CONFIDENTIAL AND PROPRIETARY
Komanda Risk T·lim
July 22nd , 2025
Risk, Audit, and Daxili n·zar·t Komandas
2
McKinsey team
members
facilitating
today·s training
McKinsey team
Ugur Cem Yigit
T·r·fda·, Baku
Emre Bayram
Assosiasiya üzvü T·r·fda·, Istanbul
Gennadiy Babenko
Ekspert Assosiasiya üzvü T·r·fda·,
Doha
Temel Can Celik
Engagement Menecer,
Istanbul
Ezgi Kalemoglu
Assosiasiya üzvü, Istanbul
Javid Novruzov
M·sl·h·tçi, Istanbul
Achim Schlitter
ESG Senior Knowledge
Ekspert, Frankfurt
Sarah Schuckers
Kiber t·hlük·sizlik Ekspert,
Frankfurt
Beyim Jafarova
M·sl·h·tçi, Istanbul
3
Günd·m of
training
Duration
Details
·sas f·aliyy·tl·r
12.30-13.30
Nahar fasil·si
11.00-11.15
·
Aç·l·· qeydl·ri and overview of the session·s key
objectives and expected outcomes
Workshop Introduction
11.15-12.30
·
Müzakir· on the rising complexity of regulations and
the costs associated with non-compliance
·
Exploration of emerging threats and the key risks
expected to shape 2025
Why Risk ·dar·etm· matters
more than ever · avoiding costly
threats and navigating emerging risks
15.00-16:30
·
Collaborative problem-solving of a real-life risk
scenarios
·
Presentations of key insights and discussions on
findings
War Room Simulyasiya: Risk in
4
M·qs·dl·r of today·s Leadership T·lim session
What we want to achieve today?
·Stay vigilant to the key risks anticipated to shape the risk
environment in 2025
·Address rising regulatory complexity and costs to reduce the risk
of financial losses and reputational damage by fostering strong risk
awareness
·Understand the expanding risk landscape, including emerging threats
such as cybersecurity and ESG risks
Why Risk ·dar·etm·
matters more than ever?
·Understand the critical role of risk management framework in
establishing consistent, structured, and effective risk oversight across
organizations
·Explore key tools and methodologies that help identify, assess, and
mitigate risks proactively
Risk ·dar·etm·
Ç·rçiv·s and Al·tl·r
·Collaboratively navigate real-life risk scenarios to practice decision-
making in managing potential risk situations
·Discuss and reflect on group outcomes to reinforce shared learning
and identify practical steps for improving risk management
War Room Simulyasiya:
Risk in Action
5
Günd·m of
training
Duration
Details
·sas f·aliyy·tl·r
12.30-13.30
Nahar fasil·si
11.00-11.15
·
Aç·l·· qeydl·ri and overview of the session·s key
objectives and expected outcomes
Workshop Introduction
11.15-12.30
Why Risk ·dar·etm· matters
more than ever · avoiding costly
threats and navigating emerging risks
15.00-16:30
·
Collaborative problem-solving of a real-life risk
scenarios
·
Presentations of key insights and discussions on
findings
War Room Simulyasiya: Risk in
Action
16.30-17.00
·
Recap of key takeaways from the training and
simulation exercise
·
6
1.A. Survey: Understanding how
participants perceive key risks
3 minutes
Question
How to do
What are the top
three emerging
risks you believe
will be most
critical in 2025?
