Strategic Risk Management Study Material
Strategic Risk Management Study Material
PROGRAM: BMS
Semester – VI
STUDY MATERIAL
2023
Course Objective: -
1. To develop an understanding of risk and the types of risk faced by an organization.
2. To demonstrate an understanding of terms such as risk appetite, risk attitude and risk culture
in an organizational context.
3. To understand the concept and process involved in Enterprise risk management, importance
of risk identification, risk assessment, risk response and risk monitoring.
Hours
Module 1 : Risk Management
Explain Risk appetite and identify the factors influencing risk appetite. Explain risk
attitude, risk environment, risk awareness and risk culture. Explain and assess the role
of a risk manager in identifying and monitoring risk. Explain and evaluate the role of
the risk committee in identifying and monitoring risk. Describe and assess the role of
internal or external risk auditing in monitoring risk. 12
Explain Enterprise Risk Management. Analyse the ERM approach and the components
of COSO framework for ERM. Evaluate the COSO framework. Describe and evaluate
other ERM frameworks such as the Management of Risk framework, CoCo Model, 12
The GRC capability model - Open Compliance & Ethics Group (OCEG). Explain IS0
31000:2009 standards and the pros and cons.
Module 4: Strategic Risk Management III
Explain the methods of risk identification. Explain and analyse the concepts of
assessing the severity and probability of risk events. Describe the various risk
management strategies. Explain Controlling and Monitoring Risk. 12
3. The Institute of Risk Management: Risk culture Under the Microscope Guidance
for Boards
4. Hopkins, Paul - Fundamentals of Risk Management ( 5th edition)(Chapter -1 )
[Link]
5. Roberts, Alexander, Wallace William et al, -( publication of Heriott watt university
– 2012 ) –Strategic Risk Management
6. Coso guidance - Risk appetite to Success, COSO publication May 2020
7. Muller Robert.R, Coso enterprise risk management, second edition , wiley finance,
Enterprise risk management Coso -Oct 2019
Course BLOOMS
TAXANOMY
Outcomes
(CO)
CO1 Identify the key principles and concepts of risk management in an Understanding (2)
organization.
Recognize the role of a risk manager and articulate the concepts of Understanding (2)
CO2 risk appetite, risk attitude and risk culture in an organizational context.
Employ various ERM frameworks to make informed decisions and Applying (3)
CO3 contribute to enhancing risk management practices.
Interpret the severity and probability scores of risk events the Applying (3)
CO4 organization is Exposed to.
CO5 Employ various ERM frameworks to make informed decisions and Analyze (4)
contribute to enhancing risk management practices.
Module Page
No.
5-24
Module – 1 : RISK MANAGEMENT
25-52
Module – 2 : STRATEGIC RISK MANAGEMENT I
53-75
Module – 3 : STRATEGIC RISK MANAGEMENT II
76-104
Module – 4 : STRATEGIC RISK MANAGEMENT III
Risk Management
Structure
1.1 Introduction to Risk Management
1.2 Definition or Meaning
1.3 Objective and process of Risk Management
1.4 Risk and Uncertainty
1.5 Types of Risk
1.6 Financial Risk
1.7 Market Risk
1.8 Operational Risk and Project Risk
1.9 Environmental Risk
1.10 Strategic Risk
1.11 Importance of strategic Risk
1.12 Managing Strategic Risk
1.1 Introduction
Risk management is the process of identifying, assessing and controlling threats to an
organization's capital and earnings. These risks stem from a variety of sources including
financial uncertainties, legal liabilities, technology issues, strategic management errors,
accidents and natural disasters. Financial risks can be quantified using statistical tools to
generate a probability distribution of profits and losses. Risk that can be measured can be
managed better. The term “Risk” as a noun means a situation involving exposure or danger
and as a verb means expose to danger, harm or loss. It is said that the word Risk is derived
from the early Italian word “risco” which means danger or “risicare,” which means “to dare”
or French word “risqué”. Risk is known or unknown but is always inherent in individual or
business actions therefore it is more of a “choice” rather than a faie accompli.
Risk and reward are two sides of the same coin. Good Risk leaders select their actions well
or take calculated risks. They evaluate risks carefully and take actions with full cognizance
of consequences. They integrate decisions with corporate strategy, and strike a healthy
balance between risk management as an opportunity and a protection shield. The modern
terms for managing risk rose after World War II, but the discipline mostly began as a study
of using insurance to manage risk. Later, from the 1950s to the 1970s, risk managers began
to realize that it was too expensive to manage every risk with insurance, so the discipline
began to expand to alternatives to insurance. For example, training and safety programs might
Each strategy and business action is accompanied with its expected risk and reward. Good risk
management therefore does not imply avoiding all actions and associated, rather it implies
making informed and coherent choices. The risks that the organization wants to take in pursuit
of its objectives and in particular choices it makes to manage and mitigate those risks.
Risk management is a central part of any organization's strategic management. It is the process
whereby organizations methodically address the risks attaching to their activities with the goal
of achieving sustained benefit within each activity and across the portfolio of all activities. Risk
management should be a continuous and developing process which runs throughout the
organization's strategy and the implementation of that strategy. It should address methodically
all the risks surrounding the organization's activities past, present and in particular, future. It
must be integrated into the culture of the organization with an effective policy and a programme
led by the most senior management. It must translate the strategy into tactical and operational
objectives, assigning responsibility throughout the organization with each manager and
employee responsible for the management of risk as part of their job description. It supports
accountability, performance measurement and reward, thus promoting operational efficiency
at all levels.
According to Warren Buffett –Risk comes from not knowing what you are doing. Risk
management is about people and processes and not about models and technology.
Again the CFA Institute practical risk management guide defines risk management as Risk
management is the art of using lessons from the past to mitigate misfortune and exploit future
opportunities—in other words, the art of avoiding the stupid mistakes of yesterday while
recognizing that nature can always create new ways for things to go wrong.
We cannot lose sight of the most important aspect of risk management— managing risk. That
means making the tactical and strategic decisions to control those risks that should be
controlled and to exploit those opportunities that should be exploited. Managing risk cannot be
divorced from managing profits; modern portfolio theory tells us that investment decisions are
the result of trading off return for risk, and managing risk is simply part of managing returns
and profits. Managing risk must be a core competence for any financial firm. The ability to
effectively manage. risk is the single most important characteristic separating financial firms
Develop a common understanding of risk across multiple functions and business units
so as to manage risk cost-effectively on an enterprise wide basis.
Achieve a better understanding of risk for competitive advantage.
Build safeguards against earnings-related surprises.
Build and improve capabilities to respond effectively to low probability, critical,
catastrophic risks.
Achieve cost savings through better management of internal resources and allocate
capital more efficiently.
A business event if it occurs; can have a positive or negative impact on business’s objectives.
Generally, when we discuss risks we fall into the trap of thinking that risks have inherently
negative dimension. However, one should be open to those risks that create positive
opportunities; you can make your business faster, better and more profitable. Let us look at an
example here say on account of non-compliance with environmental laws few old suppliers of
a Corporate entity were restricted from supplying materials to the Corporate entity at preferred
rates. This posed a challenge to the corporate entity as they have to find new suppliers who
would be compliant with environment laws and also perhaps the new rates would be
significantly higher than the preferred rates of the old suppliers. The Corporate entity
undertakes a detailed supplier discovery exercise and realizes that the new suppliers are willing
to supply materials at rates that are lower than the preferred rates (agreed with their old
suppliers), thus a potential challenge or threat has been converted into an opportunity to reduce
the Corporate entity’s procurement spend. Think of the adage – “Accept the inevitable and turn
it to your advantage.” That is what you do when you take business risks to create opportunities.
In our day to day life, there are many circumstances, where we have to take risks, which
involves exposure to lose or danger. Risk can be understood as the potential of loss. It is not
exactly same as uncertainty, which implies the absence of certainty of the outcome in a
particular situation. There are instances, wherein uncertainty is inherent, with respect to the
forthcoming events, i.e. there is no idea, of what can happen next. So, in short, risk describes
a situation, in which there is a chance of loss or danger. Conversely, uncertainty refers to a
condition where you are not sure about the future outcomes.
In the ordinary sense, the risk is the outcome of an action taken or not taken, in a particular
situation which may result in loss or gain. It is termed as a chance or loss or exposure to danger,
arising out of internal or external factors, that can be minimised through preventive measures.
In the financial glossary, the meaning of risk is not much different. It implies the uncertainty
regarding the expected returns on the investments made i.e. the probability of actual returns
may not be equal to the expected returns. Such a risk may include the probability of losing the
part or whole investment. Although the higher the risk, the higher is the expectation of returns,
because investors are paid off for the additional risk they take on their investments. The major
elements of risk are defined as below:
Systematic Risk: Interest Risk, Inflation Risk, Market Risk, etc.
Unsystematic Risk: Business Risk and Financial Risk
By the term uncertainty, we mean the absence of certainty or something which is not known.
It refers to a situation where there are multiple alternatives resulting in a specific outcome, but
the probability of the outcome is not certain. This is because of insufficient information or
knowledge about the present condition. Hence, it is hard to define or predict the future outcome
or events.
Uncertainty cannot be measured in quantitative terms through past models. Therefore,
probabilities cannot be applied to the potential outcomes, because the probabilities are
unknown.
Since uncertainty cannot be controlled or estimated, we resort to insurance for the same and
examples are crop insurance, natural disaster like floods, storm, fire, and earthquake, tornado
insurances being taken by corporates.
In his seminal work Risk, Uncertainty, and Profit, Frank Knight (1921) established the
distinction between risk and uncertainty.
Uncertainty must be taken in a sense radically distinct from the familiar notion of Risk, from
which it has never been properly separated. The term "risk," as loosely used in everyday speech
and in economic discussion, really covers two things which, functionally at least, in their causal
relations to the phenomena of economic organization, are categorically different. The essential
fact is that "risk" means in some cases a quantity susceptible of measurement, while at other
times it is something distinctly not of this character; and there are far-reaching and crucial
differences in the bearings of the phenomenon depending on which of the two is really present
and operating. It will appear that a measurable uncertainty, or "risk" proper, as we shall use the
term, is so far different from an immeasurable one that it is not in effect an uncertainty at all.
We accordingly restrict the term "uncertainty" to cases of the non-quantitative type.
Thus, Knightian uncertainty is immeasurable, not possible to calculate, while in the Knightian
sense risk is measurable
Fundamental Risks are impersonal in nature. They are present in nature and the economy,
and are beyond the control of man. Their effect is pervasive and usually impacts a large group
of people. Earthquakes, war, inflation, mass unemployment, etc., are examples of such
fundamental risks. Generally, these risks are not insurable and it is left to the Government to
deal with the effects of these events. However, in situations where the occurrences are irregular
and the impact in minimal, the insurers can venture to insure these risks.
Particular Risks have their origin in individual events which can be partially controlled. They
occur due to the action of the individuals, for example, meeting with an accident while crossing
the road. These risks are insurable with conditions.
Dynamic Risks may arise due to changes in the economy like fluctuations in price levels,
consumer references, distribution of income, product development, shifts in technology, etc.
These are called Dynamic Risks. As they are less predictable, generally, they are not insurable.
Control risks are associated with unknown and unexpected events. They are sometimes
referred to as uncertainty risks and they can be extremely difficult to quantify. Control risks
are often associated with project management. In these circumstances, it is known that the
events will occur, but the precise consequences of those events are difficult to predict and
control. Therefore, the approach is based on minimizing the potential consequences of these
events.
Risks are also caused due to two factors – Internal and External and further can be divided into
controllable and uncontrollable factors as per table below
Uncontrollable Uncontrollable
Accidents Economic Recession or boom
People exiting organization Floods, Earthquake
Frauds Market /Environment
Technology changes
Credit risk - The risk of loss arising from outright default due to the inability or
unwillingness of the customer or counterparty to meet their commitments. Credit risk is the
probability of loss from a credit transaction. It is also called as default risk.
Liquidity risk - The potential inability to meet commitments as they fall due. It arises
whenever the bank is unable to generate cash to meet out its liability payment obligations or
increase in assets or its failure to manage the unplanned decreases or changes in the funding
sources. Liquidity risk also arises on account of its failure to address the changes in the
market conditions that affect its ability to liquidate its assets quickly and with minimal
losses. Liquidity risk may arise due to changes or variations in the market conditions such
as, volatility of rate of interest or the Foreign exchange rate /Investment mismatch or risk or
poor economic conditions like depression / inflation / loss of confidence in the business by
its customers/ rumours about the business and its effects of run on the liquidity/ failure of
some of the banks where its deposits got struck or blocked or war like situations with the
enemies of state are some of the examples where the businesses will be facing liquidity crisis
as it may cause heavy outflow of funds.
Operational Risk- The risk associated with the operations of an organization. It is the risk
of loss resulting from failure of people employed in the organization, internal process,
systems or external factors acting upon it to the detriment of the organization. It includes
Legal Risk and excludes strategic and Reputational Risks as they are not quantifiable. It is
the risk of loss due to inadequate monitoring systems, management failure, defective
controls, fraud, and/or human errors. Operational risk is particularly relevant to derivatives
Project risk –Overall project risk is the effect of uncertainty on the project as a whole.
Individual risk is defined as an uncertain event or condition that if it occurs, has a positive or
negative effect on project’s objectives. Project risk is also defined as the exposure of
stakeholders to the consequences of variations in outcome. E.g. BMRCL metro project gets
time extension for metro, comes at a significant additional cost.
Compliance Risk – It includes material financial loss or loss of reputation which may occur
as result of its failure to comply with the laws includes, regulations, rules, related self-
regulatory organization, standards and code of conduct applicable to its business activities.
E.g. failure to comply with GST returns filing on monthly, IT returns and TDS filings,
Annual report filing on timely basis, compliances under various labour laws if not done
properly can be visited with penalties.
Regulatory Risk - Regulatory Risk arises due to changes made in policies and procedures
by the regulators viz, RBI, Central and State Governments, SEBI, IRDA, etc. Withdrawal
of licenses, change in capital adequacy requirements, change in NPA norms etc. may be
grouped under this category. Any changes in the rules and regulations which may have a
negative impact on the business activities can be classified under this risk. E.g. Fines and
regulatory control imposed by RBI on Yes bank and PCMB bank by appointing its own
person as administrator and superseding the erstwhile management.
legislative change, regulations, climate change, natural disasters, loss of business, competition,
economic slowdown and stock market fluctuations. These are outside the organisation’s control
but can be mitigated to some extent through environmental scanning and contingency planning.
Strategic Risk - The current and prospective impact on earnings, capital, reputation or good
standing of an organization arising from its poor business decisions, improper
implementation of decisions or lack of response to industry, economic or technological
changes. Failure of strategies will adversely impact the business objectives and attainment
of the goals. Strategic risks – those that affect or are created by business strategy decisions
– are critical to the growth and performance of an entity’s business. The importance of
strategic risk—particularly given the typical high failure rate of strategic initiatives and
empirical studies that show the impact of strategic risk exceeds the impact of all other forms
of risk combined. measures Measuring strategic risk using economic capital, shareholder value-
added, and other risk adjusted performance. Managing strategic risk through strategic planning,
risk appetite, new business development, mergers and acquisitions (M&A), and capital
management processes. Ongoing monitoring and feedback, including the integration of key
performance indicators, key risk indicators, and performance feedback loops to support board
and management oversight.
Strategic risks may lack historical precedent and/or originate outside an industry. Signals
related to emerging strategic risks are often faint or intermittent, which can make them hard to
detect, easy to dismiss, and difficult to interpret. Traditional tools cannot reliably locate and
analyze them.
