0% found this document useful (0 votes)
26 views140 pages

Strategic Risk Management Study Material

The document outlines the syllabus and course objectives for the Strategic Risk Manager course in the BMS program, focusing on understanding various types of risks faced by organizations and the processes involved in enterprise risk management. It includes modules on risk management fundamentals, strategic risk management, risk identification, and communication of risk management strategies. Additionally, the course emphasizes skill development through case studies, simulations, and role plays, supported by various reference materials.

Uploaded by

sandeepaaglecha
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
26 views140 pages

Strategic Risk Management Study Material

The document outlines the syllabus and course objectives for the Strategic Risk Manager course in the BMS program, focusing on understanding various types of risks faced by organizations and the processes involved in enterprise risk management. It includes modules on risk management fundamentals, strategic risk management, risk identification, and communication of risk management strategies. Additionally, the course emphasizes skill development through case studies, simulations, and role plays, supported by various reference materials.

Uploaded by

sandeepaaglecha
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

STRATEGIC RISK MANAGER

PROGRAM: BMS

Semester – VI

STUDY MATERIAL
2023

For Private Circulation Only 1


SYLLABUS
Program: BMS
Name of the Course: STRATEGIC RISK MANAGER
Course Code:

No. of Hours per Week Total No. of Teaching


Course Credits
Hours

4 Credits 4Hrs 60Hrs

Course Objective: -
1. To develop an understanding of risk and the types of risk faced by an organization.
2. To demonstrate an understanding of terms such as risk appetite, risk attitude and risk culture
in an organizational context.
3. To understand the concept and process involved in Enterprise risk management, importance
of risk identification, risk assessment, risk response and risk monitoring.


Hours
Module 1 : Risk Management

Explain risk management to an organization. Compare risk and uncertainty. Explain


the types of risks –strategic, operational, financial, market, environmental and project
risk. Examine the relationship between risk and stakeholder perception.
12

Module -2: Strategic Risk Management I

Explain Risk appetite and identify the factors influencing risk appetite. Explain risk
attitude, risk environment, risk awareness and risk culture. Explain and assess the role
of a risk manager in identifying and monitoring risk. Explain and evaluate the role of
the risk committee in identifying and monitoring risk. Describe and assess the role of
internal or external risk auditing in monitoring risk. 12

Module 3: Strategic Risk Management II

Explain Enterprise Risk Management. Analyse the ERM approach and the components
of COSO framework for ERM. Evaluate the COSO framework. Describe and evaluate
other ERM frameworks such as the Management of Risk framework, CoCo Model, 12
The GRC capability model - Open Compliance & Ethics Group (OCEG). Explain IS0
31000:2009 standards and the pros and cons.
Module 4: Strategic Risk Management III
Explain the methods of risk identification. Explain and analyse the concepts of
assessing the severity and probability of risk events. Describe the various risk
management strategies. Explain Controlling and Monitoring Risk. 12

For Private Circulation Only 2


Module 5:- Strategic Risk Management IV
Determine a process for communicating, resourcing and managing risk
management strategies. Evaluate a risk management strategy including a disaster
recovery plan. Evaluate the outcomes of risk management strategies
12

Skill Development Activities:


1. Case study Analysis
2. Business Simulations
3. Role plays
4. Asynchronous Learning
Reference Books: -
1. Institute of Leadership and Management (IoL&M) study material
2. ICAI risk management study material

3. The Institute of Risk Management: Risk culture Under the Microscope Guidance
for Boards
4. Hopkins, Paul - Fundamentals of Risk Management ( 5th edition)(Chapter -1 )
[Link]
5. Roberts, Alexander, Wallace William et al, -( publication of Heriott watt university
– 2012 ) –Strategic Risk Management
6. Coso guidance - Risk appetite to Success, COSO publication May 2020
7. Muller Robert.R, Coso enterprise risk management, second edition , wiley finance,
Enterprise risk management Coso -Oct 2019

Course BLOOMS
TAXANOMY
Outcomes
(CO)
CO1 Identify the key principles and concepts of risk management in an Understanding (2)
organization.
Recognize the role of a risk manager and articulate the concepts of Understanding (2)
CO2 risk appetite, risk attitude and risk culture in an organizational context.

Employ various ERM frameworks to make informed decisions and Applying (3)
CO3 contribute to enhancing risk management practices.

Interpret the severity and probability scores of risk events the Applying (3)
CO4 organization is Exposed to.

CO5 Employ various ERM frameworks to make informed decisions and Analyze (4)
contribute to enhancing risk management practices.

For Private Circulation Only 3


INDEX

Module Page
No.
5-24
Module – 1 : RISK MANAGEMENT

25-52
Module – 2 : STRATEGIC RISK MANAGEMENT I

53-75
Module – 3 : STRATEGIC RISK MANAGEMENT II

76-104
Module – 4 : STRATEGIC RISK MANAGEMENT III

Module – 5 : STRATEGIC RISK MANAGEMENT IV 105-139

Model Question Paper 140

For Private Circulation Only 4


Module I

Risk Management

Structure
1.1 Introduction to Risk Management
1.2 Definition or Meaning
1.3 Objective and process of Risk Management
1.4 Risk and Uncertainty
1.5 Types of Risk
1.6 Financial Risk
1.7 Market Risk
1.8 Operational Risk and Project Risk
1.9 Environmental Risk
1.10 Strategic Risk
1.11 Importance of strategic Risk
1.12 Managing Strategic Risk

1.1 Introduction
Risk management is the process of identifying, assessing and controlling threats to an
organization's capital and earnings. These risks stem from a variety of sources including
financial uncertainties, legal liabilities, technology issues, strategic management errors,
accidents and natural disasters. Financial risks can be quantified using statistical tools to
generate a probability distribution of profits and losses. Risk that can be measured can be
managed better. The term “Risk” as a noun means a situation involving exposure or danger
and as a verb means expose to danger, harm or loss. It is said that the word Risk is derived
from the early Italian word “risco” which means danger or “risicare,” which means “to dare”
or French word “risqué”. Risk is known or unknown but is always inherent in individual or
business actions therefore it is more of a “choice” rather than a faie accompli.

Risk and reward are two sides of the same coin. Good Risk leaders select their actions well
or take calculated risks. They evaluate risks carefully and take actions with full cognizance
of consequences. They integrate decisions with corporate strategy, and strike a healthy
balance between risk management as an opportunity and a protection shield. The modern
terms for managing risk rose after World War II, but the discipline mostly began as a study
of using insurance to manage risk. Later, from the 1950s to the 1970s, risk managers began
to realize that it was too expensive to manage every risk with insurance, so the discipline
began to expand to alternatives to insurance. For example, training and safety programs might

For Private Circulation Only 5


be considered insurance alternatives. Regulators started recognizing the relevance and
significance of the subject of risk management and started prescribing advisories from 1980s;
however, the awakening and intensity of detailed regulatory interventions came about greatly
post the global financial crisis in the year 2007.

Each strategy and business action is accompanied with its expected risk and reward. Good risk
management therefore does not imply avoiding all actions and associated, rather it implies
making informed and coherent choices. The risks that the organization wants to take in pursuit
of its objectives and in particular choices it makes to manage and mitigate those risks.

Risk management is a central part of any organization's strategic management. It is the process
whereby organizations methodically address the risks attaching to their activities with the goal
of achieving sustained benefit within each activity and across the portfolio of all activities. Risk
management should be a continuous and developing process which runs throughout the
organization's strategy and the implementation of that strategy. It should address methodically
all the risks surrounding the organization's activities past, present and in particular, future. It
must be integrated into the culture of the organization with an effective policy and a programme
led by the most senior management. It must translate the strategy into tactical and operational
objectives, assigning responsibility throughout the organization with each manager and
employee responsible for the management of risk as part of their job description. It supports
accountability, performance measurement and reward, thus promoting operational efficiency
at all levels.

1.2 Definition or meaning

According to Warren Buffett –Risk comes from not knowing what you are doing. Risk
management is about people and processes and not about models and technology.

Again the CFA Institute practical risk management guide defines risk management as Risk
management is the art of using lessons from the past to mitigate misfortune and exploit future
opportunities—in other words, the art of avoiding the stupid mistakes of yesterday while
recognizing that nature can always create new ways for things to go wrong.
We cannot lose sight of the most important aspect of risk management— managing risk. That
means making the tactical and strategic decisions to control those risks that should be
controlled and to exploit those opportunities that should be exploited. Managing risk cannot be
divorced from managing profits; modern portfolio theory tells us that investment decisions are
the result of trading off return for risk, and managing risk is simply part of managing returns
and profits. Managing risk must be a core competence for any financial firm. The ability to
effectively manage. risk is the single most important characteristic separating financial firms

For Private Circulation Only 6


that are successful and survive over the long run from firms that are not successful. At
successful firms, managing risk always has been and continues to be the responsibility of line
managers—from the board through the CEO and down to individual trading units or portfolio
managers. Managers have always known that this is their role, and good managers take their
responsibilities seriously. The only thing that has changed in the past 10–20 years is the
development of more sophisticated analytical tools to measure and quantify risk. One result
has been that the technical skills and knowledge required of line managers have gone up.

1.3 Objective and Process of Risk Management


The first step to defining risk management goals and risk management objectives is to define
the organization's shared vision. Once the shared vision is articulated, overall risk management
goals and objectives must be defined. While a vision statement is often aspirational, the goals
and objectives should ordinarily describe in simple terms what is to be accomplished. They
should be actionable by the organization. They should be defined in the context of the
organization’s business strategy.
For example, some common risk management objectives chosen by companies to frame their
risk management approach include the following.

 Develop a common understanding of risk across multiple functions and business units
so as to manage risk cost-effectively on an enterprise wide basis.
 Achieve a better understanding of risk for competitive advantage.
 Build safeguards against earnings-related surprises.
 Build and improve capabilities to respond effectively to low probability, critical,
catastrophic risks.
 Achieve cost savings through better management of internal resources and allocate
capital more efficiently.

A business event if it occurs; can have a positive or negative impact on business’s objectives.
Generally, when we discuss risks we fall into the trap of thinking that risks have inherently
negative dimension. However, one should be open to those risks that create positive
opportunities; you can make your business faster, better and more profitable. Let us look at an
example here say on account of non-compliance with environmental laws few old suppliers of
a Corporate entity were restricted from supplying materials to the Corporate entity at preferred
rates. This posed a challenge to the corporate entity as they have to find new suppliers who
would be compliant with environment laws and also perhaps the new rates would be
significantly higher than the preferred rates of the old suppliers. The Corporate entity
undertakes a detailed supplier discovery exercise and realizes that the new suppliers are willing
to supply materials at rates that are lower than the preferred rates (agreed with their old
suppliers), thus a potential challenge or threat has been converted into an opportunity to reduce
the Corporate entity’s procurement spend. Think of the adage – “Accept the inevitable and turn
it to your advantage.” That is what you do when you take business risks to create opportunities.

For Private Circulation Only 7


1.4 Risk and Uncertainty
Risk and Uncertainty are used interchangeably in Risk management. However, as students of
SRM you need to know the difference between the two clearly to enable you to understand,
analyse, appreciate and evaluate the outcomes in each category which will help make better
quality decisions in real life.
Risk arises on account of uncertainty of occurrence and unknown consequences if the risk event
were to occur. Uncertainty is unpredictable, and has an uncontrollable outcome; taking risks
means taking steps or business actions in spite of uncertainty. The degree of uncertainty or
likelihood of occurrence and impact of the risk outcome combined together forms the
magnitude of the risk. Therefore, measurement of uncertainty and unknown consequences lie
at the heart of Risk Management.

In our day to day life, there are many circumstances, where we have to take risks, which
involves exposure to lose or danger. Risk can be understood as the potential of loss. It is not
exactly same as uncertainty, which implies the absence of certainty of the outcome in a
particular situation. There are instances, wherein uncertainty is inherent, with respect to the
forthcoming events, i.e. there is no idea, of what can happen next. So, in short, risk describes
a situation, in which there is a chance of loss or danger. Conversely, uncertainty refers to a
condition where you are not sure about the future outcomes.
In the ordinary sense, the risk is the outcome of an action taken or not taken, in a particular
situation which may result in loss or gain. It is termed as a chance or loss or exposure to danger,
arising out of internal or external factors, that can be minimised through preventive measures.

In the financial glossary, the meaning of risk is not much different. It implies the uncertainty
regarding the expected returns on the investments made i.e. the probability of actual returns
may not be equal to the expected returns. Such a risk may include the probability of losing the
part or whole investment. Although the higher the risk, the higher is the expectation of returns,
because investors are paid off for the additional risk they take on their investments. The major
elements of risk are defined as below:
 Systematic Risk: Interest Risk, Inflation Risk, Market Risk, etc.
 Unsystematic Risk: Business Risk and Financial Risk

By the term uncertainty, we mean the absence of certainty or something which is not known.
It refers to a situation where there are multiple alternatives resulting in a specific outcome, but
the probability of the outcome is not certain. This is because of insufficient information or
knowledge about the present condition. Hence, it is hard to define or predict the future outcome
or events.
Uncertainty cannot be measured in quantitative terms through past models. Therefore,
probabilities cannot be applied to the potential outcomes, because the probabilities are
unknown.

For Private Circulation Only 8


The comparison between risk and Uncertainty can be listed out as follow: -

SL No Basis for Comparison Risk Uncertainty


1 Meaning The probability of Uncertainty implies
winning or losing a situation, where the
something worthy is future events are not
known as risk known
2 Ascertainment Can be measured Cannot be measured
3 Outcomes Chances are known Outcome not known
4 Control Controllable Uncontrollable
5 Minimisation Possible Not possible
6 Probabilities Can be assigned Cannot be assigned

Since uncertainty cannot be controlled or estimated, we resort to insurance for the same and
examples are crop insurance, natural disaster like floods, storm, fire, and earthquake, tornado
insurances being taken by corporates.

In his seminal work Risk, Uncertainty, and Profit, Frank Knight (1921) established the
distinction between risk and uncertainty.

Uncertainty must be taken in a sense radically distinct from the familiar notion of Risk, from
which it has never been properly separated. The term "risk," as loosely used in everyday speech
and in economic discussion, really covers two things which, functionally at least, in their causal
relations to the phenomena of economic organization, are categorically different. The essential
fact is that "risk" means in some cases a quantity susceptible of measurement, while at other
times it is something distinctly not of this character; and there are far-reaching and crucial
differences in the bearings of the phenomenon depending on which of the two is really present
and operating. It will appear that a measurable uncertainty, or "risk" proper, as we shall use the
term, is so far different from an immeasurable one that it is not in effect an uncertainty at all.
We accordingly restrict the term "uncertainty" to cases of the non-quantitative type.
Thus, Knightian uncertainty is immeasurable, not possible to calculate, while in the Knightian
sense risk is measurable

1.5 Types of Risks


Paul Hopkins (in Fundamentals of Risk Management) divides risks into three categories: -

 Hazard (or pure) risks;


 Control (or uncertainty) risks;
 Opportunity (or speculative) risks.
Pure Risks are associated with uncertainties which may cause loss. In a pure risk situation, a
loss occurs or no loss occurs – there is no possibility for gain. These uncertainties may be due
to perils such as fire, floods, etc. or may arise from human action such as theft, accident etc.
There are certain risk events that can only result in negative outcomes such as fire accidents or

For Private Circulation Only 9


leakage of harmful chemicals from a manufacturing plant. These risks are hazard risks or pure
risks, and these may be thought of as operational or insurable risks. A good example of a hazard
risk faced by many organizations is that of theft. There are different types of pure risks:

 Personal risks - It includes early death, sudden accident and disability,


unemployment, etc.
 Property risks - reduction in value of assets due to physical damage, fire,
theft, etc.
Liability Risks - the risk of legal liability for damages accruing to customer, suppliers, vendors,
etc. Such risks are also connected with compensation payable to employees for injuries and
other harm afflicted in the workplace. All these are insurable.

Fundamental Risks are impersonal in nature. They are present in nature and the economy,
and are beyond the control of man. Their effect is pervasive and usually impacts a large group
of people. Earthquakes, war, inflation, mass unemployment, etc., are examples of such
fundamental risks. Generally, these risks are not insurable and it is left to the Government to
deal with the effects of these events. However, in situations where the occurrences are irregular
and the impact in minimal, the insurers can venture to insure these risks.
Particular Risks have their origin in individual events which can be partially controlled. They
occur due to the action of the individuals, for example, meeting with an accident while crossing
the road. These risks are insurable with conditions.
Dynamic Risks may arise due to changes in the economy like fluctuations in price levels,
consumer references, distribution of income, product development, shifts in technology, etc.
These are called Dynamic Risks. As they are less predictable, generally, they are not insurable.

Control risks are associated with unknown and unexpected events. They are sometimes
referred to as uncertainty risks and they can be extremely difficult to quantify. Control risks
are often associated with project management. In these circumstances, it is known that the
events will occur, but the precise consequences of those events are difficult to predict and
control. Therefore, the approach is based on minimizing the potential consequences of these
events.

Certain other risks can be as follows:


Events can have negative impact, positive impact, or both. Events with a negative impact
represent negative risks, which can prevent value creation or erode existing value. Events with
positive impact may offset negative impacts or represent opportunities. Risk and opportunity
management are closely related, organisations with superior competencies and knowledge
database attempt to convert negative risk events into positives by creating a focussed group of
experts who brainstorm on breakthrough ideas that could help the organisation move in a
positive direction. This is a contemporary phenomenon and is commonly referred to as
“catching the ball” or “idea funnel”. Risk management is all about value protection,

For Private Circulation Only 10


maximizing gains from risk outcomes and seizing the opportunities by formulating
management action plans. Disruptive start up culture is all about identifying real life problems
and convert the same to opportunities. Business risks can arise due to the influence by two
major risks: - internal risks (risks arising from the events taking place within the organization)
and external risks (risks arising from the events in real life problems) and converting them into
business opportunities.
Businesses face different type and extent of risks; few may cause serious loss of profits or even
bankruptcy. Large companies have extensive "risk management" departments; smaller
businesses tend not to look at the issue in such a systematic way but may have a more hands
on approach to risk management. A successful business needs a comprehensive, well-thought-
out business plan. However, business is dynamic; things change, and the best-laid plans can
sometimes appear out-dated in quick time. When the company’s strategy becomes less
effective in the market place and it struggles to reach its goals as a result; the company is facing
strategic risks or model risks. It could be due to technological changes, a powerful new
competitor entering the market, shifts in customer demand, spikes in the costs of raw materials,
or any number of other large-scale changes.

Risks are also caused due to two factors – Internal and External and further can be divided into
controllable and uncontrollable factors as per table below

Internal Factors External factors


Controllable Controllable
 Stability and financial position of the  Compliance with regulation and its
entity changes
 Labour strikes
 Machine breakdown
 Staff morale

Uncontrollable Uncontrollable
 Accidents  Economic Recession or boom
 People exiting organization  Floods, Earthquake
 Frauds  Market /Environment
 Technology changes

1.6 Financial Risk


Financial risk - These risks are associated with the financial assets, structure and
transactions of the particular industry. Financial risk relates to the financial operation of a
business, such as credit risk, liquidity risk, currency risk, interest rate risk and cash flow risk.
Some of these risks arise from cultural and legal differences between countries, such as the
demand in some countries for cash payments to arrange local sales. Obtaining money from
customers in other countries or recovering the cost of lost goods in transit may also be difficult

For Private Circulation Only 11


due to different legal or banking regulations. While these are typically outside the
organisation’s control, organisations can take action to mitigate those risks, for example, by
credit control procedures, hedging, export insurance.

Credit risk - The risk of loss arising from outright default due to the inability or
unwillingness of the customer or counterparty to meet their commitments. Credit risk is the
probability of loss from a credit transaction. It is also called as default risk.

Liquidity risk - The potential inability to meet commitments as they fall due. It arises
whenever the bank is unable to generate cash to meet out its liability payment obligations or
increase in assets or its failure to manage the unplanned decreases or changes in the funding
sources. Liquidity risk also arises on account of its failure to address the changes in the
market conditions that affect its ability to liquidate its assets quickly and with minimal
losses. Liquidity risk may arise due to changes or variations in the market conditions such
as, volatility of rate of interest or the Foreign exchange rate /Investment mismatch or risk or
poor economic conditions like depression / inflation / loss of confidence in the business by
its customers/ rumours about the business and its effects of run on the liquidity/ failure of
some of the banks where its deposits got struck or blocked or war like situations with the
enemies of state are some of the examples where the businesses will be facing liquidity crisis
as it may cause heavy outflow of funds.

1.7 Market Risk


Market risk - The risk of losses caused by adverse changes in the market variables such as
interest rate, Foreign Exchange rate, equity price and commodity price. RBI has defined the
Market Risk as the possibility of loss to a bank caused by the changes in market rates / prices.
Market risk is the possibility for an investor to experience losses due to factors that affect the
overall performance of the financial markets in which he has invested money. Market risk,
also called "systematic risk," cannot be eliminated through diversification, though it can be
hedged against. Sources of market risk include recessions, political turmoil, and changes in
interest rates, natural disasters and terrorist attacks. Market risk is the risk that declining prices
or volatility of prices in the financial markets will result in a loss. There are two major types
of market risk: absolute risk and relative risk.

1.8 Operational Risk

Operational Risk- The risk associated with the operations of an organization. It is the risk
of loss resulting from failure of people employed in the organization, internal process,
systems or external factors acting upon it to the detriment of the organization. It includes
Legal Risk and excludes strategic and Reputational Risks as they are not quantifiable. It is
the risk of loss due to inadequate monitoring systems, management failure, defective
controls, fraud, and/or human errors. Operational risk is particularly relevant to derivatives

For Private Circulation Only 12


trading because derivatives are inherently highly leveraged instruments, which enable
traders to expose a firm to enormous losses using a relatively small amount of capital.

Project risk –Overall project risk is the effect of uncertainty on the project as a whole.
Individual risk is defined as an uncertain event or condition that if it occurs, has a positive or
negative effect on project’s objectives. Project risk is also defined as the exposure of
stakeholders to the consequences of variations in outcome. E.g. BMRCL metro project gets
time extension for metro, comes at a significant additional cost.

Compliance Risk – It includes material financial loss or loss of reputation which may occur
as result of its failure to comply with the laws includes, regulations, rules, related self-
regulatory organization, standards and code of conduct applicable to its business activities.
E.g. failure to comply with GST returns filing on monthly, IT returns and TDS filings,
Annual report filing on timely basis, compliances under various labour laws if not done
properly can be visited with penalties.

Regulatory Risk - Regulatory Risk arises due to changes made in policies and procedures
by the regulators viz, RBI, Central and State Governments, SEBI, IRDA, etc. Withdrawal
of licenses, change in capital adequacy requirements, change in NPA norms etc. may be
grouped under this category. Any changes in the rules and regulations which may have a
negative impact on the business activities can be classified under this risk. E.g. Fines and
regulatory control imposed by RBI on Yes bank and PCMB bank by appointing its own
person as administrator and superseding the erstwhile management.

1.9 Environmental Risk

Environmental Risk - the chance of harmful effects to human health or to ecological


systems resulting from exposure to an environmental stressor. A stressor is any physical,
chemical, or biological entity that can induce an adverse effect in humans or ecosystems. E.g
loss of eco system in major cities, like lakes in Bangalore, forest reserves lost due to mining
permits given etc. It relates to changes in the political, economic, social and financial
environment over which an organisation has little influence. Environmental risks include

legislative change, regulations, climate change, natural disasters, loss of business, competition,
economic slowdown and stock market fluctuations. These are outside the organisation’s control
but can be mitigated to some extent through environmental scanning and contingency planning.

Governance Risk - Refers to in-effective, un-ethical management of a company by its


executives and managerial levels. –e.g. if governance is not done properly there is a
possibility of a scam and affects the reputation of the entity due to regulatory interventions –
yes bank, DHFL cases, involving fund diversion and improper corporate governance
practices.

For Private Circulation Only 13


1.10 Strategic Risk

Strategic Risk - The current and prospective impact on earnings, capital, reputation or good
standing of an organization arising from its poor business decisions, improper
implementation of decisions or lack of response to industry, economic or technological
changes. Failure of strategies will adversely impact the business objectives and attainment
of the goals. Strategic risks – those that affect or are created by business strategy decisions
– are critical to the growth and performance of an entity’s business. The importance of
strategic risk—particularly given the typical high failure rate of strategic initiatives and
empirical studies that show the impact of strategic risk exceeds the impact of all other forms
of risk combined. measures Measuring strategic risk using economic capital, shareholder value-
added, and other risk adjusted performance. Managing strategic risk through strategic planning,
risk appetite, new business development, mergers and acquisitions (M&A), and capital
management processes. Ongoing monitoring and feedback, including the integration of key
performance indicators, key risk indicators, and performance feedback loops to support board
and management oversight.
Strategic risks may lack historical precedent and/or originate outside an industry. Signals
related to emerging strategic risks are often faint or intermittent, which can make them hard to
detect, easy to dismiss, and difficult to interpret. Traditional tools cannot reliably locate and
analyze them.
In addition, strategic risks may be: -
• Unique to the organization because the strategy, culture, governance structure, and business
and operating models are unique to the organization
• Damaging to the entire organization because a risk involving, say, reputation or the supply
chain in one part of the company may affect other parts
• Easy to overlook because they often seem irrelevant, unthreatening, or highly unlikely—
and management may believe they are being monitored and managed when they are not
• Difficult to address with customary risk management methods
Strategic risks may arise from low-likelihood/high-impact, so-called “black swan” events.
These events can escalate rapidly and render those who have not anticipated them confused,
paralyzed, or prone to mistakes.
Although they may take the form of financial, operational, technological, political, or other
familiar risks, strategic risks tend to be difficult to quantify and track. For example, entire
industries ranging from retail, travel, advertising and entertainment have seen their strategies
essentially undone by technological and business model disruption. In particular, emerging
technologies warrant continual monitoring as potential sources of strategic risks—should new
or existing competitors harness them—and a source of opportunities. However, such
technologies challenge conventional risk management methods when their distribution is
uncontrolled and their uses are unanticipated.

