What are the main drivers for successful ERM implementations in organizations?
CHAPTER 30 Alleged Corruption at Chessfield: Corporate Governance and the Risk Oversight Role of the Board of Directors
RICHARD LEBLANC
Associate Professor of Law, Governance, and Ethics at York University
The police and the regulator contacted the author early in the author's governance review process. When the author attended his first meeting with the chairman of the board of directors for Chessfield Inc. and the regulator, the regulator mentioned the word corruption explicitly. Now the New York Police Department was also investigating the conduct of some of Chessfield's directors, by interviewing them and collecting evidence. The author's role was to conduct a thorough governance review, with a specific focus on risk management, and report his findings and recommendations to the regulator and board of directors. Chessfield is a fictional company; however, this case is based in part on actual situations that have been modified and disguised.
CHESSFIELD INC. AND ITS BOARD OF DIRECTORS
Chessfield is a well-known American company in the sports and entertainment industry. It is headquartered in New York, and is led and governed by an outspoken and successful CEO and a blue-chip board of directors. Several directors are household names and have been on the board for many years, knowing each other in social and professional circles. One director had been on the board for 28 years, the second-longest-serving director had been on the board for 24 years, and so on. The shortest-serving director's tenure was seven years. It was an all-male board, known fondly among a few directors as “the good ol' boys.”
Governance and decision making were informal, and almost always by consensus. By externally viewing Chessfield, it would be difficult to glean that it had any governance shortcomings whatsoever. It had a majority of directors who were current or former CEOs, a separate chair, and other independent directors from prestigious New York professional services firms. It had three committees that were all composed of independent directors. The size of the board was 10 members. Chessfield appeared to comply at least in letter with all applicable governance regulations in place at the time.
WHISTLE-BLOWER COMPLAINT
A credible and anonymous whistle-blowing complaint had recently reached the regulator, from a possible former director or officer.
Chessfield was not a publicly traded company, but was in an industry that was highly regulated, given the potential for misuse of information and cash receipts, as well as the potential for harm (of patrons) and for organized crime.
The regulator had concerns about the compensation awarded to the CEO being approximately four times that of comparable industry peers, and potentially creating an incentive for undue risk taking; the apparent lack of internal controls over material risks, including operational risks; and possible impropriety by certain directors in using their positions for self-gain.
MESSAGE FROM THE CEO REQUESTING TO MEET THE AUTHOR
Chessfield's CEO e-mailed the author when the author was in Dallas, Texas, at a conference, asking for a meeting within 24 hours if possible. At that meeting in New York, with the CEO and Chessfield's legal counsel, the author was told that the company had just been put under regulatory investigation.
The author was asked whether he could assist by reviewing Chessfield's overall governance, and, in particular, risk management and compliance practices. The board chair had recommended the author to the regulator because the author had assessed a previous board on which the chair served at the time, and the author was independent.
The author agreed to conduct the governance review of Chessfield for a mutually agreed fee under two conditions. He made it clear to the board chair, CEO, and general counsel that:
1. He would be entitled to any document or access to any personnel he requested.
2. He must have a direct reporting line to the regulator, including separate meetings without the presence of any director or officer.
All parties agreed, including the regulator. The author was to have separate meetings with both the regulator and the New York Police Department official conducting the investigation.
GOVERNANCE DOCUMENTS, INTERVIEWS, AND ON-SITE OBSERVATION REQUESTED BY THE AUTHOR
As a starting point, the author asked for the following: any and all governance documents, including recent board minutes and meeting materials, bylaws, relevant correspondence, board and committee charters, risk registers, compensation plans, and financial statements (in no particular order).
The author, as part of his methodology and data collection, would also interview each director, each member of senior management, the internal audit function, and possibly other assurance staff. The author would also tour Chessfield's facilities and have access to the cash room1 so he could see operations firsthand. All requests were acceded to, and the author began his work. This work took about 30 days on a part-time basis, and a report was generated to the board and endorsed by the regulator.
DOCUMENT REVIEW
It soon became apparent that governance documentation at Chessfield was minimal. The board did not have guidelines; committees did not have charters; position descriptions for board leadership roles, directors, and the CEO did not exist; and meeting agendas and minutes were very sparse, with the average meeting agenda being one page with key headings only. There was no documented, board-approved strategic plan or risk appetite framework. Indeed, many material risks were not reported to the board at all.
Documentation for key board decisions, including evidence of review, reporting, assurance, due diligence, and deliberation, appeared to be either lacking meaningful content or nonexistent.
INTERVIEW DATA
Many noncompensation committee directors neither knew nor approved what or how the CEO and the former CEO (who was also on the board as the longest-serving director) were paid. The nonexecutive board chair had a consulting stream paid to him by Chessfield, which certain other directors did not know about. The internal auditor was junior, inexperienced, and unqualified; had operational and revenue generation responsibilities; and had little exposure to, or oversight by, the audit committee. Audit committee members did not possess adequate financial literacy or relevant qualifications. The compensation committee chair rarely attended meetings in person for health reasons, and did not possess compensation expertise. His tenure as committee chair exceeded 11 years. He was a former service provider (now retired) of a large New York law firm.
CEO COMPENSATION ISSUE
There was little correspondence evidencing the basis on which total compensation was awarded to the CEO. There was a spreadsheet with a password that was provided to the author by the CEO's assistant. When the author interviewed the chair of the compensation committee about the lack of either supporting documentation or independent assurance by a compensation consultant, the compensation committee chair told the author that the compensation committee was composed of experienced businessmen who were of the view that the CEO's compensation was appropriate given the CEO's performance.
The author was not provided with any CEO goals and objectives, key performance indicators, or trigger and target requirements for short-term or long-term incentives to be awarded or to vest. The foregoing items were asked for but, to the author's knowledge, did not exist. The compensation committee chair had friendships and social relationships with a number of directors, including the CEO. The basis for the quantum of compensation awarded to the CEO (1) relative to peers or (2) relative to company performance was not explicit.
The board chair and compensation committee chair said to the author that the regulator did not have the business judgment to opine on the quantum of CEO compensation. The author responded by saying that (1) the quantum of total compensation was very high compared to industry peers of a similar size and complexity, but, more importantly and particularly given this fact, (2) there should be a visible, diligent process to employ such business judgment of directors and to explicitly link pay to performance, which appeared to be what was lacking in any event.
RISK MANAGEMENT
There were very few explicit risk management protocols or systems to identify and mitigate material risks, including operational risk in particular. In the cash room, the controls were all manual (i.e., paper, with greater capability for management override or weaker controls, it would appear), as information technology was not used. Risk identification and assessment were not documented explicitly. There was no risk function reporting directly to the board or to a committee. Indeed, there was no risk function.
There was little evidence that internal controls over operational and compliance risks were designed and/or effective, regularly tested by the internal audit function, and reported to the board or a committee. A number of directors appeared blindingly ignorant of their obligation to oversee risk management.
SELF-DEALING ISSUE
There was not a conflict of interest policy that applied to directors. Board guidelines did not exist to address confidentiality, the use of corporate opportunity, the treatment of inside information, related-party transactions, or identifying and adequately addressing perceived conflicts of interest. The author was unable to ascertain self-dealing, but robust policies and controls did not exist to deter, detect, monitor, or enforce anticorruption, in any event.
BOARD COMPOSITION
As mentioned previously, several directors were long-serving. Independent directors were selected originally (and to the author's observation, still) on the basis of personal knowledge and prior working relationships. All directors, however, were believed to comply with formal independence standards in place. There was little if any documentation of such independence, of the expertise directors possessed, or of collective expertise that the board needed.
PREPARATION OF THE AUTHOR'S REPORT AND COMMUNICATION WITH THE REGULATOR
Given the foregoing, the author prepared 43 recommendations for the review of the regulator and the board of directors.
The regulator endorsed the 43 recommendations that the author provided, with minor modifications and with two additional recommendations to establish a compliance committee of the board and to have a board-approved strategic plan, which the regulator suggested and which the author incorporated into his report. There were 45 recommendations in the author's final report, which he was now to present to the board of directors of Chessfield. The report was 14 pages long.
CHESSFIELD BOARD MEETING TO DISCUSS THE AUTHOR'S RECOMMENDATIONS
The author was invited to present his report and 45 recommendations to the full board of directors of Chessfield Inc. in New York City at 10 A.M. on a Friday morning in December. This was a special board meeting, and the author's report was the only item on the agenda.
The author had 15 minutes to present a summary of his recommendations. (Note: The board had a full week prior to the board meeting to read the author's report.) There was to be a 45-minute period of dialogue and questions and answers, after which the author would leave the room and the board would discuss the report in closed session.
The author was told by the general counsel that the regulator had requested to the chair of the board that the board approve a resolution adopting the author's report in whole, supported by a commitment to implement the recommendations within the time frame prescribed in the report. The chairman of the board was to telephone the regulator shortly after the meeting to report whether this requested approval had occurred. (The regulator had told the chair early in the process that Chessfield was close to having its license to operate revoked because of the governance and risk shortcomings.)
When the author was invited into the boardroom, he saw that it was very formal. There were portraits of past directors on the walls, large mahogany chairs, and dark wood. The author did not observe any use of technology, such as laptops or tablet computers, which is typical in most boardrooms now.
At the board meeting, the author presented 45 recommendations based on his review and discussions with the regulator. A time frame for each recommendation was set out (up to eight months, eight to 12 months, and 12 to 18 months) within the report, along with independent validation and reporting back to the regulator, to ensure execution of the recommendations.
TWO CONTENTIOUS RECOMMENDATIONS
Directors accepted all of the recommendations initially except for two, which were: (1) that the three longest-serving directors (28, 24, and 23 years, respectively) resign, and (2) that a woman be selected for directorship and serve on the compensation committee in particular.
As far as the three longest-serving directors resigning was concerned, one director (28-year tenure) had, during the data collection phase, invited the author to his estate in Boston prior to the final report to tell the author how important the board was to him, and how he should be allowed to continue to serve so long as he is able. The author indicated politely that regulators are moving toward term limits of nine or 10 years to guard against entrenchment and compromising of independence over time. The author said that one of his recommendations was not only that he and two other directors should resign, but also that term limits be in place at 15 years for all incumbent directors and nine years for all new directors.
RECOMMENDING A WOMAN TO SERVE ON THE BOARD
The second issue was more contentious and surfaced at the board meeting itself. It was the author's recommendation that a woman be added to the board.
One director remarked, “Dr. Leblanc, you want us to put a lady on the board?” (Emphasis in original remark.) Another director remarked, “Perhaps we can have a lady in a wheelchair who is a lesbian.” Many of the directors laughed at this comment.
The author indicated that evidence existed that CEO turnover is more sensitive to stock return performance in firms with a greater proportion of women; that women are more likely to join committees that perform monitoring-performing tasks; and that male directors have fewer attendance problems, the greater the number of women on the board.2 The author also indicated that the regulator had agreed to all of his recommendations, including this one, and that there was a need for the skill set of compensation and information technology literacy on the board, given prior concerns and the transformation of the industry.
CONCLUSION
This case concluded one month after the author's presentation to the board, when the regulator asked the author to black-line, with suggested improvements, forthcoming regulations to apply to all companies under the regulator's purview, adopting many of the recommendations the author had provided for Chessfield.
QUESTIONS
1. What is your assessment of the situation at Chessfield?
2. What recommendations would you provide to the regulator?
3. What is your opinion of the governance regulation of Chessfield? In what ways should governance regulation improve, given the above?
4. What are the learnings and broader implications of this case?
NOTES
1 Part of this company's business operation involved receiving cash directly from consumers, which was assembled, tallied, and reconciled in what is known in the industry as the “cash room.”2 R. B. Adams and D. Ferreira, “Women in the Boardroom and Their Impact on Governance and Performance,” Journal of Financial Economics 94 (2009): 291–309.
REFERENCES
1. Adams, R. B., and D. Ferreira. 2009. “Women in the Boardroom and Their Impact on Governance and Performance.” Journal of Financial Economics 94, 291–309.
2. Basel Committee on Banking Supervision. 2010. “Principles for Enhancing Corporate Governance.” Bank for International Settlements Communications, October.
3. Canadian Securities Administrators. 2008. “Request for Comment: Proposed Repeal and Replacement of NP 58-201 Corporate Governance Guidelines, NI 58-101 Disclosure of Corporate Governance Practices, and NI 52-110 Audit Committees and Companion Policy 52-110CP Audit Committees, 31 OSCB 12158.”
4. Canadian Securities Administrators. 2010. “Staff Notice 58-306 2010 Corporate Governance Disclosure Compliance Review,” December.
5. Caplan, G. R., and A. A. Markus. 2009. “Independent Boards, but Ineffective Directors.” Corporate Board, March/April, 1–4.
6. Carter, D. A., F. D'Souza, B. J. Simkins, and W. G. Simpson. 2010. “The Diversity of Corporate Board Committees and Financial Performance.” Corporate Governance: An International Review 18:5 (September), 396–414.
7. Carter, D. A., B. J. Simkins, and W. G. Simpson. 2003. “Corporate Governance, Board Diversity, and Firm Value.” Financial Review 38, 33–53.
8. Elson, C. F., and C. K. Ferrere. 2012. “Executive Superstars, Peer Groups and Over-Compensation—Cause, Effect and Solution,” August 7. Available on SSRN website at http://irrcinstitute.org/pdf/Executive-Superstars-Peer-Benchmarking-Study.pdf.
9. Financial Reporting Council. 2011. “Guidance on Board Effectiveness.” Financial Reporting Council Limited, March.
10. Financial Reporting Council. 2012. “The UK Corporate Governance Code,” September. Available online at www.frc.org.uk/Our-Work/Publications/Corporate-Governance/UK-Corporate-Governance-Code-September-2012.pdf.
11. Fraser, J., and B. J. Simkins, eds. 2010. Enterprise Risk Management: Today's Leading Research and Best Practices for Tomorrow's Executives. Hoboken, NJ: John Wiley & Sons.
12. Group of 30. 2012. “Toward Effective Governance of Financial Institutions.” Washington, DC, 1–96.
13. House Committee on Financial Services. 2010. “Dodd-Frank Wall Street Reform and Consumer Protection Act.” H.R. 4173, June 25.
14. Institute of Chartered Secretaries and Administrators. 2009. “Boardroom Behaviours—A Report Prepared for Sir David Walker by the Institute of Chartered Secretaries and Administrators.” Report, June.
15. Institute of Corporate Directors. 2006. “ICD Key Competencies for Director Effectiveness.” Competency list issued, Toronto.
16. Leblanc, Richard. 2011. “A Fact-Based Approach to Boardroom Diversity.” Director Journal, Institute of Corporate Directors 154, March: 6–8.
17. Leblanc, Richard. 2012. “Discussion Notes for: OSC Dialogue.” Toronto, October 30.
18. Leblanc, Richard. 2013. “Forty Proposals to Strengthen the Public Company Board of Directors' Role in Value Creation, Management Accountability to the Board, and Board Accountability to Shareholders.” International Journal of Disclosure and Governance 10:4, 1–16.
19. Leblanc, Richard. 2013. “Review of the Regulatory Guideline for [a Regulator], Black-Lined Report,” March 19.
20. Leblanc, Richard, 2013. “Review of the Regulatory Standard for [a Regulator], Black-Lined Report,” March 6.
21. Leblanc, Richard, et al. 2012. “General Commentary on European Union Corporate Governance Proposals.” International Journal of Disclosure and Governance 9:1, 1–35.
22. Leblanc, Richard, and James Gillies. Inside the Boardroom: How Boards Really Work and the Coming Revolution in Corporate Governance. Toronto: John Wiley & Sons, 2005.
23. Leblanc, Richard, and Katharina Pick. 2011. “Separation of Chair and CEO Roles: Importance of Industry Knowledge, Leadership Skills & Attention to Board Process.” Director Notes: Conference Board. New York, August.
24. Lorsch, Jay, ed. 2012. The Future of Corporate Boards. Boston: Harvard Business Review Press.
25. Monks, R. A. G., and N. Minow. 2011. Corporate Governance. 5th ed. Chichester, UK: John Wiley & Sons.
26. National Association of Corporate Directors. 2010. “Template for Disclosure of Director Skills and Attributes,” August. [email protected].
27. National Commission on the Causes of the Financial and Economic Crisis in the United States. 2011. “The Financial Crisis Inquiry Report.” U.S. Government Printing Office. Washington, DC, January.
28. Neill, D., and V. Dulewicz. 2010. “Inside the ‘Black Box’: The Performance of Boards of Directors of Unlisted Companies.” Corporate Governance: An International Review 10:3, 293–306.
29. Trautman, Lawrence J. 2012. “The Matrix: The Board's Responsibility for Director Selection and Recruitment.” Florida State University Business Review 11, 1–66. Available at http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1998489.
30. U.S. Senate Permanent Subcommittee on Investigations. 2011. “Wall Street and the Financial Crisis: Anatomy of a Financial Collapse.” U.S. Government Printing Office. Washington, DC, April 13.
31. Useem, M. 2006. “How Well-Run Boards Make Decisions.” Harvard Business Review 84:11, 130–138.
ABOUT THE CONTRIBUTOR
Richard Leblanc is a governance lawyer, certified management consultant, and Associate Professor of Law, Governance & Ethics at York University. He holds a PhD focusing on board of director effectiveness. He has published in leading academic and practitioner journals, has advised regulators on corporate governance guidelines, and, as part of his external professional activities, has served as an external board evaluator and governance adviser for Australian Securities Exchange (ASX), London Stock Exchange (LSE), New York Stock Exchange (NYSE), NASDAQ, New Zealand Stock Exchange (NZX), and Toronto Stock Exchange (TSX) listed companies, as well as in an expert witness capacity in litigation concerning corporate governance reforms.
CHAPTER 31 Operational Risk Management Case Study Bon Boulangerie
DIANA DEL BEL BELLUZ
President, Risk Wise Inc.
Bon Boulangerie is a bakery business located in Oakville, Ontario. When the owner, Ray Pane, purchased the business three years ago, it consisted of a single site with baking facilities and a retail store and café. Based on market research with the bakery's retail and café clientele, Ray began to change and expand the product offerings to increase the volume of sales and margins. He also began a new line of business, wholesaling to local restaurants and high-end grocery stores within a 20-kilometer radius of the bakery.
Based on the success over the past three years (see Exhibit 31.1), Ray has made a strategic decision to expand his wholesale business, with the goal of tripling profits over the next three years (see Exhibit 31.2). He expects to accomplish this by: (1) covering a larger territory (i.e., expanding to a 120 km radius) for wholesaling to local restaurants and independent grocery stores across the entire Greater Toronto Area, and (2) introducing a new business line, white label products that he can supply to major supermarket chains.
|
|
(Actuals) |
|||
|
(all figures in $000's) |
Year 3 |
Year 2 |
Year 1 |
|
|
Income |
|
|
|
|
|
Café |
300 |
273 |
246 |
|
|
Retail Bakery |
718 |
624 |
562 |
|
|
Wholesale—Restaurants |
410 |
234 |
0 |
|
|
Wholesale—Other Retailers |
359 |
312 |
0 |
|
|
Total Revenue |
1,786 |
1,443 |
807 |
|
|
Operating Expenses |
|
|
|
|
|
Cost of Inventories Sold |
1,349 |
1,090 |
610 |
|
|
Marketing, General, and Administrative |
361 |
291 |
163 |
|
|
Total Expenses |
1,710 |
1,381 |
773 |
|
|
Net Income |
76 |
62 |
35 |
|
Exhibit 31.1 Financials for Past Three Years
|
|
(Projections) |
|||
|
(all figures in $000's) |
Year 6 |
Year 5 |
Year 4 |
|
|
Income |
|
|
|
|
|
Café |
348 |
331 |
315 |
|
|
Retail Bakery |
831 |
791 |
753 |
|
|
Wholesale—Restaurants |
960 |
768 |
614 |
|
|
Wholesale—Other Retailers |
4,306 |
2,153 |
1,076 |
|
|
Total Revenue |
6,444 |
4,043 |
2,759 |
|
|
Operating Expenses |
|
|
|
|
|
Cost of Inventories Sold |
4,926 |
3,105 |
2,175 |
|
|
Marketing, General, and Administrative |
1,301 |
816 |
557 |
|
|
Total Expenses |
6,227 |
3,921 |
2,732 |
|
|
Net Income |
217 |
121 |
27 |
|
Exhibit 31.2 Projections for Next Three Years
To realize this strategy, Ray has leased and outfitted a separate baking facility to be primarily dedicated to supplying the wholesale business. Ray also hired a full-time vice president of sales and marketing (see Exhibit 31.3 for a summary of the Bon Boulangerie management team) to take over from him on the wholesale side. Finally, he purchased a second previously owned delivery truck and hired a full-time distribution manager.
