1 / 25100%
1
APPROACH TO DEFINING RISK
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 1
1.1 RISK DEFINITION:
The definition of Risk according to the Oxford English Dictionary is as follows: 'the
chance or likelihood of harm, loss, injury or other adverse consequence', and the definition of
risk is 'exposure to harm'. In this context, risk is used to signify negative consequences.
However, taking risks can also result in positive outcomes. The third possibility is that risk is
related to the uncertainty of the outcome. Take the example of owning a motorized car. For
most people, owning a car is an opportunity to become more mobile and gain associated
benefits. However, there is uncertainty in owning a car associated with maintenance and
repair costs. Eventually, the car could be involved in an accident, so there are obviously
negative outcomes that could occur. It is also important to remember the legal obligations
associated with car ownership and the rules that must be adhered to when the car is driven on
the road.
Definitions of risk can be found from many sources, and some key definitions are
presented in Table 1.1. Alternative definitions are also provided to illustrate the broad nature
of risks that can affect an organization. The Institute of Risk Management (IRM) defines risk
as the combination of the likelihood of an event and its consequences. Consequences can
range from positive to negative. This is a widely applicable and practical definition that can be
easily applied. The international guide to risk-related definitions is ISO Guide 73, and this
defines risk as 'the effect of uncertainty on objectives'. This definition seems to assume a
certain level of knowledge about risk management and is not easy to apply in everyday life.
The meaning and application of this definition will become clearer as the reader progresses
through the book.
Earlier versions of Guide 73 (2002) also noted that effects may be positive, negative,
or deviations from expected. All three of these types of events can be associated with risk as
opportunity, hazard or uncertainty, and these relate to the motor car ownership example
outlined above. The guide notes that risks are often described by an event, a change in
2
circumstances, a consequence, or a combination of these and how they may affect the
achievement of objectives. The Institute of Internal Auditors (IIA) defines risk as the
uncertainty of an event occurring that could impact the achievement of objectives. The IIA
adds that risk is measured in terms of consequences and likelihood. Different disciplines
define the term risk in very different ways. The definition used by health and safety
professionals is that risk is a combination of likelihood and magnitude, but this may not be
sufficient for more general risk management purposes.
Given that there are many definitions available for the word risk, it is important for an
organization to choose the definition that is most suitable for its own purposes. The definition
can be as narrow or as comprehensive as the organization wishes. As a version of the
definition that Comprehensive of the word risk, the author offers the following: An event with
the ability to affect (hinder, increase or cause doubt about) the effectiveness and efficiency of
an organization's core processes. Risk in an organizational context is usually defined as
anything that can have an impact on the fulfillment of corporate objectives. However,
corporate objectives are usually not fully stated by most organizations. If objectives have been
set, they tend to be stated as internal, annual change objectives. This is especially true for
personal goals set for staff members within the organization, where the goals usually refer to
change or development, rather than the continuous or routine operation of the organization.
It is generally accepted that risk is best defined by concentrating on risk as an event, as
in the definition of risk given in ISO 31000 and the definition given by the Institute of Internal
Auditors, set out in Table 1.1. For a risk to materialize, an event must occur. Therefore,
perhaps a risk can simply be thought of as 'an unplanned event with unforeseen
consequences'. Greater clarity is likely to be brought to the risk management process if the
focus is on events. For example, consider what could disrupt a theater performance.
Events that can cause disruption include power outages, the absence of key actors, or
substantial transportation failures or road closures that delay audience arrival, as well as large
numbers of sick staff. After identifying the events that could disrupt the show, theater
management needs to decide what to do to reduce the likelihood of any of these events
causing the cancellation of the show. This analysis by theater management is an example of
risk management in practice.
1.2 TYPE RISK:
Risks may have positive or negative outcomes or may simply result in uncertainty.
Therefore, risk can be considered to be associated with opportunity or loss or the presence of
3
uncertainty for an organization. Each risk has its own characteristics that require specific
management or analysis. In this book, risks are divided into four categories:
•
compliance (or regulatory) risk;
•
hazard (or pure) risk;
•
control risk (or uncertainty);
•
opportunity (or speculative) risk.
In general, organizations will seek to minimize compliance risks, mitigate hazard risks,
manage control risks, and embrace opportunity risks. However, it is important to note that
there is no 'right' or 'wrong' division of risk. Readers will find other subdivisions in other texts
and these may be just as suitable. Perhaps, it is more common to find risk described as two
types, pure or speculative. Indeed, there is much debate about the terminology of risk
management. Whatever the theoretical discussion, the most important issue is that the
organization adopts the risk classification system best suited to its own circumstances.
There are certain risk events that can only result in negative outcomes. These risks are
these are hazard risks or pure risks, and these can be considered operational or insurable risks.
In general, organizations will have a tolerance for hazard risks, and these need to be managed
within the levels that the organization can tolerate. A good example of a hazard risk faced by
many organizations is theft. There are other risks that introduce uncertainty about the outcome
of a situation. These can be described as control risks and are often associated with project
management. In general, organizations will have an aversion to controlling risks. Uncertainty
can be associated with the benefits that the project generates, as well as uncertainty about
delivering the project on time, within budget and specification. Controlling risk management
will often be done to ensure that the outcomes of business activities are within the desired
range. The aim is to reduce the difference between anticipated and actual results.
At the same time, organizations deliberately take risks, especially market or
commercial risks, to achieve positive returns. This can be considered an opportunity or
speculative risk, and the organization will have a specific appetite for investing in such risks.
Opportunity risk deals with the relationship between risk and return. The aim is to take
actions that involve risk to achieve positive returns. The focus of opportunity risk will lead to
investment. The application of risk management tools and techniques to hazard risk
management is the best and oldest branch of risk management, and much of this text will
concentrate on hazard risk. There is a hierarchy of controls that apply to hazard risk, and these
are discussed in Chapter 16. Hazard risk is associated with potential sources of harm or
situations with the potential to negatively damage objectives and hazard risk management is
4
concerned with mitigating them potential impact. Hazard risk is the most common risk
associated with operational risk management, including occupational health and safety
programs.
Control risk is associated with unknown and unexpected events.
They are sometimes referred to as uncertainty risks and they can be very difficult to measure.
