Effective Risk Management Strategies
Effective Risk Management Strategies
2.1 INTRODUCTION
This unit focuses on the methods, procedures and techniques used by the risk manager so
as to minimize the risk occur in a firm.
Once we understand that risk always exist with a firm or human being activities,
managers should take different measure to avoid or reduce these losses or undesired
events.
It requires the drawing up of plans, the organizing of material and individuals for the
undertaking, the maintaining of activity among personnel for the objectives involved, the
unifying and coordinating all the activities and efforts, and finally the controlling these
activities.
1. Risk identification
The loss exposures of the business or family must be identified. Risk identification is the
first and perhaps the most difficult function that the risk manager or administrator must
perform. Failure to identify all the exposures of the firm or family means that the risk
manager will have no opportunity to deal with these unknown exposures intelligently.
2. Risk Measurement: -
After risk identification, the next important step is the proper measurement of the losses
associated with these exposures. This measurement includes a determination of:
a) the probability or chance that the losses will occur
b) the impact the losses would have upon the financial affairs of the firm or family,
should they occur.
c) the ability to predict the losses that will actually occur during the budget period.
The measurement process is important because it indicates the exposures that are most
serious and consequently most in need of urgent attention. It also yields information
needed in risk treatment.
The third alternative includes, but not limited to the purchase of insurance. In selecting
the proper tool or combination of tools the risk manager must establish the cost and other
consequences of using each tool or combination of tools. He/she must also consider the
present financial condition /position/ of the firm or family, its over all policy with
reference to risk management and its specific objectives.
4. Implementation:
After deciding among the alternative tools of risk treatment the risk manager must
implement the decisions made. If insurance is to be purchased for example, establishing
proper coverage, obtaining reasonable rates, and selecting the insurer are part of the
implementation process.
5. Controlling/monitoring:
The results of the decisions made and implemented in the first four steps must be
monitored to evaluate the wisdom of those decisions and to determine whether changing
conditions suggest different solutions.
To identify all the potential losses the risk manager needs first a checklist of all the losses
that could occur to any business. Second, he or she needs a systematic approach to
discover which of the potential losses included in the checklist are faced by his/her
business. The risk manager may personally conduct this two-step procedure or may rely
upon the services of an insurance agent, broker, or consultant.
After the checklist is developed, the second step is to discover and describe the types of
losses faced by a particular business. Because most business are complex, diversified,
dynamic operations, a more systematic method of exploring all facets of the specific firm
is highly desirable. Seven methods that have been suggested are:
1. The risk analysis questionnaire: - It does more than provide a checklist of potential
losses. It directs the risk manager to secure in systematic fashion specific information
concerning the firm’s properties and operations.
Eg. If a building is leased from some one else, does the lease make the firm responsible
for repair or restoration of damage not resulting from its own negligence?
3. Flow-chart method: - Is the 3rd systematic procedure for identifying the potential
losses facing a particular firm. First, a flow chart or series of flow charts is constructed,
which shows all the operations of the firm, starting with raw materials, electricity, and
other inputs at supplies locations and ending with finished products in the hands of
customers. Second the checklist of potential property, liability, and personal losses is
applied to each property and operation shown in the flow chart to determine which losses
the firm faces.
4. On-site inspections: - are a must for the risk manager. By observing first hand the
firm’s facilities and the operations conducted thereon the risk manager can learn much
about the exposures faced by the firm.
6. Statistical Records of losses: - Another approach that will probably suggest fewer
exposures than the others but which may identify some exposures not other wise
discovered is to consult statistical records of losses or near losses that may be repeated in
the future.
7. Analysis of the environment: By analyzing the internal and external environment such
as customers, competitors, suppliers and government, the risk manager can identify the
potential losses.
In identification process the risk manager gives more emphasis on pure risks: property
losses, personal and liability losses. No single method or procedure of risk identification
is free of weaknesses or can be called foolproof. The strategy of management must be to
employ that method or combination of methods that best fits the situation at the hand.
Firms might get exposed to liability risks which refer to injuries caused to other people or
damages caused to their property, because of their operating activities.