Growth in the first three years is attributable to enhancement of product offerings and continual drive to find efficiencies in operations. In year 4, the new baking facility will open. It is expected that it will take several years to add new wholesale customers and wholesale products. Therefore, there will be unutilized capacity in the new facility. It is anticipated that expanding the wholesale business will, at least initially, require an increased level of product development, marketing, sales, and distribution.
Exhibit 31.3 The Bon Boulangerie Team
· Ray Pane, President and CEO. After a successful legal career, Ray decided to pursue his dream of being an entrepreneur. He has a passion for fine food and is committed to providing his customers with high-quality, wholesome, and artisanal products.
· Janice Sweet, Manager, Accounting. Janice is a Chartered Professional Accountant who came to Bon Boulangerie with five years' experience in several finance roles at a furniture retailer. She joined Bon Boulangerie halfway through its third year of business. She is the company's first in-house accountant. Prior to her joining, the accounting was done by an external bookkeeper on a contract basis. Janice has begun to introduce more systematic accounting processes. She is also working with Ray to develop more forward-looking reporting, including projections and forecasts of revenues and costs.
· Joe Silkwood, Vice President, Sales and Marketing. Joe was hired near the end of year 3 when Ray decided to expand the wholesale business. Joe is a classic salesman; he's outgoing and optimistic. He has nearly 10 years' experience in the grocery business.
· Rick Kneader, Manager, Baking Operations. Ray hired Rick as the head baker for the retail bakery at the beginning of year 1. Rick is a true artisan who successfully developed the new products that have been responsible for the increases in sales in the café and retail bakery in its first three years of business. He also runs a tight ship and has managed costs well, despite shifting to products with higher-cost ingredients. With the opening of the new commercial baking facility in year 4, Ray has received a promotion to Manager of Baking Operations for both the retail and the commercial facilities. He will now spend less time working with his hands and more time overseeing junior bakers while managing the expenses at the commercial baking facility.
· Mohammed Sharif, Manager, Distribution. Mohammed has been hired by Ray to manage distribution to the expanding roster of wholesale customers—both restaurants and other retailers. He has worked in the trucking field for 15 years. He will expand and supervise the existing team of drivers who were hired in year 2 to distribute product to wholesale customers. Ray has also made it clear that he expects Mohammed to find efficiencies and reduce shipping costs.
· Jelena Zarinovic, Manager, Retail Operations. Jelena has been with the company since it started. In fact, she worked for the previous owners. She is the only full-time retail sales employee. She is friendly and adored by customers and the many part-time sales associates. However, she is less interested in paperwork and is finding it challenging to learn the new accounting procedures that Janice is implementing.
QUESTIONS
1. How does Ray's strategic objective translate to the operational level, that is, what is his key operational objective(s) for the wholesale business line?
2. What performance drivers, that is, the internal capabilities (e.g., people, processes, and systems), and external factors need to be present to achieve operational success?
3. What are the risk factors that drive the uncertainty around achieving operational objectives?
4. Which risk drivers are most likely to impact operational objectives?
5. How large of an impact might those key risk factors have? Hint: Use scenario analysis to explore the full range of potential outcomes.
6. Based on your analysis, what are the “significant few” factors on which Ray should focus his attention to manage the operational risks associated with the new facility?
7. What underlying assumptions underpin your analysis and conclusions?
ABOUT THE CONTRIBUTOR
Diana Del Bel Belluz is the President and Founder of Risk Wise Inc., a risk management consulting firm that provides advice and support to executive leadership teams and boards who want to achieve more effective, proactive, and strategic management and oversight of risk. Her forte is helping leaders to solve the people issues associated with bringing enterprise risk management (ERM) to life in their organizations. Diana advances the practice of ERM through her thought leadership as an educator, conference organizer, speaker, and author of ERM resources, including numerous articles, book chapters, and the Risk Management Made Simple Advisory, a quarterly publication of ERM implementation tips and resources available at www.riskwise.ca. She also wrote Chapter 16, “Operational Risk Management,” of the book Enterprise Risk Management: Today's Leading Research and Best Practices for Tomorrow's Executives, edited by John Fraser and Betty J. Simkins (John Wiley & Sons, 2010). She holds bachelor's and master's degrees in systems design engineering from the University of Waterloo and is a professional engineer.
CHAPTER 34 Turning Crisis into Opportunity Building an ERM Program at General Motors
MARC S. ROBINSON
Assistant Director, Enterprise Risk Management, GM
LISA M. SMITH
Assistant Director, Enterprise Risk Management, GM
BRIAN D. THELEN
General Auditor, GM
This case study chronicles the ground-up implementation of enterprise risk management (ERM) at General Motors Company (GM), starting in 2010 through the first four years of implementation. Discussion topics include lessons learned during implementation and some of the unique approaches, tools, and techniques that GM has employed. Examples of senior management reporting are also included.
I think risk management is an element of all good executive management teams and boards. It will ensure viability in downturns and high-risk periods. I think if that is done not only within the automotive industry, but on a global and specifically on a national scale, economies will be in better shape because it is additive. If everybody is doing their job in assessing and understanding risk, the ultimate outcome will be much more positive for our national economy and society, and it is incumbent that corporate leadership understands that responsibility.
—Daniel F. Akerson, Chairman and Chief Executive Officer, General Motors, October 2012
BACKGROUND AND IMPLEMENTATION
The enterprise risk management (ERM) program at General Motors was founded in late 2010 at the direction of GM's then newly appointed chief executive officer (CEO), Daniel F. Akerson, who sought to leverage the program as another means to achieve a competitive advantage in the industry. Having gone through bankruptcy in 2009 as a new board member, Akerson felt that a more robust risk management program would help guide the organization around the drivers of killer risks1 going forward. His goal was to help the company ensure that it was prepared, agile, and fast to respond in an ever-changing world. Perhaps most importantly, Akerson wanted an ERM program that would focus not only on risks but on opportunities as well.
A chief risk officer (CRO) was selected and appointed from within, and the Finance and Risk Policy Committee of the board of directors was chartered to oversee risk management as well as financial strategies and policies. In support of the program, a senior manager and director joined the team. Risk officers were also identified and aligned to all direct reports of the CEO; this helped to ensure that all aspects of the business were covered. The CEO is the ultimate chief risk officer, and his direct reports are the ultimate risk owners. Members of the risk officer team were carefully selected by senior leadership based on their strong business experience, financial acumen, and most of all their ability to lead in the identification and discussion of risk in an objective and transparent manner. These representatives were expected to actively participate in the evolving ERM program while still handling their existing responsibilities.
In 2011, the general auditor and CRO roles were combined, and in support of this change, the Audit Committee assumed oversight of risk management. The Finance and Risk Policy Committee continued its focus on financial policy and decision making.
GENERAL MOTORS' APPROACH TO ENTERPRISE RISK MANAGEMENT
The ERM process was built with GM's vision in mind: to design, build, and sell the world's best vehicles (see Exhibit 34.1). The process itself was geared toward the identification and management of key (potential “killer”) risks. The ERM team assisted line management in developing a list of top company risks, identifying risk owners, assisting management in the development of risk mitigation plans in conjunction with the management teams, providing ongoing monitoring, and reporting results to senior management and the board.
Exhibit 34.1 GM Risk Management Process
The scope of GM's initial ERM program intentionally did not fit the typical ERM definition of an all-encompassing, holistic approach. As a bottom-up implementation, senior leadership wanted ERM to focus on those elements of risk and opportunity that were most important to the company. We at GM have since enhanced our program with additional high-impact features, which are detailed later in this chapter.
Overall, however, our approach was to move away from the typical ERM view, which focuses on “what can go wrong.” We took a more actionable view of “what can go right,” placing emphasis on both opportunities and risks, to ensure that we were leveraging our ERM program to be well-positioned in the industry.
LESSONS LEARNED: IDENTIFYING RISKS
A critical success factor that has been a part of our program since inception has been to continually seek out several views, including views from sources outside the company, of risks that the industry and company may face. In addition to regular meetings with our risk officers, we conducted a number of focus groups and workshops to gain insight into potential blind spots that may exist, and to capture various views on emerging risks. To solicit this information, we reached out to deep thinkers and those with broad business experience both within and outside of our organization and sought input across demographic groups, including Generation Ys or recent college graduates and young professionals.
The careful attention devoted to capturing several perspectives from various demographics, both inside and outside of the organization, has led to some great successes and has consistently influenced the composition of our top risks list. Our commitment to seeking out diverse views has helped us to avoid confirmation bias,2 and helped us to ensure that we are not seeing our world through rose-colored glasses.
LESSONS LEARNED: DEVELOPING TOP RISKS LISTS AND REPORTING TO SENIOR MANAGEMENT
There is a tendency to underestimate risks. If you go back and look at the problems we ran into over the last four to five years, everybody knew there was a housing bubble there. Everybody knew the banks and others were stretched out. But rather than face up to the fact that you had this huge risk and understand what the consequences were of the risk materializing, it was relatively easy to say, “Well, it is a low-probability risk, so let's go on—things look good.” It may be a low-probability event, but those low-probability events have a way of materializing, and therefore we need to better understand what happens.
—Mustafa Mohatarem, Chief Economist, General Motors, October 2012
While we understand the value of assessing probability and impact for risks, we have made additional improvements to our process for ranking and prioritizing risks. In the past, we facilitated meetings at which our risk officers were asked to score proposed risks individually along defined impact and probability scales. The output of the session was a typical “heat map” with risks that were ranked or plotted based on probability and impact scores.
However, we quickly learned that not only was this a very tedious process, but it injected a great deal of subjectivity since many of the participants did not really have specific knowledge of these parts of the business. We have also learned from various world events, such as the Fukushima disaster in Japan, that there may be a tendency to dismiss risks with the potential for very high impact because they have a very low probability of occurring. These low-probability events are often risks that companies cannot afford to miss. As we looked back on what has worked well or needed improvement, we thought there was a better way to provide our board and other stakeholders with more meaningful and actionable information. This prompted us to make a number of changes to improve the program.
First, we gave the responsibility for assessing the probability and impact ratings related to risk to the senior executives who were assigned the primary responsibility for overseeing the risks, since they were uniquely positioned to provide the most accurate assessment. We stopped the practice of asking risk officers to vote on impact and likelihood levels. Instead, when developing (or refreshing) the top risks list, we employed a real-time, web-based pairwise comparison3 tool to assist in prioritizing the risks in relation to each other. When developing our top risks, we briefed participants (risk officers) with precise risk descriptions to help enable their decisions when voting on each risk pair. Once we completed the various pairing sequences, the tool generated our preliminary risks list. This preliminary list was then subjected to various sense checks4 prior to delivering a proposed top risks list to our senior management or board.
Second, we moved away from using a ranked top risks list altogether. Too much time was being spent on whether a risk should be number 3 or number 5, for example, when the choice did not at all affect how the ERM team or management would address the risk. We moved instead to a three-tiered approach (Exhibit 34.2), which more broadly separated risks by their relative importance. We did not limit ourselves to any predefined number of risks in any given tier; we looked for natural breaks in terms of concurrence on what is a top risk (often looking at the pairwise scoring) versus what is more of an emerging risk.
Exhibit 34.2 Three-Tiered Approach
Third, we focused on using three measures—the levels of inherent, current, and residual risk—as indicators of where the organization currently viewed the effect of its mitigation activity and where the level of risk was expected to be upon completion of the mitigation plans. We created a five-point scale with definitions surrounding the ratings for inherent and residual risks (see Exhibit 34.3), and asked the respective risk officers to provide these assessments in consultation with their Executive Committee members (GM senior leaders reporting directly to the CEO) using the ERM risk template. While just a minor modification to the previous ERM risk template, this assessment of current and expected future risk levels quickly became a focal point for senior management and the board committees when presented. With current and future risk levels now documented, we were able to provide the board with better insight into the status and projected movement of our top risks (see Exhibit 34.4). We continued to provide the standard heat map of risks, but the new chart provided the type of forward-looking insight and status that heat maps do not provide. The new chart has been very well received and we continue to utilize it.
Exhibit 34.3 Five-Point Scale
Exhibit 34.4 Heat Map
LESSONS LEARNED: UNDERSTANDING CORPORATE CULTURE
The ERM implementation at General Motors has enjoyed great success for several reasons: There has been excellent support from the CEO and senior management; we have a strong, knowledgeable, and highly engaged ERM team and risk officer organization that touches every part of the business; and we have been able to garner proactive involvement through understanding and properly leveraging corporate culture.
We recognized early on that we would need to ensure that the ERM environment at General Motors was an open forum where people could share freely. In fact, the importance of objectivity and transparency cannot be understated in terms of the success of any ERM program. Perhaps it is attributable to human nature, but we found in the past that people had a tendency to identify a problem and keep it to themselves while they tried to resolve or address it, rather than putting it on the table for discussion. As this was not the culture that we wanted in the ERM program, we reduced the probability that this would occur by selecting the right people to lead by example.
We looked for several specific traits when selecting our risk officers:
· High potential executives and leaders
· Strong business experience and good financial acumen, including strong technical expertise in the region/function of responsibility
· Superior communication skills; unafraid to speak up and discuss issues openly
· Big picture thinkers
· The ability to reach across the organization and provide outstanding support to the top-line executive they represent
To the extent that we had any concerns regarding the ability of participants to be objective and transparent, we were able to largely avoid these issues by seeking out and selecting the right risk officer team members. The team has been highly engaged, and we are beginning to see evidence of this culture spreading through their various areas of accountability. We are now at the point where our services are often on a “pull” rather than “push” basis, which has been very rewarding to achieve.
My role as a risk officer is to look across the product development enterprise, and identify risks which are systemic that we may already be addressing, but I am taking a look to make sure that the risk is sufficiently addressed. Or, in the case of where it is a new technology or a new risk, working with the owner to take a look from a strategic perspective. What can they do more? What can they do better in terms of addressing the risk? Are they engaging all of the cross-functional groups? Do they really understand the societal impacts of the technology they are putting in place? As engineers, we tend to think about F = MA,5 but this is about expanding the scope a little bit more so that we take it at a holistic level.
The ERM program gets quite a bit of support from senior leadership. We regularly review the status of our projects with leadership and we also seek advice and guidance from them on where they see risks in the enterprise that we might not otherwise be addressing in our regular channels.
—Katherine Johnson, Director, Global Product Development, General Motors, October 2012
We also understood that our risk officers came from various functional and regional positions, and would not necessarily be experts in risk management. As a result, we created an orientation/training for risk officers that was very well received. Once the first two individuals were given the orientation we did not have to contact anyone else to take it, as word quickly spread because it was seen as value-added and good use of their time. Risk officers contacted us to ask for the orientation, and this positively impacted the engagement of our program participants.
It was during these orientations that we learned more about various micro cultures in the company. One of the slides in the orientation talked about various risk management techniques: to avoid, accept, reduce, or transfer risk. Early on, as we explained the slide to one risk officer—that there are many ways to deal with risk—he had an insightful comment: “You know, I am really glad that you are implementing this program. Some think that risk is bad and you have to eliminate it 100 percent.”
The orientation sessions provided an environment for healthy discussions about risk being ubiquitous and therefore always a part of doing business. We stressed that the intention of this program was to manage risk, not attempt to eliminate all risk. To reinforce this, we discussed different ways to deal with identified risks, including accepting them. Going forward, we verbally included these points with every risk officer orientation. This was another means for us to support the transparency and objectivity we sought—people would not feel comfortable talking about risks openly if they thought there was a corporate culture that mandated all risk was to be eliminated.
Our orientation session also included discussions about our risk templates (see Exhibit 34.5). While companies, including General Motors, seem to embrace the use of red-yellow-green-colored charts, the problem of course is that the use of red is often associated with a failure or poor result. We were concerned, given the prior comments, that people might not adequately assess their risks if they believed the point of the program was to make everything green on the charts. At one of our risk officer meetings, a risk officer presented a chart showing a key risk that was rated with an orange color, both before and after mitigation efforts. We took time in the meeting to point this out—that some risks “are what they are”—and there is only so much we can do to be prepared. The point is not to get the risk to be rated green, but to assess it accurately for what it is, and to ensure that we are prepared and doing everything we reasonably can to deal with it.
Exhibit 34.5 Risk Template
LESSONS LEARNED: STRATEGIC RISK MITIGATION AND DECISION SUPPORT
The central philosophy of GM's ERM approach is that the responsibility for risk mitigation and opportunity seizing rests with the operational leaders of the company. No staff can or should address all the varied risks of the company; they lack the awareness, expertise, manpower, and authority. But ERM can provide—and has at GM even at this early stage—enormous value beyond the core and critical functions of risk identification and risk education. This is essential to have enterprise risk management rather than enterprise list management. GM's ERM is able to provide this value because of a combination of a unique perspective and expertise in a set of analysis, facilitation, and decision-support tools of particular relevance to risk mitigation and opportunity seizing.
Through the risk identification process, ERM staff is exposed to the entire range of global functions and issues, along with internal assessments of corporate strengths and weaknesses, in a way that is typically limited to senior management. Risk identification also requires engaging with internal and external thought leaders and experts to think through emerging risks and blind spots to create an information base similar to a partner at a strategy consulting firm. The assignment to focus on risk and opportunity, with a corporate perspective and without operational responsibilities, gives a frame of mind and freedom for strategic thinking that is often helpful to decision makers.
At GM, the unique perspective within ERM is made more valuable with a set of tools that helps decision makers better understand and evaluate issues involving external risks and opportunities, and thereby improve their decisions. Any list of top risks will have both internal risks—typically involving execution or compliance—and external risks, whether from shocks, predictable events, evolutionary changes, or actions from outside actors like competitors, current or potential partners, dealers, suppliers, governments, or unions. Internal execution risks are usually managed with special focus from operating units, while compliance risks are typically addressed by education and controls monitored by specialized staffs such as security, information technology, human resources, legal, tax, and audit.
External risks, on the other hand, are more difficult for operating leaders to evaluate and react to appropriately. There is a natural human tendency to think that tomorrow's external environment will be like today's, only better. Operating leaders tend to focus on their own strategies, worldviews, and “day jobs,” failing to fully consider external players and uncertain events.
Even in a negotiation, the tendency to focus on the company's perspective can be a problem. Of course, the negotiating team is aware of the other party at the table—whether a union, supplier, or potential partner. But even experienced negotiating teams can benefit from thinking through systematically what is truly important to both sides and how to improve negotiating leverage and to frame issues. However, the biggest blind spots for negotiators usually relate to parties not at the table or to the aftermath of a deal. For example, GM often engages in bargaining with its labor unions while those unions are simultaneously bargaining with other companies in the industry. Understanding the perspective and issues in those parallel negotiations can be important to the outcome at GM, particularly since there is often an expectation that the pattern established with one company will apply to others. Union locals or subgroups can also have powerful effects on the final outcome. In other contexts, predicting possible rejection by regulators may lead to a different strategy on a merger or acquisition deal, or understanding legislative risk might alter a corporate initiative. Identifying stresses and differences in interests in advance can lead to favorable restructuring of a joint venture or early resolution of an underlying issue.
