions to deal with each risk
(Avoid, Mitigate, Transfer, or Accept).
• Portfolio View: It is important for the organization to view all its risks as an integrated
whole, known as the "Portfolio View," which helps understand the organization's total
risk exposure.
By reviewing organizational performance, the organization can consider the efficiency of the
ERM components over time and in light of significant changes, and what revisions are needed.
ERM must be integrated into business practices with formal performance reviews. The Board
should oversee the continuous improvement of ERM's efficiency and utility.
ERM requires the continuous acquisition and sharing of necessary information, from both
internal and external sources, flowing up, down, and across the organization. Strategic
Page 24 of 94
decision-making relies on the deliberate transformation of valuable data into timely and well-
structured insights.
The ISO 31000 framework is a set of guidelines and instructions for risk management, not a
mandatory standard that requires certification. Its goal is to provide guidance to help
organizations integrate risk management into their operations and decision-making effectively.
It is general and comprehensive, meaning it can be applied to any type of organization,
regardless of its size, nature, or sector.
1. Principles: The foundation upon which effective and efficient risk management must
be built. Key principles include that risk management must be integrated into all
organizational activities, dynamic and adaptable, and based on the best available
information.
2. Framework: This component defines how risk management is integrated into the
organization's governance and leadership structures. It involves establishing, designing,
implementing, evaluating, and continually improving the risk management framework.
3. Process: This component describes the practical steps for managing any type of risk.
The process includes:
o Communication & Consultation: Exchanging information about risks with
concerned parties.
o Establishing the Context: Understanding the organization's internal and
external environment.
o Risk Assessment: Risk Identification, analysis, and evaluation.
o Risk Treatment: Making the necessary decisions and taking actions to respond
to risks.
o Monitoring & Review: Continuously tracking and reviewing risks and the
actions taken.
Page 25 of 94
Definitions (ISO 31000)
• Risk: The effect of uncertainty on objectives. The effect of risk is a deviation from
what is expected. This deviation can be positive, negative, or both, and can address,
create, or lead to opportunities and threats.
• Risks are expressed in terms of risk sources (an element with the potential, alone or in
combination, to cause risk), potential events, their consequences (outcomes of an
event affecting objectives), and their likelihood (the chance of something happening).
• Risk Management: Coordinated activities to direct and control an organization with
regard to risk.
The purpose of risk management is to create and protect value. It improves performance,
encourages innovation, and supports the achievement of objectives.
Page 26 of 94
6. Best available information: Inputs to risk management are based on historical and
current information, as well as future expectations.
7. Human and cultural factors: Human behavior and culture significantly influence all
aspects of risk management at every level and stage.
8. Continual improvement: Risk management is continually improved through learning
and experience.
Page 27 of 94
Framework (ISO 31000)
The purpose of the risk management framework is to help the organization integrate risk
management into critical activities and functions. The effectiveness of risk management
depends on its integration into the organization's governance, including the decision-making
process. This requires support from stakeholders, especially senior management, as leadership
support is the foundation of success.
Page 28 of 94
The Risk Management Process:
The risk management process involves the systematic application of policies, procedures,
and practices to the activities of: communication and consultation, establishing the
context, risk assessment, risk treatment, monitoring and review, recording, and
reporting. This process is illustrated in Figure 4.
Page 29 of 94
Comparison of ISO 31000-2018 and COSO Framework 2017
Element ISO 31000-2018 COSO Framework 2017
Committee of Sponsoring Organizations of
International Organization
Developer the Treadway Commission (COSO), primarily
for Standardization (ISO)
accounting and financial organizations
Global and flexible
Detailed framework focused more on
Scope framework applicable
governance and internal control
across all sectors
Approach Principle-Based Component-Based
On value creation and Integrating risk management with strategy and
Focus
organizational protection performance
Flexible and adaptable to More systematic and detailed with specific
Inclusiveness
the organization's needs components
Culture & Emphasizes leadership and Focuses on governance culture and the "tone
Behavior risk culture from the top"
Ultimately, the ERM framework (or set of frameworks) adopted by the organization must
include an integrated and holistic approach to identifying and managing risks, recognizing that
daily decision-making must include consideration of risks in relation to strategy, and that the
process must ultimately be about value creation and recognition.
• Pure Risk:
o Characteristics: Only two potential outcomes: loss or no loss. No potential for
gain.
o Example: Natural disasters like hurricanes. If a hurricane occurs, there is either
loss (property damage) or no loss, but the hurricane cannot lead to any financial
gain.
• Speculative Risk:
o Characteristics: Can lead to loss, no loss, or gain. There is an opportunity for
value addition to the organization.
o Example: Expansion into a new service like "Urgent Care" in a competitive
area. This expansion can lead to gains (increased referrals, improved reputation)
or losses if unsuccessful, but there is always a chance for gain.
• Acknowledging Gain: ERM doesn't just focus on protecting the organization from
losses but recognizes that some risks (Speculative) can create opportunities for gain
and value.
• Proactivity: Focuses on identifying risks proactively, not just responding to them after
they occur.
• Understanding Interconnectedness: Recognizes that risks do not exist in isolation but
are interconnected and affect the organization as a whole.
Page 30 of 94
Aligning Risk Appetite and Strategy
• Risk Appetite: Refers to the broad description of the desired level of risk the
organization will bear in pursuit of its mission.
• Risk Tolerance: Reflects the qualitative limit or range of risk to be endured in
pursuit of the strategy or to accept variations in outcomes.
Both are determined by the Board and Senior Management, integral to the strategic plan and
the ERM program, and vary significantly between organizations. They are usually articulated
through statements that include qualitative and quantitative metrics and require continuous
review and adjustment as the organization's strategy evolves.
Page 31 of 94
ASHRM ERM Framework & Guiding Principles
Guiding Principles
The following guiding principles were developed in collaboration with the mission and vision
of the American Society for Healthcare Risk Management (ASHRM) to serve as the
building blocks that support the Enterprise Risk Management (ERM) framework in
healthcare:
The ASHRM guiding principles form the logical basis for all decisions and actions of risk
managers in the health sector. Although strategies and objectives may change over time, the
philosophy of ERM in healthcare remains rooted in these fundamental principles.
Page 32 of 94
Promoting the Safety and Reliability of Healthcare
ASHRM's core purpose is to promote safe and reliable healthcare, aligning with the Institute
of Medicine's (IOM) report, "Crossing the Quality Chasm," which identified six aims for
improving healthcare delivery (STEEEP):
• Safe
• Timely
• Effective
• Equitable
• Efficient
• Patient-centered
Maximizing Value Protection and Creation: The Role of Risk Managers in Empowering
Leadership
This sustainable approach helps leadership understand interconnected risks, enabling them to
effectively assess both risks and opportunities at the operational levels. Ultimately, this
integration ensures the overall success and sustainability of the ERM program.
Integrity, honesty, and transparency are fundamental principles that must guide all
organizational levels and ERM leaders. These values ensure that ethical and trustworthy
strategic decisions are made, support the well-being of staff and patients, and enhance a
culture of readiness and success by building trust and engaging stakeholders.
Fair and Just Culture ⚖️ Traditional healthcare often blamed individuals for all errors. A
Fair and Just Culture, however, is different: it recognizes that individuals should not be
Page 33 of 94
blamed for system problems they cannot control. It also acknowledges that even skilled
professionals sometimes make mistakes and breach rules to facilitate. But a Fair and Just
Culture never tolerates reckless behavior or the deliberate disregard of obvious risks to
patients. It's about understanding and accountability, not merely assigning blame.
When any organization strives to achieve its strategic objectives, risks inevitably emerge. This
is where Enterprise Risk Management (ERM) plays its role as a tool for improving strategic
decision-making.
In summary, although the adoption of ERM is not yet complete in all healthcare organizations,
effective risk management is considered essential and crucial for sustainable success.
Risk Culture is the shared attitudes, behaviors, and understanding of risks—both positive and
negative—that influence management and employee decisions and reflect the organization's
mission, vision, and core values.
Governance and Culture are the cornerstones of effective ERM, ensuring its alignment with
the organization's mission and vision. A risk-valuing organizational culture promotes
transparency, accountability, and integrity, which is especially vital in the rapidly changing
healthcare environment, where governance helps discover new risks and opportunities.
To ensure effective oversight, it is essential that the governing body receives formal training
on ERM concepts and principles. This training aims to enable them to understand and define
the organization's risk profile and appetite, integrate risks with strategy, ensure clear
reporting and accountability, and evaluate the risk culture.