Essentially, strategic risks can gum up, delink, or erode drivers of value. If ignored, they can
become what Deloitte has described as “value killers” (see Figure 2 and sidebar: Beware of the

For Private Circulation Only 14


value killers). On the flip side, strategic risks can present new drivers of value, suggest
modifications to current drivers, or indicate the need to abandon existing drivers.

A necessary shift in perspective


Most organizations manage financial, operational, security, and other risks in the normal course
of their business. That, however, is partly why recognizing strategic risks may be challenging.
Strategic risks can result from and amplify risks that the organization ordinarily faces, or
emanate from other very unfamiliar risks. That calls for a shift in perspective, also necessitated
by ongoing business and economic conditions, and other developments. Indeed, ongoing
developments create the need for organizations to monitor strategic risks continually, while
maintaining a high level of strategic flexibility.
Generally, the following shifts in perspective would be useful:
• From a focus only on understanding traditional financial and operational risks to a broader
view of risk and the interrelatedness of risks
• From a mindset of managing known, fairly predictable risks to one of positioning the
organization to detect and respond to unknown—and even unknowable—risks
• From a sense of mastery over risk to curiosity about risk
• From a focus on traditional risk reports to a focus on scanning for emerging strategic risks
• From an inside-out view of risk to a more outside-in view
From the risk management standpoint, strategic risks pose challenges because of their
complexities and potentially high stakes. Therefore, new methods of addressing them are
needed, now and going forward

For Private Circulation Only 15


Addressing strategic risks
To detect and address strategic risks, companies might consider the potential benefits of
investing in one or more of the following areas:
• Identifying hard-to-predict strategic risks: Building on their own and other organizations’
experiences, leaders can brainstorm potential low-likelihood/ high-impact events and then
systematically examine those that could undermine strategies, and identify ways in which
the company could recognize and assess them.
• Sensing capabilities: Technology can now enable organizations to monitor numerous
variables in real time—from a huge range of credit indicators to the likelihood of storms and
droughts—that may be precursors to a risk event (see sidebar: Key risk sensing survey
results).
• Modeling and scenario analysis: Given the role of interrelated risks in strategic risk impact-
and-response modeling, generating scenarios that incorporate multiple risks can clarify the
likely impact of risk events.
• Response capabilities: Not all risks can be anticipated; however, simulating responses to
risk events and developing response plans can help improve response capabilities.

Transforming strategic risk management goes even further. It includes broad and deep risk
analysis, scenario planning, and contingency, resiliency, and recovery plans. It examines risks
generated by a strategy as well as risks to the strategy. It considers potential strategic risks in
decisions related to market entry or expansion, product initiatives, M&A activities,
compensation plans, new hires, and talent management. At the same time, it fosters awareness
of strategic risks across the organization and of potential opportunities that developments may
present to generate value and gain competitive advantage.

Scan, discover, and prepare


Many organizations believe they are already managing strategic risks when they are not. This
is particularly the case when it comes to emerging strategic risks— early-stage, off-the-radar
developments that can rapidly escalate or morph into value killer risks.
To address this, Deloitte has developed the following iterative, three-step approach to scanning,
discovering, and preparing for strategic risks (see Figure 3):

• Discover: Employ analytics and human capabilities to identify potential risks and gauge
potential outcomes
Use scenario planning to identify potential impacts

• Conduct simulations to gauge potential outcomes and responses

• Scan: Monitor the environment and interpret the signals

• Apply risk sensing technologies and tools to big data and media feeds
• Analyze signals being tracked

For Private Circulation Only 16


• Summarize results in dashboard or executive summary formats
Add insight through human analysis

• Prepare: Identify responses that will mitigate impacts or exploit risks for advantage

• Reassess your assumptions and identify new strategic options


• Develop contingency and recovery plans
• Mitigate and manage risks (such as insurance, hedging, diversification, or exit)

An Integrated approach to strategic risk.

Goals of strategic risk transformation


In an organization that has transformed its approach to strategic risk, the following five
conditions prevail:

• Senior leaders manage strategic risks proactively: Senior executives, in concert with the
Chief Risk Officer (CRO), if present, and business-unit leaders, work proactively to identify,
detect, monitor, and address strategic risks. Contingency and response plans are in place, with
specifics such as backup sources of capital identified. Insurance, diversification, hedging, and
other tools are used to mitigate strategic risks. The board and management appropriately
disclose strategic risks and measures taken to address them.
• Transactional and portfolio risks are well understood: Strategic decisions determine the
kinds of transactions the organization will engage in and the portfolios it will construct. While
there are tools for analyzing quantifiable risks in these areas, management realizes that less
quantifiable risks are generally less understood. Therefore, management looks beyond
quantifiable risks to assess all strategic risks.

For Private Circulation Only 17


• Risk infrastructure is aligned with business strategy: The risk governance and
management infrastructure is capable of recognizing and addressing strategic risks. This
infrastructure includes the risk-related roles and responsibilities of individuals, as well as
policies, procedures, and mechanisms for managing risk. The risk culture and business strategy
must be aligned in order for a strategy to succeed. This alignment also enhances the three lines
of defense of risk governance.
• Capital allocation is in line with risk appetite: While moving to increase capital efficiency
and meet regulatory expectations, management understands the risks of new business models
and changes to the risk profile. They therefore adjust the risk appetite— or the strategy—to
allocate capital to the most profitable uses.

 Regulatory environment is factored into strategy: Regulatory issues are considered in the
business strategy, as are issues of talent, organizational culture, and risk governance resources.
In addition, strategic flexibility enables the organization to adapt its strategy as regulations
evolve.
 Monitor strategic risks at all levels: Although strategic risks are owned at the C-suite and
board level, risk sensing capabilities are needed on the front lines of most business units and
functions.
 Protect drivers of value: Given that strategic risks can undermine drivers of value,
management should use specific methods appropriate for the organization to identify threats to
those drivers
 Develop strategic flexibility: In a rapidly changing environment, the ability to modify a
strategy or adopt an alternative one when needed can earn high rewards.
 Extend risk management: Risk transformation extends risk management down to the levels
where risks can be identified, tracked, and managed in the businesses and functions.
 Go beyond covering regulatory bases: Regulators are driving much of the rationale for
change. This can prompt leaders to see regulatory compliance as the chief priority.

Case study: -1-Aligning risk strategy to GRC structures

A major oil and gas company was struggling to align its risk function mandate with other risk
and assurance functions to meet management and broader stakeholder expectations. Deloitte
worked with the key governance, risk, and assurance functions to develop an integrated
strategy, mandate, and operating model to ensure delivery of the risk strategy and to embed
sound risk practices across the organization.
This involved:
• Assessing and aligning the risk function and the broader governance, risk, and compliance
(GRC) operating models
• Aligning the risk function and GRC operating model with stakeholder expectations
• Designing risk processes and assurance processes and functions, including governance,
regulatory compliance, legal, ethics, forensics, and internal audit functions

For Private Circulation Only 18


• Aligning risk and broader GRC functions and processes across a common value chain to
identify common process and methodology touch points and to integrate reporting and other
outputs
• Developing an integrated business case to drive change and deliver an integrated mandate,
internally and to stakeholders
Key results included:
• A practical integration and alignment of GRC functions, processes, and work methods
• A transformation strategy and business case for integrating key governance, risk, and
assurance functions at both the process and systems levels
• A common understanding and strategy to ensure efficient delivery of the risk and assurance
strategies to the business

Case study:2 Assessing a financial institution's risk and pricing strategies


The bank wanted a strategic assessment of pricing across its businesses to achieve adherence
with leading practices in pricing capabilities and execution.
This involved:
• Conducting a series of interviews to identify the different views of specific business
stakeholders and executives
• Documenting pricing practices across all relevant stages of the credit lifecycle
• Deploying a pricing assessment framework to assess existing policies, practices, and
procedures in light of global leading practices in pricing
• Identifying significant pain points in pricing analytics, governance, strategy, and execution
• Prioritizing gaps between current and desired practices
Key results included:
• Definition of an end-to-end pricing strategy that served as a platform for subsequent pricing
enhancement initiatives
• Identification of sector issues and their impacts while distinguishing between strategic and
tactical responses required to sustain long-term growth
• Development of a means of comparing profitability and return benchmarks for other
portfolios

1.11 Importance of Strategic Risk


One of the most important responsibilities—perhaps the most important responsibility of the
board of directors and senior management—is setting the company’s strategic direction in
order to maximize shareholder value. To do so, executives must be able to anticipate key trends
and future opportunities. But of course no matter how confident you may be, the future is not
foreseeable. In other words, strategy involves risk. As senior management gathers to set
strategic priorities, it is faced with a daunting task. Each decision is, in essence, a wager that
bets the company’s available resources on informed predictions about macroeconomic,

For Private Circulation Only 19


industry, and market trends. They are betting on the company’s core competencies and its
ability to find areas of growth even as it tries to avoid visible and unforeseen pitfalls. How large
a bet that management and the board are willing to make depends on the size of the
organization, its maturity, and how capable the company is to face the risks and opportunities
before it. A winning bet will increase shareholder value, while ill-advised or bad bets may
reduce value or, in the worst case, destroy it entirely. E.g. Reliance Jio entry into the low cost
and affordable mobile, wireless at cheaper costs than existing players which has changed th
entire contours of the telecom industry and brought out a major data connectivity revolution in
the smaller towns and villages of India.

Strategic risk can be defined as any risk that affects or is inherent in a company’s business
strategy, strategic objectives, and strategy execution. The list includes: • Consumer demand •
Legal and regulatory change • Competitive pressure • Merger integration • Technology change
• Senior management turnover • Stakeholder pressure. Other risks may qualify for particular
companies depending on the nature of their business. Siemens, the European conglomerate,
captures this sentiment in its broad definition of strategic risk: “everything, every obstacle,
every issue that has the potential to materially affect the achievement of our strategic
objectives.

Strategic Decisions Have a High Failure Rate

While reliable statistics are difficult to come by, it is no secret that many strategic initiatives
fall short of expectations. The oft-quoted 70% failure rate enshrined in management lore may
lack empirical support. But high success rates are still the exception rather than the rule. In
2008, John Kotter, a leading expert in change management, summed up his experience: He
says -From years of study, I estimate today more than 70% of needed change either fails to be
launched, even though some people clearly see the need, fails to be completed, even though
some people exhaust themselves trying, or finishes over budget, late, and with initial
aspirations unmet. Whatever the true failure rate for strategic initiatives, companies have every
incentive to improve performance by increasing the likelihood that they will achieve strategic
goals at least in some measure.

For Private Circulation Only 20


Strategic risk can take various forms. One is simply pursuing the wrong strategy, such as over
investment in a new product or a pursuit of the wrong acquisition candidate. Even with the
right strategy, failing to execute the strategy effectively is another risk. There is also the risk
of inaction or not responding to key market trends. Outside factors, such as customer trends
and emerging technologies, may render the existing strategy ineffective or outdated. This has
become increasingly common in an age when mobile devices are replacing desktop computers
(which themselves had replaced mainframes). In these cases, being on the wrong side of
technological evolution can destroy considerable value. But if you’re the disruptor, you can
actually use these same opportunities to create enormous value. Finally, strategy execution will
likely impact the overall risk profile of the company, including second-order strategic risks,
operational risks, and financial risks. All of these risks must be considered as part of ERM.

Companies ignore strategic risks at their peril. Independent studies of the largest public
companies have shown time and again that strategic risks account for approximately 60% of
major declines in market capitalization, followed by operational risks (about 30%) and
financial risks (about 10%). Yet, in practice, many ERM programs downplay strategic risks or
ignore them entirely. There are some historical reasons for that. When companies began to
develop formal ERM programs in the early 1990s, they focused almost exclusively on financial
risk, due to some high-profile losses stemming from derivatives and the fact that financial risk
(i.e., interest rate risk, market risk, credit and counter party risk, and liquidity risk) is more
quantifiable.

1.13 Managing Strategic Risk

Strategic risk management addresses the question of what specific decisions and actions are
required to optimize the long-term risk-return profile of the company. Key decision points
include:

• Risk acceptance or avoidance: The organization can decide to increase or decrease a specific
risk exposure through organic growth, its core business (new product and business
development), mergers and acquisitions (M&A), and financial activities.

• Risk-based pricing: All organizations take risks in order to be in business, but there is only
one point at which they can get compensated for the risks that they take. That is in the pricing
of their products and/or services, which should fully incorporate the cost of risk.

For Private Circulation Only 21


• Risk mitigation: This involves the implementation of business and risk control strategies in
order to manage strategic risk within defined risk tolerance levels.

• Risk transfer: If risk exposures are excessive and/or the cost of risk transfer is lower than
the cost of risk retention, an organization can decide to execute risk transfer strategies through
the insurance or capital markets.

• Resource allocation: An organization can allocate human and financial resources to business
activities that produce the highest risk-adjusted returns in order to maximize firm value.

Risk management is an ongoing process, and strategic risk is no exception. Though it presents
its own particular challenges, monitoring strategic risk can give companies a critical “heads-
up” to oncoming obstacles. This, in turn, offers the greatest possible latitude when it comes to
adjusting strategic or tactical efforts in order to mitigate downside risk or take advantage of an
unexpected opportunity.

Stakeholder requirements: Beyond regulators, the expectations and requirements of other


stakeholders—such as customers, rating agencies, stock analysts, business partners—can help
in the development of KRIs based on variables that are important to these key groups. The
strategy has to provide for organization to achieve its core mission and increase value to its
stakeholders – customers, employees, shareholders, vendors, regulators and society,
community.

Strategic risk can result throughout the strategy development and execution processes,
including:

• Design and development of the corporate strategy, including alignment with the core mission,
business-unit strategies, and operating budgets;

• Execution of the corporate and business-unit strategies to achieve key organizational


objectives;

• Actions and reactions from customers, suppliers, and competitors, as well as the impact of
emerging technologies; and

• Resultant risks (which can be strategic, operational, or financial risks) from the execution of
corporate and business-unit strategies, including the utilization of risk appetite and risk capacity

Conclusion

For Private Circulation Only 22


Strategic risks often pose greater threats than those posed by other types of risks. Yet most
organizations and management teams remain focused primarily on financial, operating,
security, and regulatory compliance risks— for understandable reasons. Managing those risks
is their primary risk management focus and in many industries regulatory demands have
reached new heights.
However, strategic risk can destroy huge amounts of value, very quickly. They can jeopardize
lines of business or the entire enterprise. Therefore, strategic risks demand attention and
resources and a trans-formative approach.
Transforming strategic risk enables executives and boards to understand and address a broad
range of risks and interactions among risks. It enhances business and operating models, as well
as risk governance and risk culture. This transformation encourages management to adjust
strategies or their implementation in response to changing conditions, while prompting the
board and the CRO to challenge the assumptions underlying strategic decisions.

Relationship between Risk and Stakeholder and Shareholder perception

The organization has many stakeholders and their perceptions of each are quite different.
The different stakeholders can be classified as follows: -

1. Shareholders- Represent owners of the entity or the promoters. They are contributing
funds to the corporate for start-up and growth, and would need to be appraised of the
current situation of risk and perceptions in the organisational policies. If not suitable
they may exit the company by withdrawing the investments. If investments are made
in areas where the risk is going to be very high they need to be advised in advance and
necessary approval may have to be taken. Otherwise the project or investment will
likely find resistance at a later stage when approvals are sought from shareholders. They
have the power as a owner and this may likely create issues for the company, and affect
its overall operations and possibly growth options too.
2. Employees/ workers- Represent key internal stakeholders who will have to take along
as they have a high stake in the organisation if too high a risk is taken they may not like
to continue
3. Customers – They are the key to success or failure of enterprise. Their perception is
mostly valued and crucial for organisations.

For Private Circulation Only 23


Reference books: [Link] of Leadership and Management (IoL&M) study material
2. ICAI risk management study material.
3. Hopkins, Paul - Fundamentals of Risk Management ( 5th edition)(Chapter -1 )
[Link]
4. Roberts, Alexander, Wallace William et al, -( publication of Heriott watt university –
2012 ) –Strategic Risk Management

Terminal questions:
Section A: 5 marks
1. Discuss the objectives and Process of Risk management.
2. State Difference between sheet between risk and uncertainty.
3. Explain types of risk in detail.
4. Discuss about strategic risk.
5. State the relationship between risk and stakeholder and shareholder perception.

Section B 9 marks
1. Explain financial risk and market risk.
2. Discuss the need of necessary shift in perspective with regarding to strategic risk.

3. Elaborate on environmental risk and operational risk in detail.

Section C 12 marks
1. Discuss the importance of strategic risk and managing the strategic risk.

Reference Books:

[Link] of Leadership and Management (IoL&M) study material

2. ICAI risk management study material

For Private Circulation Only 24


Module II

Strategic Risk Management

Structure

2.1 Risk Appetite -Definition or Meaning


2.2 Factors influencing Risk Appetite
2.3 Risk attitude
2.4 Risk Culture
2.5 Risk Awareness and Risk Culture
2.6. Risk Manager Role in Risk identifying and monitoring risk
2.7 Risk Committee and its role
2.8 Internal Auditor and its role in Monitoring risk
2.9 External Auditor and its role in Monitoring Risk

2.1 Introduction

Risk appetite is a vitally important concept in the practice of risk management. However, it is
a very difficult concept to precisely define and apply in practice. Risk appetite is sometimes
considered to be defined by the risk criteria established by the organization. The risk appetite
or risk criteria are important components in the risk ranking phase of the risk management
process. This is the next phase of the risk management process after the risks have been rated
in terms of likelihood and impact. Risk appetite is the immediate or short-term willingness of
an organization to undertake an activity that involves risk. Risk attitude and the risk criteria
represent a longer-term view of risk in the same way as a person will have an immediate
appetite for food and a longer-term attitude towards food.

One of the fundamental difficulties with the concept of risk appetite is that, generally speaking,
organizations will have an appetite to continue a particular operation, embark on a project or

For Private Circulation Only 25


embrace a strategy, rather than a direct appetite for the risk itself. In other words, risk appetite
and risk exposure should be considered as a consequence of business decisions rather than a
driver of those decisions. The decision on risk appetite is normally taken within the context of
other business decisions, rather than as a stand-alone decision. The typical advice in most risk
management standards is that risk should not be managed out of context, so questions about
the risk appetite can only be answered within the context of the strategy, tactics, operations and
compliance activities being considered. Risk appetite is the total value of the corporate
resources that the board of the organization is willing to put at risk. Most organizations have
not determined the value they should risk (risk appetite), nor calculated how much value is
actually at risk (risk exposure), nor the capability of the organization to

take risk (risk capacity). A range of definitions of risk appetite is shown in Table 25.1 and it is
obvious that different professional bodies have produced very similar definitions of risk
appetite. - Organisation Definition of Risk Appetite-

IRM 2011 The amount of risk that an organization is


willing to seek
or accept in the pursuit of long-term
objectives
ISO guide (2009) The amount and type of risk that an
organization is willing to pursue or retain
Orange book ( 2004) The amount of risk that an organization is
prepared to accept, tolerate or be exposed to
at any point in time
CIIA (2005) The level of risk that is acceptable to the
board or management. This may be set in
relation to the organization as a whole, for
different groups of risks or at an individual
risk level.
ISO 31000 The amount and type of risk that an
organisation is prepared to pursue, retain or
take.

For Private Circulation Only 26


An organization should be able to decide how much it wishes to put at risk, based on the attitude
of the organization to risk. Agreeing the risk appetite will ensure that the organization does not
put too much (or too little) value at risk. The risk capacity of the organization needs to be fully
utilized to ensure that risk taking is at the optimal level and delivers maximum benefit.
Similarly, the organization should not put more value at risk than is appropriate, given the
sector in which it operates and prevailing market conditions.

Risk Appetite for a manufacturing organisation

Business Component Risk Appetite statement


Target Credit Rating Maintain a credit rating of at least BBB+
Earnings Per share Maintain an earnings per share level within
the upper quartile of the peer group
Target Capital Ratio Maintain a debt-to-capital ratio in the range
45% to 50%
Financial Strength Maintain an earnings-before-interest and
taxes-to-interest
ratio between 5% and 7.5%

2.2 Risk Appetite can vary based on a number of factors such as-

a) Industry- Certain industries are more likely to be capable of taking higher risks like IT,
Technology etc. On the contrary entities in manufacturing typically tend to be conservative in
their approach

b) Company culture – Companies in certain culture have more risk taking abilities as
compared to others. For e.g. German companies are more risk conscious and follow a
systematic approach to risk, as compared to other European Entities, while US based
companies are more oriented towards risk seeking. In the Indian context the Reliance group,
Adani Group is said to be having higher risk appetite as compared to others like Godrej,
Piramal, Tatas etc.

c) Nature of objective to be pursued – It is a very vital aspect of risk appetite and can vary
across organisations. It is difficult for an entity to take a high risk in an area having sensitive
consumers or values which are ingrained into society or value and belief system.

For Private Circulation Only 27


d) Financial strength and capabilities – The greater the financial strength of the organization
– the greater the risk it can take – e,.g major projects are taken by Reliance and Tata’s as
compared to others based on their financial strength only. Even the recent acquisition of AI by
Tata’s is a case in point.

e) Competitors – If the sector is one where competitors are highly active and taking risks, the
entity in that sector too will have to possess higher appetite, as otherwise survival chances are
low. Competition thus becomes a key factor in the process.

f) Portfolio size - The bigger the portfolio, the greater the risk appetite. An investor with a $50
million portfolio may take on greater risk than an individual with a $5 million portfolio. If the
value of the portfolio falls, the percentage loss is significantly lower in a bigger portfolio than
in a smaller portfolio.

g) Comfort level - Each investor approaches to risk in a unique way. Some investors are
inherently more willing to take risks than others. Market volatility on the other hand, may be
exceedingly distressing for certain investors. As a result, risk appetite is closely tied to how
comfortable an investor is with taking risks.

2.3- Risk Attitude

Risk Attitude -The terms risk attitude, appetite, and tolerance are often used similarly to
describe an organization's or individual's attitude towards risk-taking. One's attitude may be
described as risk- averse, risk-neutral, or risk-seeking. Risk attitude is the chosen position
adopted by an individual or group towards risk, influenced by risk perception and pre-
disposition.

2.4 Risk Culture

Risk –Culture -An effective risk culture is one that enables and rewards individuals and groups
for taking the right risks in an informed manner. Risk culture is the values, beliefs,

knowledge and understanding about risk, shared by a group of people with a common intended
purpose, in particular the leadership and employees of an organisation A successful risk culture
would include the following: -

a) A distinct and consistent tone from the top from the board and senior management in
respect of risk taking and avoidance (and also consideration of tone at all levels).

For Private Circulation Only 28


b) A commitment to ethical principles, reflected in a concern with the ethical profile of
individuals and the application of ethics and the consideration of wider stakeholder
positions in decision making.
c) A common acceptance through the organisation of the importance of continuous
management of risk including clear accountability for and ownership of specific risks
and risk areas.
d) Transparent and timely risk information flowing up and down the organisation with bad
news rapidly communicated without fear of blame.
e) Encouragement of risk event reporting and whistle blowing, actively seeking to learn
from mistakes and near misses.
f) No process or activity too large or too complex or too obscure for the risks to be readily
understood.
a) Appropriate risk taking behaviours rewarded and encouraged and inappropriate
behaviours challenged and sanctioned.
b) Risk management skills and knowledge valued, encouraged and developed, with
a properly resourced risk management function and widespread membership of and
support for professional bodies. Professional qualifications supported as well as
technical training.

Sufficient diversity of perspectives, values and beliefs to ensure that the status quo is
consistently and rigorously challenged.

In the past cases like Enron,Libor Manipulation, Space shuttle disaster , were absent in
these features. Alignment of culture management with employee engagement and
people strategy to ensure that people are supportive socially but also strongly focused
on the task in hand.

The ten basic indicators of risk culture that would be displayed in a risk mature organization
can be listed as follows: -

1. Risk management is the process of identifying, assessing and controlling threats to an


organization's capital and earnings. These risks stem from a variety of sources including
financial uncertainties, legal liabilities, technology issues, strategic management errors,
accidents and nature Distinct and consistent tone from the top on risk-taking
2. Commitment to ethical principles and practice

For Private Circulation Only 29


3. Wide acceptance of importance of managing risk
4. Transparent and timely risk information flow up and down
5. Risk reporting and whistle-blowing is encouraged
6. Active learning from impacted risks and near-misses
7. Risk-taking behaviours rewarded or challenged
8. Risk management skills are valued, encouraged and developed
9. Properly resourced risk management function
10. Regular challenging of status quo from diverse perspectives
Although there is no single right way to measure risk culture, there are a number of

diagnostic tools available that can be used to indicate and then track the risk culture in an

organisation. The mix of tools and the order of their deployment will depend on the context

of the organisation and its risk management maturity.

We set out the details of the models, tools and approaches that we have found useful in our
companion document.

Risk Culture: Resources for Practitioners.

IRM has defined a Risk Culture Framework around which to analyse, plan and act to influence
risk culture within any organisation. We look at the effects of predisposition towards risk and
personal ethics in shaping attitudes and behaviours and we look at the role of organisational
cultures.

Figure 1 below attempts to distil what is a complex and interrelated set of relationships into a
simple and high level. approach to looking at the various influences on risk culture. Risk culture
is the sum of multiple interactions. At the lowest level, each individual’s personal
predisposition to risk contributes to their ethical stance, how they behave and make decisions.
Group behaviours and the underlying organisational culture also influence risk culture. There
may be concern that the culture of the organisation is attracting and encouraging individuals
whose inherent ethical stance or risk-taking predisposition may be at odds with the board’s
commitment to high standards of integrity in dealing with all stakeholders. Taxi drivers and
airline pilots are routinely given personality tests to determine how effectively they can exhibit
self-control under stress – we should be ready to look at other key staff, managers and board
members in the same way.

For Private Circulation Only 30


Every individual comes to an organisation with their own personal perception of risk. People
vary in all sorts of ways and this includes their predisposition towards risk. Personality research
identifies two specific traits that contribute to this:

• The extent to which people are either spontaneous and challenge convention or organised,
systematic and compliant;

• The extent to which people may be cautious, pessimistic and anxious, or optimistic, resilient
and fearless. Figure below shows IRM risk Culture framework: -

This model, developed by the IRM, identifies eight aspects of risk culture, grouped into four
themes, key indicators of the ‘health’ of a risk culture: aligned to an organization’s business
model. Diagnosis can be by means of a simple questionnaire or structured interview techniques.
A gap analysis provides pointers to areas of strength and weakness and hence allows
prioritization and focus to be brought to what can be a difficult set of issues to grasp.