In addition, strategic risks may be: -
• Unique to the organization because the strategy, culture, governance structure, and business
and operating models are unique to the organization
• Damaging to the entire organization because a risk involving, say, reputation or the supply
chain in one part of the company may affect other parts
• Easy to overlook because they often seem irrelevant, unthreatening, or highly unlikely—
and management may believe they are being monitored and managed when they are not
• Difficult to address with customary risk management methods
Strategic risks may arise from low-likelihood/high-impact, so-called “black swan” events.
These events can escalate rapidly and render those who have not anticipated them confused,
paralyzed, or prone to mistakes.
Although they may take the form of financial, operational, technological, political, or other
familiar risks, strategic risks tend to be difficult to quantify and track. For example, entire
industries ranging from retail, travel, advertising and entertainment have seen their strategies
essentially undone by technological and business model disruption. In particular, emerging
technologies warrant continual monitoring as potential sources of strategic risks—should new
or existing competitors harness them—and a source of opportunities. However, such
technologies challenge conventional risk management methods when their distribution is
uncontrolled and their uses are unanticipated.
Essentially, strategic risks can gum up, delink, or erode drivers of value. If ignored, they can
become what Deloitte has described as “value killers” (see Figure 2 and sidebar: Beware of the
Transforming strategic risk management goes even further. It includes broad and deep risk
analysis, scenario planning, and contingency, resiliency, and recovery plans. It examines risks
generated by a strategy as well as risks to the strategy. It considers potential strategic risks in
decisions related to market entry or expansion, product initiatives, M&A activities,
compensation plans, new hires, and talent management. At the same time, it fosters awareness
of strategic risks across the organization and of potential opportunities that developments may
present to generate value and gain competitive advantage.
• Discover: Employ analytics and human capabilities to identify potential risks and gauge
potential outcomes
Use scenario planning to identify potential impacts
• Apply risk sensing technologies and tools to big data and media feeds
• Analyze signals being tracked
• Prepare: Identify responses that will mitigate impacts or exploit risks for advantage
• Senior leaders manage strategic risks proactively: Senior executives, in concert with the
Chief Risk Officer (CRO), if present, and business-unit leaders, work proactively to identify,
detect, monitor, and address strategic risks. Contingency and response plans are in place, with
specifics such as backup sources of capital identified. Insurance, diversification, hedging, and
other tools are used to mitigate strategic risks. The board and management appropriately
disclose strategic risks and measures taken to address them.
• Transactional and portfolio risks are well understood: Strategic decisions determine the
kinds of transactions the organization will engage in and the portfolios it will construct. While
there are tools for analyzing quantifiable risks in these areas, management realizes that less
quantifiable risks are generally less understood. Therefore, management looks beyond
quantifiable risks to assess all strategic risks.
Regulatory environment is factored into strategy: Regulatory issues are considered in the
business strategy, as are issues of talent, organizational culture, and risk governance resources.
In addition, strategic flexibility enables the organization to adapt its strategy as regulations
evolve.
Monitor strategic risks at all levels: Although strategic risks are owned at the C-suite and
board level, risk sensing capabilities are needed on the front lines of most business units and
functions.
Protect drivers of value: Given that strategic risks can undermine drivers of value,
management should use specific methods appropriate for the organization to identify threats to
those drivers
Develop strategic flexibility: In a rapidly changing environment, the ability to modify a
strategy or adopt an alternative one when needed can earn high rewards.
Extend risk management: Risk transformation extends risk management down to the levels
where risks can be identified, tracked, and managed in the businesses and functions.
Go beyond covering regulatory bases: Regulators are driving much of the rationale for
change. This can prompt leaders to see regulatory compliance as the chief priority.
A major oil and gas company was struggling to align its risk function mandate with other risk
and assurance functions to meet management and broader stakeholder expectations. Deloitte
worked with the key governance, risk, and assurance functions to develop an integrated
strategy, mandate, and operating model to ensure delivery of the risk strategy and to embed
sound risk practices across the organization.
This involved:
• Assessing and aligning the risk function and the broader governance, risk, and compliance
(GRC) operating models
• Aligning the risk function and GRC operating model with stakeholder expectations
• Designing risk processes and assurance processes and functions, including governance,
regulatory compliance, legal, ethics, forensics, and internal audit functions
Strategic risk can be defined as any risk that affects or is inherent in a company’s business
strategy, strategic objectives, and strategy execution. The list includes: • Consumer demand •
Legal and regulatory change • Competitive pressure • Merger integration • Technology change
• Senior management turnover • Stakeholder pressure. Other risks may qualify for particular
companies depending on the nature of their business. Siemens, the European conglomerate,
captures this sentiment in its broad definition of strategic risk: “everything, every obstacle,
every issue that has the potential to materially affect the achievement of our strategic
objectives.
While reliable statistics are difficult to come by, it is no secret that many strategic initiatives
fall short of expectations. The oft-quoted 70% failure rate enshrined in management lore may
lack empirical support. But high success rates are still the exception rather than the rule. In
2008, John Kotter, a leading expert in change management, summed up his experience: He
says -From years of study, I estimate today more than 70% of needed change either fails to be
launched, even though some people clearly see the need, fails to be completed, even though
some people exhaust themselves trying, or finishes over budget, late, and with initial
aspirations unmet. Whatever the true failure rate for strategic initiatives, companies have every
incentive to improve performance by increasing the likelihood that they will achieve strategic
goals at least in some measure.
Companies ignore strategic risks at their peril. Independent studies of the largest public
companies have shown time and again that strategic risks account for approximately 60% of
major declines in market capitalization, followed by operational risks (about 30%) and
financial risks (about 10%). Yet, in practice, many ERM programs downplay strategic risks or
ignore them entirely. There are some historical reasons for that. When companies began to
develop formal ERM programs in the early 1990s, they focused almost exclusively on financial
risk, due to some high-profile losses stemming from derivatives and the fact that financial risk
(i.e., interest rate risk, market risk, credit and counter party risk, and liquidity risk) is more
quantifiable.
Strategic risk management addresses the question of what specific decisions and actions are
required to optimize the long-term risk-return profile of the company. Key decision points
include:
• Risk acceptance or avoidance: The organization can decide to increase or decrease a specific
risk exposure through organic growth, its core business (new product and business
development), mergers and acquisitions (M&A), and financial activities.
• Risk-based pricing: All organizations take risks in order to be in business, but there is only
one point at which they can get compensated for the risks that they take. That is in the pricing
of their products and/or services, which should fully incorporate the cost of risk.
• Risk transfer: If risk exposures are excessive and/or the cost of risk transfer is lower than
the cost of risk retention, an organization can decide to execute risk transfer strategies through
the insurance or capital markets.
• Resource allocation: An organization can allocate human and financial resources to business
activities that produce the highest risk-adjusted returns in order to maximize firm value.
Risk management is an ongoing process, and strategic risk is no exception. Though it presents
its own particular challenges, monitoring strategic risk can give companies a critical “heads-
up” to oncoming obstacles. This, in turn, offers the greatest possible latitude when it comes to
adjusting strategic or tactical efforts in order to mitigate downside risk or take advantage of an
unexpected opportunity.
Strategic risk can result throughout the strategy development and execution processes,
including:
• Design and development of the corporate strategy, including alignment with the core mission,
business-unit strategies, and operating budgets;
• Actions and reactions from customers, suppliers, and competitors, as well as the impact of
emerging technologies; and
• Resultant risks (which can be strategic, operational, or financial risks) from the execution of
corporate and business-unit strategies, including the utilization of risk appetite and risk capacity
Conclusion
The organization has many stakeholders and their perceptions of each are quite different.
The different stakeholders can be classified as follows: -
1. Shareholders- Represent owners of the entity or the promoters. They are contributing
funds to the corporate for start-up and growth, and would need to be appraised of the
current situation of risk and perceptions in the organisational policies. If not suitable
they may exit the company by withdrawing the investments. If investments are made
in areas where the risk is going to be very high they need to be advised in advance and
necessary approval may have to be taken. Otherwise the project or investment will
likely find resistance at a later stage when approvals are sought from shareholders. They
have the power as a owner and this may likely create issues for the company, and affect
its overall operations and possibly growth options too.
2. Employees/ workers- Represent key internal stakeholders who will have to take along
as they have a high stake in the organisation if too high a risk is taken they may not like
to continue
3. Customers – They are the key to success or failure of enterprise. Their perception is
mostly valued and crucial for organisations.
Terminal questions:
Section A: 5 marks
1. Discuss the objectives and Process of Risk management.
2. State Difference between sheet between risk and uncertainty.
3. Explain types of risk in detail.
4. Discuss about strategic risk.
5. State the relationship between risk and stakeholder and shareholder perception.
Section B 9 marks
1. Explain financial risk and market risk.
2. Discuss the need of necessary shift in perspective with regarding to strategic risk.
Section C 12 marks
1. Discuss the importance of strategic risk and managing the strategic risk.
Reference Books:
Structure
2.1 Introduction
Risk appetite is a vitally important concept in the practice of risk management. However, it is
a very difficult concept to precisely define and apply in practice. Risk appetite is sometimes
considered to be defined by the risk criteria established by the organization. The risk appetite
or risk criteria are important components in the risk ranking phase of the risk management
process. This is the next phase of the risk management process after the risks have been rated
in terms of likelihood and impact. Risk appetite is the immediate or short-term willingness of
an organization to undertake an activity that involves risk. Risk attitude and the risk criteria
represent a longer-term view of risk in the same way as a person will have an immediate
appetite for food and a longer-term attitude towards food.
One of the fundamental difficulties with the concept of risk appetite is that, generally speaking,
organizations will have an appetite to continue a particular operation, embark on a project or
take risk (risk capacity). A range of definitions of risk appetite is shown in Table 25.1 and it is
obvious that different professional bodies have produced very similar definitions of risk
appetite. - Organisation Definition of Risk Appetite-
2.2 Risk Appetite can vary based on a number of factors such as-
a) Industry- Certain industries are more likely to be capable of taking higher risks like IT,
Technology etc. On the contrary entities in manufacturing typically tend to be conservative in
their approach
b) Company culture – Companies in certain culture have more risk taking abilities as
compared to others. For e.g. German companies are more risk conscious and follow a
systematic approach to risk, as compared to other European Entities, while US based
companies are more oriented towards risk seeking. In the Indian context the Reliance group,
Adani Group is said to be having higher risk appetite as compared to others like Godrej,
Piramal, Tatas etc.
c) Nature of objective to be pursued – It is a very vital aspect of risk appetite and can vary
across organisations. It is difficult for an entity to take a high risk in an area having sensitive
consumers or values which are ingrained into society or value and belief system.
e) Competitors – If the sector is one where competitors are highly active and taking risks, the
entity in that sector too will have to possess higher appetite, as otherwise survival chances are
low. Competition thus becomes a key factor in the process.
f) Portfolio size - The bigger the portfolio, the greater the risk appetite. An investor with a $50
million portfolio may take on greater risk than an individual with a $5 million portfolio. If the
value of the portfolio falls, the percentage loss is significantly lower in a bigger portfolio than
in a smaller portfolio.
g) Comfort level - Each investor approaches to risk in a unique way. Some investors are
inherently more willing to take risks than others. Market volatility on the other hand, may be
exceedingly distressing for certain investors. As a result, risk appetite is closely tied to how
comfortable an investor is with taking risks.
Risk Attitude -The terms risk attitude, appetite, and tolerance are often used similarly to
describe an organization's or individual's attitude towards risk-taking. One's attitude may be
described as risk- averse, risk-neutral, or risk-seeking. Risk attitude is the chosen position
adopted by an individual or group towards risk, influenced by risk perception and pre-
disposition.
Risk –Culture -An effective risk culture is one that enables and rewards individuals and groups
for taking the right risks in an informed manner. Risk culture is the values, beliefs,
knowledge and understanding about risk, shared by a group of people with a common intended
purpose, in particular the leadership and employees of an organisation A successful risk culture
would include the following: -
a) A distinct and consistent tone from the top from the board and senior management in
respect of risk taking and avoidance (and also consideration of tone at all levels).
Sufficient diversity of perspectives, values and beliefs to ensure that the status quo is
consistently and rigorously challenged.
In the past cases like Enron,Libor Manipulation, Space shuttle disaster , were absent in
these features. Alignment of culture management with employee engagement and
people strategy to ensure that people are supportive socially but also strongly focused
on the task in hand.
The ten basic indicators of risk culture that would be displayed in a risk mature organization
can be listed as follows: -
diagnostic tools available that can be used to indicate and then track the risk culture in an
organisation. The mix of tools and the order of their deployment will depend on the context
We set out the details of the models, tools and approaches that we have found useful in our
companion document.
IRM has defined a Risk Culture Framework around which to analyse, plan and act to influence
risk culture within any organisation. We look at the effects of predisposition towards risk and
personal ethics in shaping attitudes and behaviours and we look at the role of organisational
cultures.
Figure 1 below attempts to distil what is a complex and interrelated set of relationships into a
simple and high level. approach to looking at the various influences on risk culture. Risk culture
is the sum of multiple interactions. At the lowest level, each individual’s personal
predisposition to risk contributes to their ethical stance, how they behave and make decisions.
Group behaviours and the underlying organisational culture also influence risk culture. There
may be concern that the culture of the organisation is attracting and encouraging individuals
whose inherent ethical stance or risk-taking predisposition may be at odds with the board’s
commitment to high standards of integrity in dealing with all stakeholders. Taxi drivers and
airline pilots are routinely given personality tests to determine how effectively they can exhibit
self-control under stress – we should be ready to look at other key staff, managers and board
members in the same way.
• The extent to which people are either spontaneous and challenge convention or organised,
systematic and compliant;
• The extent to which people may be cautious, pessimistic and anxious, or optimistic, resilient
and fearless. Figure below shows IRM risk Culture framework: -
This model, developed by the IRM, identifies eight aspects of risk culture, grouped into four
themes, key indicators of the ‘health’ of a risk culture: aligned to an organization’s business
model. Diagnosis can be by means of a simple questionnaire or structured interview techniques.
A gap analysis provides pointers to areas of strength and weakness and hence allows
prioritization and focus to be brought to what can be a difficult set of issues to grasp.
The focus is on identifying tangible actions that be taken to address areas of concern,drawing
from a tool kit. The model presupposes a continuous improvement approach where a risk
culture is moved incrementally and performance tracked over time. It is important to recognize
where positive culture cycles need to be reinforced, and vicious cycles broken, to make a step
change improvement.
• Risk skills - the embedding of risk management skills across the organisation
• Appropriate risk taking rewarded and performance management linked to risk taking.
The risk culture aspects model links with the sociability vs. solidarity analysis through planned
action to address deficiencies in the current culture. The interventions required may relate to
driving an increase in the levels of sociability and/or solidarity and pushing the organisation
into a position more conducive to effective risk management. The risk culture aspects model
specifically links the aspects shown in red in the diagram to greater impact on sociability and
the blue aspects to improvements in solidarity.
Risk awareness is the recognition of the potential for hazards, risks, and incidents that occur
within the healthcare environment and result in patient harm. In another word Risk awareness
is the raising of understanding within the population of what risks exist, their potential impacts,
and how they are managed.
Risk awareness and response agility are critical when incidents occur, but reaction times can
be particularly hindered when an organisation has grown too rapidly. This is because in the
process of fast and disparate growth, functions can become siloed, operating autonomously
using different – or non-comparable – reporting programmes. As such, they can’t be governed
and reviewed by the board in the same context. This was one of the key issues that made the
2008 financial crash so severe, with no corporate oversight – and organisations’ strategies
aiming for maximum growth at any cost – individual departments went rogue creating an illicit
black hole in the financial system.