OR
·
Visit [Link]
and use below access code
below to join the survey:
2482 9116
·Scan the QR code to
access the survey
·Select the 3 risk trends
out of the trend list
·Press the button at the
bottom of the page to
submit
7
1.A. Risk identified by the WEF as the potentially most severe current
manifesting risks for 2025 are also on the top of other rankings
Source: Based on WEF Global Riskl·r Report 2025, Allianz Risk Barometer 2025, EIU One-click report: World, as of Dec 11th 2024, ECIIA Risk in Focus 2025, NC/Protiviti Executive P
Cyber espionage
14
Adverse outcomes of AI technologies
13
Involuntary migration or displacement
11
Lack of economic opportunity or unemployment
8
Economic downturn
6
Extreme weather events
2
Geoeconomic confrontation
3
Misinformation and disinformation
4
Societal polarization
5
Erosion of human rights and/or civic freedoms
9
Inequality
10
Natural resources shortages
12
Critical change to Earth systems
7
Out of 19
8
Key themes in the Risk domain
Risk has been an integral part of management practices in recent years
Source: RiskMinds International 2024, McKinsey analysis
Kiber t·hlük·sizlik risks
are on the rise
ESG risks are shaping
business expectations
A
B
Kiber t·hlük·sizlik risks are
increasing significantly as
rapid technological
advancements introduce
new vulnerabilities, making
organizations more
susceptible to sophisticated
cyberattacks
High-impact cyber incidents,
including data leaks and
ransomware attacks, can
cause severe operational
disruptions, financial losses,
and legal consequences
ESG risks are shaping
business practices as
stakeholders place greater
emphasis on environmental,
social, and governance factors
Social responsibility and
strong governance
9
1.A. Geopolitics has become top agenda for CEOs
alongside shifts in global norms and world order
1. US Department of Commerce, 2. Fortune 3. The World Bank,4. CSIS, 5. [Link], 6. Financial Times, 7. McKinsey CEO Excellence Survey
Geopolitics is a CEO top
3 priority7, with specific
questions top of mind
Which geopolitical scenarios
do I need to be prepared for?
How can I quicken my
company·s recovery time to
improve resilience?
What actions can I take to
win amidst greater volatility?
The dramatic increase in geopolitical instability in recent years has
significantly impacted geographies, industries, and companies
$1.6T
$100B
$1.7T
in assets moved out of the
UK by financial firms in 2020
to other financial hubs in the
EU ahead of Brexit (>10%
total assets in the UK banking
sector)2
in losses to European
companies in 2023 due to
Russia operations in Ukraine,
with over half of losses from
the energy and utility sector3
in estimated reduction of
10
1.A. Proactive management enables institutions to prepare, protect, and
propel amidst geopolitical volatility
1.
Bloomberg, 2. [Link] Chase, 3. SeaCube, 4. Aviva, 5. Economic Times, 6. Wall Street Advisor
Selected examples
Prepare
Protect
Enacting a clear communication strategy to keep
internal and external stakeholders informed about
potential geopolitical impacts (e.g., [Link]
integrating geopolitics into
strategy alignment2)
Exploring strategic exits or alternative
options, divesting, and existing joint
ventures for high-risk partnerships (e.g.,
Aviva multinational divesting insurance
subsidiaries in China4)
Diversifying sourcing to less risky
markets (e.g., Apple·s ·China plus
one· strategy, Google·s shift to
Vietnam6)
Increasing functional preparedness through
scenario planning, early warning systems, business
continuity (e.g., 400 staffers at Bridgewater focused
on mapping out how certain events will
impact markets1)
Developing contingency plans for
critical operational sites (e.g., SeaCube is
considering manufacturing to be set up
outside of China, despite favorability of
11
Key aspects of the growing regulatory and compliance challenges across industries
1.B. We observe increasing regulatory and compliance complexity
The regulatory landscape is
becoming increasingly
complex due to heightened
oversight from central
banks and regulators, with
new data submissions and
changes to existing
regulations being
implemented
General Trends in
T·nziml·yici Complexity
Financial institutions face
significant regulatory
complexity, with regulations
like MiFID II, CRR, CRD IV,
and GDPR increasing the
burden since 2014
Export control and supply
chain environments are
becoming more intricate due
to expanding lists of restricted
products
Sector-Specific
Challenges
Uy·unluq functions are
evolving and becoming more
specialized due to complex
regulations and financial
12
June 2022
Oct 2022
Mar 2023
Feb 2023
June 2024
Mar 2024
1.C. Operational risks in industry has become costly for companies with
financial and reputational impact
Source: Press search
NON-EXHAUSTIVE
2022
2023
2024
Financial impact:
While precise damages
aren't public, port closure
and loss of export likely
resulted in tens of millions
USD in losses
Reputational impact:
Jordan·s handling of
hazardous materials came
under intense regulatory and
international scrutiny
A 25-ton chlorine
container dropped onto a
ship, rupturing and releasing
toxic gas across the port of
Aqaba
A Norfolk Southern freight
13
1.C. Case Example: Negligence of proper equipment
inspection caused PG&E significant financial losses
and reputational damage
Effective risk awareness could
have enabled earlier
identification of aging
infrastructure vulnerabilities
and high wildfire risk areas,
allowing PG&E to implement
proactive measures to prevent
or significantly reduce the
impact of the disaster
Key takeaway
$25.5 Bn+
financial loss in wildfire
liabilities
84
deaths and severe
reputational and operational
damages
PG&E, a major utility provider in California, was responsible for the 2018 Camp Fire·the deadliest and most
destructive wildfire in California·s history. The fire was sparked by a nearly century-old transmission line that failed
due to lack of proper inspection and maintenance. PG&E neglected to replace aging components, assess fire
risks, and manage vegetation in high-risk areas.