Control risks are often associated with project management and the implementation of tactics.
In these circumstances, it is known that events will occur, but the exact consequences of those
events are difficult to predict and control. Therefore, this approach is based on managing
uncertainty about the potential impact and consequences of these events.
There are two main aspects associated with opportunity risk. There are risks/hazards
associated with taking opportunities, but there are also risks associated with not taking
opportunities. Opportunity risks may or may not be physically visible, and are often financial
in nature. Although opportunity risks are taken with the intention of obtaining a positive
outcome, this is not guaranteed. Nevertheless, the overall approach is to embrace
opportunities and the associated opportunity risks. Opportunity risks for small businesses
include moving the business to a new location, acquiring new property, expanding the
business and diversifying into new products.
1.3 DESCRIPTION RISK:
To fully understand a risk, a detailed description is required so that a shared
understanding of the risk can be identified and ownership/responsibility clearly understood.
Table 1.2 lists the range of information that should be recorded to fully understand a risk. The
list of information listed in Table 1.2 is most appropriate for hazard risks and the list will need
to be modified to provide a complete picture of control or opportunity risks.
In order for the correct range of information to be collected about each risk, the
differences between compliance, hazard, control, and opportunity risks need to be clearly
understood. The examples below are intended to distinguish between the four types of risk, so
that the information required to describe each type of risk can be identified.
Various Computer Risks:
To understand the difference between compliance risks, hazards, controls, and
opportunities, an example using computers is helpful. Operating a computer system involves
meeting certain legal obligations; in particular, data protection requirements and this is a
compliance risk. Virus infection is an operational risk or hazard and there will be no benefit to
an organization suffering a virus attack on its software programs. When an organization
5
installs or upgrades a software package, control risks will be associated with the upgrade
project.
The selection of new software is also an opportunity risk, where the goal is to achieve
better results by installing new software, but it is possible that the new software will fail to
deliver all the intended functionality and the opportunity benefits will not be delivered. In
fact, failure of the functionality of the new software system can substantially damage the
organization's operations.
1.4 DEFAULT RISK LEVEL:
It is important to understand the uncontrollable level of all risks that have been
identified. This is the level of risk before any action is taken to change the likelihood or
magnitude of the risk. While there are advantages in identifying the inherent level of risk,
there are practical difficulties in identifying this with some types of risks.
Identifying the level of inherent risk makes it possible to identify the importance of
existing control measures. The IIA was previously of the view that the assessment of all risks
should begin with the identification of the inherent level of risk. Guidance from the IIA has
previously stated that: 'in risk assessment, we look at the inherent risk before considering any
controls.' While there is much debate on whether to conduct risk assessments at inherent or
current levels, the purpose of any risk assessment remains the same. This is to identify what is
believed to be the current level of risk and identify the key controls in place to ensure that the
current level is actually achieved.
Often, a risk matrix is used to show the inherent level of risk in terms of likelihood and
magnitude. The residual or current level of risk can be identified, after a control or controls
have been implemented. The effort required to reduce the risk from the inherent level to the
current level can be clearly shown on the risk matrix. Terminology varies and the inherent
level of risk is sometimes referred to as absolute risk or gross risk. Also, the current risk level
is often referred to as the residual level, net level, or managed risk level. Example in box
below this provides an example of how an inherently high-risk activity is reduced to a lower
risk level by the implementation of sensible and practical risk response options. Crossing the
Road
Crossing a busy road would be very dangerous if there were no controls in place and
more accidents would occur. When the risk is inherently dangerous, greater attention is paid to
existing control measures, as the perception of risk is much higher. Pedestrians do not cross
the road without looking and drivers are always aware that pedestrians can enter the road.
Often, other traffic calming measures are needed to reduce driver speed or increase risk
6
awareness of both drivers and pedestrians.
1.5 RISK CLASSIFICATION SYSTEM:
Risks can be classified according to the nature of risk attributes, such as the timescale
of impact, and the nature of the impact and/or likelihood of the risk. They can also be
classified according to the timescale of impact after the event occurs. The source of the risk
can also be used as a basis for classification. In this case, risks can be classified according to
their origin, such as counterparty or credit risk. A further way to classify risks is to consider
the nature of their impact. Some risks may cause financial losses to the organization, whereas
others will impact activities or infrastructure. Furthermore, risks may have an impact on the
organization's reputation, or on its status and the way it is perceived within the market.
Risks can also be classified according to the components or features of the
organization that will be affected. For example, risks can be classified according to whether
they will impact people, places, processes or products. An important consideration for
organizations when deciding on their risk classification system is to determine whether risks
will be classified according to the source of the risk, the components affected, or the
consequences of the risk materializing. Individual organizations will decide on the risk
classification system that works best for them, depending on the nature of the organization
and its activities. Also, many risk management standards and frameworks suggest specific risk
classification systems. If an organization adopts one of these standards, it will tend to follow
the recommended classification system.
The risk classification system chosen should be fully relevant to the organization in
question. There is no universal classification system that meets the requirements of all
organizations. It is possible that each risk will need to be classified in some way to clearly
understand its potential impact. However, many classification systems offer a common or
similar structure, as described in Chapter 11.
1.6 LIKELIHOOD AND MAGNITUDE OF RISK :
The likelihood and magnitude of risk is best demonstrated using a risk matrix. Risk
matrices can be produced in a variety of formats. Whichever format is used for the risk
matrix, it is an invaluable tool for risk management practitioners. The basic style of a risk
matrix plots the likelihood of an event against its magnitude or impact if the event
materializes. Figure 1.1 is an illustration of a simple risk matrix, also referred to as a risk map
or heat map. It is a commonly used method of illustrating the likelihood of a risk and the
magnitude (or severity) of the event should the risk materialize. The use of a risk matrix to
7
illustrate the likelihood and magnitude of risks is a fundamentally important risk management
tool. The risk matrix can be used to plot the nature of individual risks, so that the organization
can decide if the risk is acceptable and fits the risk appetite and/or risk capacity of the
organization.
Throughout this book, a standardized format for presenting the risk matrix has been
adopted.