After the risk manager has identified the various types of potential losses faced by his or
her firm, these exposures must be measured in order to determine their relative
importance and to obtain information that will help the risk manager to decide upon most
desirable combination of risk management tools.
Both loss frequency and loss severity data are needed to evaluate the relative importance
of an exposure to potential loss. However, the importance of an exposure depends mostly
upon the potential loss severity not the potential frequency. A potential loss with
catastrophic possibilities although infrequent, is far more serious than one expected to
produce frequent small losses and no large losses. On the other hand loss frequency
cannot be ignored.
If two exposures are characterized by the same loss severity, the exposure whose
frequency is greater should be ranked more important. There is no formula for ranking
the losses in order of importance, and different persons may develop different rankings.
The rational approach, however, is to place more emphasis on loss severity.
Loss-frequency Measures
One measure of loss frequency is the probability that a single unit will suffer one type of
loss from a single peril. Instead of estimating the probability that a single unit suffer one
type of loss from a single peril during the coming year, the risk manager can, in the same
way estimate the probability that the unit will suffer that type of loss from many perils.
This probability will be higher because of the additional possible causes of loss.
Loss-severity Measures
Two measures commonly used to measure loss severity are:
1. the maximum possible loss, and
2. the maximum probable loss
The maximum possible loss is the worst loss that could possibly happen and the
maximum probable loss is the worst loss that is likely to happen. The maximum possible
loss, therefore, is usually greater than the maximum probable loss. Of these two
measures, the maximum probable loss is the most difficult to estimate but also the most
useful.
In estimating the maximum possible loss and the maximum possible loss and the
maximum probable loss the risk manager, ideally, would consider all types of losses that
might result from a given peril.
In determining loss severity the risk manager must be careful to include all the types of
losses that might occur as a result of a given event as well as their ultimate financial
impact upon the firm: direct, indirect and net income losses.
The potential direct property losses are rather generally appreciated in advance of any
loss, but potential indirect and net income losses that may result from the same event are
commonly ignored until the loss occurs. This same event may also cause liability and
personnel losses.
3. Market Value: in the case of real estate, the market value established by obtaining
offers to purchase may be of value to the risk manager. The difficulty with this
approach, however, is that market value is closely linked to the supply and demand
function for real estate of the particular kind involved and the lot value, which usually
is not destroyed by most contingent events. Market value is also somewhat difficult to
establish, since each building is unique, and completely duplicate facilities seldom
exist for most forms of real estate. Finally, the market value may be higher than the
direct property loss because it may include some payments for the right to use the
property immediately.
4. Tax-Appraised Value: the value placed up on property for tax purposes has been
suggested by some as a way of establishing potential loss to property interests; but
these values have many deficiencies. For example, some states and localities set the
tax value at less than their estimate of the true value. Tax value may also be closer to
the true value on new properties that on old properties.
5. The Economics or Use Value: another way of valuing property loss is by measuring
the present value of the income it produces. For example, if a property produces a net
income of Birr 50,000 at the end of each year for three years, the present value of this
income stream is the sum of the present values of each of the three 50,000 Birr
incomes. The approximate present value of the three incomes, therefore, is 45,500 +
41,400 + 37,700 = 124,000. Thus, the value of the property loss will be Birr 124,000.
This capitalization procedure is often used when the property is rented or peculiarly
designed and the income and profit position of the firm would be directly affected by
its destruction. The major disadvantage associated with using this approach to
determine direct losses is that, like the market value, this economic value also reflects
net income losses, which should be measured separately. Furthermore, the value may
be greatly affected by the location of a building and the skill of the management. And
finally, the valuation estimates of the future incomes and the discount rates are very
subjective.
6. Reproduction Value: reproduction cost is the cost of reproducing or replacing the
existing property exactly at current prices. This measure may produce an unrealistic
value. For example, the materials or design used to construct a building now twenty
years old may be outdated. To produce a computer that is ten years old may cost more
than buying a more effective, modern computer.