Today, strategic planning in healthcare has become a continuous process, with department
heads participating to evaluate performance, new projects, and their risks, while senior
leadership takes responsibility for setting priorities. In this context, the role of risk
professionals is increasing to become strategic partners, providing insights on emerging risks
and supporting the decision-making process.
Page 34 of 94
Module 3: Risk Management Process
The risk management process involves a systematic approach to identifying, assessing, and
managing risks across the enterprise. It is an integral part of Enterprise Risk Management
(ERM).
A variety of methodologies, tools, and resources are available to aid in identifying risks and
opportunities. Risk managers must focus on existing, identified risks as well as new and
emerging risks. Given the changing nature of healthcare, not all risks can be defined. Risks
can also evolve and change. Therefore, it is good practice to identify, review, and analyze risks
continuously and consistently.
Risk identification methods can be formal or informal, internal or external to the organization,
and retrospective or concurrent. This involves actively searching for, recognizing, and
describing risks. Methods can include interviewing key individuals, using questionnaires or
Page 35 of 94
surveys, brainstorming sessions, and engaging both internal and external stakeholders through
Focus Groups. Data analysis, trend identification, and research are also crucial for this step.
Enterprise risks can be identified using various methods categorized based on their nature
(formal or informal), source (internal or external), and timing (retrospective or proactive).
• Internal Sources: Focus on risks that arise from within the organization and can be
controlled.
o Examples:
▪ SWOT Analysis: Analyzing Strengths and Weaknesses.
▪ Operational Process Review: Analyzing errors in production lines or
customer service procedures.
▪ Financial Reports: Studying financial data to identify liquidity or debt
risks.
▪ Employee Interviews: Gathering opinions from staff about the
challenges and risks they face in their work.
▪ Historical Data Analysis: Reviewing records of past incidents, such as
system failures or workplace accidents.
• External Sources: Focus on risks that arise from the surrounding environment and
cannot be directly controlled by the organization.
o Examples:
▪ SWOT Analysis: Analyzing Threats and Opportunities.
Page 36 of 94
▪ Environmental Analysis (PESTEL)
▪ Market and Competitor Analysis: Monitoring competitor movements,
consumer trends, and market changes.
▪ Tracking Political and Legal Changes: Monitoring new laws,
environmental regulations, and trade policies.
▪ Economic Analysis: Studying inflation rates, interest rates, and their
impact on the organization's investments.
Brainstorming
Brainstorming is a very common risk identification technique.
While it can be done casually, in a risk management context, it's almost always a planned,
structured meeting (like the "Risk Identification Workshops" you listed). It involves key
stakeholders, has a set agenda, and the results (the identified risks) are documented in a
formal output, such as a risk register.
The identification process relies on the knowledge, experience, and creativity of people inside
your organization (managers, employees, subject matter experts). Even if you are
brainstorming external risks (like new regulations or competitor actions), the source of the
information is your internal team.
Page 37 of 94
3. Retrospective vs. Proactive Source
Its entire purpose is to look forward and think about what might happen in the future. You are
trying to identify potential risks before they occur, which is the definition of a proactive
approach.
Triggering Questions:
These questions focus on how risks can affect your organization's highest-level goals.
• What are our main business objectives for the next year, and what could prevent us
from achieving them?
• What are our most valuable assets (e.g., intellectual property, data, reputation) and
what could happen to them that would result in a significant loss?
• What major assumptions are we making about our market, competition, or resources?
What happens if these assumptions are wrong?
• What keeps you up at night regarding this project or business unit?
• How do we know if we are achieving our objectives? What information are we most
reliant on?
These questions target day-to-day activities and the potential for process failures.
• What are the most complex or difficult activities we perform? What could go wrong
with them?
• What steps in our core processes rely on a single person or a small group of people?
• Where are the handovers between departments or teams? Is there a risk of
miscommunication or failure at these points?
• What must go right for us to succeed, and how could these things fail?
• What are the most common workarounds or manual fixes in our processes? Are these
a sign of a larger, underlying risk?
Page 38 of 94
Human resources and people-related questions
These questions address risks related to your employees and organization's culture.
• What recent changes in regulatory policy have occurred in our industry? Do any of
them apply to us?
• Are there any legal or licensing requirements that apply to our products or services?
• What emerging external threats (e.g., new competitors, economic downturns) could
impact our business?
• What are the environmental or social risks associated with our operations?
• How might public perception or a social media incident affect our reputation?
Page 39 of 94
Questions about vulnerabilities and dependencies
Page 40 of 94
The key to writing a good risk statement
Writing a clear and effective risk statement is one of the most critical steps in the entire risk
management process. A poor statement leads to confusion, while a good one makes analysis
and response planning much easier.
A weak risk statement just names a topic (etc."Server Failure"). A strong risk statement
explains why it might happen and what the "so what" is.
Here is the most common and effective structure. Think of it as a single sentence with three
parts:
1. [THE CAUSE] The definite event or existing condition why the risk might happen.
2. [THE RISK] The uncertain event that may or may not occur.
3. [THE IMPACT] The consequence or effect on your objectives (e.g., on cost,
schedule, safety, or quality) if the risk happens.
"Due to... [Cause], there is a risk of... [Risk Event], which could result in...
[Impact/Consequence]."
Indicators of a good, quality risk statement are that it can answer the following
questions:
Page 41 of 94
Examples: Bad vs. Good Risk Statements
Let's look at how this formula transforms vague problems into actionable risk statements.
Here are examples of good vs. bad risk statements across the main healthcare risk domains.
The key difference is that bad statements are often vague, broad topics, or issues that have
already happened. Good statements are specific and actionable, following the Cause → Risk
→ Impact formula.
Page 42 of 94
Clinical & Patient Safety Risk
This domain relates to harm or potential harm to patients during the delivery of care.
👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement
Operational Risk
This domain relates to failures in the day-to-day internal processes, people, and systems.
👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement
Page 43 of 94
Financial Risk
This domain relates to the financial health and stability of the organization.
👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement
This domain relates to the workforce (recruitment, retention, training, and well-being).
👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement
Page 44 of 94
Technological (IT) Risk
👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement
Due to a lack of a redundant power supply for the main data center
(Cause), there is a risk that a city-wide power outage will cause a total
EHR
EHR system failure (Risk Event), which could result in staff reverting
downtime
to paper charts, leading to lost billing, medication errors, and an
inability to access patient histories (Impact).
This domain relates to non-compliance with laws, regulations, and accreditation standards.
👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement
Page 45 of 94
Strategic Risk
This domain relates to high-level decisions that affect the organization's long-term goals and
viability.
👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement
This domain relates to the physical environment and external hazards (e.g., fire, flood,
utilities).
👎 Bad
👍 Good Statement (Cause → Risk → Impact)
Statement
Page 46 of 94
🔑 Key Tips for Writing Risk Statements
• Be Specific, Not Vague. "Supplier delay" is vague. "XYZ Corp. delaying the server
shipment by 6 weeks" is specific.
• Focus on One Risk. Don't bundle multiple risks into one statement (e.g., "fire, flood,
or theft"). Write a separate statement for each.
• It Must Be Uncertain. If it has already happened or is 100% certain to happen, it is
an issue, not a risk.
• Connect to Objectives. The impact should always relate to what your organization or
project is trying to achieve (e.g., patient safety, budget, timeline, reputation).
Once you have a well-written risk statement, you can then properly analyze its probability
and impact, which is the necessary next step before you can select a response.
Page 47 of 94
Risk Analysis (What is the probability of it happening and what is the magnitude of its
impact?)
• Analysis: Is determining the potential severity of loss associated with specific risks, the
probability/frequency of that loss occurring, and the severity/impact of that loss.
• Risk Assessment and Modeling: Once risks are identified, they are analyzed to understand
their characteristics, such as correlations and interdependencies. This involves assessing
the probability of the risk occurring and the potential severity/impact if it does happen.
Various tools can be used for this assessment, such as risk scales, risk curves, and risk
matrices. The process also distinguishes between Inherent Risk (risk before controls are
applied) and Residual Risk (risk remaining after controls).
• Risk Scoring / Ranking:
o Formula: Probability times (×) Severity/Impact} = Risk Ranking/Score
o Probability Scale: 1 (Lowest) to 5 (Highest)
o Severity/Impact Scale: 1 (Lowest) to 5 (Highest)
• Risk Map/Risk Matrix:
o The Risk Map/Heat Map/Risk Matrix graphically displays the assessed risks according
to the risk ranking, as shown in the figure.
o This visual representation is especially useful in meetings and status reports because it
provides a quick snapshot of the organization's risks according to probability and/or
likelihood and impact.