The focus is on identifying tangible actions that be taken to address areas of concern,drawing
from a tool kit. The model presupposes a continuous improvement approach where a risk
culture is moved incrementally and performance tracked over time. It is important to recognize
where positive culture cycles need to be reinforced, and vicious cycles broken, to make a step
change improvement.

Tone at the top is determined by the following factors: -

• Risk leadership - clarity of direction

For Private Circulation Only 31


• How the organisation responds to bad news

Governance is key and important for

• The clarity of accountability for managing risk

• The transparency and timeliness of risk information

Competency is vital and desirable for

• The status, resources and empowerment of the risk function

• Risk skills - the embedding of risk management skills across the organisation

Decision making must be based on

• Well informed risk decisions

• Appropriate risk taking rewarded and performance management linked to risk taking.

IRM Culture Aspects Model

The risk culture aspects model links with the sociability vs. solidarity analysis through planned
action to address deficiencies in the current culture. The interventions required may relate to
driving an increase in the levels of sociability and/or solidarity and pushing the organisation
into a position more conducive to effective risk management. The risk culture aspects model
specifically links the aspects shown in red in the diagram to greater impact on sociability and
the blue aspects to improvements in solidarity.

For Private Circulation Only 32


2.5 Risk Awareness

Risk awareness is the recognition of the potential for hazards, risks, and incidents that occur
within the healthcare environment and result in patient harm. In another word Risk awareness
is the raising of understanding within the population of what risks exist, their potential impacts,
and how they are managed.

Risk awareness and response agility are critical when incidents occur, but reaction times can
be particularly hindered when an organisation has grown too rapidly. This is because in the
process of fast and disparate growth, functions can become siloed, operating autonomously
using different – or non-comparable – reporting programmes. As such, they can’t be governed
and reviewed by the board in the same context. This was one of the key issues that made the
2008 financial crash so severe, with no corporate oversight – and organisations’ strategies
aiming for maximum growth at any cost – individual departments went rogue creating an illicit
black hole in the financial system.

Every executive hopes their company is alert to risks and that they can be resilient when hit
with disaster but with the speed and ferocity of risks ever-increasing, it is not always possible.
In an age where it only takes one employee – or one tweet – to smear the reputation of some
of the largest organisations, efficient and effective risk responses are vital.

To build a risk aware organisation, companies need to invest in risk awareness and management
programmes and work toward creating a transparent corporate culture.

Here are six steps to help businesses achieve this.

[Link] the compliance function

3. Assess enterprise risk management (ERM) programmes

4. Solidify operational risk management (ORM) processes

5. Ensure effective business continuity management (BCM)

6. Use a top-down and bottom-up approach to establish a good culture

7. Utilise technology

For Private Circulation Only 33


2.6 Role of Risk Manager

The Role of a Risk Manager varies across from entity to entity, but broadly some of the roles
played by him are as follows; -

 Provide a methodology to identify and analyze the financial impact of loss to the
organization, employees, the public, and the environment.
 Examine the use of realistic and cost-effective opportunities to balance retention
programs with commercial insurance.
 Prepare risk management and insurance budgets and allocate claim costs and premiums
to departments and divisions.
 Provide for the establishment and maintenance of records including insurance policies,
claim and loss experience.
 Assist in the review of major contracts, proposed facilities, and/or new program
activities for loss and insurance implications.
 In cooperation with General Counsel, maintain control over the claims process to assure
that claims are being settled fairly, consistently, and in the best interest of the entity.
 A Risk Manager is held accountable for analyzing, assessing, and handling the risks
faced by the organization.
 They assist the organizations regarding any sort of risks that might affect the
profitability of the organization and develop strategies and processes for managing
those business risks and ensure successful business continuity.

 The foremost task of the Risk Manager is to gather the data and carry out investigations
to recognize the risks that an organization might be exposed to. As a part of the
investigation process, the Risk Managers should analyse key risk indicators (KRI) and
conduct what-if-analyses to determine the concerns if the risks identified in the process
are about to occur. A few of the concerns/consequences include threat/leaking
organization’s confidential information, financial loss, and damage to the
organization’s assets.

 Risk Managers are also involved in implementing control systems and action plans for
safeguarding the organization’s assets and resources. This is done through mitigating
risks and potential damage caused.

For Private Circulation Only 34


 The steps taken by the Risk Manager in mitigating the risk varies from organization to
another. Some of the measures taken include defining crisis management, designing
business continuity plans, introducing operation protocols, insurance coverage, and
updating the procedures correlating to the latest best practices.

 Conducts risk assessments, collecting and analysing documentation, statistics, reports,


and market trends.
 Establishes policies and procedures to identify and address risks in the organizations
services and departments.
 Reviews and assesses risk management policies and protocols; makes
recommendations and implements modifications and improvements.
 Recommends and implements risk management solutions such as insurance, safety and
security policies, business continuity plans, or recovery measures.
 Reviews and analyzes metrics and data such as cash flow, inventory, breakage, and
employee activity that could uncover fraudulent behaviour.
 Drafts and presents risk reports and proposals to executive leadership and senior staff.
 Performs other duties as directed

Skill sets needed to be a risk manager

 Should possess good knowledge of risk assessment models.

 Should possess awareness of statistical tools and auditing and reporting procedures. 

 Should possess the ability to execute office automation tools and risk monitoring
and testing procedures. 

 Should possess attention to minute details.

 Should possess exceptional verbal and communication skills.

 Should possess time management and organizational skills.

 Should possess negotiation and diplomacy skills.


 Should be reasonably proficient in use and application of new technologies and have
good inter personal relations in his interaction with other departments 
 Thorough understanding of policies and best practices of risk management. 

For Private Circulation Only 35


 Excellent verbal and written communication skills.
 Excellent mathematical and critical thinking skills.
 Excellent analytical and problem-solving skills.
 Excellent organizational skills and attention to detail.
 Strong supervisory and leadership skills.
 Proficient with Microsoft Office Suite or related software to prepare reports and
policies.

The Role of Risk manager in Identifying and monitoring risk can be defined as under: -

Organizations and companies typically assemble a risk management team to help decision
makers go through the risk management process. A member of the team is selected as a risk
manager to identify and monitor risks.

The Risk manager must gain an understanding of the environment in which the risks are to be
managed, taking into account political and policy concerns, mission needs, stakeholder
interests, and risk tolerance. He should define the context and will inform and shape successive
stages of the risk management cycle.

The prime role of a Risk manager in this regard are: -

8. Identify Potential Risk – The Risk Manager to consider a wide variety of risks to
support decision making. These considerations include strategic, operational, and
institutional risks.

The risks that are included in any particular assessment (sometimes called the assessment’s
scope) are largely determined by the decision the assessment is designed to inform.

Unusual, Unlikely, and Emerging Risks - Prior to conducting a risk assessment, it is important
to make a concerted effort to identify risks beyond those usually considered. For example, risks
that are newly developing, even if they are poorly understood. Risks that are highly unlikely
but have high consequences should also be identified and incorporated into the assessment.
This can even include identifying the risk of the unknown as a possible risk.

Brainstorming is a common technique to identify these unusual, emerging, and rare risks. So,

For Private Circulation Only 36


too, is involving a wide range of perspectives and strategic thinkers to avoid the trap of
conventional wisdom and groupthink. Even when a risk is difficult to assess, it may still be
important for Risk Manager to try to understand it. It should also be acknowledged that no
identification of risks is likely to capture every potential unwanted outcome — there will
always be things that happen that are unanticipated.

2 Assess and Analyze Risk – The Risk Manager is also needed to assess the identified risks
and analyze the outputs of the assessment. This step consists of several tasks:

1) - Determining a methodology;
2) - Gathering data;
3) - Executing the methodology;
4) - Validating and verifying the data; and
5) - Analyzing the outputs.

In practice, these tasks, like the steps of the larger risk management cycle, rarely occur linearly.
Instead, risk managers and practitioners often move back and forth between the tasks, such as
refining a methodology after some data has been gathered. Likelihood is the chance of
something happening, whether defined, measured, or estimated in terms of general descriptors,
frequencies, or probabilities.

Consequence, or impact, is the effect of an incident, event, or occurrence, whether direct or


indirect. In risk analysis, consequences include (but are not limited to) loss of life, injuries,
economic impacts, psychological consequences, environmental degradation, and inability to
execute essential missions.

3. Develop Alternatives - In order to improve the ability to prevent, protect against, respond
to, recover from, and mitigate a variety of manmade and natural hazards, Risk managers must
focus their attention on identifying and executing actions to manage risks. Ultimately, the
objective of risk analysis is to provide decision makers with a structured way to identify and
choose risk management actions. Within the risk management process, the step of developing
alternatives involves systematically identifying and assessing available risk management
options. The Risk Manager develops alternative plans and mitigation plans for the risks
identified and brings together the proposed action plan within a framework and charts out the
course of action for each risk identified, together proposed risk management actions with the
results of a risk assessment. This provides leaders and top management with a clear picture of
the risk management benefits of each proposed action or group of actions. The picture of
potential benefits, when combined with an analysis of an action’s costs — both monetary and
For Private Circulation Only 37
non-monetary — can serve as a valuable resource for aiding decision makers in making
effective and efficient homeland security choices.

4. Decide Upon and Implement Risk Management Strategies - Risk management entails
making decisions about best options among a number of alternatives in an uncertain
environment. The key moment in the execution of any risk management process is when a
decision maker chooses among alternatives for managing risks, and makes the decision to
implement the selected course of action. This can include making an affirmative decision to
implement a new alternative, as well as the decision to maintain the status quo.

5. Evaluate and Monitor - Risk management is a process, not a project that can be
“finished” and then forgotten about. The organization, its environment, and its risks are
constantly changing, so the process should be consistently revisited, and evaluated. Determine
whether the initiatives are effective and whether changes or updates are required. Sometimes,
the team may have to start over with a new process if the implemented strategy is not effective.
If an organization gradually formalizes its risk management process and develops a risk culture,
it will become more resilient and adaptable in the face of change. This will also mean making
more informed decisions based on a complete picture of the organization’s operating
environment and creating a stronger bottom line over the long-term.

2.7 Risk Committee

The role of the committee is to perform an oversight function. In doing so, it should consider
the risk policy and plan, determine the company’s risk appetite and risk tolerance, ensure that
risk assessments are performed regularly, and ensure that the company has and maintains an
effective on-going risk assessment process, consisting of risk identification, risk quantification
and risk evaluation. This risk assessment process (using a generally recognised methodology)
should identify risks and opportunities, and measure their potential impact and likelihood. The
committee should receive assurance from internal and external assurance providers regarding
the effectiveness of the risk management process. In turn, management is responsible for the
design, implementation and effectiveness of risk management, as well as continual risk
monitoring.

It is of vital importance that members of the risk committee have experience within the
industry. This would allow them to identify areas of risk and be aware of the appropriate

For Private Circulation Only 38


methods of managing the company’s exposure via internal (the control environment) or
external (such as thorough insurance cover) means. Risk management is an often
misunderstood discipline within a company. Too often the responsibility for ensuring that the
significant risks identified and adequately managed is not acknowledged, or is inappropriately
delegated to the audit committee. There are two reasons why the risk management function
should not report to the audit committee, but should be monitored by a separate risk committee.
The first is that, as a consequence of the prescribed composition of the audit committee (all
members must be independent non-executive directors), the function will often have financial
focus when risk management should correctly extend far beyond the finances of a company.

Secondly, the audit committee should act as an independent oversight body. Having to directly
oversee the risk management function would generally involve a large amount of detailed
review of the processes and workings of the company. This would necessarily have a
detrimental effect on the objectivity of the audit committee’s members when considering
reports of the risk management function. The formation of a separate committee recognises the
fact that the identification and management of risks impacting the business, and the disclosure
of these to the shareholders is vital to good governance. Also, a combined audit and risk
committee will inevitably have a strong focus on financial risks, which may result in inadequate
attention to operation and related risk. It is our recommendation that the responsibility for risk
management be delegated by the board to a separate risk committee, comprising both executive
and non-executive directors. Where more than one committee bears responsibility for risk
management (i.e. the audit committee oversees financial risks and the remuneration committee
oversees risks pertaining to compensation), it is paramount that the responsibilities are clearly
demarcated and that communication channels are established to ensure that the respective
committees take cognisance of and consider the reports and recommendations of the other
relevant committees.

In considering whether or not to establish a risk committee one might consider the following
key factors:

• Inherent risk environment: The need for a risk committee may be precipitated by the
inherent risk environment. The extent, complexity, and potential impact of risks should be
considered, and weighed against the ability of the board or a board committee (e.g. the audit
committee) to deal sufficiently with workload.

For Private Circulation Only 39


 The needs of stakeholders: The needs of the enterprise and its stakeholders should be
considered. It may also behove the board to assess the quality and comprehensiveness of the
current risk governance and oversight structure, the risk environment, and the future needs of
the organisation. The composition and activities of the risk committee and its relationship with
other board committees could reflect the board’s assessment of those factors. • Alignment of
risk governance with strategy: The board should consider whether risk oversight and
management are aligned with management’s strategy. Enterprises vary widely in their business
models, risk appetite, and approaches to risk management. A key consideration is that the
board, management, and business units be aligned in their approach to risk and strategy - to
promote risk-taking for reward in the context of sound risk governance.
 Oversight of the risk management infrastructure: A question to consider is whether the risk
committee is responsible for overseeing the risk management infrastructure - the people,
processes, and resources of the risk management program - or whether the audit committee or
entire board will oversee it.
 Scope of risk committee responsibilities: The board may need to decide whether the risk
committee will be responsible for overseeing all risks, or whether other committees, such as
the audit committee or the remuneration committee, will be responsible for some. For example,
oversight of risks associated with financial reporting may remain under the audit committee,
while those associated with executive remuneration plans might remain with the remuneration
committee. But because functional risks (such as tax or human resources risk) are often
connected to operational or strategic risks, it is important to consider how the interconnectivity
of risks is addressed. In any event, the board will need to determine which committees will
oversee which risks.
 Communication among committees: The board should consider how the committees will
keep one another - and the board itself - informed about risks and risk-oversight practices.
Efficiency and effectiveness call for clear boundaries, communication channels, and handoff
points. This need may require the board to define these elements clearly, making adjustments
as needed.

General Role of risk committee

The risk committee will have specific responsibilities that include, but are not limited to,
oversight and approval of the enterprise risk management framework commensurate with the
complexity of the company including (note that these responsibilities are performed by the

For Private Circulation Only 40


committee on behalf of the board – ultimately the board remains responsible for the final
approval of the risk policy and risk management): • Oversight of risk appetite and risk tolerance
appropriate to each business line of the company • Appropriate policies and procedures relating
to risk management governance, risk management practices, and risk control infrastructure for
the enterprise as a whole • Processes and systems for identifying and reporting risks and risk-
management deficiencies, including emerging risks, on an enterprise-wide basis • Monitoring
of compliance with the company’s risk limit structure and policies and procedures relating to
risk management governance, practices, and risk controls across the enterprise • Effective and
timely implementation of corrective actions to address risk management deficiencies •
Specification of management and employees’ authority and independence to carry out risk
management responsibilities, and • Integration of risk management and control objectives in
management goals and the company’s compensation structure. To establish an appropriate risk
governance infrastructure, the board might consider defining the risk-related roles and
responsibilities of each committee as well as clear boundaries and communication channels
among them. The board will need to understand and define which committees are responsible
for which risks and how each committee oversees risks.

In developing risk committee charters, boards may wish to consider including provisions that
specifies: • The separate nature of the risk committee and that it has been established to exercise
enterprise-wide risk-oversight responsibilities • The risk-oversight responsibilities of the
committee and how it fulfils them • Who is responsible for oversight of management’s risk
committee, for example, whether it is the CRO, the risk committee, the full board, or the CEO
(although, typically, the full board is ultimately accountable and responsible for risk
governance) • Who is responsible for establishing the criteria for management’s reporting about
risk to the board (although the actual criteria need not be set in the charter, because they are
expected to change as the enterprise and risks change) • The composition of the risk committee
and the qualifications of risk committee members.

The board’s or risk committee’s responsibilities regarding the enterprise’s risk appetite, risk
tolerances, and utilisation of the risk appetite • The board’s or risk committee’s responsibility
to oversee risk exposures and risk strategy for broadly defined risks, including for example
credit, market, operational, compliance, legal, property, security, IT, and reputational risk.

The risk committee’s responsibility to oversee the identification, assessment, and monitoring
of risk on an on-going enterprise-wide and individual-entity or line of business basis • The risk

For Private Circulation Only 41


committee’s responsibility to approve the charter of the management risk committee - if the
board, in compliance with the company’s Memorandum of Incorporation, delegates that
responsibility to the risk committee • The reporting relationships between the risk committee,
the CEO, the CRO and the management risk committee • The risk committee’s oversight of
management’s implementation of the risk management strategy • The risk committee’s
responsibility to ensure that risk management is embedded in the business and all decision
making processes • The use of specialist in areas where risks are complex • Terms of service
of risk committee members and the chair, with incumbents subject to reappointment; term
limits (which may preclude members or chairs from having their terms renewed) may not be
desirable because they may cause the loss of individuals in valued roles.

In developing risk committee charters, boards may wish to consider including provisions that

Specifies as under :-

• The separate nature of the risk committee and that it has been established to exercise
enterprise-wide risk-oversight responsibilities and the risk-oversight responsibilities of the
committee and how it fulfils them

• Who is responsible for oversight of management’s risk committee, for example, whether it is
the CRO, the risk committee, the full board, or the CEO (although, typically, the full board is
ultimately accountable and responsible for risk governance)

• Who is responsible for establishing the criteria for management’s reporting about risk to the
board (although the actual criteria need not be set in the charter, because they are expected to
change as the enterprise and risks change)

• The composition of the risk committee and the qualifications of risk committee members

• The board’s or risk committee’s responsibilities regarding the enterprise’s risk appetite, risk
tolerances, and utilisation of the risk appetite • The board’s or risk committee’s responsibility
to oversee risk exposures and risk strategy for broadly defined risks, including for example
credit, market, operational, compliance, legal, property, security, IT, and reputational risks

The risk committee’s responsibility to oversee the identification, assessment, and monitoring
of risk on an on-going enterprise-wide and individual-entity or line of business basis

For Private Circulation Only 42


• The risk committee’s responsibility to approve the charter of the management risk committee
- if the board, in compliance with the company’s Memorandum of Incorporation, delegates that
responsibility to the risk committee.

• The reporting relationships between the risk committee, the CEO, the CRO and the
management risk committee.

• The risk committee’s oversight of management’s implementation of the risk management


strategy.

• The risk committee’s responsibility to ensure that risk management is embedded in the
business and all decision making processes.

•The use of specialist in areas where risks are complex, the terms of service of risk committee
members and the chair, with incumbent’s subject to reappointment; term limits (which may
preclude members or chairs from having their terms renewed) may not be desirable because
they may cause the loss of individuals in valued roles.

Risk committee members may be recruited from the current board and should ideally include
a combination of executive and non-executive directors.

The Roles and responsibilities of the Risk committee are as follows:


Role of Risk Committee
 To assess the Company’s risk profile and key areas of risk in particular.
 To recommend he Board and adoption of risk assessment and rating procedures.
 To articulate the Company’s policy for the oversight and management of business risks.
 To examine and determine the sufficiency of the Company’s internal processes for
reporting on and managing key risk areas.
 To assess and recommend the Board acceptable levels of risk.
 Todevelopandimplementariskmanagementframeworkandinternalcontrolsystem.
 To review the nature and level of insurance coverage.
 To have special investigations into areas of corporate risk and break -downs in internal
control.
 To review management’s response to the Company’s auditors’ recommendations
those are adopted.
 To report the trends on the Company’s risk profile, reports on specific risks and the
status of the risk management process.

For Private Circulation Only 43


Responsibility
 To define the risk appetite of the organization.

 To exercise oversight of management’s responsibilities, and review the risk profile of


the organization to ensure that risk is not higher than the risk appetite determined by
the board.

 To ensure that the Company is taking appropriate measures to achieve prudent balance
between risk and reward in both ongoing and new business activities.

 To assist the Board in setting risk strategies, policies, frameworks, models and
procedures in liaison with management and in the discharge of its duties relating to
corporate accountability and associated risk in terms of management assurance and
reporting.

 To review and assess the quality, integrity and effectiveness of the risk management
systemsandensurethattheriskpoliciesandstrategiesareeffectivelymanaged.

 To review and assess the nature, role, responsibility and authority of the risk
management function within the Company and outline the scope of risk management
work.

 To ensure that the Company has implemented an effective ongoing process to identify risk,
to measure its potential impact against a broad set of assumptions and then to activate
what is necessary to pro -actively manage these risks, and to decide the Company’s
appetite or tolerance for risk.

 To ensure that a systematic, documented assessment of the processes and outcomes


surrounding key risks is undertaken at least annually for the purpose of making its
public statement on risk management including internal control.

 To oversee formal reviews of activities associated with the effectiveness of risk


management and internal control processes. A comprehensive system of control
should be established to ensure that risks are mitigated and that the Company’s
objectives areattained.

 To review processes and procedures to ensure the effectiveness of internal systems of


control so that decision-making capability and accuracy of reporting and financial

For Private Circulation Only 44


results are always maintained at an optimal level.

 To monitor external developments relating to the practice of corporate accountability


and the reporting of specifically associate risk, including emerging and prospective
impacts.

 To provide an independent and objective oversight and view of the information


presented by the management on corporate accountability and specifically associated risk,
also taking account of reports by the Audit Committee to the Board on all categories
of identified risks facing by the Company.

 To review the risk bearing capacity of the Company in light of its reserves, insurance
coverage, guarantee funds or other such financial structures.

 To fulfill its statutory, fiduciary and regulatory responsibilities.

 To ensure that the risk awareness culture is pervasive throughout the organization.

 To review issues raised by Internal Audit that impact the risk management framework.

 To ensure that infrastructure, resources and systems are in place for risk management is
adequate to maintain a satisfactory level of risk management discipline.

 The Board shall review the performance of the risk management committee annually.

 Perform other activities related to risk management as requested by the Board of


Directors or to address issues related to any significant subject within its term of
reference.

2.8 Role of Internal Auditor in Mitigating Risk

Internal auditors can be responsible for carrying out regular ' annual, in many cases '
assessments of an organization's risk management program, particularly as they relate to
regulatory compliance. The audit compliance report forms the basis of continuous
improvement, identifying any shortcomings and enabling compliance teams to put in place
remedial actions, while developing an effective compliance and audit strategy that could be a
central part of any compliance program. Having this level of compliance monitoring gives the
business assurance that the risks they face are being tackled, and that appropriate steps are
being taken to identify and manage the full range of business risks.

For Private Circulation Only 45


Key to this is the ability of compliance and internal audit teams to work together in order to
deliver a 360-degree solution to risk assessment and mitigation as they relate to regulatory
compliance requirements. In fact, the roles should be quite different. While the compliance
team carries out ongoing measurement of their processes and effectiveness, the audit process
is more a snapshot of compliance at a given time; perhaps a once-a-year event that takes an
objective and independent look at compliance and risk management. When it comes to risk,
the internal audit function is primarily to give the organization's board and senior leadership
assurance that the business is managing risk successfully. Ideally, this assurance is two-fold:
confirming that the organization's biggest business risks are being managed effectively, and
that the processes that govern and monitor this are themselves effective. The internal auditor
may also play a consultative role; not just delivering verdicts on the effectiveness of current
risk management approaches, but advising on ways to improve them. Here, certain precautions
may be needed to ensure that the auditor remains objective ' more of which below as the lines
between audit and implementation potentially blur. While advising on best practice risk
management processes should cause no issues, auditors who assume any kind of management
responsibility for implementing these processes risk conflicts of interest when also reviewing
them.

In many ways, the internal audit function is ideally placed to lead on risk. Internal auditors
have an understanding of risk and its implications on a par with their risk manager colleagues;
in fact, they have a comprehensive oversight of all things governance, risk and compliance.

Typically, internal auditors are objective and analytical ' also key competencies for anyone
providing impartial assessment. They tend to take a moderate approach to risk, demonstrating
neither extremely risk-averse or high-risk behaviours. When reviewing risk management
processes, it's vital that internal audit is able to access a full picture of current performance,
and the procedures in place to manage and respond to the risks identified.

All too often, risk data is collated inconsistently, and obligations not clearly defined ' causing
headaches for any auditor trying to build a complete overview. Increasingly, compliance, risk
and internal audit teams are turning to compliance software solutions to deliver comprehensive
compliance and risk management programs, facilitating implementation, management and
monitoring.

For Private Circulation Only 46


Role of Internal Audit

According to the IIA the following are the acceptable role of Internal Audit

Core IA roles in ERM

• Giving assurance on RM processes

• Giving assurance that risks are correctly evaluated

• Evaluating RM processes

• Evaluating the reporting of risks

• Reviewing the management of key Risks

Legitimate IA roles with safeguards

• Facilitating identification and evaluation of risks

• Coaching management in responding to risks • Coordinating ERM activities

• Consolidating the reporting on risks

• Maintaining and developing the ERM framework

• Championing establishment of ERM

• Developing risk management strategy for board approval

The IA is an independent activity used to provide objective assurance to the Board on the
effectiveness of RM and an integral part of the RM framework. Over the years, it transitioned
from a role of checking organizational compliance with policies and procedures, to the much
broader role of risk management. According to the IIA, the role of the IA is both one of advisory
and consultancy as they consider the potential threats, which may be posed to objectivity and
independence. IA must ensure sufficient documentation and to ensure that

process protocols are implemented and properly executed. Since IAs objectivity and
independence were so often questioned, the IIA developed a position of acceptable roles

for the IA function as mentioned above. Empirical studies also found that IA increased risk
reduction.

For Private Circulation Only 47


The three lines of defense model is more popularly used.