7. Replacement Cost for New: replacement cost for new is the cost of replacing the
property with new property that is not exactly the same but meets current reasonable
specifications. For example, a risk manager may determine what it would cost to
replace a building by another that is equivalent in terms of space or volume at the
same or another location but of reasonable, current design. The basic problem here is
that the business firm would be getting a new building for an old one. On the other
hand, the argument can be made that so long as the old building stands. It can be used
in its present design and construction.
One difficulty associated with this measure is the task of measuring physical
depreciation and economic obsolescence. Physical depreciation is the result of age
and wear and tear. Economic obsolescence is illustrated by a change in fashion or the
development of new, more efficient machinery.
In valuing the cost of replacing personal property on either this basis or the basis of
replacement cost new, one must be careful to include all the costs (e.q., transporting,
installing, and ticketing costs) that would be incurred in obtaining the replacement.
The risk manager should also recognize that the same property has replacement costs
as it moves through the channel of distribution from the manufacturer to the
wholesaler to the retailer to the ultimate consumer. Finally, in assessing either real or
personal property losses one should include the expenses associated with cleaning up
the debris following an accident.
A probability distribution shows for each possible outcome, its probability of occurrence.
It is used to estimate numerically the potential loss from a risk. Using the probability
distribution, it is possible to measure the various aspects of a risk; such as:
1. the probability that the business will incur some dollar loss,
2. the probability that "severe" losses will occur,
3. the average loss per year, and
4. The risk or variation in the possible results.
Given the above distribution, the probability that the business will suffer no dollar loss is
almost 0.606. Because the business must suffer either no loss or some loss, the sum of the
probabilities of no loss and some loss must equal 1. Consequently, the probability of
some loss is equal to about 1 – 0.61 = 0.39. An alternative way to determine the
probability of some loss is to sum the probability for each of the possible total dollar
losses: i.e., 0.273 + 0.100 + 0.015 + 0.003 + 0.002 + 0.001 = 0.394 (1 – 0.606 = 0.394).
The potential severity of the total dollar losses can be measured by stating the
probability that the total losses will exceed various values.
values. For example, the risk
manager may be interested in the probability that the dollar losses will equal or exceed
5,000 Birr. These probabilities can be calculated for each of the values in which the risk
manager is interested and for all higher values. For example, the probability that the
dollar losses will equal or exceed Birr 5000 is equal to 0.003 + 0.002 + 0.001 = 0.006.
Another extremely useful measure that reflects both loss frequency and loss severity is
the expected total dollar loss or the average annual dollar loss in the long run. Because
the probabilities above represent the proportion of times each dollar loss is expected to
occur in the long run, the expected loss can be obtained by summing the products
formed by multiplying each possible outcome by the probability of its occurrence;
occurrence;
i.e., 0(0.606) + 500(0.273) + 1000(0.100) + 2000(0.015) + 5000(0.003) + 10,000(0.002)
+ 20,000 (0.001) = 321 Birr.
Birr. This measure indicates the average annual dollar loss the
business will sustain in the long run if it retains this exposure.
Up to this point, no yardstick has been suggested for measuring risk but its relationship to
the variation in the probability distribution has been noted. Statisticians measure this
variation in several ways. One of the most popular yardsticks for measuring the
dispersion around the expected values is the standard deviation.
deviation. The standard deviation
is obtained by subtracting the average value from each possible value of the variable,
squaring the difference, multiplying each squared difference by probability that the
variable will assume the value involved, summing the resulting products, and taking the
square root of the sum.
The standard deviation for the example given above is calculated as follows:
(1) (2) (3) (4) 3x4
Value (xi) Value-average (Value-average)2 Probability
$0 0 – 321 $ (-321)2 0.606 62,443
500 500 – 321 (179) 2 0.273 8,747
1000 1000 – 321 (679) 2 0.100 46,104
2000 2000 – 321 (1679) 2 0.015 42,286
5000 5000 – 321 (4679) 2 0.003 65,679
10,000 10,000 – 321 (9679) 2 0.002 187,366
20,000 20,000 – 321 (19679) 2 0.001 387,263
799,888
1. Poisson Distribution
The Poisson probability distribution can be used for the analysis of risk measurement.
