STRATEGY EXECUTION
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
1
This guidebook discusses in detail the Return Driven Strategy framework and the related Strategic Risk Management framework and applications in Strategic Risk Assessment and Strategic Risk Management. These frameworks are detailed below are useful tools in executing and ongoing Strategic Risk Assessment process. The Return Driven Strategy Framework1 The Return Driven Strategy framework is based on extensive research of the financial performance data of more than 15,000 companies for more than 30 years, along with detailed study of the pattern of strategic activities in those that met stringent criteria for sustainable high performance. These companies showed superior performance for 10 consecutive years or more in 3 key performance measures: Return on Investment, growth, and relative total shareholder returns. Cash flow ROI was at least twice that of the corporate average for at least 10 consecutive years, growth rates in investments made in the business exceeded average market growth, and total shareholder returns outperformed the market for at least 10 years. Only about one hundred companies that are currently publicly traded met this set of Return Driven Strategy criteria. This framework can be very useful as it provides a tool for understanding in detail the specific strategies being used by an organization to achieve its business objectives. Without such a structure, it may be very difficult for an auditor to understand an organization’s strategies or to know which areas to probe during a discussion with management. The Return Driven Strategy framework includes eleven tenets that represent the path to ethically create wealth. (The tenets are shown in the eleven rectangular boxes in figure 3.1.2) Tenets are arranged in a pyramid from top to bottom in order of impact on long-term financial results and valuations. Each level in the pyramid represents a type of tenet. These levels are:
• The Commitment Tenet • Goal Tenets • Competency Tenets • Supporting Tenets
Finally, the pyramid rests on three foundations, which summarize key factors of business strategy that apply to each of the eleven tenets. These foundations are (1) genuine assets, (2) vigilance to forces of change, and (3) disciplined performance measurement and valuation.
1 This section is adapted from Frigo, Mark L., and Joel Litman. DRIVEN: Business Strategy, Human Actions and the Creation of Wealth. Strategy & Execution, 2008 and Frigo, Mark L. and Richard J. Anderson, Strategic Risk Management: A Primer for Directors and Management Teams, (2011), Chapter 3. 2 Frigo, Mark L., and Joel Litman. DRIVEN: Business Strategy, Human Actions and the Creation of Wealth. Strategy & Execution, 2008
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
2
Exhibit 1 Return Driven Strategy Framework
The Commitment Tenet 1. Ethically Maximize Wealth The first tenet, which appears at the top of the Return Driven Strategy framework, focuses on the commitment of companies to create the most value with their resources and to do so within the ethical parameters of its constituents and communities. More important than any other tenet, management must:
• Be committed and focused on maximizing long-term shareholder value (achieving long-term superior and sustainable ROI) as a primary objective
• Manage the drivers of wealth (accumulated value) creation—return on investment and strategic growth
• Always function within the ethical boundaries and parameters set by its constituents and the communities in which the business operates (or hopes to operate in the future)
This tenet also includes the controls and governance necessary to conduct business within the ethical parameters of constituents and communities. Of critical importance is the focus of this tenet on the long-term not the short-term. This tenet combines the ethics of the organization with the long-term sustainability of the organization.
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
3
This tenet also applies for auditors in not-for-profit or mission driven organizations. For those organizations, this tenet becomes “Ethically Create Mission Based Value.” Again, the focus is on the ethical culture of the organization as it strives to achieve its mission in a long-term and sustainable manner. Key Questions to ask about Ethically Maximizing Value
• How does the organization communicate its ethical values? • How does the organization assess or evaluate its ethical culture? • Are the compensation and incentive plans of the organization aligned with the ethical,
long-term maximization of value? The Goal Tenets 2. Fulfill Otherwise Unmet Customer Needs and 3. Target Appropriate Customer Groups The two goal tenets are the second level from the top of the Return Driven Strategy pyramid. The goal tenets focus on the path to maximizing shareholder value by creating value for customers— lots of customers. This is done by:
• Targeting economically profitable customer groups • Targeting customer groups with growth opportunities • Identifying otherwise unmet needs of customers • Creating (innovating) and delivering offerings that fulfill those needs without close
substitute • Being the dominant fulfiller of that customer group’s needs
The Goal Tenets focus attention on customer needs and customer groups (markets) where the organization has the unique and valuable capabilities and resources, or genuine assets. These tenets can help internal auditor to understand how the business creates value for its customers, which in turn, drives financial results. Key Questions about the Goal Tenets
• Does management understand and articulate exactly the unmet needs that their strategy is intended to address?
• Are the unmet needs being addressed specifically or are they commodities that can be addressed by many organizations?
• Does management understand and articulate the specific customer segments that they are targeting?
• Is the organization’s strategy based on serving a commodity need or a specific and unique unmet need?
• On a 1-10 scale how otherwise unmet is customer need fulfilled by the company’s offerings
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
4
The Competency Tenets 4. Deliver Offerings, 5. Innovate Offerings, and 6. Brand Offerings The competency tenets, which are the third level from the top of the pyramid, focus on the offerings that the organization provides for the customer. The business must effectively deliver need-answering offerings, while balancing convenience and cost to the customer. Given scarce resources of time and money, a customer’s needs are never really fulfilled—meanwhile, profitable offerings quickly attract substitutes. Therefore, continuous innovation (changing of offerings) is necessary. Finally, the consumer’s mind must be branded with an indelible connection between an explicit understanding of need and the offering that uniquely fulfills it. Branding is defined as making the connection between your offering and the customer’s unmet need, in the mind and heart of the customer. The executability of plans must be tackled at the outset of strategy evaluation. The competency tenets help Management to understand how internal processes drive customer performance, which in turn drives financial performance. These tenets also reinforce the importance and value of the brand and the need for processes and practices to be in place to protect the brand. Key Questions about the Competency Tenets
• How well is the organization delivering its offerings? • What are the key operating processes that ensure the quality and timing of the delivery
of products? • What steps does the organization take to protect its brand? • Are there appropriate legal protections and monitoring for the brand(s)?
