RISK MANAGEMENT PROCESS
Risk Management Process
ISO 31000 Risk Management Process
Risk Management Context
Communication and consultation process (with external
Risk Assessment Process
Monitoring and Review Process
Risk Response
stakeholders)
Risk Analysis
Risk Evaluation
Risk Response
Recording and Reporting
Process
COSO ERM:2017
Performance
• Identifies Risk — principle 10
• Assesses Severity of Risk — Principle 11
• Prioritizes Risks — Principle 12
• Implements Risk Response — Principle 13
• Develop Portfolio View — Principle 14
Risk Assessment
Learning outcomes
• describe the importance of risk assessment as a critically important stage in the risk management process;
• summarize the most common risk assessment techniques, plus the advantages and disadvantages of each technique, including SWOT;
• explain the importance of the long-term attitude of an organization to risk and how that affects the perception of risk;
• describe options for classifying risks according to the nature, source, timescale, impact and consequences of the risk;
• describe the importance of risk classification systems and describe the features of the established systems, including PESTLE, FIRM and the 4Ps;
• explain the attributes of each characteristic and illustrate by means of a risk matrix the nature and attributes of a risk in terms of likelihood and
magnitude;
• illustrate, by using a risk matrix, the risk attitude of an organization and the importance of the concept of the ‘universe of risk’;
• provide examples of the use of a risk matrix, including using it to indicate the dominant risk response in each quadrant (4Ts);
• describe the main components of loss control as loss prevention, damage limitation and cost containment, and provide practical examples;
• summarize the alternative approaches to defining the upside of risk and the application of these approaches for core processes.
Risk Assessment
1. Risk assessment considerations
2. Risk classification systems
3. Risk analysis and evaluation
4. Risk Response
5. Risk Control
Risk Assessment Considerations
Risk Assessment Considerations
Importance of risk assessment
Defined (British Standard BS 3100): “ as the overall process of risk identification, risk
analysis and risk evaluation”.
The purpose of risk assessment is to identify the significant risks that could impact the
selected feature.
It is only useful if the conclusions of the assessment are used to inform decisions and/or
to identify the appropriate risk responses for the type of risk under consideration.
Risk Assessment Considerations
Approaches to risk assessment
Sometimes risk assessment are undertaken by broad of directors as a top-down exercise.
RA can also be bottom-up approach by involving individual members of staff and local
departmental management.
Risk Assessment Considerations
Top-down risk assessment
Risk Assessment Considerations
Bottom-up risk assessment
Risk Assessment Considerations
Risk assessment techniques
Risk Assessment Considerations
Risk assessment techniques
Risk Assessment Considerations
Nature of the risk matrix
When the risk has been recognized as significant, the organization needs to rate it so that
the priority significant risks can be identified.
The most common form is one that demonstrates the relationship between the likelihood
of the risk materializing and the impact of the event should the risk materialize.
Risk Assessment Considerations
Definitions of likelihood
Risk Assessment Considerations
Definitions of impact
Risk Assessment Considerations
Nature of the risk matrix
The risk matrix can be used to record the outcome of the risk rating exercise and this
will provide a simple visual presentation of the significant risks that have been
recognized or identified.
The most common form is one that demonstrates the relationship between the likelihood
of the risk materializing and the impact of the event should the risk materialize.
Risk Assessment Considerations
Nature of the risk matrix
A risk is significant if it could have an impact in excess of the benchmark test for
significance for that type of risk. Identification of potentially significant risks will be
undertaken during a risk recognition exercise. It is necessary to decide the :
• Magnitude of the event should the risk materialize;
• Size of the impact that the event would have on the organization;
• Likelihood of the risk materializing at or above the benchmark;
• Scope for the further improvement in control.
Risk Assessment Considerations
Attitude to risk
Figure below provides an empirical illustration of risk attitude using a standard risk
matrix. It represents the risk attitude of a risk averse organization.