The Poisson distribution works well when:
i) there are at least 50 units exposed independently to loss, and
ii) The probability that any particular unit will suffer a loss is the same for all
units less than 0.1 (1/10).
These conditions can be satisfied in two ways. First, the business can have at least 50
persons, properties, or activities each of which can suffer at most one occurrence per
year, and the probability being less than 0.1 (1/10) that any particular unit will have an
occurrence. Second, the number of persons, properties, or activities may be less than 50,
but each unit can have more than one occurrence during the exposure period.
P(r) =
Example 1.
1. Assume that there are 5 cars and each has experiencing about one collision
every two years.
years. The mean therefore is ½ or 0.5 collision per year. Then the probability
distribution is developed as follows.
P (0) = = 0.6065
P (1) = = 0.3033
P (2) = = 0.0758
P (3) = = 0.0126
We continue like above until we found that the sum of probability of all accidents equal
to 1. Thus the probability distribution is:
NO OF COLLISIONS PROBABILITY
0 0.6065
1 0.3033
2 0.0785
3 0.0126
Once the probability distribution is developed, it would not be difficult to determine the
probability of any number of accidents that are likely to occur. For example, the
probability of no collisions is almost 0.61 or 61%; the probability of more than three
collisions is 1- 0.9982 (0.6065 + 0.3033 + 0.758 + 0.0126) = 0.0018; and the probability
of more than one collision is 1 – (0.6065 + 0.3033) = 0.0902 or 9.02%.
Example 2.
2. (Refer the lecture note)
2. Binomial Distribution
Another method used by the risk manager to measure risk is binomial probability
distribution. To use the binomial distribution the risk manager must be familiar with the
basic assumption of the distribution.
The first assumption is that the objects are independently exposed to loss. The other
assumption is that each exposed unit suffered (experience) only one loss in a year (or
other budget period). Thus the probability that the firm will suffer r occurrences during
the year is calculated using the formula:
To illustrate, assume that there are 5 trucks which are operated by a business and if an
accident happens to a particular truck, it becomes a total loss. New trucks are purchased
at the beginning of every year to make up the lost ones so that the firm always starts the
new physical period with 5 trucks.
First it is assumed that monetary loss per accident is constant and it is Birr 5000.
Thus, the average monetary loss per accident = = 5,000, and the probability of an
accident can be estimated as P = 2/5 = 0.4
Using the formula [p(r) = pr q(n – r)]the following probability distribution can be
constructed.
Then from the above probability distribution we can determine the following:
1. the expected number of accidents or the average accidents to occur is 2.
2. the expected total monetary loss is Birr 10,000.
In addition, we can determine various aspects of the risk. For example, the probability
that the firm will face some accident is 0.92224 = 1 – 0.7776. This probability is so high
that implies the risk manager should take appropriate measures to handle the risk. The
probability that the firm will face some monetary loss is also 0.92224. And the
probability that monetary loss equals or exceeds Birr 10,000 is 0.66304 = (1 – (0.07776 +
0.25920).
3. Normal Distribution
The risk manager may also use a normal distribution method to measure risks. The
assumption here is the number of accidents or total annual monetary losses are
approximately normally distributed. The normal distribution can be well explained by
identifying only two parameters: the mean and the standard deviation.
After the risks facing the firm are identified and measured, the risk manager must decided
how to handle/manage them. Risk can be handled in several ways. However, we can
classify them into two broad measures / approaches. They are risk control tools and risk
financing tools.
Risk control approaches are designed to reduce the firm’s expected losses and to make
the annual loss experience more predictable. More specifically, risk control efforts help
individuals and organizations avoid a risk, prevent loss, lessen the amount of damage if a
loss occurs, or reduce undesirable effects of risk on an organization. The application of
risk control techniques to achieve these ends may range from simple and low cost to
complex and costly approaches.
The activities that constitute one organization’s risk control efforts may vary from those
of a similar organization in another part of the world. Although risk control programs
vary from organization to organization as a consequence of creativity and innovation, a
typology of risk control tools and methods still exist. Risk control tools and techniques
can be categorized as:
Avoidance
Avoidance of risk exists when the individual or the firm frees itself from the exposure
through (1) abandonment, or (2) refusal to accept the risk from the very beginning
(proactive avoidance). To avoid the risk the individual or the firm need to avoid the
property, person or activity with which the exposure is associated.