The Supporting Tenets 7. – 11. Activities to Better Achieve the Higher Tenets of the Pyramid Five overlapping groups of activities (Tenets 7-11) serve to enhance a business’s strategy and execution (see figure 3.1, the third level from the top of the pyramid). They include to:
7. Partner deliberately 8. Map and redesign processes 9. Engage employees and others 10. Balance focus and options 11. Communicate holistically
Great performance is evident when these activities are focused on driving innovation, operational superiority, and branding in order to achieve the Goal Tenets and maximize long- term shareholder value. Poor performance follows firms that engage in these Supporting Tenets indiscriminately.
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
5
The supporting tenets can help Management understand the strategic activities that support the competency tenets. While internal audit needs to consider carefully each of the supporting tenets, auditors may find it beneficial to focus specifically on two of the tenets; partner deliberately and engage employees and others. These two tenets lend themselves to audit coverage and represent tenets that most organizations find critical to their success. More and more organizations use partnering in the form of outsourcing, offshoring or use of third parties as critical parts of their business strategies. Similarly, the success of virtually any organization is dependent on the support and engagement of its employees. Therefore, while not ignoring the other supporting tenets, Management should consider carefully these two critical supporting tenets. Key Questions about the Supporting Tenets
• What are the critical partnering and third-party relationships that the organization is dependent on?
• How does the organization ensure quality and compliance performance of its third parties?
• Are there any single points of failure in the supply chain? • What steps does the organization take to ensure the engagement and support of its
employees? • Does the organization undertake surveys or culture studies to understand the views and
work environment of its employees? Three Foundations of Business Strategy As shown in figure 3.1, the three foundations of business strategy are (1) genuine assets, (2) vigilance to forces of change, and (3) disciplined performance measurement and valuation. The following section explains these foundations and provide questions management should ask. 1. Genuine Assets As the eleven tenets are the verbs of strategy, the genuine assets are the nouns. Over time, activities are copied by competitors and followed by price competition, and returns are reduced. By leveraging un-copiable assets (which are assets that can’t be copied, such as proprietary customer information, unique capabilities, patents, leading economies of scale and scope, distribution chain monopolies, etc.), a business can create un-substitutable offerings (which are offerings for which the customer cannot find a substitute). With that comes the potential for pricing premiums, higher margins and/or asset efficiency, and above-average returns and valuation. Coupled with activities described in the Eleven Tenets, genuine assets are the building blocks of a sustainable competitive advantage. Key Questions about the Organization’s Genuine Assets • What are the most important genuine assets of the organization? • How well are they leveraged in the strategy on 1-10 scale?
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
6
• What are the missing genuine assets that would allow the organization to create more value? • Which genuine assets are at risk and how can they be protected?
2. Vigilance to Forces of Change The Greek letter and symbol for change in mathematics (delta, Δ) forms the backdrop of the pyramid. Because business environments are so dynamic, management must leverage opportunities and avoid or manage threats arising in pursuit of each of the Tenets. Major areas for vigilance include:
• Government, legal, and regulatory changes • Demographic and cultural shifts and trends • Scientific and technological breakthroughs • Industry and competition
This foundation relates to the risks and opportunities in forces of change. Given the dynamic nature of change and risk in today’s business environment, this foundation is critical for the long- term success of the organization. It also aligns closely with the Management’ need to monitor and keep up with changes to the business and the environment. Changes identified because of this foundation should drive the internal auditor to consider needed changes to the audit risk assessment, audit plan, staff competencies, and audit approaches. For example, the shift to a digital economy will require more technology and data mining and analytics skills. Key Questions regarding Vigilance to Forces of Change
• What forces of change will create the most risk for the organization? • What forces of change will create the most opportunities for the organization? • What processes are in place to monitor the forces of change? • Does the organization have or need an enterprise risk management function to
effectively implement this foundation?
3. Disciplined Performance Measurement and Valuation This is the bedrock foundation of the framework. Performance measures must be aligned with the tenets and foundations of the Return Driven Strategy. Performance measures should also be highly aligned with superior long-term return on investment. Moreover, performance measures should include some key risk indicators for effective strategic risk management. Questions About Disciplined Performance Measurement and Valuation
• Does the organization have the right metrics that are aligned with long-term wealth creation?
• Does the organization follow a disciplined process for monitoring its key performance metrics?
• Are appropriate modeling and/or data analytics being utilized to support this process? • Do the compensation and incentive plans align with long-term wealth creation?
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
7
Strategic Risk Management Framework3 The Strategic Risk Management framework developed is derived from the Return Driven Strategy framework. It displays the high-level strategic risks inherent in each of the tenets and foundations of the strategy framework. Using the two frameworks, Management can first breakdown the business strategy of their organization into their critical components using the Return Driven Strategy framework and then assess the strategic risks associated with each strategy component by considering the respective strategic risk in the Strategic Risk Management framework. This process links the assessment of strategic risks directly with the organization’s strategy and can help focus the resulting audit coverage on certain risks that are typically not included in more traditional risk assessments. The Strategic Risk Management Framework contains 11 strategic risk categories that correspond to the 11 tenets of the strategy framework. These risk categories build on top of 9 other risk categories that correspond to the three foundations of the strategy framework. The additional risk categories are necessary because of the breadth of the three foundations of the strategy framework. For example, the foundation tenet of Vigilance to the Forces of Change encompasses sustainability risk, financial markets risks, regulatory risk and the broader category of emerging events risk. Important to Remember: Risk Elements Are Interrelated While the framework presents each risk area as separate and distinct, as with the Return Driven Strategy framework, there are clear relationships and linkages between various risk categories. For example, while Partnering is a separate risk area, that risk can also arise in other areas such as Operations. Several of the risk categories also highlight types of strategic risks that are taking on increased levels of exposure because of certain macro global trends such as off-shoring and demographic shifts. Finally, recent events, such as large losses in value as a result of certain behaviors driven by short-term incentive plans, are raising new perspective on some of the more traditional strategic risks such as Employee Engagement and Compensation. Overall, the Strategic Risk Management Framework affords Management a useful tool to assist them to consider and focus on the specific strategic risk categories that may be impacting their organizations.