GM's ERM staff has adapted a set of tools designed to improve decisions in complex, multiplayer situations or issues. The approach usually involves organizing workshops with cross-functional leaders and subject matter experts, facilitated by ERM staff. When the issue or event is known—such as a major current negotiation or an announced change in fuel economy regulations 10 years in the future—the workshop focuses on answering three questions:
1. Who else can affect the outcome? (Players)
2. What can GM and others do? (Options)
3. What do GM and the other players want? (Preferences)
The importance of thinking through these questions systematically can be shown in a mistake from GM's past. Like other auto companies, GM relies on independently owned dealers to sell its vehicles. In the late 1990s, some GM executives saw the potential for significant strategic benefits from having a few company-owned dealers, such as an unfiltered exposure to shoppers and a chance to test new marketing and retailing concepts. Though it was recognized that dealers would oppose the idea and that it would be illegal in some states, extensive planning proceeded and a major initiative—GM Retail Holdings—was announced. Within days of the announcement, GM quickly realized this was a poor decision, and within months GM's CEO went to the annual dealer association conference to announce the termination of the initiative and to apologize for it.
What happened to cause such an unfortunate outcome? First, the leaders of the initiative misread GM's preferences. They thought that GM valued the potential benefits of the company-owned dealers more than they would regret an adverse dealer reaction. When the angry reaction came forcefully through many channels to numerous executives, it turned out that the assessment was wrong. Second, some options controlled by the dealers were not well understood. When dealers started pulling or threatening to pull some of those levers, GM recognized the decision's downside potential. Third, the executives forgot a player—state legislatures. Legislation was introduced in several states (where GM Retail Holdings was considering the placement of dealerships) that would make company-owned stores illegal competition for the independent dealers, and it seemed likely that the legislation would pass. If you miss preferences, options, and/or a player, your strategy, negotiation, or initiative can fail.
GAME THEORY
When GM's actions will have an impact on what the others do (see Exhibit 34.6), a form of game theory can help avoid misunderstandings. Using game theory,6 the team can put themselves into the shoes of each player and ask whether they want each option to be taken (including options they do not control) and how important that option is relative to others on the list. With these assessments, it is possible to identify a natural outcome7—where momentum will lead the issue—as well as a danger outcome8 and a target outcome9 for GM. The information gathered is so rich that it can guide both strategy and tactics. Because there is a tight logical connection between the recommendations and the inputs provided by participants, decisions are often changed based on the analyses.
Exhibit 34.6 Game Theory
Since the combined knowledge of the participants about the external players and their options is usually strong, the predictions of their behavior are remarkably accurate. Even when there is disagreement or uncertainty about what other players want, the analysis can identify robust strategies or narrow the areas where additional information is needed. GM used to have a Defense Operations unit that once developed a design for a military vehicle that the designers thought could displace the Humvee10 used by the U.S. Army. At the time, GM had recently acquired the Hummer brand (since discontinued), which sold a civilian version of the Humvee, so this idea generated significant controversy. Game theory analysis showed that the right actions for GM depended heavily on the preferences of the Army, with disagreement about what they were. GM leaders decided to ask the Army, inviting key generals to hear about the Defense Operations concept. The generals made clear that they had no interest in switching from the Humvee, and further investment was avoided.
The high value that GM leaders attach to the predictions and insights that the game theory process generates is reflected in the more than 120 times the tool has been deployed since 1999. The issues have included negotiations of all types, competitive strategy, public policy strategy, crisis management, and new business development, and have covered every region and most functions. Speed and efficiency are also major attractions; a complex issue can be analyzed and action plans developed and approved in less than one week. When the Risk Management function was created, a natural home for these decision-making tools became obvious.
WAR GAMING AND SCENARIO PLANNING
Even when GM decisions do not affect the decisions of other players—as often is the case with long-term product or technology strategies—it can be valuable to think through how other players will act, since that can give a more accurate and unbiased assessment of the risks and opportunities. War gaming workshops often start with known information on the strategies, strengths, weaknesses, and plans of key players. The key trend or issue that is the focus of the war game is explained; for example, there may be tighter fuel economy regulations scheduled to go into effect in some country in a few years. Then participants put themselves in the shoes of the other players and predict their responses to the trend or issue. Implications for GM's strategy and opportunities to mitigate risks are then identified.
When events are highly uncertain or even have low probability, like an economic crisis or oil shock, it can still add value to assess how external actors would respond if the event were to occur. This helps to stress test the contingency plans and can identify potential opportunities or risks to mitigate. By adding external players to the scenario planning, the need to bring in additional functions becomes apparent. If and when the event occurs, the action or crisis team will have a broader perspective and connection to important expertise, and information will be easier to access. The ERM staff can facilitate this type of contingency planning and the cross-organization connections through the risk officer network.
Thinking through how an event can spread or become a crisis makes the organization more sensitive to signals and triggers for more intense planning and preparation. A tool that GM has used in contingency planning is “DefCon” level,11 an idea borrowed from the U.S. Defense Department. When a risk with high impact but low likelihood is identified, it may not make sense to spend time and resources on detailed plans and preparations, particularly if there is likely to be significant notice or more urgent signals prior to the event. Instead, there can be a “plan to plan” with only preliminary analysis done at an early stage but commitment made for further analysis and action if particular indicators or signals are seen. The leadership group decides whether the event likelihood has reached a more serious DefCon level, triggering the appropriate preparations and actions.
External risks are difficult for any organization to understand and manage, particularly if the risks are only emerging or rare, or involve parties not at the table. By going beyond risk identification to helping decision makers achieve a 360 degree understanding of the external environment and players, ERM can aid good decision making. By using their unique perspective and a broad array of tools, ERM staff can frame the risks and opportunities and make actionable recommendations, thereby making the good decisions more likely and more robust.
LOOKING FORWARD
As we enter our third year of ERM, we have a number of initiatives under way to enhance the ERM program and better integrate it with other internal control efforts. First, we have worked with our internal audit leadership to ensure that the top company risks are being considered in their annual internal audit risk assessment, which drives the internal audit plan. These top risks will be one of many factors used to assess which processes, areas, and functions in the company should be considered for an internal audit.
We continue to look for ways to identify and assess emerging and blind spot risks and opportunities earlier and more comprehensively. In that regard, we intend to engage the corporate Intelligence Network—a cross-functional and informal group of people whose jobs require looking for societal, market, technology, and competitive trends relevant to GM around the world to supplement the knowledge and sources of the risk officer network and ERM team.
There is always room for improvement in the plans to mitigate risks and seize opportunities. Both the risk officer network and the ERM staff can be valuable resources to an individual risk officer or functional leader trying to analyze a risk, develop a plan, and check it for robustness. We intend to utilize these capabilities more fully and systematically, particularly for complex cross-functional and cross-regional issues.
While our initial ERM focus has been to identify and manage top risks, we also realize that this is only one part of a successful ERM program. With reasonable attention to the top risks now in place, we are ready to address oversight of the day-to-day operational controls. In this regard, we are in the process of developing an enhanced program for operational control self-assessment (CSA),12 which is often cited as a fundamental and critical component of any successful ERM program. This program will begin with a joint risk assessment conducted across the organization in conjunction with internal audit.
GM implemented various versions of CSA over the years, but these processes waned over time and no longer fully support the business as intended, largely due to resources being redirected to support Sarbanes-Oxley resource requirements. There are many ways to achieve control self-assessment, and we recognize that typical programs are often criticized as not adding value because they lack substance or are simply check-the-box exercises. On the other hand, Sarbanes-Oxley at its core is intended to be a management self-assessment of controls over financial reporting despite having evolved into requiring very in-depth, time-consuming assessments.
There is a need to avoid either creating a burden on the organization to the point where the cost outweighs the benefits (which is how many businesses have viewed Sarbanes-Oxley) or creating a program that is low-cost but lacks any substantive value. Our goal in creating an improved CSA program is to strike a balance so that we are maximizing value to the organization and our shareholders by enhancing operational control assurance while spending resources wisely.
The approach we have developed is a policy-based CSA that will start with asking business unit operations' line managers simple yes or no questions with regard to their compliance on specific policy requirements. However, we are taking this process a few steps further by requiring the managers to attach supporting evidence for their responses. To ensure that the supporting evidence is valid and sufficient, an ERM CSA representative will consult with the manager on control design and perform a quality assurance validation of the submission. The representative will also respond to any questions and assist in action plan development as needed. The ERM CSA representative will also review any action plans to correct self-identified deficiencies to make sure that the action plan addresses the root cause of the issue (see Exhibit 34.7).
Exhibit 34.7 CSA Root Cause
We prefer this approach because it strengthens accountability at the operational level having frontline responsibility for internal controls. As a policy-based program, it drives behaviors that strengthen the company as a whole:
· Policy and process owners realize that they can leverage policies as a means to ensure results. If key risks are addressed in the policy, they will be assessed through CSA, and deficiencies will be uncovered and resolved by operating management.
· All business teams obtain a clear and consistent understanding of major activities and objectives of global or regional processes.
· CSA elevates the importance of up-to-date, accurate policies that address key risks.
Given that CSA is a global program, we expect that implementation will continue well into 2014.
CONCLUSION
We expect that the ERM tools we have implemented will improve GM's ability to identify, exploit, or mitigate, and communicate risk to senior leaders and the board of directors. We view this as a competitive advantage for General Motors that will enable us to react more quickly with improved and well-defined actions. We believe that an integrated risk management process (ERM, Sarbanes-Oxley, CSA, and consolidation of other compliance/assessment types of activities) will enable GM to utilize its compliance resources much more efficiently. Importantly, it will enable the company to have a consolidated, holistic view of risk and allow management and the board of directors to take comfort knowing that mitigation activities will be visible and tracked, and owners will be held accountable.
QUESTIONS
1. What are the pros and cons of having risk officers as part-time assignments within different functions and business units?
2. Can you think of a company whose strategy failed due to their failing to consider the actions of external players?
3. Do you think that companies need to experience a crisis to take risk seriously?
NOTES
1 Killer risks are those that would have a major effect on the short- or long-term profitability of the enterprise.2 Confirmation bias is the tendency of people to favor information that confirms their beliefs.3 Pairwise comparison is a method of ranking that compares a list two at a time. Earlier assessments are used to reduce the total number of comparisons.4 Sense checks are a means of avoiding large errors by reviewing preliminary results with experts or management.5 F = MA stands for the basic equation of mechanics: Force = Mass × Acceleration.6 Game theory is a large topic. The tool described is a practical application that predicts actions based on assessments of the options and preferences in the situation or “game.”7 Natural outcome is a stable outcome (set of choices by the various players on the options they control) that will result if players do not behave strategically. It can be thought of as momentum.8 Danger outcome is a stable outcome that is worse than the natural outcome from the perspective of the project sponsor; it can result if assessments are mistaken or players make errors.9 Target outcome is a stable outcome that is the best potentially attainable by the company, given the options and preferences of the various players. It is better for the company than the natural outcome and mitigates the risk of the danger outcome.10 Commonly known as the Humvee, the High Mobility Multipurpose Wheeled Vehicle (HMMWV) is a military transport used by the U.S. Army for many functions and produced by AM General.11 DefCon is short for defense condition and is used by the U.S. military to describe the desired state of readiness. Wikipedia has a good description and history.12 Control self-assessment is a technique that has managers review and certify the existence and quality of the controls around policies, procedures, and practices.
ABOUT THE CONTRIBUTORS
Marc Robinson is Assistant Director of Enterprise Risk Management at GM. He is an economist with over 25 years as an internal consultant at GM. He has also taught at UCLA, Stanford University, and the University of Michigan, and was Senior Staff Economist on the Council of Economic Advisers under President George H.W. Bush.
Lisa Smith, CRMA, CCSA, is Assistant Director of Enterprise Risk Management at GM. She has served in a variety of audit-related roles since joining GM in 2002, including the global implementation of ERM starting in 2010. She has an MBA from the University of Michigan and also serves as an instructor for the Institute of Internal Auditors.
Brian Thelen has been General Auditor at GM since 2011, and served as Chief Risk Officer through July 2014. Prior to that, he was Vice President of Audit Services at Delphi Corporation, Vice President of Internal Audit Services at Waste Management, and general auditor at American Standard. He started his career at Ernst & Young and has a CPA and an MBA.
CHAPTER 25 Uses of Efficient Frontier Analysis in Strategic Risk Management A Technical Examination
WARD CHING
Vice President, Risk Management Operations, Safeway Inc.
LOREN NICKEL, FCAS, CFA, MAAA
Regional Director and Actuary, Aon Global Risk Consulting
Over the past 25 years, the use of advanced quantitative financial and behavioral analysis has received increasing attention in an attempt to better understand and predict the performance impact on hazard risk portfolios. The limitations of single discipline modeling and decision making, which can lead to misreading of financial and performance risks across broad operational categories, were highlighted by the collapse of the financial markets in mid-2007. The need to answer broader risk questions has motivated the risk management industry (i.e., insurance, actuarial, finance, audit, and operations) to recalibrate and redirect core analytical protocols toward a more integrated approach.
The effort to take advantage of complex data techniques was, in part, stimulated by the evolving risk management framework integration into what is now being modestly referred to as enterprise risk management (ERM) or strategic risk management (SRM). 1
Within the 2013 Risk and Insurance Management Society (RIMS) SRM Implementation Guide, the concept of strategic risk management is defined as a “business discipline that drives the deliberations and actions surrounding business-related uncertainties, while uncovering untapped opportunities reflected in an organization's strategy and execution.”
What distinguishes this definition from previous descriptions of enterprise-wide risk management (ERM) approaches is the effort to sustainably deliver a robust fact-based strategic dialogue across the entire organization. This new strategic dialogue requires an analytical framework that is dynamic and encompasses all areas of an enterprise. In this chapter, we demonstrate how the use of efficient frontier analysis (EFA), and many of its derivative techniques, provides a robust portfolio approach to hazard, operational, market, and reputational risk domains.
STRATEGIC RISK MANAGEMENT FRAMEWORK EXAMINED
One of the most important ways SRM is beneficial for an organization is its ability to create opportunities for interaction and risk discovery (sometimes called “risk sensing”) across organizational boundaries. This has not always been the case with previous ERM frameworks, where conceptual frameworks were overly formalized and yielded very narrow risk estimates. For most active SRM practitioners, this has proven not to be the case. Even in the area of insurance, where dialogues around risk estimates of frequency and severity are common, the effort to cross internal organizational boundaries has sometimes been met with significant resistance or dismissal.
An illustration of the SRM approach as described by RIMS is shown in Exhibit 25.1 .
Exhibit 25.1 Strategic Risk Management Diagram
Source: RIMS Strategic Risk Management Implementation Guide 2012.
While first impressions might suggest that the SRM framework is a closed system, in actuality it is a continuous cycle with a robust opportunity for various parts of an organization to recognize and examine risk profiles within the context of a strategy setting, with the focus toward establishing the trade-off between risk transfer and risk assumption.
Moreover, the notion of risk appetite and risk tolerance combined with scenario and stress testing speaks to a more comprehensive analytical framework. 2 The intent of this framework is to drive a different set of “analytically informed” discussions among decision makers who may also be asking whether the risk profile of the organization constitutes a competitive opportunity.
As Fox and Merrifield point out:
Strategic risk management focuses on the risks that may impede or accelerate the organization's strategic objectives for creating value, whether that value is expressed as market share, profit, service provision, donor levels, social impact, or other benefit. Strategic risk management serves as a source of competitive advantage for decision making in two aspects: risk to the objectives themselves and risks arising from the plans to meet the objectives. While many organizations include risks to the objectives themselves, little consideration generally is given to the risks arising from the plans to meet the objectives, nor to the additional opportunities evolving from the underlying strategy and from emerging and dynamic risks. When addressed early and linked to the control framework, strategic adjustments can be made relatively quickly.
Fox and Merrifield, RIMS Strategic Risk Management Implementation Guide, 2013
The fundamental difference between traditional risk assessment and SRM is the conscious effort to define advantage or exploitable risk profiles that can be used to sustainably differentiate or distinguish the organization in a competitively noisy environment.
MODERN PORTFOLIO THEORY AS A FOUNDATION FOR EFFICIENT FRONTIER ANALYSIS
Modern portfolio theory (MPT) is a mathematical method developed in the early 1950s and built out through the mid-1970s as a theory of finance that focuses on the maximization of portfolio return while minimizing the risk for a given amount or level of expected return, by specifically choosing the proportions of various assets contained in the portfolio. For the most part, MPT consists of a number of mathematical formulations that simulate and identify the impact of a risk-adjusted strategy investment diversification where the portfolio risk profile is collectively lower in value or volatility than any one asset.
In general, MPT models asset returns as a normally distributed function and recognizes risk as the standard deviation of return where the portfolio is viewed as the weighted combination of assets. Thus, the return of a given portfolio is considered the weighted combination of the asset return streams (Markowitz 1952).
Expected return is characterized as:
where Rp is the return on the portfolio, Ri is the return on the asset i, and wi is the weighting of the asset i, which represents the asset i in the overall portfolio.
The operational concept behind MPT is that the assets in an investment portfolio should not be selected individually but should consider how their relative prices and values change across the portfolio. For many, this speaks to the relative trade-offs between calculated risk and expected return. Therefore, MPT would argue that assets and investments with higher expected returns attract higher measurable levels of risk. If the objective is to maximize the highest possible return on a portfolio of performing assets, MPT provides a way to describe and select those assets and investments that fit the return demand.
From an SRM perspective, within any operating organization there exists a series of hazard, operational, market, human capital, and reputational risks. These risks, while generally identified and mitigated separately, in fact exist in an integrated operational space—a risk portfolio. The essential questions that MPT can attempt to answer are:
· What is the economic value of an organization's material risk profile when characterized as a financial portfolio?
· How can the economic and operational volatility of an organization's risk profile be characterized dynamically and intertemporally?
· Are an organization's risk mitigation strategies and methods efficiently matching an organization's risk profile?
· If an organization changes its operations in a material way, what impact can be visualized across the organization's risk portfolio?
· Given the financial and operational activities of an organization, can an efficient 3 risk profile be determined? What trade-offs might be required to achieve an efficient risk profile? Efficiency could be defined as maximizing the contractual financial return relative to the expected utility of risk transferred to a third party. If the trade is equal—in other words, the price of the transference effectively matches the economic dynamics of the risk—then the trade may be considered efficient for both parties.
· If risk retention and risk transfer are considered two independent variables in an organization's risk profile distribution, how can the value of risk retention and risk transfer be maximized throughout an organization's insurance purchasing approach?
The approach to answering these questions is found with a number of mathematical techniques within MPT, notably efficient frontier analysis (EFA), dynamic financial analysis (DFA), capital asset pricing modeling (CAPM), or some other behavioral economic analysis of choice under conditions of information uncertainty. For the purpose of this chapter and its case study, we focus on the use of EFA within an insurance purchasing context.
It is important, however, to point out that some assumptions contained within the original MPT framework have been controversial and have generated a lively even-sided debate within the academic and practitioner literature base. 4
The key assumptions include:
· The owners of portfolios are exclusively interested in the optimization problem.
· Asset returns are jointly normally distributed and random.
· Expected correlations between assets are fixed and constant without a time frame—in effect, forever.
· All parties to the use or exploitation of the portfolio always maximize economic utility regardless of other information, expectations, or considerations.
· All parties to the portfolio are considered rational and risk-averse.
· All parties to the portfolio performance have consistent, timely, and the same information at all points in time.
· All parties have the ability to accurately conceptualize and calculate the possible distribution of returns to the portfolio, and these calculations, in fact, match the actual returns of the portfolio.
