0% found this document useful (0 votes)
13 views44 pages

Risk Decision-Making and Response Strategies

The document outlines the process of risk decision making, emphasizing the importance of establishing risk appetite and response strategies to effectively manage risks. It details various risk responses such as avoidance, transfer, mitigation, and acceptance, along with examples of risk statements and their corresponding responses. Additionally, it discusses the significance of risk appetite, tolerance, and limits in guiding organizational decision-making and integrating risk management into overall strategy.

Uploaded by

sarmadkhalifa
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views44 pages

Risk Decision-Making and Response Strategies

The document outlines the process of risk decision making, emphasizing the importance of establishing risk appetite and response strategies to effectively manage risks. It details various risk responses such as avoidance, transfer, mitigation, and acceptance, along with examples of risk statements and their corresponding responses. Additionally, it discusses the significance of risk appetite, tolerance, and limits in guiding organizational decision-making and integrating risk management into overall strategy.

Uploaded by

sarmadkhalifa
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Risk

Decision
& Risk
Messaging
EPPA6233
Risk
Identification

ERM Risk
messagin
Risk
quantificatio
Process g n

Cycle
Risk Decision
Making
Risk
Decision
Making
Risk Decision
Making
Risk decision is a decision to accept an option having a given risk function in preference to
another, or in preference to taking no action.

Decision between alternatives, at least one of which has a probability of loss.

Decision making process is underpinned by establishing risk appetite against objectives and
setting a base.
Risk
Response
The response to a given risk should reflect
 The risk type.
 The risk assessment (likelihood, impact, critically) and
 The organisation’s attitude to risk  risk appetite

Number of possible responseto risks and risks can be threats (downside or negative risk)
or opportunities (upside or positive risks).

Vague risk statements lead to poor risk response planning. After risk identification,
risk
statements/risk appetite statement/risk tolerance statement need clearly to be stated.

A risk statement provides the clarity and descriptive information required for a reasoned
and defensible assessment of the risk’s occurrence probability and areas of impact.
Avoi
d
• Risk can be avoided by removing the cause of the risk or executing

Risk
the project in a different way while still aiming to achieve project
objectives.
• E.g. Changing the strategy or reducing the scope of work.

Respo
Transfe
r
• Involves finding another party who is willing to take responsibility for
its management, and who will bear the liability of the risk is owned

nse
and management by the party best able to deal with it effectively..
• Usually involves payment of a premium, and the cost effectiveness of
this must be considered when deciding whether to adopt a transfer
strategy.
• E.g. Risk transferred to insurance company such as security of

..(1)
materials at site.

Mitigate/Reduce
• Reduces the probability and/or impact of an adverse risk event to an
acceptable threshold.
• May require resources or time and thus presents a trade off between
doing nothing versus the cost of mitigating the risk.
• E.g. removal of engineering/structural barriers, contingency plan.
Exploit

• Aim – to ensure that the opportunity is realized.


• Seeks to eliminate the uncertainty associated with a particular upside risk by
making the opportunity definitely happen.
• An aggressive response strategy, best reserved for those golden opportunities
having high probability and impacts.
• E.g. Assigning the most talented resources of organization to the project to
reduce the time for completion or providing at a lower cost that originally

Risk
planned.

Share

Respon
• Allocate risk ownership of an opportunity to another party who is best able to
maximize its probability of occurrence and increase the potential benefits if it
does occur.
• Those to whom threats are transferred take on the liability and those to whom
opportunities are allocated should be allowed to share in the potential benefits

se.. (2)
• E.g. Risk sharing, joint ventures.

Enhance
• Aim to modify the size of positive risk.
• The opportunity is enhanced by increasing its probability and/or impact, thereby
maximizing benefits realized for the project.
• E.g. Adding more resources to an activity for completing it before scheduled
time.
Acceptance
◦ Adopted when it is not possible or practical to respond to the risk by the
other strategies or response is not warranted by the importance of the
risk.
◦ Risk response strategy for both threats and opportunities
◦ A contingency plan will be identified should it occur.
◦ E.g. War and disorder, exchange rate fluctuation.
Other Risk Reject
Response .. ◦ Noaction is taken and the chance to gain from the
opportunity is rejected
(3) ◦ Risk response strategy for opportunities.
◦ Contingency plans may be put in place should the opportunity occur.
◦ E.g. political or environmental e.g. New transport links, change of
government bringing positive changes in policy/opportunities for lobbying
etc.
Examples of Risk Statement
& Risk Response
Risk Statement Risk
Response
Inaccuracies or incomplete information in the survey file could lead to rework of the design. Mitigate: Work with Surveys to verify that the survey file is
accurate and complete. Perform additional surveys as
needed.
A design change that is outside of the parameters contemplated in the Environmental Document Avoid: Monitor design changes against ED to avoid
triggers a supplemental EIS which causes a delay due to the public comment period. reassessment of ED unless the opportunity outweighs the
threat.
Design
Potential lawsuits may challenge the environmental report, delaying the start of construction or Mitigate: Address concerns of stakeholders and public during
threatening loss of funding. environmental process. Schedule additional public outreach.

