Risk
Managemen
t
CHAPTER 1
Jaweriya Mazhar
Risk" may be defined as a compound measure of the probability and
magnitude of adverse effect.
▸ A risk is a potential problem - it might happen and it might not
► Conceptual definition of risk Most read 3
• Risk concerns future happenings
• Risk involves change in mind, opinion, actions, places, etc. • Risk
involves choice and the uncertainty that choice entails
► Two characteristics of risk
• Uncertainty - The risk may or may not happen, that is, there are no
100% risks (those, instead, are called constraints)
• Loss - The risk becomes a reality and unwanted consequences or losses
occur
What is meant by Risk?
Derived from the Italian word 'rischio', meaning a source Π peril, this
everyday word is defined by the Oxford English Dictionary thus;
1. A situation involving exposure to danger.
2. The possibility that something unpleasant will happen.
3. A person or thing causing a risk or regarded in relation to risk: a fire
risk.
Risk Management Definition
► To the layman, the term 'hazard' and 'per appear to be
synonymous with 'risk'. In fact meanings are distinct:
► Hazard: A hazard is something probability of a risk occurring.
► Peril: if the risks is physical damage a building, then fire, storm,
flood and earthquake are all perils
The Language of Risk
➤ In risk management, a peril is the direct or immediate cause of a
loss (such as a fire or automobile crash)
➤ A hazard is a condition that increases the possible frequency or
severity of a loss, or both
➤ Moral hazard: deceit, often involves insurance
➤ Morale hazard: carelessness
➤ Physical hazard: tangible conditions (snow, ice)
Perils and Hazards
► Known Risks • Those risks that can be uncovered after
careful evaluation of the project plan, the business and technical
environment in which the project is being developed, and other
reliable information sources (e.g., unrealistic delivery date)
► Predictable risks • Those risks that are extrapolated from
past project experience (e.g., past turnover)
► Un predictable risks • Those risks that can and do occur,
but are extremely difficult to identify in advance
Risk Categorization in Business
Particular Risks (Micro Risks) - These refer to risks whose
future outcomes or effects can be partially controlled
(although not predictably) by individuals or groups of people.
For example, from an individual's decision to drive a motor
vehicle, or to own property, or even to cross a road. Much
depends on the individual's action and level of care (or lack of
care and attention). Particular risks are the responsibility of
individuals, such risks are 'insurable'
Types of Risks
Pure Risks and Speculative Risks
► The majority of insurable risks are what are called 'pure risks'
which include fire, accidents, theft, etc, which offer no prospect of
gain, but only of loss if the risk becomes a reality.
► Trading risks are called 'speculative risks' because they offer
the possibility of loss or gain, and in general they are not
insurable.
Types of Risks
Diversifiable risks: risks whose adverse consequences can
be mitigated simply by having a diversified portfolio of risk
exposures
Non-diversifiable risks: risks, shared by all persons or
organizations, that cannot be mitigated by adding exposures
to the portfolio
Diversifiable vs. Non-diversifiable Risks
Diversifiable Risks Non-
diversifiable Risks
▸ Reputational risk ▸ Market risk
▸ Brand risk ▸ Regulatory risk
▸ Credit risk ▸ Environmental
risk
▸ Product risk ▸ Geo-political risk
▸ Legal risk ▸ Inflation and
recession risk
▸ Physical damage risk ▸ Pandemics,
(COVID19)
Examples
▸ Operational riskof Diversifiable and Non-
▸ Social security
program risks
Diversifiable
▸ Strategic risks
risk (A kind of MICRO risks) (A kind of MACRO
risks)
Risk pool is one of the forms of risk management mostly practiced by
insurance companies.
▸ Under this system, insurance companies come together to form a
pool, which can provide protection to insurance companies against
catastrophic risks such as floods, earthquakes etc.
▸ The term is also used to describe the pooling of similar risks that
underlies the concept of insurance. ▸ Risk pooling is an important
concept in "Supply Chain Management".
► It measures by either the standard deviations or coefficient of
variation
Risk Pooling
Risk aggregation: aims to get rid of non-systematic risks with
diversification
Risk decomposition: tackles risks one by one
In practice banks use both approaches
Approaches to Bank Risk Management
If shareholders care only about systematic risk, should the same be
true of company managers?
In practice companies are concerned about total risk
Earnings stability and company survival are important managerial
objectives
The regulators of financial institutions are primarily interested in total
risk
“Bankruptcy costs” arguments show that that managers may be
acting in the best interests of shareholders when they consider total
riskRisk vs Return for Companies
What different Types of Risks are there in
Businesses?
There’s a vast landscape of potential risks that face modern
organizations. Targeted risk management practices like ORM
and SCRM have risen to address emerging areas of risk, with
those disciplines focused on mitigating risks associated with
operations and the supply chain.
Specific risk management strategies designed to address
new risks and existing risks have emerged from these facets
of risk management, providing organizations and risk
professionals with action plans and contingency plans tailored
to unique problems and issues.
Strategic Risk:
Strategic risks are those risks that could have a potential impact
on a company’s strategic objectives, business plan, and/or
strategy. Adjustments to business objectives and strategy have
a trickle-down effect to almost every function in the
organization.
