2/2/2020
To be covered
• Introduction risk
• Major risk classes
• Categories of risk and how they impact org
• Risk mitigation strategies
B6: MGT, GOVERNANCE AND • Risk management
ETHICS • Risk matrix
• COSO framework of ERM
• Elements of ERM
Topic: Risk and risk management • Components of COSO framework of ERM
• Techniques for assessment of risks under the ERM:
• Responsibility regarding risk
• Risk monitoring methodologies
• Stakeholders impacted by business risks
Compiled by EMMA_CHRIS 1 Compiled by EMMA_CHRIS 2
Introduction risk and risk management Major classes risks
• Business risk refers to the possibility of an organisation not
• Risk is the possibility that actual outcomes may be achieving its desired amount of profit or targeted rate of
different from those expected. return on investment.
• Risk can also be defined as the possibility of not • business risks can be broadly classified as internal risks and
achieving org objectives external risks.
• Risk is a combination of the probability of an event and • Internal business risks -events occurring within an
its consequences. organization. Causes
i. Technological factors-unforeseen changes in the
• All orgs operates in a risk environment technology
• Managers can be categorised basing on their risk ii. Human causes negligence and dishonesty, theft,
appetite/attitude(amunt of risk that they are willing to industrial strikes, incompetence
take or bear iii. Data integrity
– Risk lovers-goes for high risk expecting high returns iv. Physical factors-failure of plant and equipment, theft,
– Risk averse-avoids risks leakages and fire
Compiled by EMMA_CHRIS 3 Compiled by EMMA_CHRIS 4
Major classes risks Major classes risks
• Strategic risk -risk related to key decisions of the org. i.e.
fundamental strategic business objectives will fail to be
• External business risks associated with events achieved
occurring outside an organization. Arises from external • Responsibility for strategic risk rests with the BoD
factors such as • Examples of strategic risks
i. Competitors i. Investors may refuse to invest any more in the company.
ii. Suppliers ii. A competitor introduces a new product
iii. Customers iii. A bid to takeover the company emerges.
iv. The company’s primary product is getting old
iv. Political
v. Consumer taste undergoes a period of fundamental
v. Economic environment-inflation, Exchange rates, change.
Interest rates, Fiscal policies, Monetary policies
Compiled by EMMA_CHRIS 5 Compiled by EMMA_CHRIS 6
1
2/2/2020
Major classes risks Major classes risks
Factors contributing to the strategic risk • Operational risk is defined as the risk of loss
i. types of industry within which the business operates resulting from inadequate or failed processes,
ii. Competitors’ strategy and new products coming into people or systems or from external events.
the market • Existence of this risk can limit the chances of an
iii. Political state of the economy org attaining operational efficiency.
iv. Capacity of the company to deal with dynamic Examples
environment
• Liquidity problems and customer defaults
v. Fluctuating prices of the key inputs
vi. The company readiness to adapt to changing
• Customer complains on delayed dispatches
technologies • IT system being hacked
Compiled by EMMA_CHRIS 7 Compiled by EMMA_CHRIS 8
categories of risk and how they impact
Major classes risks organisations objectives
Risk Explanation Impact on org objectives
• Compliance risk non-conformance with or 1. Market risk that the market impact profitability,
violations of prescribed laws, regulations, rules, risk prices of securities will liquidity and availability of
policies, procedures and ethical guidelines. change adversely finance.
• Subcategories of compliance risks 2. Credit
the risk that receivables adversely affect cash flow
1. Reporting-possible misstatement in external will not meet their and may require additional
risk
communications to stakeholders obligations on time. financing.
2. Risk of material misstatement- chances that the FS 3. affect credit ratings and
non-availability of cash
the are materially misstated. Liquidity the ability to raise future
or cash equivalents
risk finance.