Reputational Risk: Severe public backlash and loss of stakeholder trust due to perceived negligence and failure to
prioritize safety
Public Safety & Disaster Risk: Catastrophic loss of life and widespread destruction, highlighting major gaps in safety
protocols and emergency preparedness
Operational Risk (Distribution): Significant disruption to electricity distribution operations, resulting in financial
losses, service outages, and long-term infrastructure damage.
14
1.C. Case Example: Zero accident program
succeeded in reducing work accident rate by 52%
Awareness of work accident
risk encouraged PLN to put
proactive safety measure by
implementing ·Zero Accident·
principle. This initiative
emphasized prevention and
strict safety protocols, leading
to a significant and sustained
reduction in work-related
incidents
Key takeaway
PLN, Indonesia·s state-owned electricity company, successfully implemented a "Zero Accident" program aimed at
improving workplace safety across its operations. As a result of this initiative, the company achieved a 52%
reduction in its work accident frequency rate between 2019 and 2022. The program focused on enhancing safety
culture, increasing employee awareness, conducting regular training, and enforcing strict compliance with safety
protocols
People Risk: Creating and maintaining a safe work environment reduces workplace accidents, which helps increase
employee satisfaction and retention
Reputational Risk: By prioritizing safety and successfully reducing accidents, the organization prevents damage to
its public image
Disasters and Public Safety Risk: Proactively managing workplace safety mitigates the risk of serious incidents that
could result in injury, loss of life, or threats to employee wellbeing
·There are many safety variables. But in the end, it all
comes down to how we instill awareness, discipline,
and strong individual capabilities within every
member of the organization· · Darmawan Prasodjo
Relevant risks
Description
15
Source: McKinsey Risk & Resilience Practice
1.C. Risk-led
continuous
transformation
of operating
model
In an effort of continuous
transformation of its operating
model, a global automotive
OEM has over the last year
doubled down on its supply
chain resilience leveraging AI-
based analytics and data for
financial foresight and
enhancing risk and resilience
capabilities in its business units
Journey over 1+ year
Developed a taxonomy of >40
risks, defined a risk workflow
and designed a KPI
dashboard
Leveraged data and analytics
to build smart AI models to
provide high-supplier risk
alerts, early warning KPIs,
propose mitigating actions, and
ongoing monitoring
Rolled out advanced analytics
tools and provided training to
>99% of procurement and risk
16
Key themes in the Risk domain
Risk has been an integral part of management practices in recent years
Source: RiskMinds International 2024, McKinsey analysis
Kiber t·hlük·sizlik risks
are on the rise
ESG risks are shaping
business expectations
A
B
Kiber t·hlük·sizlik risks are
increasing significantly as
rapid technological
advancements introduce
new vulnerabilities, making
organizations more
susceptible to sophisticated
cyberattacks
High-impact cyber incidents,
including data leaks and
ransomware attacks, can
cause severe operational
disruptions, financial losses,
and legal consequences
ESG risks are shaping
business practices as
stakeholders place greater
emphasis on environmental,
social, and governance factors
Social responsibility and
strong governance
17
2. Institutions
are facing a
large number of
idiosyncratic
and systemic
risks
Companies are facing
unprecedented levels of
emerging risks1
1.
Non-exhaustive
Financial risks
e.g., credit risk affecting a company·s
profitability
Geopolitical risks
e.g., geopolitical conflicts have led to
economic disruptions and downturn,
logistics challenges
Supply chain risks
e.g., shortage or lack of access to
raw materials across key industries
leading to outages/cost increases
B. ESG risks
e.g., physical (wildfires, water
scarcity etc.) and transition risks
(climate regulations) triggering re-
allocation of capital to green
initiatives (mobility, etc.)