Nesting birds, protected from harassment under the Migratory Bird Treaty Act, may delay construction Mitigate: Schedule contract work to avoid the nesting season
during the nesting season. or remove nesting habitat before starting work.
Environmental
Due to the complex nature of the staging, additional right of way or construction easements may Mitigate: Re‐sequence the work to enable ROW Certification.
be required to complete the work as contemplated, resulting in additional cost to the project.
R/W
Due to the large number of parcels and businesses, the condemnation process may have to be used Mitigate: Work with Right‐of‐ Way and Project Management to
to acquire R/W, which could delay start of construction by up to one year, increasing prioritize work and secure additional right‐of‐way resources to
construction costs and extending the time for COS. reduce impact.
Hazardous materials encountered during construction will require an on‐site storage area and Accept: Ensure storage space will be available.
Construction potential additional costs to dispose.
Unanticipated buried man‐made objects uncovered during construction require removal and disposal Accept: Include a Supplemental
resulting in additional costs. Work item to cover this risk.
Risk
Appetite

DEFINING AN ENTERPRISE’S DEFINED AS THE AMOUNT RISK APPETITE STATEMENTS CRITICAL TOOL FOR DECIDED BY THE BOARD OR
RISK APPETITE IS A STRONG AND TYPE OF RISK THAN AN MAY BE EXPRESSED EFFECTIVE DECISION MAKING CEO
FOUNDATION UPON WHICH ORGANISATION IS WILLING TO QUALITATIVE AND/OR BECAUSE THE LEVEL OF RISK
TO BUILD BROADER RISK TAKE IN ORDER TO MEET QUANTITATIVELY AND THAT AN ORGANIZATION IS
MANAGEMENT ACTIVITIES. THEIR STRATEGIC. MANAGED WITH RESPECT TO WILLING TOTAKE ON WILL
EITHER AN ALLOCATED DEFINE THE RISK RESPONSE
INDIVIDUAL INITIATIVE STRATEGIES THAT AN
AND/OR IN THE AGGREGATE. ORGANIZATION WILL CHOOSE
FOR RISKS.
RISK APPETITE

Risk Strategy
Strategic expression of overall philosophy towards risk-trading necessary to
achieve mission, so that from the Board on down there is alignment

Risk What risks to take ? Type How much risk to take? Amount

Appetite Risk Preferences


Articulating risk as opportunity,
identifying risks that need to be
Risk Tolerances
Quantitative expression of the amount
of aggregate risk that organization will
Framewor taken deliberately in the
expectation of creating value,
tolerate over varying time horizons as
a means to achieve its

k
needed to achieve the mission. mission

Risk Attractiveness
Tactical assessment of the Risk Limits
risks within the preference set, Granular operational control
reflecting current circumstances on specific risk: Express in the metrics
that are locally relevant and practical
to monitor
The amount of uncertainty of organization is prepared to accept
in total or more narrowly within a certain business unit, a
particular risk category or for a specific initiative
 Expressed in quantitative terms that can be monitored

Ris Often is communicated in terms of acceptable or unacceptable


outcomes or as limited levels of risk
k Risk tolerance statement identify the specific minimum and

Toleran maximum levels beyond which the organization is unwilling to


lose
ce Knowing how the risk tolerance effects investment decisions is
vital to the health of company portfolio
More granular tolerance levels expressed for specific risk
sources, business units, and/or products that are used to
implement the risk tolerances.