· The performance of the portfolio is free of tax or transaction costs, and there is no transactional or postreturn friction.
· All parties to the portfolio are considered price takers, and their behaviors and choices do not influence the price market for the portfolio.
· Like the transactional or postreturn friction assumption, capital to invest in the portfolio is free and without an encumbering interest rate.
· A priori risk volatility can be conceptualized, calculated, and known in advance of the portfolio's construction, including asset/investment selection. Also, the portfolio's risk volatility is constant except when significant or material changes to the asset/investment distribution are made. 5
For many, the primary criticism of the MPT model and many of its derivative subanalytics is that the assumptions are overly restrictive and do not adequately model real-world markets. Critics view MPT output and/or results as mathematical predictions about the future because many of the risk distributions, return calculations, and hypothesized correlations contained in the MPT approach are found in expected values. Since expected values are themselves statistical distributions, they may be inaccurate due to misspecification or may be subject to the influences of mitigating market information or circumstances.
Nonetheless, MPT and the use of EFA represent powerful ways to generate insight into portfolio performance and the prospective individual portfolio component efficiencies, which is a key step in implementing a strategic risk management philosophy.
PRACTICAL APPLICATIONS OF RISK MEASUREMENT FOR INSURANCE
Now we begin our journey through the practical application of risk theory applied to insurance risk and portfolios. The purpose of the process is to optimize insurance placements and risk limits for a relevant organization. We will start with a basic understanding of terminology, knowledge, and skills needed for a proper analysis, and then dive into the details and calculations necessary for a robust study. In the end, we will establish that this process can transcend insurance and be used in alternative risk transfer, noninsurance settings.
For the purposes of working through a real-life example, we need to establish insurance equivalents for the portfolio theory formulas. What follows is a list of definitions that we will use throughout this chapter and the equivalent portfolio theory definition.
From the previous section, we bring forth the standard portfolio theory formulas for the optimal return and optimal variance using the capital asset line:
Here the expected risk spend on an insurance portfolio, E(rsp), replaces the expected return on an asset, E(rp). The expected risk spend is defined as the expected losses not transferred in the insurance contract plus the costs of the insurance contract. The expected risk spend is based on the insurance contract at hand, and will differ (often significantly) based on different contracts analyzed as part of the analysis.
The risk-free rate is replaced by an insurance portfolio with no risk transfer (i.e., an uninsured risk line/portfolio).
The intent here is to set the steady state at no insurance purchase and determine if insurance will actually lower the risk to the organization. If it does, then insurance should be purchased. If it does not, insurance should not be purchased. In other words, on the capital market line for a given level of risk, you want to buy a portfolio with the highest level of return, but here you want to put together a risk portfolio with the lowest level of losses outside of the insurance contract for a given level of risk. By minimizing the losses, you are maximizing your return.
Visually, in our insurance example, you want to pick the bottom of the portfolio efficient frontier and not the one on the capital asset line as in typical portfolio theory.
Tail value at risk, also known as tail conditional expectation (TCE) or conditional tail expectation (CTE), is a risk measure associated with the more general value at risk. It quantifies the expected value of the loss given that an event outside a given probability level has occurred. 6
MODERN PORTFOLIO THEORY (MPT)
Given a portfolio of A, one would prefer B, C, or D as compared to A as shown in Exhibit 25.2 .
Exhibit 25.2 MPT Portfolio Preference
EFFICIENT FRONTIER INSURANCE FRAMEWORK
As for MPT, given a portfolio of A, one would prefer B, C, or D as compared to A as shown in Exhibit 25.3 . However, notice that the preferred portfolios are now below the stated portfolio, as the preference here is to lower the expected losses and premium dollars spent.
Exhibit 25.3 Efficient Frontier Framework Portfolio Preference
The replacement of the typical finance standard deviation is an important one. In most financial textbooks (and practical usage), the standard deviation is most often from a normal distribution. In our example, we may use any multivariate distribution that is applicable, but for practicality we have chosen closed-form lognormal/Pareto distributions, which are typically used in insurance. We have also made another significant variation in the use of the tail value at risk (TVaR) instead of the standard deviation. The intent of this replacement is that most insurance contracts are low-probability contracts, so the standard deviation does not completely describe the use or intent of the contract. By using the tail value at risk, we can focus on the main use of the insurance contract and allow for multiple distribution functions, which will better describe the underlying distribution for its intended use.
The given probability of the TVaR calculation is up to the user. We have selected a probability level of 95 percent, meaning that the worst 5 percent of outcomes are averaged to produce the TVaR figure at 95 percent.
The next complexity of selecting a TVaR calculation means that one will almost always be required to run a simulation model to determine the statistic. Only the most simplistic applications will allow for a closed-form expression of the measure of volatility. Therefore, we have chosen to use Monte Carlo simulation for our application of the efficient frontier for insurance portfolios.
The added benefit of using a simulation model is that we are now free to use multivariate distributions, complex correlations, copulas, and other transformations that may be too complex for most formulaic calculations. It is also important to note that most insurance portfolios contain more than seven to 10 different contracts/risks; so modeling is often a required component for any portfolio analysis.
We certainly do not want to gloss over the correlation concerns with insurance contracts, as there are many. It is becoming more common to use copulas (and different versions of copulas formulas—for example, a Gaussian copula or a Gumbel copula 7 ) to measure more complex correlations. The choice and use of correlations are critical elements of a proper model and should be reviewed with statisticians or actuaries versed in their use. 8 For our purposes, we have assumed no correlations, for the simplicity of the calculations and translation of the results into knowledge.
It should be noted that TVaR is a simple method to allocate capital for insurance risk. The TVaR demonstrates the level of risk for a given insurance line or contract. Capital can thus be allocated based on that level of risk. Capital allocation theory is beyond the scope of this chapter, as there are many other variations upon this theme for allocating capital. It should be noted that the next step beyond the portfolio optimization is capital allocation.
One immediate question with the introduction of the TVaR as a risk measure is: “What is the right level of risk?” Or in simpler terms: “What is the largest loss I am willing to take?” Management should make a conscious decision on the level of risk to take through a formal enterprise risk management program. Risk setting is a critical step in any efficient frontier analysis and should not be overlooked. For our purposes, we have assumed that the organization will seek to minimize risk and minimize the annual costs to the budget (i.e., uninsured losses and insurance costs).
With some liberties taken in the usage of financial theory in the development of our risk transfer methods, we can now build a framework to analyze risk and optimize risk transfer spends (i.e., like insurance). The framework is intended for financial professionals versed in financial theory and its applications. With proper application, many organizations across the world could more efficiently allocate their risk spends and reduce the risk to their balance sheets.
SAMPLE CASE STUDY
Let's start with a practical example of a large corporation with three basic insurance risks: earthquake exposure to buildings, workers' compensation insurance, and general liability insurance.
Earthquake risk is defined as the potential for loss to buildings and property from a large earthquake as well as business interruption following the event. For our sample company, management has chosen to insure earthquake risk with a policy that covers $25 million in business and personal property with a 5 percent per occurrence retention. Earthquake sprinkler leakage is not covered.
For workers' compensation, management has chosen to buy a retention policy with a $1 million per occurrence retention, with no upper limitation, as it is a statutorily unlimited coverage.
The general liability coverage is represented by a $25 million per occurrence limit and a $250,000 per occurrence retention.
Now that we have the insurance coverage, we can assume the risk of loss for each of the three lines of coverage follows basic loss distributions as follows:
1. Earthquake (EQ). Loss frequency has a Poisson distribution with mean λ = 0.1, and severity has a Pareto distribution with parameter θ = 5,000,000, α = 50,000,000.
2. Workers' compensation (WC). Loss frequency has a Poisson distribution with mean λ = 50, and severity has a lognormal distribution with parameters μ = 10, σ = 1.5.
3. General liability (GL). Loss frequency has a Poisson distribution with mean λ = 10, and severity has a lognormal distribution with parameters μ = 12, σ = 1.0.
Notice that because the retentions are rather large, we are more focused on the tail portion of the loss distributions. We have decided not to use correlations for this example, to allow the reader to more easily follow and replicate the figures. In reality, correlations would be a key input into the model and would help determine the optimal risk transfer structures.
Exhibit 25.4 is a brief summary of the expected losses for the insurance policy and to the corporation below retentions and above insurance limits. The intent of this exhibit is to show the risk profile of the corporation using the assumed distributions listed earlier.
|
|
Retention |
Limit |
Current |
|
EQ |
5% |
$25,000,000 |
$2,500,501 |
|
WC |
$1,000,000 |
Statutory |
$3,163,992 |
|
GL |
$250,000 |
$25,000,000 |
$1,597,373 |
|
Portfolio |
|
|
$7,261,866 |
Exhibit 25.4 Mean Retained Losses by Line
Note that there are many methods for fitting proper distributions and selecting the parameters to ensure good fits of historical data. Curve fitting is well beyond the scope of this chapter, and we will let the reader peruse other sources for details on loss distribution fitting.
With the knowledge of the current risk profile, we can now seek to optimize the portfolio and the insurance purchase by selecting different insurance options for our portfolio. By “options” we mean to choose different risk transfer contracts that can be used to modify the risk profile of the corporation. This can be done by taking a mathematical approach (using increments off of the current program) or by selecting common insurance contract terms known in the insurance marketplace. Exhibit 25.5 lists the options using the two different methods.
|
|
Option #1 |
Option #2 |
Option #3 |
Option #4 |
Option #5 |
|
EQ |
5% retention |
5% retention |
5% retention |
5% retention |
10% retention |
|
|
$20M limit |
$30M limit |
$40M limit |
$50M limit |
$25M limit |
|
WC |
$250K retention |
$500K retention |
$2M retention |
$3M retention |
$4M retention |
|
|
Statutory limit |
Statutory limit |
Statutory limit |
Statutory limit |
Statutory limit |
|
GL |
$500K retention |
$1M retention |
$2M retention |
$3M retention |
$500K retention |
|
|
$25M limit |
$25M limit |
$25M limit |
$25M limit |
$30M limit |
Exhibit 25.5 Portfolio Options under the Mathematical Approach
As one can see, there is almost an unlimited amount of options in the mathematical approach. The possibilities are only limited by your computing power. It should also be noted that the selections for the different options are based on simple increments from the current values. These options may not be available in the insurance marketplace. This is somewhat intentional, as the goal is to find the optimal mathematical solution and then find the insurance option that gets closest to that optimal solution. The coverage availability approach is shown in Exhibit 25.6 .
|
|
Option #1 |
Option #2 |
Option #3 |
Option #4 |
Option #5 |
|
EQ |
5% retention |
5% retention |
5% retention |
5% retention |
10% retention |
|
|
$20M limit |
$50M limit |
$75M limit |
$100M limit |
$25M limit |
|
WC |
$250K retention |
$500K retention |
$2M retention |
$5M retention |
$10M retention |
|
|
Statutory limit |
Statutory limit |
Statutory limit |
Statutory limit |
Statutory limit |
|
GL |
$500K retention |
$2M retention |
$5M retention |
$10M retention |
$500K retention |
|
|
$25M limit |
$25M limit |
$25M limit |
$25M limit |
$30M limit |
Exhibit 25.6 Portfolio Options under the Coverage Availability Approach
You will notice a subtle change in Exhibit 25.6 , as indicated by the bolded options. The difference here is that we have selected options that can be knowingly purchased in the insurance marketplace. For more historical reasons than anything else, insurance risk transfer has been based around round numbers for retentions and limits. By using these options, we are guaranteeing (assuming the entity is insurable) viable options for the corporation.
Now the mathematicians can begin their number crunching. Using the options for Exhibit 25.5 , we can determine the expected risk spend (expected losses to the corporation, which are the losses below the retention and above the limits) and the tail value at risk (TVaR) for each option, and then plot them on a graph. We have done this for each line described earlier and combined all the lines in a portfolio. We have assumed no correlations in the portfolio, to keep the mathematics and logic easier for the reader to follow.
To obtain Exhibits 25.7 to 25.10 , we have run a simulation model using a Monte Carlo simulator. There are various software programs that provide the capability to simulate losses by using different distributions. Readers may wish to try the parameters within their own software to follow along.
Exhibit 25.7 Earthquake Modeled Options
Exhibit 25.8 Workers' Compensation Modeled Options
Exhibit 25.9 General Liability Modeled Options
Exhibit 25.10 Combined Portfolio Modeled Options
Exhibit 25.10 provides the assumed insurance premiums for each of the mathematical options. In reality, we would work with insurance brokers to obtain insurance quotes for each of the options to arrive at a true market price for each option. The option exists to use an actuarial estimate of premium, which is not preferred. The reason an actuarial estimate of premium is not preferred is that the market does not always follow actuarial estimates and can often fall to other vagaries of market pricing (underwriting judgment, capital constraints, class restrictions, premium goals, etc.). Therefore, we recommend using different quotes provided by insurance brokers for each option. Given insurance premiums are presented in Exhibit 25.11 .
|
|
Current |
Option #1 |
Option #2 |
Option #3 |
Option #4 |
Option #5 |
|
EQ |
$2,941,765 |
$2,353,412 |
$3,618,371 |
$4,942,165 |
$6,008,556 |
$2,941,765 |
|
WC |
$288,796 |
$1,098,994 |
$607,957 |
$116,861 |
$64,051 |
$40,630 |
|
GL |
$1,359,385 |
$696,302 |
$261,277 |
$68,436 |
$26,041 |
$696,302 |
Exhibit 25.11 Given Insurance Premiums
Now with the options plotted (using our modeled losses, TVaR, and insurance premiums), we have created an efficient frontier and can determine the best option for a given level of risk. Ideally, we would select more than five options, and the options would be more complex. The beauty of the process is that it can be as simple or complex as one desires. The process is flexible so as to handle different risk measures (not just TVaR) and can optimize different costs of risk (losses, insurance spend, internal costs, etc.).
It is also important to have an enterprise understanding of our risk appetite and tolerance. By having a formal statement of risk appetite, we can use that knowledge in the proper selection of the options in our efficient frontier.
CASE STUDY GENERAL FINDINGS
Using the same charts as previously, we can make a few judgments about the options presented. For this example, let's assume the company does not want to lose more than $20 million in a fiscal period. This would be considered its risk appetite and is roughly equivalent to maximizing utility for a corporation. By selecting a program that puts the $20 million or more at risk, there is potential for breaching that corporate goal.
Note that the models assume that insurance is recoverable for the risk analyzed. This may not always be the case, so it is important to review coverage and ensure that the model is reflective of the coverage provided and that the insurance carrier's ability to pay is also reviewed.
The numbers and options have been chosen to reflect realistic scenarios. The results are typical of what we see in the insurance and corporate landscape.
Findings on the earthquake simulation are (see Exhibit 25.12 ):
· We have a wide variety of options and a wide variety of risk levels.
· The slope of the efficient frontier is very steep as a result.
· The options all lie close to the frontier, resulting in many efficient options.
· If the organization is using a risk appetite for only earthquake risks, then it would look at the efficient frontier below the $20 million tail value at risk level. (Options #3 and #4 qualify.)
Exhibit 25.12 Efficient Frontier on Earthquake Options
Findings on the workers' compensation simulation are (see Exhibit 25.13 ):
· We have a similar wide variety of options, but a much tighter range of risk levels.
· The slope of the efficient frontier is very shallow as a result.
· The options all lie close to the frontier, resulting in many efficient options.
· If the organization is using a risk appetite for only workers' compensation, then it would look at the efficient frontier below the $20 million tail value at risk level. All options qualify.
· Because workers' compensation risks are relatively stable, the model has only modest differences between options and all options are reasonable.
· To change the options to give a greater range of results, one could be more extreme on the options (assuming the insurance market is willing to provide such options to the corporation).
Exhibit 25.13 Efficient Frontier on Workers' Compensation Options
Findings on the general liability simulation are (see Exhibit 25.14 ):
· We have a similar wide variety of options, and a modest range of risk levels.
· The slope of the efficient frontier is shallow as a result.
· The options all lie close to the frontier, resulting in many efficient options.
· If the organization is using a risk appetite for only general liability, then it would look at the efficient frontier below the $20 million tail value at risk level. (All options qualify.)
· Similarly to workers' compensation, different options can be substituted here for a wider range of outcomes.
Exhibit 25.14 Efficient Frontier on General Liability Options
The portfolio shown in Exhibit 25.15 is simply the annual events for all three lines added together, again with no correlation assumptions (i.e., independence). Portfolio option #1 is the sum of each of the respective lines Option #1, with no aggregate insurance limitations assumed. The framework certainly allows for aggregations and correlations; we have not provided them here for simplicity.
Findings on the portfolio simulation are (see Exhibit 25.15 ):
· The portfolios no longer follow the efficient frontier, as some of the options lie considerably above the efficient frontier line.
· The slope of the efficient frontier is somewhat steep, and follows the risks that contribute to the portfolio (earthquake in this instance is driving the steep curve).
· If the organization is using a risk appetite for the entire portfolio, then it would look at the efficient frontier below the $20 million tail value at risk level. (Only option #4 qualifies.)
Exhibit 25.15 Efficient Frontier on the Combined Portfolio Options
We can now see how the efficient frontier insurance framework utilizes the information provided, combines a complex set of insurance structures, and uses a risk appetite to select the best portfolio option. This framework facilitates a company's ability to make fact-based decisions, using real-time information. The organization no longer has to wonder if it is getting the best deal or if there were other options that might have provided a better bang for its buck.
INTENDED USES FOR OUR APPROACH
It is important to note that this framework, as all others, has limitations in its use. The intended purpose for this framework is to help large corporate organizations with their risk management process and portfolio management. The framework is robust enough to handle both insurance risk and noninsurance risk. It is best used within an established enterprise risk management discipline.
The following is a brief description of the benefits of an ERM strategy and how our framework fits within those benefits, which is important for understanding the full potential of its use. We have referenced James Lam's (2003) benefits, as they are excellent.
The four benefits to risk management as defined by James Lam 9 are:
1. Managing risk is management's job.
2. Managing risk can reduce earnings volatility.
3. Managing risk can maximize shareholders' value.
4. Risk management promotes job and financial security.
In item 1, Lam indicates that management has access to critical information about the business and therefore has a duty to use it to manage risk. We agree wholeheartedly with his assessment, and our process is intended to improve senior leaders' understanding of risk and give them more transparency in managing costs.
In item 2, Lam indicates that top-tier companies better manage their earnings volatility through risk management activities. Too often firms do not consider risk management or relegate it to small, back-room activities. This often overlooks the value that can be had by minimizing volatility on major risks to the organization. By taking a more in-depth look at the portfolio of risk through the efficient frontier and making more data-driven decisions, volatility can be reduced.
In item 3, Lam indicates that firms can increase their shareholders' values by 20 to 30 percent or more by identifying opportunities for risk management and business optimization through a risk-based program. 10 This goes beyond just managing volatility and extends to a better-performing business model with more accurate information spread across the organization. Using risk-based measures is a critical element of any risk measurement department. Components like the efficient frontier require wide distribution and use; otherwise they are not getting the full attention they deserve.
For the real company this framework was modeled after, the efficient frontier was sent directly to the business leaders and they became owners of the risks for their particular areas of influence. They had to learn the language of risk and through a diverse corporate program are now using the risk assessments as part of their daily routines, leading to a better understanding of risk for the business leaders and more accurate information for the risk management team.
When implementing this framework at different companies, we often hear something to the effect of “What's in it for me?,” which really gets down to job and financial security for individuals, as noted in item 4. A truly robust framework should allow for better risk taking, as the guidelines have been set and approved by management. With a data-first strategy there should be less concern over losing your job, as long as the risk is within the tolerances set by management. Thus, when a calculated risk does happen, the organization is ready to respond. All too often, the opposite is true and a surprise event leads to the ouster of a senior leader. We believe that our framework will help provide senior leaders with the information they need to take calculated risks and therefore preserve their livelihoods, regardless of their golden parachutes.