Labor supply risks
e.g., staff and key talent shortages
18
2.A. Kiber t·hlük·sizlik is playing an increasingly critical role for
organizations
Source: Wombat Security: New Research Confirms Security Awareness T·lim Measurably Reduces Cyber Security Risk; CSO Online: "Does security
awareness training even work?·; SANS. Encouraging the people in your organization to make safer cyber decisions requires dedicated brainpower to pull off,
Cyber security is becoming a top priority for
organizations worldwide, emerging as one of the highest-
risk areas in the global risk landscape
To deal with this, organizations are increasing
investment in cybersecurity, strengthening their threat-
detection and response plans, and developing
legislations to tackle this
concern
~300%
increase in reported
cybercrimes by the FBI
79%
of global organizations
have experienced a
cyberattack in 2024
~90%
of companies reported
an increase in
cyberattacks over the
the past 3 years
$9.5Tn
2024 total cybercrime
costs
19
2.A. Kiber t·hlük·sizlik holds its top place in the Risk in
Focus 2025 survey
3,544 responses from CAEs covering all sectors and industries
Source: European Confederation of Institutes of Internal Auditing · Risk in Focus 2025
73%
51%
49%
39%
38%
32%
31%
30%
25%
24%
Kiber t·hlük·sizlik and data security
Business continuity, crisis management and disasters response
Human capital, diversity and talent management
Digital disruption, new technology and AI
Change in laws and regulations
Market changes
Financial, liquidity, and insolvency risks
Geopolitical and macroeconomic uncertainty
Organisational governance and corporate reporting
Organizational culture
Score higher than in 2024
No change from 2024
Score lower than in 2024
The top 10 risks for Risk in Focus 2025 of Chief Audit Executives (CAEs)
%s indicating those CAEs that ranked each a top five risk
Report findings:
20
2.A. Past incidents of data breaches and cyberattacks underscore the
rising criticality of cybersecurity risks
T·nziml·yici Risk
T·nziml·yici Risk
380,000 customer
records stolen leading to
£183 million fine from EU
Data leakage
383 million customer
sensitive account details
exposed including credit
cards and passports
Data leakage
Sensitive data on more
than 100 million
customers and credit
applicants
Fraud
Loses $10 Million in
SWIFT-Related Attack
Third party risk
40 million credit card
records and 70 million
customer PII records
stolen
Third party risk
$300 million in lost profits
caused by network-wide
outage
Fraud
21
2.A. ... yet severe losses can be
avoided with effective
cybersecurity risk management
Source: Press search
Risk mitigation
Proper mitigation measure in
place before the attack to
minimize impacts
Risk prioritization
Well aligned prioritization of risks
across organization
What good risk management looks like
Risk identification
Early detection of the
cyberattack due to proactive
risks identification
Understanding of the importance
to monitor cybersecurity due to
proper risk quantification and
assessment
Risk quantification
A nation-wide cyberattack in the United States that targeted
user data in utility companies
Duke Energy was able to detect and contain the cyberattack
before it could cause any significant damage due to their
good risk management protocols, such as regular assessment,
continuous monitoring, and proper training for all employees
Loss impact
Description
22
2.A. Key questions organizations should ask to proactively address
cybersecurity risk
How cyber-resilient is our organization? How well-prepared are we to manage a cyber attack? Who would we
call if we were under attack?
Where are we most vulnerable to cyber attacks? Are there any areas in which we don·t have strong
monitoring and detection visibility?
Where are we investing too much or too little in cybersecurity?
How do we protect the data required for our digital products and services? How do we ensure its availability?
How have we embedded security into our go-to-market to catch up with competitors?
How can we upskill our workforce towards security natives?
How do we measure the effectiveness of cyber risk reduction?
1
2
3
5
4
6
7
23
2.B. The momentum toward ESG is rapidly accelerating over the past
decade
Source: 2024, McKinsey article: Does ESG really matter · And why?