3. Legal, regulatory and ethical compliance- chances
that prescribed laws or regulations may be 4. risk that technology will Adversely affects the org if
breached Technolog change and will is not updated,
ical risk adversely affect the org (competition, cost)
Compiled by EMMA_CHRIS 9 Compiled by EMMA_CHRIS 10
categories of risk and how they impact
organisations objectives Risk management
Risk Explanation Impact on org objectives
5. Legal risk arises when new laws, • A risk management involves identifying risks, assessing
may attract fines, penalties their impact and likelihood of happening and taking
stds, codes®ulations
and damage to reputation. measures to avoid or minimize risks once they happen
are introduced
6. Health,
Elements of risk management process are:
safety and threats to people and fines, penalties and 1. Risk identification-usually through risk mapping
environme the environment damage to reputation 2. Risk assessment-prob of occurrence and max loss (impact
ntal risk and likelyhood)
7. may cause both mkt share 3. Risk evaluation – assigning weight in terms of high, low or
Damage to reputation medium for both impact and likelyhood
Reputatio and share
arising from all risks
n risk price to fall. 4. Risk planning-policies ad procedures on how to deal with
certain future events
8. B’nes Has to do with honesty, has many consequences
5. Risk control and monitoring- an ongoing actual activity of
probity integrity and ultimately depending on the nature managing risk
risk the risk of fraud of the fraud.
Compiled by EMMA_CHRIS 11 Compiled by EMMA_CHRIS 12
2
2/2/2020
Risk Matrix
Risk management
• Used to asses the impact and probability of
Ways in which risk can be addressed and managed risks
by organisations.
1. Risk awareness at all levels
2. Embedding risk in an organisation's systems,
procedures, culture and values include risk
awareness in systems and procedures of the
entity
3. Spreading and diversifying risk eg transferring it
to insurance company
4. Risk avoidance, reduction, acceptance and
transference
Compiled by EMMA_CHRIS 13 Compiled by EMMA_CHRIS 14
Risk Matrix Risk mitigation strategies SARA
• Four main methods of dealing with risks
1. Sharing or transferring-insurance, joint
venture or outsourcing
2. Avoidance-discontinuing the service or
production
3. Reduction-reducing risk to appropriately low
levels through diversification, contracts etc
4. Acceptance or retention-getting prepared to
deal with concequences
Compiled by EMMA_CHRIS 15 Compiled by EMMA_CHRIS 16
COSO framework of ERM Elements of ERM
Enterprise risk management encompasses six elements
• the Committee of Sponsoring Organisations (COSO) 1. Aligning risk appetite and strategy: linking risk with
defines Enterprise risk management (ERM) as a return in decision-making
process, 2. Enhancing risk response decisions: rigorous selection
Effected by an entity’s BOD, mgt and other personnel, from avoidance, reduction, sharing and accepting risk
Applied in strategy setting and across the enterprise, 3. Reducing operational surprises and losses: through
Designed to identify potential events that may affect structured event identification and response
the entity and manage risk to be within its risk 4. Identifying and managing multiple and cross
appetite, and enterprise risks: assessing the myriad risks that
businesses face
To provide reasonable assurance regarding the 5. Seizing opportunities: through proactive positioning
achievement of entity objectives
6. Improving deployment of capital: obtaining robust risk
information to assess capital needs
Compiled by EMMA_CHRIS 17 Compiled by EMMA_CHRIS 18
3
2/2/2020
Components of COSO framework of ERM Techniques for assessment of risks under the ERM:
1. Internal environment-make people work under clear These techniques assist in assessing severity and the probability of
authority and responsibility risks
2. Objective setting-decisions must be linked to shareholders • Event inventories -generic list of events is used to identify the
common risks
risk appetite
• Internal analysis – experts and stakeholders provide the company
3. Event identification-seek to find +ve and –ve events that with required information
impacts strategy • Escalation or threshold triggers- events that require assessment or
4. Risk assessment immediate action
5. Risk response • Facilitated workshops and interviews-through discussions with
experience stakeholders.
