BF3014
RISK MANAGEMENT
Risk Management Process
The risk management process is a framework
for the actions that need to be taken. There
are five basic steps that are taken to manage
risk; these steps are referred to as the risk
management process. It begins with
identifying risks, goes on to analyze risks, then
the risk is prioritized, a solution is
implemented, and finally, the risk is monitored.
In manual systems, each step involves a lot of
documentation and administration.
5 STEPS FOR RISK MANAGEMENT
IDENTIFY THE ANALYZE THE EVALUATE OR TREAT THE MONITOR AND
RISK RISK RANK THE RISK RISK REVIEW THE
RISK
1. Identify The Risk
The initial step in the risk management process is to identify the risks
that the business is exposed to in its operating environment.
There are many different types of risks:
Legal risks
Environmental risks
Market risks
Regulatory risks etc.
It is important to identify as many of these risk factors as possible. In
a manual environment, these risks are noted down manually. If the
organization has a risk management solution employed all this
information is inserted directly into the system.
2. Analyze The Risk
Once a risk has been identified it needs to be
analyzed. The scope of the risk must be
determined. It is also important to understand the
link between the risk and different factors within the
organization. To determine the severity and
seriousness of the risk it is necessary to see how
many business functions the risk affects. There are
risks that can bring the whole business to a
standstill if actualized, while there are risks that will
only be minor inconveniences in the analysis.
Risks need to be ranked and prioritized.
Most risk management solutions have
different categories of risks, depending
on the severity of the risk. A risk that
may cause some inconvenience is rated
lowly, risks that can result in
catastrophic loss are rated the highest.
It is important to rank risks because it
3. Evaluate The allows the organization to gain a holistic
Risk view of the risk exposure of the whole
organization. The business may be
vulnerable to several low-level risks, but
it may not require upper management
intervention. On the other hand, just
one of the highest-rated risks is enough
to require immediate intervention.
Risk Assesment
There are two types of risk assessments:
Qualitative Risk Assessment Quantitative Risk
Assessment
Qualitative Risk Assessment
Risk assessments are inherently qualitative – while
we can derive metrics from the risks, most risks are
not quantifiable. For instance, the risk of climate
change that many businesses are now focusing on
cannot be quantified as a whole, only different
aspects of it can be quantified. There needs to be a
way to perform qualitative risk assessments while
still ensuring objectivity and standardization in the
assessments throughout the enterprise.
Quantitative Risk Assessment
Finance related risks are best assessed through
quantitative risk assessments. Such risk assessments are
so common in the financial sector because the sector
primarily deals in numbers – whether that number is the
money, the metrics, the interest rates, or any other data
point that is critical for risk assessments in the financial
sector. Quantitative risk assessments are easier to
automate than qualitative risk assessments and are
generally considered more objective.
4. Treat The Risk
Every risk needs to be eliminated or contained as much as possible.
This is done by connecting with the experts of the field to which the risk
belongs. In a manual environment, this entails contacting each and
every stakeholder and then setting up meetings so everyone can talk
and discuss the issues. The problem is that the discussion is broken
into many different email threads, across different documents and
spreadsheets, and many different phone calls. In a risk management
solution, all the relevant stakeholders can be sent notifications from
within the system. The discussion regarding the risk and its possible
solution can take place from within the system. Upper management can
also keep a close eye on the solutions being suggested and the
progress being made within the system. Instead of everyone contacting
each other to get updates, everyone can get updates directly from
within the risk management solution.
5. Monitor The Risk
Not all risks can be eliminated – some risks are always
present. Market risks and environmental risks are just two
examples of risks that always need to be monitored. Under
manual systems monitoring happens through diligent
employees. These professionals must make sure that they
keep a close watch on all risk factors. Under a digital
environment, the risk management system monitors the entire
risk framework of the organization. If any factor or risk
changes, it is immediately visible to everyone. Computers are
also much better at continuously monitoring risks than people.
Monitoring risks also allows your business to ensure
continuity.
What is Risk Management
Risk management is an important business
practice that helps businesses identify,
evaluate, track, and improve the risk mitigation
process in the business environment. Risk
management is practiced by the business of
all sizes; small businesses do it informally,
while enterprises codify it.
Why It Is Important
Risk management is important because it tells
businesses about the threats in their operating
environment and allows them to preemptively
mitigate risks. In the absence of risk
management, businesses would face heavy
losses because they would be blindsided by
risks
[Link] Silicon
Valley Bank
Risk vs Return
THERE IS A TRADE OFF THE HIGHER THE RISK, THE
BETWEEN RISK AND HIGHER THE EXPECTED
EXPECTED RETURN RETURN
15
IF IN PRACTICE EARNINGS THE “BANKRUPTCY COSTS”
SHAREHOLDERS COMPANIES ARE STABILITY AND REGULATORS OF ARGUMENTS SHOW THAT
CARE ONLY CONCERNED COMPANY FINANCIAL THAT MANAGERS MAY BE
ABOUT ABOUT TOTAL SURVIVAL ARE INSTITUTIONS ACTING IN THE BEST
SYSTEMATIC RISK IMPORTANT ARE PRIMARILY INTERESTS OF
RISK, SHOULD MANAGERIAL INTERESTED IN SHAREHOLDERS WHEN
THE SAME BE OBJECTIVES TOTAL RISK THEY CONSIDER TOTAL
TRUE OF RISK
COMPANY
MANAGERS?
Risk vs Return for
Companies
16
What Are Bankruptcy Costs?
Lost sales (There is a Key employees leave Legal and accounting costs
reluctance to buy from a
bankrupt company.)
17
Risk aggregation: aims to get
rid of non-systematic risks
Approach with diversification
es to Bank
Risk Risk decomposition: tackles
risks one by one
Managem
ent
In practice banks use both
approaches
18