>5000
companies have made
net-zero commitments
as part of the united
nations· ·race to zero·
campaign
11x
the amount inflows
into sustainable funds
grew from 2018 ($5bn)
to 2024 (~$55bn)
5x
growth in internet
searches for ESG since
2019, as searches for
·CSR· have declined
90%+
of S&P 500 companies
now publish ESG
reports, as do ~70% of
Russell 1000 companies
What is at stake from failing to act on ESG has never been more prevalent: lost customers, CO2
taxes, fines from regulators, plastic taxes, missed price premia opportunities, missed portfolio shift
opportunities, higher energy/water/waste/raw materials costs, and lower employee productivity
24
2.B. ESG refers to the integration of Environmental, Social and
Governance factors into core processes and decision-making
Detailed next
Energy management
and GHG emissions
Land use and other
ecological impacts
Water and
wastewater
management
Circularity of
products and services
Environmental
Fair labour practices
(incl. health/safety,
diversity and
engagement)
Community relations
(incl. giveback
initiatives, local
job creation)
Customer relations
(incl. data security and
product safety)
Aging population and
reskilling revolution
Social
Business ethics
(i.e., anti-bribery and
corruption codes)
25
Non-financial risks
2.B. Environmental risks could impact range of risk types, with
implications also extended to non-financial aspects
Illustrative example
Impact of climate risk
A company could be penalized for not properly
revealing its investments in high-emission assets and
experience public disapproval for greenwashing
Financial penalties or revenue impacts
due to non-compliance with climate-related
disclosures or regulations
Reputational
risk
A manufacturing company·s long-term growth plan could
be jeopardized if it fails to account for the transition to
renewable energy sources
Misaligned strategies with climate realities
can lead to a long-term reduction
in activities and profits
Strategic
risk
A bank might see a decrease in certain revenue
streams if it is slow to adapt to new green finance
regulations
The risk of sanctions due to non-compliance
with evolving climate-related regulations
T·nziml·yici
risk
Misestimating the impact of rising sea levels could lead
to continued investment in potentially stranded coastal
26
1.
nr. of vehicles potentially equipped w. affected components - outside-in analysis of third parties
SOURCE: EPA (Environmental Protection Agency), DOJ (Department of Justice), European Commission Rulings, Company Press Releases, Capital IQ, IHS
Automotive, McKinsey Komanda Analysis
2.B. Non-compliance of environmental regulations can create costs of
several billion dollars and can have significant reputational damage
2
1.46mn
571k
101k
625k
1.68mn1
Number of affected
vehicles, estimated
units
Misconduct
Total estimated
financial impact,
global, in $bn
NOT EXHAUSTIVE, OUTSIDE-IN ANALYSIS
1.0
0.6
0.8
25.8
3.3
Key misconduct case
Voluntary Probe -
Emissions
Emissions
Misconduct · Defeat
27
September 2015, Germany (Europe)
2.B. Example: Volkswagen emission misconduct case
·Volkswagen agreed to ·
· Pay $2.8 billion criminal penalty due to its
deceptive practices
· Civil settlements that totalled ~$1.45 billion to
address claims from US owners, environmental
regulators, states, and dealers
· The recall and fixing of affected vehicles, and an
extensive buyback program for many car models
·VW renewed its focus on developing electric vehicles,
with multibillion-dollar investments announced to
rebuild its brand and address environmental
concerns
Volkswagen intentionally developed and
deployed "defeat devices" in over 11 million diesel-
engine vehicles spanning multiple brands like Audi
and Porsche
1
These software devices detected emissions
testing conditions and adjusted performance to
pass them deceitfully
2
Outside of these testing conditions, the vehicles
emitted nitrogen oxides at levels that far exceeded
EPA standards, posing environmental and health
risks
3
The exposure of the deception caused significant
global uproar, deeply damaging Volkswagen's
McKinsey & Company
28
Q&A
29
Günd·m of
training
Duration
Details
·sas f·aliyy·tl·r
12.30-13.30
Nahar fasil·si
11.00-11.15
·
Aç·l·· qeydl·ri and overview of the session·s key
objectives and expected outcomes
Workshop Introduction
15.00-16:30
·
Collaborative problem-solving of a real-life risk
scenarios
·
Presentations of key insights and discussions on
findings
War Room Simulyasiya: Risk in
Action
16.30-17.00
·
Recap of key takeaways from the training and
