questions need to be answered

profileADAM90s
2.pptx

Introduction to Risk Management Chapter 1

Sections 1.1-1.22

3/28 Class

Introduction to Risk Management

After the 2008 financial crisis, international regulatory agencies required a risk management process and disclosure.

Traditionally, risk management has been applied to the risks associated with accidental losses.

Changes are now occurring and found in more contexts.

Traditional risk management was inherent to insurance focusing on how a hazard can happen to an individual or organization.

The Risk Management Environment

Traditional Risk Management

-Associated with accidental losses and/or insurable risk

Enterprise Risk Management

–A holistic view of risk that is much broader and includes all potential risks both internal and externally.

Definitions of Risk and Risk Management

Defined very differently by ISO, COSO, and RIMS, know the definitions.

Risk Management Environment

There are four high-level categories of risk:

Hazard or pure risks

Operational risks

Financial risks

Strategic risks

Risk Management Environment, cont.

Hazard risk-A risk from accidental loss, including the possibility of loss or no loss.

Risk profile-a set of characteristics common to all risks in a portfolio.

During the 20th and 21st Centuries we have seen a global financial crisis. With the failure of Enron, the 2002 Sarbanes-Oxley Act was created.

The act requires risk management controls to be disclosed and discussed by public companies with annual financial statements.

MORE TRANSPARENCY!

Risk Management Environment, cont.

The European Union adopted both the Solvency II and Basel III Standards for risk management in financial organizations.

The risk management of accidental losses is historically the most widely practiced type of risk management, the 2011 tsunami in Japan revealed the need for a reevaluation.

Also brought-forth the need of many organizations to reevaluate their supply-chain risks.

The major challenge of risk management professionals is to navigate the evolving environment and develop a process to guide their organization toward meeting their objectives.

This challenge now involves a holistic approach and recognition of interconnections of both external and internal risks with rapid change.

Benefits of Risk Management

Then 2008 US Federal Reserve Chairman Ben Bernanke, stated that a significant factor in causing the 2008 financial crisis was risk-management weakness at large global financial institutions.

He stated that supervisors must redouble their efforts to improve their risk-management practices.

Traditionally organizations have only utilized risk management for hazard risks. Their techniques were primarily risk mitigation and transfer.

Bernanke and other economists believe that risk management must address systemic risk in the economy.

Benefits for an Organization

All organizations face many risks by operating.

Most only have a negative outcome, but other risks can have either a positive or negative outcome. (financial investment, etc.)

How Do We Reduce The Cost of Hazard Risk?

Addressing the cost of risk--The total cost incurred by an organization because of the possibility of accidental loss.

What else?

Reduce the Deterrence Effects of Hazard Risks

Fear of possible future losses.

Tends to make senior management reluctant to undertake activities they deem to be “too risky.”

Consequently, the organization is deprived of potential benefits.

Risk management reduces the deterrence effects or uncertainty about future accidental losses by making them less frequent, less severe, and more foreseeable.

Risk Management helps to alleviate fears, increase profits, and makes the organization a safer investment.

Reduce Downside Risk

Includes losses and failures.

These are inevitable in any business or speculative risk.

Examples:

A company faces a downside risk when it introduces a new product

A financial institution has a downside every time they make a loan or investment.

Operational Risk is part of an organization’s processes, and the downside risks includes delays, errors, cost increases, and failure of any aspect of the operation.

To reduce downside risk, organizations can use stop-limits.

Triggers are hit when a pre-determined stop-limit is reached, then it is reviewed.

Intelligent Risk Taking

Easy? Yeah somewhat!

Successful organizations usually take risks to grow and increase profits.

This type of risk can create either a positive or negative outcome.

Risk appetite is determined, and only the total exposed amount that an organization wishes to undertake on the basis of risk-return trade-offs for one or more desired expected return.

Maximize Profitability

Risk management can help organizations achieve the optimal risk-adjusted return on capital.

Too much or too little risk, you may exceed your capability to withstand potential losses.

Evaluate to potential risk and any activities associated.

Risk manager can help an organization evaluate their risks and potential return of each option and their effect(s) on the organization meeting its objectives.

Holistic Risk Management

Traditional risk management was conducted in silos within an organization.

This approach would look like:

Risk manager managing hazard risks

Finance manager managing financial risks-credit and exchange rate risks

Operations manager managing equipment failure risks

IT managing cyber risk

What was the problem? Transparency and Knowledge!

Now there is an integrated, holistic approach that manages risks across all levels and creates more of a complete picture of an organization’s risk portfolio and profile

Senior Management is more in the know of what is going on.

Legal and Regulatory Requirements

The US now requires public companies to use and report on risk management

In 2009 the SEC (Securities and Exchange Commission) approved a rule requiring corporate disclosure about risk.

The Sarbanes-Oxley Act of 2002 requires both management of public companies and their auditors to assess and report on financial risk and controls.

The Dodd-Frank Act of 2010 requires the financial bank holding companies and other public companies to have a risk committee with at least one member being a risk-management expert.

Basel III and Solvency II in Europe also have financial requirements.

Reduced Systemic Risk

The Dodd-Frank Act, Solvency II, and Basel III have the purpose of reducing systemic risk.

If there is not an effective risk management program in place, the organization’s risk can result in failure not only for the organization, but the economy.