3 This section is adapted from Frigo, Mark L. and Richard J. Anderson, Strategic Risk Management: A Primer for Directors and Management Teams, (2011)
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
8
Exhibit 2 Strategic Risk Management Framework
Each of the strategic risk categories is now covered in more detail along with key questions that Management may find useful. Again, this discussion and questions are intended to be an initial framework for auditors that they should consider and tailor to more specifically address their needs and their organization. Ethically Maximize Wealth 1-Investor Risk: The risk of loss of investors or shareholder value because the organization does not have an ethical culture or control practices to protect and create shareholder value. Studies in support of the Return Driven Strategy have clearly reflected that major ethical lapses cause significant loss of shareholder value. Closely related to this risk is the risk to value if the reputation of the organization suffers a significant negative event. The negative event may be the result of an ethical lapse or the result of a failure in another area that affects the organization’s overall value. In either case, the organization suffers from the lack of a culture that reinforces the importance of ethical behavior and controls and responsiveness to protect the organizations value and its reputation. The importance of developing and maintaining an ethical culture as the bedrock for protecting the organization’s value cannot be overemphasized. As part of that culture, companies must
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
9
consider and have in place response plans to respond quickly and decisively to events that threaten their ethics and reputation. In this regard, scenario analysis may be a very useful tool in thinking through the specific events that could trigger this type of risk and the related responses. In assessing its exposure to this type of strategic risk, the organization must look objectively at itself and consider whether, in reality, it has established and nurtured an ethical culture and not just the words. The landscape is littered with failed organizations (think Enron) that had written and published glowing statements on their ethics but really did not come close to living the words. Key Questions for Management:
- Have tangible steps been taken to establish and communicate the expected culture? - Does the organization have a Code of Conduct? - Is ongoing training conducted to reinforce the ethical culture? - Are surveys or assessments conducted to test the strength of the culture? - Has the organization conducted scenario analysis to identify potential risk events? - Are compensation and incentives aligned with protecting and creating shareholder value
and conducting business within the ethical parameters of its constituents? - Are corporate governance and controls aligned with protecting and creating shareholder
value and conducting business within the ethical parameters of its constituents?
Second Tier – The Goal Tenets 2-Customer Risk: The risk that the organization loses its customers because it does not have processes in place to continually research and understand the current and future unmet needs of the customers. This risk manifests itself in organizations that are described as “losing touch with their customers.” The risk results from the lack of formal processes and data on the current and future needs of the customers. It may also be apparent in organizations that are unable to precisely define who their customers even are. In situations where a new strategy is being deployed or new acquisitions considered, the strategic risk assessment must include an articulation of who the customers are and their unmet needs that would be addressed by the strategy or acquisition. The fit of those new customers and needs with the organization’s existing customers and needs is also a strategic question and risk. Understanding why customers choose the offerings of a company is critical to managing customer risk and its related innovation risk as described in a recent Harvard Business Review article.4 In many organizations, technology is deployed as a major enabler to mitigate and mange this risk. Organizations also realize that this is a very dynamic risk and managing it requires constant 4 See Christensen, Clayton, Taddy Hall, Karen Dillon and David Duncan. “Know Your Customers’ “Jobs to Be Done”” Harvard Business Review (September 2016)
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
10
attention and ongoing processes. Accordingly, management probing this risk may find it fruitful to inquire as the processes and supporting technology and data analysis that the organization is using. In some organizations, this risk may also be an example of a strategic risk to the organization that may be outside the scope and expertise of the internal audit group. If that is the case, the audit committee should be informed of that fact. Key Questions for Management:
- Does the organization have a clear understanding of who its customers are and why they do business with the organization?
- Are processes in place to capture and analyze customer data? - Does the organization have a view of what the current and future unmet needs of its
customer are? - Is customer/need assessment a required part of any new strategic initiative? - To what extent do the company’s offerings fulfill otherwise unmet customer needs vs.
commoditized needs? - Are customer needs being fulfilled by the organization increasing, decreasing or stable? - Is there disruptive innovation (e.g., Uber to the taxi industry, iPod to the music industry,
etc.) on the horizon that will change the demand for the products and the competitive landscape?
3-Market Risk: The risk of loss of customers or failure to attract customers because of the inability to identify appropriate customer groups or the inability to detect significant changes in the size or growth rates of customer groups. One of the major global trends affecting organization today is very dynamic changes in the demographics of their customer bases. For example, in the US, we are seeing the aging of the baby boomers coupled with the growth of Latino and Asian populations. On a global scale, many organizations are seeing increased customer populations in countries such as India and China. The risk evident here is the inability to retain or attract customers as these demographic shifts occur. Strategies that are focused solely at existing customers may present significant exposure to this risk. Clearly, managing this risk requires an external focus and data to monitor and get a picture of developing demographic shifts. As with the related customer segment risk discussed above, the assessment and coverage of this risk may be outside the scope and expertise of the internal audit function and not covered by the audit plan. Key Questions for Management:
- Does the organization have an updated demographic profile of its customer base? - Are processes in place to periodically update the demographic profile? - Is someone in the organization responsible for monitoring demographic data and shifts? - Does the organization segment customer groups with similar customer needs? - Are the number of customers served by the organization increasing, decreasing or stable?