Page 48 of 94
Risk Scales
Page 49 of 94
Factors Influencing Probability
1: Rare 2: 5: Almost
3: Possible 4: Likely
Factor (Very Unlikely Certain (Very
(Moderate) (High)
Low) (Low) High)
At least
one
No
similar
known No
incident
incidents incidents 1-2 near- Multiple similar
or
Historical or near- or near- misses in the incidents have
multiple
Data misses at misses in last 12-24 occurred in the
near-
this the last 2- months. last 12 months.
misses in
facility in 5 years.
the last
> 5 years.
12
months.
Standard, High-
Simple,
non- Standard risk,
non-
invasive, invasive or complex A novel,
invasive,
multi- complex interventi emergent, or
Procedure single-
step multi-step onal or extremely high-
Complexit step
procedur procedure surgical risk procedure
y procedur
e (e.g., (e.g., central operation being performed
e (e.g.,
dispensin line (e.g., under pressure.
taking
g oral insertion). cardiac
vitals).
meds). bypass).
Unit is
Unit is Meets Staffed
fully
fully minimum below
staffed
staffed staffing minimum Critically
with a
with ratios, but ratios; understaffed;
Staff mix of
experienc has some high staff are floated
Experienc new and
ed, senior new/float reliance from other units
e senior
staff. All staff or on with known
staff. All
competen minor agency or competency gaps.
competen
cies are competency float
cies are
met. gaps. staff.
met.
Page 50 of 94
1: Rare 2: 5: Almost
3: Possible 4: Likely
Factor (Very Unlikely Certain (Very
(Moderate) (High)
Low) (Low) High)
New,
fully
Mid- Mid- Older
maintaine
lifecycle lifecycle equipmen
d
equipmen equipment, t with Equipment is old,
equipmen
t, >95% >90% known known to be
Equipmen t with
maintena maintenance minor faulty, or has
t built-in
nce compliance, faults or critical overdue
Reliability redundan
complian but has some maintenance/cali
cy. 100%
ce. No known overdue bration.
calibratio
known single points maintena
n
issues. of failure. nce.
complian
ce.
Good
Cramped,
Modern, design,
high-
well- managea Older unit,
traffic
designed ble some Poorly designed,
unit,
unit, low workflow workflow/sp chaotic unit with
Environm known
noise, , meets ace known,
ental workflow
good all challenges, unaddressed
Factors issues,
workflow infection but meets workflow and IC
minor/rep
, exceeds control minimum IC violations.
eat IC
standards (IC) standards.
deviation
. standards
s.
.
Known
Full Full
General non-
complian complian
compliance, complian
ce, ce with Known major
Regulator with only ce in
considere all non-compliance;
y minor some
d a "best required currently under a
Complianc recommenda areas;
practice" standards corrective action
e tions for repeat
in all and plan or cited.
improvemen minor
recent guideline
t. findings
audits. s.
in audits.
Page 51 of 94
Risk Severity and Impact Matrix:
- Significant
- Cash - Death /
deterioratio
Liquidity: Permane
- Major labor n of brand - Loss of
Leads to 20 nt
relations event and major License
days of disabilit
market
available cash y
share loss
- Event: - Workplace
-
Suicide / Safety: Multiple -
- Property Continuous
Rape / time-loss Government
damage: negative
Child injuries / al/Federal
Critic $250,000 media
abductio Recordable Investigation
5 al coverage
n incidents
()حرج
- Breach of
Personal Health
Information - Customer
- Loss of a key
(PHI) / Private Satisfaction:
contract
Information for < 85%
more than 100
people
- Loss of
business
-
Docume
nted
incident - Temporary -
of but Government
- Cash - Significant
boundar significant al/Federal
Liquidity: loss/turnover of
y negative Inquiry (not
$150,000 key personnel
violation media investigation
Major
4 or code coverage )
()عالية
of
conduct
breach
- Property
- Major - Customer
damage: - IT system
or Satisfaction:
$100,000 to failure
critical 85-88%
$250,000
Page 52 of 94
Rati Patient Operations / Legal /
Impac
ng Financial Safety Process Reputation Regulatory
t-
(التقييم ()مالية ( سالمة ( / العمليات al ()سمعة ( / قانوني
التأثير
) )المرضى )اإلجراءات )تنظيمي
health
incident
- Non-
- Workplace
- Need for complia
Safety: Time-
unexpected nce with
loss and
additional the
recordable
capital standard
incidents
of care
- Breach of
Personal Health
Information
(PHI) / Private
Information for
up to 100
people
- - Corporate
- Negative
Increasi - Loss or non-
- Cash mention in
ng trend increased compliance
Liquidity: media
in minor turnover in key with
$50,000 (state/region
health positions financial
Mode al level)
incidents impact
rate
3
(متوسط
- Operational
)ة - Lack -
- Property disruption or
of - Customer Ramification
damage: increased cost
clinical Satisfaction: s for
$10,000 to due to
continuit 88-90% insurance
$100,000 regulatory
y access
change
- Minor
health
incidents - Minor
- Cash - Customer
(patient - Staff base violations
Liquidity: Satisfaction:
is distraction (e.g., auto
Minor $10,000 90-94%
unaware incidents)
2 (منخف
of the
)ضة
error)
- Property
damage:
$10,000
Page 53 of 94
Rati Patient Operations / Legal /
Impac
ng Financial Safety Process Reputation Regulatory
t-
(التقييم ()مالية ( سالمة ( / العمليات al ()سمعة ( / قانوني
التأثير
) )المرضى )اإلجراءات )تنظيمي
Insign
ificant - Minor
- No
(منخف property - Customer
impact
1 ضة جدا damage or - Satisfaction: -
on care
غير/ impact on > 95%
delivery
جوهرية cash liquidity
)
Page 54 of 94
Inherent Risks and Residual Risks
Inherent Risk is the baseline level of risk without any mitigation efforts.
Target Residual Risk is the desired level of risk that the organization wants to have after
implementing risk management measures.
Actual Residual Risk is the risk that remains after those measures have been taken.
Ideally, the Actual Residual Risk should be at or below the Target Residual Level. If it is higher,
the organization needs to define additional risk reduction strategies. Healthcare organizations
use various proactive processes to reduce inherent risks, such as network vulnerability
assessments, risk assessments for new services or equipment, electronic controls, auditing,
system backups, structured communication, disaster plans, engineering controls, and
equipment maintenance schedules.
Risk
Risk Evaluation Suggested Action
Rating
1-3 Low Risk Accept Risk, Maintain Existing Control
4-6 Medium Risk Accept Risk, Review Existing Control
Management Action Required: Improve existing
8-12 High Risk
Control
Immediate Senior management action required,
15-25 Critical Risk
stop activity, Improve existing control measures.
Page 55 of 94
2. Examining Risk Treatment Techniques / Methods
Avoidance (Avoid):
Risk avoidance is a strategy where the organization takes decisive action to completely
eliminate a risk by stopping the activity that causes it. It is the only risk control technique that
can reduce the probability of a specific loss to zero. This strategy is typically chosen when no
other response can reduce the risk to an acceptable level.
Primary Indication: Used for "Extreme" or "Critical" risks, typically those with both a
high likelihood and a catastrophic impact.
• When the risk's potential negative consequences are so severe (e.g., mass patient harm,
total business failure, massive legal penalties) that no other treatment is acceptable.
• When the cost of mitigating the risk to an acceptable level is prohibitively expensive or
complex, and the activity is not essential.
• When the risk falls completely outside the organization's strategic goals and risk appetite.
Treatment: They choose Avoidance by deciding not to open the new unit.
Page 56 of 94
Acceptance or Retention:
This is a conscious, documented decision to take no action to treat the risk, accepting the
potential consequences.
• Primary Indication: Used for "Low" risks, where both the likelihood and impact
are small.
• When to Use It:
o When the risk is within the organization's defined "risk appetite."
o When the cost of implementing a control (cost, time, resources) is greater than
the potential loss from the risk.
o When the risk is so insignificant that it is not worth the effort to treat.
• Healthcare Example: A hospital's risk register notes that the paint in a rarely used
basement storage closet is chipped. The impact is "Insignificant" (minor aesthetic
issue) and the likelihood of anyone being harmed is "Rare."