It is becoming more common for risk attitude matrix to contain four sections. These
sections can be represented by the 4Cs of comfort, cautious, concerned and critical.
Risk Assessment Considerations
Attitude to risk
Risk Classification systems
Risk Classification systems
Short-, medium-, and long term risk
Although it is not a formalized system, the classification of risks into short, medium, and
long term helps to identify risks as being related (primarily) to operations, tactics, and
strategic, respectively.
Risk Classification systems
Short term risk
Short-term risk has the ability to impact the objectives, key dependencies and core
processes, with the impact being immediate. These risks can cause disruption to operation
immediately when the event occurs. Short-term risks are predominantly hazard risks,
although this is not always the case.
Short-term risks usually impact the ability of the organization to maintain effective and
efficient core processes that are concerned with the continuity and monitoring of routine
operations. There is a need to mitigate short-term risks.
Risk Classification systems
Medium-term risk
Medium-term risk has the ability to impact the organization following a (short) delay
after the event occurs. Typically, the impact of a medium-term risk would be apparent
immediately, but would be apparent within months, or at most a year after the
[Link] with the management of tactics, projects, and other change programs.
These are often associated with projects, tactics, enhancements and other developments.
Risk Classification systems
Long-term risk
Long-term risk has the ability to impact the organization some time after the event
occurs. Typically, the impact could occur between one and five years (or more) after the
event. Long-term risks usually impact the ability of the organization to maintain the core
process that are concerned with the development and delivery of effective and efficient
strategy.
Risk Classifications
Bow-tie representation of risk management
Risk Classifications
Industry portfolio of risks
Risk Classification systems
Nature of risk classification systems
In order to identify all of the risks facing an organization, a structure for risk
identification is required, and will enable the organization to better identify the risk
appetite, risk capacity and total risk exposure in relation to each risk, group of similar
risks or generic type of risk.
The FIRM risk scorecard provides such a structure, but there are many risk classification
system available.
FIRM means: Financial, Infrastructure, Reputational or Marketplace in nature.
Risk Classifications
Bow-tie and risks to premises
Risk Classifications
Examples of risk classification systems
Risk Classifications
Attributes of the FIRM risk scorecard
Risk Classifications
Attributes of the PESTLE risk scorecard
Risk analysis and evaluation
Risk Analysis
Application of a risk matrix
The use of a risk matrix is a very simple way of demonstrating the level of risk that a
particular event represents to an organization
A risk matrix is normally used to represent the residual or current level of risk. This can
also be referred to as the net risk.
Large organizations frequently make use of a risk as a means of summarizing risk
profile.
Risk Analysis
Personal risk matrix
Risk Analysis & evaluation
Inherent, current and target levels of risk
Risk Analysis
Benchmark tests for risk significance
Risk response
Key dependencies and significant risks
Risk analysis
Analysis of risk by drivers - influence diagram
Risk analysis
Analysis of risk by drivers - influence diagram
Risk analysis
Linking objectives to strategies to risks to KRIs
Risk analysis
Linking objectives to strategies to risks to KRIs
Risk analysis & evaluation
Portfolio view of risk
Risk analysis & evaluation
Qualitative and quantitative approaches to risk assessment
Risk analysis & evaluation
Risk Map
Risk analysis & evaluation
Risk Map Model
Risk analysis & evaluation
Illustrative combined risk and opportunity map
Risk response
Risk Response
Control confidence
It is not possible for an organization to be absolutely confident that controls will always be fully
implemented and will be as effective as expected or required. Controls will need to be audited in order to
allow confidence that the control selected has been properly designed and implemented and is producing
the desired effect.
The level of control confidence can also be illustrated on a risk matrix. If the effectiveness of a control is
uncertain, a greater variability of the outcome may be expected. This can be demonstrated on a risk matrix
by using a circle or ellipse to represent a risk, instead of representing the risk as a single point on the risk
matrix. By doing this, the level of uncertainty or variability in the outcome can be illustrated in relation to
both the likelihood and impact of the event materializing.
