0% found this document useful (0 votes)
5 views21 pages

Risk Management Strategies E-Book

The e-book by Eduardo Person Pardini discusses the significance of structured risk management in organizations, emphasizing its role in achieving strategic objectives and creating value. It outlines the risk analysis process, the importance of integrating risk management into corporate culture, and the frameworks such as COSO and ISO 31000 that guide effective practices. The document serves as a comprehensive guide for implementing risk management as a critical component of corporate governance.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views21 pages

Risk Management Strategies E-Book

The e-book by Eduardo Person Pardini discusses the significance of structured risk management in organizations, emphasizing its role in achieving strategic objectives and creating value. It outlines the risk analysis process, the importance of integrating risk management into corporate culture, and the frameworks such as COSO and ISO 31000 that guide effective practices. The document serves as a comprehensive guide for implementing risk management as a critical component of corporate governance.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

E-BOOK

MANAGEMENT OF
RISC OS

2019 Eduardo Person Pardini

W WW. C RO S S O V E R B R A Z I L . C O M
E-book Risk Management
Eduardo Person Pardini

CONTENT

1. Introduction
2. The importance of risk management
3. Concept of Risk
4. Risk management as the second line of defense
5. Paradigms of good practices
6. The Risk Analysis Process
7. Conclusion
8. Bibliography
9. About the Author
10. About the Crossover

EDITION 1 – SÃO PAULO – BRAZIL - 2019


PUBLICATION: Crossover Consulting & Auditing

The total or partial reproduction of this work is permitted, by any electronic means, including by xerographic processes.
as long as the source and the author are indicated. If in doubt, contact us via email: contato@[Link]

Page 1
E-book Risk Management
Eduardo Person Pardini
1. INTRODUCTION

Having a good and structured risk management process is essential


for the consolidation of a management based on good governance practices.
We know that risk management increases the organization's ability to achieve
your strategic objectives that, if aligned with your mission, will enable the
organization create value for related parties.
Atualmente uma grande gama de normas, regulamentos e leis estabelecem a
mandatory risk management by organizations, for example:
Joint Normative Instruction MP/CGU 01, Susep Circular 521, Law 13.303, not to mention
the norms of the Central Bank, CVM and others, what is motivating a wave of
implementation in private and public sector organizations.
It is also worth mentioning that risk management for a company in the sector
private or a public sector company follows the same structure, what changes is
some legal requirements and the nature of the business, the rest, are similar.
Let's address the main factors that should be considered to have a
structured and integrated risk management process, a key element for
an effective corporate governance.

Page2
E-book Risk Management
Eduardo Person Pardini
2. THE IMPORTANCE OF RISK MANAGEMENT

All organizations, without exception, have the creation of value as a strategic landmark.
for the related parties, which is translated in the organization’s mission. For
to achieve the mission, the strategy is defined and consequently the business objectives.
Organizations rely on 4 basic types of resources: Financial, Human,
Technological and Materials. To direct these resources in an optimized way, in
process of executing the necessary actions to achieve the objectives
strategic, the company is organized into business cycles, which in turn are
composed of operational processes, each with its layer of objectives, which
they must always be related to the strategic objectives.
It is clear that risk is always present in any corporation, whether the risk of
not achieving strategic objectives, or the risk of not achieving the objectives
operational. The big challenge of management is to define how much risk it is willing to take.
run to create value for the related parties.

The great challenge of management is to define how much risk it is willing to take.
run to create value for the related parties

It is precisely at this point that the importance of the company having a


risk management process integrated with its culture and internal environment, and
not just a process of creating spreadsheets. It must be present in the activities
management daily, being part of operational or strategic decisions.
It is not possible to have effective corporate governance without good
awareness and risk management, which in turn requires an effective system of
internal controls.
Risk management increases the organization's capacity to achieve its goals,
allowing the visualization of opportunities that positively impacted the
organization as a whole.
COSO, in its review of the good practices framework, indicates some benefits of doing so.
to have good risk management. Here are some that I understand as priorities:
• Allows entities to improve their ability to identify risks and define the
appropriate responses, reducing surprises and costs or losses
correspondents and taking advantage of the other favorable developments.