It is inherently assumed that the lines of insurance or risk transfer can be modeled appropriately. This is certainly not an insignificant assumption, as data limitations, information asymmetry, internal disputes, and plain modeling foibles can easily derail the best intentions of the framework.
To combat these issues, it is always important to stress test any model, back-test the model if possible, involve different business leaders to vet the results of the model, and use independent experts to question and test the assumptions in the model. Any model is only as good as its creators, so it is advised to hire the best and then “trust but verify.”
MODERN PORTFOLIO CONCERNS CONTAINED IN THE FRAMEWORK
There are several modern portfolio shortcomings that we should address in relevance to our framework, represented in these MPT assumptions: 11
· Asset returns are (jointly) normally distributed random variables.
· Correlations between assets are fixed and constant forever.
· All investors have access to the same information at the same time.
· All securities can be divided into parcels of any size.
· Risk and volatility of an asset are known in advance and are constant.
To address the first point, we have already discussed our use of nonnormal distributions and feel the framework is robust enough to handle any variation of distributions that a modeler feels is appropriate. In postmodern portfolio management, the use of normal distributions has also been relaxed for similar reasons, so this is not as much of a concern as originally stated.
Correlations are clearly not constant or fixed, and once more, they are hard to measure without good historical data. The modeler will often make assumptions around correlations and use copulas to simulate different relationships between correlations at different points of a distribution. It is clear that, again, modern computing power has allowed us to use correlations in a much different way than in the past. Unfortunately, the flexibility is not always a good thing. As correlations are often a modeler's assumption, the use and selection of them should be highly scrutinized.
In insurance, the market is very far from what one would call efficient. On stock exchanges there are clearinghouses and information services to provide an up-to-date information exchange. And even then, the market is not truly efficient. In insurance, pricing different contracts is dealt serious information asymmetry and is fraught with poor information, as the data and pricing start with an actuary in a corporate insurance company, then are translated by an underwriter, and then are ignored by sales professionals (only slight exaggerations involved). This lack of an efficient market is what makes our risk framework so critical. Without it, the insurance buyer has little chance of getting the best deal.
Our framework does have an issue with the ability to fractionalize options and to get the insurance market to respond to all potential mathematical pricing options. This can happen for a variety of reasons: internal restrictions, lack of proper information, risk limits, reinsurance requirements, and so on. The framework can, however, lead insurance markets to more optimal insurance contracts. So even if an option is not technically available, the closest option available in the marketplace can be substituted in similar fashion.
In insurance, especially for large corporations, the party who controls the information can hold a competitive advantage. Both parties to a transaction (corporation and insurance company) have pieces of the puzzle in determining the true risk exposure for the corporation. The insurance company has a significantly larger database of similar risks, and the corporation has very specific data to its risk profile and a much better understanding of how its risk profile is changing. All of this means that the underlying risk is clearly not constant and is difficult to predict. Thankfully, to optimize a risk portfolio one does not require perfect information, only relative accuracy and reasonable assumptions on information that is not available.
In our framework, we are not fully constrained by the limitation of modern portfolio theory, as we are not developing a theory, but rather a practical modeling application. We also have use of greater computer power than ever before, which allows the relaxation of many of the constraints presented earlier in this chapter. We believe that we have addressed the major concerns of modern portfolio theory and its application to insurance, but we will leave that conclusion fully up to the reader.
CONSIDERATION OF BEHAVIORAL CONCERNS IN STRUCTURE
A commonly stated concern with the efficient frontier theory is that is breaks down due to behavioral concerns with the market participants. The participants do not always maximize utility, information is not always readily available, and people do not always make decisions based solely on mean and standard deviations of returns. 12 Because of these concerns, it is necessary to discuss the behavioral implications for our framework.
We start with the definition of common behavioral errors associated with information processing and then move on to the types of informational errors.
Definition: “Information processing—errors in information processing can lead investors to misestimate the true probabilities of possible events or associated rates of return.” 13
The different types of informational processing errors are:
· Forecasting errors
· Overconfidence
· Conservatism
· Sample size neglect and representativeness 14
People often have problems forecasting the future. The most typical concern is using the most recent information to forecast the future. As risk professionals, we see this every day as everyone thinks that the most recent years of information reflect the best and most reliable information. In reality, forecasting is much more complex than that. In our model, we rely on forecasting techniques, but concentrate on methods that use a minimum of five years of information and often 10 years or more of information if it is available. This reduces any forecasting errors and relies on data methods, which are more consistent than human forecasts.
Overconfidence is another common behavioral trait that is difficult to overcome. People often believe they forecast better than they actually do and are often unwilling to recognize that blind spot. This is where a robust process and using several independent experts can reduce the bias that comes from overconfidence. Any one person can have his or her own biases, even experts. So involving a team of experts and a process to reduce the bias is critical to getting a more accurate estimate of risk.
Sometimes a process or framework can be too slow to react to new information. A slow response often occurs in insurance where there is an unrecognized change in a company's risk profile. The client history and the industry data are naturally slow to reflect trends, and large volumes of data are required to finally identify new information. This phenomenon is the counterbalance to being too fast to react. The conservatism bias is best handled by involving business experts in the process to question and comment on changes in the business and to get a common understanding on how those changes are reflected in the modeling work.
Sample size bias is usually pretty well handled by expert modelers. They understand that small sample sizes are less credible than large ones and therefore provide less usable information within a forecast. This can be difficult to communicate, however, so it should be noted that communication of the biases of sample size neglect and representativeness is just as important as realizing them.
We next consider behavioral biases. It has been stated that “Behavioral biases largely affect how investors frame questions of risk versus return, and therefore make risk-return trade-offs.” 15
The main types of behavioral biases are:
· Framing
· Mental accounting
· Regret avoidance
· Prospect theory 16
Framing is the way a question is posed about risk. The question can be posed as “Will you lose $50 million under a worst-case scenario?” or be posed as “Will you stand to make $5 million on the expected basis under the same scenario?” Different questions can lead to different responses, even in seemingly rational people. The way we approach framing is to include the positive and the negative, as well as several other scenarios to provide a range of responses. This can be information overload at first, but after the framework is understood, it provides key information to avoid the framing bias.
Oftentimes people segregate risks based on a particular belief or internal structure within an organization, saying it is fine to take risk in this particular area but not in another one. This is called mental accounting. Organizations are plagued with mental accounting as different divisions; regions, locations, and management all create some level of mental accounting for an organization. The only way to minimize this bias is to have the C-level executives dictate the level of risk they want to adhere to as an organization; otherwise the line-level managers will all view risk through their own lenses. Consultants can often point out this bias within a company, but a company that is not already aware of this bias can fail to use any risk framework appropriately.
Another large corporate risk is regret avoidance. This is the phenomenon that losing a bet on a scenario with long odds is more painful than losing the same amount on a game with a better expected outcome. This is illustrated in the saying “No one ever got fired by hiring IBM.” Large corporations have different cultures and approaches to this bias. Some companies in Silicon Valley make an extra effort to avoid this bias and to create a risk-taking culture. Either way, this is a concern for our analysis. Any option we present, no matter how risk reducing to the organization, will look suboptimal to the current one based on our behavioral biases.
Prospect theory does not apply as well in a corporate environment as in a personal one. In prospect theory the change in wealth from one's current wealth is what is important, not the absolute wealth. For an organization, each employee has his or her own “wealth” and access to company funds. Many are limited in this area, and any change in wealth for the company is not often felt by the employee. There is a disengagement from the wealth of the corporation. This does not mean there is a certain level of bias in the corporation.
As we have shown, there are several behavioral considerations to make in any risk framework. We have tried to comment on how we address those concerns, but are sure there are many other successful ways to handle these biases. The key consideration here is to be aware of the biases and to make sure the organization addresses these issues as part of its enterprise risk management program.
QUESTIONS
1. How does efficient frontier analysis differ from other forms of complex risk assessment techniques?
2. What limitations might an analyst encounter through the use of efficient frontier analysis?
3. How can efficient frontier analysis results be communicated and utilized with nonmathematical decision makers?
ACKNOWLEDGMENTS
Special recognition is given to the following editors of this chapter:
· Jillian Hagan, FCAS
· Virginia Jones, ACAS
· Betty Simkins, PhD
NOTES
1 “RIMS Strategic Risk Management Implementation Guide,” 2013. 2 “Details of Risk Appetite and Tolerance,” www.theirm.org/publications/documents/IRM_Risk_Appetite_Consultation_Paper_Final_Web.pdf . 3 We have defined efficient to mean the maximum return on investment for keeping risk or transferring risk to a third party. 4 Milan Vaclavik and Josef Jablonsky, “Revisions of Modern Portfolio Theory Optimization Model,” 2011. 5 Jerry A. Miccolis and Marina Goodman, “Next Generation Investment Risk Management: Putting the ‘Modern’ Back in Modern Portfolio Theory,” Journal of Financial Planning, January 2012. 6 Ibid. 7 Ibid. Bodie, Zvi, Alex Kane, and Alan Marcus. Investments. 8th edition. New York: McGraw-Hill. 8 For reference, a good article on copulas is available on the CAS website: www.casact.org/library/studynotes/feldblum-dependency2013.pdf . 9 James Lam, “Enterprise Risk Management from Controls to Incentives,” 6–9. 10 Ibid., 8. 11 Miccolis and Goodman, “Next Generation Investment Risk Management,” 2012. 12 www.investopedia.com/articles/investing/041213/modern-portfolio-theory-vs-behavioral-finance.asp . 13 Zvi Bodie, Alex Kane, and Alan Markus, Investments, 8th ed. (New York: McGraw-Hill, 2008), 385. 14 Ibid., 386. 15 Ibid., 387. 16 Ibid., 387–388.
REFERENCES
1. Bodie, Zvi, Alex Kane, and Alan Marcus. 2008. Investments. 8th edition. New York: McGraw-Hill.
2. “RIMS Strategic Risk Management Implementation Guide.” 2013.
3. “Managed Futures—Reducing Portfolio Volatility, A Look into the Top 3 Managed Futures Accounts Worldwide.” 2011. Emanagedfutures.com, March 19.
4. Markowitz, H. M. 1952. “Portfolio Selection.” Journal of Finance 7:1, 77–91.
5. Markowitz, H. M. 1959. Portfolio Selection: Efficient Diversification of Investments. New York: John Wiley & Sons, reprinted by Yale University Press, 1970.
6. Merton, Robert. 1972. “An Analytical Derivation of the Efficient Frontier.” Journal of Financial and Quantitative Analysis 7, September.
7. Miccolis, Jerry A., and Marina Goodman. 2012. “Next Generation Investment Risk Management: Putting the Modern Back in Modern Portfolio Theory.”Journal of Financial Planning, January.
8. Lam, James. 2003. Enterprise Risk Management from Controls to Incentives. Hoboken, NJ: John Wiley & Sons.
9. Taleb, Nassim Nicholas. 2007. The Black Swan: The Impact of the Highly Improbable. New York: Random House.
10. Vaclavik, Milan, and Josef Jablonsky. 2011. “Revisions of Modern Portfolio Theory Optimization Model.”
ABOUT THE CONTRIBUTORS
Ward Ching is Vice President, Risk Management Operations, at Safeway Inc., located in Pleasanton, California. His responsibilities include enterprise risk management, integrated risk finance, hazard loss control, environmental compliance, property risk control/engineering, and a variety of retail, distribution, and manufacturing risk management initiatives, including Safeway's Culture of Safety. Prior to joining Safeway, he was a principal at Towers Perrin and a managing director at Marsh. He completed his undergraduate and graduate degrees in international relations and economics at the University of Southern California, and has taught and written extensively on the subjects of international relations, game theoretical applications in foreign policy, and enterprise risk management.
Loren Nickel, FCAS, CFA, MAAA, is the Regional Director and Actuary for the Northwest Region (Seattle, San Francisco, and Los Angeles) and National Leader for Operational Risk for Aon Global Risk Consulting. He is responsible for providing clients with actuarial support as well as a variety of financial and tailored risk services. His work includes pricing, reserving, profitability studies, retention studies, dynamic financial analysis, and captive analysis for all major lines of insurance. He provides professional actuarial opinions as well as a variety of innovative risk solutions.
CHAPTER 22 JAA Inc.—A Case Study in Creating Value from Uncertainty Best Practices in Managing Risk
JULIAN DU PLESSIS
Head of Internal Audit, AVBOB Mutual Assurance Society
ARNOLD SCHANFIELD
Principal, Schanfield Risk Management Advisors LLC
ALPASLAN MENEVSE
Risk Officer, Sekerbank T.A.S., Turkey
This case study describes how enterprise risk management (ERM) was implemented at a fictitious company, JAA Inc. It provides extensive detail as to the governance structure, the processes, and the various tools used. The case is built on the principles/guidance of ISO 310001 and the implementation guidance created by HB 436.2 The key players in this case are the heads of Internal Audit and Risk Management. It is interesting to see what they have done in the five years expended to implement ERM. We offer special thanks and appreciation to Grant Purdy from Broadleaf International in Australia for his continued support, dedication, and help provided to our efforts.
SETTING THE CONTEXT
It was a beautiful Wednesday afternoon in Chicago. Matt Damison, the chief internal auditor (CIA), and Frank Gillespie, the chief risk officer (CRO), were having lunch in JAA's cafeteria and reminiscing about the times at JAA when the company's performance was much lower than the current state. Only five years earlier, in 2008, the company had embarked on a comprehensive enterprise risk management (ERM) program. Both Matt and Frank, together with executive management and the board, had been actively involved in this initiative. At that time, JAA was also undergoing various regulatory audits, and employee morale was quite poor. The company has now been able to satisfactorily address these issues, and in fact has won numerous awards and been written about in various journals for its risk management program. JAA has progressed from being considered risk management novices to one of being leaders in the field of effective risk management, having accomplished this in less than four years but still recognizing that improvements need to be made. Matt and Frank have just received a phone call from the Wall Street Journal press. They agreed to be interviewed to explain the genesis of JAA's ERM implementation undertaken five years previously and how as a company it has since flourished. Senior and executive management have encouraged Matt and Frank to conduct such an interview to highlight the company's achievements.
BUSINESS BACKGROUND
In 1972, JAA commenced operations as a private company founded by three brothers (Emile, Robert, and Frank Bergand) in Chicago, Illinois. In 1988 the brothers decided to take the company public and launched an initial public offering (IPO), as market conditions at that time were quite favorable and the brothers wished to reap financial benefits (i.e., cash out) after years of hard work. The brothers remained with the company and served in executive roles until they retired in 2003. JAA is listed on major stock exchanges, is headquartered in Chicago, and has a December 31 year-end. The financial statements appear in Appendix A.
The company has three operating segments:
1. A U.S. wholesale business
2. A U.S. retail business
3. An international business (wholesale and retail)
The aforementioned segments reflect the way the business is managed and performance is evaluated. The wholesale business focuses on the sale of undecorated apparel products to distributors in the United States and internationally. The international wholesale operating segments also produce apparel products that satisfy the preferences of those customers that favor a more local traditional style, to stay sufficiently competitive in those markets. This was determined from a risk workshop that identified the loyalty factor of international customers as a major business opportunity.
The company operates 57 retail stores in 10 different countries:
· North America—United States (28)
· South America—Argentina and Brazil (7)
· Asia—China, South Korea, and Japan (11)
· Australia (4)
· Europe—Switzerland and Turkey (4)
· Africa—South Africa (3)
The retail stores cater directly to the consumer, and most such stores are situated in major shopping malls using leased space. The stores target middle-aged men and women. Retail store customers represent quite a sophisticated group of shoppers. The stores compete on the basis of location, merchandise availability, price, and customer service. Retail sales are promoted via major newspapers and online media. JAA's major competitors are McCory, Bertang, and Keramtor.
The wholesale customer base comprises 100 key distributors. The split between retail and wholesale is 40 percent/60 percent, respectively. Competition at both the retail and wholesale levels is fierce and has necessitated that the company outsource part of its manufacturing to lower-cost countries. Key product cost competition is from China, Bangladesh, and Vietnam.
The apparel business/industry is characterized by rapid movements in fashion, changing consumer demand, and significant competitive pressures. JAA has emphasized quality merchandise at an affordable price. Wholesale customers are secured through a lean, but stellar, sales force established in the major cities around the globe (45 major cities). No one single distributor exceeds 5 percent of the company's sales. JAA also has an online catalog operation, whose critical success factors are website availability and design, advertising response times, and social media recognition.
The Bergand brothers are now the largest company shareholders, owning some 22 percent of the stock. There are a couple of large institutional investors that collectively own an additional 12 percent of the outstanding shares.
The executive and senior management teams comprise:
· President and CEO Michael Menorix
· Chief Financial Officer Jillian Verdiger
· VP of Marketing and Sales Mary Mordensti
· VP of Production Boris Dentiger
· VP of Human Resources Francine Tanserki
· Chief Internal Auditor Matt Damison
· Chief Risk Officer Frank Gillespie
· VP of Legal and Compliance Michael Perstay
JAA has its core U.S. manufacturing in a 360,000-square-foot facility, which also contains the corporate/executive offices and warehousing/distribution. The company also has two small satellite manufacturing facilities in Tampa, Florida, and Los Angeles, California, on company-owned properties. JAA has outsourced 25 percent of production in various agreements with third parties in Turkey, China, and South Africa. The company's apparel product line initially focused on men's coats, but over a period of time expanded to include a full line of men's clothing inclusive of pants, shirts, and coats. In 1999, an upscale line of women's clothing was added to the product portfolio.
The company purchases all fabric from 50 key suppliers, having trimmed its supplier base from 400 over the past five years. All suppliers are ISO 9000 certified and, as such, are subject to rigorous reviews prior to becoming JAA's suppliers. JAA uses state-of-the-art technology to enhance marketplace competitiveness.
The company has been fortunate in attracting high-caliber employees. It has had minimal turnover over the past three years, and it provides a generous compensation and incentive package to its employees. It is not subject to any collective bargaining agreements but to various environmental regulations in the United States and overseas. One other key area JAA is heavily focused on, and in strong compliance with, is monitoring compliance at third-party manufacturing facilities overseas.
Effective management of risk was recognized by the current management team as being critical to JAA's success. Thus the company sought individuals who were experienced in this field for key leadership positions in Internal Audit and Risk Management, as well as for the key board positions. When the current heads of Internal Audit and Risk Management joined the company in 2008, JAA had sustained six years of losses. JAA's creditworthiness is currently BBB as rated by the major rating agencies, having improved from junk status to this rating within four years.
INITIAL STEPS: STRATEGIC PLANNING AND BUSINESS OBJECTIVES
JAA's management recognized in 2008 that there were concerns with the annual strategic planning process because the board members typically did not attend such meetings. This impeded their ability to address the key strategic questions JAA faced, and did not create an environment that could generate fresh insights. Typically, the focus on short-term performance was failing to identify risks that threatened long-term objectives. Such short-term thinking also neglected to think about untapped business opportunities.
JAA decided to discard the annual process and replace it with a much more intense form of strategic engagement with management and the board. They are now devoting extra time at each board meeting to pressure-test the strategy in view of its progress and changes in critical variables. There is a strong communication process of this new strategy throughout the organization to both the internal and external stakeholders. JAA prides itself in doing this well under President Michael Menorix's leadership. Management knows who the stakeholders are and their needs and has established different communication channels with them as appropriate, including webinars, phone conference calls, town hall meetings, written media, and so on.