The financial crisis of 2008-2009 caused a wide-array of negative consequences that caused a lot of uncertainty.

The benefits of a risk management program at a systemic level reduces the risk and reassures investors and the public about reasonable risk and provides economic growth.

Risk Management Objectives and Goals

A very structured and logical foundation.

The support of an organization’s senior management is essential for a risk management program.

Why?

The risk management professional should design their program with objectives and goals that align with the organization’s overall objectives.

This should reflect the risk appetite internally and externally.

Risk Management Goals

A company’s risk management program should have goals to manage the risks that the organization will face.

These goals should be incorporated into the risk management framework and the process designed to meet a particular organization’s objectives.

Typical risk management goals include:

-Tolerable uncertainty -Legal and regulatory compliance

-Survival -Business continuity

-Earnings stability -Profitability and growth

-Social responsibility -Economy risk management operations

Tolerable Uncertainty

Your goal is tolerable uncertainty, meaning to align risks with the organization’s risk appetite.

VaR-Value at risk can be used to analyze various financial portfolios with different assets and risk factors.

Can be calculated quickly and easily to determine risk factor returns on a portfolio.

Legal and Regulatory Compliance

Legal obligations are satisfied

Typically include:

Standard of care that is owed to others

Contracts entered into by the organization

Federal, state, local, provincial, territorial laws and regulations

Survival

An organization can be viewed as a structured system of resources such as financial assets, machinery and raw materials, employees, and managerial leadership.

The organization generates income for its employees and owners by producing goods and services to meet others’ needs.

Many risks can threaten the survival of the organization.

Traditionally hazard risk was viewed as a major threat to survival (injury to employees or customers), but techniques such as loss control and risk transfer (insurance) are used to manage the risk.

There are more broader risks and ultimate survival depends on anticipating and recognizing emerging risks.

Business Continuity

#1 Goal!

An organization cannot interrupt its operations for any time.

The risk management professional must set forth a clear, detailed understanding of specific operations with a maximum tolerable interruption interval for each operation.

Steps that should be taken to provide continuity include:

-Identify activities whose interruptions cannot be tolerated

-Identify the types of accidents that could interrupt such activities

-Determine standby resources that must be immediately available.

-Ensure that the availability of the standby resources at the most difficult time.

Earnings Stability

Important goal!

Rather than strive for the highest possible level of current profits, look at earnings stability over time.

Precision forecasting with fluctuations in asset values, liability values, and risk management costs for insurance are important.

Profitability and Growth

An organization’s senior management might establish a minimum amount of profit (or surplus) that no event should reduce.

This is achieved by the risk manager identifying the risks that could prevent this goal from being reached, as well as the risks that could help achieve this goal within the context of the organization’s overall objectives.

Most organizations set goals for growth, and a risk manager focuses on two opposing effects:

1) The reduction of potentially negative consequences of risk.

2)Supporting the organization’s entrepreneurial risk-taking.

Social Responsibility

A goal for most organizations.

Shows their commitment of ethical conduct, as well to the local community and society.

The risk manager must look at societal commitments and overall reputation.

Economy of Risk Management Operations

Risk management programs should operate economically and efficiently.

One way to measure the economy of a program is through benchmarking, in which an organization’s risk management costs are compared with those of similar organizations.

RIMS (Risk and Insurance Management Society), a global organization conducts an annual benchmarking survey that organizations can use to compare their cost of hazard risk with others in their industry.

The survey combines expenditures for risk assessment, control, financing, as well as administrative costs of risk management programs.

Trade-Offs Among Goals

Risk management objectives a goals on an organization are interrelated, but sometimes are not consistent.

Senior management might be advised by the risk manager that a growth goal may not be achievable without adjusting either risk appetite or growth strategy.

Legal obligations or restrictions may conflict with an operational goal and are nonnegotiable.

Alternative treatments or approaches may need to be considered that will provide the same benefits.

Basic Risk Measures

According to physicist Lord Kevin, “To measure is to know…if you cannot measure it, you cannot improve it.”

Risk managers need to measure risk in order to know the nature of the risks and how to manage to meet their organization’s objectives.

Quantifying risks that can be measured should be done for the basis of a risk assessment.

The Basic Measures That Apply to Risk Management

Exposure- Any condition that presents a possibility of gain or loss, whether or not an actual loss occurs.

Volatility-Frequent fluctuations, such as in the price of an asset.

Likelihood-Relies on the Law of Large Numbers which is a mathematical principle stating that as the number of similar but independent exposure units increases, the relative accuracy of predictions about future outcomes (losses) also increases.

Consequences-The measure of the degree to which an occurrence could positively or negatively affect an organization.

Time Horizon-Estimated duration.

Correlation-A relationship between variables.

Questions

1. What are the definitions of risk and risk management from ISO 31000, COSO, and RIMS?

2. Define the four high-level categories of risk.

3. Summarize the significance of the Sarbanes-Oxley Act, Dodd-Frank Act, and Solvency II and Basel III.

4. How can risk management create new risks even when it brings old risks under control? Explain.

5. Risk management utilizes a holistic approach for determining and addressing risks and does not use the common silo-approach. What is the main problem with the silo approach?

6. Define and provide a real-world example for each of the eight risk management goals.