simulation exercise
·
Reflections on insights gained and key learning
moments
Yekun v· ba·lan··
14:45-15.00
30
We will meet again at 13:30
Lunch break
30
1 hour
31
Günd·m of
training
Duration
Details
·sas f·aliyy·tl·r
11.00-11.15
·
Aç·l·· qeydl·ri and overview of the session·s key
objectives and expected outcomes
Workshop Introduction
15.00-16:30
·
Collaborative problem-solving of a real-life risk
scenarios
·
Presentations of key insights and discussions on
findings
War Room Simulyasiya: Risk in
Action
16.30-17.00
·
Recap of key takeaways from the training and
simulation exercise
·
Reflections on insights gained and key learning
moments
Yekun v· ba·lan··
14:45-15.00
Fasil·
13.30-14.45
32
Risk management framework can be structured around five key sub-
processes
Risk mitigation
Risk monitoring through
dashboards
Risk escalation and
reporting
Risk identification
Risk appetite setting
Risk ·dar·etm· Ç·rçiv·
Source: McKinsey analysis
·
Identification and
grouping of risks via a
defined taxonomy,
enabling a structured and
comprehensive view of
risk types
·
Prioritization of KRIs by
magnitude, aligned with
taxonomy and tailored to
relevant monitoring
audiences
·
Documentation of risks
with impact, likelihood,
ownership, and monitoring
details in a structured
register for tracking
33
A | A Risk taxonomy should be in place and disseminated across the
organization to serve as a common risk language
Source: McKinsey Risk Practice
Additional unique risks for each SC
Example of template risk taxonomy
Designing the risk
taxonomy
encompasses a few
principles·
L1
L2
Operational
T·nziml·yici &
compliance
Supply
chain and
procurement
Market &
commercial
Strategic &
reputational
Financial
Human
capital
Environ-
mental
Technology
& Data
1
2
34
A| A structured risk assessment and prioritization approach should be
established, leveraging KRIs and aligned with the RAS
Selection and prioritization of KRIs
Map at least one KRI to each Level 3 risk,
with multiple KRIs for high-impact risks
Assign KRIs to Riskl·r
1
Refine KRIs and ensure each KRI is
measurable, reliable, and aligned with the
risk it represents
Validate KRIs
2
Classify KRIs into three tiers:
·
Group 1: For RAS tracking and top
management oversight
·
Group 2: For regular monitoring by
the Risk team
·
Group 3: For medium-term monitoring
by functional teams
Group KRIs
3
Finalize key metric set for RAS
4
Risk hierarchy
Levels
3
2
35
A | Riskl·r should be classified based on their potential impact and
likelihood, and documented in a comprehensive risk register
Medium-High
Medium-Low
Low
High
Medium-Low
Medium-High
Low
High
Medium-High
Medium-Low
Low
High
Medium-High
Medium-Low
Low
High
Medium-Low
Low
High
Medium-High
Low
Medium-Low
Medium-High
High
Likelihood
Identify risk score
Granular perspective · All risks
·
36
B | An effective RAS is shaped through a four-step approach that
ensures risk appetite is clearly defined, measurable, and actionable
ILLUSTRATIVE
Stage
Description
Set risk levels and articulate risk appetite statements
Determine current
exposure
Decide desired
risk level
Select thresholds
Finalized
statements
List the current
values for selected
KRI·s on L3 risks
Determine risk
levels on the
selected L3
Risk/KRIs
Assign a threshold
for the KRIs
Develop
statements that
apply quantitative
and qualitative
elements
37
B | Breach type can be identified through the quantitative RAS
representation
Current value
Financial
Risk
Credit &
liquidity
Liquidity
Coverage
Ratio
25%
L2 Risk
KRI
L1 Risk
Current
Value
Shortlisted KRI
Cash flow
L3 Risk
Preferred risk levels typically covers a range and is
represented by green colour
Low
Medium
Zero
High
Risk levels
ILLUSTRATIVE
100%
24%
50%
38
Risk management framework can be structured around five key sub-
processes
Risk mitigation
Risk monitoring through
dashboards
Risk escalation and
reporting
Risk identification
Risk appetite setting
Risk ·dar·etm· Ç·rçiv·
Source: McKinsey analysis
·
Identification and
grouping of risks via a
defined taxonomy,
enabling a structured and
comprehensive view of
risk types
·
Prioritization of KRIs by
magnitude, aligned with
taxonomy and tailored to
relevant monitoring
audiences
·
Documentation of risks
with impact, likelihood,
ownership, and monitoring
details in a structured
register for tracking
39
C | Risk dashboards deliver significant value by enhancing risk
monitoring capabilities
Enhanced trans-
parency and visibility
Automated data
integration with high-
frequency updates
Early warning
mechanism
Improved decision-
making
Holistic risk
oversight