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
11
- Does the organization monitor the factors that affect the ability of customers to buy your offerings?
Third Tier – The Competency Tenets 4-Operations Risk: The risk that the organization’s processes, operations and technology are inadequate to efficiently execute the strategy and deliver its offerings. Often, this risk is monitored on a real-time basis through metrics such as error or processing rates or systems metrics such as up-time. While these monitoring activities are important, they may not address the strategic aspects of this risk. For example, a new business strategy may anticipate significant growth in customers but not have sufficient operating support to deliver to those new customers. In some cases, investments in new strategies are focused at marketing or acquiring customers without sufficient investment in operational support. In tough economic times, cost-cutting initiatives can raise the profile of this risk. For example, consolidating locations or suppliers may give rise to increased exposure to this risk. Other areas where this risk has taken strategic implications are current trends in outsourcing and off-shoring. An organization may find itself exposed to significant operations for a third-party risk as a result of these initiatives. The assessing and coverage of operational issues and risk is typically a strong point of internal audit. Accordingly, in strategic risk assessments, the ability of internal audit to understand the organization’s exposure to this risk on both strategic and tactical levels is critical. Both levels require detailed assessment, assurance and consulting efforts from internal audit. Key Questions for Management:
- Is someone in the organization responsible for monitoring Operations Risk? - Are operating metrics and processes in place to monitor the quality and efficiency of
operations? - Has the organization assessed its operational exposure to third-parties? - Are trigger points in place to identify potential problems as they develop? - Are appropriate contingency and backup plans in place with key operations and suppliers?
5-Innovation Risk: The risk of loss of customers or market share because of the inability to innovate offerings to better fulfill customer needs. Clearly the inability to innovate offerings is a major strategic risk. However, monitoring and mitigating this risk may be more complicated than one might think. Truly innovated offerings and services are end products. Accordingly, simply measuring R&D spending is not sufficient to address this risk. The organization must determine what innovating really means to them in end products and establish monitoring processes accordingly. This does not mean that the
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
12
organization will not have some mistakes or failures as it innovates offerings. However, the organization must have processes in place to measure and monitor its overall success with innovation. Key Questions for Management:
- How does the organization define its innovation activities? - Does the organization have a culture that promotes and nurtures innovation? - Who in the organization is responsible to monitor and report on innovation activities? - Are processes in place to monitor and report on innovation activities? - How does the organization monitor the innovation activities of its competition? - Does innovation focus on changing the entirety of the offerings to better fulfill customers’
unmet needs? - Does the organization have the capabilities to co-create offerings with customers and
suppliers? 6-Brand / Reputation Risk: The risk to shareholder value because of the inability to correctly brand the offerings or to protect the brand and the organization’s reputation once established from negative internal or external events. We view brand risk as more closely related to an organization’s offerings and customers, while reputation risk encompasses the overall organization. Often, an organization realizes that its brand or brands are significant assets and the risk is the loss of value to that asset because of a negative event. Organizations also realize that exposure to this risk is not just because of a negative event, often the risk relates to the timeliness of actions in response to an event that threatens the brand. The Tylenol case is often cited as an example where timely action protected a valuable brand at Johnson & Johnson. Reputation risk also has an extremely wide impact in terms of the stakeholders it can affect. Beyond investor stakeholders, loss of reputation can impact the organization’s employees, its Board, suppliers, customers, and virtually any other stakeholders of the organization. Brand risk is another category where scenario analysis may be a useful tool for management as part of this risk assessment. Brainstorming sessions with management to consider possible events that could negatively impact the brand may be useful to both assess the risk and also help management to develop action plans to respond to brand threats. Scenario brainstorming should also be very broad and consider both internal and external events. Here again, the organization may incur risk through strategic initiatives such as outsourcing or off-shoring of its suppliers or manufacturers and Management should consider broadly the potential implications of this risk and its related risk tenets. Key Questions for Management:
- Who in the organization is responsible for monitoring and protecting the brand? - Are effective processes in place to ensure product quality?
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
13
- Are effective processes in place to ensure products meet regulatory requirements? - If products are safety-related, does the organization have effective processes in place to
handle product recalls accurately and promptly? - Is an executive responsible for reputation risk? - Are actions plans in place to respond to events that threaten the reputation? - Has the organization assessed the exposure to its brand from third parties? - Have scenario analyses been conducted to identify possible threats to the brand? - Are action plans in place to respond to events that threaten the brand? - Does the organization continually monitor its reputation and brand? - Does the organization monitor social media to keep abreast of discussion related to its
reputation and brand? - How well does the brand of the organization make the connection between its offerings
and its customers’ otherwise unmet needs?