• Treatment: They choose Acceptance. They formally document the risk and the
decision, and agree to simply monitor it, as the cost of repainting is not justified by
the tiny risk.
Risk Acceptance: Involves acknowledging and accepting the potential consequences of a risk
without taking any additional action to mitigate or transfer it.
Risk Retention: Involves bearing the potential losses associated with a specific risk and
establishing plans to cover any financial consequences of those losses. This response is
appropriate when the risk already falls within the organization's defined "risk appetite." If
management wishes to accept a risk that exceeds this appetite, approval from a higher authority,
such as the Board of Directors, is usually required. When an organization accepts or retains a
risk, it agrees to cover any resulting financial losses with its own internal funds, meaning the
financial exposure is not transferred to another party, such as an insurance company.
Transfer or Share:
Risk Transfer: Is a strategy to reduce the severity of a risk by shifting a portion of its financial
obligation to a third party. This action reduces the residual risk to a level aligned with the
organization's "risk appetite."
This strategy involves shifting the financial burden or liability of a risk to a third party. It
does not eliminate the risk itself, but it protects the organization from its financial impact.
Page 57 of 94
• Primary Indication: Used for risks with a low probability but a very high financial
impact, or for risks that require highly specialized management.
• When to Use It:
o When the risk's potential financial cost is catastrophic but manageable for a larger
entity (like an insurer).
o When a third party has more expertise in managing the risk (e.g., outsourcing
cybersecurity).
o When it is more cost-effective to pay a premium (for insurance or an outsourced
service) than to manage the risk internally.
• Healthcare Example: A hospital faces a low-likelihood risk of its main building
being destroyed by an earthquake. The financial impact would be catastrophic.
• Treatment: They cannot avoid or mitigate the earthquake. They choose Transfer by
purchasing a comprehensive property insurance policy. If the event occurs, the
financial loss is transferred to the insurance company.
Risk Mitigation:
Risk mitigation is a strategy that focuses on preparing for and reducing the negative effects
of potential threats and disasters on the organization. It is comparable to "risk reduction" and
involves taking active steps to lessen the impact of a risk.
This is the most common strategy. It involves implementing controls or actions to reduce the
risk's likelihood or impact (or both) to an acceptable level.
• Primary Indication: Used for "High" or "Medium" risks that are central to the
organization's objectives and cannot be avoided.
• When to Use It:
o When the risk is a core part of your operations (e.g., you can't avoid performing
surgery, but you can mitigate the risks involved).
o When the risk is at an unacceptable level, but a cost-effective control exists to
reduce it.
o When required by law or regulation (e.g., patient safety standards, infection
control protocols).
• Healthcare Example: A hospital identifies a "High" risk of patient falls on a specific
ward.
Page 58 of 94
• Treatment: They cannot avoid admitting patients. Instead, they choose Mitigation.
They implement a new fall-prevention bundle: new non-slip flooring, hourly patient
rounding, bed-exit alarms, and staff training. This reduces the likelihood of falls.
Key Techniques used in Risk Mitigation: Risk prevention, reduction, and segregation. After
implementing these measures, some risks may still remain, which the organization may
formally accept.
• Risk Prevention: Risk prevention techniques affect the frequency or number of times
an event will occur. They do not eliminate the probability, but they reduce the
likelihood of the risk occurring.
• Risk Reduction: Risk reduction techniques reduce or lessen the loss once the event has
actually occurred. For example, having emergency preparedness plans is a risk
reduction technique because once a disaster occurs, the preparedness plans will help
minimize any further losses and mitigate the impact of those that have already occurred.
• Risk Segregation: Segregating exposure units reduces loss uncertainty by increasing
the predictability of both loss frequency and severity. Segregation of exposure units can
take one of two forms:
1. Separation: Dividing an asset or process that could be stored or performed in
one location among two or more separate locations. An example is having a
travel policy that states the maximum number of Board members or senior
leaders allowed to travel together to avoid a catastrophic event involving
multiple Board members, senior leadership, or clinical staff.
2. Duplication: Involves replicating an asset or facility. Examples include backup
disks, cloud storage, duplicate keys, and double-checking of medication
administration.
Extreme / Critical
"Is this risk so catastrophic that we should
Avoidance ↑ High Probability + ↑ not do this activity at all?"
High Impact
Low
"Is the cost of treating this risk more than
Acceptance ↓ Low Probability +
the cost of the risk itself?"
↓ Low Impact
Page 59 of 94
HIERARCHY OF RISK CONTROLS:
• Elimination: Removing the hazard (the potential source of harm) or the target (the
person or entity exposed to the risk) is the most robust response. If the hazard is entirely
eliminated, there is no chance for it to cause harm. An example is closing a low-volume
surgical program that does not provide sufficient practice for surgeons to maintain
competency. This essentially transfers the risk to another organization. This example
can also be considered target elimination, as patients at risk of harm from that surgery
will not be seen by this institution.
• Engineering Controls: Anything other than elimination that does not rely on people
doing the right thing. These include strategies such as physical barriers, isolation,
forcing functions, human factors/ergonomics engineering, and fail-safe design.
Examples might include placing a second set of locked doors between a locked
psychiatric unit and the rest of the hospital, or computerized physician order entry
systems that include a "hard stop" to prevent a ten-fold overdose of high-risk
medications.
• Administrative Controls: Motivate people to improve safety by doing the right thing.
These include policies, procedures, training, signage, alarms, and other controls that
rely on people taking the intended action. Although they are the least robust category
of risk response, healthcare organizations have historically focused most of their risk
response efforts on administrative controls.
First, predict the effects that the available risk management options are likely to have on the
organization's ability to achieve its objectives. Second, identify and apply criteria that measure
how well each alternative risk ranking technique contributes to each organizational objective
in cost-effective ways.
Evaluation Criteria:
"This is unacceptable."
Page 61 of 94
4. Implementing the Selected Treatment Techniques/Methods
Implementing the selected techniques requires attention to the technical risk management
decisions that the risk professional must make and the administrative decisions that must be
made in collaboration with other managers across the organization to execute the chosen
techniques.
The risk management program is monitored, evaluated, and improved to measure and assess
the effectiveness of the techniques used to identify, analyze, and treat risks.
This involves continuous tracking of identified risks, the effectiveness of risk responses, and
the organization's overall risk profile. Metrics, measures, and targets are established to gauge
performance. This ensures that risk is managed within the organization's defined "risk
appetite" and tolerance levels.
The risk management process is iterative and dynamic, requiring regular review and
adjustment. As the organization's strategy, objectives, and environment change, the risk profile
evolves, necessitating continuous learning and adaptation of risk management practices. This
systematic approach, which goes beyond traditional reactive methods, allows healthcare
organizations to proactively manage risks, seize opportunities, and align risk management with
strategic objectives to protect and create value.
Risk Register
The Risk Register is an essential and critical document in the Enterprise Risk Management
(ERM) program. It is a centralized record of all potential risks that may affect the
organization's objectives. The Risk Register is not just a list; it is a dynamic tool used to
systematically document, analyze, track, and monitor risks.
A Risk Register typically includes the following information for each identified risk:
• Risk Name: A brief and clear description of the risk (e.g., "Loss of sensitive data due
to a cyber-attack").
• Risk Description: A more detailed explanation of the risk, clarifying its nature,
potential causes, and potential effects on the organization.
Page 62 of 94
• Risk Category: Classification of the risk within defined categories (e.g., Financial,
Operational, Strategic, Legal, Technology).
• Risk Owner: The person or department responsible for managing and following up on
this risk.
• Likelihood: Assessment of the probability of the risk occurring.
• Impact: Assessment of the magnitude of harm or effect that will occur if the risk
materializes (Financial, Reputational, Operational).
• Risk Score: The result of calculating the Likelihood multiplied by the Impact. This
helps in prioritizing risks.
• Current Response: The actions currently being taken by the organization to control
this risk.
• Mitigation Plan: Additional planned actions to reduce the probability or impact of the
risk.
• Review Date: The last time this risk was reviewed and assessed.
The Risk Register is the backbone of the ERM program for the following reasons:
In summary, the Risk Register is a practical tool that helps transform risk management from a
reactive process into a proactive and systematic one.
