Nile University
School of Business Administration
CORPORATE
GOVERNANCE
Dr. Yasser Elsamadisy
Module 05
Risk Management
Definitions of Risk
The effect of uncertainty on
objectives, and the effect could be
a positive or negative deviation
from what is expected. ISO 31000 Opportunities Business
Positive risks Objectives
Threats
The possibility that events will Negative risks
occur and affect the achievement
of strategy and business
objectives. COSO ERM
An uncertain event or condition Current
that, if it occurs, has a positive or State
a negative effect on one or more
project’s objectives.
Project Management Institute
Corporate Governance - Dr. Yasser Elsamadisy 2
Categories of Risk according to Impact
Compliance Strategic
Compliance risks may arise from the Strategic risks are associated with
ineffective or inefficient means of macro-economics and politics that
evidencing compliance legal rules may affect long term plan and
and regulations e.g. Health & Safety, competitiveness. It affects strategy
Environment, Employment, selection and deployment – e.g.
International Trade, etc. investment in alternative industries
and technologies.
Operational Financial
Operational risks arising during Financing involves risks. For
execution of business functions example inadequate financial
to achieve business objectives. appraisal and monitoring of
It may arise from people, performance may result in
process, equipment or inefficient allocation of available
technology involved in financial resources and poor
operations. financial return.
Corporate Governance - Dr. Yasser Elsamadisy 3
Strategic Risks
Competition Risk
Reputation Risk
Macroeconomy Risks
Geopolitical Risks
Change Risks
Governance & Regulations Risks
Corporate Governance - Dr. Yasser Elsamadisy 4
Operational Risks
Human Resources Risk
Technology Risk
Business Process Risks
Business Disruption Risks
Corporate Governance - Dr. Yasser Elsamadisy 5
Financial Risks
Liquidity Risk
Credit Risk
Interest Rate Risks
Exchange Rate Risks
Commodity Risks
Equity Price Risks
Corporate Governance - Dr. Yasser Elsamadisy 6
Compliance Risks
Corruption Risk
Health & Safety Risk
Environmental Risks
Quality Risks
Privacy Breach Risks
Corporate Governance - Dr. Yasser Elsamadisy 7
Risk Management Process
Scope, Context &
Criteria
Communication & Consultation
Risk Assessment
Monitoring & Review
Identify
Analyze
Evaluate
Risk Treatment
Recording & Reporting
Corporate Governance - Dr. Yasser Elsamadisy 8
1. Planning for Risk Management
Process of defining how to conduct risk
management activities:
q Risk management policy
q Risk management organization
q Methodology
q Risk management process
q Frequency of risk management activities
q Budget / Reserves
q Risk Categories
q Risk Criteria
q Tools & Techniques
q Definition of Risk Factors probability and impact
q Reporting Formats & Tracking
Corporate Governance - Dr. Yasser Elsamadisy 9
2. Risk Organization
Board of
Directors
Internal
Auditor
Top
Management
CRO / ERM
Manager
Risk Risk Risk Risk Risk
Champion Champion Champion Champion Champion
Risk Owner Risk Owner Risk Owner Risk Owner Risk Owner
Corporate Governance - Dr. Yasser Elsamadisy 10
3. Organizational Context
Macro
The external environment consists of
all outside influences impacting an Environment
organization.
Completitors
Micro
Economics
Environment Emerging
Policy and
Macro-Environment Regulation
Suppliers Firm Customers
Micro-Environment
Substitutes
Societal Disruptive
Trends Technology
The
Organiza
tion
Corporate Governance - Dr. Yasser Elsamadisy 11
4. Risk Appetite
q The degree of uncertainty that Top Management is willing to accept in the pursuit
of strategy achievement.
q Driven by perception, tolerance & other biases.
Risk Seeker:
Prefers an uncertain
outcome and may be
Risk Neutral: willing to pay a
Tolerance to risk is penalty to take a
proportional to the high risk.
Risk Averter: amount of money at
Not likely to take a stake.
risk that is
considered a high
risk.
Corporate Governance - Dr. Yasser Elsamadisy 12
5. Risk Identification
Facilitated Sessions to identify as
many of the risks – that may affect
on business objectives – as
possible:
q Brainstorming.
q Delphi Technique.
q Cause and Effect Analysis.
q Interviews.
q SOWT Analysis.
What do you see here ?