The horizontal axis is used to represent likelihood. The term likelihood is used rather than
frequency, as the word frequency implies that the event will definitely occur and the risk
matrix records how often this event occurs. Likelihood is a broader word that includes
frequency, but also refers to the possibility of an unlikely event occurring. However, in the
risk management literature, the word 'probability' will often be used to describe the likelihood
of a risk occurring.
The vertical axis is used to indicate magnitude in Figure 1.1. The word magnitude is
used rather than severity, so the same style of risk matrix can be used to describe compliance,
hazard, control, and opportunity risks. Severity implies that the event is undesirable and,
therefore, associated with compliance and hazard risks. The magnitude of the risk can be
thought of as its gross or inherent level before controls are applied. Figure 1.1 plots likelihood
against the magnitude of an event. However, the more important consideration for risk
managers is not the magnitude of the event, but the impact of the event and the consequences
that follow. For example, a large fire may occur that destroys the warehouse of a distribution
and logistics company. While the magnitude of the event may be large, if adequate insurance
is in place, the impact in terms of financial costs to the company may be minimal, and if the
company has made plans to cope with such an event, the consequences to the overall business
may be much less than expected.
The magnitude of an event can be thought of as the level to which the event is
attached and the impact can be thought of as the level to which the risk is managed. Since the
impact (and associated consequences) of an event is usually more important than its
magnitude (or severity), each risk matrix used in the rest of this book will plot impact against
likelihood, rather than magnitude against likelihood.
The risk matrix is used throughout this book to provide a visual representation of risk.
It can also be used to indicate possible risk control mechanisms that can be implemented. The
risk matrix can also be used to record inherent, current (or residual) and target risk levels.
Shading or color coding is often used on the risk matrix to provide a visual representation of
the importance of each risk being considered. As the risk moves to the upper right corner of
the risk matrix, the risk becomes more likely and has a greater impact. Therefore, the risk
8
becomes more important and quick and effective risk control actions need to be taken.
IMPACT OF RISK ON THE ORGANIZATION
2.1 LEVEL OF RISK:
Following the events in the world financial system during 2008, all organizations took
a greater interest in risk and risk management. It is increasingly understood that explicit and
structured risk management brings benefits. By taking a proactive approach to risk and risk
management, organizations will be able to achieve the following four areas of improvement:
•
Strategy, as the risks associated with different strategic options will be fully analyzed
and better strategic decisions will be reached.
•
Tactics, as consideration will be given to the selection of tactics and the risks involved
in the alternatives that may be available.
•
Operations, as events that may cause disruptions will be identified in advance and
actions taken to reduce the likelihood of such events occurring, limit the damage caused
by such events and bear the costs of such events.
•
Compliance will be enhanced as risks associated with failure to achieve compliance
with laws and customer obligations will be recognized.
It is no longer acceptable for organizations to find themselves in a position where unforeseen
events cause financial loss, disruption to normal operations, reputational damage and loss of
market presence. Stakeholders now expect that organizations will take full account of risks
that could lead to disruptions in operations, delays in project delivery, or failure to execute
strategies. The exposure presented by an individual risk can be defined in terms of the
likelihood of the risk materializing and the impact of the risk when it does materialize. As the
risk exposure increases, the likelihood of impact will also increase. Guide 73 refers to this
measurement of likelihood and impact as the current or residual 'risk level'. This risk level
should be compared to the organization's risk attitude and risk appetite for that type of risk.
Risk appetite is sometimes described as a set of risk criteria.
Throughout this book, the term 'major' is used to indicate the size of the event that has
or may occur. The term 'impact' is used to specify how the event affects the organization's
finances, operations, reputation and/or markets (FIRMs). The use of this terminology is also
consistent with the use of impact in business continuity planning evaluations. It is a measure
of risk at the current level. The term 'consequence' is used in this book to indicate the extent to
which the event results in a failure to achieve effective and efficient strategy, tactics,
9
operations, and compliance (STOC).
Injuries to Key Players:
Sports clubs want to reduce the chances of key players missing out due to injury.
However, key players can get injured and clubs need to consider the impact of such an event
before it happens. If the injury is serious, the player may be out for a long time. There is likely
to be a substantial impact, which will be most obvious on the pitch where the team's success is
likely to be reduced. However, other consequences can also occur and these can include loss
of revenue from the sale of jerseys and other merchandise with the player's name and number.
Arrangements to mitigate the potential loss of revenue should also be considered.
2.2 RISK IMPACT HAZARD:
The risk of harm undermines the objective, and the degree of impact of that risk is a
measure of its significance. Risk management has the longest history and earliest origin in
hazard risk management. Hazard risk management is closely related to insurable risk
management. Remember that hazard (or pure) risk can only have negative outcomes. Hazard
risk management deals with issues such as health and safety in the workplace, fire prevention,
avoiding property damage and the consequences of defective products. Hazard risks can cause
disruption to normal operations, as well as result in increased costs and bad publicity
associated with disruptive events.
The risk of harm is related to business dependencies, including IT and other
supporting services. There is an increasing reliance on the IT infrastructure of most
organizations and IT systems can be disrupted by computer breakdowns or fires in server
rooms, as well as virus infections and deliberate hacking or computer attacks. Theft and fraud
can also be a significant hazard risk for many organizations. This is especially true for
organizations that handle cash or manage a large number of financial transactions. Relevant
techniques to avoid theft and fraud include adequate security procedures, separation of
financial duties, and authorization and delegation procedures, as well as pre-employment
checks of staff.
It is worth reflecting on the terminology, as this is very important in relation to the risk
of harm, should an event occur. If a hazard risk materializes, it may be of a very large
magnitude, such as the destruction of an organization's main distribution warehouse. An event
of this magnitude would impact the organization in terms of potential financial costs,
infrastructure destruction, reputational damage, and inability to function in the marketplace.
Magnitude represents the gross or inherent level of risk.
10
However, the impact of the event will be reduced due to the controls in place. Impact
represents the net, residual or current level of risk. These controls reduce the financial impact,
the extent of infrastructure damage, as well as controls designed to protect reputation and
market activity. But, also important to the organization are the consequences of a large
warehouse fire. These consequences relate to the effects that a fire may have on the strategy,
tactics, operations, and compliance activities within the organization. It is possible that a
major fire will cause financial losses that significant covered by insurance, so this major event
had little impact on the organization's finances. Effective crisis management and business
continuity will ensure that the consequences of this major fire from the customer's perspective
will be well managed so that the customer does not need to realize that there has been a major
fire. Finally, the importance of compliance risk should not be underestimated.