First line of Defense –Lies with the business and process owners. Operational management is
responsible for maintaining effective internal controls and for executing risk and control
procedures on a day to day basis. This consists of identifying, assessing controls and mitigating
control risks. Additionally, business and process owners guide the development and
implementation of internal policies and procedures and ensure activities are consistent with
goals and objectives. Mid-level managers may design and implement detailed procedures that
serve as controls and supervision execution of those procedures by their employees.

Second line of defense –Supports management to help ensure risks and controls are effectively
managed. Management establishes various risk management and compliance functions to help
build or /and monitor the first line of defence controls. The typical controls are

A risk management function that facilitates and monitors the implementation of effective risk
management practices by operating management and assists risk owners in defining the target
of risk exposure and reporting adequate risk –related information throughout the organization
A compliance function to monitor various specific risks such as non-compliance with
applicable laws and regulations. The separate function reports directly to senior management
A controllership function that monitors financial risks and financial reporting issues.

For Private Circulation Only 48


In many ways, the internal audit function is ideally placed to lead on risk. Internal auditors
have an understanding of risk and its implications on a par with their risk manager colleagues;
in fact, they have a comprehensive oversight of all things governance, risk and compliance.
Typically, internal auditors are objective and analytical ' also key competencies for anyone
providing impartial assessment. They tend to take a moderate approach to risk, demonstrating
neither extremely risk-averse or high-risk behaviours.

2.9 Role of External Auditors in mitigating risk

The Role of External auditors has traditionally been involved in auditing of financial statements
of entities and providing assurance to investors and management that the financial statements
are free from any material mis-statements and that they represent a true and fair view of the
financial statements. Though primarily it has been related to accounting, records examination,
of late the role of External auditors as provider of valuable inputs on the risks the companies
face is increasing. The legal landscape is also becoming more complex and has put considerable
burden on the external auditor address the issues arising in the process, and the reporting
requirements have undergone a sea-change.

The role of external auditor in mitigating risk is important and valuable for following reason-

 Certification by External auditor brings good confidence to investors and management


as to internal control systems functioning properly and that suitable risk mitigation
processes are in place
 Can be relied upon as evidence in case of any financial mis-statements coming to light
later, though it is not exonerating the management responsibility in any way
 Certification is according to the provisions of Companies Ac 2013, in India for listed
companies, and for UK companies as per corporate law provisions of the UK and the
FRC –Financial Reporting Council, Uk directives.
 Helps companies to understand the risks in areas related to legal compliance, tax
adequacy provisions, and an assurance that financial statements are free of any material
mis-statements.
 As they are experts in audit and accounting standards, it will also help to know the right
treatment, and a pre-consultation with them helps in the process.

For Private Circulation Only 49


 External auditors test the design effectiveness of internal controls, and also focus on the
different layers of management, the risk arising at various levels, and their mitigation
strategies applied in the organization. It thus helps in Risk identification and Mitigation
in the process, which are primarily important in SRM function.
 External auditors are authorized by statute to audit the books of accounts, and issue the
certificate and it is in many cases mandatory under different laws. This forms a control
and risk mitigating approach to the entire audit process, which is highly valued upon.
 In case of strategic acquisitions and takeovers it is mandatory to conduct due diligence
of target companies , and in this process the role of strategic auditor is to identify the
critical risk factors in the business and whether the transactions have actually captured
all the components or elements, appropriateness of their accounting treatment,
magnitude of transactions which can occasion or give rise to a risk have been properly
considered in the financial statements and they reflect the correct position in this regard.
 Regulators place a great reliance on the reports of the organization as certified by the
Statutory or external auditor.
 External auditor is also requested for advise on the possible risks certain processes,
which may be involved in internal controls, operations, and various departments like
procurement, marketing, etc. He is also asked report on the compliance under various
laws from time to time, and whether there are any violations or risks arising in the
process due to compliance not being fully met with.
 As External auditor is appointed by shareholders in General meeting and is accountable
to them, primarily the reports and advisory coming from him are more valued and
regarded as compared to that of an internal auditor. As per statutory regulations these
reports have to be filed with respective Govt or quasi Govt-bodies, set-up in the
regulatory framework, and these documents aim at capturing risk and other aspects of
business in addition to statutory reporting of annual figures of financial and operational
performance of entities. In view of these factors the importance of External auditors in
Risk mitigation is crucial and important.

For Private Circulation Only 50


Reference books: [Link] of Leadership and Management (IoL&M) study material

9. ICAI risk management study material

10. The Institute of Risk Management : Risk culture Under the Microscope
Guidance for Boards

11. Coso guidance - Risk appetite to Success, COSO publication May 2020

12. Muller Robert.R, Coso enterprise risk management, second edition , wiley
finance, Enterprise risk management Coso -Oct 2019
13. [Link]
exams- study-resources/strategic-business-leader/technical-articles/coso-enterprise-risk-
management- [Link]
14. Hampton , John –Fundamentals of Enterprise Risk Management –Second Edition-
American Management Association (2015)

For Private Circulation Only 51


Terminal Questions:

Section –A ( 5 marks)

• Define Risk appetite and list out its key elements.


• Briefly discuss the Risk culture framework as defined by IRM.
• Explain risk awareness and how it is achieved in organizations.
• Examine the role of Internal auditor in risk mitigation for corporates

Section B (9 marks)
1. List out the skill sets needed by Risk manager, in brief.
2. List out the responsibilities of the risk committee, briefly.
3. Briefly outline the three defences model used by internal auditors.
4. Examine the role of external auditor and the value addition he brings in the context of
risk mitigation in organizations.

Section –C ( 12 marks)

1. Explain the ten basic indicators of matured risk culture in organizations with
examples you know of.
2. Discuss the key factors which decide the tone at the top, and its importance
3. Examine the role of a Risk Manager and the activities he performs in the context of
strategic risk management.
4. Discuss the role of external as well as internal auditor, in mitigating risks and how it
helps add value to the decisions made by Corporate Boards/ Top management.
5. Elaborate the importance, role of risk committees in assisting the top management to
control risks and mitigation, and to enable meet the management objectives.

For Private Circulation Only 52


Module III

Strategic Risk Management


Structure

3.1. Enterprise Risk Management


3.2. ERM Approach – Analysis
3.3. COSO –Components of ERM
3.4. COSO –framework
3.5. Management of Risk framework
3.6. CoCo Model framework
3.7. GRC Capability model
3.8. OCEG model
3.9. ISO 31000 model
3.10. Pros and Cons -ISO 31000

3.1 Introduction: Enterprise Risk Management

Fast-changing business scenario, uncertainty arising from global events, disruptive


competition, and protectionist agenda of cultural majorities and volatility of commodity and
currency prices creates stress and complexity in managing businesses. Gradually, these
events start playing on the minds of stakeholders. The occurrence of risk events coupled with
their poor handling impacts organizational performance. Enterprise Risk Management
(ERM)/ Business Risk Management (BRM) is a structured form to assists organizations in
preparing for the worst-case scenario, while aspiring to be “better, faster and cheaper”. ERM
is arguably the only effective tool in contemporary times that assists in the evaluation and
bridging of the gap between uncertainty and performance in organizations; also a simplified
approach to problem solving and making the organization nimble footed. Iconic entities that
feature in the top global rankings consistently practice integrated risk management.

Enterprise risk management (ERM) is a leading best practice approach to effectively manage
and optimize business events that have the potential to impact business objectives or risks,

For Private Circulation Only 53


enabling a company to determine how much uncertainty and risk are acceptable to an
organization.

Various definitions of risk management are enumerated as below:

CIMA Official Terminology, 2005

A process of understanding and managing the risks that the entity is inevitably subject to in
attempting to achieve its corporate objectives. For management purposes, risks are usually
divided into categories such as operational, financial, legal compliance, information and
personnel. One example of an integrated solution to risk management is enterprise risk
management.

Webster's New World Law Dictionary

The process of assessing risk and acting in such a manner, or prescribing policies and
procedures, so as to avoid or minimize loss associated with such risk

With a company-wide span, ERM serves as a strategic analysis tool, cutting across business
units and departments, and considering end-to-end processes. In adopting an ERM approach,
companies gain the ability to align their risk criteria to business strategy by identifying events
that could have an adverse effect on their organizations and then developing an action plan
to mitigate them. .

ERM can help organizations in the following ways: -

1. Identify strategic risk opportunities that, if undertaken, can facilitate


achieving organizational goals.
2. Introduce a common language within the organization where people
recognize problems and adopt a problem solving approach by developing risk
treatment actions.
3. Provide senior management with the most up-to-date information regarding
risk that may be used in the decision-making process.
4. Establish linkage between the ERM initiative and adherence to capital market
reporting disclosures and other corporate laws and regulations.
5. Align annual performance goals with risk identification and management.
6. Encourage and reward upstream reporting of business-risk opportunities and
challenges.

For Private Circulation Only 54


7. Align other risk monitoring initiatives such as self-appraisals, internal
auditing activities, control assessments, continuous control monitoring, to
organizational objectives.
8. Imagining key Risk Scenarios that could potentially result in a stress on the
financial position of the company.
9. Financial Risk monitoring a part of the ERM initiative can balance the
financial stability equation of the company

Enterprise risk management (ERM) is a plan-based business strategy that aims to identify,
assess and prepare for any dangers, hazards and other potentials for disaster – both physical
and figurative – that may interfere with an organization's operations and objectives.
Relatively new (it's less than a decade old), the discipline not only calls for corporations to
identify all the risks they face and to decide which risks to manage actively; it also involves
making that plan of action available to all stakeholders, shareholders and potential investors,
as part of their annual reports. Industries as varied as aviation, construction, public health,
international development, energy, finance and insurance all utilize ERM. Risk management
in an organization minimizes the impact of risk on the business with the help of a chief risk
officer or a risk committee but it does not give a guarantee that the organization will become
risk free.

3.2 Approaches to ERM

ERM is a new approach in the ways organizations are assessing, managing and communicating
business risks. By assisting organizations climb up on the risk maturity scale, ERM makes a
major contribution towards helping an organization manage risks to achieve its objectives. ERM
helps an organization become a risk managed business. An ERM policy is first put in place
which defines the guiding principles showing responsibility of line management for ERM and
the broad activities covered by the risk management processes. Whatever the definition, everyone
recognized ERM as a broad and complex concept that reaches into every major area of an
organization. As such, it is not surprising that many approaches have been advanced to install
ERM. They fall into three categories:

1. Strategy. This definition focuses on results, inasmuch as ERM is expressed in terms of


organizational objectives.

For Private Circulation Only 55


2. Function. This definition describes ERM in terms of activities that reduce risk.

3. Process. This focuses on actions undertaken by managers to manage risk.

Here are some of the commonly used ERM approaches:

COSO ERM Framework: The Committee of Sponsoring Organizations of the Treadway


Commission (COSO) developed a widely recognized ERM framework. It provides a structured
approach to risk management and is divided into eight components: internal environment,
objective setting, event identification, risk assessment, risk response, control activities,
information and communication, and monitoring.

ISO 31000: ISO 31000 is an international standard for risk management developed by the
International Organization for Standardization (ISO). It provides principles, guidelines, and a
risk management process applicable to all types of organizations and risks. The ISO 31000
framework emphasizes the importance of risk identification, analysis, evaluation, treatment,
and monitoring.

Scenario Analysis: This approach involves creating hypothetical scenarios representing


potential risks and their impacts on the organization. By analyzing these scenarios, businesses
can identify vulnerabilities and develop suitable risk response strategies.

Risk Appetite Frameworks: Risk appetite refers to the level of risk that an organization is
willing to accept to achieve its objectives. Establishing risk appetite frameworks helps
organizations define their risk tolerance and align risk management decisions with their overall
business strategy.

Top-Down and Bottom-Up Approaches: Some organizations implement ERM through a top-
down approach, where the risk management strategy is set by the board or top management
and cascaded down to various departments. Conversely, a bottom-up approach involves
individual departments identifying and assessing risks, which are then aggregated at the
organizational level.

Organizations often customize these approaches to fit their specific needs and risk profiles. The
chosen ERM approach should align with the organization's size, industry, complexity, and risk
appetite while promoting a risk-aware culture throughout the organization.

For Private Circulation Only 56


3.3 COSO COMPONENTS OF ERM:

The COSO enterprise risk management framework identifies eight core components that
define how a company should approach creating its ERM practices.

Internal Environment: A company's internal environment is the atmosphere and corporate


culture within the company set by its employees. This sets the precedence of what the
company's risk appetite is and what management's philosophy is regarding incurring risk. The
internal environment may be set by upper management or the board and communicated
throughout an organization, though it is often reflected through the actions of all employees.

Objective Setting: As a company determines its purpose, it must set objectives that support
the mission and goals of a company. These objectives must then be aligned with a company's
risk appetite. For example, an ambitious company that has set far-reaching strategic
plans must be aware there may be internal risks or external risks associated with these lofty
goals. In response, a company can align the measures to be taken with what it wants to
accomplish such as hiring additional regulatory staff for expansion areas it is currently
unfamiliar with.

Event Identification: Positive events may have a great impact on a company. On the other
hand, negative events may have detrimental outcomes on a company's ability to continue to
operate. ERM guidance recommends that companies identify important areas of the business
and associated events that may have dire outcomes. These high risk events may pose risks to
operations (i.e. natural disasters that force offices to temporarily close) or strategic
(i.e. government regulation outlaws the company's primary product line).

Risk Assessment: In addition to being aware of what may happen, the ERM framework
details the step of assessing risk by understanding the likelihood and financial impact of risks.
This includes not only the direct risk (i.e. a natural disaster yields an office unusable) but
residual risks (i.e. employees may not feel safe returning to the office). Though difficult, the
ERM framework encourages companies to consider quantifying risks by assessing the percent
change of occurrence as well as the dollar impact.

Risk Response: A company can respond to risk in the following four ways:

For Private Circulation Only 57


1. The company can avoid risk. This results in the company leaving the activity that
causes the risk as the company would rather forgo the benefits of the activity than incur
the risk. An example of risk avoidance is a company shutting down a product line and
discontinuing selling a specific good.
2. The company can reduce risk. This results in the company staying engaged in the
activity but putting forth effort in minimizing the likelihood or magnitude of the risk.
An example of risk reduction is a company keeping the product line above open but
investing more in quality control or consumer education on how to property use the
product.
3. The company can share risk. This results in the company moving forward as-is with
the current risk profile of the activity. However, the company leverages an independent
third party to share in the potential loss in exchange for a fee. An example of risk
sharing is purchasing an insurance policy.
4. The company can accept risk. This results in the company analyzing the potential
outcomes and determining whether it is financially worth pursuing mitigating
practices. An example of risk acceptance is the company keeping open the product line
with no changes to operations and risk sharing.

Control Activities: Control activities are the actions taken by a company to create policies
and procedures to ensure management carries out operations while mitigating risk. Control
activities, often referred to as internal controls, are broken into two different types of
processes:

1. Preventative control activities are in place to stop an activity from happening. These
controls aim to mitigate risk by disallowing certain events from happening. An
example of a preventative control is a keypad or physical lock preventing all
employees from entering into a sensitive area.
2. Detective control activities are in place to recognize when a risky action has taken
place. Although the event is allowed to happen (or was not supposed to happen but
still did), detective controls may alert management to ensure appropriate follow-up
steps occur. An example of a detective control is an alarm for the room or a l

Information and Communication: Information systems should be able to capture data useful
to management to better understand a company's risk profile and management of risk. This
means not granting exceptions for departments outperforming others; all aspects of a company

For Private Circulation Only 58


should be continually monitored. By extension, some of this data should be analyzed and
communicated to employees if it is relevant to mitigating risk. By communicating with
employees, there is more likely to be greater buy-in for processes and protection over company
assets.

Monitoring: A company can turn to an internal committee or an external auditor to review its
policies and practices. This may include reviewing what is actually performed compared to
what policy documents suggest. This may also entail getting feedback, analyzing company
data, and informing management of unprotected risks. In an ever-changing environment,
companies must also be ready to assess their ERM environment and pivot as needed.

3.4 COSO ERM Framework: This framework defines essential enterprise risk management
components, discusses key ERM principles and concepts, suggests a common ERM
language, and provides clear direction and guidance for enterprise risk management.

COSO framework states that Enterprise Risk Management (ERM) is defined as a process,
affected by an entity's board of directors, management, and other personal, applied in strategy
setting and across the enterprise, designed to identify potential events that may affect the
entity, and manage risk to be within its risk appetite, to provide reasonable assurance
regarding the achievement of entity objectives. ERM includes the following activities:

 Determining the risk appetite.

 Establishing an appropriate internal environment, including a risk


management policy and framework.

 Identifying potential threats to the achievement of its objectives and


assessing the risk, i.e., the impact and likelihood of the threat occurring.

 Undertaking control and other response activities.

 Communicating information on risks in a consistent manner at all levels


in the organization.

 Centrally monitoring and coordinating the risk management processes


and the outcomes, and

 Providing assurance on the effectiveness with which risks are managed.

For Private Circulation Only 59


The term 'risk appetite' used in the above definition refers to the extent of risk that the Board
is willing to take to pursue the objectives. Risk appetite setting is done at different levels,
viz. for the organization at the entity level, process level, and different risk groups and for
individual key risks. Risk appetite provides a standard against which a risk can be
compared and where the risk is above the risk appetite, it is considered a threat to the
reasonable assurance that the objective will be achieved.

3.5 Management of Risk framework: Effective risk management plays a crucial role in
any company's pursuit of financial stability and superior performance. The adoption of a risk
management framework that embeds best practices into the firm's risk culture can be the
cornerstone of an organization's financial future. A risk management framework (RMF) is a
set of practices, processes, and technologies that enable an organization to identify, assess, and
analyse risk to manage risk within your organization.

Identifying, assessing, and analysing risk can be overwhelming for many companies. You may
struggle with knowing where to start or how to set goals. However, a risk management
framework enables you to create repeatable processes that allow you to define, review, and
mitigate IT risks to more effectively set and monitor controls.

The 5 Components of RMF: There are at least five crucial components that must be
considered when creating a risk management framework. They include risk identification; risk
measurement and assessment; risk mitigation; risk reporting and monitoring; and risk
governance.

Identification: The first component in implementing the Risk Management Framework is


to identify the risks that the organization faces. These might include strategic, legal, operational
and privacy risks.

It is important to note that risk identification is not a one-time process. The risks that an
organization faces tend to change over time, so risk assessments will need to be performed on
a periodic basis.

For Private Circulation Only 60


Measurement and assessment: The goal behind the measurement and assessment component
is to create a risk profile for each risk that has been identified. There are any number of different
ways that organizations might complete the measurement and assessment phase of the process.
In some cases, risk measurement might be based on something as simple as how much capital
could potentially be lost as a result of the risk. However, in other cases, measuring the potential
impact of a risk might be far more difficult. In the field of information security, for example,
an organization might attempt to quantify the cost of a security breach compared with the cost
of implementing a security mechanism that can help to mitigate the risk.

Mitigation: The third component in the framework is risk mitigation. Risk mitigation involves
examining the risks that have been identified and determining which risks can and should be
eliminated, as opposed to the risks that are deemed to be acceptable.

Part of this process involves coming up with mitigation strategies, such as cyber insurance. For
example, if an organization identifies cybersecurity risks that need to be dealt with, then it may
choose to integrate security controls into its development lifecycle. Such an organization would
likely also put additional baseline security controls in place.

Reporting and monitoring: The fourth component in the process is risk reporting and
monitoring. This essentially means regularly re-examining the risks in order to make sure that
the risk mitigation strategies the organization has adopted are having the desired effect.

Governance: The last component in the process is risk governance. Risk governance is the
process of making sure that the risk mitigation techniques that have been adopted are put into
place and that the employees adhere to those policies.

3.6 CoCo Framework model:

The COCO framework is a powerful tool in that it allows an organization to focus on key
structures, values and processes that together form this concept of internal control, far outside
the narrow financial focus that used to be the case. The individual is part of the process but it
can be hard to get a corporate solution down to grassroots. The criteria of control (CoCo) is a
further control framework that can mean more to teams and individuals and includes an
interesting learning dynamic. CoCo was developed by the Canadian Institute of Chartered
Accountants (CICA) and is now an international standard.

For Private Circulation Only 61


The CICA website ([Link]) gives an account of their understanding of control as a
platform for the criteria that was developed.

Control needs to be understood in a broad context. Control comprises those elements of an


organization (including its resources, systems, processes, culture, structure and tasks) that,
taken together, support people in the achievement of the organization’s objectives. The
effectiveness of control cannot be judged solely on the degree to which each criterion, taken
separately, is met. The criteria are interrelated, as are the control elements in an organization.
Control elements cannot be designed or evaluated in isolation from each other.

Control should cover the identification and mitigation of risks. These risks include not only
known risks related to the achievement of a specific objective but also two more fundamental
risks to the viability and success of the organization.

 failure to maintain the organization’s capacity to identify and exploit opportunities;

 failure to maintain the organization’s capacity to respond and adapt to unexpected risks
and opportunities, and make decisions on the basis of the tell-tale indications in the
absence of definitive information.

The principles may be organized according to the four groupings of the CICA criteria of control
framework. The main components are explained below:

 Purpose – The model starts with the need for a clear direction and sense of purpose.
This includes objectives, mission, vision and strategy; risks and opportunities; policies;
planning; and performance targets and indicators. It is essential to have a clear driver
for the control criteria and since controls are about achieving objectives, it is right that
people work to the corporate purpose. Much work can be done here in setting objectives
and getting people to have a stake in the future direction of the organization. The crucial
link between controls and performance targets is established here as controls must fit
in with the way an organization measures and manages performance to make any sense
at all.

 Commitment – The people within the organization must understand and align
themselves with the organization’s identity and values. This includes ethical values,
integrity, human resource policies, authority, responsibility and accountability, and

For Private Circulation Only 62


mutual trust. Many control systems fail to recognize the need to get people committed
to the control ethos as a natural part of the way an organization works. Where people
spend their time trying to ‘beat the system’, there is normally a lack of commitment to
the control criteria. The hardest part in getting good control is getting people to feel
part of the arrangements.

 Capability – People must be equipped with the resources and competence to


understand and discharge the requirements of the control model. This includes
knowledge; skills and tools; communication processes; information; co-ordination; and
control activities. Where there is a clear objective, and everyone is ready to participate
in designing and installing good controls, there is still a need to develop some expertise
in this aspect of organizational life. Capability is about resourcing the control effort by
ensuring staff have the right skills, experience and attitudes not only to perform well
but also to be able to assess risks and ensure controls make it easier to deal with these
risks. Capability can be assisted by training and awareness seminars, either at induction
or as part of continuing improvement programs.

 Action – This stage entails performing the activity that is being controlled. Before
employee’s act, they will have a clear purpose, a commitment to meet their targets and
the ability to deal with problems and opportunities. Any action that comes after these
prerequisites has more chance of leading to a successful outcome.

 Monitoring and learning – People must buy into and be part of the organization’s
evolution. This includes monitoring internal and external environments, monitoring
performance, challenging assumptions, reassessing information needs and information
systems, follow-up procedures, and assessing the effectiveness of control. Monitoring
is a hard control in that it fits in with inspection, checking, supervising and examining.
Challenging assumptions is an important soft control in that it means people can
develop and excel.

3.7 GRC capability- OCEG Model framework:

Concept of GRC: The acronym GRC is a shorthand reference to the collection of critical
capabilities that must work together to achieve Principled Performance. GRC denotes
governance, risk management, and compliance, but it connotes much more than those three

For Private Circulation Only 63


terms simply put together into an acronym. It is important to remember that organizations have
been governed, and risk and compliance have been managed, for a long time — GRC is nothing
new. However, many have not approached these activities in a mature way, nor have these
efforts supported each other to enhance the likelihood of achieving organizational objectives.
That makes GRC, as we understand it today, totally revolutionary. In a forward-thinking
organization, GRC is viewed as a well-coordinated and integrated collection of all of the
capabilities necessary to support Principled Performance at every level of the organization.
GRC doesn’t burden the business, it supports and improves it.

 Having a unified vocabulary and taxonomies for information; establishing common


repositories for data, documents, and information; creating standardized procedures and
templates for things such as policies and training; ensuring regular and consistent
communication between and amongst all relevant roles including strategic decision-
makers — these are all aspects of effective integrated GRC capabilities, whether
established for enterprise-wide objectives, or for those of particular departments or
projects.
 The benefits of integrating GRC capabilities, and the negative impacts of a siloed
approach, are two sides of the same coin. In the OCEG GRC Maturity surveys
conducted in 2012 and 2015, a majority of respondents provided information on the
positive outcomes they have gained from being “on the GRC journey,” and the
remainder offered a clear picture of the failure of a siloed structure. In particular, the
difference between these two groups was striking in the levels of confidence they have,
or do not have, in what they know about threats to the organization and their ability to
effectively manage those threats. Those who have at least partially integrated GRC
capabilities, as compared to those who remain siloed, are three times as likely to feel
confident that they can evaluate their performance against established objectives and
that they have selected and are implementing the right risk and compliance controls to
protect that performance. They are more confident that they are establishing the right
objectives and strategies and are better able to create and evaluate performance reports.
They are simply more agile, resilient and competitive.
 Improved alignment of objectives with mission, vision, and values of the organization
 Better decision-making agility and confidence
 Sustained, reliable performance and delivery of value
 Capital allocation to the right initiatives at the right time

For Private Circulation Only 64


 Top to bottom accountability for key objectives, risks, requirements, and related
 initiatives
 Meaningful cost savings within the integrated capabilities
These outcomes enhance the critical attributes that an organization needs to be confident and

competitive. Confidence comes from being aware of what is going on both internally and

externally, so that organizations can evaluate information before taking action and responding

appropriately. It means being agile; moving not just quickly but with the ability to shift
direction when called for to avoid threats or grasp opportunities. It allows for the organization
to be both lean, with more muscle and less fat, and also more resilient so that it can recover
from adversity. When an organization, and everyone making decisions within it, are
appropriately confident (because you can also be confident when you should not be) and
understand the organization’s decision-making criteria and strategic goals, they can take
advantage of risk in a way that others cannot, without going beyond established risk thresholds
and tolerances. That is a real competitive advantage.