Risk response
4T of hazard risk response
The options presented for risk response can be described as the 4Ts of hazard management, which are:
tolerate, treat, transfer and terminate.
• Tolerate will be the dominant response for the low-likelihood/low-impact risks.
• Treat will be the dominant response for high-likelihood/low-impact risks.
• Transfer will be the dominant response for high-impact/low-likelihood risks.
• Terminate will be the dominant response for high-impact/high-likelihood risks.
Risk response
4T of hazard risk response
Risk response
Risk matrix and the 4Ts of hazard risk response
Risk response
Tolerate risk
Risk tolerance is defined in Guide 73 as the organization’s or stakeholder’s readiness to bear the risk
after risk treatment in order to achieve its objectives. The guide then adds that risk tolerance can be
influenced by legal or regulatory (compliance) re- quirements.
The concept of tolerate is normally concerned with the organization being willing to retain or tolerate a
risk, even if it is higher than the organization would choose to accept.
An organization may have to tolerate risks that have a current level beyond its comfort zone and its risk
appetite
When the hazard risk is considered to be within the risk appetite of the organization, the organization
will tolerate that risk. Risk tolerance is shown as the approach that will be adopted in relation to low-
likelihood risks with low impact
Risk response
Treat risk
When the level of risk exposure (likelihood) associated with a particular hazard is high but the potential loss
(impact) associated with it is low, the organization will wish to treat the risk. Risk treatment will often be
undertaken with the risk at the inherent and/or current level, so that when the risk has been treated, the new current
level or target level may become tolerable.
There is an issue of terminology associated with treat risk. ISO 31000 considers that ‘treat risk’ is the main heading
under which various options exist, such as:
• avoiding the risk by deciding not to start or continue with the activity;
• taking or increasing the risk in order to pursue an opportunity;
• removing the risk source;
• changing the likelihood or the consequences;
• sharing the risk with another party or parties;
• retaining the risk by informed decision.
Risk response
Transfer risk
When the likelihood of a risk materializing is low but the potential is high, the organization
will wish to transfer that risk. Insurance is a well-established mechanism for transferring the
financial impact of losses arising from hazard risks and (to a lesser extent) control risks.
In some cases, risk transfer is closely related to the desire to eliminate or terminate the risk.
However, many risks cannot be transferred to the insurance market, either because of
prohibitively high insurance premiums or because the risks under consideration have
(traditionally) not been insurable.
Risk response
Terminate risk
When a risk is both of high likelihood and high potential impact, the organization will wish
to terminate or eliminate the risk. It may be that the risks of trading in a certain part of the
world or the environmental risks associated with continuing to use certain chemicals are
unacceptable to the organization and/or its stakeholders.
In these circumstances, appropriate responses would be elimination of the risk by stopping
the process or activity, substituting an alternative activity or outsourcing the activity that is
associated with the risk.
Risk response
Risk versus reward in strategy
Risk response
Opportunity risks and risk appetite
Risk control
ERM Maturity model
ERM Maturity Model
ERM Glossary
• Impact – The significance of a risk to an organization. Impact captures the importance of the risk. It can be measured
quantitatively or qualitatively.
• Inherent Risk – The level of risk that resides with an event or process prior to management taking mitigation action.
• Likelihood – An estimate of the chance or probability of the risk event occurring. Opportunity – The upside of risks.
• Residual Risk – The level of risk that remains after management has taken action to mitigate the risk.
• Risk – Any event or action that can keep an organization from achieving its objectives.
Risk Appetite – The overall level of risk an organization is willing to accept given its capabilities
• and the expectations of its stakeholders.
• Risk Tolerance – The level of risk an organization is willing to accept around specific objectives. Risk tolerance is a narrower
level than risk appetite.