Page3
E-book Risk Management
Eduardo Person Pardini
• Reduction of performance fluctuation
• Better distribution of resources,
• Increase in the company's resilience.

The risk in summary has a negative impact; however, the management process
risks should be seen as a positive fact, since it gives rise to
strategic opportunities and important differentiating competencies, such as
score the COSO.

Page4
E-book Risk Management
Eduardo Person Pardini
3. CONCEPT OF RISK

There are many definitions of risk, many define risk as uncertainty.


to achieve the planned results. Others define it as being events that
positively or negatively impact the corporation.
I prefer to define risk as:
Probability of occurrence of events associated with loss or an adverse effect that
negatively impacts the organization's ability to achieve its goals
established, whether they are operational or strategic.

It is important to emphasize that, in my opinion, events that bring a positive impact are
considered opportunities, which once identified must be transferred
for the management of strategic planning.
Risk is always present and can be measured in a matrix way, that is:
Probability of occurrence and its impact if it occurs, so it is also not a
uncertainty. The answers to the uncertainties, if they exist, will be subjective, in turn,
the answers to the risks will always be objective, as we can measure the risk
objectively.
I can also say that risk is the negative way of looking at a situation, the
that helps us recognize the presence of the threat that can at a certain moment, if
to exist the exposure, to materialize in a risk event.
The term 'threat' has also been used as a synonym for risk, so let's
see this:
• Threat - it is the event that may occur under certain circumstances and can cause
a loss.
• Risk - it is the probability of the threat materializing and causing an effect.
adverse or a loss to the organization.
• Example: The risk of destruction of the corporate data center increases when a
hurricane (threat) is approaching.

Risk is part of any type of operation; there is no initiative without it.


Risk is always present and is inherent to the business. This is also a truth.
for our personal lives, we are always at the mercy of events that can impact
negatively our ability to achieve our professional goals or
individuals.
Risk is always associated with the objective. The analysis of risks increases our
ability to not be "caught off guard".

Page 5
E-book Risk Management
Eduardo Person Pardini
4. RISK MANAGEMENT AS A SECOND LINE OF DEFENSE

The three lines of defense model emerged with the publication on September 21 of
2010 by FERMA and ECIIA on Guidance on the 8th EU Company law
recommendation for the implementation of the law requirements for monitoring the
effectiveness of the internal control system, internal audit and management of
risks.
As highlighted in the IIA's positioning statement on the subject:

The Three Lines of Defense model is a simple and effective way to improve
the communication of risk management and control through
clarification of essential roles and responsibilities.

The significant point in this model is the transparency about what the
responsibilities of each of the stakeholders in conducting business and
operation of the organization, in order to organize the process so that there are no
gaps due to a lack of understanding of each one's real responsibilities in this
governance process.

Page 6
E-book Risk Management
Eduardo Person Pardini
In summary, the first line of defense consists of managers who have the role of
responsibility for managing the risks of its processes, the supervision and the
alignment of the internal control system with inherent risks, technology, and fraud.
As a second line of defense are the support areas or staff that assist the
managers executing their responsibilities. There are the areas of internal control,
compliance, risk management and others.
And as the third line of defense, we have internal audit which has the
responsibility to carry out periodic monitoring through an evaluation
regardless of the governance process, risk management, and control system
internals that the first line of defense managers are responsible for.
I usually say that the internal controls sector does not control, but helps the manager to
to have an effective and optimized system of internal controls. The same is true for the area
of risk management; it does not manage risks, but supports managers in doing so.
risk analysis of your processes.

Page 7
E-book Risk Management
Eduardo Person Pardini
5. PARADIGMS OF GOOD PRACTICES

It is always important to rely on structures recognized as best practices.


in order to assist, whether in assessing the maturity of risk management
existing or in other words for the development and implementation of a structured process of
risk analysis.
There are two structures of COSO - Committee of Sponsoring Organizations of
Treadway Commission

COSO Internal Control framework, updated in 2013, which focuses on the part
operational of the organization. It indicates that a system of internal controls exists
to mitigate three basic types of risks:
• Operational – Risk of efficiency and effectiveness, including asset safeguarding and
compliance with the policies and procedures of the organization.