Compliance risk can be substantial for many organizations, especially highly regulated
business sectors. In some cases, compliance with mandatory requirements, represents a
'license to operate' and failure to achieve the level of compliance activities required by the
relevant regulator can have a significant impact on the organization's reputation and
substantial consequences for routine business activities.
2.3 RISK LINKAGE:
While most standard definitions of risk refer to risks inherent to the company's
objectives, Figure 2.1 provides an illustration of options for risk attachment. Risks are shown
in the diagram as risks capable of affecting key dependencies that deliver the organization's
core processes. Company objectives and stakeholder expectations help define the
organization's core processes. These core processes are key components of the existing nature
and future enhancements of the business model and can relate to operations, corporate tactics
and strategy, and compliance activities, as discussed further in Chapter 19.
The intent of Figure 2.1 is to show that significant risks can be associated with
organizational features other than corporate objectives. Significant risks can be identified by
considering the organization's key dependencies, corporate objectives and/or stakeholder
expectations, as well as by analysis of the organization's core processes. For example,
Northern Rock's failure occurred because the wholesale money market, on which the bank
depends, ceased to function. Another way to look at the concept of risk attachment is to
consider that the features shown in Figure 2.1 offer alternative starting points for conducting
risk assessments.
For example, a risk assessment can be conducted by asking 'what do our stakeholders
expect from us?' and 'what risks could affect the fulfillment of those stakeholder
11
expectations?' In light of the recent financial crisis, banks and other financial institutions set
operational and strategic objectives. By analyzing these objectives and identifying risks that
could prevent their achievement, risk management contributes to the achievement of high-risk
objectives that ultimately lead to organizational failure. This example illustrates that attaching
risks to attributes other than objectives is not only possible but may be desirable in these
circumstances.
It is clear that risks are greater under circumstances of change. Therefore, linking risks
to change objectives is not unreasonable, but the analysis of individual objectives in turn may
not lead to strong risk recognition/identification. After all, business objectives are usually
stated at too high a level for successful risk implementation.
To be useful to the organization, corporate objectives should be presented as complete
statements of the organization's short, medium and long-term goals. Internal, annual change
objectives are usually inadequate, as they may fail to fully identify the operational (or
efficiency), change (or competition), and strategic (or leadership) requirements of the
organization. The most important disadvantage associated with an 'objectives-based' approach
to risk and risk management is the danger of considering risks outside the context that gave
rise to them. Risks that are analyzed in a way that is divorced from the situation that gave rise
to them will not be capable of rigorous and informed evaluation. It can be argued that a more
robust analysis can be achieved when a 'dependency-based' approach to risk management is
adopted.
It is still the case that many organizations continue to use corporate objectives analysis
as a means to identify risks, as several benefits do arise from this approach. For example,
using this 'goal-driven' approach facilitates the analysis of risks in relation to positive and
uncertain aspects of possible events, as well as facilitating the analysis of negative and
compliance aspects. If the decision is taken to link risks to organizational objectives, it is
important that these objectives have been fully and completely developed. Not only do
objectives need to be challenged to ensure that they are full and complete, but the assumptions
that support the objectives should also receive careful and critical attention.
The core processes are discussed in Chapter 19 and can be considered as high-level
processes that are drives the organization. In the sports club example, one of the key processes
is the operational process of 'delivering successful outcomes on the pitch'. Risks may be
inherent to this core process, as well as inherent to key objectives and/or dependencies. Core
processes can be classified as strategic, tactical, operational and compliance (STOC). In all
cases, the core processes must be effective and efficient. Mature (or sophisticated) risk
management activities can then be designed to improve the effectiveness and efficiency of the
12
core processes. Although risk can be attached to other features of the organization, the
standard approach is to attach risk to corporate objectives. One standard definition of risk is
that a risk is something that can affect (weaken, enhance or cast doubt on) the achievement of
a company's objectives. This is a useful definition, but it does not provide the only starting
point for identifying significant risks. The attachment of risk to key dependencies and,
especially, stakeholder expectations is becoming more common. The importance of
stakeholders and their expectations is discussed in more detail in Chapter 29. Using key
dependencies to identify risks can be an easy exercise. The organization needs to ask what
features or components of the organization and its external context are key to success. This
will result in identifying the strengths, weaknesses, opportunities and threats facing the
organization. This is often referred to as a SWOT analysis. Having identified the key
dependencies, as set out in Table 13.1, the organization can then consider the risks that will
impact these dependencies. This approach is discussed in more detail with practical examples
of risks presented in Table 13.1 and Table 15.2.
2.4 RISK AND REWARD :
Another feature of risk and risk management is that many risks are taken by
organizations to achieve rewards. Figure 2.2 illustrates the relationship between the level of
risk and the size of the anticipated reward. A business will launch a new product because it
believes that greater profits are available from the successful marketing of the product. In
launching the new product, the organization will place resources at risk because it has decided
that a certain amount of risk-taking is appropriate. The value at risk represents the
organization's risk appetite with respect to the activity undertaken.
When an organization places value on risk in this way, it must
does so with full knowledge of the risk exposures and must be satisfied that the risk exposures
are within the organization's appetite. More importantly, it must ensure that it has sufficient
resources to cover the risk exposure. In other words, the risk exposure must be quantified, the
willingness to take on that level of risk must be confirmed, and the organization's capacity to
withstand foreseeable adverse consequences must be clearly established. Not all business
activities will offer the same return for the same level of risk. Start-up operations are usually
high risk and the expected initial return may be low. Figure 2.2 shows the possible risk versus
reward development for a new organization or new product. Activities will start in the lower
right corner as initial operations, which are high risk and low return.
As the business develops, it will likely move to a higher rate of return for the same
level of risk. This is the growth phase for a business or product. As the investment matures,
13
the rewards may remain high, but the risk will reduce. Finally, an organization will become
fully mature and move towards the low risk, low reward quadrant. The normal expectation in
a highly mature market is that the organization or product will go into decline.
