1 / 26100%
238
TRAINING AND RISK COMMUNICATION
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 10
26.1 CONSISTENT APPROACH TO RISK :
One of the main reasons for communicating risk information and providing risk
training is to ensure that a consistent response to similar risk events is always achieved. This
can only be ensured by sharing information and experience. A consistent response is required
in relation to hazard, control, and opportunity risks. When an organization has an intranet, this
is an ideal way to achieve a consistent response to risks by ensuring that appropriate
information is readily available.
In addition to consistent responses to individual risks, consistent risk protocols also
need to be established and communicated. Part of ensuring a consistent response is to identify
risks in advance and confirm the controls to be applied for those risks. This approach is
relevant to strategic, project and operational risks, and training and communication protocols
should be introduced to improve consistency of response to risks across the organization. It
should be a requirement of every organization that a risk assessment is attached to every
capital expenditure request. This risk assessment should include the risks that the project
intends to manage and the risks within the project itself. Risks within the project can affect the
ability to deliver the project on time, within budget and to specification.
The risk assessment inherent to strategic analysis is also a problem that
is essential and is part of ensuring a consistent response to risk. The production of an 'issues
manual' as a means of communicating risk across the organization and ensuring a consistent
response to risk may also be valuable. Issue manuals will identify risks, circumstances and
other events that require a response. The provision of adequate information, supervision and
training will ensure that consistent and appropriate risk management procedures are more
likely to be followed. An important consideration regarding the need for consistent responses
to risks is when new risks arise or existing risks change substantially. In these circumstances,
risk escalation may be required so that the changed circumstances can be brought to the
attention of senior management. The design and introduction of robust risk escalation
procedures is required, with appropriate training provided in these procedures.
The need for a consistent response to risk is critical in a crisis. When a disaster
239
recovery plan has been created by an organization, training for directors, managers and staff is
essential. Also, the requirements of the business continuity plan need to be communicated to
everyone who may be affected if the plan is implemented. Again, the importance of training
to ensure a consistent response to adverse circumstances is critical.
26.2 RISK TRAINING AND CULTURE RISK:
As listed in Table 24.3, organizational risk culture can be defined by leadership,
engagement, learning, accountability, and communication (LILAC). The LILAC title also
gives an indication of the components of a successful initiative to embed risk management in
the organization. The engagement, learning, accountability and communication components
of a risk-aware culture are all highly relevant to risk training and risk communication. Proper
risk management documentation will provide managers and staff with information on the
engagement required and the level of accountability the organization expects. A good level of
learning and communication can be established with adequate risk training and this will
enhance the organization's risk-aware culture.
Consider the example of a publisher facing defamation and libel risks. Companies
should prepare risk guidelines, protocols and procedures including reference to awareness
training for all staff. Comprehensive procedures for managing libel and slander risks should
reflect the level of risk exposure. The level of attention given to such risks will depend on
each magazine title and the following framework may be appropriate:
•
all journalists were given basic defamation and slander training;
•
special review procedures introduced for political office;
•
legal evaluation of each issue of the satirical magazine.
Training needs to be provided for staff in the revised procedures, and information should be
included on the company intranet site. Managers and staff should be encouraged to comment
on the new procedures, so that they can be further improved as part of a learning culture
within the company.
Risk training is an important part of learning and communication and is essential for
the engagement of managers, staff and other stakeholders. It should cover a wide range of
topics and achieve a greater understanding of all risk-related issues, as well as provide
information on the control measures in place and the important role played by staff in the
successful implementation of these controls. Risk management training is required on an
ongoing basis, but Table 26.1 provides some examples of when risk management training
may be particularly relevant and/or necessary.
240
The following partial excerpt from the 2010 risk management handbook of the United
Nations Educational, Scientific and Cultural Organization (UNESCO) is a good example of a
well-structured training program with clear training objectives:
The objectives of the risk management training are to raise basic awareness of risk
management concepts and mechanisms, to enable participants to identify and manage risks in
their own units and to strengthen project management through adequate forward planning of
potential risks.
The half-day training module on risk management introduces the definition of risk and
the purpose of risk management and discusses the steps towards effective management of
risk. The course goes beyond the provision of generic tools and extends to elements of
revisiting organizational culture, decision-making and situational awareness. By the end of the
training session, participants should be able to:
•
understand UNESCO's approach to risk management;
•
understand how risk management affects decision-making;
•
conduct risk analysis by compiling a risk profile and using a risk matrix;
•
identify risks/uncertainties to achieve a set of objectives and expected outcomes;
•
prioritize this uncertainty; and
•
deciding how to act on uncertainty.
When to Provide Safety Training?
When identifying health and safety training needs within your organization, you should:
•
take into account workers' abilities, training, knowledge and experience; and
•
ensure that the demands of the job do not exceed their ability to carry out their work
without risk to themselves and others.
Some employees may have specific training needs, for example:
•
New employees need basic induction training on how to work safely, including
arrangements for first aid, fire and evacuation.
•
People changing jobs or taking on extra responsibilities need to know about the new
health and safety implications.
•
Young employees are particularly prone to accidents and you need to pay special
attention to their needs, so their training should be a priority. It is also important that
new, inexperienced or young employees are adequately supervised.
241
•
Some people's skills may need to be updated with refresher training.
Your risk assessment should identify further specialized training needs.
26.3 INFORMATION AND COMMUNICATION RISK:
Component 7 of the US COSO ERM framework considers the importance of risk
information and communication. Risk communication begins with identifying the
stakeholders who have an interest in the particular risk being considered. Once the
stakeholders have been identified, the nature of the risk information that needs to be
communicated must be decided. Finally, the purpose of communicating risk information to
each stakeholder group must be analyzed.