• Disclosure - Risk of loss of consistency and integrity of information and


data transacted in various operating systems, whether financial
and non-financial.

• Compliance - Risk of non-compliance with laws, regulations, standards


regulatory, whether from the Union, State, Municipality or regulatory agency and body.

Page 8
E-book Risk Management
Eduardo Person Pardini
This structure works with five important components for the definition of a
risk-based internal control system. Note that the control environment
is at the top of the structure due to its significant importance, as it is more important than
having a risk assessment process means having a culture and awareness of risks and
control in a way that there is commitment from management to these good practices.
It is important to emphasize that before defining a control, an assessment is necessary
risks; communication and information are the basis of the process and must flow consistently
top down and vice versa. Monitoring must be continuous,
responsibility of management, and also periodic by internal audit.
This process must happen at all levels of the organization, without exception.

COSO Enterprise Risk Management Framework, updated in 2017, integrating the


risk management with strategy and performance. It highlights the
importance of considering risk both in the process of defining strategies
as well as in performance improvement.
Every time we make a choice on the path to achieving a goal, it has its
risks, and dealing with these risks in these choices is part of the decision-making process. According to
the COSO this new structure and way of analyzing risks provides senior management
real possibilities of dealing with the increasing volatility, complexity and
ambiguity of the world, especially in the business world.

The two main points in this structure are that previously, risk management was
based on the analysis of the risks of not achieving strategic objectives. Now the
risk management rises to a new level, the Council becomes part of risk management and not
another user.

Page 9
E-book Risk Management
Eduardo Person Pardini
Eles devem, de forma objetiva, avaliar se a estratégia definida está alinhada à missão
of the organization and also needs to assess if this strategy is within the appetite to
corporate risk and whether there are resources for its execution.
For me, these are definitely the most significant changes of this new framework,
and completely changes the positioning of risk management in the organization.

Unlike the previous structure, which operated in a cube with eight components and
four major objectives, this new structure works with five components for the
management processes, which aim to improve the process and
improve the value created for related parties.
It follows the same process as the COSO ICF structure and defines twenty principles that
guide the understanding of the five components.
É importante mencionar que o COSO não excluiu o CUBO, deixando o profissional à
the desire to continue using it, even as he mentions, this is not a law
It is indeed a best practice that may or may not be used by corporations.

Another similar structure is ISO 31000:2019 developed by the Technical


Management Board Working Group on Risk Management, which aims to define and
standardize concepts and processes of risk management. In my understanding it
you are mistaken when you assert that risk is a deviation from the expected, which can
to be positive or negative. However, apart from that, its structure provides generic guidelines.
for risk management that can also be applied to any and all
types of organizations.
Another model that also catches my attention, and in some way, in my view
who complements the structures mentioned earlier is the Orange Book
published by HM Treasury of the United Kingdom in 2001 and updated in the year of
2004. One of the points I like and that is quite significant is that the component

Page10
E-book Risk Management
Eduardo Person Pardini
communication and learning is not a stage of the process, but is inserted within it, of
so that with each cycle the process matures through monitoring and
feedback.
Existem estruturas base para o gerenciamento de riscos as quais podem ser utilizadas
as parameters, but the main ones are the ones mentioned above. For some sectors
There is legislation regarding this process, such as Joint IN MP/CGU No. 1.
from 16 that establishes the parameters for federal entities; SUSEP Circular 521;
Law 13303/16 for mixed and public companies; CVM, Central Bank and others.
For those companies that are in regulated sectors, the others must
choose the paradigm that best fits your culture and complexity
operational.
Sometimes I am asked if there is any legal requirement, if it is imperative to
the quality of the process to take one of these structures as a paradigm, and mine
the answer is no, it is not necessary, however, it is advisable to have one.
good practice parameter, it can be more effective and economical.