Every executive hopes their company is alert to risks and that they can be resilient when hit
with disaster but with the speed and ferocity of risks ever-increasing, it is not always possible.
In an age where it only takes one employee – or one tweet – to smear the reputation of some
of the largest organisations, efficient and effective risk responses are vital.
To build a risk aware organisation, companies need to invest in risk awareness and management
programmes and work toward creating a transparent corporate culture.
7. Utilise technology
The Role of a Risk Manager varies across from entity to entity, but broadly some of the roles
played by him are as follows; -
Provide a methodology to identify and analyze the financial impact of loss to the
organization, employees, the public, and the environment.
Examine the use of realistic and cost-effective opportunities to balance retention
programs with commercial insurance.
Prepare risk management and insurance budgets and allocate claim costs and premiums
to departments and divisions.
Provide for the establishment and maintenance of records including insurance policies,
claim and loss experience.
Assist in the review of major contracts, proposed facilities, and/or new program
activities for loss and insurance implications.
In cooperation with General Counsel, maintain control over the claims process to assure
that claims are being settled fairly, consistently, and in the best interest of the entity.
A Risk Manager is held accountable for analyzing, assessing, and handling the risks
faced by the organization.
They assist the organizations regarding any sort of risks that might affect the
profitability of the organization and develop strategies and processes for managing
those business risks and ensure successful business continuity.
The foremost task of the Risk Manager is to gather the data and carry out investigations
to recognize the risks that an organization might be exposed to. As a part of the
investigation process, the Risk Managers should analyse key risk indicators (KRI) and
conduct what-if-analyses to determine the concerns if the risks identified in the process
are about to occur. A few of the concerns/consequences include threat/leaking
organization’s confidential information, financial loss, and damage to the
organization’s assets.
Risk Managers are also involved in implementing control systems and action plans for
safeguarding the organization’s assets and resources. This is done through mitigating
risks and potential damage caused.
Should possess awareness of statistical tools and auditing and reporting procedures.
Should possess the ability to execute office automation tools and risk monitoring
and testing procedures.
The Role of Risk manager in Identifying and monitoring risk can be defined as under: -
Organizations and companies typically assemble a risk management team to help decision
makers go through the risk management process. A member of the team is selected as a risk
manager to identify and monitor risks.
The Risk manager must gain an understanding of the environment in which the risks are to be
managed, taking into account political and policy concerns, mission needs, stakeholder
interests, and risk tolerance. He should define the context and will inform and shape successive
stages of the risk management cycle.
8. Identify Potential Risk – The Risk Manager to consider a wide variety of risks to
support decision making. These considerations include strategic, operational, and
institutional risks.
The risks that are included in any particular assessment (sometimes called the assessment’s
scope) are largely determined by the decision the assessment is designed to inform.
Unusual, Unlikely, and Emerging Risks - Prior to conducting a risk assessment, it is important
to make a concerted effort to identify risks beyond those usually considered. For example, risks
that are newly developing, even if they are poorly understood. Risks that are highly unlikely
but have high consequences should also be identified and incorporated into the assessment.
This can even include identifying the risk of the unknown as a possible risk.
Brainstorming is a common technique to identify these unusual, emerging, and rare risks. So,
2 Assess and Analyze Risk – The Risk Manager is also needed to assess the identified risks
and analyze the outputs of the assessment. This step consists of several tasks:
1) - Determining a methodology;
2) - Gathering data;
3) - Executing the methodology;
4) - Validating and verifying the data; and
5) - Analyzing the outputs.
In practice, these tasks, like the steps of the larger risk management cycle, rarely occur linearly.
Instead, risk managers and practitioners often move back and forth between the tasks, such as
refining a methodology after some data has been gathered. Likelihood is the chance of
something happening, whether defined, measured, or estimated in terms of general descriptors,
frequencies, or probabilities.
3. Develop Alternatives - In order to improve the ability to prevent, protect against, respond
to, recover from, and mitigate a variety of manmade and natural hazards, Risk managers must
focus their attention on identifying and executing actions to manage risks. Ultimately, the
objective of risk analysis is to provide decision makers with a structured way to identify and
choose risk management actions. Within the risk management process, the step of developing
alternatives involves systematically identifying and assessing available risk management
options. The Risk Manager develops alternative plans and mitigation plans for the risks
identified and brings together the proposed action plan within a framework and charts out the
course of action for each risk identified, together proposed risk management actions with the
results of a risk assessment. This provides leaders and top management with a clear picture of
the risk management benefits of each proposed action or group of actions. The picture of
potential benefits, when combined with an analysis of an action’s costs — both monetary and
For Private Circulation Only 37
non-monetary — can serve as a valuable resource for aiding decision makers in making
effective and efficient homeland security choices.
4. Decide Upon and Implement Risk Management Strategies - Risk management entails
making decisions about best options among a number of alternatives in an uncertain
environment. The key moment in the execution of any risk management process is when a
decision maker chooses among alternatives for managing risks, and makes the decision to
implement the selected course of action. This can include making an affirmative decision to
implement a new alternative, as well as the decision to maintain the status quo.
5. Evaluate and Monitor - Risk management is a process, not a project that can be
“finished” and then forgotten about. The organization, its environment, and its risks are
constantly changing, so the process should be consistently revisited, and evaluated. Determine
whether the initiatives are effective and whether changes or updates are required. Sometimes,
the team may have to start over with a new process if the implemented strategy is not effective.
If an organization gradually formalizes its risk management process and develops a risk culture,
it will become more resilient and adaptable in the face of change. This will also mean making
more informed decisions based on a complete picture of the organization’s operating
environment and creating a stronger bottom line over the long-term.
The role of the committee is to perform an oversight function. In doing so, it should consider
the risk policy and plan, determine the company’s risk appetite and risk tolerance, ensure that
risk assessments are performed regularly, and ensure that the company has and maintains an
effective on-going risk assessment process, consisting of risk identification, risk quantification
and risk evaluation. This risk assessment process (using a generally recognised methodology)
should identify risks and opportunities, and measure their potential impact and likelihood. The
committee should receive assurance from internal and external assurance providers regarding
the effectiveness of the risk management process. In turn, management is responsible for the
design, implementation and effectiveness of risk management, as well as continual risk
monitoring.
It is of vital importance that members of the risk committee have experience within the
industry. This would allow them to identify areas of risk and be aware of the appropriate
Secondly, the audit committee should act as an independent oversight body. Having to directly
oversee the risk management function would generally involve a large amount of detailed
review of the processes and workings of the company. This would necessarily have a
detrimental effect on the objectivity of the audit committee’s members when considering
reports of the risk management function. The formation of a separate committee recognises the
fact that the identification and management of risks impacting the business, and the disclosure
of these to the shareholders is vital to good governance. Also, a combined audit and risk
committee will inevitably have a strong focus on financial risks, which may result in inadequate
attention to operation and related risk. It is our recommendation that the responsibility for risk
management be delegated by the board to a separate risk committee, comprising both executive
and non-executive directors. Where more than one committee bears responsibility for risk
management (i.e. the audit committee oversees financial risks and the remuneration committee
oversees risks pertaining to compensation), it is paramount that the responsibilities are clearly
demarcated and that communication channels are established to ensure that the respective
committees take cognisance of and consider the reports and recommendations of the other
relevant committees.
In considering whether or not to establish a risk committee one might consider the following
key factors:
• Inherent risk environment: The need for a risk committee may be precipitated by the
inherent risk environment. The extent, complexity, and potential impact of risks should be
considered, and weighed against the ability of the board or a board committee (e.g. the audit
committee) to deal sufficiently with workload.
The risk committee will have specific responsibilities that include, but are not limited to,
oversight and approval of the enterprise risk management framework commensurate with the
complexity of the company including (note that these responsibilities are performed by the
In developing risk committee charters, boards may wish to consider including provisions that
specifies: • The separate nature of the risk committee and that it has been established to exercise
enterprise-wide risk-oversight responsibilities • The risk-oversight responsibilities of the
committee and how it fulfils them • Who is responsible for oversight of management’s risk
committee, for example, whether it is the CRO, the risk committee, the full board, or the CEO
(although, typically, the full board is ultimately accountable and responsible for risk
governance) • Who is responsible for establishing the criteria for management’s reporting about
risk to the board (although the actual criteria need not be set in the charter, because they are
expected to change as the enterprise and risks change) • The composition of the risk committee
and the qualifications of risk committee members.
The board’s or risk committee’s responsibilities regarding the enterprise’s risk appetite, risk
tolerances, and utilisation of the risk appetite • The board’s or risk committee’s responsibility
to oversee risk exposures and risk strategy for broadly defined risks, including for example
credit, market, operational, compliance, legal, property, security, IT, and reputational risk.
The risk committee’s responsibility to oversee the identification, assessment, and monitoring
of risk on an on-going enterprise-wide and individual-entity or line of business basis • The risk
In developing risk committee charters, boards may wish to consider including provisions that
Specifies as under :-
• The separate nature of the risk committee and that it has been established to exercise
enterprise-wide risk-oversight responsibilities and the risk-oversight responsibilities of the
committee and how it fulfils them
• Who is responsible for oversight of management’s risk committee, for example, whether it is
the CRO, the risk committee, the full board, or the CEO (although, typically, the full board is
ultimately accountable and responsible for risk governance)
• Who is responsible for establishing the criteria for management’s reporting about risk to the
board (although the actual criteria need not be set in the charter, because they are expected to
change as the enterprise and risks change)
• The composition of the risk committee and the qualifications of risk committee members
• The board’s or risk committee’s responsibilities regarding the enterprise’s risk appetite, risk
tolerances, and utilisation of the risk appetite • The board’s or risk committee’s responsibility
to oversee risk exposures and risk strategy for broadly defined risks, including for example
credit, market, operational, compliance, legal, property, security, IT, and reputational risks
The risk committee’s responsibility to oversee the identification, assessment, and monitoring
of risk on an on-going enterprise-wide and individual-entity or line of business basis
• The reporting relationships between the risk committee, the CEO, the CRO and the
management risk committee.
• The risk committee’s responsibility to ensure that risk management is embedded in the
business and all decision making processes.
•The use of specialist in areas where risks are complex, the terms of service of risk committee
members and the chair, with incumbent’s subject to reappointment; term limits (which may
preclude members or chairs from having their terms renewed) may not be desirable because
they may cause the loss of individuals in valued roles.
Risk committee members may be recruited from the current board and should ideally include
a combination of executive and non-executive directors.
To ensure that the Company is taking appropriate measures to achieve prudent balance
between risk and reward in both ongoing and new business activities.
To assist the Board in setting risk strategies, policies, frameworks, models and
procedures in liaison with management and in the discharge of its duties relating to
corporate accountability and associated risk in terms of management assurance and
reporting.
To review and assess the quality, integrity and effectiveness of the risk management
systemsandensurethattheriskpoliciesandstrategiesareeffectivelymanaged.
To review and assess the nature, role, responsibility and authority of the risk
management function within the Company and outline the scope of risk management
work.
To ensure that the Company has implemented an effective ongoing process to identify risk,
to measure its potential impact against a broad set of assumptions and then to activate
what is necessary to pro -actively manage these risks, and to decide the Company’s
appetite or tolerance for risk.
To review the risk bearing capacity of the Company in light of its reserves, insurance
coverage, guarantee funds or other such financial structures.
To ensure that the risk awareness culture is pervasive throughout the organization.
To review issues raised by Internal Audit that impact the risk management framework.
To ensure that infrastructure, resources and systems are in place for risk management is
adequate to maintain a satisfactory level of risk management discipline.
The Board shall review the performance of the risk management committee annually.
Internal auditors can be responsible for carrying out regular ' annual, in many cases '
assessments of an organization's risk management program, particularly as they relate to
regulatory compliance. The audit compliance report forms the basis of continuous
improvement, identifying any shortcomings and enabling compliance teams to put in place
remedial actions, while developing an effective compliance and audit strategy that could be a
central part of any compliance program. Having this level of compliance monitoring gives the
business assurance that the risks they face are being tackled, and that appropriate steps are
being taken to identify and manage the full range of business risks.
In many ways, the internal audit function is ideally placed to lead on risk. Internal auditors
have an understanding of risk and its implications on a par with their risk manager colleagues;
in fact, they have a comprehensive oversight of all things governance, risk and compliance.
Typically, internal auditors are objective and analytical ' also key competencies for anyone
providing impartial assessment. They tend to take a moderate approach to risk, demonstrating
neither extremely risk-averse or high-risk behaviours. When reviewing risk management
processes, it's vital that internal audit is able to access a full picture of current performance,
and the procedures in place to manage and respond to the risks identified.
All too often, risk data is collated inconsistently, and obligations not clearly defined ' causing
headaches for any auditor trying to build a complete overview. Increasingly, compliance, risk
and internal audit teams are turning to compliance software solutions to deliver comprehensive
compliance and risk management programs, facilitating implementation, management and
monitoring.
According to the IIA the following are the acceptable role of Internal Audit
• Evaluating RM processes
The IA is an independent activity used to provide objective assurance to the Board on the
effectiveness of RM and an integral part of the RM framework. Over the years, it transitioned
from a role of checking organizational compliance with policies and procedures, to the much
broader role of risk management. According to the IIA, the role of the IA is both one of advisory
and consultancy as they consider the potential threats, which may be posed to objectivity and
independence. IA must ensure sufficient documentation and to ensure that
process protocols are implemented and properly executed. Since IAs objectivity and
independence were so often questioned, the IIA developed a position of acceptable roles
for the IA function as mentioned above. Empirical studies also found that IA increased risk
reduction.
First line of Defense –Lies with the business and process owners. Operational management is
responsible for maintaining effective internal controls and for executing risk and control
procedures on a day to day basis. This consists of identifying, assessing controls and mitigating
control risks. Additionally, business and process owners guide the development and
implementation of internal policies and procedures and ensure activities are consistent with
goals and objectives. Mid-level managers may design and implement detailed procedures that
serve as controls and supervision execution of those procedures by their employees.
Second line of defense –Supports management to help ensure risks and controls are effectively
managed. Management establishes various risk management and compliance functions to help
build or /and monitor the first line of defence controls. The typical controls are
A risk management function that facilitates and monitors the implementation of effective risk
management practices by operating management and assists risk owners in defining the target
of risk exposure and reporting adequate risk –related information throughout the organization
A compliance function to monitor various specific risks such as non-compliance with
applicable laws and regulations. The separate function reports directly to senior management
A controllership function that monitors financial risks and financial reporting issues.
The Role of External auditors has traditionally been involved in auditing of financial statements
of entities and providing assurance to investors and management that the financial statements
are free from any material mis-statements and that they represent a true and fair view of the
financial statements. Though primarily it has been related to accounting, records examination,
of late the role of External auditors as provider of valuable inputs on the risks the companies
face is increasing. The legal landscape is also becoming more complex and has put considerable
burden on the external auditor address the issues arising in the process, and the reporting
requirements have undergone a sea-change.
The role of external auditor in mitigating risk is important and valuable for following reason-
10. The Institute of Risk Management : Risk culture Under the Microscope
Guidance for Boards
11. Coso guidance - Risk appetite to Success, COSO publication May 2020
12. Muller Robert.R, Coso enterprise risk management, second edition , wiley
finance, Enterprise risk management Coso -Oct 2019
13. [Link]
exams- study-resources/strategic-business-leader/technical-articles/coso-enterprise-risk-
management- [Link]
14. Hampton , John –Fundamentals of Enterprise Risk Management –Second Edition-
American Management Association (2015)
Section –A ( 5 marks)
Section B (9 marks)
1. List out the skill sets needed by Risk manager, in brief.
2. List out the responsibilities of the risk committee, briefly.
3. Briefly outline the three defences model used by internal auditors.
4. Examine the role of external auditor and the value addition he brings in the context of
risk mitigation in organizations.