The particular risks that an organization faces need to be identified by the management
or organization. Appropriate risk management techniques then need to be applied to the risks
that have been identified. The nature of these risk responses and the nature of their impact are
discussed in Part Four of this book. The above discussion on risks and rewards applies to
opportunity risks. However, it should always be the case that risk management efforts result in
rewards. In the case of hazard risk, the likely reward for increased risk management efforts
will be fewer disruptive events. In the case of project risk, the reward for increased risk
management effort is that the project is more likely to be completed on time, within budget,
and to specification/quality.
For opportunity risk, the risk versus reward analysis should result in fewer failed new
products and higher profit rates or (at worst) lower loss rates for all new activities or new
products. In all cases, the profit or improved service level is the reward for taking the risk.
The concept of risk versus reward analysis in relation to strategic risk is discussed in more
detail in Figure 15.2.
Risk Versus Reward:
In the Formula 1 Grand Prix, the Ferrari team decided to send a driver on wet weather
tires, before the rain actually started. Wet weather tires wear out very quickly in dry
conditions and make the car much slower. If it had rained immediately, this would have been
a very good decision. In fact, it didn't rain for four or five laps, by which time the driver had
been overtaken by most of the other drivers and his wet weather tires were damaged in dry
conditions. He had to return to the pits to get a new set of tires better suited to the race
conditions. In this case, a high-risk strategy is adopted in anticipation of significant rewards.
However, the desired reward is not achieved and a significant loss occurs.
2.5 ATTITUDE TOWARDS RISK :
Different organizations will have different attitudes towards risk. Some organizations
may be considered risk-averse, while others will be aggressive towards risk. To some extent,
an organization's attitude towards risk will depend on the sector and the nature and maturity of
the market in which it operates, as well as the attitude of individual board members. Risk
cannot be considered outside the context that gave rise to it. It may appear that an
organization is taking a risk, when in fact, the board has decided that there is an opportunity
14
that should not be missed. However, the fact that the opportunity carries a high risk may not
have been fully considered.
One of the key contributions of successful risk management is to ensure that
seemingly high-risk strategic decisions are made with all available information. Increased
robustness of decision-making activities is one of the key benefits of risk management.
Attitude to risk is a complex subject and is closely related to an organization's risk appetite,
but they are not the same. Risk attitude indicates the organization's long-term view of risk and
risk appetite indicates the short-term willingness to take risks. This is similar to the difference
between a person's long-term or established attitude towards the food they eat and their
appetite at any given moment. Other key factors that will determine an organization's attitude
towards risk include its stage in the maturity cycle, as shown in Figure 2.2. For organizations
that are in the start-up phase, a more aggressive attitude towards risk is required than for
organizations enjoying growth or mature organizations in mature markets. Where an
organization is operating in a mature market and experiencing a downturn, the attitude
towards risk will be much more risk-averse.
Since the attitude towards risk should be different when an organization is a start-up
operation than a mature organization, it is often said that certain top-tier entrepreneurs are
very good at start-up entrepreneurship but not as successful at running a mature business.
Different attitudes towards risk are required at different parts of the business maturity cycle
shown in Figure 2.2. The referendum in the UK on continued membership of the European
Union (EU) in June 2016 resulted in a vote in favor of the UK's exit (Brexit). The UK
government had to activate procedures so that UK exit from the EU. The text box below
provides an outline of the most commonly discussed options available to the UK government.
Overall, the challenge for the UK government is to ensure the continued success of the UK
economy based on Brexit strategies and tactics that will ensure the continued resilience of the
UK.
Brexit: What Departure Options Are There for the UK
Key benefits for businesses arising from EU membership include:
•
the existence of a single market: no tariffs or other trade barriers;
•
freedom to provide services and freedom of establishment;
•
A 'passport' that allows financial services to be traded across the EU;
•
visa-free migration of people within the EU;
•
access to EU free trade agreements with 53 countries around the world. Following the
Brexit vote, the UK government must now decide which agreements to keep. Broadly
15
speaking, there are three models that the UK could aim for. The Norway model
Norway is a member of the European Economic Area, but not the EU. It has full
access to the single market, but must adopt EU standards and regulations and cannot impose
immigration restrictions. Also, Norway must contribute to the EU budget.
Swiss model:
Switzerland has had some success in establishing a two-way deal with the EU, which
essentially allows it to access certain parts of the European market in exchange for accepting
EU legislation in relevant areas as well as making contributions to the EU budget.
Canadian Model:
Canada recently (November 2016) ratified the most far-reaching trade deal with
Europe ever made, and it is possible that the UK could aim to replicate this kind of
relationship. Such an agreement may not permit the continued passporting of financial
services. All of these models struggle to reconcile the central issue of regulatory control.
Using these three models as a basis, the UK must now evaluate how Brexit will create
business risks and opportunities.
2.6 RISKS AND TRIGGERS:
Risk is sometimes defined as the uncertainty of an outcome. This is a somewhat
technical, yet useful definition, and it is especially applicable to control risk management.
Control risks are the most difficult to identify and define, but are often associated with
projects. The overall goal of a project is to deliver the desired results on time, within budget
and specification, quality or performance. For example, when a building is being constructed,
the nature of the ground conditions may not always be known in detail. As construction work
progresses, more information will become available about the nature of the conditions. This
information may be positive news that the soil is stronger than expected and less foundation
work is required. Alternatively, it may be found that the soil is contaminated or weaker than
expected or that there are other potentially adverse circumstances, such as archaeological
remains being found.
Given this uncertainty, these risks should be considered as control risks and overall
project management should take into account the uncertainties associated with these different
types of risks. It would be unrealistic for the project manager to assume that only adverse
aspects of the ground conditions will be found. Similarly, it would be unwise for the project
16
manager to assume that conditions will be better than expected, simply because he or she
wants them to be.
Because control risks cause uncertainty, it can be assumed that organizations will have
an aversion to them. Perhaps, the real aversion is to the potential variability in the results that
then needs to be managed. A certain degree of deviation from the project plan can be
tolerated, but it should not be too great. Tolerance in relation to controlling risk can be
thought of as having the same meaning as in the manufacture of engineering components,
where the components must be of a certain size, within acceptable tolerance limits.
