Risk Management Strategies E-Book
Risk Management Strategies E-Book
MANAGEMENT OF
RISC OS
W WW. C RO S S O V E R B R A Z I L . C O M
E-book Risk Management
Eduardo Person Pardini
CONTENT
1. Introduction
2. The importance of risk management
3. Concept of Risk
4. Risk management as the second line of defense
5. Paradigms of good practices
6. The Risk Analysis Process
7. Conclusion
8. Bibliography
9. About the Author
10. About the Crossover
The total or partial reproduction of this work is permitted, by any electronic means, including by xerographic processes.
as long as the source and the author are indicated. If in doubt, contact us via email: contato@[Link]
Page 1
E-book Risk Management
Eduardo Person Pardini
1. INTRODUCTION
Page2
E-book Risk Management
Eduardo Person Pardini
2. THE IMPORTANCE OF RISK MANAGEMENT
All organizations, without exception, have the creation of value as a strategic landmark.
for the related parties, which is translated in the organization’s mission. For
to achieve the mission, the strategy is defined and consequently the business objectives.
Organizations rely on 4 basic types of resources: Financial, Human,
Technological and Materials. To direct these resources in an optimized way, in
process of executing the necessary actions to achieve the objectives
strategic, the company is organized into business cycles, which in turn are
composed of operational processes, each with its layer of objectives, which
they must always be related to the strategic objectives.
It is clear that risk is always present in any corporation, whether the risk of
not achieving strategic objectives, or the risk of not achieving the objectives
operational. The big challenge of management is to define how much risk it is willing to take.
run to create value for the related parties.
The great challenge of management is to define how much risk it is willing to take.
run to create value for the related parties
Page3
E-book Risk Management
Eduardo Person Pardini
• Reduction of performance fluctuation
• Better distribution of resources,
• Increase in the company's resilience.
The risk in summary has a negative impact; however, the management process
risks should be seen as a positive fact, since it gives rise to
strategic opportunities and important differentiating competencies, such as
score the COSO.
Page4
E-book Risk Management
Eduardo Person Pardini
3. CONCEPT OF RISK
It is important to emphasize that, in my opinion, events that bring a positive impact are
considered opportunities, which once identified must be transferred
for the management of strategic planning.
Risk is always present and can be measured in a matrix way, that is:
Probability of occurrence and its impact if it occurs, so it is also not a
uncertainty. The answers to the uncertainties, if they exist, will be subjective, in turn,
the answers to the risks will always be objective, as we can measure the risk
objectively.
I can also say that risk is the negative way of looking at a situation, the
that helps us recognize the presence of the threat that can at a certain moment, if
to exist the exposure, to materialize in a risk event.
The term 'threat' has also been used as a synonym for risk, so let's
see this:
• Threat - it is the event that may occur under certain circumstances and can cause
a loss.
• Risk - it is the probability of the threat materializing and causing an effect.
adverse or a loss to the organization.
• Example: The risk of destruction of the corporate data center increases when a
hurricane (threat) is approaching.
Page 5
E-book Risk Management
Eduardo Person Pardini
4. RISK MANAGEMENT AS A SECOND LINE OF DEFENSE
The three lines of defense model emerged with the publication on September 21 of
2010 by FERMA and ECIIA on Guidance on the 8th EU Company law
recommendation for the implementation of the law requirements for monitoring the
effectiveness of the internal control system, internal audit and management of
risks.
As highlighted in the IIA's positioning statement on the subject:
The Three Lines of Defense model is a simple and effective way to improve
the communication of risk management and control through
clarification of essential roles and responsibilities.
The significant point in this model is the transparency about what the
responsibilities of each of the stakeholders in conducting business and
operation of the organization, in order to organize the process so that there are no
gaps due to a lack of understanding of each one's real responsibilities in this
governance process.
Page 6
E-book Risk Management
Eduardo Person Pardini
In summary, the first line of defense consists of managers who have the role of
responsibility for managing the risks of its processes, the supervision and the
alignment of the internal control system with inherent risks, technology, and fraud.
As a second line of defense are the support areas or staff that assist the
managers executing their responsibilities. There are the areas of internal control,
compliance, risk management and others.