Section –C ( 12 marks)
1. Explain the ten basic indicators of matured risk culture in organizations with
examples you know of.
2. Discuss the key factors which decide the tone at the top, and its importance
3. Examine the role of a Risk Manager and the activities he performs in the context of
strategic risk management.
4. Discuss the role of external as well as internal auditor, in mitigating risks and how it
helps add value to the decisions made by Corporate Boards/ Top management.
5. Elaborate the importance, role of risk committees in assisting the top management to
control risks and mitigation, and to enable meet the management objectives.
Enterprise risk management (ERM) is a leading best practice approach to effectively manage
and optimize business events that have the potential to impact business objectives or risks,
A process of understanding and managing the risks that the entity is inevitably subject to in
attempting to achieve its corporate objectives. For management purposes, risks are usually
divided into categories such as operational, financial, legal compliance, information and
personnel. One example of an integrated solution to risk management is enterprise risk
management.
The process of assessing risk and acting in such a manner, or prescribing policies and
procedures, so as to avoid or minimize loss associated with such risk
With a company-wide span, ERM serves as a strategic analysis tool, cutting across business
units and departments, and considering end-to-end processes. In adopting an ERM approach,
companies gain the ability to align their risk criteria to business strategy by identifying events
that could have an adverse effect on their organizations and then developing an action plan
to mitigate them. .
Enterprise risk management (ERM) is a plan-based business strategy that aims to identify,
assess and prepare for any dangers, hazards and other potentials for disaster – both physical
and figurative – that may interfere with an organization's operations and objectives.
Relatively new (it's less than a decade old), the discipline not only calls for corporations to
identify all the risks they face and to decide which risks to manage actively; it also involves
making that plan of action available to all stakeholders, shareholders and potential investors,
as part of their annual reports. Industries as varied as aviation, construction, public health,
international development, energy, finance and insurance all utilize ERM. Risk management
in an organization minimizes the impact of risk on the business with the help of a chief risk
officer or a risk committee but it does not give a guarantee that the organization will become
risk free.
ERM is a new approach in the ways organizations are assessing, managing and communicating
business risks. By assisting organizations climb up on the risk maturity scale, ERM makes a
major contribution towards helping an organization manage risks to achieve its objectives. ERM
helps an organization become a risk managed business. An ERM policy is first put in place
which defines the guiding principles showing responsibility of line management for ERM and
the broad activities covered by the risk management processes. Whatever the definition, everyone
recognized ERM as a broad and complex concept that reaches into every major area of an
organization. As such, it is not surprising that many approaches have been advanced to install
ERM. They fall into three categories:
ISO 31000: ISO 31000 is an international standard for risk management developed by the
International Organization for Standardization (ISO). It provides principles, guidelines, and a
risk management process applicable to all types of organizations and risks. The ISO 31000
framework emphasizes the importance of risk identification, analysis, evaluation, treatment,
and monitoring.
Risk Appetite Frameworks: Risk appetite refers to the level of risk that an organization is
willing to accept to achieve its objectives. Establishing risk appetite frameworks helps
organizations define their risk tolerance and align risk management decisions with their overall
business strategy.
Top-Down and Bottom-Up Approaches: Some organizations implement ERM through a top-
down approach, where the risk management strategy is set by the board or top management
and cascaded down to various departments. Conversely, a bottom-up approach involves
individual departments identifying and assessing risks, which are then aggregated at the
organizational level.
Organizations often customize these approaches to fit their specific needs and risk profiles. The
chosen ERM approach should align with the organization's size, industry, complexity, and risk
appetite while promoting a risk-aware culture throughout the organization.
The COSO enterprise risk management framework identifies eight core components that
define how a company should approach creating its ERM practices.
Objective Setting: As a company determines its purpose, it must set objectives that support
the mission and goals of a company. These objectives must then be aligned with a company's
risk appetite. For example, an ambitious company that has set far-reaching strategic
plans must be aware there may be internal risks or external risks associated with these lofty
goals. In response, a company can align the measures to be taken with what it wants to
accomplish such as hiring additional regulatory staff for expansion areas it is currently
unfamiliar with.
Event Identification: Positive events may have a great impact on a company. On the other
hand, negative events may have detrimental outcomes on a company's ability to continue to
operate. ERM guidance recommends that companies identify important areas of the business
and associated events that may have dire outcomes. These high risk events may pose risks to
operations (i.e. natural disasters that force offices to temporarily close) or strategic
(i.e. government regulation outlaws the company's primary product line).
Risk Assessment: In addition to being aware of what may happen, the ERM framework
details the step of assessing risk by understanding the likelihood and financial impact of risks.
This includes not only the direct risk (i.e. a natural disaster yields an office unusable) but
residual risks (i.e. employees may not feel safe returning to the office). Though difficult, the
ERM framework encourages companies to consider quantifying risks by assessing the percent
change of occurrence as well as the dollar impact.
Risk Response: A company can respond to risk in the following four ways:
Control Activities: Control activities are the actions taken by a company to create policies
and procedures to ensure management carries out operations while mitigating risk. Control
activities, often referred to as internal controls, are broken into two different types of
processes:
1. Preventative control activities are in place to stop an activity from happening. These
controls aim to mitigate risk by disallowing certain events from happening. An
example of a preventative control is a keypad or physical lock preventing all
employees from entering into a sensitive area.
2. Detective control activities are in place to recognize when a risky action has taken
place. Although the event is allowed to happen (or was not supposed to happen but
still did), detective controls may alert management to ensure appropriate follow-up
steps occur. An example of a detective control is an alarm for the room or a l
Information and Communication: Information systems should be able to capture data useful
to management to better understand a company's risk profile and management of risk. This
means not granting exceptions for departments outperforming others; all aspects of a company
Monitoring: A company can turn to an internal committee or an external auditor to review its
policies and practices. This may include reviewing what is actually performed compared to
what policy documents suggest. This may also entail getting feedback, analyzing company
data, and informing management of unprotected risks. In an ever-changing environment,
companies must also be ready to assess their ERM environment and pivot as needed.
3.4 COSO ERM Framework: This framework defines essential enterprise risk management
components, discusses key ERM principles and concepts, suggests a common ERM
language, and provides clear direction and guidance for enterprise risk management.
COSO framework states that Enterprise Risk Management (ERM) is defined as a process,
affected by an entity's board of directors, management, and other personal, applied in strategy
setting and across the enterprise, designed to identify potential events that may affect the
entity, and manage risk to be within its risk appetite, to provide reasonable assurance
regarding the achievement of entity objectives. ERM includes the following activities:
3.5 Management of Risk framework: Effective risk management plays a crucial role in
any company's pursuit of financial stability and superior performance. The adoption of a risk
management framework that embeds best practices into the firm's risk culture can be the
cornerstone of an organization's financial future. A risk management framework (RMF) is a
set of practices, processes, and technologies that enable an organization to identify, assess, and
analyse risk to manage risk within your organization.
Identifying, assessing, and analysing risk can be overwhelming for many companies. You may
struggle with knowing where to start or how to set goals. However, a risk management
framework enables you to create repeatable processes that allow you to define, review, and
mitigate IT risks to more effectively set and monitor controls.
The 5 Components of RMF: There are at least five crucial components that must be
considered when creating a risk management framework. They include risk identification; risk
measurement and assessment; risk mitigation; risk reporting and monitoring; and risk
governance.
It is important to note that risk identification is not a one-time process. The risks that an
organization faces tend to change over time, so risk assessments will need to be performed on
a periodic basis.
Mitigation: The third component in the framework is risk mitigation. Risk mitigation involves
examining the risks that have been identified and determining which risks can and should be
eliminated, as opposed to the risks that are deemed to be acceptable.
Part of this process involves coming up with mitigation strategies, such as cyber insurance. For
example, if an organization identifies cybersecurity risks that need to be dealt with, then it may
choose to integrate security controls into its development lifecycle. Such an organization would
likely also put additional baseline security controls in place.
Reporting and monitoring: The fourth component in the process is risk reporting and
monitoring. This essentially means regularly re-examining the risks in order to make sure that
the risk mitigation strategies the organization has adopted are having the desired effect.
Governance: The last component in the process is risk governance. Risk governance is the
process of making sure that the risk mitigation techniques that have been adopted are put into
place and that the employees adhere to those policies.
The COCO framework is a powerful tool in that it allows an organization to focus on key
structures, values and processes that together form this concept of internal control, far outside
the narrow financial focus that used to be the case. The individual is part of the process but it
can be hard to get a corporate solution down to grassroots. The criteria of control (CoCo) is a
further control framework that can mean more to teams and individuals and includes an
interesting learning dynamic. CoCo was developed by the Canadian Institute of Chartered
Accountants (CICA) and is now an international standard.
Control should cover the identification and mitigation of risks. These risks include not only
known risks related to the achievement of a specific objective but also two more fundamental
risks to the viability and success of the organization.
failure to maintain the organization’s capacity to respond and adapt to unexpected risks
and opportunities, and make decisions on the basis of the tell-tale indications in the
absence of definitive information.
The principles may be organized according to the four groupings of the CICA criteria of control
framework. The main components are explained below:
Purpose – The model starts with the need for a clear direction and sense of purpose.
This includes objectives, mission, vision and strategy; risks and opportunities; policies;
planning; and performance targets and indicators. It is essential to have a clear driver
for the control criteria and since controls are about achieving objectives, it is right that
people work to the corporate purpose. Much work can be done here in setting objectives
and getting people to have a stake in the future direction of the organization. The crucial
link between controls and performance targets is established here as controls must fit
in with the way an organization measures and manages performance to make any sense
at all.
Commitment – The people within the organization must understand and align
themselves with the organization’s identity and values. This includes ethical values,
integrity, human resource policies, authority, responsibility and accountability, and
Action – This stage entails performing the activity that is being controlled. Before
employee’s act, they will have a clear purpose, a commitment to meet their targets and
the ability to deal with problems and opportunities. Any action that comes after these
prerequisites has more chance of leading to a successful outcome.
Monitoring and learning – People must buy into and be part of the organization’s
evolution. This includes monitoring internal and external environments, monitoring
performance, challenging assumptions, reassessing information needs and information
systems, follow-up procedures, and assessing the effectiveness of control. Monitoring
is a hard control in that it fits in with inspection, checking, supervising and examining.
Challenging assumptions is an important soft control in that it means people can
develop and excel.
Concept of GRC: The acronym GRC is a shorthand reference to the collection of critical
capabilities that must work together to achieve Principled Performance. GRC denotes
governance, risk management, and compliance, but it connotes much more than those three
competitive. Confidence comes from being aware of what is going on both internally and
externally, so that organizations can evaluate information before taking action and responding
appropriately. It means being agile; moving not just quickly but with the ability to shift
direction when called for to avoid threats or grasp opportunities. It allows for the organization
to be both lean, with more muscle and less fat, and also more resilient so that it can recover
from adversity. When an organization, and everyone making decisions within it, are
appropriately confident (because you can also be confident when you should not be) and
understand the organization’s decision-making criteria and strategic goals, they can take
advantage of risk in a way that others cannot, without going beyond established risk thresholds
and tolerances. That is a real competitive advantage.
On the flip side, it is observed from past research that the more siloed the risk and compliance
operations, and the more separated from business operations, the less likely that critical
information about these areas of concern is shared with strategic decision-makers in a timely
fashion. The greatest risk of a heavily siloed approach is that wrong decisions cause the
organization to face too much risk or fail to grasp opportunities
There are other risks identified in our research as well. Siloed risk and compliance operations
spend too many resources trying to reconcile disparate information, have gaps and unnecessary
overlaps in activities, put too much burden on the business by failing to coordinate schedules
and requests for information, and even worse, may create new risks themselves. Rather than
support the organization’s ability to achieve objectives, they burden it.
Members to be involved -Board members, Senior executives, business unit head and
project heads are all involved in governance at enterprise, business unit or project unit
levels. People engaged in strategic planning, business continuity activities, technology
managers, HR managers all have a GRC role. GRC roles thus have become extremely
critical and can greatly affect the direction, strategy, future and reputation of the
organisations and most corporates have started taking the issue quite seriously.
The need to ensure collaboration and communication in these critical relationships may be best
seen through a few examples of key GRC roles.
The Role of the Risk Executive and Managers: Whether engaged in Enterprise Risk
Management (ERM) or business unit risk control efforts,the Chief Risk Officer (CRO)
and risk managers play an essential part in driving the organization toward Principled
Performance. Risk teams both directly under the CRO and within business units must
consider threats and opportunities presented to the organization and ensure that this
information is available as strategic plans are developed and implemented. The
organization must integrate consideration of risk into decision-making across the
enterprise. Controlling threats and enhancing opportunities in light of set objectives and
strategies is only one part of the equation; it is equally important to ensure that any
fluctuation that arises due to changes in the internal or external context is evaluated to
determine how changes may impact achievement of objectives. This must be
communicated to the governing authority and strategic planners. This is the case not
only at the enterprise level, but also within business units and as risk is managed project
by project. Accordingly, risk assessment is not a “one-and-done” activity; it requires
ongoing monitoring of change and modifications to ensure continued alignment
between objectives, strategies, risks, rewards, and controls.
The Role of Compliance and ethics Executive and Manager
Compliance and Ethics Executives (sometimes a combined Chief Ethics and
Compliance Officer or CECO role) and managers with compliance and ethics
responsibilities must be concerned not only with the organization meeting legal
requirements but also with satisfying internally established values, policies,
procedures, and codes of conduct. These can be defined as the mandatory and
voluntary boundaries and the job of this team is to make sure that the organization (or
collects and maintains information in ways that allow it to deliver the right information to the
right people or systems, at the right time and in the right format. This is an essential aspect of
integrated GRC capabilities. Protecting an organization’s information security and ensuring
availability of necessary technology resources and information are critical to this undertaking.
The CIO and information technology managers must be involved in helping to design the GRC
technology strategic plan that will determine the right combination of solutions based on user
and stakeholder needs. Then, they must work with business operators and key GRC executives
to determine what technologies are currently in use, evaluating them to determine what should
be kept, changed or integrated. This enables a fully architected approach to GRC technology
ISO 31000 is the family of risk management standards recognized internationally. This
framework sets out principles, guidelines and a process to provide risk management
practitioners with guidance on recognized best practices for implementing risk management.
However, this standard is broad as it isn’t written for any specific industry or even specific
management levels. It provides an internationally-recognized benchmark for the practice of
risk management. Your industry or country might have derivative standards based on ISO
31000 that are more specific, recognized frameworks and best practices relevant to your
organization.
When we talk about adopting a risk management standard, we’re talking about finding an
appropriate standard and aligning the way you do risk management in your organization to that
particular standard.
For example:
Everyone in the company will use standard terminology when discussing risk,
regardless of whether they are working at project level, enterprise risk management
level or somewhere in between.
It’s easier to recruit experienced (and good) risk specialists because we can specify we
need them to have experience in the standard. This will make their onboarding easier
because they don’t have to learn your specific processes. Longer term, using national
or international standards can also help retention and staff development as entities
invest in their development.
Any standard will work with any risk management tools. Regardless of what software
entities are using, entities should easily be able to customize the processes to fit the
tools they have. There’s no need to invest in additional software (assuming they have
some that does the job already).
Adopting a risk management standard can help entity win more business, as customers
want to see that entity take risk management seriously. Seeing that entity has adopted a
recognized standard makes that instantly visible to them.
It’s easier to benchmark entity performance against other organizations using the same
approach.
