Final report

profilem21q8
RSMKuwait-InternsERMTraining-July2020T1week2riskmangement.pdf

1

RISK MANAGEMENT TRAINING

July 13, 2020

RSM Albazie Consulting W.L.L

2

Learning objectives

The course focuses on the following elements:

• Core concepts and definitions

• Risk management standards and frameworks

• Enterprise risk management

• Risk assessment and analysis

• Risk appetite and risk responses

• Roles and responsibilities

3

RISK AND RISK MANAGEMENT

CORE CONCEPTS AND DEFINITIONS

4

The effect of uncertainty on objectives.

Definition of Risk

International Organization for Standardization (ISO)

5

The possibility of an event occurring that

will have an impact on the achievement of

objectives. Risk is measured in terms of

impact and likelihood.

Definition of Risk

Institute of Internal Auditors (IIA)

6

Risk is the combination of the probability

of an event and its consequence.

Consequences can range from positive to

negative.

Definition of Risk

Institute of Risk Management (IRM)

7

Risk categories (Types)

• STRATEGIC RISK

• COMPLIANCE RISK

• FINANCIAL RISK

• OPERATIONAL RISK

• TECHNOLOGY RISK

• OPPORTUNITY RISK

8

Assessing the level of risk

INHERENT RISK:

The level of a risk before any control activities are in

place.

RESIDUAL RISK:

The level of a risk taking into account the mitigating

controls currently in place.

9

Inherent and residual risk - Example

Likelihood

Im p

a c

t

Low High

Inherent riskResidual risk

Controls

Residual risk

L o

w H

ig h

Example:

A company has a warehouse that stores various types

of cheese and meats in coolers and freezers, which

are sold to restaurants and hotels.

Objective/Activity: Ensure items are stored properly

to maintain quality and shelf-life.

Risk: Coolers/Freezers may malfunction causing

items to spoil. This may lead to financial, reputational,

regulatory, … losses.

Controls:

1) Monthly maintenance contract on coolers/freezers

2) Back-up power generators are installed in case of

power outage

Inherent Risk?

Residual Risk?

10

RISK MANAGEMENT STANDARDS AND FRAMEWORKS

11

Why do organizations

formalize their risk

management frameworks?

Discussion

12

Benefits of risk management

Informed decision making

Comply with regulatory requirements

Support cost effective internal control

Stronger and more effective corporate governance

Sets the tone / culture for the business

13

Why do organisations take risk?

To increase financial returns

Gain competitive advantage

Lack of understanding / poor decision making

14

Risk Management models and standards

• COSO ERM framework

• ISO 31000:2018

• COBIT: Specialist information technology risk management

guidance published by ISACA

• Basel (Banking)

15

COSO Framework

16

ISO ERM Framework

Principles

Framework Process

17

ISO ERM Framework - Principles

18

ISO ERM Framework - Framework

19

ISO ERM Framework

20

PUTTING IT IN TO PRACTICE

21

Risk management process

Decision making

supported by

information

Business strategy

Identify risk areas

Assess risk

Implement risk

responses

Monitor controls

Assurance

Review, refine,

improve

22

Setting objectives

To understand risk, an organization should have a clear view of its objectives

Analyses

•Internal and external analyses to support objective setting

Set strategic objectives

•Set strategic objectives – organizational level

Departmental / divisional objectives

•Set tactical objectives at appropriate level of delegation / responsibility

Operational objectives

•Team / personal objectives

Alignment (between objectives at each level)

23

IDENTIFYING RISKS

24

How do organizations identify risks?

workshops horizon scanning

competitors sector / industry news peers & sharing insights

supply chain monitoring

internal processes

internal reports and indicators

regulatory news

internal audit

whistleblowing

complaints / incidents

health & safety function

external advisors

staff feedback and surveys

25

ASSESSING RISKS

26

The bow tie model

ConsequencesCauses

EVENT

Recovery measuresControl measures

Underlying

threats

Immediate

threats

Immediate

consequences

Ultimate

consequences

27

If you were to group risks, how

would you do it?

Risk categorization / risk taxonomy

28

Risk categorisation (example risk sources)

Strategic

Business Continuity

EnvironmentReputation Financial

Fraud / crime

People / Succession

Legal / regulatory /

political

Technology Reputation

Financial / Economic

29

Other ways to classify risks

External risks

New or

volatile risks

Existing or

stable risks

Internal risks

Non-routine

and emerging

external risks

Internal

change

management

risks

Routine

external risks

Routine

internal risks

30

Advantages and disadvantages of

each approach

Top down vs bottom up risk assessment

31

Risk assessment

Who should assess risks?

Top down

Bottom up

32

How would you rate

LIKELIHOOD and IMPACT

when assessing a risk?

Risk analysis

33

The response to a risk should be proportionate to the

organization’s risk appetite

RISK APPETITE AND RISK RESPONSE

34

The level of risk that is acceptable to the board or management. This may be set in relation to the organization as a whole, for different groups or risks or at an individual

risk level.

Definition of Risk Appetite

Chartered IIA

35

Risk appetite could look like this…

Likelihood

Im p

a c

t

Within Risk Appetite

Exceeding Risk Appetite

Inherent riskResidual risk

Low High

L o

w H

ig h

36

Risk appetite could look like this…

Likelihood

Im p

a c

t

Within Risk Appetite

Exceeding Risk Appetite

Inherent riskResidual risk

Low High

L o

w H

ig h

37

Appetite to take risk - Example

Classification Matrix

38

Appetite to take risk

Risk Appetite/Tolerance

39

Responses to risk

T

T

T

T

reat

ransfer

olerate

erminate

40

RESPONSIBILITIES FOR RISK MANAGEMENT AND RISK DECISIONS

41

Roles and responsibilities regarding risk management?

• Ultimate responsibility for risk management

• Define risk appetite Board of directors

• Reviewing control systems

• Receiving assurances from auditors Audit Committee

• Responsibility for risk management process and frameworkRisk Committee

• Facilitating process

• Reporting to Risk and Audit Committees

CRO / Risk Manager

42

Roles and responsibilities regarding risk management?

• Reporting to Board via audit / risk committees

• Identify risks. Monitor effectiveness

Risk Management group

• Assurance re internal controls & risk responses

• Support management in improving risk mgmt. Internal audit

• Be aware of risk

• Flag / escalate potential risks All employees

• As all employees

• Own action / responses to specific risks process Senior managers

43

Three Lines of Defence Model The three lines of defense, a model adopted by Organizations across the globe. Each of these three lines play a distinct roles within the Organization’s

wider governance framework. However, each of these three lines face challenges of alignment. Organizations face inconsistent expectations and

decentralized activities in different lines of business and coverage across the three lines of defense

44

REPORTING AND MONITORING

45

A simple risk register

46

Reporting and Monitoring – an example

Strategic Risks

Annually Board

A formal refresh by the Board

to ensure alignment with

the organisations

business plan

Quarterly Board

Receive a verbal update from the Finance and

Audit Panel

Audit Committee Discuss the number/type of primary risks identified and

review of the progress against their risk management action

plans;

Review the latest assurance reports

Senior Management Discuss changes in the number/type of all risks identified and

review of the progress against risk management action plans

in connection with all risks

Review the assurances received in connection with the

effectiveness of risk controls, in particular those classified

as Contingency i.e. where the reliance on key

controls is considered most important.

Monthly Senior Management

Discuss changes in the

number/type

of primary risks identified and

review

the progress against risk

management action plans in

connection with risks classified as

primary;

47

QUESTIONS/DISCUSSION

.

48

THANK YOU FOR

YOUR TIME AND

ATTENTION