Date of
Risk Impact Overal Rank
Risk Likelihoo
Ris Descriptio Risk Severit l risk (Critical -
Risk identifie Affected االرتباط d
k n& Categor y Rating High -
identifie d Departme Cause االحتمالية باألهداف
ID / Impact y التصنيف التأثيرMedium –
d تاريخ nt s االستراتيج (L)
Ref وصف فئة (S) اإلجمالي Low -
المخاطر التعرف القسم ية Score (1-
: المخاطر المخاطر Score R=L Insignifican
على 5)
واألثر (1-5) S t)
المخاطر
Page 63 of 94
Risk Appetite and Strategy
The concept of "Risk Appetite" can be confusing for healthcare risk managers who have
traditionally been trained to consider all risks undesirable and to be avoided. However, in the
context of Enterprise Risk Management (ERM), Risk Appetite is defined as the total
amount and type of risk that an organization is willing to accept in the pursuit of value.
It acknowledges that taking calculated risks is essential for growth, adding new services,
adopting modern technologies, and ultimately, progressing toward the organization's mission.
An organization's risk appetite is shaped by factors such as its history, culture, and financial
stability. It reflects a strategic agreement between senior leadership and the Board of Directors
on the acceptable level of risk, considering the entity's resources and capabilities.
The Relationship between Risk Appetite, Risk Capacity, and Risk Tolerance
Organizations constantly balance the risks they undertake with the potential rewards of their
strategic goals. This balance is heavily influenced by the organization's culture, whether it is
"risk-averse" or "risk-seeking." The following interconnected concepts distinguish between
three fundamental notions in ERM:
• Risk Capacity: This is the maximum amount of risk an organization can absorb
without compromising its ability to meet its obligations or sustain itself. It is influenced
by tangible factors such as financial size, cash position, and asset liquidity.
• Risk Appetite: Refers to the amount of risk the organization is willing to accept to
protect and create value under uncertainty in achieving its objectives. The
organization's appetite is usually set below its total capacity to maintain a safety margin.
• Risk Tolerance: Defined as the amount of risk exposure or potential adverse events
that the organization is willing to endure while pursuing its objectives.
The primary goal of ERM is to maintain strategic alignment among these three elements,
ensuring that current risks (Risk Profile) plus the desired additional risks (Appetite) do not
exceed the organization's maximum ability to absorb loss (Capacity).
Page 64 of 94
Defining and Formulating Risk Appetite
• There is no single universal approach to defining risk appetite. The process begins by
analyzing the organization's current risk profile in relation to its risk capacity.
• Process: This should involve high-level discussions between senior leadership and
the Board of Directors, taking into consideration past and current objectives and the
potential impact on key stakeholders.
• Formulation: Formulating the risk appetite statement is a flexible process, but the most
important characteristic is that the statement must be linked to the organization's
overall strategy, mission, and values.
The RAS provides a clear boundary for risk-taking, serving as a guide for decision-making at all
levels of the organization. It includes qualitative and quantitative measures to define acceptable
Page 65 of 94
risk levels, ensuring consistency and transparency in managing risk across various departments
and functions.
Formulating risk appetite is a top-down process that links your strategy to your daily
operations. Here are the key steps.
You cannot define your risk appetite in a vacuum. It must be directly tied to what you are
trying to achieve.
• Ask: "To achieve our goal (e.g., 'become the #1 cardiac center'), what risks must we
take, and what risks must we avoid?"
• Example: To be #1, we have a high appetite for investing in new, unproven surgical
technology (Technological Risk) but an extremely low appetite for any harm to
patients (Clinical Risk).
You don't have one "risk appetite." You have multiple appetites for different types of risk.
Use your risk domains to break it down.
For each category, assign a qualitative statement. This is the core of the "Appetite
Statement." Most organizations use a simple scale.
Page 66 of 94
Adapted from Quail (2012)
This is where you make the qualitative appetite measurable. The risk tolerance puts hard
numbers on your appetite statement.
Setting quantitative risk tolerances is the most critical step to make a risk appetite actionable.
It translates the high-level, qualitative philosophy (e.g., "We are Averse," "We are Cautious")
into specific, measurable, and non-negotiable boundaries.
• Appetite is the statement: "We have an Averse appetite for patient harm."
Tolerance is the number: "Therefore, we will tolerate zero (0) sentinel events."
• Appetite is the statement: "We have a Cautious appetite for operational downtime."
Tolerances are the triggers. When a tolerance is breached, it signals to management that the
organization is operating outside its desired appetite, requiring an immediate response.
Page 67 of 94
Here is one example of a Risk Appetite Statement for a hospital, which integrates this entire
framework.
Our mission at [Example Hospital] is to provide safe, innovative, and high-quality care to our
community. To achieve this, we must thoughtfully balance risk and opportunity. This
statement defines the amount and type of risk we are willing to accept (our Appetite) to
achieve our strategic objectives.
We empower our staff to innovate and improve, but we will not pursue any opportunity that
compromises our commitment to patient safety, regulatory compliance, or community trust.
This statement serves as a guide for all management in strategic planning and daily decision-
making.
We define our appetite for risk across five levels, which are applied to our major risk
domains.
Page 68 of 94
3. Risk Appetite & Tolerances by Domain
The following table maps our philosophy to measurable tolerances (Key Risk Indicators -
KRIs).
Page 69 of 94
Appetite Level Quantitative Risk Tolerances
Risk Domain Guiding Rationale
(Philosophy) (The Measurable Limit)
months if strategically
approved.
The final Risk Appetite Statement (a document combining the qualitative statements and
quantitative tolerances) must be approved by the board. It should then be communicated to all
managers so they can make decisions.
This is not a "set it and forget it" document. It must be reviewed annually, or whenever the
organization's strategic objectives change.
Page 70 of 94
Module 4: Risk Governance and Culture
The Board of Directors holds the ultimate responsibility for risk management. Its role is not
limited to approving strategies but includes:
• Setting the Vision: Establishing the organization's Risk Appetite, defining the level
of risk the organization accepts to achieve its objectives.
• Oversight: Supervising executive management to ensure the risk management system's
effectiveness and monitoring performance through periodic reports.
• Integration: Ensuring that risk management is an integral part of the strategic
decision-making process.
• Ensuring that risk management strategies align with the organization's strategic
objectives.
• Approving the ERM framework.
• Forming subcommittees such as the Risk Committee or Audit Committee.
Senior leadership bears the responsibility for designing, implementing, and maintaining the
ERM program. They set the "tone from the top" and ensure risk management is integrated into
the organization's strategy and daily operations.
Page 71 of 94
3. ERM Committee (Risk Management Committee) 🤝
5. Risk Owners 💼
• Role: These are the individuals or groups within the organization directly responsible
for managing specific risks within their area of expertise or department. They are the
First Line of Defense in risk management.
• Key Tasks and Responsibilities:
o Identifying, assessing, and monitoring risks in their daily operations.
o Developing and implementing risk mitigation and management plans.
o Providing regular updates on risk status to the ERM Committee.
Page 72 of 94
Essential Elements of a Governance Structure
Any governance structure must contain a set of elements that ensure its effectiveness and
transparency. The most important of these elements are:
• Leadership 👨💼: There must be clear and accountable leadership, typically the Board
of Directors, which sets the strategy and oversees implementation. Leadership sets the
organization's overall direction.
• Accountability ⚖️: Every individual in the organization must be accountable for their
role and duties. Accountability ensures there is a party responsible for outcomes,
whether positive or negative.
• Transparency 🔍: Decisions, processes, and procedures must be clear and
communicated to relevant parties. Transparency builds trust and prevents
misunderstandings.
• Oversight: Oversight includes monitoring and review processes to ensure adherence
to policies and procedures. Oversight helps in detecting and addressing problems early.
• Policies and Procedures 📜: There must be a set of rules and controls governing
internal operations. These rules ensure that work is performed consistently and
systematically.
• Ethics and Values ✨: Governance must be based on a set of ethical values that guide
the behavior of individuals and ensure that decisions are made fairly and honestly.
• Supportive Corporate Culture: Promoting integrity and ethical values within the
organization through staff training and dedicating a culture of transparency and
accountability.
Page 73 of 94
• Adherence to Ethical Values: Instilling integrity and commitment to the highest
standards of professional conduct among all employees, and activating corporate codes
of conduct and ethics.
• Establishing a Governance Culture: Governance must become an integral part of the
company's culture, adhered to by all employees from the top to the bottom of the
pyramid.
• Focusing on Stakeholder Value: The primary goal of governance must be maximizing
stakeholder value, while considering the rights of all concerned parties.
• Using Technology: Technology can enhance the efficiency and effectiveness of
governance systems, such as using information systems to monitor performance and
manage data.
• Seeking Advice: Organizations can hire experts and consultants to evaluate governance
systems and provide recommendations for improvement.