There’s often a community of standard users. If needed help, it’s easier to ask for help
with elements of a recognized standard than it is within entity’s own bespoke
methodology. Everyone in the extended community will already know what entity are
talking about!
Having said that, the risk management standard you choose should be your baseline. It’s OK
to customize the standard to better fit your working practices or your industry. The way you do
risk management is specific to your business – and while there are guidelines out there to help,
ultimately you get to decide how risk management works in your own organization.
Changing how entities manage risk in your organization can be a big upheaval. There are many
people to train in new methods and terminology. There is process documentation to be
rewritten. And that’s on top of the bulk of the work of creating a gap analysis to establish how
to do the move in the first place.
Entity champions for risk management, might face challenge from senior leaders in the
organization who don’t see the value in changing the way risk is managed. If the way the entity
manages risk is perceived to be adequate already, going through a large risk re-engineering
program might not be considered a priority – especially if it can’t easily tie back the work to a
tangible ROI.
The changes we’re talking about aren’t cosmetic. It’s not simply a case of updating the
language in entity’s risk documentation to ensure it’s using the new standard vocab. In reality,
we are looking at a complete review of entity ‘s current processes and practices.
The new standard might not easily fit to what the entity is doing already, so we could have to
introduce new ways of working. And the standards might need customizing to particular
industry or business. All of this takes time and investment.
Improving the identification of threats (risks with a negative outcome for the business)
and opportunities (risks with a positive outcome for the business)
Increasing the likelihood that your organization will achieve its strategic goals due to
better oversight and governance.
References:
1. [Link]
Terminal Questions:
Section –A ( 5 marks)
1) Define the concept of ERM, and briefly examine the importance of ERM in corporates
today.
2) Define the process of COSO framework and how different elements are related.
3) Briefly comment on the importance of ERM today and justify the reasons for its
adoption in major organizations.
4) Elaborate on Risk management components in detail.
5) State the advantages of adopting a Risk management Standard.
Section B ( 9 marks)
1. Explain the COCO Framework model concept .
2. Distinguish between traditional approach to Risk management and the ERM approach
to Risk management
3. Briefly elucidate the Pros and Cons of following 1SO -31000 standards in risk
management
4. Explain briefly the importance of GRC and its various components .
1) Explain the full process of Enterprise Risk management , and list out the advantages
that organizations adopting ERM can get over the others .Give examples of any
company you know adopting the ERM.
2) Explain the GRC framework elements in Risk management in today’s organization
and its importance with examples.
Structure
Identifying risks is the first and perhaps the most important step in the risk management
process. It involves generating a comprehensive list of threats and opportunities based on
events that might enhance, prevent, degrade, accelerate or delay the achievement of your
objectives. If you don’t identify a risk, you can’t manage it. It’s also important to scan the
environment from time to time to identify new and emerging risks, as the department’s
exposure to risk may be constantly changing.
Identifying risks is a key step in a proactive risk management process. As part of this process
you must look at the following sources:
Sources Description
Risk registers Provide a foundation for evaluating existing risks and their potential risk
and risk reports to an objective.
Business Impact Detailed risk analysis that examines the nature and extent of disruptions
Analysis and the likelihood of the resulting consequences.
Sources/Approach Description
SWOT analysis Commonly used as a planning tool for analysing a business, its
resources and its environment by looking at internal strengths and
weaknesses; and opportunities and threats in the external
environment
PESTLE approach Commonly used as a planning tool to identify and categorise threats
in the external environment (political, economic, social,
technological, legal, environmental
Scenario Analysis Uses possible (often extreme) future events to anticipate how
threats and opportunities might develop.
Working groups Useful to surface detailed information about the risks i.e. source,
causes, consequences, stakeholder impacted, existing controls
Corporate knowledge History of risks provide insight into future threats or opportunities
through: • Experiential knowledge – collection of information that
a person has obtained through their experience. • Documented
knowledge – collection of information or data that has been
documented about a particular subject. • Lessons learned –
knowledge that has been organised into information that may be
relevant to the different areas within the organisation.
Other jurisdictions Issues experienced and risks identified by other jurisdictions should
be identified and evaluated. If it can happen to them, it can happen
here
There is no easy scientific method that will guarantee that we will identify all risks. Some
additional better practice approaches to and sources for identifying risks include:
Information that we should collect during the Risk identification step can be as under:-
What are the sources of risk or threat – the things which have the inherent potential to
harm or facilitate harm.
What could happen – events or incidents that could occur whereby the source of risk or
threat has an impact on the achievement of objectives.
Risk identification should be approached in a methodical way to ensure that all significant
activities within the organization have been identified and all the risks flowing from these
activities defined.
All associated volatility related to these activities should be identified and categorized.
Business activities and decisions can be classified in a range of ways, examples of which
include:
• Strategic - These concern the long-term strategic objectives of the organisation. They can
be affected by such areas as capital availability, sovereign and political risks, legal and
regulatory changes, reputation and changes in the physical environment.
Financial - These concern the effective management and control of the finances of the
organisation and the effects of external factors such as availability of credit, foreign exchange
rates, interest rate movement and other market exposures.
Knowledge management - These concern the effective management and control of the
knowledge resources, the production, protection and communication thereof. External factors
might include the unauthorised use or abuse of intellectual property, area power failures, and
competitive technology. Internal factors might be system malfunction or loss of key staff.
Compliance - These concern such issues as health & safety, environmental, trade descriptions,
consumer protection, data protection, employment practices and regulatory issues. Whilst risk
identification can be carried out by outside consultants, an in-house approach with well
communicated, consistent and coordinated processes and tools is likely to be more effective.
In-house ‘ownership’ of the risk management process is essential
(i) Initial risk identification (for an organisation which has not previously identified its risks in
a structured way, or for a new organisation, or perhaps for a new project or activity within an
organisation), and there is;
(ii) Continuous risk identification which is necessary to identify new risks which did not
previously arise, changes in existing risks, or risks which did exist ceasing to be relevant to the
organisation (this should be a routine element of the conduct of business
In either case risks should be related to objectives. Risks can only be assessed and prioritised
in relation to objectives (and this can be done at any level of objective from personal objectives
to organisational objectives). Care should be taken to identify generic risks which will impact
on business objectives but might not always be immediately apparent in thinking about the
particular business objective. When a risk is identified it may be relevant to more than one of
the organisation’s objectives, its potential impact may vary in relation to different objectives,
and the best way of addressing the risk may be different in relation to different objectives
(although it is also possible that a single treatment may adequately address the risk in relation
The individual risks which an organisation identifies will not be independent of each other;
rather they will typically form natural groupings. For instance, there may be a number of risks
which can be grouped together as “resources” and further risks which can be grouped together
as “environmental”. Some risks will be relevant to several of the organisation’s objectives.
These groupings of risks will incorporate related risks at strategic, programme and operational
levels (see 1.6). It is important not to confuse a grouping of risks with the risks themselves.
Risks should be identified at a level where a specific impact can be identified and a specific
action or actions to address the risk can be identified. All risks, once identified, should be
assigned to an owner who has responsibility for ensuring that the risk is managed and
monitored over time. A risk owner, in line with their accountability for managing the risk,
should have sufficient authority to ensure that the risk is effectively managed; the risk owner
may not be the person who actually takes the action to address the risk.
Risk self-assessment: An approach by which each level and part of the organisation is invited
to review its activities and to contribute its diagnosis of the risks it faces. This may be done
through a documentation approach (with a framework for diagnosis set out through
questionnaires), but is often more effectively conducted through a facilitated workshop
approach (with facilitators with appropriate skills helping groups of staff to work out the risks
affecting their objectives). A particular strength of this approach is that better ownership of
risk tends to be established when the owners themselves identify the risks.
Risk Estimation
Examples are given in the tables overleaf. Different organizations will find that different
measures of consequence and probability will suit their needs best.
For example many organisations find that assessing consequence and probability as high,
medium or low is quite adequate for their needs and can be presented as a 3 x 3 matrix.
Other organisations find that assessing consequence and probability using a 5 x 5 matrix
gives them a better evaluation.
High High Financial impact on the organisation is likely to exceed £x
Significant impact on the organisation’s strategy or operational
activities Significant stakeholder concern.
Low Low Financial impact on the organisation likely to be less that £y Low
impact on the organisation’s strategy or operational activities Low
stakeholder con
High ( probable) Likely to occur each year or Potential of it occurring several times
more than 25% chance of within the time period (for example -
occurring ten years). Has occurred recently
Likely to occur in a ten year Could occur more than once within the
time period or less than 25% time period (for example - ten years).
Medium ( possible)
chance of occurrence Could be difficult to control due to
some external influences. Is there a
history of occurrence?
Low (Remote) Not likely to occur in a ten Has not occurred. Unlikely to
year period or less than 2%
Occur.
chance of occurrence
Assessing risks
record the assessment of risk in a way which facilitates monitoring and the
identification of risk priorities;
ensure that there is a clearly structured process in which both likelihood and impact are
considered for each risk;
be clear about the difference between, inherent and residual risk
Some types of risk lend themselves to a numerical diagnosis – particularly financial risk. For
other risks - for example reputational risk - a much more subjective view is all that is possible.
In this sense risk assessment is more of an art than a science.
It will be necessary, however, to develop some framework for assessing risks. The assessment
should draw as much as possible on unbiased independent evidence, consider the perspectives
of the whole range of stakeholders affected by the risk, and avoid confusing objective
assessment of the risk with judgement about the acceptability of the risk.
This assessment needs to be done by evaluating both the likelihood of the risk being realised,
and of the impact if the risk is realised. A categorisation of high / medium / low in respect of
each may be sufficient, and should be the minimum level of categorisation – this results in a
“3x3” risk matrix. A more detailed analytical scale may be appropriate, especially if clear
When the assessment is then compared to the risk appetite , the extent of action required
becomes clear. It is not the absolute value of an assessed risk which is important; rather it is
whether or not the risk is regarded as tolerable, or how far the exposure is away from
tolerability, which is important
At the organisational level risk appetite can become complicated, but at the level of a specific
risk it is more likely that a level of exposure which is acceptable can be defined in terms of
both a tolerable impact if a risk is realised, and tolerable frequency of that impact. It is against
this that the residual risk has to be compared to decide whether or not further action is required.
Tolerability may be informed by the value of assets lost or wasted in the event of an adverse
impact, stakeholder perception of an impact, the balance of the cost of control and the extent
of exposure, and the balance of potential benefit to be gained or losses to be withstood .
Care should also be taken to capture information about the inherent risk. If this is not done the
organisation will not know what its exposure will be if control should fail. Knowledge about
the inherent risk also allows better consideration of whether there is over-control in place – if
the inherent risk is within the risk appetite, resources may not need to be expended on
controlling that risk. This need to have knowledge about both inherent and residual risk means
that the assessment of risk is a stage in the risk management process which cannot be separated
from addressing risk; the extent to
which the risk needs to be addressed is informed by the inherent risk whereas the adequacy of
the means chosen to address the risk can only be considered when the residual risk has been
assessed.
Risk assessment should be documented in a way which records the stages of the process.
Documenting risk assessment creates a risk profile for the organisation which:-
• facilitates identification of risk priorities (in particular to identify the most significant risk
issues with which senior management should concern themselves);
• captures the reasons for decisions made about what is and is not tolerable exposure;
• allows all those concerned with risk management to see the overall risk profile and how their
areas of particular responsibility fit into it;
Once risks have been assessed, the risk priorities for the organisation will emerge. The less
acceptable the exposure in respect of a risk, the higher the priority which should be given to
addressing it. The highest priority risks (the key risks) should be given regular attention at the
highest level of the organisation, and should consequently be considered regularly by the
Board. The specific risk priorities will change over time as specific risks are addressed and
prioritisation consequently changes.
Impact (or consequence) refers to the extent to which a risk event might affect the enterprise.
Impact assessment criteria may include financial, reputational, regulatory, health, safety,
security, environmental, employee, customer, and operational impacts. Enterprises typically
define impact using a combination of these types of impact considerations (as illustrated
below), given that certain
risks may impact the enterprise financially while other risks may have a greater impact to
reputation or health and safety. When assigning an impact rating to a risk, assign the rating for
the highest consequence anticipated. For example, if any one of the criteria for a rating of 5 is
met, then the impact rating assigned is 5 even though other criteria may fall lower in the scale
Objective
Very Low / Moderate / Very High
Low / 0.1 High / 0.4
0.05 0.2 /0.8
Insignificant
5 - 10% 10 - 20% > 20%
Time change in < 5% increase
increase increase increase
schedule
Project end
Barely
Minor areas Major areas Unacceptable item
Scope noticeable
affected affected reduction effectively
scope decrease
useless
Impacts are often defined as the consequences, or effects of a risk event on the project
objectives. These impacts can be both beneficial or harmful to the objectives .The impact of
risk events on different project objectives can be defined in both a qualitative and quantitative
manner. These project objectives are cost, schedule, quality, scope, health, safety, etc.
The Impact scale can vary, but the most common scale is the five-point scale. Typically, the
impacts are described relatively; as very low, low, moderate, high and very high, but often also
defined using numerical scales. Dependent on the objective, the scales are given a description
of what the impact entails . One risk event can affect more than one objective, so the impact of
all the possible objectives effected must be considered . Table 1 shows how the impact can be
defined for various objectives. The possible impacts on each objective is described and given
a ranking. The ranking in table 1 is both relative, from very low to very high, and numerical,
giving numerical values based on the specific project.
Probability
Risk probability, or likelihood, is the possibility of a risk event occurring. The likelihood can
be expressed in both a qualitative and quantitative manner. When discussing probability in a
qualitative manner, terms such as frequent, possible, rare etc. are used. It is also possible to
describe the probability in a numerical manner. This can be done using scores, percentages and
frequencies defined by the organizations dependent on the relative description Table 1 show
an example on how an organization can define the ranking for the likelihood of risks. The table
shows the ranking in both a relative and numerical manner and a description of the ranking is
given.
Likelihood Description
Risk analysis is a two-stage process, with qualitative assessment being the first stage. By using
qualitative methods for risk assessment, the risk can be categorized for further quantitative
assessment or even risk response planning. Quantitative assessment is the next stage in risk
analysis. The process involves analyzing the effects of risks on the overall project objectives.
They primarily focus on the risks which have been prioritized in the qualitative assessment. To
ensure the quality and credibility of the analysis, general definitions of impact and probability
levels must be fitted to individual project context.
Qualitative Analysis
Qualitative methods for risk assessment are relatively rapid in practice, cost effective and easily
understood . The results from the qualitative assessments are not an accurate estimate of risk.
However, they provide a rather descriptive result and often with sufficient information for
planning responses. The results from these assessments also set the foundation for more
detailed quantitative analysis, if possible and warranted. It is performed regularly throughout a
projects life cycle as new risks may emerge at later stages as well as a risk response may result
in other risk events . Classifying the risks enables organizations to reduce uncertainty levels
and focus primarily on the high-risk events. There are two qualitative methods of assessing risk
events in terms of impact and probability, both involving rating the impact and probability.
These are Risk Probability and Impact Assessment and Probability and Impact matrix
The probability assessment involves estimating the likelihood of a risk occurring. The impact
assessment estimates the effects of a risk event on a project objective. These impacts can be
both positive and negative; i.e., opportunities and threats. The project objectives are numerous,
e.g. the schedule, cost, quality and scope. For each identified risk, the impact and probability
are assessed. Interviews and meeting with experienced project participants, stakeholders, and
experts in the subject are the basis for the impact and probability assessment. These impacts
and probabilities are rated and their level assessed. The risks which receive high ratings are
investigated further or an appropriate response is planned. The low rated risks do not require
an immediate action, but should be included in the Risk register for monitoring
The Probability and Impact Matrix is one the most commonly used qualitative assessment
method. It is based on the two components of risk, probability of occurrence and the impact on
objective(s) if it occurs. The matrix is a two-dimensional grid that maps the likelihood of the
risks occurrence and their effect on the project objectives . The risk score, often referred to
as risk level or the degree of risk, is calculated by multiplying the two axes of the matrix.