Provide regular visibility
and transparency by
delivering continuous,
clear insight into the
organization·s risk
exposure, enabling
effective governance
and accountability
Streamline the
consolidation of data
from multiple sources,
ensuring up-to-date, and
consistent information
with frequent updates
Highlight emerging risks
or deviations from risk
appetite thresholds,
40
C | Example: ·cmal Dashboard
Key risks over the past 6 quarters
Business metrics over the past 6 quarters
·cmal
Key risks and
metrics
Admin
Key risks and
metrics
Time periods
Supervised Company overview dashboard
2025 Q2
Target
8
Outside tolerance
3
Within tolerance
5
Key highlights
·The report highlights both
current and historical risk
status, enabling the RMC to
track shifts in risk exposure
over the last six quarters
·By combining key risks
and business metrics
insights, the report equips
the SC RMC with a
comprehensive view of the
company·s overall risk
41
Risk
dashboard
·cmal
Admin
C | Example: Key Riskl·r and Metrics Dashboard
Key risks and business metrics dashboard
2025 Q2
Key highlights
·The dashboard offers
comprehensive monitoring
of KRIs, capturing both the
current values and trends
over the past 12 months
(clicable for detailed
analysis) to identify patterns
and shifts in risk exposure
·Each KRI is evaluated
against defined
thresholds, signaling
whether it falls within
acceptable risk limits
·Additionally, it presents
forecasts for the coming
month, supporting proactive
risk management decisions
ILLUSTRATIVE
NOT EXHAUSTIVE
Key risks and
metrics
Status
42
Risk management framework can be structured around five key sub-
processes
Risk mitigation
Risk monitoring through
dashboards
Risk escalation and
reporting
Risk identification
Risk appetite setting
Risk ·dar·etm· Ç·rçiv·
Source: McKinsey analysis
·
Identification and
grouping of risks via a
defined taxonomy,
enabling a structured and
comprehensive view of
risk types
·
Prioritization of KRIs by
magnitude, aligned with
taxonomy and tailored to
relevant monitoring
audiences
·
Documentation of risks
with impact, likelihood,
ownership, and monitoring
details in a structured
register for tracking
43
D| For each risk, organizations can select the most suitable risk
mitigation approach for them
Deep dive next
·and execution (·how to do·)
Key decision-stages for mitigation
Selected option (illustrative)
Decision-making points
Decide on·
Identify
risks
Risk 1
Risk 2
·
·strategy (·what to do·)·
Select risk mitigation
approach
Reduce
Transfer
Avoid
Evaluate
mitigation options
·
Mitigation option 1
Mitigation option 2
Mitigation option 3
Action plan 1
Action plan 2
Implement
mitigation action
Do not
44
D| There are 3 potential risk mitigation actions that can lessen the impact
and / or likelihood of each risk
Effective Inherent Risk
(pre-treatment)
Possible Residual Risk
(post-treatment)
Typical outcome
(illustrative):
Risk treatment:
Avoid
Transfer
Reduce
Risk responsibility:
N/A · risk avoided
Joint / shared with external
Internal / self-owned
Description:
Fully eliminate risk, including foregoing
any current / potential upside from
maintaining risk level
Moving some of the risks to other entities
(e.g., third-parties, partners) who can control
or absorb them
Directly lowering the impact and / or
likelihood of risk to the organization
Example:
·
Divestment
·
Significantly change operating model /
45
Risk management framework can be structured around five key sub-
processes
Risk mitigation
Risk monitoring through
dashboards
Risk escalation and
reporting
Risk identification
Risk appetite setting
Risk ·dar·etm· Ç·rçiv·
Source: McKinsey analysis
·
Identification and
grouping of risks via a
defined taxonomy,
enabling a structured and
comprehensive view of
risk types
·
Prioritization of KRIs by
magnitude, aligned with
taxonomy and tailored to
relevant monitoring
audiences
·
Documentation of risks
with impact, likelihood,
ownership, and monitoring
details in a structured
register for tracking
46
E | There should be multiple layers for structured escalation supported
by targeted reporting at each organizational level
3
6
10+
RMC report
Report
FO Risk
SC Board
Risk Divisions
Audience
Quarterly
Quarterly
Ongoing
Frequency
# of report pages
Audience
Family Office RMC
Supervised
Company RMC
Risk
function-level
governance
SC ·cmal Dashboard
SC Key Riskl·r and Metrics
Dashboard
SC Risk Register
Dashboard
Dashboard
FO ·cmal Dashboard
47
E | Effective and actionable risk reporting is conducted according to five
key design principles
Principles
Description