Tools to represent the risk management process so that it becomes more accessible to
managers and other stakeholders associated with risk management activities continue to
evolve. One tool for representing risk management activities that has been recently developed
is the bow-tie. The bow-tie as a representation of the risk management process is used several
times throughout this book. Figure 2.3 shows a simple representation of a bow-tie that applies
to events that may cause disruption to normal efficient operations.
The left side of the bow tie represents a specific hazard source and will indicate the
classification system used by the organization for risk sources. In Figure 2.3, the risk sources
used are high-level strategic, tactical, operational, and compliance (STOC) risk sources. The
right side of the bow tie defines the impact if the event risk occurs, and Figure 2.3 uses the
high-level components of financial, infrastructure, reputational, and market (FIRM) impacts
of risk materialization. In the center of the bow tie is the risk event. Table 3.2 shows the
categories of disruptions that can affect an organization, and the same categories of people,
places, processes and products are used here. The purpose of using the bow tie illustration is
to demonstrate the risk classification system used by the organization and the various
potential impacts if the risk materializes. Controls can be put in place to prevent events from
occurring and these can be represented by the vertical lines on the left side of the bow tie. In
the same way, recovery controls can be shown on the right side of the bow tie.
The bow tie representation of the risk management process can be used in many ways,
including the representation of opportunity risk. In addition, the bow tie can be used to
illustrate the different types of controls available to the organization and these are discussed in
more detail in Chapter 13 on loss control.
The use of bow ties has become widespread, especially in the public sector. The box
below provides a practical application of the bow tie to identify prevention and response
controls associated with fires in residential kitchens.
Risk Management and the Butterfly Tie:
17
There are various risk analysis techniques available. The most popular method for
analyzing risk is using a bow tie. A bow tie is a simple way to analyze risk to gain a better
understanding. The first stage is to place the risk description into the center box. The cause of
the risk then needs to be noted along with preventative controls to stop the risk occurring. The
impact of the risk is also considered. This allows the identification of response controls to
reduce the impact of the risk should it occur.
TYPES OF RISK
3.1 IMPACT TIMESCALE RISK:
Risks can be classified in many ways. Hazard risks can be divided into many types of
risks, including risks to property, risks to people and risks to business continuity. There are
various formal risk classification systems and these are considered in Chapter 11. While not
necessarily considered a formal risk classification system, this section considers the value of
classifying risks according to the timeframe of risk impact. The classification of risks as long,
medium and short-term impact is a very useful way to analyze the risk exposure of an
organization. These risks will be related to the strategy, tactics and operations of the
organization, respectively. In this context, risks can be considered to be related to events,
changes in circumstances, actions or decisions.
In general, long-term risks will have an impact several years, possibly up to five years,
after the event has occurred or a decision has been made. Therefore, long-term risks relate to
strategic decisions. When a decision is made to launch a new product, the results of that
decision (and the success of the product itself) may not be fully visible for some time.
Medium-term risks have an impact some time after the event occurs or the decision is made,
and usually this will happen about a year later. Mid-term risks are often associated with
projects or work programs. For example, if a new computer software system is to be installed,
then the choice of computer system is a long-term or strategic decision. However, the decision
regarding the project to implement the new software would be a medium-term decision with
accompanying medium-term risks.
Short-term risks have an impact as soon as the event occurs. Workplace accidents,
traffic accidents, fire and theft are all short-term risks that have a direct impact and immediate
consequences as soon as the event occurs. These short-term risks cause immediate disruption
to normal efficient operations and are probably the easiest types of risks to identify and
manage or mitigate. Insurable risks are often short-term risks, although the exact timing and
18
magnitude/impact of the insured event is uncertain. In other words, insurance is designed to
provide protection against risks that have immediate consequences. In the case of insurable
risks, the nature and consequences of the event can be understood, but the timing of the event
cannot be predicted. In fact, whether the event will occur at all is unknown at the time the
insurance policy is taken out.
For example, consider the operation of a new computer software system in more
detail. The organization will install new software in anticipation of greater efficiency and
functionality. The decision to install new software and the choice of software involves
opportunity risk. The installation will require a project, and certain risks will be involved. The
risks associated with the project are control risk. Once the new software is installed, it will be
exposed to the risk of danger. It may not provide all the necessary functions and the software
may be exposed to various risks and virus infections. This is the risk of harm associated with
this new software system.
An increasingly important consideration for organizations is what would be the trigger
mechanism that causes a risk to materialize. It is possible for an organization to face a number
of serious risks and many of these may be catastrophic if they materialize. The challenge for
management is then based on recognizing the circumstances under which one or more
significant risk events may be triggered. The question of what would trigger such an event
requires consideration as much as the source of the risk and the nature of that event should it
occur. The box below considers the events that triggered Northern Rock's failure.
Triggering the Great Crisis:
In September 2007, Northern Rock - a bank formed by the conversion of the Northern
Rock Building Society to banking status in 1997 - discovered that a liquidity crisis had
resulted in customers queuing up to withdraw their savings. This was the first 'run' on a UK
bank by depositors for over 150 years. The immediate trigger for the crisis was the drying up
of liquidity in the global institutional debt market - known as the 'wholesale' market -
following an increase in mortgage defaults in the United States. These defaults were
concentrated in 'sub-prime' mortgages - home loans to borrowers with poor credit quality.
Northern Rock has been building its mortgage portfolio very quickly. At
simultaneously it became more and more dependent on the wholesale market for finance,
rather than personal savers. With liquidity drying up in the wholesale market, Northern Rock's
business model began to unravel. All this happened despite the fact that there was no evidence
that the credit quality of Northern Rock's assets - its mortgages and loans - was in question.
19
3.2 FOUR TYPES OF RISK:
Chapter 1 states that risks can be divided into four categories and definitions of the
four types of risks are also given in Appendix B. They are:
•
compliance risk;
•
risk of harm;
•
controlling risk;
•
opportunity risk.
A common language of risk is required throughout the organization if the contribution of risk
management is to be maximized. The use of a common language will also enable the
organization to develop an agreed risk perception and attitude to risk. Part of developing this
common language and risk perception is to agree on a risk classification system or set of such
systems.