As the impact and probability can be described in both a relative and numerical manner so can
the risk score. The higher the combined ratings are, the higher the score and thus the risk level.
These ratings are generally defined from low to high or from very low to very high . The ratings
for likelihood and impact are made using gathered opinions from interviews These ratings
must be classified by each organization, specific for each activity. The organizations must
define their risk tolerance. Creating these definitions of impact and probability levels can help
reducing the influence of bias . The result from these risk matrices are used to prioritize the
risks, plan the risk response, identify risks for quantitative assessment and guide resource
allocations . However, the objective effected by the risk must also be considered. E.g., a risk
events which has high safety or health risk would be prioritized over a risk event which would
have very high financial risk
Probability Threats
Low impact – Low probability: The risks that are characterized as low, or very low, risks
have both a low impact and likelihood of occurrence. For negative risks, threats, the response
required is not necessarily as proactive management action. However, they should be included
within the risk register for future monitoring. Positive risks, opportunities, within the low-risk
category should be monitored or just simply accepted. Opportunity acceptance means taking
advantage of the opportunity if it arises, but not actively pursuing it .
High impact – Low probability: Risks with high impact but low likelihood of occurrence can
be characterized from low to high risks but most often within the moderate category. The
Low impact – High probability: Risks with low impact but high likelihood of occurrence can
be characterized from low to high risks but most often within the moderate category. The
characterization is dependent on the organizations defined threshold. These risks are mostly
due to uncertainties of numerous elements that individually, are minor risks but combined,
could amount to higher risks. These are such uncertainties as actual cost and duration of
different aspects of a project, changes to activates or other similar uncertainties, that alone,
have little impact
High impact – High probability: The risks that are characterized as high risks have both a
high impact and likelihood of occurrence. A risk which has a negative impact, is a threat to the
objective, may need priority actions and aggressive responses. These aggressive responses
could be mitigation of the risk or even terminating the project if the risk is to great. A risk that
has a positive impact, is an opportunity, is most likely obtained easily, with the greatest benefits
and should thus be targeted first.
Quantitative Analysis
Quantitative assessment methods provide more accurate analysis results than the qualitative
assessment. However, they are costlier and often time consuming, so only the risk prioritized
by the qualitative assessment are analyzed. These methods are mostly used to analyze the
combined effects of all affecting risks. The most important benefit is that the information
produced support decision-making, and reduce project uncertainty. In some cases, quantitative
methods are not applicable due to lack of sufficient data, but that must be evaluated by the
project manager. The analysis should be repeated as a part of risk control to determine whether
the overall risks are reaching a desirable state. There various methods for quantitative analysis;
e.g. Sensitivity analysis, Expected Monetary Value analysis and Monte Carlo Simulations.
The result of the risk analysis process can be used to produce a risk profile which gives a
significance rating to each risk and provides a tool for prioritising risk, treatment efforts. This
ranks each identified risk so as to give a view of the relative importance. This process allows
the risk to be mapped to the business area affected, describes the primary control procedures
in place and indicates areas where the level of risk control investment might be increased,
decreased or reapportioned. Accountability helps to ensure that ‘ownership’ of the risk is
recognised and the appropriate management resource allocated.
The potential loss from an adverse outcome is a function of the probability or likelihood that
the adverse outcome will occur, and the impact of the outcome if it does occur.
When an initial review is carried out to identify and assess risks, the assessment of both
probabilities and impact might be based on judgement and experience rather than on a detailed
statistical and numerical analysis.
Each risk can then be plotted on a risk map. A risk map is simply a 2 × 2 table or chart, showing
the probabilities for each risk and their potential impact.
Probability or -High
Likelihood – Low
A risk map immediately indicates which risks should be given the highest priority.
High-probability, high-impact risks should be given the highest priority for management,
whether by monitoring or by taking steps to mitigate the risk.
For each high-probability, high-impact risk, further analysis should be carried out, with a view
to: estimating the probability of an adverse (or favourable) outcome more accurately, and
assessing the impact on the organisation of an adverse outcome.
This is an area in which the finance department should be able to contribute by providing
suitable and relevant financial information.
An alternative layout for a risk map shown above) would be a tabular format. The table might
have the following columns:-
(5) The risk owner i.e. the name of a manger or director who watches out for this risk arising.
(6) Whether assurance is sufficient. This might be given a score out of, say, 10, or a yes/no
type response.
The different Risk management strategies are of five types . They are as under
1. Risk avoidance: Where risks have such serious consequences on the project outcome that
they are totally unacceptable. Risk avoidance measures might include a review of the
employer’s brief and a reappraisal of the project, perhaps leading to an alternative design
solution that eliminates the risk or even project cancellation. Risk avoidance occurs where risks
have such serious consequences on the project outcome that they are totally unacceptable. Risk
avoidance measures might include a review of the employer’s brief and a reappraisal of the
project, perhaps leading to an alternative development mix, alternative design solution or
cancellation of the project
2. Risk reduction: Where the level of risk is unacceptable and actions are taken to reduce
either the chance of the risk occurring or the impact of the risk should it occur. Typical actions
to reduce the risk can include: further site investigation to improve information, using different
materials/suppliers to avoid long lead times or using different construction methods. Risk
reduction occurs where the level of risk is unacceptable
3. Risk transfer to the contractor: Risk transfer occurs where accepting the risk would not
give the employer best value for money. The object of transferring risk is to pass the
responsibility to another party better able to control the risk. Whenever risk is transferred there
is usually a premium to be paid (i.e. the receiving party’s valuation of the cost of the risk). To
be worthwhile, risk transfer should give better overall value for money to the employer (the
total cost of the risk to the employer is reduced by more than the cost of the risk premium).
Risk transfer measures include taking out insurance cover where appropriate.
4. Risk sharing by both employer and contractor: This is when a risk is not wholly
transferred to one party and some elements of the risk are retained by the employer. In
accordance with NRM, the approach for dealing with risks that are apportioned between the
client and the employer will normally be dealt with using provisional. quantities, with the
pricing risk being delegated by the contractor and the quantification risk being allocated to the
employer. Risk sharing occurs when risk is not entirely transferred and the employer retains
some element of risk.
Risk retention occurs when the employer retains risks that are not necessarily controllable. This
remaining risk is called the residual risk exposure
Interrelationship of risks
There are often interrelationships between risks (known as consequential risks) that increase
the complexity of assessing them. It is not uncommon for one risk to trigger or increase the
impact and/or likelihood of another. Such knock-on effects can turn a relatively minor event,
such as the decoration of a single room, into a major event; i.e. the facility cannot be handed
over until the room is complete and the client is not able to receive a rental income.
Interrelationships of risks often cross boundaries in the project plan (i.e. ownership, funding,
decision-making and organisational/geographical structures). The risk manager should be able
to communicate and liaise across these boundaries. Identifying, assessing and tracking down
interrelationships of risks are essential parts of the risk management process. Care must be
taken with overarching risks and double counting within the risk register. Classification of risks
in strategic and project operation and regular reviews of the register, led by an experienced
facilitator who is familiar with the project, will help mitigate problems in this regard.
The strategies for mitigating risk for each risk rating level (red, amber, orange and green)
should suit the level of risk appetite defined by the project team (risk appetite will vary
depending on the client’s core business and also the personnel responsible for the project). The
project team should agree on the risk mitigation approach and follow this when defining actions
for specific risks. Figure 3 shows an example of a risk mitigation approach.
Figure -3
Risk monitoring and control refers to the process of continuously identifying risks and
establishing the best methods of dealing with those risks.
Risk monitoring and control begins at the start of projects when all potential and known risks
are identified, and then just as importantly, continues throughout a project as those initial risks
are continuously tracked while new risks are also identified as work continues, changes and
progress.
Risk monitoring and control is a really important project management activity, because it
enables companies to manage one of the most powerful forces in project management: risk.
The overarching purpose of risk monitoring and control is to mitigate and eliminate the risks
which could de-rail a project or impact a company, and within these broader goals there are
some more specific purposes:
To make sure that the right and appropriate risk responses have and are being
implemented as planned
To determine the validity of the assumptions which were made prior to projects and
will likely be made again
To track and ensure that proper risk management and risk control procedures are
followed
Without proper risk monitoring and control, a company is powerless to understand how their
initial risk plans are going, as well as to respond quickly to the inevitable risks which arise
during the course of projects.
There are a range of controls that can be applied to hazard risks. The most convenient
classification system is to describe these controls as preventive, corrective, directive and
detective. This is the risk classification system suggested in the Orange Book.
1 Preventive (terminate)
These controls are designed to limit the possibility of an undesirable outcome being realized.
The more important it is to stop an undesirable outcome, then the more important it is to
implement appropriate preventive controls.
2 Corrective (treat)
These controls are designed to limit the scope for loss and reduce any undesirable outcomes
that have been realized. They may also provide a route of recourse to achieve some recovery
against loss or damage.
3 Directive (transfer)
These controls are designed to ensure that a particular outcome is achieved. They are based on
giving directions to people on how to ensure that losses do not occur. They are important, but
depend on people following established safe systems of work.
4 Detective (tolerate)
These controls are designed to identify occasions when undesirable outcomes have been
realized. Their effect is, by definition, ‘after the event’ so they are only appropriate by
definition, ‘after the event’ so they are only appropriate when it is possible to accept that the
loss or damage has occurred.
Directive controls are designed to ensure that a particular outcome is achieved. In health and
safety terms, directive controls would include instructions/directions given to employees to
follow, for example, in the use of personal protective equipment. Training in how to respond
to a particular risk event and detailed instructions and procedures are directive controls.
Directive controls are also associated with actions that must be taken in the event of a loss
to limit the damage and contain the costs. Detective controls are designed to identify occasions
when an undesirable outcome has occurred. The control is intended to detect when these
undesirable events have happened, to ensure that the circumstances do not deteriorate
These are the most important type of risk controls, and all organizations will use
risks is not possible on a cost-effective basis, nor may it be desirable for the future of the
organization and the continuation of certain activities. Examples of preventive controls include
the separation of duty, whereby no person has authority to act without the consent of another
when paying an invoice. Also, expenditure systems should prevent the same person from
ordering goods and then authorizing the payment for them. In health and safety terms,
preventive controls include the elimination or removal of the hazard and providing a less risky
substitute. For example, a hazardous chemical used in a cleaning operation may be substituted
with a less harmful alternative. The advantage of preventive controls is that they eliminate the
hazard, so that no further consideration of it is required. In reality, this may not be a cost
effective option and may not be possible for operational reasons. The disadvantages of
preventive controls are that beneficial activities may be eliminated and either outsourced or
replaced with something less effective and efficient. Health and safety practitioners refer to the
elimination of hazardous activities ‘so far as is reasonably practicable’. Achieving something
so far as is reasonably practicable involves the balance between cost in terms of time, trouble
and money against the benefit in terms of the reduction in the level of risk that is achieved. For
example, reducing the risk of collapse can be achieved in underground mines by the provision
of support beams and props. However, the extent to which this is reasonably practicable will
need to take into account the cost of providing these props against the level of risk reduction
that would be achieved in that particular mine.
Corrective Controls
Corrective controls are the next option after it has been decided that preventive controls are not
technically feasible, operationally desirable or cost-effective. Corrective controls are capable
of producing an entirely satisfactory result, whereby the current level of risk is reduced to
within the risk appetite of the organization. Examples of corrective controls can be found in
the management of health and safety at work. Engineering containment by way of barriers or
guards is a very well-established type of corrective control. In relation to fraud exposures, use
of passwords or other access controls can be considered to be corrective controls. Staff rotation
and regular change of supervisors also fit into this category of controls. The advantage of many
corrective controls is that they can be simple and costeffective. Also, they do not require that
Sometimes, corrective controls are over-engineered and their cost is disproportionate to the
benefit that is achieved. It is for risk management practitioners and internal auditors, as well as
employees themselves, to identify where expensive and/or ineffective corrective controls have
been implemented.
Very often, corrective controls are put in place because of regulatory requirements. This may
be unsatisfactory from the point of view of the organization and introduce additional costs
and/or inefficiency. However, it is for the organization to ensure that the appropriate level of
corrective control is achieved in order to comply with the minimum requirements of legislation.
The design and implementation of corrective controls is often the cause of considerable
discussion and even disagreement. For example, there is sometimes discussion with building
occupiers about fitting sprinklers as a corrective control that will activate in case of fire and
reduce the damage caused by the fire. Occupiers of premises with computer installations will
often say that sprinklers in computer rooms are inappropriate. Whilst understanding that water
does damage computer installations, fire engineers will usually counteract the
objections by pointing out that ‘water causes damage, but fire destroys’. Although this analysis
is correct and sprinklers do prevent total destruction, the disadvantages and unintended
consequences of installing additional controls always need to be carefully considered.
Detective Controls
As suggested in the title, detective controls are those procedures that identify when the hazard
has materialized. Detecting that a hazard has materialized some time after the event is not
entirely satisfactory, but can be justified in certain circumstances. Sometimes, other controls
may be unable to completely eliminate the chances of a risk materializing. Examples of
detective controls include stock or asset checks to ensure that stock or assets have not been
removed without authorization. Bank reconciliation exercises can detect unauthorized
transactions. Also, post implementation reviews can detect the lessons learnt from projects that
can be applied in future. Detective controls are closely related to review and monitoring
The disadvantage of the detective controls is that the risk will already have materialized before
it is detected. It could be argued, of course, that the fact that detective controls are in place will
deter certain individuals from attempting to circumvent other risk controls.
Detection of fraud is often only possible after the fraud has taken place. However, there are
considerable advantages in detecting fraud early, so that the nature and scale of the fraud may
be reduced and the scope for future similar fraudulent activities eliminated. Even in health and
safety arrangements, there is scope for the use of detective controls. Certain work activities
have hazards associated with them that can lead to permanent and serious health issues. By
having detective controls to identify the early symptoms of these occupational ill health
conditions, employees will be diagnosed early and further exposure can be eliminated.
Examples of these types of controls in health and safety include early detection of lung disease
from dust exposure, skin conditions such as dermatitis and finally deafness
(i) Ensure the execution of the risk plans and evaluate their effectiveness in reducing
risk.
(ii) Keep track of the identified risks, including the watch list.
(iii) Monitor trigger conditions for contingencies
(iv) Monitor residual risks and identify new risks arising during project execution.
(v) Update the organizational process assets.
The purpose of Risk monitoring is to determine if:
References:
Terminal questions
Section -A (5 marks )
Section –B ( 9 marks)
Structure
The Communication of Risk management strategies is one of the key aspects of effective risk
management. It is therefore important for Risk professionals to be aware of the importance,
relevance and criticality of Risk management strategies. Component 7 of the COSO ERM cube
considers the importance of risk information and communication.
Risk communication starts with the identification of the stakeholders that have an interest in
the particular risk under consideration. Once the stakeholders have been identified, the nature
of the risk information that needs to be communicated must be decided. Finally, the purpose of
communicating risk information to each group of stakeholders should be analyzed.
Stakeholders will already have a perception of risks, so risk communication should be provided
against the background of that existing perception. The guidelines relevant to risk
communication set out in Table 26.2 should be followed. These guidelines seek to establish
rules for communicating risk issues to a broad range of stakeholders.
Know the stakeholders, by identifying both external and internal stakeholders and
finding out their interests and concerns.