Fourth Tier – The Supporting Tenets 7-Partnering Risk: The risk to the value of the organization arising from inappropriate, ineffective or unethical activities by its partners. As previously noted in some of the tenets above, many organizations are facing increased risks because of various partnering activities being conducted with third parties. While the concept of partnering is not new, certain partnering activities are now being undertaken as part of an organization’s core business strategies and accordingly have a much higher level of strategic importance. Examples of these include outsourcing information technology, off-shoring of major processing and accounting activities, outsourcing manufacturing or large joint ventures. The risks associated with certain of these activities have become more evident lately. For example, the well-publicized problems that certain US companies have encountered as a result of the use of lead paint by their suppliers in China. Often, these strategic partnering activities are being undertaken with the objectives of reducing the organization’s cost structures by moving processes to either lower-cost locations or having the process performed by third parties who specialize in the activities as a core competence. When seeking these cost advantages, organizations must also consider carefully the risk implications of the partnering initiative and how those risks will be monitored and mitigated. These types of risk may include both the activities of the third party, as well as the dependencies the organization places on that third party. Clearly, a lower-cost structure that significantly increases an organization’s risk profile is not desirable. Contingency planning is a critical aspect of mitigating this risk. As an organization’s dependency on any third-party increases, so does its needs to have contingency and backup plans in the event that third party is unable to perform up to the expectations or contractual requirements of the
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
14
arrangement. Management should consider carefully the contingency plans and related testing that management should be performing related to this risk category. Timing is also a critical factor in addressing this area of strategic risk. The risks, monitoring and mitigation activities must be considered and addressed during the negotiating phase of a relationship. Once the relationship is formalized in a contact, it may be very difficult to go back and require the third party to perform needed monitoring or reporting. Management should be involved during the contract negotiations to see that they either have audit rights or that an appropriate third party will provide the necessary assurances to the organization. This is an excellent example of why strategic risk management needs to start with the planning process. Key Questions for Management:
- Has the organization identified all its key strategic partners? - Are appropriate performance monitoring and measurement processes in place to
monitor the performance of third parties? - Do contracts appropriately address the performance criteria including unethical activities
and controls, and regulatory compliance that are required from third parties? - Are contingency plans in place for each strategic partner? - Is an assessment of Partnering Risk required for any proposed initiative with a new
strategic partner? - Does the risk assessment include all key risks, financial, operational, compliance,
reputational, strategic, regulatory, etc.? 8-Value Chain Risk: The risk to the organization from the failure or inability to perform by any key element of its value chain. The failure of any key element of its value chain is a clear strategic risk. For example, the failure of a key supplier in the supply chain can expose the organization to a significant loss of business. Or, poor or even negligent or illegal activities by a key supplier can also have a huge negative impact on the organization. Another element of this risk can be inefficiencies in the value chain. Today’s global marketplace, with its ability to shift processes to lower-cost environments, has placed an increased premium on cost effectiveness and accordingly, the risk associated with it. Mitigating this risk also involves maintaining an appropriate balance with other tenets such that the quest for cost efficiencies does not simply trump all other tenets. Cost effective processes must still be able to achieve the organization’s strategic goals and tenets. Management must also consider both the internal and external elements of the value chain including not only its core operating processes but also support functions such as, finance, control or legal.
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
15
Key Questions for Management:
- Are appropriate processes in place to monitor performance across the organization’s value chain and supply chain?
- Are appropriate backup plans and redundancies in place for key elements of the value chain?
- Does the assessment process for cost-cutting initiatives include assessment of the impacts on other strategy tenets?
- Does the assessment process cover the total cost of doing business, including foreign exchange, tax, regulatory and environmental compliance considerations?
- Is there an ongoing, continuous improvement process to ensure that operational processes are reviewed to increase their efficiency?
9-Employee Engagement Risk: The risk that the organization is unable to execute the strategy because of the inability to attract, retain, compensate or otherwise appropriately engage its employees. Human resources risk is another area where an acknowledged, traditional risk category has taken on much more strategic implications in recent times. The ability to attract and retain talent has long been a critical factor and risk in any organization’s ability to execute its strategy. While this continues to be the case, two additional areas are presenting increased risk to organizations related to engaging their employees. The first risk is the inability to attract or manage a more diverse workforce in the face of changing demographics. In the US, as the baby boomer population moves into its retirement phase, organizations will increasingly be unable to rely on their traditional methods of attracting talent. They will be faced with the challenge of attracting and then managing a more diverse and mobile workforce in order to fill their human capital needs. There simply will not be an adequate supply of traditional talent or talent with the necessary skills for the digital economy. A related trend is the move to more global operating models. This necessitates that organizations develop the ability to attract and manage global workforces. This can create strategic risks in that the labor pool in some countries may not have the risk and control orientation and education that is expected. A second area of employee engagement risk that has become more evident is the risk imbedded in management compensation and incentive plans. Recent events in some companies have highlighted the risks that some incentive plans may not be aligned with the organization’s long- term goals. Further, some plans may drive activity that presents significant strategic risk to the organization, as evidenced by the huge loss in value at certain financial services companies where executives were highly compensated for creating and trading highly complex derivative instruments. Management may find it beneficial to utilize third-party human resource or
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
16
compensation experts to assist them in providing the needed audit coverage of this critical risk area. Key Questions for Management:
- Is an executive of the organization responsible for overseeing Employee Engagement Risk?
- Are appropriate processes in place to monitor this risk? - Are benefit and compensation plans reviewed for consistency with the organization’s
strategic goals and objectives? - Are the role and activities of the board Compensation Committee appropriate and
supporting the alignment and disclosure of the organization’s executive compensation programs?
- Do the employees understand the objectives and strategies of the organization and how they contribute to achieving them?
- Does the organization have the right incentives to create alignment between employee engagement and the organizations’ objectives and strategies?
- Does the organization provide growth and development opportunities for its employees that enhance employee engagement toward achievement of the organizations’ objectives and strategies?