• Independence: Ensuring the independence of units such as Internal Audit and Risk
Management to avoid conflicts of interest.
• Continuous Training: Raising the competency of employees in understanding and
managing risks.
• Flexibility: Designing a structure that is adaptable to environmental and regulatory
changes.
These practices help in enhancing corporate trust and reputation, ensuring sustainability, and
achieving the organization's objectives efficiently and fairly.
Conclusion
The Risk Management Governance Structure is a hierarchical system that ensures effective
coordination among all levels of the organization to identify, assess, and manage risks. Its
success depends on clear roles, integration with strategy, and the use of technological tools.
Through a strong governance structure, organizations can transform risks into opportunities
and achieve their goals sustainably.
Page 74 of 94
The Three Lines Model
The "Three Lines Model" (The Three Lines Model) was developed by the Institute of Internal
Auditors (IIA) to become a practical and vital framework for enhancing governance and risk
management within organizations. The model aims to clarify the different roles and
responsibilities in oversight and risk management, and it emphasizes the importance of
coordination and cooperation among the concerned parties.
It is a framework that helps organizations manage risks and achieve their objectives by
defining roles and responsibilities.
Because organizations operate in a complex and risk-filled world. This model ensures the
existence of strong governance and effective risk management. It clarifies who does what,
and how everyone works together.
The model consists of three main lines of defense, in addition to the Board of Directors, which
oversees them:
Page 75 of 94
1. The First Line: Operational Management (Risk Owners) 👷♀️
• Role: This line represents the employees and managers directly responsible for
achieving the organization's operational objectives. They are the "Risk Owners,"
meaning they are responsible for identifying the risks that could affect their daily work
and applying the necessary controls to manage them.
• Responsibilities:
o Leading and directing actions to achieve the organization's objectives.
o Applying daily control checks.
o Ensuring compliance with internal and external regulations in daily activities.
• Value: First Line personnel possess deep knowledge of operational processes, making
them the most capable of identifying and immediately addressing potential risks.
2. The Second Line: Risk Management and Compliance Functions (Oversight Functions)
⚖️
• Role: This line represents the Internal Audit function, which is completely
independent of management and operational activities. Its core role is to provide
"Objective Assurance" to the Board and senior management that the First and Second
Lines of Defense are working effectively.
• Responsibilities:
o Evaluating the effectiveness of governance, risk management, and internal
controls.
o Operating with complete independence, reporting directly to the Board of
Directors or the Audit Committee.
o Ensuring that risks are properly managed and that internal controls are adequate.
• Value: The independence of this line is essential to its credibility, as it gives the Board
confidence that the organization is managing its risks efficiently.
Page 76 of 94
The Role of the Governing Body (Board of Directors):
The Board of Directors and Senior Management are above these lines, responsible for setting
strategic objectives and defining the risk appetite. They also have the overall oversight
responsibility for the entire risk management system to ensure its effectiveness.
• This model enhances internal control and reduces instances of fraud and resource
misuse.
• It improves transparency and accountability, contributing to good governance.
• It helps ensure that risk management is effectively managed, especially in large and
complex organizations.
• It encourages cooperation and coordination among all lines to ensure the flow of
information and work effectively to achieve common goals.
Key Terms:
Page 77 of 94
Principle 3: Management Roles and the First- and Second-Lines Management, in achieving
organizational objectives, assumes responsibility that includes the roles of the First and Second
Lines.
• First Line roles are directly associated with delivering products or services to the
entity's clients, and they include the roles of support functions.
• Second Line roles provide assistance in risk management.
First and Second Line roles can be integrated or separated. Some Second Line roles may be
assigned to specialists to provide complementary expertise, support, monitoring, and challenge
to those assigned First Line roles. Second Line roles may focus on specific risk management
objectives, such as adherence to laws and regulations, acceptable ethical conduct, internal
control, information security and technology, sustainability, and quality assurance. In contrast,
Second Line roles may include broader risk management responsibility such as Enterprise Risk
Management. However, the responsibility for risk management remains part of the First Line
roles and within the scope of management.
Principle 4: Third Line Roles Internal Audit provides independent and objective assurance
and advice on the adequacy and effectiveness of governance and risk management. Internal
Audit achieves this through the specialized application of systematic, disciplined processes,
expertise, and deep insight. Internal Audit communicates its findings to management and the
Board to enhance and facilitate continuous improvement. In doing so, it may take into account
assurance from other internal and external service providers.
Principle 5: Third Line Independence The independence of Internal Audit from management
responsibilities is crucial for its objectivity, authority, and credibility, and is established
through: Accountability to the Board, unrestricted access to the people, resources, and data
necessary to complete its work, and freedom from bias or interference in the planning and
execution of audit services.
Principle 6: Creating and Sustaining Value All roles working together collectively
contribute to creating and sustaining value when they are aligned with each other and consistent
with the priority interests of stakeholders. This alignment is achieved through communication,
synergy, and cooperation, which will ensure the reliability, interconnectedness, and
transparency of information necessary for risk-based decision-making.
• Keep using the terms "First Line," "Second Line," and "Third Line" from the
original model due to their common usage.
• The word "Lines" is not intended to denote structural elements but a useful distinction
between roles.
• Some view support functions like Human Resources, Administrative Affairs, and
building services as Second Line roles.
• The Three Lines Model considers First Line roles to include both direct customer
activities and administrative support activities, and Second Line roles include
complementary activities focused on risk-related matters.
• In some entities, other Third Line roles are defined, such as oversight, inspection,
investigation, and evaluation, which may be part of the Internal Audit function or
operate separately.
Page 78 of 94
Key Roles in the Three Lines Model
Entities vary significantly in their distribution of responsibilities; however, the following high-
level roles strengthen the principles of the Three Lines Model.
Board of Directors 🏛️
• Accepting accountability to stakeholders for the oversight and supervision of the entity.
• Working with stakeholders to monitor their interests and being transparent when
reporting on the achievement of objectives.
• Establishing a culture that promotes ethical behavior and accountability.
• Establishing governance structures and processes, including forming auxiliary
committees as needed.
• Delegating responsibilities and providing resources to management to achieve the
entity's objectives.
• Determining the organizational risk-taking level and exercising oversight and
supervision over risk management (including internal control).
• Ensuring oversight of compliance with legal, regulatory, and ethical expectations.
• Establishing and overseeing an independent, objective, and competent internal audit
function.
Management 💼
• First Line Roles: Managing and directing actions (including risk management) and
using resources to achieve the entity's objectives.
• Second Line Roles: Providing complementary expertise, support, monitoring, and
challenge related to risk management.
• Shared Management Tasks:
o Maintaining continuous dialogue with the Board and reporting on planned,
actual, and expected outcomes related to the entity's objectives and risks.
o Establishing and managing appropriate structures and processes for managing
business operations and risks (including internal control).
o Ensuring compliance with legal, regulatory, and ethical expectations.
o Establishing and implementing risk management practices and continuously
improving them, including internal control at the process, system, and entity
levels.
o Achieving risk management objectives, such as adherence to laws and
regulations, acceptable ethical conduct, internal control, information security
and technology, sustainability, and quality assurance.
o Providing analysis and reporting on the adequacy and effectiveness of risk
management (including internal control).
Page 79 of 94
Internal Audit 🛡️
The Board typically charts the entity's course by defining the vision, mission, values, and
organizational risk-taking level. The Board then assigns responsibility for achieving the entity's
objectives to management and provides the necessary resources. The Board receives reports
from management on planned, actual, and expected outcomes, as well as reports on risks and
risk management.
• Entities vary in the degree of overlap and separation between the roles of the Board and
management.
• There must be strong communication between management and the Board, typically
with the CEO acting as the link.
• Some Second Line leaders, such as the Chief Risk Officer, may have a direct reporting
line to the Board, which is entirely consistent with the model's principles.
The independence of Internal Audit from management ensures that its planning and execution
of work are not hindered or biased, and that it has unrestricted access to the people, resources,
and information it needs.
Page 80 of 94
• Cooperation and communication between the First- and Second-Line roles of
management and Internal Audit are necessary to avoid unnecessary duplication,
overlap, or gaps.
Internal Audit is accountable to the Board, sometimes described as the Board's "eyes and ears."
The Board is responsible for overseeing Internal Audit, which requires:
The Board, management, and Internal Audit each have different responsibilities, but all
activities should be aligned with the entity's objectives. The foundation of successful
interconnectedness is coordination, synergy, and regular, meaningful communication.