JAA's management is aware of the many pitfalls of strategic planning and has recognized the need to view risk and strategy as two sides of the same coin because it knows that the two are linked. The company aims to increase shareholder value and to address the needs of the other stakeholders through successful pursuit of the following strategic objectives:
· Maintaining market leadership
· Sustaining technology leadership
· Strengthening global presence
· Delivering quality service
· Being seen as a leader in compliance with all laws and regulations
ESTABLISHING THE GOVERNANCE SYSTEM
JAA has developed an excellent governance system by using many different metrics as described later. The Governance Framework is depicted in Exhibit 22.1. The board consists of external directors, including Sally Hendrix, who serves as chair of the Audit Committee. The Audit Committee members have served for periods ranging from two to seven years. All committee members, in addition to their professional qualifications and experience, are well versed in risk management. They have all attended formal training in this subject matter at leading risk organizations and have received training by both the Internal Audit and Risk Management groups of JAA as well.
Exhibit 22.1 Governance Framework
The company's risk governance framework illustrates the governance arrangements for the board, management, independent control functions, and ongoing business operations that exercise governance over risk.
JAA's board is responsible for the governance processes that it requires management to execute. The company understands that effective oversight by its board and senior management is critical to the overall governance effort. It protects its shareholders and other stakeholders by ensuring sustainability of the business through achievement of superior performance. The board provides leadership to JAA by understanding and accepting its responsibilities for the adoption of strategic plans, monitoring of operational performance and management, determining the philosophy and effectiveness of the approach for managing risk (including internal controls for managing the day-to-day operations), and compliance with all relevant laws and regulations.
The directors of JAA Inc. have applied the principles of discipline, transparency, independence, accountability, responsibility, fairness, and social responsibility to ensure that sound governance is practiced consistently throughout the company. Being listed on the New York Stock Exchange and subjected to its listing requirements emanating from the Securities Exchange Act, the company requires:
· An independent board of directors with a majority of nonexecutive directors (NEDs)
· An Audit Committee
· Compensation and Nominating Committees
· That board members must gain approval prior to undertaking any other board assignments and in no event can any board member serve on more than three other boards
· Attendance of at least 75 percent of board meetings and its subcommittees annually
· Strong continuing education in various areas, including risk management, governance, and internal control
· Presence and functioning of an Executive Risk Oversight Committee (EROC)
· Presence and functioning of a Risk and Strategy Committee (RSC)
JAA continually seeks to improve its knowledge of international frameworks and standards to augment its governance processes. As such, it has incorporated best practices from South Africa (King III),3Canada (Criteria of Control),4 United Kingdom (Combined Code,5 Risk Management Consultation Draft—FRC6), and Australia (ASX and HB 4367) to update its risk management and governance frameworks.
The board of directors has delegated certain functions to the various committees. The board is kept up to date on:
· Business performance relative to strategy, budgets, business plans, risk criteria, capital adequacy and preservation, and earnings volatility
· Noncompliance with board policies, regulations, statutes, and accounting policies
· Significant breakdowns in operations, unsatisfactory financial performance, noncompliance with laws and regulations, ineffective management supervision and monitoring, internal controls or process failure, and organizational system or structure failure
· Effectiveness of the corporate governance process
· Corrective actions implemented in respect of these
Specific responsibilities of different committees are discussed next in the following subsections, namely Compensation Committee, Risk and Strategy Committee, and Executive Risk Oversight Committee.
The Compensation Committee
· Reviews and approves remuneration policy throughout the business
· Ensures that the remuneration policies adopted do not result in excessive risk taking
· Ensures that the compensation plans and compensation awarded to senior management are based on the achievement of objectives as a result of managing risks effectively
· Designs and approves the principles to be used in the performance agreements of management to ensure that key performance indicators (KPIs) of management encourage prudent risk taking and the management thereof
The Risk and Strategy Committee
· Sets and reviews JAA's risk criteria
· Oversees the risks to which the company is exposed, and monitors the activities of the Executive Risk Oversight Committee (EROC)
· Approves the risk management policy on behalf of the board
· Reviews the design, completeness, and effectiveness of the risk management framework to ensure that changes and updates to risk management are performed in accordance with processes approved by the board as documented in the risk management policy and that oversight of it is effective
· Ensures that infrastructure, resources, and systems exist to adequately oversee and monitor JAA's risks (this is done to ensure that risk taking is consistent with the risk criteria set by the board; at all times the board is aware of the comprehensiveness, accuracy, and status of the risk attitude)
· Reviews the effectiveness of risk reporting (including timeliness and events that could impact business objectives and the company's risk profile)
· Ensures that all strategic transactions undergo appropriate review and due diligence before submission to the board, particular focus being accorded to the risk criteria
· Reviews and challenges capital and liquidity stress testing
The Executive Risk Oversight Committee (EROC)
· Scrutinizes and challenges the risks identified to which the company is exposed and evaluates the assessment of these risks
· Assists the board in defining JAA's risk criteria that align with the objectives and strategies of the organization and monitors that risks are managed within the risk criteria
· Establishes the risk management policy
· Ensures that the framework for managing risk continues to remain effective
· Ensures that the necessary resources are allocated to manage risk
· Determines that the risk management performance indicators are aligned with KPIs of management performance of the organization
· Ensures and monitors legal and regulatory compliance
· Reviews results of stress and scenario testing for JAA's strategic objectives and attainment of them
· Assigns accountabilities and responsibilities at appropriate levels within the organization
· Reports on how managing risk is performed to provide assurance to stakeholders
BUSINESS OPERATIONS
In addition to the oversight functions (described next), JAA has embedded risk management into underlying business operations. For example, a risk management policy (see Appendix B) has been implemented across the company to support the effective implementation of risk management. A risk management framework, supported by various risk policies, has been implemented to provide guidance to all employees on how to address organizational components, such as business and strategy planning, budgeting, and performance management and reporting, as well as human resources, compliance, and information security. Heads of departments are responsible for the maintenance of the risk registers, which include treatment actions. All risks in this register are further consolidated and reported to the EROC with possible treatment options.
Oversight Functions
The company's independent oversight functions, namely the Risk Management department, the Legal department, the Compliance department, and the Internal Audit department, provide the required assurance. These functions report periodically to the board and its committees as appropriate.
Risk Management Department
The Risk Management department has a unique advisory role to all management levels as well as to the board while managing risks. Also, the department reviews and challenges the outcome and results of risk assessment activities performed by management and the resulting risk registers produced that include the risks that constitute the risk profile of JAA.
Legal Department
The Legal department is responsible for providing advice to the company, its divisions, and its employees on matters of law and legal protection by:
· Representing the company in all meetings, conferences, and public forums
· Preparation of protocols, claims, and court counterclaims
· Representation of the company in court
· Protection of the company's rights and interests in judicial settings
· Creation of legal documentation requirements
Compliance Department
The Compliance department helps in the following areas:
· Regulatory risk management—keeping company activities in strict compliance with current legislation
· Compliance monitoring—evaluating and measuring the state of compliance across the organization
· Investigations—managing investigations into wrongdoing and anything that increases regulatory-related risks
Internal Audit Department
The Internal Audit (IA) function is best in class. Matt Damison, who has 20 years of relevant internal audit and risk management experience, joined JAA in 2008 with strong academic and professional certifications. He belongs to several leading professional organizations such as the Institute of Risk Management in London, the Conference Board of Canada, and the Risk Management Institute of Australia. He also speaks and writes extensively on this subject matter.
Matt reports directly to the Audit Committee chair, Sally Hendrix, with dotted-line daily responsibilities to the chief executive officer, Michael Menorix. Matt meets with the Audit Committee on a periodic basis. He also attends the key meetings in the strategic planning process.
This is a summary of what he has done during this five-year period:
· The department adopted a comprehensive risk-based approach to the audit plan. All audit projects are derived from this risk-based plan. Special requests by management that are external to the risk assessment performed by management are reviewed very carefully, especially if the requests do not appear to address issues that are generating any new risks. Audits are thus focused on the company's highest risks or on the highest risks that are now reduced to within the stated risk criteria through management actions. Comprehensive reviews of every business/operational process are not performed, because such processes include areas of lower risks.
· Several senior-level personnel in the company formerly worked in the Internal Audit function, and Internal Audit has a track record of promoting high-quality performers to line management positions. The function has a solid track record with minimal turnover to outside the organization.
· The Internal Audit group consistently demonstrates how it has contributed to the success of the company by linking all commentaries on its accomplishments to the company's strategic objectives.
· Internal Audit annually evaluates risk management, and issues an opinion on it according to the 11 risk management principles stated in ISO 31000. This year, it has completed its third such review, focusing on:
. The design of the risk management framework, including such things as assignment of responsibilities and accountabilities, context of the company, communication with the stakeholders, and mandate and commitment by the board
. The implementation of the risk management framework
. The risk process implementation, culminating in the generation of the risk register
. Monitoring and review
. Continuous improvement
EXTERNAL AUDITORS
Matt has also been successful in helping the company reinvent its relationship with the external auditor in the following areas:
· Prior to the heads of Internal Audit and Risk Management joining the company, the external audit process left much to be desired. Specifically, JAA never received a well-written management letter; if it received any letter at all, it was written quite superficially and was received by the company nine months subsequent to year-end. There was extensive overlap in some of the areas covered by external and internal audit. There were, as well, some key areas missed in the external audit that created surprises for the company.
· As a result of the foregoing, the following changes were implemented, creating many positive effects for the risk management framework:
. The external auditors were invited to sit in on the key strategic planning sessions of the company.
. There were ongoing meetings between the head of Internal Audit and the principal partner on the external audit team.
. The external audit team compiled and wrote a comprehensive management letter with special emphasis on root cause analysis (meaning that they understood the root causes of specific problems). They ensured as well that all such comments were addressed by management of JAA and did not appear in the following year's management letter comments.
. The external auditors, in performing their planning work for the current year's audit, began to utilize the existing risk management framework and process at the company, as created by the risk management function. This was to ensure that all parties' efforts were clearly aligned.
. The internal auditors, in assessing effectiveness of the risk management framework at the end of the year, summarized as well the contributions to it by the external auditors.
. The internal auditors did not act as surrogates for the external auditors, meaning that no internal audit time was expended in performing external audit work to reduce cost of the external audit.
EVOLUTION OF RISK MANAGEMENT
When initially appointed to their positions in 2008, the current heads of Internal Audit and Risk Management met with the CEO, as well as with the rest of the executive management team. After a number of discussions, it was decided to implement enterprise risk management (ERM) throughout the company so that JAA could achieve its business objectives, unlike the prior six financial years when performance was generally poor. As the CRO, Frank Gillespie was the key person who facilitated the risk management program with a team of three professionals reporting to him. The risk management team determined that the source of the problems in the company over the past several years stemmed from:
· Weak commitment to each of the business objectives
· Poor internal communications
· Absence of initiative taking
· Inconsistencies in internal reporting
· Unclear organization roles and responsibilities
· Failure to adequately monitor the international brand licenses and copyrights
· Failure to provide a safe working environment
These issues further served to demotivate the existing workforce, which in turn had the compounding effect of creating an environment where employees became hesitant to undertake new projects. Ultimately, this caused JAA to fall behind its competitors.
As the team scoured the marketplace in 2008, they noted that ISO 31000:20098 was in draft stage, but its predecessor, AS/NZS 4360:2004, existed together with the accompanying HB 436 handbook. They decided to launch their risk management efforts using these guides.
After performing a detailed gap analysis of the existing risk management framework, Frank prepared the training curricula for all company employees. At the senior management level, he rolled out leadership and soft skill coaching courses. For the lower levels of management, he introduced training in communications, body language, and project management. In addition, for both groups, he introduced personnel conflict resolution, negotiations, presentation skills, and human behavior/bias training workshops. To create a teamlike environment and a great atmosphere between the different layers of management, Frank organized group hobby sessions such as photography, cooking, and several weekend hiking events. These served to repair impaired lines of communication, which in turn helped to reinvent JAA's new corporate culture.
Having performed a few cycles of workshops with senior management, Frank suggested that they needed to prepare a risk management policy with the information gathered from all key executives. The risk management policy became the foundation for the company's risk management framework. Frank also created standard risk management terminology to ensure that everyone gained a common understanding of risk management words and phrases. This was incorporated into the risk management policy.
INTRODUCTION OF ISO 31000 AND HB 436 TO THE COMPANY
After three years of diligent efforts in implementing this framework, benefits materialized through greater profits, revenue growth, shareholder value improvement, and individual performance. In 2009, when ISO 31000 became the international risk management standard, the company adopted it through its entire business. ISO 31000 represented an opportunity to create effective risk management within JAA as this was merely an upgrade of AS/NZS 4360.
Frank's group performed a new gap analysis while upgrading to ISO 31000 to determine what additional changes needed to be made in JAA's current risk management principles, framework, and process. JAA adopted ISO 31000 in two phases. The initial phase was at the business level since it was critical to incorporate this into the decision making processes of the company. The second phase was at the strategic level, which also included monitoring of the initial phase. The company made extensive use of the HB 436 handbook to help with the implementation process.
DEFINING THE CONTEXT OF JAA
The internal and external context of the company was clearly defined by the ERM team (see Exhibit 22.2). The objectives, stakeholders, and current business environment were compiled to ascertain strengths, weaknesses, opportunities, and threats facing the company. The team identified the following stakeholders of the company: shareholders, board members, employees, media, third-party outsourcing vendors, the World Trade Organization, regulatory agencies, stock exchanges, the Internal Revenue Service (IRS), environmentalists, suppliers, customers, labor unions, and immigration authorities.
Exhibit 22.2 Using Context for Risk Criteria
The risk management policy in Appendix B is its third version in an effort to keep up to date with the latest developments and/or evolution in respect to risk management best practices, as well as how the business is supposed to operate. The latest update was performed during 2011 to address the principal elements of ISO 31000. The company also conducted an impact analysis using worst-case scenarios to set an operational baseline, and this further helped to formulate the risk criteria and JAA's attitude toward risks.
DEFINING RISK CRITERIA
JAA undertook the following six-step process to establish risk criteria at the company.
First, it selected each of the five strategic objectives and articulated its position on expected outcomes and how it would measure such outcomes.
The five objectives were:
1. Maintaining market leadership
2. Sustaining technology leadership
3. Strengthening global presence
4. Delivering quality service
5. Being seen as a leader in compliance with all laws and regulations
For example, the expected outcomes for “being seen as a leader in compliance with all laws and regulations” are minimal injury to employees, zero fatalities, not facing prosecutions and enforcement actions, and minimizing the cost of any cleanup. It decided to measure such outcomes by people impact, legal actions, and duration and cost of any cleanup.
Second, it developed scales for each consequence type using ordinal measurement with the low end representing tolerable or insignificant deviations from the expected values and the high end representing very high consequences that may be retained only by board approval. Such consequences are demonstrated in Exhibit 22.3 for quantitative consequences and in Exhibit 22.4 for qualitative consequences.
|
|
|
|
Metric for Impact or Consequence |
||||
|
Objective Type |
Measure |
Scenario |
5—Very High |
4—High |
3—Moderate |
2—Low |
1—Very Low |
|
Financial |
Sales growth |
Quarterly sales expectations |
> +25% < –25% |
> +15% < –15% |
> +10% < –10% |
> +7% < –7% |
> +4% < –4% |
|
|
Brand value |
Market price volatility |
> +25% < –25% |
> +15% < –15% |
> +10% < –10% |
> +7% < –7% |
> +4% < –4% |
|
Reputation |
Public relations |
Media coverage value (+/–) |
> $10M International media coverage |
> $7M National media coverage |
> $4M Local media coverage |
> $2M Within the sector |
> $1M Partial sector |
|
|
Employee commitment |
Key personnel turnover |
15% |
10% |
5% |
3% |
1.5% |
|
Regulatory |
Local licenses |
Regulatory fines |
> $1M |
> $700,000 |
> $500,000 |
> $300,000 |
> $100,000 |
|
|
Legal |
Contract liabilities |
> $10M |
> $7M |
> $4M |
> $2M |
> $1M |
|
Customers |
Quality perception |
Customer satisfaction |
> 80% |
> 60% |
> 40% |
> 20% |
> 5% |
|
|
Retail customer growth |
New customers and retention |
> 15% |
> 10% |
> 5% |
> 3% |
> 1.5% |
|
|
Retail branches |
Branch performance |
> +25% < –25% |
> +15% < –15% |
> +10% < –10% |
> +7% < –7% |
> +4% < –4% |
|
Sustainability Business |
Business continuity |
Disruptions |
> 3 days |
> 2 days |
> 1 day |
> half day |
> 1 hour |
|
|
Markets |
Order delivery delays |
> 5 days |
> 3 days |
> 1 day |
> half day |
> 1 hour |
|
|
Technology |
Project delivery delays |
> 3 months |
> 2 months |
> 1 month |
> 15 days |
> 1 week |
|
Safety and Environment |
Work safety |
Incidents |
1 casualty |
> 1 major wound |
> 1 minor wound |
Minor wound |
Local physical damage only |
Exhibit 22.3 Consequence Scales for Quantifiable Effect
|
Rating |
Financial |
Reputation |
Regulatory |
Customer |
Sustainability |
Safety |
Environment |
|
Massive |
Available financial resources affected highly so that revisions of business plans needed |
Organization assets that represent value to company brand and market credibility severely affected |
Market existence and/or ability to generate business severely affected |
Performance or quality severely affected |
Business flow severely affected |
Multiple fatalities or irreversible disability to many individuals |
Natural resources severely affected |
|
Major |
Available financial resources affected remarkably so that revisions of some of the elements of business plans needed |
Organization assets that represent value to company brand and market credibility significantly affected |
Market existence and/or ability to generate business significantly affected |
Performance or quality significantly affected |
Business flow significantly affected |
Fatality and/or irreversible disability to one or many individuals/ persons |
Natural resources significantly affected |
|
Moderate |
Available financial resources affected noticeably so that revisions of a few of the elements of business plans needed |
Organization assets that represent value to company brand and/or market credibility noticeably affected |
Market existence and/or ability to generate business noticeably affected |
Performance or quality noticeably affected |
Business flow noticeably affected |
Moderate irreversible injury or impairment to one or more persons |
Natural resources noticeably affected |
|
Minor |
Financial resources affected at manageable level so that changes stay within the budget limit |
Limited effect on brand value or market credibility |
Effect stays limited and does not cause long-term business change |
Effect can be considered manageable with little resources |
Effect stays in expected regions and manageable with current assets |
Hospitalization required; largely reversible injury to one or more persons |
Visible local effect |
|
Insignificant |
Adjustments can be made with short-term arrangements of funds |
Manageable with daily operations |
Manageable with simple adjustments |
Manageable with local resources |
Manageable with local resources and current assets |
Reversible injury requiring hospital treatment |
Can be treated with current assets |
Exhibit 22.4 Consequence Scales for Nonquantifiable Effect
Third, it decided how likelihood would be expressed, and chose ranges from rare to very often with their associated probabilities, as can be seen in Exhibit 22.5a.
|
Likelihood |
Probability |
Possible Example Event |
|
5—Very often |
More than 10 times or once in 0–5% of the target time period |
Contract liabilities are violated 12 times in 3 years |
|
4—Often |
5–10 times or once in 5–25% of the target time period |
Imitation of JAA products is observed 9 times in 5 years |
|
3—Even |
3–5 times or once in 25–50% of the target time period |
M&A is observed with outsourced contractors 3 times in 5 years |
|
2—Few |
1–3 times or once in 50–75% of the target time period |
Dye technology is changed once in 5 years |
|
1—Rare |
1–2 times or once in 75–100% of the target time period |
Environmental pollution is caused once in 10 years |
Exhibit 22.5a Likelihood/Probability Scales and Risk Levels
Fourth, it developed a table to derive the level of risk, and this can be seen in Exhibit 22.5b. The company opted to express the level of risk as a distribution instead of a point level so that different levels of impact could be expressed with the corresponding likelihood.
|
Risk Level |
Quantitative Level |
Qualitative Level |
|
High |
More than $10M or >1.5% of the net sales |
Frequent occurrence and high or very high impact or above |
|
Medium–high |
$5–10M or 0.75–1.5% of the net sales |
All between high and medium |
|
Medium |
$1–5M or 0.15–0.75% of the net sales |
Few occurrences and low impact |
|
Low |
Less than $1M or < 0.15% of the net sales |
All below medium |
Exhibit 22.5b Defining Risk Levels
Fifth, it decided how the level of risk would be expressed by using a scale consisting of four levels from high to low, based on the combination of impact and likelihood mentioned before. With this table, for each risk, a treatment method is determined by multiplying the likelihood (probability) with impact level. Bow tie analysis9 is being used to map objectives and the events or consequences.