10-Planning Risk: The risk that the organization is unable to appropriately respond to unanticipated changes impacting its objectives and strategies because of the lack of flexibility or options in its planning processes. Put simply, this risk emphasizes the point that objectives and strategies need both monitoring and “Plan B’s.” Monitoring is addressed more specifically as one of the foundations. The focus with Planning Risk, is the need for alternatives or contingency plans to address unanticipated changes impacting the objectives and strategies. As generals are aware that battles are rarely fought exactly as they had planned them, so too, businesses need to consider the risk that their strategies will not be implemented exactly as planned. Mitigating this risk requires a pro-active not a reactive approach. Businesses need to consider and think through options before events place them in a situation where they do not have luxury to think but are in a critical reactive stance. Planning Risk is also focused on options and responses, not necessarily trying to anticipate every event that could impact the strategy. It is really focused on having alternatives and options. Conversely, the absence of any “Plan B” options or contingency plans may be evidence that this risk has not been considered and addressed. For Management, the key concern related to this risk is whether the organization has a formal, well-developed, and robust strategic planning process. That process is critical to the organization and should provide a basis for audit coverage of the process. Of particular importance to the
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
17
internal auditor is whether that planning process includes the documentation of key planning elements including the assumptions that the strategies are based on, the risks related to those strategies and clear performance measures that can be used to determine objectively whether the strategies are achieving their desired objectives or not. Key Questions for Management:
- Does the organization have a documented, formal strategic planning process? - Does the strategic planning process include the articulation of the basic assumptions that
underlie the strategies being considered? - Does the strategic planning process include the identification and documentation of the
strategic risks related to any strategic plan or initiative? - Does the organization’s planning process include a structured process to monitor and
report on the results of the plan compared to expected outcomes documented at the inception of the plan?
- Does the organization’s strategic planning process require the presentation and inclusion of options and alternatives?
- Does the strategic planning process include periodic assessments to identify and respond to unanticipated events?
- Are strategic plans or initiatives assessed for alignment with the organization’s overall business objectives?
- Does the organization have new options in the pipeline to support future growth? 11-Communication Risk: The risk that the organization is unable to design or execute two-way communications strategies with its stakeholders, employees and customers that build a common understanding of the organization’s culture, strategy and offerings. Common understanding of expected culture, strategy and offerings is another necessary ingredient for successful strategy. Particularly in the area of culture, communications and understanding is critical. Communications also plays a key role in strategy implementation, as it is one of the principal change management techniques used in implementing significant changes. Management and the directors may have a clear understanding of the culture and strategies they are implementing, but without effective two-way communications, the risk increases that they will not be successful as employees, customers and others may not understand and align around the expected strategies. The organization also needs to consider external communications to customers and other external stakeholders. Customers in particular need to understand how new strategies will be responsive to their needs. Other external stakeholders such as regulators or rating agencies also need clear and effective communications of the organization’s strategies and culture. Key Questions for Management:
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
18
- Are appropriate ongoing communications conducted to communicate and reinforce the organization’s objectives, strategies and culture?
- Do communications processes support effective two-way communications? - Are communications processes broad enough and include appropriate external
stakeholders? - Does the organization test or assess the effectiveness of its communication processes? - Does the organization have a consistent internal and external message which reflects its
core values and strategies? - Does the organization monitor when and how it is being mentioned in the press and
Internet, including social networking platforms and Blogs? - Does the organization proactively communicate its brand and core values? - Are investor relations activities aligned with drivers of strategic valuation (return on
invested capital; capital efficient profitable growth)? The Foundations Genuine Assets and Unique Capabilities A-Genuine Assets and Unique Capabilities Risk: The risk of the loss of value because of the inability to create, protect and grow the organization’s genuine assets and unique capabilities. Organizations typically are concerned about the risk of loss of assets, particularly through fraud. However, this concern is usually focused on financial statement assets. These may not include significant genuine assets and unique capabilities of the organization. For example, the organization may have human or technology capabilities that far exceed those of its competitors. Management and the directors need to understand the definition and strategic importance of the organization’s genuine assets. Or in the case of new strategies, what genuine assets are being developed or grown as an objective of the new strategy. Assessing this strategic risk then must start with a clear understanding of what the organization’s genuine assets are. It may be a very beneficial exercise for Management to discuss with management whether they have defined their genuine assets, as compared with its financial assets, and then consider how its genuine assets are protected and grown. Management may identify significant exposure in certain of its genuine assets that are not protected by the same level of controls as certain of its financial assets. For example, an organization may decide that it has market or customer data that are genuine assets but find that the data has a much lower level of security and protection than some of its financial data this is not as valuable. Key Questions for Management:
- Has the organization defined and inventoried its intangible and tangible genuine assets, including its unique capabilities?
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
19
- Has the organization assessed the adequacy of its controls to protect its genuine assets, including its unique capabilities?
- Has the organization identified its genuine assets, including its unique capabilities to grow or create as part of its strategies?
Vigilance to Forces of Change B1-Emerging Events Risk: The exposure presented because of the inability of the organization to identify or correctly size emerging internal or external events. Recent history has witnessed a number of large-scale events that have had significant negative impacts on organization. Some of these events have been situations where their probability of occurrence would have been considered very low, however, their impacts were not only significant but, in some cases, catastrophic to the organization. This has pointed to the need for ongoing processes to identify, assess and respond promptly to emerging risks. In implementing or executing its strategy, an organization must consider more than just financial performance measures to understand the ongoing performance of its strategy. Forward-looking processes must be in place to enable it to consider change events, both internal and external, that would give rise to risks to the organization and its strategy. In particular, the processes must consider the possible impacts of external events and systemic events that are beyond the control of the organization. All of these considerations should be subjected to probing and analysis by internal audit as they assess the adequacy of management’s process to identify and manage these emerging risks. Key Questions for Management:
- Are ongoing processes in place to identify emerging risks and events? - Is someone in the organization responsible for monitoring and responding to emerging
risks? - Are policies and practices in place to encourage information and knowledge sharing
across the organization to help identify emerging risks and events? - Are executive management and directors periodically informed of emerging risks?
B2-Financial Market Risk: The risk that the organization is unable to execute its strategy because of the inability to access capital or cash. Exposure to financial market risk is a more traditional strategic risk facing organizations, particularly those dealing with financial instruments. However, here again, recent history has included systemic and in some cases, seismic events in financial markets that are unprecedented. For example, the loss of liquidity in the credit markets as banks responded to unprecedented stress in their portfolios.