Page 11
E-book Risk Management
Eduardo Person Pardini
6. THE RISK ANALYSIS PROCESS

In order for there to be a risk-based business management, it must work with


the following vision:

Objective Risk Response

The risk is closely related to the objectives, that is, if we do not have or
If we do not know the objectives, we cannot objectively identify the risks.
inherent, that is, those risks that are directly related to the objective.
In a simple way, risk is any event that negatively impacts the capacity.
of achieving the objective. So once we are aware that the risk
there is a need for a process to be able to identify and address it, in order to
increase the organization’s chances of achieving the pre-established objectives.
Conceptually, risk management is the process that anticipates what could impact
negatively affects the organization's ability to achieve its goals, promoting the
possibility of executing mitigating or contingency actions.
The opposite of risk management is crisis management.
Basically, the process is simple. It consists of three basic stages: stage of
identification of risks, then evaluation of their magnitude, and finally treatment
of the risks, and if necessary, depending on the magnitude of the risk, the creation of a plan
of contingency.
We observe that this process aims for the company, once it knows its risks
raw (risks without any mitigation process) can take the necessary actions to
reduce it to the maximum economically possible, allowing for residual risk (risk
remaining after the mitigating actions) is aligned with your risk appetite.
In this way, defining and understanding risk appetite is essential for effectiveness.
risk management. Risk appetite is the amount of risk that the organization feels
comfortable in running to create value for related parties.
Let's see the process in the following figure:

Page12
E-book Risk Management
Eduardo Person Pardini

Let’s examine each of these activities for risk assessment of a process.


operational
a. Risk Identification

At this stage, we first need to define the objectives of the process that
it will be evaluated. The more detailed the definition of the objective, the better it will be
to begin the identification of inherent risks. Inherent risk is nothing more than the
than the negative of the objective, for example: If the objective of the process is to buy
only services and products necessary for the operation, the inherent risks
will be: Not buying or buying what is not necessary. The most
used for risk identification is the 'Brainstorm', which can be
supported by some other tools to assist in the formalization and
organization, such as: Ishikawa, Bowtie, and others.

It is important that at this stage as well, based on the COSO ICF,


we can identify the risks of legal compliance, of the application of
information technology in the process and also the risk of fraud. The process is
the same, with minor differences in the definition of the objectives.

Once the risks have been identified, we need to identify their causes.
also known as risk factors. You will notice that the answer
The treatment is not for the risk itself, but for its cause.

The formalization of this stage can be in a simple matrix, where in the first
the goals of the object under evaluation are defined in the first column, in the second column
the risks for each of the objectives are identified and a third column

Page 13
E-book Risk Management
Eduardo Person Pardini
where the risk factors will be identified for each of the risks
identified. By the end of this stage, we will have three columns of the risk matrix.
filled (objective, risk and risk factor)

b. Evaluation of Magnitude

The risk can be measured and this is done in a matrix form through reading.
of the probability of occurrence and its impact on the organization.

At this point, it is essential for the company to have a metric (ruler) for the
measurement of probability and another for measuring impact, in such a way that
to carry out the measurement of the magnitude in a more objective way, even knowing that
there is a great subjectivity in this process.

The challenge here is to be as simple as possible, within the complexity of


operation.

There's no point in having sophisticated mathematical models if in the end the manager or
the specialist will have to have a subjective position, or else it becomes so complex that
the manager spends a good part of the time working on the calculation, leaving aside the
What has real meaning are the actions to bring the gross risk to the appetite.
corporate risk.

For the formalization of this measurement, we suggest that three columns be added.
in the spreadsheet used for the formalization of the above-identified risks, being:
one for probability, another for impact, and one for magnitude
(result of probability x impact).

c. Risk management

The risk can only be addressed once its magnitude is known, as


para que se possa definir uma resposta adequada, o apetite e a tolerância ao
risks should be taken into account. Keep in mind that it is not just any response,
mas sim aquela que consegue fazer com que o risco residual esteja alinhado ao
appetite at risk.

There are four basic types of responses:


• Accept the risk,
• share the risk,
• avoid the risk and
• mitigate the risk.