1) The production of some products and the provision of some service may provide
rewards whose expected value far exceeds potential loss pr costs at the margin.
2) It is impossible to avoid all the properties such as vehicles, buildings, machinery,
inventory etc. Without them operations of business would become impossible.
3) The context of the decision also may make avoidance impossible. A risk does not
exist in a vacum, and a decision to avoid a risk might actually create a new risk
else ware or enhance some existing risk. For example, if the Addis Ababa city
Administration learned that Ras Tefere Bridge is in a state of serious disrepair, in
response the administration decided to close the bridge and divert all traffic to the
other alternative bridge. The traffic load will made failure of the second
alternative bridge more likely to occur, and within a year the second bridge will
collapse. That means the measure taken to avoid risk in the first bridge bring
another risk in the second road.
4) The risk may be so fundamental to the organization’s reason for being that
avoidance cannot be contemplated. A mining concern may not avoid the risk of
tunnel collapse, but true avoidance would mean leaving the mining business,
which is the reason for existence.
Loss control measures attack risk by lowering the chance a loss will occur (loss
frequencies) or by reducing the amount of damage when the loss does occur (loss
severity). Loss control tools can be classified as: loss prevention and loss reduction
measures.
ENVIRONMENT
4. Improperly trained worker * Training (on the job and off the job)
5. Building susceptible to fire * Fire resistive construction
6. Slippery shop floor * Installation of absorbent mats
7. Dangerous working environment * Regular inspection and Internal control
warning poster.
Tight quality control can avoid a product liability risk that might arise due to product’s
quality.
A sprinkler system is a classic example of loss reduction effort; because fire is required to
activate the sprinklers.
A firm that employees an effective risk prevention and risk reduction programs is
benefiting not only itself but the society as well. For instance, the firm that makes strict
quality control to prevent liability losses is safeguarding the society from possible harms.
A destruction of inventory of a firm may affect society because those goods are no more
available to the society.
Therefore, effective loss prevention and reduction measures should be designed to benefit
both the firm and the society. However, these measures involve costs which include
expenditures for the acquisition of safety equipments and devices, operating expenses
such as salary payments to guards, inspectors, and other employees engaged in safety
work and training and seminar costs. The risk manager will have to design the most
efficient measures in order to minimize such costs without reducing the desired safety
level.
Neutralization
Neutralization is the process of balancing a chance of loss against a chance of gain. For
example, a person who has bet that a certain team will win the national cup series may
neutralize the risk involved by also placing a bet on the opposing team. The risk is
transferred to the person who accepts the second bet.
Information Management
Information emanating from an organization’s risk management department can have
important effects in reducing uncertainty in an organization’s stakeholders such as,
suppliers, customers, creditors, employees etc.
Risk transfer
Transfer as a risk control tool refers to transferring the loss that causes a loss to some
entity other than the one experiencing it to bear the burden of the loss. Transfer may be
accomplished in two ways:
1. The activity or property responsible for the risk can be transferred to some other
person or groups of persons.
For example, an organization that sells one of its buildings can transfer the risk associated
with ownership of the building to the new owner. The main contractor can transfer some
of the risks by hiring sub-contractor who can handle some part of the project.
One may ask a question “what makes transfer different from avoidance?” Risk transfer
measure attempt to transfer risk that results in an exposure to a particular peril for some
other person or organization, whereas in the case of avoidance through abandonment the
risk is passed to no one.
2. The risk, but not the property or activity, may be transferred. For example, a
manufacturer may be able to force a retailer to assume responsibility for any damage to
products that occur after the products leave the manufacturer’s premises.
Separation
This refers to scattering the firm’s property exposed to risk to different places. The
principle is “do
“do not put all your eggs in one basket.”
basket.” For example, instead of placing its
entire inventories in one warehouse, a firm may put them in different warehouses and
separate exposure. Another example, a firm can store files depending on their respective
importance. Top secret files, say, can be put in fire proof cabinets, others in locked
cabinets and the less importance once can be left on tables.