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
20
While many organizations have well-developed treasury functions that are constantly monitoring this risk, an organization must consider and develop response plans to both expected and unexpected levels of this risk. For example, how would they access cash or capital if their traditional banking lines were frozen? Key Questions for Management:
- Are processes in place to effectively monitor exposure to financial market risks? - Is someone in the organization responsible for monitoring and managing Financial Market
Risk? - Are appropriate analytical tools and techniques utilized to monitor this exposure? - Are appropriate action plans in place to respond to events in the financial markets that
threaten the organization’s ability to execute its strategies? - Has the organization considered exposure to systemic market disruptions?
B3-Sustainability Risk: The risk that the organization is unable to continue to execute its strategies because of the lack of sustainable processes and operations. Sustainability may be one of the newest areas of strategic risk for many US companies. In some other parts of the world, Europe for example, sustainability has been an issue and risk for a longer time. However, in the US, sustainability is growing in importance as a key issue with various stakeholders, particularly customers. Because of its newness, this is another risk area where it may be necessary as a first step to develop a definition and view on their risk area within an organization. It may be beneficial to conduct an assessment or inventory to identify where the risk may currently present in the organization or its strategies. This knowledge may then be used to consider where, on a more forward-thinking basis, the risk may be or developing in new strategies or initiatives. Key Questions for Management:
- Has the organization assessed its exposure to corporate sustainability? - Does the organization have corporate sustainability strategic objectives? - Is someone in the organization responsible for monitoring this risk? - Is the organization effectively monitoring new developments and processes impacting
sustainability? - If the organization is reporting publicly on sustainability, are there appropriate controls in
place to ensure the consistency and accuracy of the information being reported? B4-Regulatory Risk: The risk that regulatory or legislative changes will inhibit the organization’s ability to achieve its objectives. Organizations today operate in an environment with a significant amount of regulatory and legal requirements. Further, the pace of change and the breadth of new regulations appear to be increasing. Coupled with this pace of change is the increased aggressiveness of various state,
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
21
federal and regulatory organizations in policing and litigating infractions. Accordingly, it is imperative for the organization to be vigilant for changes to regulation that can impact them and also vigilant in operating in compliance with new laws and regulations. While regulatory risk is not new to Management, the potential magnitude of possible actions and sanctions has raised this risk to the level of a strategic risk. Key Questions Management:
- Does the organization maintain a current inventory of legal and regulatory requirements? - Does the organization have a process to monitor possible new laws and regulations? - Are regulatory exposures assessed as part of any new strategic initiative? - For any operations in countries outside the organization’s home country, are there
controls and monitoring activities to ensure that legal and regulatory requirements of the other countries being monitored and complied with?
- Does the organization have a process in place to notify designated management and directors and respond appropriately to any potentially significant legal or regulatory matter?
- Does Internal Audit coordinate assurance engagements with other assurance providers to minimize gaps and duplication and ensure issues identified by various assurance providers that impact their opinions of the areas in scope are considered?
Disciplined Performance Measurement & Valuation C1- Governance Risk: The risk of loss of assets or exposure to legal or regulatory actions because of the lack of appropriate and effective governance, legal, control or risk management processes and practices. Several recent events, including major frauds, systemic risks, and the changing legal and regulatory environment have combined to raise the level of governance risk in many organizations. Investors, regulators, and other third parties, such as rating agencies, are also seeking more transparency around risk, control and governance processes. In the US, the Sarbanes-Oxley Act has raised the focus on financial controls, but recently other risk and control areas such as enterprise risk management are receiving increased attention. More specific to strategy, there is an increased focus on strategic risk management by directors, shareholders and rating agencies. Good governance practices must include the identification, monitoring and mitigation of risks embedded in business strategies or strategic initiatives. Organizations must also have sound and appropriate governance processes to enable achievement of their strategic objectives. Key Questions for Management:
- Has the organization defined its governance processes and activities? - Has the organization assessed the adequacy of its governance processes?
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
22
- What are the expectations of the key stakeholders related to internal audit’s coverage of the governance processes?
- Are processes in place to identify and respond to developing practices in corporate governance?
C2-Financial Reporting Risk: The risk of loss of value or reputation because of inaccurate or fraudulent financial reporting. Addressing financial reporting risk was the primary objective of the Sarbanes-Oxley Act. Public companies who report under the requirements of that act have been required to put processes in place to both assess and report on the adequacy of their controls over this risk. External auditors have also been required to revise their auditing processes to place increased focus on this risk. For many organizations, complying with the requirements of SOX has been a very costly and time- consuming undertaking. But, as a result of these efforts, this area of strategic risk in most public companies has received the most attention and is quite possibly in the best shape. The challenge for companies going forward is to sustain the effectiveness of these financial reporting controls as SOX compliance continues to be made more routine. For Management, addressing this risk must involve detailed discussions and close coordination with the organization’s external auditors and Controller Staff. Key Questions for Management:
- If the organization reports under the Sarbanes-Oxley Act, are management and the directors satisfied with the effectiveness and operations of the compliance efforts?