Simplify the language and presentation, although not the content if complex issues need
to be communicated.
Be objective in the information provided and differentiate between opinions and facts
Clearly, these rules become more important when the communication about risk is with
external bodies. Nevertheless, they provide a useful set of guidelines for risk communication
with internal as well as external stakeholders. Internal stakeholders have additional reasons for
being provided with risk information. There will normally be an expectation by the
organization that managers and staff will play a role in the future management of the risk,
whereas this may not always be the case for external stakeholders.
The first reason an organization needs a risk language is to underpin its risk culture. Everyone
in the organization has a role in an effective risk management process. Most organizations have
many layers (eg executives, line managers and employees) and ‘silos’(eg technology, treasury,
operations, quality management and compliance). A common language is needed to cut
through the layers and break down the silos. Conversely, without a common language, the risk
management team will spend too much time resolving communication issues at the expense of
their primary responsibilities.
Formal means of risk communication exist where the organization has to report to financial
stakeholders. When risk communication is required, a range of communication techniques can
Information can be provided on the intranet about the generic risk assessments that have been
undertaken and the control measures that have been identified. The intranet can also be used to
communicate urgent risk information, as well as providing updates on risk assessments, control
measures and the current level of any particular risk.
An important consideration in the collection, retention and supply of risk information is that it
should be aligned with other management information systems within the organization.
Providing risk information as a separate management information stream is likely to result in
risk management activities failing to be aligned or embedded within other activities. The
danger that risk information will become irrelevant to managers in the organization is greater
when the organization has a dedicated risk management information system (RMIS).
The distribution of risk management guidelines, protocols and procedures may be undertaken
by way of a risk management information system (RMIS) software package. The RMIS could
be placed on the intranet of the organization. The RMIS will also facilitate the collection and
communication of risk information, including the reporting of events by local management as
they occur.
The following types of information may be handled, stored, managed, distributed and
communicated using a risk management information system :-
Risk information needs to be shared throughout an organization to enhance risk awareness and
ensure improved risk performance. It is almost always the case that individuals within an
organization will have the best understanding of the risks, as well as detailed practical
knowledge of the actions that should be taken to mitigate risk events. Communication is also
important to share information about incidents that have occurred, including lessons that were
learn and the actions that were taken to ensure that the event is not repeated.
Beyond simply satisfying rules and regulations, it’s in a company’s own best interest –
economic and otherwise – to commit to risk communication in order to prevent or minimize
public risk conflicts and business crises.
Effective risk communication must address both the expert’s as well as the layperson’s
perspectives and approaches to characterizing risks. What is at stake is the extent to which the
risk issue could become a critical business factor. Even a "minor" risk can develop into a
serious problem for a company, even to the extent of putting it into a business crisis.
The capacity of a risk issue to evolve into a problem is influenced by a number of factors .These
characteristics determine to what extent a risk issue is likely to attract public attention and to
what extent it may become politicized. It is important to note that this progression depends
more on the perspective of the layperson than on views and assessments of the experts. Once
on its course, the company or organization is less and less able to have an influence on the risk
issue. Communication can only be successful if attempts are made to contribute to the debate
as early as possible in the emergence phase.
Various societal groups may be involved at different stages of the lifecycle. From the viewpoint
of a company, the most important groups to address in risk discussions are:
The defining moment in the lifecycle of a risk problem is the occurrence of an accident or other
critical event that causes harm to people or the environment, or at least is perceived to do so.
Companies have to expect serious consequences, up to and including a business crisis, if they
are perceived as being responsible or if they knew and condoned the risk, in spite of it being
perceived as intolerable. The situation is completely different if the companies themselves are
perceived as being the victims of aggression or a natural disaster. Fig. 4 presents the details of
this relationship. Therefore Risk communication should be structured separately for each of
these different circumstances.
Every company should know and periodically check the extent to which it needs to engage in
risk communication. The audit tool presented here aims at:
assessing the existing potential for exposure to risk issues using Table 3
determining the sensitivity towards risk issues for the company's specific operating
environment using Table 4
The assessment criteria presented here are solely a guideline and should in no way be
considered exhaustive or conclusive. The assessment should be made in qualitative terms, since
the overall picture of the "susceptibility to risk" can be gained only from a broader overview.
Analyses of the company's strengths/weaknesses and opportunities/threats can then be
performed to determine the appropriate actions that should be taken.
The more questions are answered in the affirmative in Table 3, the more the company has to
count on being involved in risk debates. This is because there tends to be a direct relationship
between the number and extent of the potential risks within the company and the probability
of the public becoming aware of these potential risks. And the greater is the need to
communicate appropriately in order to build sound foundation for effective risk management
Needless to say, if the answer to some of the questions is simply not known, that may point to
a lack of information that should be addressed. Ignorance, or more precisely, “not knowing the
knowable” does not make for an effective risk communication strategy and is likely to be
interpreted as a negligent attitude.
The below checklist explores the company's corporate culture, or, to be more precise, its
attitude towards risks and how it deals with the public. These factors determine which obstacles
to risk communication within the company must be overcome.
Is communication
considered an afterthought Communication is an
within the company? unnecessary luxury – we
need to concentrate on the
real problems
Does the company believe that it
is far too small to become Crises affect only big
involved in a public debate? businesses that are in the
public eye
Is it assumed that accidents
can be positively ruled out?
"Accidents are
Does the company have no inconceivable" attitude
contact with the press?
Never held a press conference
Does the company have no
contact with environmental and Never held a meeting with
consumer activist or community an environmental activist
action groups? association
All organizations of all kinds face internal and external factors and influences that make it
uncertain whether, when and the extent to which they will achieve or exceed their objectives.
These objectives are its highest expression of intent and purpose, and typically reflect an
The international risk management standard, ISO 31000:2009, defines risk as the effect of
uncertainty on objectives. The effective management of risk is therefore essential if
organisations are to achieve their objectives and satisfy the needs of their stakeholders.
It has been long recognised that good governance and effective management are best achieved
through the development and deployment within an organisation of one coherent and consistent
framework, methodology and vocabulary for management of risk, to be used for all types of
activity. This ensures that:
There is a consistent and defensible basis for decision making at all levels, particularly
where effort or capital is expended
Change activities are more likely to succeed
The organisation can pre-empt and capitalise on external changes such as those
involving demographics, customers’ needs and government policy
All employees are encouraged to focus on and give priority to actions that aid and
enhance the execution of strategic and project plans and the organisation’s objectives
The organisation is prepared for and protected from major incidents and losses
Tactical moves, to identify and seize opportunities are stimulated and enhanced
Accountability for risks and, most importantly, for controls and the monitoring and
assurance of controls is clear and not doubtful.
In time this will also lead to a significant change in culture as the organisation as its employees
engage on activities directly related to ensuring the achievement of goals and objectives and
the successful completion of projects.
An organisation’s ability to manage risk effectively depends on its intentions and its capacity
to achieve those intentions. This intent and capacity is referred to as its risk management
framework and is part of its system of governance and management.
The risk management framework should not attempt to replace the natural capability of people
to manage risk; rather it should enhance good practices so that the process is reliable,
comprehensive and consistent. For this to occur and for the required capability to be achieved,
the organisation requires:
The typical elements of a framework and an illustration of how this supports the integration of
the risk management process is shown in the figure below
The core of this management of change process involves internal stakeholder representatives
participating in a facilitated gap analysis and evaluation that then leads to a clear and practical
enhancement and implementation plan. This is depicted in the “Y Model” shown in the figure
and described below.
This approach has the added benefit that the participants of this process then become the
organisation’s “Champions” who are motivated to lead the implementation process in their
own departments and functions. They also act to convince their superiors of the merits of the
approach and motivate acceptance and use.
These steps can be tackled separately and the results fed back to senior management. However,
after many years and numerous attempts we have found that most efficient approach, and the
one that gains the greatest degree of ownership and endorsement, is to involve representatives
of senior internal stakeholders in all these steps over a short space of time. This approach is
described in detail below.
Evaluation studies typically start with an initial meeting where the detailed arrangements,
including the schedule of activities and delivery dates, the documents to review reviewed and
the interview candidates are agreed.
The Y model
These steps can be tackled separately and the results fed back to senior management. It is fel
that the most efficient approach, and the one that gains the greatest degree of ownership and
endorsement, is to involve representatives of senior internal stakeholders in all these steps over
a short space of time. This approach is described in detail below.
Phase 1 - Preparation
Evaluation studies typically start with an initial meeting where the detailed arrangements,
including the schedule of activities and delivery dates, the documents to review reviewed and
the interview candidates are agreed.
Prior to the meeting we issue a checklist of background documentation we would like to review
and will often open up a secure Internet portal to which documents can be uploaded. This list
can include:
Normally a preliminary review of the materials is undertaken and, from this, develop an aide
memoire of sample questions that the risk team might ask those they want to interview. This
document is sent to those who are to be interviewed to allow them to prepare.
Experts observe that it is vital to observe and review how risk management takes place in
practice. This is particularly true if there might be any discontinuity of practice across the
organisation or inconsistent processes and systems. It is also important to test management’s
perceptions of the current approach to risk management to see if it is currently viewed as
effective and is likely to satisfy their future needs.
They therefore undertake this observation through a series of structured interviews with senior
managers from which they will draw conclusions on:
The suitability of the current framework and tools to manage risk associated with an
organisation of a comparable size and complexity, its risk profile and the risk criteria
that should reflect its attitude (appetite)
The drivers of that attitude, based on what are recognised as the ‘key success factors’
and growth objectives for the organisation
The perceived usefulness of the current risk management process and its degree of
integration into key decision-making processes;
The strengths and limitations of the other approaches to risk management specific to
particular kinds of risks that co-exist in the organisation
Whether the tools and methods currently being used are capable of providing the
organisation with a current, correct and comprehensive understanding of its risks and
inform it whether the risks are within its risk criteria
The level of understanding of senior managers about aspects of the risk management
culture
An outline of the perceived risk profile of the organisation and whether this varies from
the risks reported to senior management and oversight committees.
While the predominant purpose of the interviews is to obtain information from the participants
to support the review, they also provide an opportunity to explain the purpose of the study.
At the conclusion of the series of interviews it normally provides immediate feedback to the
organisation’s risk staff on:
The findings
Using the information, the experts/reviewer have gathered the conduct a detailed gap analysis
and evaluation of effectiveness using the guidelines and principles in ISO 31000 and what they
understand is world’s best practice as a basis for comparison. Often this is conducted as a
facilitated workshop involving the management team.
The gap analysis looks at how the organisation expresses its intentions for managing risk and
the elements of the capacity it claims it provides. In practice this involves at looking all the
elements of the risk management framework and process shown above to determine if they are
present and are suitable for the organisation and its environment.
Normally a full gap analysis is prepared with a evaluation report that includes expert’s findings
in terms of:
The framework and how it facilitates the integration of risk management into decision
making, including risk management plans and the strategy for their implementation
How risk management is applied in strategy development and during the concept and
development phases of projects, for decision-making and change management and as
part of design review
Control assurance and reporting
The reliability of each element of the risk management process
It is important that senior managers appreciate and can comment on the reviewer’s findings
and conclusions and that this leads to support for any enhancement plan. It is important that
this takes place before their report is made available to the oversight committee so that it can
indicate management’s response.
The Reviewer or expert, therefore normally present their findings and recommendations at a
short meeting with senior managers. A typical draft agenda will be:
The planning component of this session follows the ‘Y model’ (see above) to elicit feedback
and ownership of the current situation, the wanted situation and what needs to change. The
management team is encouraged to discuss and compare options and then to finalise the
enhancement plan actions and agree timelines. These agreements are recorded and included in
final report.
In most cases the oversight committee is provided with progress reports against this
enhancement plan at subsequent meetings.
93% of firms without a robust disaster recovery plan that endures a data breach incident had to
shut down their operations within a year. In contrast, 96% of firms with a reliable disaster
recovery plan were able to outlast attacks These figures demonstrate why it is absolutely critical
for companies to put in place a robust disaster recovery plan.
As firms today increasingly rely on electronic data for everyday operations, the volume of data
and IT infrastructure lost to data breaches continues to grow. Data loss can be damaging to any
business. Yet, it is something that only a few businesses are ready to deal with. One way
companies can be ready and protect themselves from breaches is to establish a disaster recovery
plan (DRP). Companies must develop a disaster recovery plan that can address all kinds of
disasters.
What is a DRP?
A disaster recovery plan is an official document conceived by a firm that comprises exhaustive
guidelines on ways to respond to unforeseen incidents such as cyberattacks, power outages,
and any other disruptive incidents. The plan includes approaches on curtailing the effects of an
infringement, so a firm can continue their operations or quickly resume after a disruption.
Lengthy disruptions can lead to revenue loss, damage to the brand, and unhappy customers.
The longer the recovery time, the bigger the unfavourable business impact. Consequently, a
good disaster recovery plan must facilitate rapid recovery, irrespective of the source of the
disruption.
The objective of testing a disaster recovery plan is to understand the shortcomings within the
plan. By testing a plan, it is possible to find quick solutions before they deteriorate and disrupt
the ability to re-establish key business operations. It is extremely important that businesses test
their disaster recovery plan so that they can be well-equipped to cope with any incident that
may impinge on critical business processes.
Likewise, DR testing is essential for managed service providers. Testing disaster recovery plan
also boosts their capacity to respond to and recuperate from different breaches, irrespective of
whether it is a human-made disaster, a communication breakdown or even a natural disaster.
DR testing validates a disaster recovery program and business continuity.
Also, it is not sufficient to test a disaster recovery plan once in a while. Regular testing is the
surest way to guarantee that the IT disaster recovery team or the cyberattack recovery team can
restore customer operations immediately after a catastrophe. Companies today can outsource
the task of testing the suitability and efficacy of an IT disaster recovery plan.
There are several steps that can be taken to test a disaster recovery plan. A simple walkthrough
to assess process flow with disaster drills and simulations can help in testing the efficacy of the
plan. To establish efficient strategies, situations are manifested to quickly manage the disaster.
Here is a checklist to testing a disaster recovery plan:
Offer a detailed DR testing plan when trying to get authorization and aid to run tests.
Identify goals, procedures, and the things that you seek in the post-testing assessments.
Form a test team that include SMEs and make sure each person is available for the
scheduled date of testing.
Meticulously document and be ready to revise your DR plan and DR testing scripts.
Incorporate all pertinent tech components and procedures being tested, no matter how
insignificant.
Make sure the test ecosystem is ready, available and will have no effect on production
systems before commencing. Ensure testing does not clash with other activities.
Plan a DR test that will take hours, far in advance; inform other IT supervisors of the
approaching test.
Carry out a dry run before the disaster recovery test goes live to unearth and resolve
potential obstacles.
Halt and assess the test when problems arise. Resume if the issue can be circumvented;
postpone if needed.
Appoint a timekeeper to record start and end times and a transcriber to help with the
test's after-action report, which illustrates what transpired during the test, what did and
did not work and what has been understood.
Update disaster recovery and BCP and other documents based on what has been
understood from the DR test.
These measures can halt business activities. To avoid any hindrance to your daily operations,
non-critical business units must be shut down temporarily while testing is conducted. If an
extensive test is carried out, all functions would be interrupted.
Extensive tests are the best as all processes can entirely be tested in case of an incident.
Disasters can affect the whole infrastructure. Moreover, such tests can help in establishing
whether or not a firm will recuperate from a disaster or not. Disaster recovery testing will test
a company’s strategy and prepare them on simulated scenarios. Triumphs and failures must be
documented including any lessons learned during this process. Testing exercises for disasters
must be carried out to stay updated and refreshed
A disaster recovery plan must be evaluated, examined, and reorganized at least once every
year. Every time there are major changes made to recovery tactics, human resources, operating
software, and IT infrastructure, a business continuity and disaster recovery test must be
conducted.