• Chief Audit Executive (CAE): The individual holding the highest position in the entity
and assuming responsibility for Internal Audit services.
• The Three Lines Model achieves optimal effectiveness when adapted and tailored to
align with the entity's objectives and circumstances.
• The Board may form committees to provide additional oversight on certain aspects of
its responsibilities, such as audit and risk.
• Functions, teams, and even individuals may be entrusted with responsibilities
encompassing both First- and Second-Line roles.
• Second Line roles remain part of management's responsibilities and are not completely
independent of it.
• A distinguishing feature of Third Line roles is their independence from management,
which is the basis for the distinct value of the assurance and advice they provide.
• The independence of Internal Audit is only achieved by refraining from making any
decisions or taking any actions that fall within the scope of management's
responsibilities. In case the Chief Audit Executive assumes additional responsibilities
(such as compliance aspects), a qualified external party must be engaged to provide
independent and objective assurance.
Page 81 of 94
Oversight and Assurance
• The Board relies on reports submitted by management, those assigned First and Second
Line roles, Internal Audit, and others to exercise oversight.
• Management provides valuable assurance, also referred to as affirmations, regarding
outcomes, risks, and risk management.
• Those assigned Second Line roles provide additional assurance on risk-related matters.
• The assurance provided by Internal Audit is characterized by the highest degree of
objectivity and confidence because it is independent of management.
• Effective governance calls for the appropriate assignment of responsibilities and the
strong alignment of activities through synergy, cooperation, and communication.
• The Board seeks assurance from Internal Audit that governance structures and
processes are designed for their purpose and operate as intended.
Page 82 of 94
Risk Culture
What is Risk Culture?
Risk Culture is a fundamental concept in ERM, defining how individuals and the organization
as a whole approach and manage risk. Simply put, it is "how we think and act toward risks
here."
Risk culture is not limited to written policies and procedures but extends to include informal
behaviors, daily decisions, and how employees interact with each other and with leadership
regarding risk.
• Influences Decisions: Determines whether employees will report risks, ignore them,
or even take excessive risks.
• Enhances Effectiveness: When the risk culture is strong, risk management becomes
more effective because it is part of the daily operational fabric.
• Supports Objectives: Helps the organization achieve its strategic goals by consciously
managing risks and opportunities.
• Prevents Disasters: Many major corporate crises were the result of a weak or toxic
risk culture.
Risk culture typically evolves through several stages within an organization, from being almost
non-existent to becoming an integral part of the organization's DNA:
1. Initial / Ad Hoc:
o Characteristics: No real risk awareness or understanding. Risks are handled
individually and randomly after they occur. No clear policies or procedures.
Employees fear reporting errors or risks for fear of blame.
o Common Phrase: "We deal with problems when they happen."
2. Emerging:
o Characteristics: The organization begins to realize the existence of risks and the
importance of managing them, often after a significant adverse event or due to
regulatory requirements. Some basic policies and procedures are set, but the focus
is still on responding to risks rather than preventing them.
o Common Phrase: "We follow the rules to avoid problems."
3. Managed / Conforming:
o Characteristics: Risk management roles and responsibilities are clearly defined.
Risk management is integrated into some key processes. There is a better
understanding of the organization's risk appetite.
o Common Phrase: "We integrate risk management into how we operate."
4. Integrated / Advancing:
o Characteristics: Risk management becomes an essential part of strategic planning
and decision-making. Risks are identified proactively and continuously analyzed.
Innovation is encouraged within risk appetite limits.
o Common Phrase: "We use our understanding of risk to create value."
5. Optimized / Leading:
Page 83 of 94
o Characteristics: The organization is a leader in risk management. Risk culture is
deeply rooted and constantly adapts to changes. All employees are empowered to
be "risk managers." Risks are used as opportunities for continuous growth and
innovation.
o Common Phrase: "Smart risk-taking is part of our identity, and we learn and adapt
continuously."
Seven Key Attributes of Risk Culture (Based on RIMS Risk Maturity Model)
Attribute Translation and Meaning
1. Adoption of Measures the organization's risk culture and the support of executive
ERM-Based Process management and the Board for the ERM program.
Measures the organization's adoption of a unified methodology for
2. ERM Process risk management across its culture and decision-making processes,
Management and the efficiency of following the steps of identifying, assessing,
treating, and monitoring risks.
Evaluates the level of awareness of risk-return trade-offs, setting risk
3. Risk Appetite
tolerance limits, and the effectiveness in closing the gap between
Management
actual and potential risks.
Evaluates the extent to which the organization focuses on identifying
4. Root Cause
risks through their source or root cause instead of merely dealing
Discipline
with symptoms and outcomes.
Measures the quality and coverage of risk assessments, the method of
5. Uncovering Risks information gathering, and the ability to uncover enterprise-wide
trends and correlations.
Determines the organization's ability to execute its vision and
6. Performance strategy, and evaluates the strength of planning, communication, and
Management measurement of core organizational objectives using a risk-based
process.
7. Business Evaluates the extent to which a risk-based methodology is used in
Resiliency and business continuity planning, operational processes, and other
Sustainability sustainability activities.
Page 84 of 94
Module 5: Advanced concepts
To ensure the success of an Enterprise Risk Management (ERM) program, a set of essential
factors must be present to support the overall framework and guarantee its effectiveness. These
factors work together to create an environment capable of dealing with risks proactively and
systematically.
Explicit and clear commitment from senior management is the cornerstone of any successful
risk management program. When leadership believes in the program's importance and supports
its implementation, it sends a strong message to the rest of the staff that this is a top priority.
This support includes providing necessary resources, allocating budgets, assigning a
specialized team, and integrating risk management into business strategies.
The program's success heavily relies on having a corporate culture that understands and
embraces collective responsibility for risk management. All employees, at different levels,
must recognize their role in identifying and reporting risks. This culture requires continuous
training and workshops to raise awareness, along with encouraging open communication about
risks.
The framework must be carefully designed to suit the organization's nature and size, covering
all types of risks it may face (financial, operational, strategic, compliance risks). The
framework must be integrated into daily operations and activities, not just a formal addition.
This framework includes defining the Risk Appetite, which is the level of risk the organization
accepts to achieve its objectives.
The risk management program is not a one-time process; it is a continuous cycle of identifying,
assessing, analyzing, and treating risks. There must be clear mechanisms for regularly
identifying new and emerging risks, and assessing their impact and probability of occurrence
using standardized tools and techniques. This continuous assessment ensures the organization
is aware of current and potential risks.
Effective communication is the lifeline of the risk management program. There must be clear
communication channels for disseminating risk-related information and providing periodic
reports to senior management and stakeholders. These reports must be accurate, transparent,
Page 85 of 94
and offer actionable insights into the organization's risk status and the effectiveness of
treatment plans.
Using appropriate technology such as GRC (Governance, Risk, and Compliance) software
can make a significant difference. These tools facilitate data collection, analysis, report
generation, and systematic and effective risk tracking, which reduces human error and saves
time and effort.
In conclusion, the success of an ERM program lies in its nature as not just a set of procedures,
but an integral part of the organization's culture and daily operations, supported by the
commitment of senior management and the interaction of all employees.
Page 86 of 94
Risk Quantification
Risk Quantification is the process of converting identified risks into numerical values or
measurable quantities, instead of merely describing them qualitatively (such as "high" or
"low").
This analysis relies on available data, such as historical records, or on statistical estimates, to
estimate two key factors:
1. Probability: What is the likelihood of the risk occurring? (Example: 5%, 20%).
2. Financial Impact: What is the potential financial cost or loss if the risk occurs?
(Example: $50,000, $10 million).
This is the most common method, used to estimate the total cost of the risk. It is
calculated by multiplying the value of the potential impact by its probability.
Example:
2. Sensitivity Analysis
Used to determine which project variables (e.g., raw material price, labor cost) have the
greatest impact on project objectives if they change.
Page 87 of 94
3. Monte Carlo Simulation
Considered one of the most complex and accurate methods. It uses mathematical
models to generate thousands of possible scenarios for a project or process, based on
random variables, providing a wide range of potential outcomes (such as minimum cost,
maximum cost, and the most likely average cost).
This method represents possible decisions and their potential outcomes in a tree
diagram, helping to calculate the expected value of each course of action and determine
the optimal decision.
The potential cost of loss is calculated by analyzing all the direct and indirect financial
components that might result from the risk occurring. This analysis requires expertise in the
field and includes several factors:
1. Direct Costs:
These are clear and straightforward costs that can be easily tracked.