On the flip side, it is observed from past research that the more siloed the risk and compliance
operations, and the more separated from business operations, the less likely that critical
information about these areas of concern is shared with strategic decision-makers in a timely
fashion. The greatest risk of a heavily siloed approach is that wrong decisions cause the
organization to face too much risk or fail to grasp opportunities

There are other risks identified in our research as well. Siloed risk and compliance operations

spend too many resources trying to reconcile disparate information, have gaps and unnecessary
overlaps in activities, put too much burden on the business by failing to coordinate schedules
and requests for information, and even worse, may create new risks themselves. Rather than
support the organization’s ability to achieve objectives, they burden it.

 Members to be involved -Board members, Senior executives, business unit head and
project heads are all involved in governance at enterprise, business unit or project unit
levels. People engaged in strategic planning, business continuity activities, technology
managers, HR managers all have a GRC role. GRC roles thus have become extremely
critical and can greatly affect the direction, strategy, future and reputation of the
organisations and most corporates have started taking the issue quite seriously.

For Private Circulation Only 65


 The Principled Performance View of Integration looks at the governance, management,
and assurance of performance, risk, and compliance. Each of these activities
encompasses many individual roles and sets of responsibilities. For example,
management of compliance may well be parcelled out amongst a number of business
unit mangers and compliance professionals within an organization, and give individuals
compliance responsibility within units such as Information Technology or Environment,
Health and Safety. The same is true when looking at performance, which requires
collaboration between business unit operators and supportive teams from HR,
technology, procurement, and others. Risk management must be embedded deep within
the business operations, but have ongoing support from risk professionals with analytic
tools and insight across the organization.
 When responsibilities are spread out across a significant number of individuals, each
must fully understand and appreciate the impact his or her actions and decisions have
on other parts of the organization, and how others may affect them. Too often, even
those with “Chief something or other” titles become too siloed in their points of view
and neglect to see the bigger picture and the part they have in it.

 Figure 1 – The Principled Performance View of Integration

The need to ensure collaboration and communication in these critical relationships may be best
seen through a few examples of key GRC roles.

 The Role of Governing authority


The core task of any governing authority, be it the corporate board or a committee
overseeing a particular project, is to provide oversight distinct from the direction and
control provided by those managing the entity or activity being governed. Oversight
includes providing the direction and decision-making criteria that managers and
auditors will use in performance of their duties. This includes setting the mission, vision,

For Private Circulation Only 66


and values, as well as risk appetite, risk tolerances and capacities, ethical guidelines,
and a high-level statement of goals and objectives
 The Role of Chief Financial officer and Managers
The job of the modern Chief Financial Officer (CFO) goes far beyond the traditional
role of preserving assets and managing financial records. Today, the CFO is a
significant member of the strategic team and contributes to establishing the direction
of the organization, in part by ensuring understanding an appropriate distribution of
financial resources throughout the business. The CFO must help managers perform
better by establishing and explaining decision making criteria related to the financial
mindset of the organization.

 The Role of the Risk Executive and Managers: Whether engaged in Enterprise Risk
Management (ERM) or business unit risk control efforts,the Chief Risk Officer (CRO)
and risk managers play an essential part in driving the organization toward Principled
Performance. Risk teams both directly under the CRO and within business units must
consider threats and opportunities presented to the organization and ensure that this
information is available as strategic plans are developed and implemented. The
organization must integrate consideration of risk into decision-making across the
enterprise. Controlling threats and enhancing opportunities in light of set objectives and
strategies is only one part of the equation; it is equally important to ensure that any
fluctuation that arises due to changes in the internal or external context is evaluated to
determine how changes may impact achievement of objectives. This must be
communicated to the governing authority and strategic planners. This is the case not
only at the enterprise level, but also within business units and as risk is managed project
by project. Accordingly, risk assessment is not a “one-and-done” activity; it requires
ongoing monitoring of change and modifications to ensure continued alignment
between objectives, strategies, risks, rewards, and controls.
 The Role of Compliance and ethics Executive and Manager
Compliance and Ethics Executives (sometimes a combined Chief Ethics and
Compliance Officer or CECO role) and managers with compliance and ethics
responsibilities must be concerned not only with the organization meeting legal
requirements but also with satisfying internally established values, policies,
procedures, and codes of conduct. These can be defined as the mandatory and
voluntary boundaries and the job of this team is to make sure that the organization (or

For Private Circulation Only 67


unit or project) stays within those boundaries while striving to meet objectives.
Similarly, compliance and ethics officers and risk officers must communicate about
requirements, how best to stay within the boundaries or affect where the boundaries
fall, and how compliance requirements affect risk analyses. Communicating with HR
managers and working together to establish and teach ethical decision-making is also
important.

 The Role of CIO


The Chief Information Officer (CIO) must establish systems to ensure that the organization

collects and maintains information in ways that allow it to deliver the right information to the
right people or systems, at the right time and in the right format. This is an essential aspect of
integrated GRC capabilities. Protecting an organization’s information security and ensuring
availability of necessary technology resources and information are critical to this undertaking.

The CIO and information technology managers must be involved in helping to design the GRC
technology strategic plan that will determine the right combination of solutions based on user
and stakeholder needs. Then, they must work with business operators and key GRC executives
to determine what technologies are currently in use, evaluating them to determine what should
be kept, changed or integrated. This enables a fully architected approach to GRC technology

 Ten Universal Outcomes of Principled Performance


1. Achieve Business Objectives. Ensure that all parts of the organization work together
toward the achievement of enterprise objectives.
2. Ensure Risk Aware Setting of Objectives and Strategic Planning. Provide timely,
reliable and useful information about risks, rewards, and responsibilities to the
governing authorities, strategic planners, and business managers responsible for
execution at all levels.
3. Enhance Organizational Culture. Inspire and promote a culture of performance,
accountability, integrity, trust, and communication.
4. Increase Stakeholder Confidence. Grow stakeholder trust in the organization.
5. Prepare and Protect the Organization. Prepare the organization to address risks and
requirements while protecting the organization from adversity and surprise and
enabling it to grasp opportunities.

For Private Circulation Only 68


6. Prevent, Detect, and Reduce Adversity and Weaknesses. Establish actions and
controls to prevent negative outcomes, reduce impact, detect potential problems, and
address issues as they arise.
7. Motivate and Inspire Desired Conduct. Provide incentives and rewards for desirable
conduct, especially in the face of challenging circumstances.
8. Stay Ahead of the Game. Learn information necessary to support quick changes in
strategic and tactical direction while avoiding obstacles and pitfalls.
9. Improve Responsiveness and Efficiency. Establish capabilities that make the
organization as a whole more responsive and efficient so that it has a competitive
advantage.
10. Optimize Economic Return and Values. Allocate human and financial resources in
a way that maximizes the economic return generated for the organization while
maximizing its values.
To achieve Principled Performance, an organization should implement and operate a
collection of integrated capabilities that drive cooperation, coordination, and
collaboration of efforts. This might be done at the enterprise level, or with a smaller
focus on a particular department, region or project. In some organizations this is
achieved by keeping existing capabilities and integrating them better. For others it
requires developing some or all new capabilities. In every case, the organization must
establish a high level commitment, not only to the concept of Principled Performance
but also to allocation of resources necessary to support integrated GRC capabilities.
Only then can planning, designing, and operating of the integrated capabilities succeed.

 How to Achieve the Principled performance: To achieve Principled Performance,


an organization should implement and operate a collection of integrated capabilities
that drive cooperation, coordination, and collaboration of efforts. This might be done
at the enterprise level, or with a smaller focus on a particular department, region or
project.
Here is a short summary of the key steps to undertake:
● Commit. Obtain commitment to integrated capabilities that enable Principled
Performance from every relevant level of governing authority and executive
management.

For Private Circulation Only 69


● Plan. Use the GRC Capability Model and associated resources to guide your planning.
Determine other relevant governance, risk management, and compliance frameworks,
standards, and guidance for your organization. Inventory and analyse the as-is state of
GRC capabilities and define you’re to-be state. Allocate GRC roles and responsibilities
to individuals and committees. Define GRC capability processes and synchronize them
with existing business processes. Establish an approach to evaluating the effectiveness
and efficiency of the GRC capabilities.
● Do. Roll out the plan, taking into consideration the need for change management and
communication with employees and stakeholders.
● Check. Don’t let it end there. Be sure to evaluate the plan against the established
goals and performance indicators to determine if design and operation are effective.
● Act. Use the results of that evaluation to fine tune and improve the integrated
capabilities.
 Anatomy of the GRC Capability Model
An organization that strives to achieve Principled Performance will have a number of
integrated capabilities. The GRC Capability Model discusses and outlines these
capabilities. Here are definitions and an overview of several key terms in the GRC
Capability Model.
 Components
Components outline an iterative continuous improvement process to achieve Principled
Performance. While there is an implied sequence, Components operate concurrently.
 L – LEARN — Examine and analyze context, culture, and stakeholders to learn what
the organization needs to know to establish and support objectives and strategies.
 A – ALIGN — Align performance, risk and compliance objectives, strategies,
decision-making criteria, actions and controls with the context, culture and stakeholder
requirements.
 P – PERFORM — Address threats, opportunities, and requirements by encouraging
desired conduct and events, and preventing what is undesired, through the application
of proactive, detective, and responsive actions and controls.
 R – REVIEW — Conduct activities to monitor and improve design and operating
effectiveness of all actions and controls, including their continued alignment to
objectives and strategies.

For Private Circulation Only 70


 Elements
 Each Element expands on the Component it sits within, to describe key aspects of high
performing integrated capabilities. Each Element includes a discussion of key
management actions and controls and addresses design and implementation
considerations. Elements define the core aspects of effective capabilities and can serve
as the starting point for assessing the current state of your organization’s approach.
Elements can be applied at many levels in the organization to address enterprise
objectives, departmental capabilities, or actions and controls within specific areas of
concerns. Each Element is further supported by detailed Practices, that can be
customised to specific organisations and used
 Learn – External context, Internal context, culture, stakeholders
 Align –Direction, Objectives, Identification, Assessment, Design
 Perform –Controls, Policies, Communication, Education, Incentives, Notification,
Inquiry, Response,
 Review –Monitoring, Assurance, Improvement

3.8 WHAT IS A RISK MANAGEMENT STANDARD?

A risk management standard is a country-wide or global standard approach to managing risk


in organizations.

ISO 31000 is the family of risk management standards recognized internationally. This
framework sets out principles, guidelines and a process to provide risk management
practitioners with guidance on recognized best practices for implementing risk management.

However, this standard is broad as it isn’t written for any specific industry or even specific
management levels. It provides an internationally-recognized benchmark for the practice of
risk management. Your industry or country might have derivative standards based on ISO
31000 that are more specific, recognized frameworks and best practices relevant to your
organization.

When we talk about adopting a risk management standard, we’re talking about finding an
appropriate standard and aligning the way you do risk management in your organization to that
particular standard.

For Private Circulation Only 71


3.9 ADVANTAGES OF ADOPTING A RISK MANAGEMENT STANDARD

There are plenty of advantages to adopting internally-recognized ways of working in relation


to risk.

For example:

 Everyone in the company will use standard terminology when discussing risk,
regardless of whether they are working at project level, enterprise risk management
level or somewhere in between.

 It’s easier to recruit experienced (and good) risk specialists because we can specify we
need them to have experience in the standard. This will make their onboarding easier
because they don’t have to learn your specific processes. Longer term, using national
or international standards can also help retention and staff development as entities
invest in their development.

 Any standard will work with any risk management tools. Regardless of what software
entities are using, entities should easily be able to customize the processes to fit the
tools they have. There’s no need to invest in additional software (assuming they have
some that does the job already).

 Adopting a risk management standard can help entity win more business, as customers
want to see that entity take risk management seriously. Seeing that entity has adopted a
recognized standard makes that instantly visible to them.

 It’s easier to benchmark entity performance against other organizations using the same
approach.

 There’s often a community of standard users. If needed help, it’s easier to ask for help
with elements of a recognized standard than it is within entity’s own bespoke
methodology. Everyone in the extended community will already know what entity are
talking about!

Having said that, the risk management standard you choose should be your baseline. It’s OK
to customize the standard to better fit your working practices or your industry. The way you do
risk management is specific to your business – and while there are guidelines out there to help,
ultimately you get to decide how risk management works in your own organization.

For Private Circulation Only 72


DISADVANTAGES OF ADOPTING A RISK MANAGEMENT STANDARD

Changing how entities manage risk in your organization can be a big upheaval. There are many
people to train in new methods and terminology. There is process documentation to be
rewritten. And that’s on top of the bulk of the work of creating a gap analysis to establish how
to do the move in the first place.

Entity champions for risk management, might face challenge from senior leaders in the
organization who don’t see the value in changing the way risk is managed. If the way the entity
manages risk is perceived to be adequate already, going through a large risk re-engineering
program might not be considered a priority – especially if it can’t easily tie back the work to a
tangible ROI.

The changes we’re talking about aren’t cosmetic. It’s not simply a case of updating the
language in entity’s risk documentation to ensure it’s using the new standard vocab. In reality,
we are looking at a complete review of entity ‘s current processes and practices.

The new standard might not easily fit to what the entity is doing already, so we could have to
introduce new ways of working. And the standards might need customizing to particular
industry or business. All of this takes time and investment.

The main reasons to adopt a risk management standard are:

 Improving the identification of threats (risks with a negative outcome for the business)
and opportunities (risks with a positive outcome for the business)

 Allocating resources to risk management activities more effectively

 Increasing the likelihood that your organization will achieve its strategic goals due to
better oversight and governance.

References:

1. [Link]

2. Institute of Leadership and Management (IoL&M) study material

3. ICAI risk management study material

For Private Circulation Only 73


4. The Institute of Risk Management : Risk culture Under the Microscope Guidance for
Boards

5. OEGC Red book.

6. COSO Enterprise Risk Management: Establishing Effective Governance, Risk, and


Compliance Processes Second Edition by ROBERT R. MOELLER

Terminal Questions:

Section –A ( 5 marks)

1) Define the concept of ERM, and briefly examine the importance of ERM in corporates
today.
2) Define the process of COSO framework and how different elements are related.
3) Briefly comment on the importance of ERM today and justify the reasons for its
adoption in major organizations.
4) Elaborate on Risk management components in detail.
5) State the advantages of adopting a Risk management Standard.

Section B ( 9 marks)
1. Explain the COCO Framework model concept .
2. Distinguish between traditional approach to Risk management and the ERM approach
to Risk management
3. Briefly elucidate the Pros and Cons of following 1SO -31000 standards in risk
management
4. Explain briefly the importance of GRC and its various components .

Section –C (12 marks)

1) Explain the full process of Enterprise Risk management , and list out the advantages
that organizations adopting ERM can get over the others .Give examples of any
company you know adopting the ERM.
2) Explain the GRC framework elements in Risk management in today’s organization
and its importance with examples.

For Private Circulation Only 74


3) Explained the process of Risk management under ISO 9000 framework in details, and
give example of any organisation that follows the ISO 9000-standards.
4) Explain the importance having a good risk management policy in an organisation in
the context of GRC framework to manage strategic risks.

For Private Circulation Only 75


Module IV

Strategic Risk Management

Structure

4.1 Methods of Identifying risk


4.2 Concept of Severity and probability of Risk events
4.3 Risk Management Strategies
4.4 Risk Controlling
4.5 Risk Monitoring

4.1 Introduction: Identification of Risk

Identifying risks is the first and perhaps the most important step in the risk management
process. It involves generating a comprehensive list of threats and opportunities based on
events that might enhance, prevent, degrade, accelerate or delay the achievement of your
objectives. If you don’t identify a risk, you can’t manage it. It’s also important to scan the
environment from time to time to identify new and emerging risks, as the department’s
exposure to risk may be constantly changing.

Identifying risks is a key step in a proactive risk management process. As part of this process
you must look at the following sources:

Sources Description

Risk registers Provide a foundation for evaluating existing risks and their potential risk
and risk reports to an objective.

For Private Circulation Only 76


Issue log Record of issues faced and the actions taken to resolve them. Any issues
that were formally identified as risks should be analysed.

Audit reports Independent view of adherence to regulatory guidelines including a


review of compliance preparations, security policies, access controls and
management of risks.

Business Impact Detailed risk analysis that examines the nature and extent of disruptions
Analysis and the likelihood of the resulting consequences.

Internal & Reviews undertaken to evaluate the suitability, adequacy and


External effectiveness of the department’s systems, and to look for improvement
Reviews opportunities.

Sources/Approach Description

SWOT analysis Commonly used as a planning tool for analysing a business, its
resources and its environment by looking at internal strengths and
weaknesses; and opportunities and threats in the external
environment

PESTLE approach Commonly used as a planning tool to identify and categorise threats
in the external environment (political, economic, social,
technological, legal, environmental

Brain storming Creative technique to gat/9her risks spontaneously by group


members. Group members verbally identify risks in a ‘no wrong
answer’ environment. This technique provides the opportunity for
group members to build on each other’s ideas

Scenario Analysis Uses possible (often extreme) future events to anticipate how
threats and opportunities might develop.

Surveys/Questionnaire Gather data on risks. Surveys rely on the questions asked.

For Private Circulation Only 77


Personal interview Discussions with stakeholders to identify/explore risk areas and
detailed or sensitive information about the risk

Stakeholder analysis Process of identifying individuals or groups who have a vested


interest in the objectives and ascertaining how to engage with them
to better understand the objective and its associated uncertainties

Working groups Useful to surface detailed information about the risks i.e. source,
causes, consequences, stakeholder impacted, existing controls

Corporate knowledge History of risks provide insight into future threats or opportunities
through: • Experiential knowledge – collection of information that
a person has obtained through their experience. • Documented
knowledge – collection of information or data that has been
documented about a particular subject. • Lessons learned –
knowledge that has been organised into information that may be
relevant to the different areas within the organisation.

Process Analysis An approach that helps improve the performance of business


activities by analyzing current processes and making decisions on
new improvements.

Other jurisdictions Issues experienced and risks identified by other jurisdictions should
be identified and evaluated. If it can happen to them, it can happen
here

There is no easy scientific method that will guarantee that we will identify all risks. Some
additional better practice approaches to and sources for identifying risks include:

Information that we should collect during the Risk identification step can be as under:-

 What are the sources of risk or threat – the things which have the inherent potential to
harm or facilitate harm.
 What could happen – events or incidents that could occur whereby the source of risk or
threat has an impact on the achievement of objectives.

For Private Circulation Only 78


 Where – the physical locations/assets where the event could occur or where the direct
or indirect consequences may be experienced.
 When – specific times or time periods when the event is likely to occur and/or the
consequences realized.
 How – the manner or method in which the risk event or incident could occur. • Causes
– what are the direct and indirect factors that create the source of risk or threat.
 Business consequences – what would be the impact on objectives if the risk was
realized.
 Business areas/stakeholders affected – what parts of the organization and what
stakeholders might be involved or impacted?
 Existing controls – a preliminary review of existing controls should be undertaken to
identify i) What controls currently exist to minimize the likelihood and consequences
of each risk? ii) What vulnerabilities exist that could undermine the effectiveness of
the control

Risk Identification – IRM standard

Risk identification sets out to identify an organisation’s exposure to uncertainty. This


requires an intimate knowledge of the organisation, the market in which it operates, the legal,
social, political and cultural environment in which it exists, as well as the development of a
sound understanding of its strategic and operational objectives, including factors critical to
its success and the threats and opportunities related to the achievement of these objectives.

Risk identification should be approached in a methodical way to ensure that all significant
activities within the organization have been identified and all the risks flowing from these
activities defined.

All associated volatility related to these activities should be identified and categorized.

Business activities and decisions can be classified in a range of ways, examples of which
include:

• Strategic - These concern the long-term strategic objectives of the organisation. They can
be affected by such areas as capital availability, sovereign and political risks, legal and
regulatory changes, reputation and changes in the physical environment.

For Private Circulation Only 79


• Operational - These concern the day-today issues that the organisation is confronted with
as it strives to deliver its strategic objectives.

Financial - These concern the effective management and control of the finances of the
organisation and the effects of external factors such as availability of credit, foreign exchange
rates, interest rate movement and other market exposures.

Knowledge management - These concern the effective management and control of the
knowledge resources, the production, protection and communication thereof. External factors
might include the unauthorised use or abuse of intellectual property, area power failures, and
competitive technology. Internal factors might be system malfunction or loss of key staff.

Compliance - These concern such issues as health & safety, environmental, trade descriptions,
consumer protection, data protection, employment practices and regulatory issues. Whilst risk
identification can be carried out by outside consultants, an in-house approach with well
communicated, consistent and coordinated processes and tools is likely to be more effective.
In-house ‘ownership’ of the risk management process is essential

There is another approach to identification of Risk as specified in the Orange book.

These are based on separating into two distinct phases as under :-

(i) Initial risk identification (for an organisation which has not previously identified its risks in
a structured way, or for a new organisation, or perhaps for a new project or activity within an
organisation), and there is;

(ii) Continuous risk identification which is necessary to identify new risks which did not
previously arise, changes in existing risks, or risks which did exist ceasing to be relevant to the
organisation (this should be a routine element of the conduct of business

In either case risks should be related to objectives. Risks can only be assessed and prioritised
in relation to objectives (and this can be done at any level of objective from personal objectives
to organisational objectives). Care should be taken to identify generic risks which will impact
on business objectives but might not always be immediately apparent in thinking about the
particular business objective. When a risk is identified it may be relevant to more than one of
the organisation’s objectives, its potential impact may vary in relation to different objectives,
and the best way of addressing the risk may be different in relation to different objectives
(although it is also possible that a single treatment may adequately address the risk in relation

For Private Circulation Only 80


to more than one objective). In stating risks, care should be taken to avoid stating impacts
which may arise as being the risks themselves, and to avoid stating risks which do not impact
on objectives; equally care should be taken to avoid defining risks with statements which are
simply the converse of the objectives. A statement of a risk should encompass the cause of the
impact, and the impact to the objective (“cause and consequence) which might arise.

The individual risks which an organisation identifies will not be independent of each other;
rather they will typically form natural groupings. For instance, there may be a number of risks
which can be grouped together as “resources” and further risks which can be grouped together
as “environmental”. Some risks will be relevant to several of the organisation’s objectives.
These groupings of risks will incorporate related risks at strategic, programme and operational
levels (see 1.6). It is important not to confuse a grouping of risks with the risks themselves.
Risks should be identified at a level where a specific impact can be identified and a specific
action or actions to address the risk can be identified. All risks, once identified, should be
assigned to an owner who has responsibility for ensuring that the risk is managed and
monitored over time. A risk owner, in line with their accountability for managing the risk,
should have sufficient authority to ensure that the risk is effectively managed; the risk owner
may not be the person who actually takes the action to address the risk.

The two approaches used commonly to identify risks are:-

Commissioning a risk review: A designated team is established (either in house or


contracted in) to consider all the operations and activities of the organisation in relation to its
objectives and to identify the associated risks. The team should work by conducting a series
of interviews with key staff at all levels of the organisation to build a risk profile for the
whole range of activities (but it is important that the use of this approach should not
undermine line management’s understanding of their responsibility for managing the risks
which are relevant to their objectives);

Risk self-assessment: An approach by which each level and part of the organisation is invited
to review its activities and to contribute its diagnosis of the risks it faces. This may be done
through a documentation approach (with a framework for diagnosis set out through
questionnaires), but is often more effectively conducted through a facilitated workshop
approach (with facilitators with appropriate skills helping groups of staff to work out the risks
affecting their objectives). A particular strength of this approach is that better ownership of
risk tends to be established when the owners themselves identify the risks.

For Private Circulation Only 81


These approaches are not mutually exclusive, and a combination of approaches to the risk
identification process is desirable – this sometimes exposes significant differences in risk
perception within the organisation. These differences in perception need to be addressed to
achieve effective integration of risk management at the various levels of the organisation.

Risk Estimation

Risk estimation can be quantitative, semi-quantitative or qualitative in terms of the


probability of occurrence and the possible consequence. For example, consequences both in
terms of threats (downside risks) and opportunities (upside risks) may be high. medium or
low. Probability may be high, medium or low but requires different definitions in respect of
threats and opportunities.

Examples are given in the tables overleaf. Different organizations will find that different
measures of consequence and probability will suit their needs best.

For example many organisations find that assessing consequence and probability as high,
medium or low is quite adequate for their needs and can be presented as a 3 x 3 matrix.

Other organisations find that assessing consequence and probability using a 5 x 5 matrix
gives them a better evaluation.
High High Financial impact on the organisation is likely to exceed £x
Significant impact on the organisation’s strategy or operational
activities Significant stakeholder concern.

Medium Medium Financial impact on the organisation likely to be between £x


and £y Moderate impact on the organisation’s strategy or operational
activities Moderate stakeholder concern.

Low Low Financial impact on the organisation likely to be less that £y Low
impact on the organisation’s strategy or operational activities Low
stakeholder con

For Private Circulation Only 82


Consequences –Threats and Opportunities

Probability of Occurrences/ Threats

Estimation Description Indicators

High ( probable) Likely to occur each year or Potential of it occurring several times
more than 25% chance of within the time period (for example -
occurring ten years). Has occurred recently

Likely to occur in a ten year Could occur more than once within the
time period or less than 25% time period (for example - ten years).
Medium ( possible)
chance of occurrence Could be difficult to control due to
some external influences. Is there a
history of occurrence?

Low (Remote) Not likely to occur in a ten Has not occurred. Unlikely to
year period or less than 2%
Occur.
chance of occurrence

Probability of Occurrences- Opportunities

Estimation Description Indicators

High (probable) Favourable outcome is Clear opportunity which can be


likely to be achieved in relied on with reasonable certainty,
one year or better than to be achieved in the short term
75% chance of based on current management
occurrence. processes

Medium( Possible) Reasonable prospects of Opportunities which may be


favourable results in one achievable but which require
year of 25% to 75% careful management. Opportunities
chance of occurrence. which may arise over and above the
plan

Low (Remote) Some chance of Possible opportunity which has yet


favourable outcome in the to be fully investigated by

For Private Circulation Only 83


medium term or less than management. Opportunity for
25% chance of which the likelihood of success is
occurrence. low on the basis of management
resources currently being applied

4.2 Concept of Probability and severity of Risk events

The concept of Probability and Severity of Risk events is of utmost importance in


understanding and containing the risk. However, prior to the same, we need to assess the risks
involved.

