Final report
1
RISK MANAGEMENT TRAINING
July 13, 2020
RSM Albazie Consulting W.L.L
2
Learning objectives
The course focuses on the following elements:
• Core concepts and definitions
• Risk management standards and frameworks
• Enterprise risk management
• Risk assessment and analysis
• Risk appetite and risk responses
• Roles and responsibilities
3
RISK AND RISK MANAGEMENT
CORE CONCEPTS AND DEFINITIONS
4
The effect of uncertainty on objectives.
Definition of Risk
International Organization for Standardization (ISO)
5
The possibility of an event occurring that
will have an impact on the achievement of
objectives. Risk is measured in terms of
impact and likelihood.
Definition of Risk
Institute of Internal Auditors (IIA)
6
Risk is the combination of the probability
of an event and its consequence.
Consequences can range from positive to
negative.
Definition of Risk
Institute of Risk Management (IRM)
7
Risk categories (Types)
• STRATEGIC RISK
• COMPLIANCE RISK
• FINANCIAL RISK
• OPERATIONAL RISK
• TECHNOLOGY RISK
• OPPORTUNITY RISK
8
Assessing the level of risk
INHERENT RISK:
The level of a risk before any control activities are in
place.
RESIDUAL RISK:
The level of a risk taking into account the mitigating
controls currently in place.
9
Inherent and residual risk - Example
Likelihood
Im p
a c
t
Low High
Inherent riskResidual risk
Controls
Residual risk
L o
w H
ig h
Example:
A company has a warehouse that stores various types
of cheese and meats in coolers and freezers, which
are sold to restaurants and hotels.
Objective/Activity: Ensure items are stored properly
to maintain quality and shelf-life.
Risk: Coolers/Freezers may malfunction causing
items to spoil. This may lead to financial, reputational,
regulatory, … losses.
Controls:
1) Monthly maintenance contract on coolers/freezers
2) Back-up power generators are installed in case of
power outage
Inherent Risk?
Residual Risk?
10
RISK MANAGEMENT STANDARDS AND FRAMEWORKS
11
Why do organizations
formalize their risk
management frameworks?
Discussion
12
Benefits of risk management
Informed decision making
Comply with regulatory requirements
Support cost effective internal control
Stronger and more effective corporate governance
Sets the tone / culture for the business
13
Why do organisations take risk?
To increase financial returns
Gain competitive advantage
Lack of understanding / poor decision making
14
Risk Management models and standards
• COSO ERM framework
• ISO 31000:2018
• COBIT: Specialist information technology risk management
guidance published by ISACA
• Basel (Banking)
15
COSO Framework
16
ISO ERM Framework
Principles
Framework Process
17
ISO ERM Framework - Principles
18
ISO ERM Framework - Framework
19
ISO ERM Framework
20
PUTTING IT IN TO PRACTICE
21
Risk management process
Decision making
supported by
information
Business strategy
Identify risk areas
Assess risk
Implement risk
responses
Monitor controls
Assurance
Review, refine,
improve
22
Setting objectives
To understand risk, an organization should have a clear view of its objectives
Analyses
•Internal and external analyses to support objective setting
Set strategic objectives
•Set strategic objectives – organizational level
Departmental / divisional objectives
•Set tactical objectives at appropriate level of delegation / responsibility
Operational objectives
•Team / personal objectives
Alignment (between objectives at each level)
23
IDENTIFYING RISKS
24
How do organizations identify risks?
workshops horizon scanning
competitors sector / industry news peers & sharing insights
supply chain monitoring
internal processes
internal reports and indicators
regulatory news
internal audit
whistleblowing
complaints / incidents
health & safety function
external advisors
staff feedback and surveys
25
ASSESSING RISKS
26
The bow tie model
ConsequencesCauses
EVENT
Recovery measuresControl measures
Underlying
threats
Immediate
threats
Immediate
consequences
Ultimate
consequences
27
If you were to group risks, how
would you do it?
Risk categorization / risk taxonomy
28
Risk categorisation (example risk sources)
Strategic
Business Continuity
EnvironmentReputation Financial
Fraud / crime
People / Succession
Legal / regulatory /
political
Technology Reputation
Financial / Economic
29
Other ways to classify risks
External risks
New or
volatile risks
Existing or
stable risks
Internal risks
Non-routine
and emerging
external risks
Internal
change
management
risks
Routine
external risks
Routine
internal risks
30
Advantages and disadvantages of
each approach
Top down vs bottom up risk assessment
31
Risk assessment
Who should assess risks?
Top down
Bottom up
32
How would you rate
LIKELIHOOD and IMPACT
when assessing a risk?
Risk analysis
33
The response to a risk should be proportionate to the
organization’s risk appetite
RISK APPETITE AND RISK RESPONSE
34
The level of risk that is acceptable to the board or management. This may be set in relation to the organization as a whole, for different groups or risks or at an individual
risk level.
Definition of Risk Appetite
Chartered IIA
35
Risk appetite could look like this…
Likelihood
Im p
a c
t
Within Risk Appetite
Exceeding Risk Appetite
Inherent riskResidual risk
Low High
L o
w H
ig h
36
Risk appetite could look like this…
Likelihood
Im p
a c
t
Within Risk Appetite
Exceeding Risk Appetite
Inherent riskResidual risk
Low High
L o
w H
ig h
37
Appetite to take risk - Example
Classification Matrix
38
Appetite to take risk
Risk Appetite/Tolerance
39
Responses to risk
T
T
T
T
reat
ransfer
olerate
erminate
40
RESPONSIBILITIES FOR RISK MANAGEMENT AND RISK DECISIONS
41
Roles and responsibilities regarding risk management?
• Ultimate responsibility for risk management
• Define risk appetite Board of directors
• Reviewing control systems
• Receiving assurances from auditors Audit Committee
• Responsibility for risk management process and frameworkRisk Committee
• Facilitating process
• Reporting to Risk and Audit Committees
CRO / Risk Manager
42
Roles and responsibilities regarding risk management?
• Reporting to Board via audit / risk committees
• Identify risks. Monitor effectiveness
Risk Management group
• Assurance re internal controls & risk responses
• Support management in improving risk mgmt. Internal audit
• Be aware of risk
• Flag / escalate potential risks All employees
• As all employees
• Own action / responses to specific risks process Senior managers
43
Three Lines of Defence Model The three lines of defense, a model adopted by Organizations across the globe. Each of these three lines play a distinct roles within the Organization’s
wider governance framework. However, each of these three lines face challenges of alignment. Organizations face inconsistent expectations and
decentralized activities in different lines of business and coverage across the three lines of defense
44
REPORTING AND MONITORING
45
A simple risk register
46
Reporting and Monitoring – an example
Strategic Risks
Annually Board
A formal refresh by the Board
to ensure alignment with
the organisations
business plan
Quarterly Board
Receive a verbal update from the Finance and
Audit Panel
Audit Committee Discuss the number/type of primary risks identified and
review of the progress against their risk management action
plans;
Review the latest assurance reports
Senior Management Discuss changes in the number/type of all risks identified and
review of the progress against risk management action plans
in connection with all risks
Review the assurances received in connection with the
effectiveness of risk controls, in particular those classified
as Contingency i.e. where the reliance on key
controls is considered most important.
Monthly Senior Management
Discuss changes in the
number/type
of primary risks identified and
review
the progress against risk
management action plans in
connection with risks classified as
primary;
47
QUESTIONS/DISCUSSION
.
48
THANK YOU FOR
YOUR TIME AND
ATTENTION