Frequency of the tests depends on the type of business plan being analysed. A disaster recovery
plan entails the management of activities between multi-layered technology configurations and
vendor partnerships. The suggestion for DRP testing is every year, but because of the
inclusiveness of a business continuity plan, more frequent testing is essential.
There are BCP and DRP training course to help people become more familiar with the nitty-
gritty of disaster recovery testing. Also, there are vendors who offer business continuity
management certifications to help conduct sufficient DR testing.
After the testing stage of a disaster recovery and business continuity plan, a business can
interpret what worked and what did not. All that did not work can be examined to see what can
be enhanced so that the process can be altered in favor of the business. The MetricStream
Business Continuity Management Product enables an integrated approach to business continuity
management processes with abilities to simplify workflows, automate metric computations,
and integrate BCM activities.
As organizations rely more on technology and electronic data for their daily operations, the
amount of data and information technology infrastructure lost to disasters appears to be
increasing. Organizations are estimated to lose revenue and incur expenses every year due to
disasters, unpreparedness, and lost productivity. Measures must be taken to protect your
organization from disasters.
One way your organization can prepare and protect itself from disasters is to create and
implement a disaster recovery plan (DRP). Organizations should create a disaster recovery plan
that can address any type of disaster. The plan should be easy to follow and understand, and be
customized to meet the unique needs of the organization. Typical elements in a disaster
recovery plan include the following
1. Create a disaster recovery team. The team will be responsible for developing,
implementing, and maintaining the DRP. A DRP should identify the team members, define
each member’s responsibilities, and provide their contact information. The DRP should also
identify who should be contacted in the event of a disaster or emergency. All employees should
be informed of and understand the DRP and their responsibility if a disaster occurs.
2. Identify and assess disaster risks. Your disaster recovery team should identify and assess
the risks to your organization. This step should include items related to natural disasters, man-
made emergencies, and technology related incidents. This will assist the team in identifying
the recovery strategies and resources required to recover from disasters within a predetermined
and acceptable time frame.
4. Specify backup and off-site storage procedures. These procedures should identify what
to back up, by whom, how to perform the backup, location of backup and how frequently
backups should occur. All critical applications, equipment, and documents should be backed
up. Documents that you should consider backing up are the latest financial statements, tax
returns, a current list of employees and their contact information, inventory records, customer
and vendor listings. Critical supplies required for daily operations, such as checks and purchase
orders, as well as a copy of the DRP, should be stored at an off-site location.
5. Test and maintain the DRP. Disaster recovery planning is a continual process as risks of
disasters and emergencies are always changing. It is recommended that the organization
routinely test the DRP to evaluate the procedures documented in the plan for effectiveness and
appropriateness. The recovery team should regularly update the DRP to accommodate for
changes in business processes, technology, and evolving disaster risks
In summary, an organization must develop a recovery team to create a disaster recovery plan
that includes identifying and assessing disaster risks, determining critical applications, and
specifying backup procedures. Other procedures may be included in the plan based on the
organization. The recovery team and organization must then implement the DRP and follow
through on the plan procedures. The DRP should be continually tested and maintained to
consistently prepare the organization for evolving disasters and emergencies
As disaster and emergency managers, we always have to plan for the unexpected. In this regard,
it is always important to understand what a disaster is and what qualifies as a hazard in order
to react accordingly. A low magnitude earthquake in the East African region in 2019 was a
natural hazard but it was not a disaster. The intensity of the earthquake was very low and did
not have any impact on people or property. In contrast, the cyclone Udai in Zimbabwe and
Mozambique, a natural hazard escalated into a disaster with high loss of life and property.
Disasters and emergencies happen after an interaction between a hazard and a vulnerable
population that disrupts lives and communities. Due to this, we always evaluate disasters in
terms of their intensity, location, scale, and the extent to which they are human-made or
‘natural’ and the vulnerability of the population affected. Of key importance, after a disaster,
the efficiency of the after response is usually critical to the recovery of the affected community.
When the response is well coordinated and touches on the key needs of the community focusing
on rebuilding with locally available resources the population bounces back fast. Our task, as
we focus on quick disaster recovery, is to find the most efficient manner to hand a disaster and
it’s aftermath. For this to be possible, Monitoring and Evaluation plays a key role in the process.
On the other hand, Evaluation seeks to determine whether a project is achieving what it set out
to do and whether it is making a previously projected impact. If the set objective is being
achieved, the evaluation seeks to understand how and why the intervention has worked so well.
If the project is unsuccessful, questions are raised as to what could have been done better or
differently. Evaluations’ main purpose is to keep track of key outcomes and impacts related to
the different project components, assessing whether the objectives, aims and goals are being
achieved.
In disaster recovery, we need a Monitoring and Evaluation Framework to ensure the programs
being implemented are evaluated to gauge their effectiveness. By improving the quality of
evaluations, it makes it possible to improve subsequent disaster recovery programs. The
learning we obtain from these evaluations is incorporated into program design and delivery.
Therefore, disaster recovery is a set of activities deployed to achieve the desired recovery
objective and outcome after the occurrence of a disaster. In most cases, the sets of program are
above and beyond usual services that government provides to the same community while not
affected with disaster. For us, the main focus of this program is bringing back the community
where they can continue to process on their own.
We define disaster recovery as a continuous and interactive process through which programs
are custom-made since the affected community needs evolve and the impact of the disaster
changes in scope and intensity. The progress towards sustainability and resilience cannot,
therefore, be captured retrospectively. We have to continuously engage in monitoring of
Available resources can are redirected to other areas of need as earlier targets are
achieved
All the groups involved in the delivery of recovery programs are accountable for their
respective performance.
Monitoring should be followed through with Community Recovery Progress Reports (CRPR).
These reports should be compiled in accordance with a timetable set out in the evaluation plan,
which should occur at least annually, or on a more regular basis in the earlier phases. The CRPR
should include sections that:
review key activities to be performed by the next reporting period and the expected
outcome to be achieved
identify where expectations have not been met and discussing why and how best to
approach such in future.
Report on ways the local community has been involved in the recovery process.
Evaluation of Findings
Alternative results proposal with evaluations on how external factors contributed to the
overall recovery program
Positive and negative consequences discovered on the cause of the evaluation process
a discussion of the extent to which the different data collection methods lead to similar
results and a discussion of any differences.
In conclusion
Monitoring and Evaluation of disaster recovery processes assist in making data models to
predefine a scale-up of your capabilities enabling responders to work with an expectation of
the worst. By doing this (not limiting a disaster to one’s capabilities) it forces us, the recovery
team, to look at alternatives means; we think differently. More importantly, it demands us to
look for solutions that are not merely scaling up current systems or practices. Clearly, through
M&E processes, we are able to change our way of thinking accommodating changing threats.
This is the ultimate objective, and this approach will save the most lives.
A risk management plan can never be perfect. However, the degree of its success depends upon
risk analysis, management policies, planning and activities. A well-defined management plan
can be successful only if risks are properly accessed. And if not, the main objective of risk
management plan itself is defeated. Critical evaluation of a risk management plan at every stage
is very necessary especially at an early stage. It will allow companies to discover the flaws
before it gets into the action. Once you’re through the process, you can address the issues and
then introduce it.
The below mentioned steps can help in analyzing and evaluating a risk management plan:
Problem Analysis: Keep a note of all the events and activities of a risk management
plan. Check out the problems arising from their implementation and assess if they have
a serious impact on the whole process. Make a note of those that have serious
implications.
Match the Outcomes of a Risk Management Plans with its Objectives: Ends justify
means. Check if the possible outcomes of a risk management plan are in tandem with
its pre-defined objectives. It plays a vital role in analyzing if the plan in action is perfect.
If it produces desired results, it does not need to be changed. But if it fails to produce
what is required can be a really serious issue. After all, an organization deploys its
resources including time, money and human capital and above all, the main aim of the
organization is also defeated.
Evaluate If All the Activities in the Plan are Effective: It requires a thorough
investigation of each activity of a risk management plan. Checking out the efficiency
of all the activities and discovering the flaws in their implementation allow you to
analyze the whole plan systematically.
Evaluate the Business Environment: A thorough study and critical evaluation of
business environment where a risk management plan is to be implemented is essential.
Take time to assess, analyze and decide what exactly is required.
Make Possible Changes in Faulty Activities: After evaluating the effectiveness and
efficiency of all the activities, try to make possible changes in the action plan to get
desired results. It may be very time consuming but is necessary for successful
implementation of your risk management plan.
1. An executive within the organization decides that a business continuity plan is needed.
This might be due to an auditor’s report or the result of a business disruption that was more
financially painful than it would have been if a plan had been in place. Or it could be that an
alert employee realized that a good plan did not exist and brought this to the executive’s
attention. This executive usually becomes the sponsor for the project.
2. The first (and most important) step that the sponsor takes is to select someone to lead the
project. This person is most often called the Business Continuity Manager and is responsible
for the successful completion of the project.
3. The project sponsor and the Business Continuity Manager meet to clearly define the scope
of the project, the project timeline, and expectations. The Business Continuity Manager must
be comfortable that the resources available are adequate to meet all the objectives of the
project.
4. The Business Continuity Manager selects the team that will work together to complete the
project. Both technical and political considerations are important in selecting a team that can
successfully develop a workable business continuity plan.
5. The Business Continuity Manager together with the team now develops the project plan to
be used in managing the project. Tasks are identified and assigned, task duration calculated,
and activities are sequenced as the project plans are developed.
6. The project plans are executed. The Business Continuity Manager oversees the project as
the plan unfolds, keeping everyone focused on completing their tasks and ensuring that
milestones are met and that important stakeholders are kept informed as to the project’s
progress. It is here where the actual continuity plans for the organization are created.
A project plan organizes the team so members focus their skills on specific actions to get the
job done. This respects their time and brings the project to a prompt,
Business continuity planning emerged from disaster recovery planning in the early 1970s.
Financial organizations, such as banks and insurance companies, invested in alternative sites.
Backup tapes were stored at protected sites away from computers. Recovery efforts were
almost always triggered by a fire, flood, storm or other physical devastation. The 1980s saw
the growth of commercial recovery sites offering computer services on a shared basis, but the
emphasis was still only on IT recovery.
The 1990s brought a sharp increase in corporate globalization and the pervasiveness of data
access. Businesses thought beyond disaster recovery and more holistically about the
entire business continuity process. Companies realized that without a thorough business
continuity plan they might lose customers and their competitive advantage. At the same time,
business continuity planning was becoming more complex because it had to consider
application architectures such as distributed applications, distributed processing, distributed
data and hybrid computing environments.
Organizations today are increasingly aware of their vulnerability to cyber attacks that can
cripple a business or permanently destroy its IT systems. Also, digital transformation and
hyper-convergence creates unintended gateways to risks, vulnerabilities, attacks and failures.
Business continuity plans are having to include a cyber resilience strategy that can help a
business withstand disruptive cyber incidents. The plans typically include ways to defend
against those risks, protect critical applications and data and recover from breach or failure in
a controlled, measurable way.
It’s important to have a business continuity plan in place to identify and address resiliency
synchronization between business processes, applications and IT infrastructure. According to
IDC, on average, an infrastructure failure can cost USD $100,000 an hour and a critical
application failure can cost USD $500,000 to USD $1 million per hour.
To withstand and thrive during these many threats, businesses have realized that they need to
do more than create a reliable infrastructure that supports growth and protects data. Companies
are now developing holistic business continuity plans that can keep your business up and
running, protect data, safeguard the brand, retain customers – and ultimately help reduce total
operating costs over the long term. Having a business continuity plan in place can minimize
downtime and achieve sustainable improvements in business continuity, IT disaster recovery,
corporate crisis management capabilities and regulatory compliance.
Yet developing a comprehensive business continuity plan has become more difficult because
systems are increasingly integrated and distributed across hybrid IT environments – creating
potential vulnerabilities. Linking more critical systems together to manage higher expectations
complicates business continuity planning – along with disaster recovery, resiliency, regulatory
compliance and security. When one link in the chain breaks or comes under attack, the impact
can ripple throughout the business. An organization can face revenue loss and eroded customer
trust if it fails to maintain business resiliency while rapidly adapting and responding to risks
and opportunities.
Strategy: Objects that are related to the strategies used by the business to complete
day-to day activities while ensuring continuous operations
Organization: Objects that are related to the structure, skills, communications and
responsibilities of its employees
Applications and data: Objects that are related to the software necessary to enable
business operations, as well as the method to provide high availability that is used to
implement that software
Processes: Objects that are related to the critical business process necessary to run the
business, as well as the IT processes used to ensure smooth operations
Technology: Objects that are related to the systems, network and industry-specific
technology necessary to enable continuous operations and backups for applications and
data
Facilities: Objects that are related to providing a disaster recovery site if the primary
site is destroyed
The business continuity plan becomes a source reference at the time of a business continuity
event or crisis and the blueprint for strategy and tactics to deal with the event or crisis.
The following figure illustrates a business continuity planning process used by IBM Global
Technology Services. It’s a closed loop that supports continuing iteration and improvement as
the objective. There are three major sections to the planning process:
Integration into IT: Take the input from business prioritization and perform an overall
business continuity program design.
− Identification of critical businesses, owned and shared resources with supporting functions
to come up with the Business Impact Analysis (BIA)
− Formulating Recovery Time Objectives (RTO), based on BIA. It may also be periodically
fine-tuned by bench marking against industry best practices
− Critical and tough assumptions in terms of disaster, so that the framework would be
exhaustive enough to address most stressful situations
− Identification of the Recovery Point Objective (RPO), for data loss for each of the critical
systems and strategy to deal with such data loss
− Alternate procedures during the time systems are not available and estimating resource
requirements
iii) Impact on restoring critical business functions, including customer-facing systems and
payment and settlement systems such as cash disbursements, ATMs, internet banking, or
call centres
• BCP should evolve beyond the information technology realm and must also cover people,
processes and infrastructure
• The methodology should prove for the safety and well-being of people in the branch /
outside location at the time of the disaster.
• To arrive at the selected process resumption plan, one must consider the risk acceptance
for the bank, industry and applicable regulations
• Action plans, i.e.: defined response actions specific to the bank’s processes , practical
manuals( do and don’ts, specific paragraph’s customised to individual business units) and
testing procedures
• Compatibility and co-ordination of contingency plans at both the bank and its service
providers
• Having specific contingency plans for each outsourcing arrangement based on the degree of
materiality of the outsourced activity to the bank's business
• Periodic updating to absorb changes in the institution or its service providers. Examples of
situations that might necessitate updating the plans include acquisition of new equipment,
upgradation of the operational systems and changes in:
a) Personnel
c) Business strategy
e) Legislation
• Security threats
[Link]
7. Sabharwal, M., & Swarup, A. (2012). The implementation of disaster management by Indian
banks. International Journal on Arts, management and humanities, 1(1), 73-80. T
8. Wallace, Michael and Webber Lawrence, - the disaster recovery handbook, third edition,
Amacom publications
10. Disaster recovery and Business Continuity plan – Grant Thorton publication
Section –A ( 5 marks)
Section –C ( 12 marks)
1. Explain the key guidelines for Risk communication. Examine the reasons for its
importance
2. Examine the four phases of assessing the effectiveness of Risk Management plan and
its importance with examples.
3. Enumerate the key features of a Business Continuity plan , with s suitable example
from any organization you know of .
4. Explain the importance of testing of a DRP, and the frequency of testing a DRP an
organization.
Section –B
Answer any two of the following questions. ( 9 marks)
Section –C
Answer the following question. ( 12 marks)