Customized reports that address the unique needs of key stakeholders, such as the
Family Office RMC and Supervised Company RMC, emphasizing most relevant /
material risks
1
Relevance and
prioritization
Accurate and consistent reports that maintain a specific and consistent content
presentation to enable reliable comparisons throughout different reporting cycles and
allow for confidence in decision-making
2
Accuracy and
consistency
Documented actions and decisions made across key meetings (e.g., Supervised
Company RMC, Risk Divisions, etc.) with clear task owners to ensure accountability
and transparency
3
Clear
actionability
Organized report format that structures agenda items, findings / recommendations,
actions, and supporting material to simplify and focus discussions
4
Structured
documentation
Concise recommendations, supported by risk analyses, suggesting risk mitigation
and remediation actions in line with the organization's strategic goals and risk appetite
Focused
48
Risk report sections
Action log from
previous meeting
1
Recap of key risks reported, treatment actions carried out,
and status of risks since last risk report
Executive
summary
2
Summary of prioritized risks and key risk-related updates
that need to be reported to RMC
Risk
transformation
updates
5
·cmal of ongoing initiatives such as transformation
projects that strengthen risk capabilities and monitoring
Forward looking
perspectives and
insights
Summary insights or perspectives on topics that can further
enhance risk management and potential mitigation actions
E | Risk reports can typically be structured around five key sections
Key characteristics of the
RMC risk reports
Concise risk
reporting with
tailored content
Quarterly submission
and presentation in
49
E | Example: Prioritised board-level KRIs list in the RMC report
Key risk indicators (KRIs)
Residual risk change vs. last report:
Breach
Warning
Status (KRI vs. threshold):
Lower
Higher
Similar
ILLUSTRATIVE EXAMPLE
Financial
L1 Risk
Current
value
Strategic
Credit &
liquidity risk
Investment
L2 Risk
Main KRI
Rationale /
Explanation
Status
Change vs.
previous quarter
Warning
limit
Breach
limit
Cash flow
50
Günd·m of
training
Duration
Details
·sas f·aliyy·tl·r
11.00-11.15
·
Aç·l·· qeydl·ri and overview of the session·s key
objectives and expected outcomes
Workshop Introduction
15.00-16:30
·
Collaborative problem-solving of a real-life risk
scenarios
·
Presentations of key insights and discussions on
findings
War Room Simulyasiya: Risk in
Action
16.30-17.00
·
Recap of key takeaways from the training and
simulation exercise
·
Reflections on insights gained and key learning
moments
Yekun v· ba·lan··
14:45-15.00
Fasil·
13.30-14.45
51
We will meet again at 15:00
Coffee break
51
15 minutes
52
Günd·m of
training
Duration
Details
·sas f·aliyy·tl·r
11.00-11.15
·
Aç·l·· qeydl·ri and overview of the session·s key
objectives and expected outcomes
Workshop Introduction
15.00-16:30
War Room Simulyasiya: Risk in
Action
16.30-17.00
·
Recap of key takeaways from the training and
simulation exercise
·
Reflections on insights gained and key learning
moments
Yekun v· ba·lan··
13.30-14.45
·
·cmal of core components of effective risk
management frameworks
·
Practical tools and techniques used to identify, assess,
monitor, and escalate risks
Risk ·dar·etm· Ç·rçiv·s and
Al·tl·r (incl., Q&A session)
53
War Room Simulyasiya:
Risk in Action
Introducing the objective
and structure of the real-
life risk simulation
exercise
10 mins
Analyzing and working
through real-life risk
scenarios in groups
50 mins
30 mins
Sharing group
findings and cross-
team reflections
53
90 minutes
54
Günd·m of
training
Duration
Details
·sas f·aliyy·tl·r
11.00-11.15
·
Aç·l·· qeydl·ri and overview of the session·s key
objectives and expected outcomes
Workshop Introduction
13.30-14.45
·
·cmal of core components of effective risk
management frameworks
·
Practical tools and techniques used to identify, assess,
monitor, and escalate risks
Risk ·dar·etm· Ç·rçiv·s and
Al·tl·r (incl., Q&A session)
11.15-12.30
·
Müzakir· on the rising complexity of regulations and
the costs associated with non-compliance
·
Exploration of emerging threats and the key risks
expected to shape 2025
Why Risk ·dar·etm· matters
more than ever · avoiding costly
threats and navigating emerging risks
12.30-13.30
55
55
Yekun v· ba·lan··
·Recap of key takeaways from
today·s training and simulation
·Personal reflection: ·One specific
action I commit to taking to mitigate
risks going forward·
30 minutes
56
Thank you all
for your
contribution!