Finally, it decided on the rules for evaluating a risk, and such rules are listed in the upcoming “Risk Attitude” exhibit, and in Appendix B, “Risk Management Policy.”
BRINGING EVERYTHING TOGETHER
At the initial stage with individual participants at a risk identification and assessment workshop, the CRO did not intervene, even though he believed that there was some bias in the opinions being expressed. As the sessions continued, interaction among the different participants resulted in a diminution of the biases. At the conclusion of each workshop, all the risks were prioritized according to group consensus. Communication among the team members and the great facilitation by the CRO helped to reduce the biases. A set of risk criteria10 was developed (depicted in Exhibits 22.3, 22.4, and 22.5), which was used to guide strategic business decisions with respect to the apparent risks.
A new communication channel was established with the EROC and the risk owners, who met and continue to meet quarterly. This structure helped JAA establish a sound and trusted medium for the exchange of ideas, thus reducing misunderstandings. The meeting agenda usually included ongoing projects, new perceptions of risk, and changes in the context and alignment of the current risk profile with the organization's risk management policy and the risk attitude. The EROC demonstrated executive management's commitment to managing risk, and helped to establish a risk consciousness and risk culture within JAA.
The need for an increased awareness of sustainability among stakeholders was one area of concern, and as such it was one of the new projects undertaken by JAA. The company added new policies and a few application projects to increase public awareness. These projects also helped to increase the brand value.
These projects later fostered a corporate culture of “learning to give.” The company has also encouraged its employees to get involved in volunteer projects. JAA started to use natural dye colors wherever possible on the fabrics in the manufacturing process, which was greatly welcomed by its customers. Also, the company's credit rating increased one notch with the last rating revision. This in turn has helped the company access cheaper and longer-term loans.
The communication infrastructure is now robust. The Internet phone network is set up with regional sales functions for easy access to customer needs and resolving issues. Low-cost and high-availability web meetings were enabled with this project. An “I suggest” project, which helps the workforce describe innovative ideas about their jobs, has now been implemented with web-based software. Suggestions are reviewed and evaluated by risk and control owners. Prizes are provided for those whose suggestions are implemented. The project is also helpful to the company's efforts at enhancing the whistle-blower hotline.
During the risk workshops, it was identified that one of the root causes for a risk at the company was the potential for significant age gaps between the senior management and other personnel. Additionally, during the prior five years, most of the key personnel had left the company. Therefore, the company adopted new human resources performance and competence criteria so that highly qualified personnel could be retained. With these treatments, previously high-level risks and weaknesses have been reduced to low levels and JAA has enabled a forward-looking and proactive management approach to be put in place.
MOVING FORWARD: OVERSEEING STRATEGY AND RISKS
To ensure that risks were adequately considered during the strategic planning process, JAA nominated its board-level Risk Oversight Committee to also be its Strategy Oversight Committee and named it the Risk and Strategy Committee (RSC). However, to ensure there is day-to-day monitoring of risks and controls and timely implementation of risk treatment plans to achieve strategic goals, JAA established an Executive Risk Oversight Committee (EROC) chaired by the CEO. The board believed this would reflect the corporate commitment of senior management to play an active role in day-to-day decision making and set the tone across the company that risk management is central to corporate culture.
Nonexecutive oversight of strategy and risk is the responsibility of the RSC, which regularly scrutinizes and exercises independent judgment over the most significant risks and effectiveness of the treatment plans and controls across the business. Discussions with the CRO and the heads of other oversight functions are also conducted without executive management being present. The nonexecutive directors (NEDs) are a step removed from the daily operations of the business, enabling them to assess and challenge the risk treatment plans. The complete board of JAA is responsible for overseeing achievement of strategy and the long-term goals of JAA through the risk governance structures it has established and maintained.
LOOKING TO THE FUTURE: JAA'S MANAGEMENT OF UNCERTAINTY
The successful turnaround in the fortunes of JAA is evidenced by its financial performance (see Appendix A) achieved through meeting its strategic objectives. JAA successfully seized opportunities emanating from the uncertainties impacting on those objectives. What follows is a comprehensive discussion on how JAA went about responding to the risks comprising its risk profile. The risk profile of the company appears in Exhibit 22.6a with a related risk map in Exhibit 22.6b. They clearly indicate how the risks of JAA have been changing due to its successful treatment of risks (i.e., emerging and current). The perceptions or flat trends exist because the treatment plans are a work in progress. As the treatment results are achieved, relative levels of risk will decrease as the benefits emerge for the objectives. The risks comprising the risk profile of the organization and the risk treatments selected to manage them are discussed next.
|
Risk Source |
2013 Perception |
2014 Forecast |
Trend |
|
EU Anti-Dumping regulation changes |
Medium |
High |
↑ |
|
Outsourcing and supplier contract management: Quality and delivery assurance |
Medium |
Medium |
↓ |
|
Competitors' marketing strategies |
Medium–high |
High |
↗ |
|
Imports: National FITs for trade discrimination |
Medium–high |
Medium–high |
↘ |
|
Cost variability and management |
Medium |
Medium |
↙ |
|
Local trade laws and regulations |
Medium |
Medium |
↔ |
|
New fabric production and dye technologies |
Medium |
Medium–high |
↙ |
|
Reaching target customers in new locations (countries) |
Medium |
Medium |
↔ |
|
Environmental sensitivity of creditors |
Medium |
Medium–high |
↗ |
|
Imitation of JAA's products |
Medium–high |
Medium |
↘ |
Trends: ↑: Impact is increasing, ↗: Both impact and likelihood increasing, ↘: Impact decreasing but likelihood increasing, ↔: Same from the last assessment, ↙: Both likelihood and impact decreasing.
Exhibit 22.6a Current Risk Profile
Exhibit 22.6b Risk Map
Likelihood and Impact Matrix: Sizes of the bubbles are proportional to the relative interdependency of risk sources. The bigger the bubble, the greater the effect on other risk sources.
European Union (EU) Anti-Dumping Regulation Changes
Because of the latest data from the World Trade Organization (WTO), JAA noted that there is increased market penetration from Eastern markets to EU markets. Also, complaints from local manufacturers have commenced. The EU Parliament may start to investigate anti-dumping measures against Asian countries in the textile industry, which could very well result in increased tariffs. If this scenario is realized, this will strengthen global presence and help to maintain market leadership, two of the strategic objectives of JAA. This will also have an impact on production costs, satisfying new quotas, and logistics. If the net effect is negative, JAA may need to change its business model, which could create additional hardships on the company. To avoid this situation, the maturity level of markets in the Middle East and South Africa needs to be evaluated for both logistics and production sites as alternatives. This step will help to ensure preservation of competitive advantage and the ability to identify new markets.
Outsourcing and Supplier Contract Management: Quality and Delivery Assurance
The latest trends demonstrate that there will be high volatility caused by mergers and acquisitions among outsourced suppliers. The agreed standards of service-level agreements (SLA) may be degraded, which could cause delivery delays and quality issues because of laid-off workers who are more experienced and certified but more costly. This kind of situation may impact JAA's objective of strengthening its global presence. Therefore, it decided to maintain a database of potential suppliers and set up procedures for sample production lots with them so that it can respond in a timely fashion and shift outsourcing arrangements to limit delays and maintain product quality.
Competitors' Marketing Strategies
JAA noted that there has been an increase in new entries to the sector with aggressive marketing strategies, which may affect its objective of maintaining market leadership. The quality of its products and customer satisfaction have become increasingly important. To have timely and more comprehensive information, a new customer survey for both current satisfaction and future expectations will be needed among both customers and local retail partners. This will provide JAA with the information and ability to act promptly. If JAA fails to obtain adequate information on competition, then this could result in faulty strategy setting at JAA with severe consequences.
Imports: National Feed-In Tariffs for Trade Discrimination
Market sentiment has become more sensitive. Local producers in the countries in which JAA operates have become increasingly sensitive to price changes. It has been decided to monitor closely the price levels in these countries. Any changes in national feed-in tariffs (FITs) will have an effect in either direction, which will also affect all of JAA's objectives.
Cost Variability and Management
Because of social movements and environmental issues in some of the countries, the working conditions may be affected severely, which in turn may impact JAA's sales and production costs as well as business continuity. The risk treatment decided for reaching new markets and contractors will help to decrease the cost volatility in the long run. In the short term, risk acceptance criteria will be reduced and hedging will be required for short positions of the foreign exchange portfolio above the agreed risk criteria. In the long run, the cost parameters will be monitored continuously. According to the monitoring results, moving of production lines to different countries will be reevaluated (see Exhibit 22.7).
Exhibit 22.7 Risk Attitude
· All negative risks must reside in a low region, and all positive risks must remain at least at a medium level. Exceptions must be decided according to Executive Risk Oversight Committee (EROC) approval and authorization levels. Specific limits and tolerances are set within the risk criteria to enhance risk management treatments. Each specific attitude is set consistently with the risk scales established as per Exhibit 22.3 or Exhibit 22.4. Exceeding the maximum or falling below the minimum is considered a risk indicator. Hence this must be immediately evaluated by the risk owner.
· Human resources personnel turnover rate: Maximum 2 percent of the sector median. Maximum compensation can be two times the minimum compensation at the same level in the responsibility level. If the performance parameters do not match higher compensation, then it must be decided by the Compensation Committee whether or not to continue with this policy.
· Business continuity: Maximum allowable total business disruption is three days in severe conditions (i.e., disasters) for operating centers.
· Health and safety: Maximum of one occurrence in a three-year period. No employee or nonemployee deaths are acceptable. Maximum is one minor event per year.
· Legal: No delays accepted in reporting and replying to official letters. Contract failures must strictly reside at low levels.
· Concentration: No one single customer can exceed 5 percent of JAA's sales.
· Customer satisfaction: Maximum yearly returned products 1 percent, and maximum yearly replaced products 1 percent of prior year's sales.
· Market risk: Nonhedged foreign exchange portfolio balance can be a maximum 30 percent of the aggregate total open positions.
Local Trade Laws and Regulations
Compliance with local laws and regulations is one of JAA's strategic objectives. Therefore, a chief compliance officer position was established to bolster the compliance department and to improve its monitoring and assessment capability.
One of the most important risk sources is the potential U.S. and European Union Free Trade Agreement. It will highly impact JAA's business and result in new opportunities and threats. The non-EU operations may be affected negatively, whereas EU operations will benefit from this agreement. The compliance department will use its contacts and sources to proactively acquire information about the details of the agreement. This will ensure a precise risk assessment as to how these developments may benefit JAA or the threat they may pose for its EU operations.
New Fabric Production and Dye Technologies
JAA has the ability to reduce costs and demonstrate market leadership among competitors through the efficient deployment of technology. It decided to engage in several research projects with universities that have a high reputation in these areas to stay ahead of competitors, as stated in the company's objectives. Also, this will be done to ensure that disruptive entrants to its market can be dissuaded due to the technological advantages JAA enjoys and the cost other companies would incur to enter and compete in its market.
Reaching Target Customers in New Locations
Being unable to reach target customers in new locations is considered a major risk because it would affect the market share of JAA in the future. Since the treatment of this risk would affect some other consequences that would arise from other risks, it has a special priority because of this dependency. A special markets research team was established to gather detailed information about potential new markets and customers. This team will be responsible for the extraction of information about the cultural and behavioral expectations in the targeted countries.
Environmental Sensitivity of Creditors
There is a high interest from creditors of JAA concerning the environmental effect of production/chemical usage and treatment actions. Even though special agreements exist in the SLAs with our contractors, any failure to comply will severely degrade the credibility and the reputation of the company. Therefore all the outsourcing arrangements allow JAA to receive monitoring reports from the external and internal auditors of its business partners to ensure that governance processes and controls are effective and their operations efficient. They also allow the company to initiate its own assessments if these aforementioned assurances cannot be provided.
Imitation of JAA's Products
Given the high quality and international acceptance of JAA's products, it noted that several attempts have been initiated to copy the brand with inferior products. A market research team will also be responsible to detect such illegal activities and report as necessary, with action to be taken accordingly.
Each risk is reassessed whenever significant new information is collected from any item in the context, as well as on the feedback from the results of treatments. Risk levels are not changed until results from the treatments are validated.
APPENDIX A: JAA INC. FINANCIAL STATEMENTS
|
JAA Inc. |
||
|
Balance Sheet |
||
|
Period Ended: December 31, 2013 |
||
|
Consolidated Balance Sheets |
||
|
(amounts and shares in thousands, except per share amounts) |
||
|
|
Years ended |
|
|
|
December 31, |
|
|
|
2013 |
2012 |
|
Assets |
|
|
|
Current Assets |
|
|
|
Cash |
$ 28,242 |
$ 12,853 |
|
Trade accounts receivable, net of allowances of $2,085 and $2,195 at December 31, 2013 and 2012, respectively |
18,631 |
14,962 |
|
Prepaid expenses and other current assets |
11,248 |
7,631 |
|
Inventories, net |
153,438 |
164,229 |
|
Restricted cash |
1,997 |
733 |
|
Income taxes receivable and prepaid income taxes |
149 |
530 |
|
Deferred income taxes, net of valuation allowance of $12,760 and $12,003 at December 31, 2012 and 2011, respectively |
317 |
494 |
|
Total current assets |
214,022 |
201,432 |
|
Property and equipment, net |
89,778 |
87,438 |
|
Deferred income taxes, net of valuation allowance of $64,818 and $61,770 at December 31, 2013 and 2012, respectively |
961 |
1,529 |
|
Other assets, net |
38,586 |
33,783 |
|
Total assets |
343,347 |
324,182 |
|
Liabilities and stockholders' equity |
|
|
|
Current liabilities |
|
|
|
Revolving credit facilities and current portion of long-term debt |
64,375 |
80,556 |
|
Accounts payable |
43,425 |
33,920 |
|
Accrued expenses and other current liabilities |
34,181 |
41,516 |
|
Income taxes payable |
3,945 |
2,137 |
|
Deferred income tax liability, current |
1,594 |
296 |
|
Current portion of capital lease obligations |
3,705 |
1,903 |
|
Total current liabilities |
151,225 |
160,328 |
|
Long-term debt, net of unamortized discount of $27,929 and $20,183 at December 31, 2012 and 2011, respectively |
97,445 |
107,012 |
|
Capital lease obligations, net of current portion |
4,371 |
3,844 |
|
Deferred tax liability |
583 |
262 |
|
Deferred rent, net of current portion |
30,706 |
24,706 |
|
Other long-term liabilities |
17,695 |
10,695 |
|
Total liabilities |
302,025 |
306,847 |
|
JAA Inc. |
||
|
Balance Sheet |
||
|
Period Ended: December 31, 2013 |
||
|
Commitments and Contingencies |
||
|
Stockholders' Equity |
$ |
$ |
|
Preferred stock, $0.0001 par value per share, authorized 1,000 shares; none issued |
— |
— |
|
Common stock, $0.0001 par value per share, authorized 230,000 shares; 110,111 shares issued and 107,181 shares outstanding at December 31, 2013, and 108,870 shares issued and 105,588 shares outstanding at December 31, 2012 |
2013 |
2012 |
|
Additional paid-in capital |
6,786 |
6,786 |
|
Accumulated other comprehensive loss |
(2,725) |
(3,356) |
|
Accumulated profit |
39,407 |
16,051 |
|
Less: Treasury stock, 304 shares at cost |
(2,157) |
(2,157) |
|
Total stockholders' equity |
41,322 |
17,335 |
|
Total liabilities and stockholders' equity |
343,347 |
324,182 |
|
JAA Inc. |
||
|
Income Statement |
||
|
Period Ended: Dec. 31, 2013 |
||
|
JAA, Inc. and Subsidiaries |
||
|
Consolidated Statements of Operations and Comprehensive Gain |
||
|
(Amounts and shares in thousands, except per share amounts) |
||
|
|
Years Ended |
|
|
|
December 31, |
|
|
|
2013 |
2012 |
|
Net sales |
$779,534 |
$694,559 |
|
Cost of sales |
384,783 |
359,927 |
|
Gross profit |
394,751 |
334,632 |
|
Selling expenses |
239,625 |
217,447 |
|
General and administrative expenses (including related party charges of $1,090 and $912 for the years ended December 31, 2013 and 2012, respectively) |
120,625 |
97,327 |
|
Income (loss) from operations |
34,501 |
19,858 |
|
Interest expense |
859 |
1,283 |
|
Foreign currency transaction loss (gain) |
775 |
(1,235) |
|
Other expense (income) |
4,384 |
(904) |
|
Gain before income taxes |
28,483 |
20,714 |
|
Income tax provision |
5,127 |
3,729 |
|
Net gain |
$ 23,356 |
$ 16,985 |
|
Basic and diluted earnings per share |
$ 0.21 |
$ 0.15 |
|
Weighted average basic and diluted shares outstanding |
105,980 |
105,980 |
|
Net gain (from above) |
$ 23,356 |
$ 16,985 |
|
Other comprehensive (loss) income item: |
|
|
|
Foreign currency translation, net of tax |
631 |
631 |
|
Comprehensive gain |
$ 23,987 |
$ 17,616 |
|
Number of common shares issued |
110,111 |
108,870 |
APPENDIX B: RISK MANAGEMENT POLICY
PURPOSE
Risk management is considered critical to the company and as such it is viewed as a lifetime strategic project for JAA. JAA continuously monitors and reviews its risk management framework in view of the 11 principles of ISO 31000 and puts great effort into achieving outstanding results through the ongoing learning process.
JAA encourages transparent communications and making decisions with the best available information. It also motivates its employees to clearly understand the business and be proactive in detecting opportunities and threats.
All personnel are expected and encouraged to understand this culture and thus be instrumental in being part of JAA's decision making process. Utilization of uniform terminology is considered a crucial component for building and maintaining the desired culture throughout the company.
This document has been accepted and signed by the board of directors as an indication that there is a common understanding of how the company will manage its risks. The target audience of this policy is the entire organization comprising both the internal and external stakeholders. Each employee is required to understand, manage, monitor, and act according to the policies, principles, and methodology stated in this document. The Risk and Strategy Committee (RSC) approves and oversees the risk management policy and monitors the effect of risk management on the organization. The RSC is assisted by the Executive Risk Oversight Committee (EROC) with the oversight and monitoring of the risks impacting JAA.
SCOPE
This document supplies overarching principles and a framework for JAA for effective risk management. Each business unit is responsible for taking the necessary actions for treatment within the risk criteria. Each business unit is required to use the policies and the methodology that follow to design its processes and procedures.
OBJECTIVES OF RISK MANAGEMENT
The only purpose of risk management is to accomplish our business objectives, as that is what we are accountable for to the stakeholders of the company. Each employee has a vested interest to ensure that this happens to the best of his or her abilities and in a way that is consistent with his or her job descriptions. All risks must be understood and all key decisions must factor into such understanding before an action is taken. JAA acknowledges that increasing personal capabilities will also increase organization capabilities. Therefore, maximum prudent effort is expected from each employee in the decision making process to prioritize organization resources so that JAA's objectives are attained at all levels.
TERMINOLOGY
· Risk: Effect of uncertainty on objectives.
· Risk criteria: Terms of reference against which the significance of a risk is evaluated.