6. Control activities-policies to ensure chosen risk responses
are carried out • Leading event indicators - conditions that lead to the occurrence of
certain events
7. Build information & control system and ensure info flow • Loss event data methodologies-trend analysis on data is performed
8. Monitoring-on going review • Process flow analysis- identification of entire process consisting of
9. Responsibility- everyone in org is resp for risk mgt inputs, tasks, responsibilities and output.
Compiled by EMMA_CHRIS 19 Compiled by EMMA_CHRIS 20
Responsibility regarding risk Responsibility regarding risk
Involves BoD, Management, Risk officer, Internal 2. Management is responsible for setting tune of
auditors and other personnel. org’s risk mgt process
1. Board of directors is responsible for overall – CEO should set risk management policies
functioning of the company as well as risk – Manager and leaders should be responsible for their
management units
• It is specifically responsibe for 3. Risk officer- is the head of Board’s risk
– Setting framework for risk management committee. Responsible for
– Defines and communicates ethical and intergrity stds 1. Ensuring implementation of risk mgt process
to mgt 2. Monitoring progress
– Reserves authority in key decisions 3. Assisitng other managers in reporting risk
– Overseeing ERM information
Compiled by EMMA_CHRIS 21 Compiled by EMMA_CHRIS 22
Responsibility regarding risk Responsibility regarding risk
4. Internal auditors-play an important role in 5. Other personnel - the responsibility of
the monitoring of enterprise risk everyone in an entity
management and the quality of performance – Should be in everyone’s JD
– Assist management and BoD or audit committee
– Recommend improvement to mgt’s enterprise risk
management process.
Compiled by EMMA_CHRIS 23 Compiled by EMMA_CHRIS 24
4
2/2/2020
Risk monitoring methodologies Risk monitoring methodologies
Includes risk committee, Risk manager and Risk auditing 2. Risk manager-is a member of the risk committee who is
1. A risk committee responsible to:
– identify the major risks i. provide overall leadership, vision and direction to the risk
committee
– assess and review the generic risks (market, liquidity,
reputation,) ii. guide the risk committee in setting up risk management
– create and increase the risk awareness policies
– ensure that sufficient risk management processes are in iii. implement the risk management policies
place iv. to create and improve risk awareness
– provide recommendations to the board on v. to assist in the identification of the risks and establish risk
• the risk appetite, identification tools
• risk capacity and vi. to monitor the implementation of the risk mitigation
• risk management strategies
Compiled by EMMA_CHRIS 25 Compiled by EMMA_CHRIS 26
Risk monitoring methodologies.. Risk monitoring methodologies
vi. maintaining adequate internal controls 3. Risk auditing - is when the organisation
vii. ensure that the entity complies with the risk undertakes an independent review and
rules applicable under relevant codes, assessment of the risks, controls and
regulations safeguards in an organisation.
viii. to report the above matters to management
and risk committee • External risk auditing occurs when a person
ix. to support the external auditors by providing from outside the organisation conducts risk
assurance of the risk management auditing.
x. to prepare a risk management policy statement, • Internal risk auditing occurs when risk
procedures, manual etc auditing is undertaken within the entity.
Compiled by EMMA_CHRIS 27 Compiled by EMMA_CHRIS 28
Risk monitoring methodologies Stakeholders impacted by business risks
Advantages of risk auditing 1. Directors and managers-performance related
• identification of the major risks pay
• assurance that the risk identification procedures in place 2. Employees-not receiving sufficient incentives or
• assessment of the impact of the risks loosing jobs
• assurance that proper risk management procedures are in 3. Shareholders-loosing their investment
• Suggestion of corrective action 4. Accounts payables- not receiving dues on
• recommendations the risk committee time/loosing business
• An external risk auditor is independent 5. Customers-not be supplied with quality
• External risk auditing (like external auditing) is a good products
practice
6. Communities and general public-
unemployment, health risk and safety risk
Compiled by EMMA_CHRIS 29 Compiled by EMMA_CHRIS 30
Best PDF Encryption Reviews
5