And as the third line of defense, we have internal audit which has the
responsibility to carry out periodic monitoring through an evaluation
regardless of the governance process, risk management, and control system
internals that the first line of defense managers are responsible for.
I usually say that the internal controls sector does not control, but helps the manager to
to have an effective and optimized system of internal controls. The same is true for the area
of risk management; it does not manage risks, but supports managers in doing so.
risk analysis of your processes.
Page 7
E-book Risk Management
Eduardo Person Pardini
5. PARADIGMS OF GOOD PRACTICES
COSO Internal Control framework, updated in 2013, which focuses on the part
operational of the organization. It indicates that a system of internal controls exists
to mitigate three basic types of risks:
• Operational – Risk of efficiency and effectiveness, including asset safeguarding and
compliance with the policies and procedures of the organization.
Page 8
E-book Risk Management
Eduardo Person Pardini
This structure works with five important components for the definition of a
risk-based internal control system. Note that the control environment
is at the top of the structure due to its significant importance, as it is more important than
having a risk assessment process means having a culture and awareness of risks and
control in a way that there is commitment from management to these good practices.
It is important to emphasize that before defining a control, an assessment is necessary
risks; communication and information are the basis of the process and must flow consistently
top down and vice versa. Monitoring must be continuous,
responsibility of management, and also periodic by internal audit.
This process must happen at all levels of the organization, without exception.
The two main points in this structure are that previously, risk management was
based on the analysis of the risks of not achieving strategic objectives. Now the
risk management rises to a new level, the Council becomes part of risk management and not
another user.
Page 9
E-book Risk Management
Eduardo Person Pardini
Eles devem, de forma objetiva, avaliar se a estratégia definida está alinhada à missão
of the organization and also needs to assess if this strategy is within the appetite to
corporate risk and whether there are resources for its execution.
For me, these are definitely the most significant changes of this new framework,
and completely changes the positioning of risk management in the organization.
Unlike the previous structure, which operated in a cube with eight components and
four major objectives, this new structure works with five components for the
management processes, which aim to improve the process and
improve the value created for related parties.
It follows the same process as the COSO ICF structure and defines twenty principles that
guide the understanding of the five components.
É importante mencionar que o COSO não excluiu o CUBO, deixando o profissional à
the desire to continue using it, even as he mentions, this is not a law
It is indeed a best practice that may or may not be used by corporations.
Page10
E-book Risk Management
Eduardo Person Pardini
communication and learning is not a stage of the process, but is inserted within it, of
so that with each cycle the process matures through monitoring and
feedback.
Existem estruturas base para o gerenciamento de riscos as quais podem ser utilizadas
as parameters, but the main ones are the ones mentioned above. For some sectors
There is legislation regarding this process, such as Joint IN MP/CGU No. 1.
from 16 that establishes the parameters for federal entities; SUSEP Circular 521;
Law 13303/16 for mixed and public companies; CVM, Central Bank and others.
For those companies that are in regulated sectors, the others must
choose the paradigm that best fits your culture and complexity
operational.
Sometimes I am asked if there is any legal requirement, if it is imperative to
the quality of the process to take one of these structures as a paradigm, and mine
the answer is no, it is not necessary, however, it is advisable to have one.
good practice parameter, it can be more effective and economical.
Page 11
E-book Risk Management
Eduardo Person Pardini
6. THE RISK ANALYSIS PROCESS
The risk is closely related to the objectives, that is, if we do not have or
If we do not know the objectives, we cannot objectively identify the risks.
inherent, that is, those risks that are directly related to the objective.
In a simple way, risk is any event that negatively impacts the capacity.
of achieving the objective. So once we are aware that the risk
there is a need for a process to be able to identify and address it, in order to
increase the organization’s chances of achieving the pre-established objectives.
Conceptually, risk management is the process that anticipates what could impact
negatively affects the organization's ability to achieve its goals, promoting the
possibility of executing mitigating or contingency actions.
The opposite of risk management is crisis management.
Basically, the process is simple. It consists of three basic stages: stage of
identification of risks, then evaluation of their magnitude, and finally treatment
of the risks, and if necessary, depending on the magnitude of the risk, the creation of a plan
of contingency.
We observe that this process aims for the company, once it knows its risks
raw (risks without any mitigation process) can take the necessary actions to
reduce it to the maximum economically possible, allowing for residual risk (risk
remaining after the mitigating actions) is aligned with your risk appetite.