Corporate Governance - Dr. Yasser Elsamadisy 13
Risk Register
Treatment Control Close
SN Risk Consequences Category P I RF Ownr Due
Options Measures out
Risk Risk Current
Control Probability
Description Causes
scale
Risk ID
Impact Risk
scale Impact
Corporate Governance - Dr. Yasser Elsamadisy 14
Selecting Risk Criteria
Low Liklihood Scale High
rare
Low Impact Scale High
The Risk Criteria should:
q reflect the organization's values, objectives and resources.
q be derived from legal and regulatory requirements
q be consistent with the organization's risk management policy
q be defined at the beginning of any risk management process and be continually reviewed
Corporate Governance - Dr. Yasser Elsamadisy 15
6. Risk Analysis
Corporate Governance - Dr. Yasser Elsamadisy 16
Qualitative Analysis
Risk Likelihood Impact Priority
Manpower Shortage High High 1st
Project Delay High Medium 2nd
Budget Cut Medium Medium 3rd
Machinery Procurement Low Medium 4th
High 3 3 6 9
Likelihood
Medium 2 2 4 6
Low 1 1 2 3
1 2 3
Low Medium High
Impact
Corporate Governance - Dr. Yasser Elsamadisy 17
Quantitative Analysis
Risk Likelihood Impact Priority
Manpower Shortage 75% $100k 1st
Project Delay 85% $55k 2nd
Budget Cut 35% $53k 3rd
Machinery Procurement 7% $57k 4th
– ٦٦
ﻋﺎﻟﻲ 3 3 6 9
٪١٠٠
Likelihood
– ٢١
ﻣﺗوﺳط2 2 4 6
٪٦٥
اﻗل ﻣن
ﻣﻧﺧﻔض1 1 2 3
٪٢٠
1 2 3
Impact
ﻣﻧﺧﻔض ﻣﺗوﺳط ﻋﺎﻟﻲ
اﻋﻠﻰ ﻣن
٢٥ اﻗل ﻣن٦٥-٢٥
اﻟف٦٥
اﻟف دوﻻر اﻟف دوﻻر
دوﻻر
Corporate Governance - Dr. Yasser Elsamadisy 18
7. Risk Evaluation
q Risk evaluation involves comparing the results of
the risk analysis with the established risk criteria
to determine where additional action is required.
This can lead to a decision to:
q do nothing further;
q consider risk treatment options;
q undertake further analysis to better
understand the risk;
q maintain existing controls;
q reconsider objectives.
q Decisions should take account of the wider
context and the actual and perceived
consequences to external and internal
stakeholders.
Corporate Governance - Dr. Yasser Elsamadisy 19
8. Risk Treatment
q Developing strategies to enhance opportunities and
reduce threats to the business objectives.
• Avoid
Downside Risks • Transfer
• Mitigate
• Exploit
Upside Risks • Share
• Enhance
• Passive
Acceptance
• Active
Corporate Governance - Dr. Yasser Elsamadisy 20
Downside Risk Options
• Eliminate the threats by removing the cause.
Avoid • Ex: Change the plan, site, method statement.
• Shifts the risk & its ownership to a third party against
premium cost.
Transfer
• Ex: Outsourcing specific task to a consultant or buy
insurance.
• Reduce the probability or impact of a potential risk
Mitigate event to an acceptable level.
• Ex: Simplifying business process, Prototype.
Corporate Governance - Dr. Yasser Elsamadisy 21
Upside Risk Options
• Make sure that a positive risk is fully realized.
Exploit • Ex: Make advantage of talented contractor to increase
quality. New legislation of incentives for taxes free
investment.
• Partner up with another party to give your team the
best chance of seizing the opportunity.
Share
• Ex: A manufacturer making JV with marketing firm to
capitalize on an opportunity.
• Increase the probability that an opportunity will occur.
Enhance • Ex: Opening new market.
Corporate Governance - Dr. Yasser Elsamadisy 22
Risk Acceptance Options
• Willing to accept the consequences of risk if it occur
Passive without preparing any plan.
• Ex: What it happens, it happens.
• Willing to accept & develop contingency reserves
(planning alternatives to deal with the risk if it occur).
Active
• Ex: Risk response strategy developed in advance
before things go wrong.
Corporate Governance - Dr. Yasser Elsamadisy 23
9. Risk Monitoring and Review
q “Risk Management Team” meetings on
regular basis (iterative).
q Monitor the pre-identified risks, new risks &
outdated risks
q Implement the risk response strategies
Inherent
Risk
q Track the residual risks & secondary risks
q Monitor risk triggers, risk register & risk
priorities Control Current
q Communicate to Management the risk
Measures Risk
status
q Re-assess the business assumptions &
determine their validity Residual
Treatment Risk
q Reserve Analysis: check contingency
reserves still appropriate & sufficient if
needed
q Evaluate the effectiveness of ERM process
by Internal Auditor.
Corporate Governance - Dr. Yasser Elsamadisy 24
End of Module
[Link] [Link]
Thank you