- Is there appropriate communications and coordination with the external auditors? - Have internal and external auditors jointly discussed and shared their views of the
organization’s exposure to this risk? - If SOX compliance does not apply to the organization, has management and the directors
considered how to assess and monitor financial reporting risks? - Do the directors periodically receive information from the organization’s external
auditors on their views of the organization’s controls over financial reporting? C3-Valuation Risk: The risk of loss of value through inappropriate or erroneous models and valuation techniques. Increasingly, organizations exposed to various types of valuation risks, which can present significant exposures as various types of models are being used to generate both financial information and critical management information. Typically, these include valuation and risk models for certain types of derivative financial instruments, credit rating and exposure models, loss projection models and other types of statistical models. It became apparent during the
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
23
financial crisis that in certain financial services organizations, the level of exposure presented by inappropriate or erroneous models was much higher than anyone anticipated. There are also significant exposures related to the valuation of illiquid or thinly-traded assets such as synthetic securities, certain types of securities or debt from emerging economies. It may also be an example of a type of risk where there are very few individuals in an organization who have the technical skills and knowledge to understand fully the workings of models or valuation techniques being used. Internal audit may need to consider engaging third parties for access to appropriate subject matter experts to supplement the audit team. As a starting point, some Management have found it useful to undertake an inventory of models and types of exposures that are being impacted. Here again, Management must consider risks in more than just the financial areas and think about where else critical decisions or performance assessments are being driven or impacted by mathematical models. Key Questions for Management:
- Has the organization conducted an inventory to identify all critical models and valuation tools?
- Are policies in place requiring appropriate independent validation of key models and tools?
- Have appropriate staff reviewed and approved the key assumptions in the models? - Do policies require appropriate controls over modifications and generation of new tools?
C4-Fraud Risk: The risk of loss of genuine assets because of internal or external fraud. Here again is an example of a more traditional area of risk that has taken on more operational or transaction-related risk. However, recent history has revealed a number of financial frauds of a size and magnitude that they destroyed entire entities. World Com and Enron are examples of this type of situation. As a direct result of those frauds, US public companies who are reporting in accordance with the Sarbanes-Oxley Act, must conduct a fraud risk assessment. Accordingly, fraud risk must be considered as a strategic risk with potential to impact shareholder value. Addressing this exposure should also involve detailed discussions with the organization’s external auditors who also need to consider and address the organization’s risk of financial fraud. Key Questions for Management:
- Has the organization conducted a comprehensive fraud risk assessment, or reviewed assessments conducted by its internal or external auditors?
- Are appropriate processes in place to allow employees and customers to communicate concerns about possible frauds, for example whistleblower hotlines?
- Are processes in place to ensure that investigations of suspected frauds are handled by appropriate parties?
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
24
- Is the organization in compliance with the requirements of significant legal requirements such as the UK Bribery Act, Foreign Corrupt Practices Act and the Federal Sentencing Guidelines?
Strategic Risk Examples The following examples show the relationship between the tenets of Return Driven Strategy and associated Strategic Risk Management framework. By learning and applying these two frameworks in the strategic risk assessment process, Management can add value to their organizations.
Examples of the linkage between tenets and risks Ethically maximize wealth
• Define wealth explicitly on terms of monetary goals, timetables, and acceptable risk levels
• Commit managers to wealth creation as defined, and align the entire organization’s plans and activities toward the wealth-creation goals
• Create an ethical culture and operate within the ethical boundaries of the communities served – as those communities would define, or all wealth potential is put at unnecessary risk
Investor risk Loss of investor or shareholder value because of;
• Compensation and incentive plans are not aligned with protecting and creating shareholders value
• Accounting irregularities or fraud • Unethical or illegal business
practices • Major recalls of dangerous
products • Inappropriate or illegal executive
actions
1
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
25
Examples of the linkage between tenets and risks
Fulfill otherwise unmet customer needs
• Identify – and have a process for continually identifying – exactly what needs cause customer to buy
• Identify – and have a process for continually identifying – what customers would buy if it were available, but cannot.
• Be vigilant to forces of change which affect customer needs, customer perceptions of their needs, and the ability to gather information about those needs. Adjust to these changes, even radically when necessary
Customer risk
• Loss of revenue or margin because of the inability to retain a niche market
• Loss of revenue because of the inability to anticipate niche needs
• Unsuccessful investments as a result of creating and attempting to sell offerings that the customer base does not want
• Unsuccessful investments because of inability to identify unmet needs of new customer base or fit into existing offerings
2
Examples of the linkage between tenets and risks
Partner Deliberately • Consider a wide range of potential
partnerships and be creative in developing new types of relationships that can support the competencies of the firm
• Deliberately choose partners based on an assessment of the Genuine Assets brought by each partner and how that can help the firm to build unique offerings as the competency tenets require
• Create performance measures that bring incentives to the partners that support the business strategy.
Partnering risk • Loss of revenue because of significant
failure in the supply chain by a strategic partner
• Damage to reputation and value because of ethical , legal or regulatory matters of a strategic partner
• Losses due to fraud on the part of a strategic partner
• Loss of intellectual property or proprietary processes because of theft by a strategic partner
• Issues because of accounting irregularities by a strategic partner
• Contractor challenges 3
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li
Strategic Risk Assessment Frameworks: A Guidebook for Management Teams1 Mark L. Frigo and Ricard J. Anderson 2017
(For Classroom Use Only) © Copyright Mark L. Frigo and Richard J. Anderson
26
Examples of the linkage between tenets and risks Engage Employees and Others • Realize the existence of the complete
end-to-end employee life cycle, including firm awareness and recruiting at one end and alumni or customer status at the other end of the cycle
• Create incentives, compensation plans, and other offerings throughout the entire employee life cycle that will create employee engagement toward the firm’s goals
• Create performance measures that are aligned with the achievement of the higher tenets
Employee engagement risk • Losses in revenue or opportunity
losses because of: – Inability to attract and retain talent – Inability to attract a global workforce – Inability to provide the right incentives
• Increases in expenses for hiring or for third parties because of the inability of in-house employees to execute the strategy
• Loss of investment and capital because of the lack of an adequate workforce to execute the strategy or staff growth plans.
• Loss of key employees to competitors
4
Licensed to: Kaihan Li S/N:34ed34ac143322d90093d862c8a6c21c
S/N:34ed34ac143322d90093d862c8a6c21cLicensed to: Kaihan Li