In this way, defining and understanding risk appetite is essential for effectiveness.
risk management. Risk appetite is the amount of risk that the organization feels
comfortable in running to create value for related parties.
Let's see the process in the following figure:
Page12
E-book Risk Management
Eduardo Person Pardini
At this stage, we first need to define the objectives of the process that
it will be evaluated. The more detailed the definition of the objective, the better it will be
to begin the identification of inherent risks. Inherent risk is nothing more than the
than the negative of the objective, for example: If the objective of the process is to buy
only services and products necessary for the operation, the inherent risks
will be: Not buying or buying what is not necessary. The most
used for risk identification is the 'Brainstorm', which can be
supported by some other tools to assist in the formalization and
organization, such as: Ishikawa, Bowtie, and others.
Once the risks have been identified, we need to identify their causes.
also known as risk factors. You will notice that the answer
The treatment is not for the risk itself, but for its cause.
The formalization of this stage can be in a simple matrix, where in the first
the goals of the object under evaluation are defined in the first column, in the second column
the risks for each of the objectives are identified and a third column
Page 13
E-book Risk Management
Eduardo Person Pardini
where the risk factors will be identified for each of the risks
identified. By the end of this stage, we will have three columns of the risk matrix.
filled (objective, risk and risk factor)
b. Evaluation of Magnitude
The risk can be measured and this is done in a matrix form through reading.
of the probability of occurrence and its impact on the organization.
At this point, it is essential for the company to have a metric (ruler) for the
measurement of probability and another for measuring impact, in such a way that
to carry out the measurement of the magnitude in a more objective way, even knowing that
there is a great subjectivity in this process.
There's no point in having sophisticated mathematical models if in the end the manager or
the specialist will have to have a subjective position, or else it becomes so complex that
the manager spends a good part of the time working on the calculation, leaving aside the
What has real meaning are the actions to bring the gross risk to the appetite.
corporate risk.
For the formalization of this measurement, we suggest that three columns be added.
in the spreadsheet used for the formalization of the above-identified risks, being:
one for probability, another for impact, and one for magnitude
(result of probability x impact).
c. Risk management
When we talk about mitigating operational risk, we are talking about defining a
internal control to respond to the likelihood of occurrence, in order to
Page 14
E-book Risk Management
Eduardo Person Pardini
detect the loss before it occurs. Depending on the magnitude, it will be
it is also necessary to have a contingency plan.
The idea is that internal control activity is to bring the residual risk to the level.
from appetite to organizational risk. Here we suggest the development of a matrix
of control where all internal controls identified in the process flow
are related to their objective, responsible, evidence, type,
nature, periodicity, etc.
d. Contingency
As I said, depending on the magnitude of the risk, it will be necessary, in addition to the
definition of the response, the creation of a contingency plan.
We know that an internal control is not absolute, it can fail, and that is why it is
It is necessary to have a plan to reduce the impact of the event, resulting from the failure.
of the control.
When the response is directly in the impact, in cases of external factors, the
Mitigation will not be a control, but rather a contingency plan for reduction.
of the impact if the event materializes.
Page 15
E-book Risk Management
Eduardo Person Pardini
7. CONCLUSION
Page 16
E-book Risk Management
Eduardo Person Pardini
8. BIBLIOGRAPHY
Guide to the CICS Common Body of Knowledge, version 7.1 – Internal Control Institute,
USA
COSO Framework ICF 2013 and ERM 2017 – Committee of Sponsoring Organizations of
the Treadway Commission, USA
The Orange Book, Management of Risk – Principles and Concepts, HM Treasury, UK
Research on Risk Management Process Maturity in Brazil, 1st edition, KPMG
Brazil
ABNT - Brazilian Association of Technical Standards, NBR ISO 31000:2019, Brazil
MP/CGU - Joint Normative Instruction No. 1 of 2013, Brazil
Page 17
E-book Risk Management
Eduardo Person Pardini
9. ABOUT THE AUTHOR
Page 18
E-book Risk Management
Eduardo Person Pardini
10. ABOUT THE CROSSOVER
Page 19
E-book Risk Management
Eduardo Person Pardini
Page 20