Some events that could cause strategic risks to be realized are:
major technological changes in the company, like switching to a
new tech stack; large layoffs or reductions-in-force (RIFs);
changes in leadership; competitive pressure; and legal changes.
Compliance Risk:
Compliance risks materialize from regulatory and compliance
requirements that businesses are subject to, like Sarbanes-
Oxley for publicly-traded US companies, or GDPR for
companies that handle personal information from the EU.
The consequence or impact of noncompliance is generally a
fine from the governing body of that regulation. These types of
risks are realized when the organization does not maintain
compliance with regulatory requirements, whether those
requirements are environmental, financial, security-specific, or
related to labor and civil laws.
Financial Risk:
Financial risks are fairly self-explanatory — they have the
possibility of affecting an organization’s profits.
These types of risks often receive significant attention due to
the potential impact on a company’s bottom line.
Financial risks can be realized in many circumstances, like
performing a financial transaction, compiling financial
statements, developing new partnerships, or making new
deals.
Operational Risk:
Risks to operations, or operational risks, have the potential to
disrupt daily operations involved with running a business.
Needless to say, this can be a problematic scenario for
organizations with employees unable to do their jobs, and
with product delivery possibly delayed.
Operational risks can materialize from internal or external
sources — employee conduct, retention, technology failures,
natural disasters, supply chain breakdowns — and many
more.
Reputational Risk:
Reputational risks are an interesting category. These risks look
at a company’s standing in the public and in the media and
identify what could impact its reputation. The advent of social
media changed the reputation game quite a bit, giving
consumers direct access to brands and businesses.
Reputational risks are realized when a company receives bad
press or experiences a successful cyber attack or security
breach; or any situation that causes the public to lose trust in
an organization.
Quality Risk:
Quality risks are specifically associated with the products or
services that a company provides. Producing low-quality
goods or services can cause an organization to lose
customers, ultimately affecting revenue.
These risks are realized when product quality drops for any
reason — whether that’s technology changes, outages,
employee errors, or supply chain disruptions.
Risk
Management
process
Step 1: Risk Identification
The first step in the risk management process is risk
identification. This step takes into account the organization’s
overarching goals and objectives, ideally through
conversations with management and leadership. Identifying
risks to company goals involves asking, “What could go
wrong?” with the plans and activities aimed at meeting those
goals. As an organization moves from macro-level risks to more
specific function and process-related risks, risk teams should
collaborate with critical stakeholders and process owners,
gaining their insight into the risks that they foresee.
As risks are identified, they should be captured in formal
documentation — most organizations do this through a risk
Step 2: Risk Analysis or Assessment
Analyzing risks, or assessing risks, involves looking at the
likelihood that a risk will be realized, and the potential impact
that risk would have on the organization if that risk were
realized.
By quantifying these on a three- or five-point scale, risk
prioritization becomes simpler. Multiplying the risk’s likelihood
score with the risk’s impact score generates the risk’s overall
risk score. This value can then be compared to other risks for
prioritization purposes.
Likelihood Impact
The likelihood that a risk The potential impact of a risk, should it
will be realized asks the be realized, asks the risk assessor to
risk assessor to consider consider how the business would be
how probable it would be affected if that risk occurred.
for a risk to actually occur.
Impact, on a 5×5 risk matrix, is broken
Likelihood, on a 5×5 risk out into:
matrix, is broken out into: [Link] Impact
[Link] Unlikely [Link] Impact
[Link] [Link] Impact
[Link] [Link] Impact
[Link] [Link] Impact
[Link] Likely
Risk Assessment matrics help visualize the relationship between likelihood and impact,
serving as a valuable tool in risk professionals’ arsenals.
Step 3: Controls Assessment and
Implementation
Once risks have been identified and analyzed, controls that
address or partially address those risks should be mapped. Any
risks that don’t have associated controls, or that have controls
that are inadequate to mitigate the risk, should have controls
designed and implemented to do so.
Developing and implementing new controls and control
processes is timely and costly; there’s usually a learning curve
for employees to get used to changes in their workflow.
Using the risk register and corresponding risk scores,
management can more easily allocate resources and budget to
priority areas, with cost-effectiveness in mind. Each year,
leadership should re-evaluate their resource allocation as part of
Step 4: Risk Monitoring,
Reviewing, and Reporting
The last step in the risk management lifecycle is monitoring
risks, reviewing the organization’s risk posture, and reporting
on risk management activities. Risks should be monitored on
a regular basis to detect any changes to risk scoring,
mitigation plans, or owners. Regular risk assessments can
help organizations continue to monitor their risk posture.
As an organization reviews and monitors its risks and
mitigation efforts, it should apply any lessons learned and use
past experiences to improve future risk management plans.
Four generally accepted
“treatment” strategies for risks:
•Risk Acceptance: Risk thresholds are within acceptable
tolerance, and the organization chooses to accept this risk.
•Risk Transfer: The organization chooses to transfer the risk or
part of the risk to a third-party provider or insurance company.
•Risk Avoidance: The organization chooses not to move
forward with that risk and avoids incurring it.
•Risk Mitigation: The organization establishes an action plan
for reducing or limiting risk to acceptable levels.f
Thank you
For
Being Attentive
Jaweriya Mazhar