Combination
This is some how similar to separation as it involves increasing the number of exposure
units to make loss exposures more predictable. Their difference lies on the fact that
unlike separation, which simply spreads a specified number of exposure units,
combination (pooling) increases the number of exposure units under the control of the
firm. Combination follows the law of large numbers, which states that when the exposure
units increase, the loss will be more predictable with high degree of accuracy and then
reduces risk.
Examples:
- A taxi owner increasing the number of fleets
- Merger with other firms (the merger of Lion Insurance and Hibret Insurance). In
this case combination results in the pooling of resources of the two companies.
This leads to financial strength, thereby reducing the adverse effect of the
potential loss.
- Use of spare parts and reserve machines
Diversification
Diversification is another risk control tool used to handle most speculative risks. For
example, businesses can diversify their product line so that a decline in profit of one
product could be compensated by profits form other product lines. Here we can take our
country as an example. Ethiopia can minimize international trade risk by producing and
selling different types of products in addition to coffee export which accounts the lion
share in our export trade. This can be noticed from the current situation. The country has
lost thousands of foreign exchange from coffee export because of the decline in the world
price of coffee.
2.8.2 Risk Financing Tools
In most risk management programs, some losses occur in spite of the best risk control
efforts. This means some measures must be used to finance losses that do occur. Risk
control measures by altering the loss itself, either reduce the potential losses or make
those losses more predictable. The risk financing tools, on the other hand, are ways of
financing the losses that do occur. It includes:
Retention (Self-Insurance)
The most common and easiest method of risk handling tools used by firm is retention. It
is an arrangement under which the firm or an individual experiencing the loss bears the
direct financial consequences. In other words, the person or the firm consciously or
unconsciously, decides to assume the risk and pays for the loss without any attempt to
transfer it to somebody else. The sources of the funds is the firm itself. Retention may be
passive or active, unconscious or conscious, unplanned or planned.
The retention is passive or unplanned when the risk manager is not aware that exposure
exists and consequently does not attempt to handle it. By default, therefore, the firm has
elected to retain the risk associated with that exposure. Retention is active or planned
when the risk manager considers other methods of handling the risk and consciously
decides not to transfer the potential losses. For this, the firm may set aside a fund for the
contingencies (self Insurance).
Why person or a firm decides to retain the risk? Planned retention exist for a number of
reasons. Some of these are:
In most cases retention is not the only possible tool. The choice is between retention and
insurance. The major factors to be considered in making the choice are:
a) The maximum probable cost relative to the firm’s capacity for bearing the risk.
b) Expected loss and risk
If the business believes that its expected losses are less than those assumed by the
insurer in calculating its premium, it may reason that in the long run it can save
the difference between the two expected losses estimated by retaining the loss
c) Restrictions or legal limitations applying to risk transfers. In such types of
situation the only option may be retention.
d) Opportunity costs related to investment of funds that is going to be paid as a
premium if the risk is transferred to the insurance companies.
e) Quality of service provided by the insurance companies.
4. The risk may be remote: If the risk manager knows that the risk is so remote that
cannot exist in the near future, then he/she may prefer to retain the loss.
Transfer
Transfer as a risk-financing tool is an arrangement under which some entity other than
the one experiencing the loss bears the direct financial consequences. Under "risk
financing transfer”, the transferor seeks external funds that will pay for the losses that do
occur. In this arrangement, unlike the risk "control transfer”, the risk itself is not shifted
rather it is assumed by somebody else.
The most common form of risk transfer is by way of insurance. Insurance is so important
in the management of pure risks. We will explore insurance as a risk transfer mechanism
in more detail in the next three units.
In the previous section, we have discussed large number of risk management tools. These
tools may not be appropriate in all situations to all firms or individuals at all times. As a
result, a risk manager should be knowledgeable enough to make analysis and select the
“best” risk handling tool(s). Cost-benefit analysis is important in selecting an appropriate
risk management tool(s).