For example, consider people reviewing their financial position and the risks they
currently face regarding finances. Perhaps a key financial dependency relates to achieving
adequate income and managing expenses. The review should include an analysis of risks to
employment security and pension arrangements, as well as property holdings and other
investments. This part of the analysis will provide information on the risks to income and the
nature of those risks (opportunity risks).
As a practical example of the nature of compliance, hazard, control and opportunity risk,
Table
3.1 Consider the risks associated with owning a car. In this case, compliance risk relates to the
legal obligations associated with owning and driving a car. Hazard risk relates to events that
are undesirable to the owner. Uncertainty is the known costs involved, but these can vary.
Finally, opportunities are the benefits that car ownership offers.
Regarding expenditure, the review will consider spending patterns to determine
whether cost-cutting is necessary (harm risk). It will also consider leisure activities, including
vacation arrangements and hobbies, and there will be some uncertainty regarding the spending
and costs of these activities (control risk). Hazard risks are risks that can only hinder the
achievement of the company's mission. Typically, these are the types of risks or hazards that
can be insured against, and would be including fires, storms, floods, injuries, and so on. The
discipline of risk management has strong origins in the control and mitigation of hazard risks.
Normal efficient operations can be disrupted by loss, damage, destruction, theft, and other
threats associated with various dependencies. Table 3.2 provides examples of disruptions
caused by people, places, processes, and products (4Ps). These dependencies can also be a
20
source of risk and the 4Ps can be considered as an example of a risk classification system.
Control risks are risks that cast doubt on the ability to achieve the organization's
mission. Internal financial control protocols are a good example of a response to control risk.
If control protocols are removed, there is no way to be sure what will happen. Control risk is
the most difficult type of risk to explain, but Chapter 31 on project risk management will help
with understanding. Control risks are associated with uncertainty, and examples include
potential failure to achieve legal compliance and losses caused by fraud. They usually depend
on the successful management of people and the implementation of effective control
protocols. While most organizations ensure that control risks are carefully managed, they
remain potentially significant.
Opportunity risks are risks that are (usually) deliberately sought or embraced by the
organization. These risks arise as the organization seeks to improve mission accomplishment,
although they may hinder the organization if the outcome is adverse. This is the type of risk
that is most critical to the future long-term success of any organization. Many organizations
are willing to invest in high-risk business strategies in anticipation of high profits or returns.
These organizations can be considered to have a great appetite for opportunity investment.
Often, the same organization will have the opposite approach to hazard risk and have little
hazard tolerance. This may be appropriate, as the organization's attitude may not want hazard-
related risks to consume organizational resources when it places so much value on the risk of
investing in opportunities.
In addition to hazard, control, and opportunity risks, further compliance risk categories
may require separate consideration. For highly regulated industries, such as energy, finance,
gambling, and transportation, compliance issues are particularly important. Due to the special
nature of compliance risks, they are often considered a separate risk category and are often
managed or minimized differently. Many organizations want to ensure full compliance with
all rules and regulations and have no risks in this category. This may be the case for
compliance risks, but almost certainly will not be the case for hazard, control, and opportunity
risks. Further consideration of compliance risks is included in Chapter 19, as part of the
discussion of strategic, tactical, operational and compliance (STOC) risks.
3.3 EMBRACING RISK OPPORTUNITIES:
Some risks are taken intentionally by organizations to achieve their mission. These
risks are often market or commercial risks that have been taken in the hope of achieving
positive returns. These opportunity risks may be referred to as commercial, speculative, or
business. Opportunity risks are the types of risks that have the potential to enhance (although
21
they can also hinder) the achievement of the organization's mission. These risks are those
associated with embracing business opportunities.
All organizations have an appetite for seizing opportunities and are willing to invest in
them. There will always be a desire for organizations to have effective and efficient
operations, tactics and strategies. Opportunity risk is usually associated with the development
of new or changed strategies, although opportunities can also arise from improving the
efficiency of operations and implementing change initiatives. Each organization needs to
decide what desire it has to capture new opportunities, and the appropriate level of
investment. For example, an organization may realize that there is a requirement in the market
for a new product that its expertise will enable it to develop and supply.
However, if the organization does not have the resources to develop a new product, it
may not be able to implement that strategy and it would be unwise to embark on a potentially
high-risk course of action. It will be the responsibility of the company's management to decide
whether they have the appetite to seize the perceived opportunity. Just because an
organization has that appetite, it does not mean that it is the right thing to do. Therefore,
corporate boards should be aware of the fact that, while they may have the desire to seize the
opportunity, the organization may not have the risk capacity to support the action.
Opportunity management is an approach that seeks to maximize
benefits from taking entrepreneurial risks. Organizations will have an appetite for investing in
opportunity risk. There is a clear link between opportunity management and strategic
planning. The desire is to maximize the likelihood of significant positive outcomes from
investments in business opportunities. The example below, related to personal lifestyle
decisions, considers risk factors by classifying them as controllable and uncontrollable. While
the example relates to personal health risk factors, consideration of whether or not business
risks are within the control of the organization is an important component of successful
business risk management.
Risk Factors for Heart Disease:
Controllable risk factors for heart disease and stroke are those that can be changed
through diet, physical activity, and not using tobacco. These risk factors are different from
uncontrollable ones, such as age, gender, race, or genetic traits. Having one or more
uncontrollable risk factors does not mean one will have a heart attack or stroke; however, with
proper attention to controllable risk factors, one can reduce the impact of those risk factors
that cannot be controlled or changed.
Controllable risk factors for heart disease or stroke include high blood pressure, high
22
blood cholesterol, type-2 diabetes and obesity. Healthy lifestyle habits, such as developing
good eating habits, increasing physical activity and not using tobacco, are effective steps in
preventing and improving controllable risk factors.
3.4 MANAGING RISK UNCERTAINTY:
When undertaking projects and implementing change, organizations must accept a
degree of uncertainty. Uncertainty or control risk is an inevitable part of project
implementation. Contingency funds to anticipate the unexpected need to be part of the project
budget, as well as unexpected time built into the project schedule. When looking to develop
appropriate responses to control risks, organizations must make the necessary resources
available to identify controls, implement controls and respond to the consequences of any
control risks that materialize.