Assessing risks

 record the assessment of risk in a way which facilitates monitoring and the
identification of risk priorities;
 ensure that there is a clearly structured process in which both likelihood and impact are
considered for each risk;
 be clear about the difference between, inherent and residual risk
Some types of risk lend themselves to a numerical diagnosis – particularly financial risk. For
other risks - for example reputational risk - a much more subjective view is all that is possible.
In this sense risk assessment is more of an art than a science.

It will be necessary, however, to develop some framework for assessing risks. The assessment
should draw as much as possible on unbiased independent evidence, consider the perspectives
of the whole range of stakeholders affected by the risk, and avoid confusing objective
assessment of the risk with judgement about the acceptability of the risk.

This assessment needs to be done by evaluating both the likelihood of the risk being realised,
and of the impact if the risk is realised. A categorisation of high / medium / low in respect of
each may be sufficient, and should be the minimum level of categorisation – this results in a
“3x3” risk matrix. A more detailed analytical scale may be appropriate, especially if clear

For Private Circulation Only 84


quantitative evaluation can be applied to the particular risk - “5x5” matrices are often used,
with impact on a scale of “insignificant /minor / moderate/ major/ catastrophic” and likelihood
on a scale of “rare / unlikely / possible / likely / almost certain”. There is no absolute standard
for the scale of risk matrices - the organisation should reach a judgement about the level of
analysis that it finds most practicable for its circumstances. Colour (“Traffic Lights”) can be
used to further clarify the significance of risks.

Simple Risk Tolerability matrix.

When the assessment is then compared to the risk appetite , the extent of action required
becomes clear. It is not the absolute value of an assessed risk which is important; rather it is
whether or not the risk is regarded as tolerable, or how far the exposure is away from
tolerability, which is important

At the organisational level risk appetite can become complicated, but at the level of a specific
risk it is more likely that a level of exposure which is acceptable can be defined in terms of
both a tolerable impact if a risk is realised, and tolerable frequency of that impact. It is against
this that the residual risk has to be compared to decide whether or not further action is required.
Tolerability may be informed by the value of assets lost or wasted in the event of an adverse
impact, stakeholder perception of an impact, the balance of the cost of control and the extent
of exposure, and the balance of potential benefit to be gained or losses to be withstood .

For Private Circulation Only 85


Thinking about risk frequently focuses on residual risk (ie- the risk after control has been
applied which, assuming control is effective, will be the actual exposure of the organisation -
see 1.4). Residual risk, of course, will often have to be re-assessed – for example, if control is
adjusted. Assessment of the anticipated residual risk is necessary for the evaluation of proposed
control actions

Care should also be taken to capture information about the inherent risk. If this is not done the
organisation will not know what its exposure will be if control should fail. Knowledge about
the inherent risk also allows better consideration of whether there is over-control in place – if
the inherent risk is within the risk appetite, resources may not need to be expended on
controlling that risk. This need to have knowledge about both inherent and residual risk means
that the assessment of risk is a stage in the risk management process which cannot be separated
from addressing risk; the extent to

which the risk needs to be addressed is informed by the inherent risk whereas the adequacy of
the means chosen to address the risk can only be considered when the residual risk has been
assessed.

Risk assessment should be documented in a way which records the stages of the process.
Documenting risk assessment creates a risk profile for the organisation which:-

• facilitates identification of risk priorities (in particular to identify the most significant risk
issues with which senior management should concern themselves);

• captures the reasons for decisions made about what is and is not tolerable exposure;

• facilitates recording of the way in which it is decided to address risk;

• allows all those concerned with risk management to see the overall risk profile and how their
areas of particular responsibility fit into it;

• facilitates review and monitoring of risks

Once risks have been assessed, the risk priorities for the organisation will emerge. The less
acceptable the exposure in respect of a risk, the higher the priority which should be given to
addressing it. The highest priority risks (the key risks) should be given regular attention at the
highest level of the organisation, and should consequently be considered regularly by the
Board. The specific risk priorities will change over time as specific risks are addressed and
prioritisation consequently changes.

For Private Circulation Only 86


Impact

Impact (or consequence) refers to the extent to which a risk event might affect the enterprise.
Impact assessment criteria may include financial, reputational, regulatory, health, safety,
security, environmental, employee, customer, and operational impacts. Enterprises typically
define impact using a combination of these types of impact considerations (as illustrated
below), given that certain

risks may impact the enterprise financially while other risks may have a greater impact to
reputation or health and safety. When assigning an impact rating to a risk, assign the rating for
the highest consequence anticipated. For example, if any one of the criteria for a rating of 5 is
met, then the impact rating assigned is 5 even though other criteria may fall lower in the scale

Table 1: Impact Scale Example [5]

Relative / Numerical Scale

Objective
Very Low / Moderate / Very High
Low / 0.1 High / 0.4
0.05 0.2 /0.8

Insignificant < 10% 10 - 20% 20 - 40% > 40%


Cost
change in cost increase increase increase increase

Insignificant
5 - 10% 10 - 20% > 20%
Time change in < 5% increase
increase increase increase
schedule

Project end
Barely
Minor areas Major areas Unacceptable item
Scope noticeable
affected affected reduction effectively
scope decrease
useless

For Private Circulation Only 87


Quality
Barely Only Project end
reduction Unacceptable
noticeable demanding item
Quality requires quality
quality applications effectively
sponsor reduction
degradation effected useless
approval

Impacts are often defined as the consequences, or effects of a risk event on the project
objectives. These impacts can be both beneficial or harmful to the objectives .The impact of
risk events on different project objectives can be defined in both a qualitative and quantitative
manner. These project objectives are cost, schedule, quality, scope, health, safety, etc.

The Impact scale can vary, but the most common scale is the five-point scale. Typically, the
impacts are described relatively; as very low, low, moderate, high and very high, but often also
defined using numerical scales. Dependent on the objective, the scales are given a description
of what the impact entails . One risk event can affect more than one objective, so the impact of
all the possible objectives effected must be considered . Table 1 shows how the impact can be
defined for various objectives. The possible impacts on each objective is described and given
a ranking. The ranking in table 1 is both relative, from very low to very high, and numerical,
giving numerical values based on the specific project.

Probability

Risk probability, or likelihood, is the possibility of a risk event occurring. The likelihood can
be expressed in both a qualitative and quantitative manner. When discussing probability in a
qualitative manner, terms such as frequent, possible, rare etc. are used. It is also possible to
describe the probability in a numerical manner. This can be done using scores, percentages and
frequencies defined by the organizations dependent on the relative description Table 1 show
an example on how an organization can define the ranking for the likelihood of risks. The table
shows the ranking in both a relative and numerical manner and a description of the ranking is
given.

Table 1: Probability Scale Example

Likelihood Description

For Private Circulation Only 88


Relative Numerical

Very Low 0.1 Highly unlikely to occur.

Will most likely not


Low 0.3
occur

Moderate 0.5 Possible to occur

High 0.7 Likely to occur

Very High 0.9 Highly likely to occur

Risk analysis is a two-stage process, with qualitative assessment being the first stage. By using
qualitative methods for risk assessment, the risk can be categorized for further quantitative
assessment or even risk response planning. Quantitative assessment is the next stage in risk
analysis. The process involves analyzing the effects of risks on the overall project objectives.
They primarily focus on the risks which have been prioritized in the qualitative assessment. To
ensure the quality and credibility of the analysis, general definitions of impact and probability
levels must be fitted to individual project context.

Qualitative Analysis

Qualitative methods for risk assessment are relatively rapid in practice, cost effective and easily
understood . The results from the qualitative assessments are not an accurate estimate of risk.
However, they provide a rather descriptive result and often with sufficient information for
planning responses. The results from these assessments also set the foundation for more
detailed quantitative analysis, if possible and warranted. It is performed regularly throughout a
projects life cycle as new risks may emerge at later stages as well as a risk response may result
in other risk events . Classifying the risks enables organizations to reduce uncertainty levels
and focus primarily on the high-risk events. There are two qualitative methods of assessing risk
events in terms of impact and probability, both involving rating the impact and probability.
These are Risk Probability and Impact Assessment and Probability and Impact matrix

For Private Circulation Only 89


Risk Probability and Impact Assessment

The probability assessment involves estimating the likelihood of a risk occurring. The impact
assessment estimates the effects of a risk event on a project objective. These impacts can be
both positive and negative; i.e., opportunities and threats. The project objectives are numerous,
e.g. the schedule, cost, quality and scope. For each identified risk, the impact and probability
are assessed. Interviews and meeting with experienced project participants, stakeholders, and
experts in the subject are the basis for the impact and probability assessment. These impacts
and probabilities are rated and their level assessed. The risks which receive high ratings are
investigated further or an appropriate response is planned. The low rated risks do not require
an immediate action, but should be included in the Risk register for monitoring

Probability and Impact Matrix

The Probability and Impact Matrix is one the most commonly used qualitative assessment
method. It is based on the two components of risk, probability of occurrence and the impact on
objective(s) if it occurs. The matrix is a two-dimensional grid that maps the likelihood of the
risks occurrence and their effect on the project objectives . The risk score, often referred to
as risk level or the degree of risk, is calculated by multiplying the two axes of the matrix.

Risk = Impact x Probability

As the impact and probability can be described in both a relative and numerical manner so can
the risk score. The higher the combined ratings are, the higher the score and thus the risk level.
These ratings are generally defined from low to high or from very low to very high . The ratings
for likelihood and impact are made using gathered opinions from interviews These ratings
must be classified by each organization, specific for each activity. The organizations must
define their risk tolerance. Creating these definitions of impact and probability levels can help
reducing the influence of bias . The result from these risk matrices are used to prioritize the
risks, plan the risk response, identify risks for quantitative assessment and guide resource
allocations . However, the objective effected by the risk must also be considered. E.g., a risk
events which has high safety or health risk would be prioritized over a risk event which would
have very high financial risk

For Private Circulation Only 90


Table 3: Impact vs Probability Matrix

Probability Threats

Very High / 0.9 0.05 0.09 0.18 0.36 0.72

High / 0.7 0.04 0.07 0.14 0.28 0.56

Moderate / 0.5 0.03 0.05 0.10 0.20 0.40

Low / 0.3 0.02 0.03 0.06 0.12 0.24

Very Low / 0.1 0.01 0.01 0.02 0.04 0.08

Moderate / Very High /


Impact Very Low / 0.05 Low / 0.1 High / 0.4
0.2 0.8

High risk | Score > 0.14


A organization defines its risk thresholds, low,
moderate and high. These thresholds can
differ between projects.

Low impact – Low probability: The risks that are characterized as low, or very low, risks
have both a low impact and likelihood of occurrence. For negative risks, threats, the response
required is not necessarily as proactive management action. However, they should be included
within the risk register for future monitoring. Positive risks, opportunities, within the low-risk
category should be monitored or just simply accepted. Opportunity acceptance means taking
advantage of the opportunity if it arises, but not actively pursuing it .

High impact – Low probability: Risks with high impact but low likelihood of occurrence can
be characterized from low to high risks but most often within the moderate category. The

For Private Circulation Only 91


characterization is dependent on the organizations defined threshold. These events rarely occur,
defined as rare catastrophes. It is difficult to determine the probability based on historical
records due to lack of data. Therefore, the probabilities must be estimated subjectively. The
most commonly responses are to insure or mitigate the problem. .

Low impact – High probability: Risks with low impact but high likelihood of occurrence can
be characterized from low to high risks but most often within the moderate category. The
characterization is dependent on the organizations defined threshold. These risks are mostly
due to uncertainties of numerous elements that individually, are minor risks but combined,
could amount to higher risks. These are such uncertainties as actual cost and duration of
different aspects of a project, changes to activates or other similar uncertainties, that alone,
have little impact

High impact – High probability: The risks that are characterized as high risks have both a
high impact and likelihood of occurrence. A risk which has a negative impact, is a threat to the
objective, may need priority actions and aggressive responses. These aggressive responses
could be mitigation of the risk or even terminating the project if the risk is to great. A risk that
has a positive impact, is an opportunity, is most likely obtained easily, with the greatest benefits
and should thus be targeted first.

Quantitative Analysis

Quantitative assessment methods provide more accurate analysis results than the qualitative
assessment. However, they are costlier and often time consuming, so only the risk prioritized
by the qualitative assessment are analyzed. These methods are mostly used to analyze the
combined effects of all affecting risks. The most important benefit is that the information
produced support decision-making, and reduce project uncertainty. In some cases, quantitative
methods are not applicable due to lack of sufficient data, but that must be evaluated by the
project manager. The analysis should be repeated as a part of risk control to determine whether
the overall risks are reaching a desirable state. There various methods for quantitative analysis;
e.g. Sensitivity analysis, Expected Monetary Value analysis and Monte Carlo Simulations.

For Private Circulation Only 92


Risk Profile

The result of the risk analysis process can be used to produce a risk profile which gives a
significance rating to each risk and provides a tool for prioritising risk, treatment efforts. This
ranks each identified risk so as to give a view of the relative importance. This process allows
the risk to be mapped to the business area affected, describes the primary control procedures
in place and indicates areas where the level of risk control investment might be increased,
decreased or reapportioned. Accountability helps to ensure that ‘ownership’ of the risk is
recognised and the appropriate management resource allocated.

The potential loss from an adverse outcome is a function of the probability or likelihood that
the adverse outcome will occur, and the impact of the outcome if it does occur.

When an initial review is carried out to identify and assess risks, the assessment of both
probabilities and impact might be based on judgement and experience rather than on a detailed
statistical and numerical analysis.

In an initial analysis, it might be sufficient to categorise the probability of an adverse outcome


as ‘high’, ‘medium’ or ‘low’, or even more simply as ‘high’ or ‘low’. Similarly, it might be
sufficient for the purpose of an initial analysis to assess the consequences or impact of an
adverse outcome as ‘severe’ or ‘not severe’.

Each risk can then be plotted on a risk map. A risk map is simply a 2 × 2 table or chart, showing
the probabilities for each risk and their potential impact.

The two by two matrix will consist of details as under

Impact –Low High

Probability or -High

Likelihood – Low

A risk map immediately indicates which risks should be given the highest priority.

High-probability, high-impact risks should be given the highest priority for management,
whether by monitoring or by taking steps to mitigate the risk.

For Private Circulation Only 93


Low-probability, low-impact risks can probably be accepted by the organisation as within
the limits of acceptability.

High-probability, low-impact risks and low-probability, high-impact risks might be analysed


further with a view to deciding the most appropriate strategy for their management.

For each high-probability, high-impact risk, further analysis should be carried out, with a view
to: estimating the probability of an adverse (or favourable) outcome more accurately, and
assessing the impact on the organisation of an adverse outcome.

This is an area in which the finance department should be able to contribute by providing
suitable and relevant financial information.

An alternative layout for a risk map shown above) would be a tabular format. The table might
have the following columns:-

(1) The risk name e.g. fraud.

(2) The likelihood of that risk arising e.g. medium.

(3) The impact of the risk if it does arise e.g. high.

(4) Controls already in place.

(5) The risk owner i.e. the name of a manger or director who watches out for this risk arising.

(6) Whether assurance is sufficient. This might be given a score out of, say, 10, or a yes/no
type response.

(7) Controls to be implemented in the future

4.3 –Risk Management Strategies

Risk response strategy

The management of risks involves trying to ensure that:

 Exposure to severe risks is minimised.

 Unnecessary risks are avoided.

 Appropriate measures of control are taken.

 The balance between risk and return is appropriate.

For Private Circulation Only 94


The estimate of the potential loss for each risk should be compared with the acceptable risk
limit for the company. If the risk is greater than the acceptable limit, the next stage is to consider
how the risk should be managed or controlled, to bring it down in size.

The different Risk management strategies are of five types . They are as under

1. Risk avoidance: Where risks have such serious consequences on the project outcome that
they are totally unacceptable. Risk avoidance measures might include a review of the
employer’s brief and a reappraisal of the project, perhaps leading to an alternative design
solution that eliminates the risk or even project cancellation. Risk avoidance occurs where risks
have such serious consequences on the project outcome that they are totally unacceptable. Risk
avoidance measures might include a review of the employer’s brief and a reappraisal of the
project, perhaps leading to an alternative development mix, alternative design solution or
cancellation of the project

2. Risk reduction: Where the level of risk is unacceptable and actions are taken to reduce
either the chance of the risk occurring or the impact of the risk should it occur. Typical actions
to reduce the risk can include: further site investigation to improve information, using different
materials/suppliers to avoid long lead times or using different construction methods. Risk
reduction occurs where the level of risk is unacceptable

3. Risk transfer to the contractor: Risk transfer occurs where accepting the risk would not

give the employer best value for money. The object of transferring risk is to pass the
responsibility to another party better able to control the risk. Whenever risk is transferred there
is usually a premium to be paid (i.e. the receiving party’s valuation of the cost of the risk). To
be worthwhile, risk transfer should give better overall value for money to the employer (the
total cost of the risk to the employer is reduced by more than the cost of the risk premium).
Risk transfer measures include taking out insurance cover where appropriate.

4. Risk sharing by both employer and contractor: This is when a risk is not wholly
transferred to one party and some elements of the risk are retained by the employer. In
accordance with NRM, the approach for dealing with risks that are apportioned between the
client and the employer will normally be dealt with using provisional. quantities, with the
pricing risk being delegated by the contractor and the quantification risk being allocated to the
employer. Risk sharing occurs when risk is not entirely transferred and the employer retains
some element of risk.

For Private Circulation Only 95


5. Risk retention by the employer: In the event where risks are to be retained by the employer,
the appropriate risk allowance identified in the cost plan will be reserved and managed by the
employer.

Risk retention occurs when the employer retains risks that are not necessarily controllable. This
remaining risk is called the residual risk exposure

Interrelationship of risks

There are often interrelationships between risks (known as consequential risks) that increase
the complexity of assessing them. It is not uncommon for one risk to trigger or increase the
impact and/or likelihood of another. Such knock-on effects can turn a relatively minor event,
such as the decoration of a single room, into a major event; i.e. the facility cannot be handed
over until the room is complete and the client is not able to receive a rental income.
Interrelationships of risks often cross boundaries in the project plan (i.e. ownership, funding,
decision-making and organisational/geographical structures). The risk manager should be able
to communicate and liaise across these boundaries. Identifying, assessing and tracking down
interrelationships of risks are essential parts of the risk management process. Care must be
taken with overarching risks and double counting within the risk register. Classification of risks
in strategic and project operation and regular reviews of the register, led by an experienced
facilitator who is familiar with the project, will help mitigate problems in this regard.

The strategies for mitigating risk for each risk rating level (red, amber, orange and green)
should suit the level of risk appetite defined by the project team (risk appetite will vary
depending on the client’s core business and also the personnel responsible for the project). The
project team should agree on the risk mitigation approach and follow this when defining actions
for specific risks. Figure 3 shows an example of a risk mitigation approach.

Figure -3

For Private Circulation Only 96


4.4- Risk Monitoring

Risk monitoring and control definition

Risk monitoring and control refers to the process of continuously identifying risks and
establishing the best methods of dealing with those risks.

Risk monitoring and control begins at the start of projects when all potential and known risks
are identified, and then just as importantly, continues throughout a project as those initial risks
are continuously tracked while new risks are also identified as work continues, changes and
progress.

Risk monitoring and control is a really important project management activity, because it
enables companies to manage one of the most powerful forces in project management: risk.

The overarching purpose of risk monitoring and control is to mitigate and eliminate the risks
which could de-rail a project or impact a company, and within these broader goals there are
some more specific purposes:

 To make sure that the right and appropriate risk responses have and are being
implemented as planned

 To determine the validity of the assumptions which were made prior to projects and
will likely be made again

 To ensure risk responses actions are effective

 To identify risk triggers for now and in the future

 To track and ensure that proper risk management and risk control procedures are
followed

 To analyse trends and patterns in risk

Without proper risk monitoring and control, a company is powerless to understand how their
initial risk plans are going, as well as to respond quickly to the inevitable risks which arise
during the course of projects.

For Private Circulation Only 97


4.5 Risk Controls

There are a range of controls that can be applied to hazard risks. The most convenient
classification system is to describe these controls as preventive, corrective, directive and
detective. This is the risk classification system suggested in the Orange Book.

Description of types of hazard controls

1 Preventive (terminate)

These controls are designed to limit the possibility of an undesirable outcome being realized.
The more important it is to stop an undesirable outcome, then the more important it is to
implement appropriate preventive controls.

2 Corrective (treat)

These controls are designed to limit the scope for loss and reduce any undesirable outcomes
that have been realized. They may also provide a route of recourse to achieve some recovery
against loss or damage.

3 Directive (transfer)

These controls are designed to ensure that a particular outcome is achieved. They are based on
giving directions to people on how to ensure that losses do not occur. They are important, but
depend on people following established safe systems of work.

4 Detective (tolerate)

These controls are designed to identify occasions when undesirable outcomes have been
realized. Their effect is, by definition, ‘after the event’ so they are only appropriate by
definition, ‘after the event’ so they are only appropriate when it is possible to accept that the
loss or damage has occurred.

For Private Circulation Only 98


Directive Controls

Directive controls are designed to ensure that a particular outcome is achieved. In health and
safety terms, directive controls would include instructions/directions given to employees to
follow, for example, in the use of personal protective equipment. Training in how to respond
to a particular risk event and detailed instructions and procedures are directive controls.
Directive controls are also associated with actions that must be taken in the event of a loss

to limit the damage and contain the costs. Detective controls are designed to identify occasions
when an undesirable outcome has occurred. The control is intended to detect when these
undesirable events have happened, to ensure that the circumstances do not deteriorate

further. An example of detective controls in a project is undertaking a post incident review.

There is a clear hierarchy of effectiveness of controls that is represented by the order


preventive, corrective, directive and finally detective. Preventive controls are clearly the most
effective, followed by controls that correct adverse circumstances. Providing training and
direction to staff is a weaker level of control, and detective controls only confirm that an
adverse event has occurred.

For Private Circulation Only 99


Preventive controls

These are the most important type of risk controls, and all organizations will use

preventive controls to treat certain types of risks. Prevention or elimination of all

risks is not possible on a cost-effective basis, nor may it be desirable for the future of the
organization and the continuation of certain activities. Examples of preventive controls include
the separation of duty, whereby no person has authority to act without the consent of another
when paying an invoice. Also, expenditure systems should prevent the same person from
ordering goods and then authorizing the payment for them. In health and safety terms,
preventive controls include the elimination or removal of the hazard and providing a less risky
substitute. For example, a hazardous chemical used in a cleaning operation may be substituted
with a less harmful alternative. The advantage of preventive controls is that they eliminate the
hazard, so that no further consideration of it is required. In reality, this may not be a cost
effective option and may not be possible for operational reasons. The disadvantages of
preventive controls are that beneficial activities may be eliminated and either outsourced or
replaced with something less effective and efficient. Health and safety practitioners refer to the
elimination of hazardous activities ‘so far as is reasonably practicable’. Achieving something
so far as is reasonably practicable involves the balance between cost in terms of time, trouble
and money against the benefit in terms of the reduction in the level of risk that is achieved. For
example, reducing the risk of collapse can be achieved in underground mines by the provision
of support beams and props. However, the extent to which this is reasonably practicable will
need to take into account the cost of providing these props against the level of risk reduction
that would be achieved in that particular mine.

Corrective Controls

Corrective controls are the next option after it has been decided that preventive controls are not
technically feasible, operationally desirable or cost-effective. Corrective controls are capable
of producing an entirely satisfactory result, whereby the current level of risk is reduced to
within the risk appetite of the organization. Examples of corrective controls can be found in
the management of health and safety at work. Engineering containment by way of barriers or
guards is a very well-established type of corrective control. In relation to fraud exposures, use
of passwords or other access controls can be considered to be corrective controls. Staff rotation
and regular change of supervisors also fit into this category of controls. The advantage of many
corrective controls is that they can be simple and costeffective. Also, they do not require that

For Private Circulation Only 100


existing practices and procedures are eliminated or replaced with alternative methods of work.
The controls can be implemented within the framework of existing activities. The disadvantage
of some corrective controls is that the marginal benefits that are achieved may be difficult to
quantify or confirm as cost-effective.

Sometimes, corrective controls are over-engineered and their cost is disproportionate to the
benefit that is achieved. It is for risk management practitioners and internal auditors, as well as
employees themselves, to identify where expensive and/or ineffective corrective controls have
been implemented.

Very often, corrective controls are put in place because of regulatory requirements. This may
be unsatisfactory from the point of view of the organization and introduce additional costs
and/or inefficiency. However, it is for the organization to ensure that the appropriate level of
corrective control is achieved in order to comply with the minimum requirements of legislation.

The design and implementation of corrective controls is often the cause of considerable
discussion and even disagreement. For example, there is sometimes discussion with building
occupiers about fitting sprinklers as a corrective control that will activate in case of fire and
reduce the damage caused by the fire. Occupiers of premises with computer installations will
often say that sprinklers in computer rooms are inappropriate. Whilst understanding that water
does damage computer installations, fire engineers will usually counteract the

objections by pointing out that ‘water causes damage, but fire destroys’. Although this analysis
is correct and sprinklers do prevent total destruction, the disadvantages and unintended
consequences of installing additional controls always need to be carefully considered.

Detective Controls
As suggested in the title, detective controls are those procedures that identify when the hazard
has materialized. Detecting that a hazard has materialized some time after the event is not
entirely satisfactory, but can be justified in certain circumstances. Sometimes, other controls
may be unable to completely eliminate the chances of a risk materializing. Examples of
detective controls include stock or asset checks to ensure that stock or assets have not been
removed without authorization. Bank reconciliation exercises can detect unauthorized
transactions. Also, post implementation reviews can detect the lessons learnt from projects that
can be applied in future. Detective controls are closely related to review and monitoring

For Private Circulation Only 101


exercises undertaken as part of the risk management process. The advantage of detective
controls is that they are often simple to [Link] any case, they are essential in many
circumstances where the organization will require early warning that other risk control
measures have broken down.

The disadvantage of the detective controls is that the risk will already have materialized before
it is detected. It could be argued, of course, that the fact that detective controls are in place will
deter certain individuals from attempting to circumvent other risk controls.