When we talk about mitigating operational risk, we are talking about defining a
internal control to respond to the likelihood of occurrence, in order to

Page 14
E-book Risk Management
Eduardo Person Pardini
detect the loss before it occurs. Depending on the magnitude, it will be
it is also necessary to have a contingency plan.
The idea is that internal control activity is to bring the residual risk to the level.
from appetite to organizational risk. Here we suggest the development of a matrix
of control where all internal controls identified in the process flow
are related to their objective, responsible, evidence, type,
nature, periodicity, etc.

d. Contingency
As I said, depending on the magnitude of the risk, it will be necessary, in addition to the
definition of the response, the creation of a contingency plan.

We know that an internal control is not absolute, it can fail, and that is why it is
It is necessary to have a plan to reduce the impact of the event, resulting from the failure.
of the control.

When the response is directly in the impact, in cases of external factors, the
Mitigation will not be a control, but rather a contingency plan for reduction.
of the impact if the event materializes.

Page 15
E-book Risk Management
Eduardo Person Pardini
7. CONCLUSION

As you can see, the structuring of the risk management process is


relatively simple, however, its implementation is not so simple, as it affects
directly to the culture and the way of managing decision-making processes.

In a maturity survey of risk management processes in Brazil conducted


according to the auditing firm KPMG, the five most cited obstacles to implementation
of risk management are:
• 65% - Lack of culture in risk management
• 56% - Existence of other priorities
• 52% - Lack of clarity regarding potential benefits
• 45% - Lack of support from executives
• 36% - Resistance to changes within the Board of Directors and
board
Another interesting fact is that only 19% of participating companies have.
Appetite for risk formalized and implemented. This data alone already demonstrates the lack
the effectiveness of risk management in companies in Brazil.
As you can see, the difficulties in implementing the process are numerous,
So try to be as simple as possible within the complexity of the organization.
in the definition of the process, especially in measuring the magnitude. It doesn't matter
to know ten houses after the decimal, what we need to know is if the magnitude of the risk is 3
or 4, if it is 3.2785.
What needs to be addressed is the action that will be taken based on the risk assessment, and
not the form and accuracy of how it is being measured. Avoid 'one fits all' solutions
All or complex ones will lose time, money, and credibility.
Seek simplicity that not only improves performance but is also economically very
more effective.

Page 16
E-book Risk Management
Eduardo Person Pardini
8. BIBLIOGRAPHY

Guide to the CICS Common Body of Knowledge, version 7.1 – Internal Control Institute,
USA
COSO Framework ICF 2013 and ERM 2017 – Committee of Sponsoring Organizations of
the Treadway Commission, USA
The Orange Book, Management of Risk – Principles and Concepts, HM Treasury, UK
Research on Risk Management Process Maturity in Brazil, 1st edition, KPMG
Brazil
ABNT - Brazilian Association of Technical Standards, NBR ISO 31000:2019, Brazil
MP/CGU - Joint Normative Instruction No. 1 of 2013, Brazil

Page 17
E-book Risk Management
Eduardo Person Pardini
9. ABOUT THE AUTHOR

EDUARDO PERSON PARDINI


Bachelor's degree in Accounting from FACESP - Faculty of
Economic Sciences of São Paulo. Postgraduate in
Administration concentration in Finance. Specialization in
Strategy by Wharton Business School. Specialization on
Governance, Bribery and Fraud by Milliken University
CICP Certificate – Certified Internal Control Institute USA.
External auditor at Coopers & Lybrand, Manager at Price Waterhouse, Director of
International Audit Latin America of Grand Metropolitan PLC, Chief Financial
Officer Latin America of ISP International Specialty Products, Chief Financial Officer of
Iochep Maxion, Chief Financial Officer of Milliken Corp.
Principal partner of Crossover Consulting & Auditing Corporation, Chief Executive Officer of
Internal Control Institute Brazil. Speaker and professor of Risk Management,
governance, internal audit and internal controls by Crossover Brazil, ICI Brazil, and
MBA professor at Trevisan School of Business.

Page 18
E-book Risk Management
Eduardo Person Pardini
10. ABOUT THE CROSSOVER

Page 19
E-book Risk Management
Eduardo Person Pardini

Page 20

You might also like