Risks More practical in that they can be expressed using metrics that
are measurable and relevant to managers at the local level

Limits Must also be tested to be sure that they can be expressed in


controlling risk tolerances.
Risk Appetite, Risk Tolerance &
Risk Limit Risk Appetite

Board/CEO Risk Tolerance Statements

Executive Management Risk Limit Risk Limit Risk Limit

Business Unit Leaders


Risk Limit Risk Limit Risk Limit
(i.e. risk owners)
Key Risk Indicators
(KRIs)
 KRIs are an important tool within risk management and are used to enhance the monitoring
and mitigation of risks and facilitate risk reporting.
Defined as measurement, or metrics, used by an organization to manage current and potential
exposure to various operational, financial, strategic and reputational risks.
 Purpose - to provide measures of risk exposures over time.
In addition, KRIs is useful to track risk metrics related to control effectiveness –
lagging indicators(key control indicators) and leading indicators (early warning indicators)
Ideally, KRIs are tracked against risk tolerance levels and integrated with related key
performance indicators (KPIs)
KRIs Corresponding Risk
Exposure
Attempted attacks on Risk of a data security
information breach
Examples technology
of Key Calls to customer service Risk of poor
product/service
Risk quality
Indicators Lawsuits filed against the Litigation risk
(KRIs) company
Unemployment rate Disability insurance risk

Complaints related to human Risk of employment-


resource issues, within a related lawsuit or scandal
single business unit
Risk Response
Control
Having selected risk responses, management identifies control activities needed to help ensure that the risk responses are carried out
properly and in a timely manner.

Risk monitoring and controlling or risk review is an iterative process that uses progress status and deliverable status to monitor and
control risks. This is enabled by various status report, such as quality report, progress report, follow up reports and so forth.

Risk control
◦ Execution of the risk response strategy
◦ Monitoring of triggering events
◦ Initiating contingency plans
◦ Watching for new risks

Establishing a change management system


◦ Monitoring, tracking and reporting risk
◦ Fostering an open organization environment
◦ Repeating risk identification/assessment exercises
◦ Assigning and documenting responsibility for managing risk
Risk Monitoring & Controls
Includes:
Identify new risk and planning for them
Keeping track of existing risks to check if
◦ Reassessment of risks is necessary
◦ Any of risk conditions have been triggered
◦ Monitor any risks that could become more critical over time
◦ Tackle the remaining risks that require a longer term, planned and managed approach with risk action plans

Risk reclassification
◦ For the risks that cannot be closed, the criticality has to go down over a period of time due to implementing the action
plan. If this is not the case then the action plan might not be effective and should be re-examined.

Risk reporting
◦ The risk register is continuously updated from risk identification through risk response planning and status update during risk
monitoring and control. This project risk register is the primary risk reporting tool and is available in the central project server,
which is accessible to all stakeholders.
Monitoring & Controlling risk -
Inputs
Risk register – the key inputs to risk register includes identified risks and owner of risk, agreed
upon risk response, specific actions to be implemented, symptoms/warning signs of any risk,
residual/secondary risk, list of low priority risks and contingency measure in terms of time/cost.

Risk management plan – contain risk tolerance, assignment of manpower including bearer of
risks, time and other resources to project risk management.

Work performance information – related to various performance results is to be quantified in


terms of deliverable status, schedule progress and costs incurred.

Performance reports – will be analysed for variance analysis, earned value data and forecasting
the likely data of completion of project
Monitoring and Controlling Risks: Tools
& Techniques
Risk reassessment – monitoring and controlling risks may also result in identification of new risks.

Risk audits – examine and document the effectiveness of the risk response planning in controlling risk and the effectiveness of the risk
owner.

Variance and Trend Analysis – using performance information for comparing planned results to the actual results, in order to control and
monitor risk events and to identify trends in the planning execution. Outcome from this analysis may forecast potential deviation from
cost and schedule targets.

Technical performance measurement – comparing technical accomplishments during execution to the management plan’s schedule.

Reserve Analysis - as execution progresses, some risk events may happen with positive or negative impact on cost or schedule
contingency reserves. Reserve analysis compares available reserves with amount of risk remaining at the time and determines whether
reserves are sufficient

Status meetings – should be used to report on the progress of risk management. Frequent status meetings ensure that risks are at the
forefront of people’s minds.
Three Types of
Indicators
Key performance indicators
◦ An indicator which enables an organization to define its performance target based on its goals and objective
and to monitor its progress towards achieving these targets.
◦ KPIs are used to answer the question: “Are we achieving our desired levels of performance?””

Key risk indicators


◦ An indicator which is used by organisations to help define its risk profile and monitor changes in the profile
◦ KRIs are used to answer the question: “How is our risk profile changing and is it within our desired tolerance
levels?”’

Key control indicators


◦ An indicator used by organisations to define their control environment and monitor levels of control relative
to desired tolerances.
◦ KCIs are used to answer the question: “Are our internal control effective? Are we in control?””
Risk
Reporting
Reporting to external audiences

Reporting to internal audiences


◦ Essential for internal decision makers to integrate risk evaluations into their operational and capital
investments decision, review of performance and compensation/rewards decisions.
Value Based ERM –
Integrating
ERM into Decision
Making
Value Based ERM - Risk Appetite
& Risk Limit

Allows for a maximum limit to be set on the enterprise’s risk exposure which stakeholders are
comfortable with.