Detection of fraud is often only possible after the fraud has taken place. However, there are
considerable advantages in detecting fraud early, so that the nature and scale of the fraud may
be reduced and the scope for future similar fraudulent activities eliminated. Even in health and
safety arrangements, there is scope for the use of detective controls. Certain work activities
have hazards associated with them that can lead to permanent and serious health issues. By
having detective controls to identify the early symptoms of these occupational ill health
conditions, employees will be diagnosed early and further exposure can be eliminated.
Examples of these types of controls in health and safety include early detection of lung disease
from dust exposure, skin conditions such as dermatitis and finally deafness

caused by exposure to occupational noise.

Risk monitoring and control is required in order to: -

(i) Ensure the execution of the risk plans and evaluate their effectiveness in reducing
risk.
(ii) Keep track of the identified risks, including the watch list.
(iii) Monitor trigger conditions for contingencies
(iv) Monitor residual risks and identify new risks arising during project execution.
(v) Update the organizational process assets.
The purpose of Risk monitoring is to determine if:

(i) Risk responses have been implemented as planned.


(ii) Risk response actions are as effective as expected or if new responses should be
developed.
(iii) Project assumptions are still valid.
(iv) Risk exposure has changed from its prior state, with analysis of trends.
(v) A risk trigger has occurred.

For Private Circulation Only 102


(vi) Proper policies and procedures are followed.
(vii) New risks have occurred that were not previously identified

References:

1. Institute of Leadership and Management (IoL&M) study material


2. ICAI risk management study material
3. The Institute of Risk Management : Risk culture Under the Microscope Guidance for
Boards

4. Hampton , John –Fundamentals of Enterprise Risk Management –Second Edition-American


Management Association (2015)
5. [Link]
Jain University notes, COSO - Risk assessment in practice, Oct 2012

Terminal questions
Section -A (5 marks )

1. Describe in brief the ways in which Risk estimation happens.


2. Define briefly the PESTLE approach to Risk identification
3. List out any four sources of Risk identification
4. Define the key elements of Risk response strategy
5. Briefly explain concept of Stakeholder analysis and why it is important .

Section –B ( 9 marks)

1) Explain ways in which probability of Threats and Opportunities is determined.


2) Briefly name the four types of compliance risks and give example of any two risks
3) Explain briefly the concept of Risk profile and its importance.
4) Elaborate on probability and risk matrix.

Section –C (12 marks)

1) Explain the importance and relevance of Risk identification


2) Differentiate between commissioning a risk review and Risk Self-assessment

For Private Circulation Only 103


3) Explain the Role played by Impact and Probability while measuring risks, and how it
will impact business. Give any two examples you are aware of.
4) Elaborate the various Risk management strategies that can be applied to contain risks.
5) Explain fully the four types of Controls that are applied to reduce risks.

For Private Circulation Only 104


Module V

Strategic Risk Management

Structure

5.1 Process for communicating risk management strategies


5.2 Resourcing and managing Risk Management Strategies
5.3 Evaluation of Risk management strategies
5.4 Disaster Recovery plan and its evaluation
5.5 Outcomes of Risk management strategies and its evaluation

5.1 Communication of Risk management strategies

The Communication of Risk management strategies is one of the key aspects of effective risk
management. It is therefore important for Risk professionals to be aware of the importance,
relevance and criticality of Risk management strategies. Component 7 of the COSO ERM cube
considers the importance of risk information and communication.

Risk communication starts with the identification of the stakeholders that have an interest in
the particular risk under consideration. Once the stakeholders have been identified, the nature
of the risk information that needs to be communicated must be decided. Finally, the purpose of
communicating risk information to each group of stakeholders should be analyzed.
Stakeholders will already have a perception of risks, so risk communication should be provided
against the background of that existing perception. The guidelines relevant to risk
communication set out in Table 26.2 should be followed. These guidelines seek to establish
rules for communicating risk issues to a broad range of stakeholders.

Risk Communication Guidelines

 Know the stakeholders, by identifying both external and internal stakeholders and
finding out their interests and concerns.
 Simplify the language and presentation, although not the content if complex issues need
to be communicated.
 Be objective in the information provided and differentiate between opinions and facts

For Private Circulation Only 105


 Communicate clearly and honestly, taking account of the level of understanding of the
audience
 Deal with uncertainty and discuss situations where not all information is available and
indicate what can be done to overcome these problems
 Be cautious when putting risks in perspective, although comparing an unfamiliar risk
with a familiar one can be helpful.
 Develop key messages that are clear, concise and to the point, with no more than three
messages communicated at any one time
 Be prepared to answer questions and agree to provide further information if it is not
currently available

Clearly, these rules become more important when the communication about risk is with
external bodies. Nevertheless, they provide a useful set of guidelines for risk communication
with internal as well as external stakeholders. Internal stakeholders have additional reasons for
being provided with risk information. There will normally be an expectation by the
organization that managers and staff will play a role in the future management of the risk,
whereas this may not always be the case for external stakeholders.

The first reason an organization needs a risk language is to underpin its risk culture. Everyone
in the organization has a role in an effective risk management process. Most organizations have
many layers (eg executives, line managers and employees) and ‘silos’(eg technology, treasury,
operations, quality management and compliance). A common language is needed to cut
through the layers and break down the silos. Conversely, without a common language, the risk
management team will spend too much time resolving communication issues at the expense of
their primary responsibilities.

Risk information can be made available to stakeholders by a variety of means. Many


organizations produce brief guides and leaflets for stakeholders to communicate the current
risk issues and concerns. The appropriate means of communication will vary according to the
nature of the stakeholder and the nature and complexity of the message to be communicated.

Formal means of risk communication exist where the organization has to report to financial
stakeholders. When risk communication is required, a range of communication techniques can

For Private Circulation Only 106


be used. A formal report to the stock exchange or to other financial stakeholders may be backed
up by an informal video, slide presentation and/or a telephone conference call, as appropriate.

There is often an additional means of risk communication available to organizations. Many


organizations have developed an intranet for use by staff and this can be used to cover risk and
risk management information. For many large organizations, it is common for the intranet to
be used to communicate health and safety information and business continuity plans.

Information can be provided on the intranet about the generic risk assessments that have been
undertaken and the control measures that have been identified. The intranet can also be used to
communicate urgent risk information, as well as providing updates on risk assessments, control
measures and the current level of any particular risk.

An important consideration in the collection, retention and supply of risk information is that it
should be aligned with other management information systems within the organization.
Providing risk information as a separate management information stream is likely to result in
risk management activities failing to be aligned or embedded within other activities. The
danger that risk information will become irrelevant to managers in the organization is greater
when the organization has a dedicated risk management information system (RMIS).

The distribution of risk management guidelines, protocols and procedures may be undertaken
by way of a risk management information system (RMIS) software package. The RMIS could
be placed on the intranet of the organization. The RMIS will also facilitate the collection and
communication of risk information, including the reporting of events by local management as
they occur.

The following types of information may be handled, stored, managed, distributed and
communicated using a risk management information system :-

 Risk management policy and protocols


 Risk profile data, values and information
 Emergency contact arrangements and contact details
 Insurance values and cost of risk data
 Insurance claims handling and management protocols
 Historical loss/claims experience/information
 Insurance policy coverage and other information
 Risk management action plans (risk register)

For Private Circulation Only 107


 Risk improvement plans and implementation
 Business continuity plans and responsibilities
 Disaster recovery plans and responsibilities
 Corporate governance arrangements and reports
It is generally accepted that the application of a RMIS software tool to an enterprise risk
management (ERM) initiative can be very helpful. However, the disadvantage that is often
encountered is that entering a substantial amount of risk data onto a computer database can be
very time-consuming. Nevertheless, the benefits of having the data available for detailed
analysis can make the effort worthwhile. Many software tools are available that can be used
for these purposes .

Risk information needs to be shared throughout an organization to enhance risk awareness and
ensure improved risk performance. It is almost always the case that individuals within an
organization will have the best understanding of the risks, as well as detailed practical
knowledge of the actions that should be taken to mitigate risk events. Communication is also
important to share information about incidents that have occurred, including lessons that were
learn and the actions that were taken to ensure that the event is not repeated.

5.2 Resourcing and managing Risk management strategies

Risk communication is legally required. On a fundamental level, corporate social responsibility


demands that companies communicate their risks. Indeed, this obligation is codified in various
legal statutes and regulatory directives.

Beyond simply satisfying rules and regulations, it’s in a company’s own best interest –
economic and otherwise – to commit to risk communication in order to prevent or minimize
public risk conflicts and business crises.

Effective risk communication must address both the expert’s as well as the layperson’s
perspectives and approaches to characterizing risks. What is at stake is the extent to which the
risk issue could become a critical business factor. Even a "minor" risk can develop into a
serious problem for a company, even to the extent of putting it into a business crisis.

For Private Circulation Only 108


Fig – Life cycle of A Risk Issue

The capacity of a risk issue to evolve into a problem is influenced by a number of factors .These
characteristics determine to what extent a risk issue is likely to attract public attention and to
what extent it may become politicized. It is important to note that this progression depends
more on the perspective of the layperson than on views and assessments of the experts. Once
on its course, the company or organization is less and less able to have an influence on the risk
issue. Communication can only be successful if attempts are made to contribute to the debate
as early as possible in the emergence phase.

Various societal groups may be involved at different stages of the lifecycle. From the viewpoint
of a company, the most important groups to address in risk discussions are:

 Political interest groups and government


 the company's own employees
 affected persons, e.g. nearby residents
 media (local, regional, and national)
 industry press
 the interested public and citizens’ action groups

 environmental and consumer activist organizations


 the company's clients and suppliers
 insurance providers

The defining moment in the lifecycle of a risk problem is the occurrence of an accident or other
critical event that causes harm to people or the environment, or at least is perceived to do so.

For Private Circulation Only 109


The public reaction to such critical events and, therefore, their potential impact on the company
depends on how this critical event is interpreted. Here again, perception is crucial. The left
column of Fig. 4 shows different "perceived causes" of harm. The core question is who or what
was responsible for the harm. Does the company have to be held responsible, or are external
factors beyond the company’s control to blame? The right column shows the reactions which
can be expected, depending on how the cause for the problem is interpreted by the public.

Companies have to expect serious consequences, up to and including a business crisis, if they
are perceived as being responsible or if they knew and condoned the risk, in spite of it being
perceived as intolerable. The situation is completely different if the companies themselves are
perceived as being the victims of aggression or a natural disaster. Fig. 4 presents the details of
this relationship. Therefore Risk communication should be structured separately for each of
these different circumstances.

Every company should know and periodically check the extent to which it needs to engage in
risk communication. The audit tool presented here aims at:

 assessing the existing potential for exposure to risk issues using Table 3

 determining the sensitivity towards risk issues for the company's specific operating
environment using Table 4

 reviewing the risk culture within the company.

The assessment criteria presented here are solely a guideline and should in no way be
considered exhaustive or conclusive. The assessment should be made in qualitative terms, since
the overall picture of the "susceptibility to risk" can be gained only from a broader overview.
Analyses of the company's strengths/weaknesses and opportunities/threats can then be
performed to determine the appropriate actions that should be taken.

For Private Circulation Only 110


Table 3: Assessing exposure to risk issues
Questions Examples Assessmen
t
 Production and handling of
 Are incidents/accidents possible?
hazardous substances in large
quantities
 Are the risks imported from suppliers
known?  Dioxins in animal feed
 Is there a danger of harm to the  Emissions and
environment and/or health from residues from
normal operational releases? production
 Are there any risks involved in
using and disposing of products?  Persistent substances
 Do emissions constitute a nuisance
(but not a health threat) to nearby  Dust, noise, odors
residents?
 Could the soil be contaminated  “Inherited” contamination
from past production processes at
the site?  Effects on vegetable or
 Is an impact on agriculture likely? animal production
 Damage to or loss of
 Could property values in the
value of surrounding
community suffer? buildings
 Is there knowledge of previous
 “Inherited” contamination,
environmental damages around the
past land uses, presence of
site? other hazardous
plants.
Summary assessment

The more questions are answered in the affirmative in Table 3, the more the company has to
count on being involved in risk debates. This is because there tends to be a direct relationship
between the number and extent of the potential risks within the company and the probability
of the public becoming aware of these potential risks. And the greater is the need to
communicate appropriately in order to build sound foundation for effective risk management

Needless to say, if the answer to some of the questions is simply not known, that may point to
a lack of information that should be addressed. Ignorance, or more precisely, “not knowing the
knowable” does not make for an effective risk communication strategy and is likely to be
interpreted as a negligent attitude.

The below checklist explores the company's corporate culture, or, to be more precise, its
attitude towards risks and how it deals with the public. These factors determine which obstacles
to risk communication within the company must be overcome.

For Private Circulation Only 111


The more questions are answered in the affirmative in relation to risk culture , the greater the
need for the company to improve its communication processes.

Table 4: Risk culture within the company

Questions Examples Assessment

 Does the company consider  "We are too big/too small –


itself "invulnerable" regardless nothing can happen to us"
of how public opinion sees it? attitude

 Is communication
considered an afterthought  Communication is an
within the company? unnecessary luxury – we
need to concentrate on the
real problems
 Does the company believe that it
is far too small to become  Crises affect only big
involved in a public debate? businesses that are in the
public eye
 Is it assumed that accidents
can be positively ruled out?
 "Accidents are
 Does the company have no inconceivable" attitude
contact with the press?
 Never held a press conference
 Does the company have no
contact with environmental and  Never held a meeting with
consumer activist or community an environmental activist
action groups? association

 Does the company have little or no


contact with the local population?  Never held an open day

 Lack of employee support for the


 Employees worried/afraid
company
about products and
production processes
Summary assessment

5.3 Evaluating Risk management strategy

All organizations of all kinds face internal and external factors and influences that make it
uncertain whether, when and the extent to which they will achieve or exceed their objectives.
These objectives are its highest expression of intent and purpose, and typically reflect an

For Private Circulation Only 112


organisation’s explicit and implicit goals, values, and imperatives or relevant enabling
legislation.

The international risk management standard, ISO 31000:2009, defines risk as the effect of
uncertainty on objectives. The effective management of risk is therefore essential if
organisations are to achieve their objectives and satisfy the needs of their stakeholders.

It has been long recognised that good governance and effective management are best achieved
through the development and deployment within an organisation of one coherent and consistent
framework, methodology and vocabulary for management of risk, to be used for all types of
activity. This ensures that:

 There is a consistent and defensible basis for decision making at all levels, particularly
where effort or capital is expended
 Change activities are more likely to succeed

 The organisation can pre-empt and capitalise on external changes such as those
involving demographics, customers’ needs and government policy 

 All employees are encouraged to focus on and give priority to actions that aid and
enhance the execution of strategic and project plans and the organisation’s objectives 

 The organisation is prepared for and protected from major incidents and losses 

 Tactical moves, to identify and seize opportunities are stimulated and enhanced 

 Accountability for risks and, most importantly, for controls and the monitoring and
assurance of controls is clear and not doubtful.

In time this will also lead to a significant change in culture as the organisation as its employees
engage on activities directly related to ensuring the achievement of goals and objectives and
the successful completion of projects.

Setting up the framework

An organisation’s ability to manage risk effectively depends on its intentions and its capacity
to achieve those intentions. This intent and capacity is referred to as its risk management
framework and is part of its system of governance and management.

For Private Circulation Only 113


The quality of the framework is important because effective risk management requires:

 Clear expectations from ‘the top’


 Appropriate capability (skills, resources, support)
 Sound relationships with stakeholders
 Integration of necessary risk management practices into the day-to-day activities and
accountabilities of the management team
 A commitment to continually learn and improve.

The risk management framework should not attempt to replace the natural capability of people
to manage risk; rather it should enhance good practices so that the process is reliable,
comprehensive and consistent. For this to occur and for the required capability to be achieved,
the organisation requires:

1. A set of suitable ‘tools’


2. A coherent approach to training and communicating to people so that they can use those
tools in a competent and consistent manner
3. An approach that signals and reinforces the correct behaviour and way of thinking.

The typical elements of a framework and an illustration of how this supports the integration of
the risk management process is shown in the figure below

For Private Circulation Only 114


The Framework for Evaluating Risk Management strategy

The core of this management of change process involves internal stakeholder representatives
participating in a facilitated gap analysis and evaluation that then leads to a clear and practical
enhancement and implementation plan. This is depicted in the “Y Model” shown in the figure
and described below.

To enable those stakeholder representatives to participate effectively, they need to be well


briefed on current risk management thinking and shown examples drawn from other
organisations of elements of a risk management framework.

This approach has the added benefit that the participants of this process then become the
organisation’s “Champions” who are motivated to lead the implementation process in their
own departments and functions. They also act to convince their superiors of the merits of the
approach and motivate acceptance and use.

To be successful and efficient, the management of change approach requires:

1. An accepted and accurate representation of the current arrangements for managing


different forms of risk – the present situation
2. The fundamental concepts of risk and risk management and the desired goals in terms
of the risk management framework and process to be clearly understood by those
sponsoring the change – the wanted situation
3. A clear and accepted appreciation of the elements of the existing framework that need
to be enhanced or improved and the nature of those changes and any additional elements
that need created – what needs to change
4. The exploration of options, constraints, enablers and critical paths leading to an
appropriate plan of actions with timings
5. A clear commitment to the plan and its implementation through the allocation of
suitable resources by senior management and by their continued oversight of progress.

These steps can be tackled separately and the results fed back to senior management. However,
after many years and numerous attempts we have found that most efficient approach, and the
one that gains the greatest degree of ownership and endorsement, is to involve representatives
of senior internal stakeholders in all these steps over a short space of time. This approach is
described in detail below.

For Private Circulation Only 115


Phase 1 - Preparation

Evaluation studies typically start with an initial meeting where the detailed arrangements,
including the schedule of activities and delivery dates, the documents to review reviewed and
the interview candidates are agreed.

The Y model

To be successful and efficient, the management of change approach requires:

1. An accepted and accurate representation of the current arrangements for managing


different forms of risk – the present situation
2. The fundamental concepts of risk and risk management and the desired goals in terms
of the risk management framework and process to be clearly understood by those
sponsoring the change – the wanted situation

For Private Circulation Only 116


3. A clear and accepted appreciation of the elements of the existing framework that need
to be enhanced or improved and the nature of those changes and any additional elements
that need created – what needs to change
4. The exploration of options, constraints, enablers and critical paths leading to an
appropriate plan of actions with timings
5. A clear commitment to the plan and its implementation through the allocation of
suitable resources by senior management and by their continued oversight of progress.

These steps can be tackled separately and the results fed back to senior management. It is fel
that the most efficient approach, and the one that gains the greatest degree of ownership and
endorsement, is to involve representatives of senior internal stakeholders in all these steps over
a short space of time. This approach is described in detail below.

Various phases of evaluating Risk management plan

Phase 1 - Preparation

Evaluation studies typically start with an initial meeting where the detailed arrangements,
including the schedule of activities and delivery dates, the documents to review reviewed and
the interview candidates are agreed.

Prior to the meeting we issue a checklist of background documentation we would like to review
and will often open up a secure Internet portal to which documents can be uploaded. This list
can include:

 Relevant policy statements, framework descriptions, internal standards and procedures,


with a particular focus on decision support and controls assurance
 Internal standards, procedures or guidelines that deal with particular applications of risk
management. For example in the area of safety, procurement, security, operations,
maintenance, BCM, compliance and project management
 The current strategic plan and objectives
 Examples of risk management plans and control assurance plans
 Extracts from the risk management information system including risk registers and risk
treatment plans
 Methodology for and outputs from any quantitative risk analysis studies (range
analyses) for schedule, capital and value evaluation and contingency estimation

For Private Circulation Only 117


 Copies of recent reports to any risk management steering committees or review groups
and the oversight committee that show risk management performance
 Copies of any existing training and briefing materials that deal with risk management.

Normally a preliminary review of the materials is undertaken and, from this, develop an aide
memoire of sample questions that the risk team might ask those they want to interview. This
document is sent to those who are to be interviewed to allow them to prepare.

Phase 2 - Elicitation and verification

Experts observe that it is vital to observe and review how risk management takes place in
practice. This is particularly true if there might be any discontinuity of practice across the
organisation or inconsistent processes and systems. It is also important to test management’s
perceptions of the current approach to risk management to see if it is currently viewed as
effective and is likely to satisfy their future needs.

They therefore undertake this observation through a series of structured interviews with senior
managers from which they will draw conclusions on:

 The suitability of the current framework and tools to manage risk associated with an
organisation of a comparable size and complexity, its risk profile and the risk criteria
that should reflect its attitude (appetite)
 The drivers of that attitude, based on what are recognised as the ‘key success factors’
and growth objectives for the organisation
 The perceived usefulness of the current risk management process and its degree of
integration into key decision-making processes;
 The strengths and limitations of the other approaches to risk management specific to
particular kinds of risks that co-exist in the organisation
 Whether the tools and methods currently being used are capable of providing the
organisation with a current, correct and comprehensive understanding of its risks and
inform it whether the risks are within its risk criteria
 The level of understanding of senior managers about aspects of the risk management
culture
 An outline of the perceived risk profile of the organisation and whether this varies from
the risks reported to senior management and oversight committees.

For Private Circulation Only 118


The interview of the member of organisation’s risk function will help to transfer knowledge.

While the predominant purpose of the interviews is to obtain information from the participants
to support the review, they also provide an opportunity to explain the purpose of the study.

At the conclusion of the series of interviews it normally provides immediate feedback to the
organisation’s risk staff on:

 The findings

 Their conclusions on the level of maturity, the strengths and weaknesses


 Their initial thoughts on where the organisation could enhance the management of risk
and the steps that should be taken.

This meeting also allows any misunderstandings or misperceptions to be rectified

Phase 3 - Gap analysis and evaluation

Using the information, the experts/reviewer have gathered the conduct a detailed gap analysis
and evaluation of effectiveness using the guidelines and principles in ISO 31000 and what they
understand is world’s best practice as a basis for comparison. Often this is conducted as a
facilitated workshop involving the management team.

The gap analysis looks at how the organisation expresses its intentions for managing risk and
the elements of the capacity it claims it provides. In practice this involves at looking all the
elements of the risk management framework and process shown above to determine if they are
present and are suitable for the organisation and its environment.

Normally a full gap analysis is prepared with a evaluation report that includes expert’s findings
in terms of:

 The framework and how it facilitates the integration of risk management into decision
making, including risk management plans and the strategy for their implementation
 How risk management is applied in strategy development and during the concept and
development phases of projects, for decision-making and change management and as
part of design review
 Control assurance and reporting
 The reliability of each element of the risk management process

For Private Circulation Only 119


 How risk management is used to deal with changes and to provide contingency
arrangements that respond to disruptions, including how learning and feedback take
place after events, incidents and decisions
 How the overall risk profile of the company is obtained and evaluated through
aggregation and roll-up and how risks are treated at a corporate level
 The form and content of governance reporting
 How risk treatments are closed out and monitoring and review of risks, controls and
risk treatments occurs
 The organisation’s culture as it pertains to the management of risks in terms of both
intent and practice
 The adequacy and effectiveness of the systems and resources available to support the
management of risk, including human resources

Phase 4 - Gaining ownership and detailed planning

It is important that senior managers appreciate and can comment on the reviewer’s findings
and conclusions and that this leads to support for any enhancement plan. It is important that
this takes place before their report is made available to the oversight committee so that it can
indicate management’s response.

The Reviewer or expert, therefore normally present their findings and recommendations at a
short meeting with senior managers. A typical draft agenda will be:

 Fundamentals of risk and best practice risk management

 Overall findings and assessment of the bench marking review


 Suggested improvements and enhancement strategies
 Draft enhancement plan.

The planning component of this session follows the ‘Y model’ (see above) to elicit feedback
and ownership of the current situation, the wanted situation and what needs to change. The
management team is encouraged to discuss and compare options and then to finalise the
enhancement plan actions and agree timelines. These agreements are recorded and included in
final report.

Phase 5 - Report to the oversight committee

For Private Circulation Only 120


Often the findings are presented to the organisation’s oversight committee. This provides them
with the confidence that the evaluation was conducted in an independent manner and to enable
the members to challenge and question any outcomes.

Normally the reviewer/expert’s report is accompanied by the management-agreed


enhancement plan, to indicate the organisation’s commitment to improvement.

In most cases the oversight committee is provided with progress reports against this
enhancement plan at subsequent meetings.

5.4 Disaster Recovery plan and its evaluation

93% of firms without a robust disaster recovery plan that endures a data breach incident had to
shut down their operations within a year. In contrast, 96% of firms with a reliable disaster
recovery plan were able to outlast attacks These figures demonstrate why it is absolutely critical
for companies to put in place a robust disaster recovery plan.

As firms today increasingly rely on electronic data for everyday operations, the volume of data
and IT infrastructure lost to data breaches continues to grow. Data loss can be damaging to any
business. Yet, it is something that only a few businesses are ready to deal with. One way
companies can be ready and protect themselves from breaches is to establish a disaster recovery
plan (DRP). Companies must develop a disaster recovery plan that can address all kinds of
disasters.

What is a DRP?

A disaster recovery plan is an official document conceived by a firm that comprises exhaustive
guidelines on ways to respond to unforeseen incidents such as cyberattacks, power outages,
and any other disruptive incidents. The plan includes approaches on curtailing the effects of an
infringement, so a firm can continue their operations or quickly resume after a disruption.

Lengthy disruptions can lead to revenue loss, damage to the brand, and unhappy customers.
The longer the recovery time, the bigger the unfavourable business impact. Consequently, a
good disaster recovery plan must facilitate rapid recovery, irrespective of the source of the
disruption.

For Private Circulation Only 121


An idea disaster recovery plan outlines a disaster recovery solution that includes processes,
business assets, business partners, infrastructure, human resources, and more in the aftermath
of a disaster. The disaster recovery plan must be hinged on business impact analysis, risk
assessment, and Incidence Response Plan that classifies and collects data about critical business
operations, their comparative positioning, susceptibility assessments, attack behaviours, and
likely response and recovery plan

The importance of Testing DRP

The objective of testing a disaster recovery plan is to understand the shortcomings within the
plan. By testing a plan, it is possible to find quick solutions before they deteriorate and disrupt
the ability to re-establish key business operations. It is extremely important that businesses test
their disaster recovery plan so that they can be well-equipped to cope with any incident that
may impinge on critical business processes.