These are costs that are not immediately obvious but can be significantly larger than
direct costs.
o Lost Revenue: Revenue that was not generated due to the production line
stoppage or project delay.
o Idle Labor Costs: Wages of employees and workers whose work stopped due
to the machine breakdown.
o Loss of Company Reputation: Costs associated with losing customers or
damage to the company's reputation due to delays or failure to meet
commitments.
o Administrative Costs: Time and resources spent by management to resolve the
problem.
To estimate this value, the risk management team sits with experts from the relevant
departments (such as the maintenance team, finance team, and project manager) to estimate
each of these potential cost components, which are then summed to reach the total amount.
Page 88 of 94
What is the Difference Between Qualitative and Quantitative Risk Analysis?
Is the process of evaluating risks subjectively and classifying them into categories based on an
analysis of their likelihood and severity of impact. Precise financial figures are not used;
instead, it relies on the project team's experience and personal judgment.
• Methodology: A simple Risk Matrix is used to assess each risk on a scale of Low,
Medium, or High.
• Output: A descriptive classification of risks (e.g., High Risk, Medium Risk, Low
Risk).
• Goal: Quick prioritization of risks that warrant further attention.
Example: A project manager might qualitatively assess the risk of raw material delivery delay
as "High" because its likelihood is "Medium" and its impact on the schedule is "Severe."
Is the process of converting risks into numerical and objective values using statistical and
financial methods. It aims to estimate the potential financial impact of the risk with greater
precision.
Example: Instead of saying the risk of raw material delay is "High," it can be quantified as
"10% probability of a loss of $50,000."
Page 89 of 94
References:
• Overview of Enterprise Risk Management The CAS Enterprise Risk Management
Committee.
[Link]
• Betty J. Simkins. Enterprise Risk Management John Fraser, 2009.
[Link]
• Enterprise risk management (ERM): An overview.
[Link]
• Enterprise risk management.
[Link]
• Enterprise Risk Management: Its Origins and Conceptual Foundation.
[Link]
• The Seven Deadly Sins of Enterprise Risk Management and How to Avoid Them.
[Link]
[Link]
• Enterprise Risk Management (ERM) Fundamentals.
[Link]
• Enterprise Risk Management for Health Care Boards Leveraging the Value.
[Link]
20Boards%20and%20Trustees_2022-[Link]
• Health Care Enterprise Risk Management Playbook, Second Edition.
[Link]
• ASRMS Enterprise Risk Management: Implementing ERM.
[Link]
for-Sucecess-White-Paper_FINAL.pdf
• ERM Quick Reference Tool.
[Link]
• Health Care Enterprise Risk Management Playbook, Second Edition.
[Link]
• COSO: Integrating with Strategy and Performance: Compendium of Examples.
[Link]
• David A. Hillson: A prominent figure in risk management who has developed a four-
level risk maturity model. [Link]
[Link]
• Risk Management Maturity Level Development, April 2002.
[Link]
[Link]/sites/785/uploads/6985/R
M_Maturity_Level_Development_200220150902-[Link]
• Risk Management: A Maturity Model Based on ISO 31000.
[Link]
_Model_Based_on_ISO_31000
Page 90 of 94
• Business Wargaming - Chris Paton. [Link]
wargaming-chris-paton/
• How should risk leaders of the future work with Artificial Intelligence (AI)?.
[Link]
with-ai__compressed.pdf
• IRM's risk management standard.
[Link]
• Cyber risk. [Link]
[Link].
• [Link]
• International risk management standards. From the cube to the rainbow double helix:
a risk practitioner’s guide to the COSO ERM Frameworks.
[Link]
[Link]
• Standard Deviations A Risk Practitioners Guide to ISO 31000.
[Link]
• From the cube to the rainbow double helix: a risk practitioner’s guide to the COSO
ERM Frameworks. [Link]
[Link]
• Fit for the future?. [Link]
report-25-10-16_final.pdf
• Risk management and the business model. [Link]
[Link]
• Risk Appetite Statements. [Link]
[Link]
• Risk appetite and tolerance (Executive Summary). [Link]
say/thought-leadership/risk-appetite-and-tolerance/
• Managing Cost Risk & Uncertainty In Infrastructure Projects.
[Link]
• Short Guide to Contract Risk Management.
[Link]
[Link]
• Short Guide to the Risk Management Process.
[Link]
• Short Guide to RAID. [Link]
• Short Guide to Artificial Intelligence (AI) in Risk Management.
[Link]
[Link]
• Short Guide to Effective Facilitation. [Link]
[Link]
• Short Guide to Risk Management Plans. [Link]
[Link]
• Short Guide to Assumptions Analysis (ABCD Technique).
[Link]
Page 91 of 94
• Sustainability in Infrastructure Short Guide to using the UN SDGs.
[Link]
• Guide To Overcoming Bias. [Link]
[Link]
• Risk culture Resources for Practitioners. [Link]
[Link]
• Competition law risk. [Link]
[Link]
• Risks in the extended enterprise. [Link]
[Link]
• Risk management for charities. [Link]
[Link]
• How to embed Emerging Risk identification and management.
[Link]
[Link]
• How to Assess and Treat Emerging Risks.
[Link]
[Link]
• An Introduction to Emerging Risks and how to Identify them.
[Link]
[Link]
• Technology and cyber security: Tackling the risks.
[Link]
[Link]
• Tools for stakeholder mapping. [Link]
[Link]
• Tools for providing assurance on regulatory compliance.
[Link]
[Link]
• An introduction to understanding and managing regulatory risk.
[Link]
• Risk governance for charities Risk management structures and accountabilities.
[Link]
• Setting your risk appetite: supplementary guidance.
[Link]
[Link]
• Establishing risk appetite. [Link]
[Link]
• IRM Charities SIG Risk Management Maturity Framework.
[Link]
[Link]
• Risk management for charities Getting started: supplementary guidance.
[Link]
• An introduction to understanding and managing regulatory risk.
[Link]
Page 92 of 94
• Risk culture Under the Microscope Guidance for Boards.
[Link]
• Risk management for charities Getting started: supplementary guidance.
[Link]
• RISK MANAGEMENT PERSPECTIVES OF GLOBAL CORPORATIONS.
[Link]
corporations_correct-covers_final.pdf
• Fuelling the debate Latest risk management trends in the energy sector 2019.
[Link]
• Professional Standards in Risk Management. [Link]
psrm-brochure_web.pdf
• How to hire a great Chief Risk Officer. [Link]
[Link]
• RISK MANAGEMENT FOR THE CONSUMER SECTORS.
[Link]
sectors_compressed.pdf
• SCENARIO APPLICATIONS: STRESS TESTING COMPANIES IN THE
ENERGY VALUE CHAIN. [Link]
companies-in-the-energy-value-chain_compressed.pdf
• Disruption, uncertainty and the role of risk management.
[Link]
[Link]
• COSO Enterprise Risk Management Framework
• Committee of Sponsoring Organizations of the Treadway Commission (COSO).
[Link]
• ISO 31000: Risk Management – Guidelines
• International Organization for Standardization (ISO) [Link]
[Link]
• OECD Corporate Governance and Risk Management Principles
• Organisation for Economic Co-operation and Development (OECD)
• 🔗 [Link]
• World Economic Forum – Global Risks Report
• Annual analysis of global strategic and operational risks
• 🔗 [Link]
• Institute of Risk Management (IRM) – Risk Management Standards and Insights
[Link]
• Harvard Business Review – Managing Risks: A New Framework
[Link]
• Deloitte Insights – Enterprise Risk Management
[Link]
• McKinsey & Company – Risk and Resilience Research
[Link]
• Business Wargaming, Chris Paton. [Link]
wargaming-chris-paton/
Page 93 of 94
• [Link]
process/#:~:text=The%204%20essential%20steps%20of,and%20Report%20on%20th
e%20risk.
• Benjamin Power, August, 2022. The Key(s) to Writing Good Risk Statements.
[Link]
writing-good-risk-statements
• 3 Components of an Effective Risk Statement.
[Link]
• Guide to Risk Statements. [Link]
secretariat/corporate/risk-management/[Link]
• Risk appetite and tolerance. Institute of Risk Management.
[Link]
• James Vesper, Ph.D., MPH, ValSource, LLC. What Are Risk Appetite & Risk
Tolerance In Pharma & Medical Devices?. February 23, 2022.
[Link]
pharma-medical-devices-0001
Page 94 of 94