Controlling risk and the appropriate response depend on the level of uncertainty and
the nature of the risk. Uncertainty is the deviation from a desired or expected outcome. When
an organization undertakes a project, such as a process improvement, the project must be
delivered on time, within budget and to specification. Also, the upgrade must deliver the
required benefits. Deviations from the anticipated project benefits are uncertainties that can
only be accepted within a certain range.
Control management is the basis of the risk management approach adopted by internal
auditors and accountants. The risk management requirements of the UK corporate governance
code (as at September 2016) concentrate on internal control with little reference to risk
assessment. Control management is concerned with reducing the uncertainty associated with
significant risks and reducing the variability of outcomes. There is a danger if organizations
become overly concerned with control management. Organizations should not become
obsessed with control risk, as it is sometimes suggested that too much focus on internal
control and control management suppresses entrepreneurial efforts.
3.5 REDUCING THE RISK OF HARM:
As discussed in Chapters 1 and 2, organizations face exposure to various risks. These
risks will be hazard risks, control risks and opportunity risks. Organizations need to tolerate
exposure to hazard risks, accept exposure to control risks and invest in opportunity risks. In
terms of health and safety risks, it is generally accepted that organizations should be intolerant
of these and should take all appropriate measures to eliminate them. In practice, this is not
possible and organizations will minimize safety risks to the lowest level that is cost-effective
and compliant with the law.
23
For example, an automatic braking system installed on a train to stop it from passing
through a red light is technically feasible. However, it may be an unreasonable investment for
the train operating company. The consequences of a train passing through a red light may be
considered the risk exposure or hazard tolerance of the organization, but the cost of
introducing an automatic braking system may be considered very high. A less emotive
example relates to theft. Most organizations will experience low-level petty theft and this may
be tolerated. For example, a business based in an office environment will experience some
theft of stationery, including paper, envelopes and pens. The cost of eliminating these petty
thefts may be so great that it becomes cost-effective for the organization to accept that these
losses will occur. The approach to in-store theft may be very different in different retail
sectors, as illustrated by the examples below.
Store Safety Standards:
An example can be seen in the operation of a security-conscious jewelry store.
Customers are allowed to enter the store one by one. They are captured on CCTV as they wait
to enter. Items are stored securely, and customers are invited to request to see specific items
under the suspicious gaze of shop assistants. Of course, some customers are put off, but the
stores suffer from negligible levels of shoplifting all the same.
Compare this to a supermarket, where there are no barriers to entry and customers are
allowed to handle all the goods. There are CCTVs monitoring the shops, and there are likely
to be shop detectives on patrol - but the purpose of the security is to deter rather than prevent
shoplifting. Shoplifting does occur, but at rates that are acceptable to the shopkeeper.
Conversely, few potential customers are put off visiting a store because of such actions.
The range of hazard risks that can affect the organization needs to be identified.
Hazard risks can result in unplanned disruptions to the organization. Disruptive events cause
inefficiency and should be avoided, unless they are part of, for example, planned maintenance
or testing of emergency procedures. The desired state in relation to hazard risk management is
that there should be no unplanned disruptions or inefficiencies from any of the reasons shown
in Table 3.2. Table 3.2 provides a list of events that can lead to unplanned disruptions or
inefficiencies. These events are divided into categories, such as people, places, processes and
products. For each hazard risk category, the organization needs to evaluate the types of
incidents that can occur, the source of those incidents and their possible impact on normal
efficient operations.
Hazard management is traditionally an approach adopted by the insurance world.
Organizations will have a tolerance for hazard risk. The approach should be based on
24
reducing the likelihood and magnitude/impact of hazard losses. Insurance is a mechanism to
limit the cost of financial loss. Also, some hazard risks will be associated with regulatory
requirements and can be considered as compliance risks. Most organizations will try to
minimize compliance risk.
When an organization considers the level of insurance it will buy, the organization's
hazard tolerance needs to be fully analyzed. The organization may be willing to accept a
certain number of motor accidents as a financial cost that will be funded from the
organization's day-to-day profits and losses. This will only be tolerated to a certain degree and
the organization needs to determine what level is acceptable. Insurance should then be
purchased to cover losses that may exceed that level.
3.6 MINIMIZE COMPLIANCE RISK:
All organizations will be aware of the various compliance requirements they must
meet. These compliance requirements vary greatly between business sectors, and many
sectors are highly regulated with their own specific regulators for that industry or sector. For
example, organizations operating in the gambling or gaming industry have significant
regulatory requirements that are implemented in most countries around the world. Failure to
comply with regulatory requirements can result in the 'license to operate' being revoked by the
regulator. If the regulator takes this extreme measure, the organization could eventually cease
to exist.
All organizations that handle financial transactions are required to introduce
procedures to reduce the likelihood of money laundering activities being carried out. Banks
and other organizations that handle large amounts of cash need to introduce money laundering
arrangements and, in many cases, dedicated money laundering senior executives. In the
insurance industry, compliance issues are significant and can be complex. Where insurance
policies are issued in one country to protect assets and/or cover liabilities in another country,
compliance issues present particular difficulties.
Failure to comply with all obligations may result in insurance claims
not be paid or, in the extreme, be illegal in certain countries, if unauthorized types of
insurance or illegal insurance policies have been issued. For organizations that do not have a
regulator dedicated to that industry or business sector, there are still various regulatory
requirements that must be met. In particular, health requirements and Safety exists in most
countries of the world, and this places an obligation on organizations to ensure the health,
safety and welfare of employees and others who may be affected by their work activities.
Typically, these safety requirements will not only apply to workplaces that are under
25
the direct control of the organization, but will also cover the health and safety of employees
working in other countries. Also, detailed road safety obligations will apply to organizations
that own vehicles, especially if they are involved in the transport of people or dangerous
goods. In general, organizations will work to ensure full compliance with all applicable rules
and regulations and, in doing so, minimize compliance risks.
In many cases, a dedicated team of specialized risk professionals will be employed and
these are mainly related to health and safety, money laundering, and security arrangements. It
is important for organizations to recognize their compliance risks and include consideration of
these risks in their risk management activities. It is also important to ensure that the different
areas of risk management expertise within the company cooperate with each other, so that an
organized and/or coordinated approach to compliance can be achieved.
Students also viewed