Risk appetite is not only a set of quantitative measures but judgemental estimates.

The setting of the risk appetite should be an interactive process that requires debate and should
ultimately result in consensus among the members of senior management.
Risk Appetite & Risk
Limits
A risk appetite statement including soft and hard limits.
◦ Hard limits show the maximum levels of risk exposure which
should never be exceeded
◦ Soft limits may be exceeded for temporary duration with
suitable explanation provided.
◦ Exceeding the soft limits should act as an early warning sign
that the hard limits may be exceeded in the foreseeable
future.
Risk Appetite & Risk
Limits
Example of a risk appetite statement
Risk Appetite & Risk
Limits
Decomposing the risk appetite statement into tangible limits that will form the responsibility of
the various functions and activities within the organization is the next step.

This acts to spread the risk exposure across the business thereby preventing excessive risk
concentration.

Reasons why risk limits are used


◦ Diversification – diversify the risk exposure preventing too much concentration of exposures in any one
area, such as single business segment or even a single source of risk.
◦ Risk return management – risk limits can be used to manage the risk return balance for portions of the
business below the enterprise level such as business segment
Risk Appetite & Risk
Limits
◦ Managing enterprise risk exposures – to allocate, or budget, enterprise risk exposure in a
traditional
ERM approach.
◦ Habit

How to define risk limits


◦ Main problem they rarely involve top down allocation of risk appetite
◦ Approach of top down allocation of risk appetite to risk limits involved 3 steps process
◦ Attribution analysis- identify the portion of the current enterprise risk exposure that is attributable to each business segment.
◦ Risk return adjustment
◦ Scaling up
Value Based ERM: Integrating ERM
into Decision Making
Involved two types of decisions
◦ Risk priority decision making involves decision whose primary goal is related to managing the level of risk
to an appropriate level (up or down). E.g. managing enterprise risk exposure to within risk appetite
(Managing Risk)
◦ Return priority decision making involves decisions whose primary goal is related to increasing company
value. E.g. strategic planning (Enhancing Value)

Decision making process involved two step process


◦ Recalculate risk and return metrics
◦ Evaluate risk –return trade off
Integrating ERM into Decision
Making
Recalculate risk and return metrics
1. Revise distributable cash flow projection
◦ Capture how the decision expected to impact future revenues & expenses
2. Revise discount rate
3. Recalculate baseline company value
4. Revise key risk scenarios
5. Recalculate enterprise risk exposure

Value based ERM centre on the simulation model of risk quantification. The five
steps above represent the five areas that can be adjusted to take into account
the impact of the various what if scenarios.
Integrating ERM into Decision
Making
Evaluate risk return trade off
1. Impact on enterprise risk exposure
◦ First item considered by risk priority decisions in cases where the enterprise risk exposure either exceeds risk appetite or is too far
below in order to evaluate decisions how effectively they manage exposure to the appropriate level.
◦ Return priority decisions to ensure that it does not violate risk appetite limits

2. Impact on downside standard deviation


◦ Impact of a decision on the level of firm risk.

3. Impact on baseline company value


4. Impact on probabilistic expectation of company value
◦ Another view whether the decision being considered is adding value.
Risk Priority Decision
Making
Managing enterprise risks exposure within risk appetite
◦ 4 situation
1. Enterprise risk exposure exceeds the hard limit of risk appetite – urgent needs to reduce exposure to below the hard
limit
2. Enterprise risk exposure is at, or exceeds, the soft limit of risk appetite but is below the hard limit – immediate actions
to reduce exposures to a comfortable range below the soft limit
3. Enterprise risk exposure is excessively below the soft limit or risk appetite – to increase risk exposure i.e. risk
exploitation
4. Enterprise risk exposure is in a reasonably comfortable range below the soft limit of risk appetite – does not take risk
priority action as the enterprise risk exposure is precisely where it ought to be.
Risk Priority Decision
Making
Two types of ERM information routinely provided to maintain appropriate level of enterprise risk
exposure.
◦ Exposure information
◦ Routinely reported to the board of directors, management and the ERM team
◦ Include comparison of enterprise risk exposure to risk appetite.
◦ Reported to corresponding level of authority for them to oversees, direct or take actions to manage the exposure within its
tolerance limit
◦ Key risk indicator
◦ Most useful KRIs are leading indicators which are highly correlated with the exposure metrics and serve as an advance warning to
management about a likely impending change in the level
◦ E.g. Table 6.4 pp. 248
Risk Priority Decision
Making
Mitigation decisions
◦ Types of mitigation decisions
◦ Mitigation decisions reduce the likelihood of occurrence of a key risk scenario (e.g. lobbying efforts may prevent harmful legislation
together), the severity of its impact (e.g. a business continuity plan put in the place to partially mitigate a pandemic key risk
scenario) or both.
◦ Other examples in Table 6.5 (pp. 249) & cases (pp 250)
◦ Management selected mitigation if the cost was reasonable and it produced a satisfactory result.
◦ Leveraging existing risk management models
◦ ERM – considered strategic risk management which defined what to do, in term of which key risk scenarios to concentrate on, and in
what priority order
◦ Risk management – tactical risk management which focuses on the key scenarios prioritized in the risk strategy provided by ERM. It
defines the how, in terms of how best to mitigate the key risk scenario
◦ ERM Model – Figure 6.3 pp. 253
Risk Priority Decision
Making
◦ Determining the value of mitigation in place
◦ Establish the value of a mitigation related department
◦ Technique used to establish for the first time, the value of a department or unit whose role is mitigation related.
◦ Measure directly the impact on the baseline company value
Value of mitigation = CoValueBaseline – CoValue Excel Mitigation