Likewise, DR testing is essential for managed service providers. Testing disaster recovery plan
also boosts their capacity to respond to and recuperate from different breaches, irrespective of
whether it is a human-made disaster, a communication breakdown or even a natural disaster.
DR testing validates a disaster recovery program and business continuity.

Also, it is not sufficient to test a disaster recovery plan once in a while. Regular testing is the
surest way to guarantee that the IT disaster recovery team or the cyberattack recovery team can
restore customer operations immediately after a catastrophe. Companies today can outsource
the task of testing the suitability and efficacy of an IT disaster recovery plan.

Testing A Disaster Recovery plan

There are several steps that can be taken to test a disaster recovery plan. A simple walkthrough
to assess process flow with disaster drills and simulations can help in testing the efficacy of the
plan. To establish efficient strategies, situations are manifested to quickly manage the disaster.
Here is a checklist to testing a disaster recovery plan:

 Offer a detailed DR testing plan when trying to get authorization and aid to run tests.

 Identify goals, procedures, and the things that you seek in the post-testing assessments.

 Form a test team that include SMEs and make sure each person is available for the
scheduled date of testing.

For Private Circulation Only 122


 Find out what needs to be tested, for instance, employee notification system, or the
backup and recovery system.

 Meticulously document and be ready to revise your DR plan and DR testing scripts.

 Evaluate and verify that all code in test scripts is correct.

 Incorporate all pertinent tech components and procedures being tested, no matter how
insignificant.

 Make sure the test ecosystem is ready, available and will have no effect on production
systems before commencing. Ensure testing does not clash with other activities.

 Plan a DR test that will take hours, far in advance; inform other IT supervisors of the
approaching test.

 Carry out a dry run before the disaster recovery test goes live to unearth and resolve
potential obstacles.

 Halt and assess the test when problems arise. Resume if the issue can be circumvented;
postpone if needed.

 Appoint a timekeeper to record start and end times and a transcriber to help with the
test's after-action report, which illustrates what transpired during the test, what did and
did not work and what has been understood.

 Update disaster recovery and BCP and other documents based on what has been
understood from the DR test.

These measures can halt business activities. To avoid any hindrance to your daily operations,
non-critical business units must be shut down temporarily while testing is conducted. If an
extensive test is carried out, all functions would be interrupted.

Extensive tests are the best as all processes can entirely be tested in case of an incident.
Disasters can affect the whole infrastructure. Moreover, such tests can help in establishing
whether or not a firm will recuperate from a disaster or not. Disaster recovery testing will test
a company’s strategy and prepare them on simulated scenarios. Triumphs and failures must be
documented including any lessons learned during this process. Testing exercises for disasters
must be carried out to stay updated and refreshed

For Private Circulation Only 123


Frequency of Testing a DRP

A disaster recovery plan must be evaluated, examined, and reorganized at least once every
year. Every time there are major changes made to recovery tactics, human resources, operating
software, and IT infrastructure, a business continuity and disaster recovery test must be
conducted.

Frequency of the tests depends on the type of business plan being analysed. A disaster recovery
plan entails the management of activities between multi-layered technology configurations and
vendor partnerships. The suggestion for DRP testing is every year, but because of the
inclusiveness of a business continuity plan, more frequent testing is essential.

There are BCP and DRP training course to help people become more familiar with the nitty-
gritty of disaster recovery testing. Also, there are vendors who offer business continuity
management certifications to help conduct sufficient DR testing.

After the testing stage of a disaster recovery and business continuity plan, a business can
interpret what worked and what did not. All that did not work can be examined to see what can
be enhanced so that the process can be altered in favor of the business. The MetricStream
Business Continuity Management Product enables an integrated approach to business continuity
management processes with abilities to simplify workflows, automate metric computations,
and integrate BCM activities.

As organizations rely more on technology and electronic data for their daily operations, the
amount of data and information technology infrastructure lost to disasters appears to be
increasing. Organizations are estimated to lose revenue and incur expenses every year due to
disasters, unpreparedness, and lost productivity. Measures must be taken to protect your
organization from disasters.

One way your organization can prepare and protect itself from disasters is to create and
implement a disaster recovery plan (DRP). Organizations should create a disaster recovery plan
that can address any type of disaster. The plan should be easy to follow and understand, and be
customized to meet the unique needs of the organization. Typical elements in a disaster
recovery plan include the following

For Private Circulation Only 124


Five elements of DRP

1. Create a disaster recovery team. The team will be responsible for developing,
implementing, and maintaining the DRP. A DRP should identify the team members, define
each member’s responsibilities, and provide their contact information. The DRP should also
identify who should be contacted in the event of a disaster or emergency. All employees should
be informed of and understand the DRP and their responsibility if a disaster occurs.

2. Identify and assess disaster risks. Your disaster recovery team should identify and assess
the risks to your organization. This step should include items related to natural disasters, man-
made emergencies, and technology related incidents. This will assist the team in identifying
the recovery strategies and resources required to recover from disasters within a predetermined
and acceptable time frame.

3. Determine critical applications, documents, and resources. The organization must


evaluate its business processes to determine which are critical to the operations of the
organization. The plan should focus on short-term survivability, such as generating cash flows
and revenues, rather than on a long term solution of restoring the organization’s full functioning
capacity. However, the organization must recognize that there are some processes that should
not be delayed if possible. One example of a critical process is the processing of payroll.

4. Specify backup and off-site storage procedures. These procedures should identify what
to back up, by whom, how to perform the backup, location of backup and how frequently
backups should occur. All critical applications, equipment, and documents should be backed
up. Documents that you should consider backing up are the latest financial statements, tax
returns, a current list of employees and their contact information, inventory records, customer
and vendor listings. Critical supplies required for daily operations, such as checks and purchase
orders, as well as a copy of the DRP, should be stored at an off-site location.

5. Test and maintain the DRP. Disaster recovery planning is a continual process as risks of
disasters and emergencies are always changing. It is recommended that the organization
routinely test the DRP to evaluate the procedures documented in the plan for effectiveness and
appropriateness. The recovery team should regularly update the DRP to accommodate for
changes in business processes, technology, and evolving disaster risks

For Private Circulation Only 125


Outcomes of Risk management strategies and its evaluation

In summary, an organization must develop a recovery team to create a disaster recovery plan
that includes identifying and assessing disaster risks, determining critical applications, and
specifying backup procedures. Other procedures may be included in the plan based on the
organization. The recovery team and organization must then implement the DRP and follow
through on the plan procedures. The DRP should be continually tested and maintained to
consistently prepare the organization for evolving disasters and emergencies

As disaster and emergency managers, we always have to plan for the unexpected. In this regard,
it is always important to understand what a disaster is and what qualifies as a hazard in order
to react accordingly. A low magnitude earthquake in the East African region in 2019 was a
natural hazard but it was not a disaster. The intensity of the earthquake was very low and did
not have any impact on people or property. In contrast, the cyclone Udai in Zimbabwe and
Mozambique, a natural hazard escalated into a disaster with high loss of life and property.

Disasters and emergencies happen after an interaction between a hazard and a vulnerable
population that disrupts lives and communities. Due to this, we always evaluate disasters in
terms of their intensity, location, scale, and the extent to which they are human-made or
‘natural’ and the vulnerability of the population affected. Of key importance, after a disaster,
the efficiency of the after response is usually critical to the recovery of the affected community.

When the response is well coordinated and touches on the key needs of the community focusing
on rebuilding with locally available resources the population bounces back fast. Our task, as
we focus on quick disaster recovery, is to find the most efficient manner to hand a disaster and
it’s aftermath. For this to be possible, Monitoring and Evaluation plays a key role in the process.

Monitoring and evaluation (M&E) as a process provides key:

 guidance on future intervention activities;

 information on what an intervention is doing, how well it is performing and whether it


is achieving its aims and objectives

M&E can be classified as an essential part of accountability to stakeholders and funding


agencies. Therefore it’s necessary to plan for Monitoring and Evaluation to be done at the

For Private Circulation Only 126


beginning of an intervention development process. Monitoring is the regular collection of
information about all project activities. It shows whether things are going according to plan
and helps project managers to identify and solve problems and or issues identified in a prompt
manner.

On the other hand, Evaluation seeks to determine whether a project is achieving what it set out
to do and whether it is making a previously projected impact. If the set objective is being
achieved, the evaluation seeks to understand how and why the intervention has worked so well.
If the project is unsuccessful, questions are raised as to what could have been done better or
differently. Evaluations’ main purpose is to keep track of key outcomes and impacts related to
the different project components, assessing whether the objectives, aims and goals are being
achieved.

As an ongoing process, we engage in Monitoring throughout an intervention while evaluations


take place at specific times during interventions. It is common to start with baseline research
towards the beginning of an intervention so as to obtain information with which subsequent
changes can be compared. Further evaluations are usually done at intervals in between the
intervention processes.

In disaster recovery, we need a Monitoring and Evaluation Framework to ensure the programs
being implemented are evaluated to gauge their effectiveness. By improving the quality of
evaluations, it makes it possible to improve subsequent disaster recovery programs. The
learning we obtain from these evaluations is incorporated into program design and delivery.

Therefore, disaster recovery is a set of activities deployed to achieve the desired recovery
objective and outcome after the occurrence of a disaster. In most cases, the sets of program are
above and beyond usual services that government provides to the same community while not
affected with disaster. For us, the main focus of this program is bringing back the community
where they can continue to process on their own.

Monitoring disaster recovery

We define disaster recovery as a continuous and interactive process through which programs
are custom-made since the affected community needs evolve and the impact of the disaster
changes in scope and intensity. The progress towards sustainability and resilience cannot,
therefore, be captured retrospectively. We have to continuously engage in monitoring of

For Private Circulation Only 127


outcomes, and how programs are delivering those outcomes. Regular and planned monitoring
of disaster recovery outcomes helps ensure:

 Programs are modified to cater to emerging needs

 Available resources can are redirected to other areas of need as earlier targets are
achieved

 An early warning system is set up to identify non-performing programs.

 Progress toward successful recovery is communicated to the community and other


relevant stakeholders

 All the groups involved in the delivery of recovery programs are accountable for their
respective performance.

Monitoring should be followed through with Community Recovery Progress Reports (CRPR).
These reports should be compiled in accordance with a timetable set out in the evaluation plan,
which should occur at least annually, or on a more regular basis in the earlier phases. The CRPR
should include sections that:

 Report on key indicators significant for progress on a particular recovery program

 provide appropriate qualitative assessments of recovery progress

 review key activities performed in the reporting period

 review key activities to be performed by the next reporting period and the expected
outcome to be achieved

 identify where expectations have not been met and discussing why and how best to
approach such in future.

 Report on ways the local community has been involved in the recovery process.

Evaluation of Findings

We engage in Evaluations of recovery programs to determine whether; they contribute to the


improvement of that recovery effort and its successive recovery efforts. In other words, while
evaluations promote accountability, that is funds are not misappropriated and programs are
delivered as planned, they also are important to ensure learning takes place and is used to
improve the overall program (current and subsequent).

For Private Circulation Only 128


Evaluation report findings should be presented in a way that is suitable for the intended
audience particularly if the audience is inclusive of the affected community. A balance needs
to be struck between the accessibility of these findings to the affected communities and to the
broader public, and the need to be sufficiently comprehensive to inform decision-making.

Therefore an evaluation report itself should include:

 A comparison of attained results with other similar recovery programs.

 Biases discovered that could limit the scope of the evaluation

 Alternative results proposal with evaluations on how external factors contributed to the
overall recovery program

 Positive and negative consequences discovered on the cause of the evaluation process

 a discussion of the extent to which the different data collection methods lead to similar
results and a discussion of any differences.

In conclusion

With Monitoring and Evaluation capabilities involvement in the implementation of a disaster


recovery program, frameworks can be developed to build skills needed on matters of speculated
possible disasters. As emergency managers, we tend to limit our plans and exercises in
accordance with our capabilities with the thought of scaling up with regards to a disaster. In all
regards, this a clear set up to fail. With the dynamic nature of disasters, it is becoming
increasingly important to plan for the maximum impact of any disaster.

Monitoring and Evaluation of disaster recovery processes assist in making data models to
predefine a scale-up of your capabilities enabling responders to work with an expectation of
the worst. By doing this (not limiting a disaster to one’s capabilities) it forces us, the recovery
team, to look at alternatives means; we think differently. More importantly, it demands us to
look for solutions that are not merely scaling up current systems or practices. Clearly, through
M&E processes, we are able to change our way of thinking accommodating changing threats.
This is the ultimate objective, and this approach will save the most lives.

For Private Circulation Only 129


5.5 Evaluate outcomes of risk management strategies

A risk management plan can never be perfect. However, the degree of its success depends upon
risk analysis, management policies, planning and activities. A well-defined management plan
can be successful only if risks are properly accessed. And if not, the main objective of risk
management plan itself is defeated. Critical evaluation of a risk management plan at every stage
is very necessary especially at an early stage. It will allow companies to discover the flaws
before it gets into the action. Once you’re through the process, you can address the issues and
then introduce it.

The below mentioned steps can help in analyzing and evaluating a risk management plan:

 Problem Analysis: Keep a note of all the events and activities of a risk management
plan. Check out the problems arising from their implementation and assess if they have
a serious impact on the whole process. Make a note of those that have serious
implications.

 Match the Outcomes of a Risk Management Plans with its Objectives: Ends justify
means. Check if the possible outcomes of a risk management plan are in tandem with
its pre-defined objectives. It plays a vital role in analyzing if the plan in action is perfect.
If it produces desired results, it does not need to be changed. But if it fails to produce
what is required can be a really serious issue. After all, an organization deploys its
resources including time, money and human capital and above all, the main aim of the
organization is also defeated.
 Evaluate If All the Activities in the Plan are Effective: It requires a thorough
investigation of each activity of a risk management plan. Checking out the efficiency
of all the activities and discovering the flaws in their implementation allow you to
analyze the whole plan systematically.
 Evaluate the Business Environment: A thorough study and critical evaluation of
business environment where a risk management plan is to be implemented is essential.
Take time to assess, analyze and decide what exactly is required.
 Make Possible Changes in Faulty Activities: After evaluating the effectiveness and
efficiency of all the activities, try to make possible changes in the action plan to get
desired results. It may be very time consuming but is necessary for successful
implementation of your risk management plan.

For Private Circulation Only 130


 Review the Changed Activities: After making changes in already existing activities
and events of a risk management plan, go for a final review. Try to note down the
possible outcomes of the changed activity and match them with the main objectives of
the risk management plan. Go ahead in case they are in line with them.

BCP - A Superset of DRP

Most Business Continuity projects follow the below steps :-

1. An executive within the organization decides that a business continuity plan is needed.
This might be due to an auditor’s report or the result of a business disruption that was more
financially painful than it would have been if a plan had been in place. Or it could be that an
alert employee realized that a good plan did not exist and brought this to the executive’s
attention. This executive usually becomes the sponsor for the project.

2. The first (and most important) step that the sponsor takes is to select someone to lead the
project. This person is most often called the Business Continuity Manager and is responsible
for the successful completion of the project.

3. The project sponsor and the Business Continuity Manager meet to clearly define the scope
of the project, the project timeline, and expectations. The Business Continuity Manager must
be comfortable that the resources available are adequate to meet all the objectives of the
project.

4. The Business Continuity Manager selects the team that will work together to complete the
project. Both technical and political considerations are important in selecting a team that can
successfully develop a workable business continuity plan.

5. The Business Continuity Manager together with the team now develops the project plan to
be used in managing the project. Tasks are identified and assigned, task duration calculated,
and activities are sequenced as the project plans are developed.

6. The project plans are executed. The Business Continuity Manager oversees the project as
the plan unfolds, keeping everyone focused on completing their tasks and ensuring that
milestones are met and that important stakeholders are kept informed as to the project’s
progress. It is here where the actual continuity plans for the organization are created.

For Private Circulation Only 131


7. Once the business continuity plans have been developed and tested, the Business
Continuity Manager closes the project by making sure that everything was documented
properly and handing the project results over to the individual(s) responsible for keeping the
plan up to date. Each affected department will usually have someone responsible for keeping
their portion of the plan current. A report is also generated for the sponsor recapping the
project and documenting lessons learned.

A project plan organizes the team so members focus their skills on specific actions to get the
job done. This respects their time and brings the project to a prompt,

but successful, solution.

Evolution of business continuity plans

Business continuity planning emerged from disaster recovery planning in the early 1970s.
Financial organizations, such as banks and insurance companies, invested in alternative sites.
Backup tapes were stored at protected sites away from computers. Recovery efforts were
almost always triggered by a fire, flood, storm or other physical devastation. The 1980s saw
the growth of commercial recovery sites offering computer services on a shared basis, but the
emphasis was still only on IT recovery.

The 1990s brought a sharp increase in corporate globalization and the pervasiveness of data
access. Businesses thought beyond disaster recovery and more holistically about the
entire business continuity process. Companies realized that without a thorough business
continuity plan they might lose customers and their competitive advantage. At the same time,
business continuity planning was becoming more complex because it had to consider
application architectures such as distributed applications, distributed processing, distributed
data and hybrid computing environments.

Organizations today are increasingly aware of their vulnerability to cyber attacks that can
cripple a business or permanently destroy its IT systems. Also, digital transformation and
hyper-convergence creates unintended gateways to risks, vulnerabilities, attacks and failures.
Business continuity plans are having to include a cyber resilience strategy that can help a
business withstand disruptive cyber incidents. The plans typically include ways to defend
against those risks, protect critical applications and data and recover from breach or failure in
a controlled, measurable way.

For Private Circulation Only 132


There’s also the issue of exponentially increasing data volumes. Applications such as decision
support, data warehousing, data mining and customer resource management can require
petabyte-size investments in online storage.

Data recovery no longer lends itself to a one-dimensional approach. The complex IT


infrastructure of most installations has exceeded the ability of most shops to respond in the way
they did just a few years ago. Research studies have shown that without proper planning,
businesses that somehow recovered from an immediate disaster event frequently didn’t survive
in the medium term.

Why is a business continuity plan important?

It’s important to have a business continuity plan in place to identify and address resiliency
synchronization between business processes, applications and IT infrastructure. According to
IDC, on average, an infrastructure failure can cost USD $100,000 an hour and a critical
application failure can cost USD $500,000 to USD $1 million per hour.

To withstand and thrive during these many threats, businesses have realized that they need to
do more than create a reliable infrastructure that supports growth and protects data. Companies
are now developing holistic business continuity plans that can keep your business up and
running, protect data, safeguard the brand, retain customers – and ultimately help reduce total
operating costs over the long term. Having a business continuity plan in place can minimize
downtime and achieve sustainable improvements in business continuity, IT disaster recovery,
corporate crisis management capabilities and regulatory compliance.

Yet developing a comprehensive business continuity plan has become more difficult because
systems are increasingly integrated and distributed across hybrid IT environments – creating
potential vulnerabilities. Linking more critical systems together to manage higher expectations
complicates business continuity planning – along with disaster recovery, resiliency, regulatory
compliance and security. When one link in the chain breaks or comes under attack, the impact
can ripple throughout the business. An organization can face revenue loss and eroded customer
trust if it fails to maintain business resiliency while rapidly adapting and responding to risks
and opportunities.

For Private Circulation Only 133


Key features of an effective business continuity plan (BCP)

The components of business continuity are:

 Strategy: Objects that are related to the strategies used by the business to complete
day-to day activities while ensuring continuous operations

 Organization: Objects that are related to the structure, skills, communications and
responsibilities of its employees

 Applications and data: Objects that are related to the software necessary to enable
business operations, as well as the method to provide high availability that is used to
implement that software

 Processes: Objects that are related to the critical business process necessary to run the
business, as well as the IT processes used to ensure smooth operations

 Technology: Objects that are related to the systems, network and industry-specific
technology necessary to enable continuous operations and backups for applications and
data

 Facilities: Objects that are related to providing a disaster recovery site if the primary
site is destroyed

The business continuity plan becomes a source reference at the time of a business continuity
event or crisis and the blueprint for strategy and tactics to deal with the event or crisis.

The following figure illustrates a business continuity planning process used by IBM Global
Technology Services. It’s a closed loop that supports continuing iteration and improvement as
the objective. There are three major sections to the planning process:

 Business prioritization: Identify various risks, threats and vulnerabilities, and


establish priorities.

 Integration into IT: Take the input from business prioritization and perform an overall
business continuity program design.

 Manage: Administer what has been assessed and designed.

For Private Circulation Only 134


BCP Methodology-( RBI publication )

Phase 1: Business Impact Analysis

− Identification of critical businesses, owned and shared resources with supporting functions
to come up with the Business Impact Analysis (BIA)

− Formulating Recovery Time Objectives (RTO), based on BIA. It may also be periodically
fine-tuned by bench marking against industry best practices

− Critical and tough assumptions in terms of disaster, so that the framework would be
exhaustive enough to address most stressful situations

− Identification of the Recovery Point Objective (RPO), for data loss for each of the critical
systems and strategy to deal with such data loss

− Alternate procedures during the time systems are not available and estimating resource
requirements

For Private Circulation Only 135


Phase 2: Risk Assessment

− Structured risk assessment based on comprehensive business impact analysis. This


assessment considers all business processes and is not limited to the information processing
facilities.

− Risk management by implementing appropriate strategy/ architecture to attain the bank’s


agreed RTOs and RPOs.

iii) Impact on restoring critical business functions, including customer-facing systems and
payment and settlement systems such as cash disbursements, ATMs, internet banking, or
call centres

Dependency and risk involved in use of external resources and support

Phase 3: Determining Choices and Business Continuity Strategy

• BCP should evolve beyond the information technology realm and must also cover people,
processes and infrastructure

• The methodology should prove for the safety and well-being of people in the branch /
outside location at the time of the disaster.

• Define response actions based on identified classes of disaster.

• To arrive at the selected process resumption plan, one must consider the risk acceptance
for the bank, industry and applicable regulations

Phase 4: Developing and Implementing BCP

• Action plans, i.e.: defined response actions specific to the bank’s processes , practical
manuals( do and don’ts, specific paragraph’s customised to individual business units) and
testing procedures

• Establishing management succession and emergency powers

• Compatibility and co-ordination of contingency plans at both the bank and its service
providers

For Private Circulation Only 136


• The recovery procedure should not compromise on the control environment at the recovery
location

• Having specific contingency plans for each outsourcing arrangement based on the degree of
materiality of the outsourced activity to the bank's business

• Periodic updating to absorb changes in the institution or its service providers. Examples of
situations that might necessitate updating the plans include acquisition of new equipment,
upgradation of the operational systems and changes in:

a) Personnel

b) Addresses or telephone numbers

c) Business strategy

d) Location, facilities and resources

e) Legislation

f) Contractors, suppliers and key customers

g) Processes–new or withdrawn ones

h) Risk (operational and financial

Key factors in BCP design

Following factors should be considered while designing the BCP:

• Probability of unplanned events, including natural or man-made disasters, earthquakes,


fire, hurricanes or bio-chemical disaster

• Security threats

• Increasing infrastructure and application interdependencies

• Regulatory and compliance requirements, which are growing increasingly complex

• Failure of key third party arrangements

• Globalisation and the challenges of operating in multiple countries.

For Private Circulation Only 137


References:

1. Institute of Leadership and Management (IoL&M) study material


2. ICAI risk management study material
3. The Institute of Risk Management: Risk culture Under the Microscope Guidance for
Boards

4. Hampton , John –Fundamentals of Enterprise Risk Management –Second Edition-American


Management Association (2015)
5. [Link]

[Link]

6. Chapter -7 – Business Continuity planning -Report of the working group on Electronic


Banking – RBI publication

7. Sabharwal, M., & Swarup, A. (2012). The implementation of disaster management by Indian
banks. International Journal on Arts, management and humanities, 1(1), 73-80. T

8. Wallace, Michael and Webber Lawrence, - the disaster recovery handbook, third edition,
Amacom publications

9. Disaster Recovery – Best practices – CISCO –white-paper

10. Disaster recovery and Business Continuity plan – Grant Thorton publication

11. Disaster recovery – Best Practices by Meity – Govt of India


12. Hopkin, Paul- Fundamentals of Risk management, understanding, evaluating and
implementing effective risk management -5th edition – IRM publication – Kogan page
13. Business Continuity plan – HDFC
14. Business Continuity plan – SBI
15. Private sector participation in disaster recovery and mitigation –Disaster Recovery Guidance
series – GFDRR and World bank publication

For Private Circulation Only 138


Terminal Questions:

Section –A ( 5 marks)

1) List out the different phases of a Risk management plan.


2) Prepare a checklist to testing a disaster recovery plan
3) Explain the importance of a BCP
4) Explain the 4th Phase of Developing and implementing a BCP
5) Enumerate the key factors involved in a BCP plan design
6) Illustrate the importance of Business Impact Analysis in a BCP plan
Section B (9 marks)
1. Elaborate on Resourcing and managing Risk management strategies.
2. Explain Framework for Evaluating Risk Management strategy along with Y
model.
3. Discuss on importance of Testing DRP and checklist for testing DRP
4. Elaborate on Evaluation outcomes of risk management strategies

Section –C ( 12 marks)

1. Explain the key guidelines for Risk communication. Examine the reasons for its
importance
2. Examine the four phases of assessing the effectiveness of Risk Management plan and
its importance with examples.
3. Enumerate the key features of a Business Continuity plan , with s suitable example
from any organization you know of .
4. Explain the importance of testing of a DRP, and the frequency of testing a DRP an
organization.

For Private Circulation Only 139


Model question paper

Strategic Risk Manager Total marks: 50


Section A
Answer any four of the following questions. (5 marks)
1. State the relationship between risk and stakeholder and shareholder perception.
2. Define Risk appetite and list out its key elements.

3. State the advantages of adopting a Risk Management Standard.


4. List out any four sources of Risk identification
5. List out the different phases of a Risk management plan.

Section –B
Answer any two of the following questions. ( 9 marks)

1. Explain financial risk and market risk.


2. Explain the ten basic indicators of matured risk culture in organizations with examples you
know of.
3. Briefly name the four types of compliance risks and give example of any two risks

Section –C
Answer the following question. ( 12 marks)

1. Explain COSO ERM Framework along with components in detail.

For Private Circulation Only 140

You might also like