· Risk management: A discipline for managing uncertainty.
· Risk monitoring: Continuous checking, supervising, critically observing, or determining the status in order to identify change from the performance level required or expected.
· Risk register: A dynamic record that is maintained to monitor and review risks continuously. It is not intended to be used as a static document, and it represents one of the critical outputs of the risk management process.
· Risk treatment: Process to modify risk.
· Stakeholder: Entity that affects, is affected by, or perceives that it can be affected by a decision of the organization. Each stakeholder's needs and expectations have to be addressed explicitly in the risk management process. In addition, a robust communication process needs to be established with all stakeholders.
RISK OVERSIGHT PRINCIPLES
The board acknowledges that it will not always be able to manage all of the risks the company faces within the set risk criteria. Consequently, a set of high-level principles that set the overarching boundaries for how the company will manage its risks effectively is in place, so that the strategic objectives can be achieved:
· The board will adopt measures to ensure a low level of volatility in revenues and earnings.
· The board will promote orderly business operations to guard against a loss of confidence in the company by all stakeholders, including shareholders, customers, suppliers, and regulatory agencies.
· The board will adopt measures to minimize regulation-related risks.
· The board will review any changes to the existing risk profile caused by the introduction of any new significant projects.
· The board will monitor business and strategic performance via reporting of key performance indicators. The risk criteria statements will provide a basis for strategic evaluation and assessment of new strategic directions.
A discussion of JAA's business strategy must include an analysis of the uncertainties impacting objectives of that strategy. This will provide JAA with an opportunity to improve the likelihood of strategic success by thinking about risks proactively.
ROLES AND RESPONSIBILITIES
The board of directors (BOD) is accountable to ensure that the organization manages all risks. The BOD fulfills this duty by establishing the RSC, as well as an EROC for the governance process. The BOD evaluates the structure and effectiveness of the RSC and EROC yearly.
The chief risk officer (CRO) is an adviser to all committees. He or she is responsible for facilitating risk workshops and providing support to establish training curricula. He or she collaborates between the risk oversight and other risk management groups.
RISK MANAGEMENT METHODOLOGY
JAA uses the ISO 31000 Risk Management Standard and HB 436 to organize its risk management activities. The BOD oversees risk management through its established committees and delegates authority to management where needed. This mandate and commitment function is executed by the EROC. Risk policies adopted for the organization must be consistent with the ISO 31000 principles.
In the objective setting process, as part of business strategy, there must be an alignment with SMART criteria (i.e., specific, measurable, attainable, relevant, and timely). All company personnel need to understand the company's internal and external context. Risk assessment consists of event identification, risk analysis, and risk evaluation.
Scenario analysis and strengths, weaknesses, opportunities, and threats (SWOT) analysis are conducted to identify, analyze, and evaluate the risks. Surveys are conducted monthly to detect any changes in perception. Risk sources stated in the context are always included in threat and benefit analyses. Risk workshops are facilitated by the risk management department to identify, analyze, and evaluate JAA's risks.
All identified major risks are reported to the EROC, which in turn is responsible for the implementation and monitoring of risk treatment plans. Treatment plans include measurement and monitoring activities together with performance and success criteria. All risks are subjected to three different scenarios for what-if analysis. Each scenario set is divided into four categories as worst case, current conditions, best case, and most expected case, and is analyzed accordingly. The RSC oversees execution of the risk treatment plans.
Monitor and Review: At each fiscal year-end, monthly impacts of consequences are statistically combined and mapped to risk levels in the risk criteria to verify whether the previous predictions occurred. If there are any identified gaps and/or significant errors, the root cause of these gaps needs to be identified and results communicated to stakeholders to ensure that these can be included in the next assessment.
GENERAL RISK MANAGEMENT POLICIES
General risk management policies apply to the entire company. Policies provide high-level guidelines for managing risks within JAA. Commitment to comply with the general policies is a company-wide requirement. The following are key risk policies:
· Corporate ethics policy. Corporate ethics rules are monitored and maintained by the Audit Committee. Ethics are included in each training seminar and such seminars need to be taken periodically.
· Customer satisfaction and retention policy. Internal and external customer expectations are periodically monitored and communicated in a timely fashion to ensure that service levels are achieved for operational objectives.
· Ownership policy. No information, data, process, report, or asset can exist without having an owner attached to it. Change of ownership can be initiated only upon approval of a designated internal stakeholder. Ownership is assigned according to priority criteria of “most used by,” “first created by,” and “most impacted by.”
· Training policy. Each item in this policy statement must be included in the company's training program. Corporate culture can be established and maintained only by providing timely and sufficient training to each employee. No employee can be assigned responsibilities without adequate measurement of his or her competencies.
· Information systems policy. Objectives at all levels (strategic, tactical, and operational) should be mapped down to the infrastructure level. (see Exhibit 22.2). Context definition should be monitored and reviewed at least yearly and whenever a major event occurs. All risk owners must be cognizant of their dependency on other areas of the business. Integrity, consistency, and accessibility objectives are set by business lines, and information technology (IT) hardware and software architectures are designed to ensure the achievement of such objectives.
· Access rights policy. Access rights should be provided according to each employee's responsibility level. Access rights should not be changed without approval of a senior manager. All access rights need to be consistent with the authorization levels in Exhibit 22.8. No conflict of interest and segregation of duties issues are permitted to exist.
Exhibit 22.8 Authorization Levels for Risk Acceptance or Retaining of Risk
All management level personnel are to be assigned an authorization level by the board of directors (BOD). Purchases and borrowings must be performed in accordance with the levels of authority.
Risk attitudes are defined with risk criteria, and different risk attitudes may be assigned to specific risks in specific circumstances. Risk criteria are established by the RSC to evaluate the significance of risks and to distinguish the possible risk levels. For qualitative risk types, high-level risks can be accepted and retained only by the BOD; medium-level risks can be accepted and retained by the RSC; low-level risks can be accepted and retained by the EROC. The business lines are responsible for the implementation of the treatment of risks to align with risk criteria for the risks they own and need to manage.
For quantifiable risks, the following authorization levels are/should be applied:
· Level A: Signature authority up to $10 million; $10 million to $50 million needs a second signature, and any level above this must be signed by the board of directors as well.
· Level B: $1 million to $10 million
· Level C: $500,000 to $1 million
· Level D: Up to $500,000
· Level E: No spending authorization
The BOD has a Level A authority, C-level executives have Level B authority, department heads have Level C authority, line managers have Level D authority, and all other personnel have Level E authority.
· Human resources policy. Background screening and training are required for all employees. Compensation is evaluated and performance is monitored by the Compensation Committee. Compensation must be proportional to responsibilities and should not motivate unnecessary and inconsistent risk taking as compared with JAA's risk criteria. Especially, performance measures will include and reflect a fair amount of collaborative and teamwork performance as well as individual performance to prevent destructive competition. Any contrary action will be considered a failure to comply with the corporate policies and will be treated according to company laws and regulations.
· Outsourcing and contract management policy. Outsourcing is used whenever it is beneficial for the organization to do so. A comprehensive risk assessment must be conducted and results must be communicated among internal stakeholders before establishing any outsourcing engagement. Service-level agreements (SLAs) are determined according to business needs and set within the tolerance levels of the objectives. Monitoring of SLAs is the responsibility of the owner of the business line signing the contract. Dependency on a single outsource agreement must be avoided by establishing alternate sources.
· Business continuity policy. Impact analysis is conducted yearly to assess the impact level of disruption to all business units. Service-level agreements are based on this impact analysis and must be signed by all parties. IT departments use this impact analysis to determine parameters for service levels. Each employee must have a designated backup coordinator.
· Conflict of interest policy. Conflicts of interest must be avoided. Special emphasis needs to be given to those areas sensitive to public perceptions. Corporate ethics is included in each training curriculum to establish enhanced awareness at JAA.
· Segregation of duties policy. Critical processes as defined by business lines are subject to design criteria of the “four eyes principle.”11 A commencer of any process should not have the capability to terminate it, and a second person should review and approve it.
· Internal communications policy. The company should establish specific communication channels. Stakeholders must be informed prior to any major changes being made. Communication response times should be created and compliance levels should be measured to ensure quality.
· Public relations and external communications policy. Corporate brand and reputation are our most critical assets. Therefore, maximum effort should exist to protect and increase their value. External communications must be carried out by trained and authorized personnel. All media and external relations need to be monitored by the public relations department. Any communications outside the company must be properly authorized.
· Patents, trademarks, and copyrights policy. Any type of innovation that would have an effect on corporate objectives is strongly encouraged and rewarded proportionally to its contribution to effectiveness or efficiency throughout the organization. Patent rights belong to JAA. Appropriate permission and rights can be granted with the approval of JAA.
· Sustainability and environmental protection policy. Maximum effort must be provided to preserving the environment and the resources in each project to enable achievement of business objectives. Carbon emissions must be reduced as a priority throughout the business. Green sources of energy must be utilized if available. Energy backups must contain solar cells in production locations where at least moderate seismic rates are recorded.
· Insurance policy. Insurance needs are decided upon after evaluating the current risk profile. Market research must be conducted annually to identify the best total value, which is not necessarily the lowest rate.
· Market risk policy. Fluctuations in market prices and exchange rates affect the valuation and cost of JAA's products. Therefore, JAA's ability to compete in the marketplace may change accordingly. Close monitoring of costs is required throughout the entire business. Exchange rate risks above the limit of accepted amounts in export contracts must be hedged by futures contracts to ensure cost/profit stability. Market risk attitude was provided in Exhibit 22.7. Also, key risk indicators must be accepted and reviewed periodically for effectiveness. Liquidity risks need to be managed by the financial control and accounting departments. Liquidity figures are updated monthly and projected for the fiscal year. This document is reviewed yearly and updated as necessary by the EROC. The Internal Audit department is responsible for assessing the adequacy and alignment with this policy document of the applications and procedures throughout the organization.
PART A – QUESTIONS
1. How high do you assess the knowledge level of the business strategy throughout the company by the average employee? Is it your assessment that there is a robust understanding of JAA's business strategy? Support your position with examples.
2. As you are aware, effective implementation of ISO 31000 involves effective design and implementation of a risk management framework and effective implementation of the risk management processes. This will be verified by incorporation of 11 key principles. Find an example in the case for each of the 11 principles in action.
3. Why is it important that the company be able to identify JAA's major stakeholders? How should a company identify its stakeholders? What is meant by the concept that stakeholders select the company instead of the company selects the stakeholders?
4. What characteristics do you see in the board of directors that lend themselves to a strong tone at the top and a culture that fully embraces risk management?
5. If you compare the internal audit department at JAA to several that you know of currently in the marketplace, what are some of the major differences that you see at JAA that obviously have contributed to superior performance? What is unique and refreshing about the approach to the external audit as compared to what you have seen in industry?
6. What is your opinion of the risk (event) identification techniques in place at JAA? How do you think that the company evolved to using such techniques?
7. What is the linkage at JAA between the strategic objectives, context, stakeholders, and risk criteria? Support your comments with specific examples of the link in these four areas.
8. Why is it important that risk criteria be created as per JAA? Do you think it is possible for any reasonable risk treatment plan to be in place without creation of such criteria?
9. Review the risk management policy in Appendix B and describe the kinds of things that constitute a best-in-class policy.
10. What other types of general or specific polices can you describe to manage risks?
11. Why is it that “tone at the top” and a strong risk culture are critical components for a company's success, such as what you see at JAA?
PART B – QUESTIONS
1. If the internal audit department did not report directly to the Audit Committee, but to the CFO, what kind of issues would this raise in your mind? Is this something that you would support? Can you cite specific examples?
2. Is it important that internal audit annually reviews the company's risk management function? What advice would you provide to a head of internal audit that was not performing such a review? Have you seen any examples where internal audit has conducted such reviews and if not, why do you think this to be the case?
3. In many companies, it is typical for internal audit to itself perform a risk assessment which it will use for audit planning and execution purposes. Do you have any thoughts on what you see as the pitfalls in this? What is the ideal situation in a company?
4. Is it appropriate that internal audit provides an opinion on the integrity of work performed by the external auditors, as in the JAA case, and what do you see as pitfalls where internal audit does not do this? Should internal audit be asked to opine on the performance by the external auditors, when in fact not too long ago external auditors were the ones providing an opinion on internal audit performance?
5. What specific characteristics differentiate this external audit function from those you have seen over the past several years? How do you envision external audit fitting into JAA's overall risk management system?
6. If JAA was not using ISO 31000 and HB 436, but instead was using the COSO ERM framework and as well the new COSO internal controls framework, what challenges do you think the company would face in trying to roll out a credible program? Do you think they could be as successful? Support your opinion.
7. Would you consider using alternative internal control frameworks and if so, which ones?
8. Suppose the board decided that they did not need to monitor the risks at all and that this could be delegated down to the CEO. What problems do you see occurring in future?
9. Evaluate the different risk identification and analysis methods being used by JAA, and compare to other methods you are aware of that are not being used. Support your opinion on this subject matter.
10. Suppose that JAA did not have a formal system of risk management using ISO 31000. Do you think it is possible that they could still be doing an excellent job at managing their business risks? Please support your opinion in this regard.
11. How would the board measure the success of their risk management?
12. How would the Compensation Committee use risk management in their reward and compensation process of the company?
NOTES
1 ISO 31000:2009, “Risk Management—Principles and Guidelines,” was issued by the International Organization for Standardization (ISO) and provides principles, framework, and a process for managing risk. It can be used by any organization regardless of its size, activity, or sector. Using ISO 31000 can help organizations increase the likelihood of achieving objectives, improve the identification of opportunities and threats, and effectively allocate and use resources for risk treatment.2 HB 436.SA/SNZ HB 436:2013, “Risk Management Guidelines: Companion to AS/NZS ISO 31000:2009.”3 The Institute of Directors in Southern Africa (IoDSA) formally introduced the King Code of Governance Principles and the King Report on Governance (King III) in September 2009. Like its 56 commonwealth peers, King III has been written in accordance with the “comply or explain” principle based approach of governance, but specifically the “apply or explain” regime. This regime is unique in the Netherlands and now in South Africa. While this approach remains a hotly debated issue globally, the King III Committee continues to believe it should be a nonlegislative code on principles and practices.4 In 1995, the Criteria of Control Board of the Canadian Institute of Chartered Accountants (CICA) had written this guidance for people who are responsible for or concerned about control in organizations. Conceptually, it was considered a leader in thinking about control but was later abandoned by the CICA and ultimately overtaken in popularity by COSO's Internal Control Framework.5 The UK Corporate Governance Code (formerly the Combined Code) sets out standards of good practice in relation to board leadership and effectiveness, remuneration, accountability, and relations with shareholders. The latest edition was issued in September 2012.6 In November 2013, the Financial Reporting Council issued its Risk Management, Internal Control and the Going Concern Basis of Accounting Consultation on Draft Guidance to the directors of companies applying the UK Corporate Governance Code, and associated changes to the code.7 “Risk Management Guidelines: Companion to AS/NZS 4360:2004.” The Risk Management Guidelines companion to the AS/NZS ISO 31000:2009 handbook provides guidance for establishing and implementing effective risk management processes in any organization.8 See note 1.9 The use of bow tie analysis is described in ISO 31010 “Risk Management—Risk Assessment Techniques.”10 See ISO 31000:2009 section 5.3.5 for additional detail on risk criteria.11 The “four eyes principle” refers to having two people view each transaction so that one checks on the other.
REFERENCES
1. AS/NZS 4360:2004, “Risk Management.”
2. Canadian Standards Association. 1997. Q850-97 “Risk Management: Guideline for Decision-Makers.”
3. COSO Internal Control Framework. 1992/1994. “Committee of Sponsoring Organizations of the Treadway Commission.”
4. COSO Internal Control Framework. 2013. “Committee of Sponsoring Organizations of the Treadway Commission.”
5. Financial Reporting Council. “Consultation Draft on Risk Management, Internal Control and the Going Concern Basis of Accounting.”
6. Fraser, John, and Betty J. Simkins, eds. 2010. Enterprise Risk Management: Today's Leading Research and Best Practices for Tomorrow's Executives. Hoboken, NJ: John Wiley & Sons.
7. HB 436:2004, “Implementation Guidelines to AS/NZS 4360:2004.”
8. HB 436:2013, “Implementation Guidelines to ISO 31000 Risk Management.”
9. ISO 31000:2009, “Risk Management Framework.”
10. ISO 31010:2009, “Risk Management—Risk Assessment Techniques.”
11. ISO Guide 73:2009.
12. “King III Report on Corporate Governance.” 2009.
13. Purdy, Grant. 2011. “Risk Appetite: Is Using This Concept Worth the Risk?” Broadleaf Capital International, Risk Post, NZ Society for Risk Management, September.
ABOUT THE CONTRIBUTORS
Julian du Plessis has more than eight years' financial sector experience. He is the Head of Internal Audit at AVBOB Mutual Assurance Society, a long-term insurer in the life and savings business. He joined AVBOB during 2011 as its Governance Officer. He previously worked at FirstRand Bank, one of the largest banking institutions in South Africa, as a senior risk manager starting out in the Group ERM department focusing on strategic risk management. Julian is a South African chartered accountant, and completed his professional training at Pricewaterhouse- Coopers. Julian has an MPhil (business management) master's degree obtained from the University of Johannesburg (2011), a B Compt Honors accounting degree from the University of South Africa (2000), and a B Admin (international politics) degree majoring in economics and political science from the University of Pretoria (1994).
Arnold Schanfield is a Principal with Schanfield Risk Management Advisors LLC. He is an internal audit and risk professional with diversified industry expertise, including consumer products, higher education, life sciences, manufacturing, not for profit, retail, trading companies, and higher education. He specializes in risk management implementations and has leveraged his prior experiences in internal audit, public accounting, and governance to the risk management discipline. Arnold holds an undergraduate degree (BSC) from Loyola College in Montreal and a graduate degree in public accountancy from McGill University in Montreal. In addition, he holds certifications of certified public accountant and certified internal auditor in the United States as well as a Chartered Accountant from Canada. Arnold has a passion for the risk management discipline and has used his experiences to develop seminar and training material that has been delivered to numerous companies. In addition, he comments and speaks frequently on risk management–related matters.
Alpaslan Menevse is currently the Risk Officer at Sekerbank T.A.S., which has in excess of 310 branches in Turkey. He has 28 years of experience in information systems, both as an academic and as a practitioner. In the early years of his career, he joined work groups as a team member of Business Process Management (BPM) in the manufacturing industry. During his academic career, as a computer and aeronautics engineer he was involved in several Information and Communication Technology (ICT) projects and completed his master's thesis in EUCLID RTP 11.3 artificial intelligence project of F-16 fighter jet simulator development, where he modeled pilot behaviors of risk assessments in BVR (beyond visual range) flight. He also led different sizes of local area network (LAN) and wide area network (WAN) projects during 1995–2004, specializing in business continuity and disaster recovery management.
He is a silver member of Information Systems Audit and Control Association (ISACA) and holds Certified Information Systems Auditor (CISA) and Certified in Risk and Information Systems Control (CRISC) certificates where he was one of the members of the review work group of the CRISC 2011 manual, which is the first book published in this area. He joined Sekerbank as the Internal IS Auditor and started working with AS/NZS 4360 in 2007. He is responsible for implementing ISO 31000 throughout the organization. He has a special interest in human behaviors and the human side of change management. Additionally, he is a member of the ISO 31000 TC 262 Technical Committee, United Nations Economic Commission for Europe (UNECE) - Risk Management Group (GRM) and also the chairman of the Turkish Standards Institute TS ISO 31000 MTC 132 Risk Management National Mirror Technical Committee.
Note: Authors of this case study manage the group on LinkedIn titled “Risk Management: Creating Value From Uncertainty.” Any questions or comments can be forwarded either personally or as a discussion topic.