CoValueBaseline = Baseline company value


CoValue Excel Mitigation = Recalculated company value based on excluding mitigation
◦ Evaluate appropriateness of specific mitigation items
◦ Evaluate on individual existing mitigation item, such as insurance policy or a hedge
◦ Evaluate past mitigation decisions based merely on rule of thumb or subjective management judgement
◦ Integrate ERM into Internal Audit Plans
Return- Priority Decision
Making
Integrating ERM into strategic planning
◦ Strengthens the strategic planning into three major ways
1. Aligns baseline assumptions
2. Aligns scenario assumptions
3. Convert static document into dynamic planning tool

Integrating ERM into business decision making


◦ The need for speed
◦ Dealing with soft assumptions
◦ Stock buyback or issuance
◦ Prioritizing between shareholders
◦ Mergers and acquisitions
Risk
Messaging
Value Based ERM – Risk
Messaging
Two types
◦ Internal messaging
◦ External messaging

Internal messaging
◦ Refers to incorporating ERM information into performance measurement and management
◦ Two aspects
◦ Integrating ERM into business performance analysis
◦ Integrating ERM into incentive compensation
◦ Effective internal risk messaging is necessary to drive the appropriate ERM activities in the risk
identification, risk quantification and risk decision making ERM process steps.
Internal Risk Messaging – Business
Performance Analysis
Two methods
◦ Financial results
◦ Balanced score card

Shortcoming of financial results based on traditional methods


◦ Lacks of rigor
◦ Use of subjective and inconsistent approach in setting risk adjusted goal implicitly
◦ Goals may be set based on varying targets such hurdle rate for return on assets or return on investment in explicitly setting risk adjusted goal.
◦ Traditional economic capital models calculate risk exposure
◦ Missing future new business
◦ Missing integrated impacts
◦ Incomplete
◦ Ignore the changes that occur during the year that may alter the trajectory of future revenue and expenses, versus the baseline strategic plan
projection.
◦ Ignore the changes that occur during the year that may alter the riskiness of the firm, changing the enterprise risk exposure, the downside standard
deviation and thereby the discount rate.
Internal Risk Messaging – Business
Performance Analysis
ERM support both rigorous and complete
◦ Rigorous –business performance is measured by the amount that company value is increased, over the past
period in comparison to the increase expected in the strategic plan.
◦ Complete – fully captures all future impacts on value as well as the impacts over the prior single period.
Covers changes that impact distributable cash flows, alter the trajectory of future distributable flows and
alter the riskiness of the firm.

Balanced score card


◦ Use of several non financial measures along with financial measure to analyse business performance.
◦ Problem – relative weight or emphasis placed on each of the scorecard elements using arbitrarily 
unbalanced
◦ Value based ERM approach can be used to directly calculate more appropriate weight for the balanced
scorecard. It converts the less tangible, nonfinancial items into tangible items that can be quantified in term
of financial results.
Internal Risk Messaging – Incentive
Compensation
Incentive compensation is used to align management interest with shareholders

E.g. Stock option

Mismatch of interest due to


◦ Information mismatch for award value
◦ Poor metrics for calculating award amount
External Risk
Messaging
Refer to communicating ERM information to external stakeholders

4 types
◦ Shareholders
◦ Stock analysts
◦ Rating agency
◦ Regulators

Communication to shareholders
◦ Voluntary risk disclosures
◦ Mandatory risk disclosures

You might also like