Stakeholders already have a perception of risk, so risk communication should be
conducted against the background of existing perceptions. The guidelines relevant to risk
communication set out in Table 26.2 should be followed. These guidelines seek to establish
rules for communicating risk issues to various stakeholders. Obviously, these rules become
more important when communication about risks is done with external bodies. Nevertheless,
they provide a useful set of guidelines for risk communication with internal as well as external
stakeholders. Internal stakeholders have an additional reason to be provided with risk
information. There will usually be an expectation by the organization that managers and staff
will play a role in risk management in the future, whereas this may not always be the case
with external stakeholders.
The delivery of risk training should be aligned with other training activities in the
organization. As with all other types of training, the content should be consistent with job
requirements. Training on risk issues will be required in several circumstances, including
when new risks arise or existing risks have changed significantly. Training will also be
required when someone takes on a new job or assumes additional responsibilities. Also, risk
training will be important after incidents occur and new or enhanced procedures are
introduced.
An important part of risk information and communication is ensuring that there are
adequate arrangements for 'whistleblowers'. While staff members and other individuals may
gather confidential information about the organization that is not normally disclosed, there
needs to be arrangements for staff and other stakeholders to raise concerns, if they have
reasonable grounds to believe serious malpractice has occurred. The text box below provides
an excerpt from the University of Cambridge's whistleblowing policy.
242
Whistleblowing Investigation Process:
The person to whom the disclosure is made will usually consider the information and
decide whether there is a prima facie case to answer. He or she will decide whether an
investigation should be conducted and what form it should take. This will depend on the
nature of the issues raised and may:
•
internally investigated;
•
referred to an external auditor;
•
subject of independent investigation.
Following an investigation, some matters will need to be referred to relevant outside bodies,
including the police or funding councils. If the person to whom the disclosure is made decides
not to pursue the investigation, the decision will be explained as fully as possible to the
individual who raised the concern. It is then open to the individual to re-disclose either to
another person or to the chair of the audit committee.
26.4 SHARED RISK VOCABULARY:
Part of successful communication on risk issues is the development of a common risk
language. Appendix B provides the vocabulary used in this book, and refers to the definitions
used in ISO Guide 73, which provides internationally recognized terms related to risk
management. However, sometimes an organization needs to develop its own risk vocabulary,
for aspects that may be specific and unique to it. A common understanding of risk based on
the use of terminology within the organization is more important than arguments about what
terms mean to different risk management practitioners. In fact, as part of an effort to
harmonize risk management and embed risk considerations into routine operations, it may be
appropriate for risk managers to use terminology that already exists in an organization. Even
if the organization's vocabulary conflicts with a strict risk management definition,
communication will be more successful if an established vocabulary is used.
In this book, standardized vocabulary has been used to help with recognition and
explanation of concepts relevant to risk management. At times, this vocabulary conflicts with
ISO Guide 73, but has been used to aid communication and understanding. The subject of risk
vocabulary and agreed definitions can take a lot of time and effort, and compromise is usually
required. A common language and agreed definitions are important so that all parties to the
discussion have a common understanding of the terminology used. This is illustrated by the
summary in the box below.
Common Language of Risk
243
The first reason an organization needs a risk language is to support its risk culture.
Everyone in the organization has a role to play in an effective risk management process. Most
organizations have multiple layers (e.g. executives, line managers, and employees) and 'silos'
(e.g. technology, treasury, operations, quality management, and compliance). A common
language is needed to cut through the layers and break down the silos. Conversely, without a
common language, risk management teams will spend too much time resolving
communication issues at the expense of their core responsibilities.
26.5 RISK INFORMATION ON THE INTRANET:
Risk information can be made available to stakeholders in various ways. Many
organizations produce short guides and leaflets for stakeholders to communicate current risk
issues and concerns. The appropriate means of communication will vary according to the
nature of the stakeholders and the nature and complexity of the message to be communicated.
Formal risk communication means exist through which the organization must report to
financial stakeholders. When risk communication is required, a variety of communication
techniques may be used. Formal reports to stock exchanges or other financial stakeholders
may be supported by informal videos, slide presentations and/or telephone conference calls,
where appropriate.
There are often additional risk communication tools available to organizations. Many
organizations have developed intranets for use by staff and these can be used to communicate
risk to include risk and risk management information. For many large organizations, it is
common for the intranet to be used to communicate health and safety information and
business continuity plans. Information can be provided on the intranet about general risk
assessments that have been conducted and control measures that have been identified. The
intranet can also be used to communicate urgent risk information, as well as provide updates
on risk assessments, control measures and the current level of a particular risk.
An important consideration in the collection, storage, and provision of risk
information is that it should be aligned with other management information systems in the
organization. Providing risk information as a separate management information stream will
likely result in risk management activities failing to be aligned or embedded in other
activities. The danger that risk information will become irrelevant to managers in the
organization is greater when the organization has a dedicated risk management information
system (RMIS).
244
26.6 RISK MANAGEMENT INFORMATION SYSTEM (RMIS):
Distribution of risk management guidelines, protocols and procedures can be done
through a risk management information system (RMIS) software package. The RMIS can be
placed on the organization's intranet. The RMIS will also facilitate the collection and
communication of risk information, including the reporting of events by local management as
they occur. Typically, an RMIS may include a variety of information, as summarized in Table
26.3.
RMIS has been used for some time to record insurance claim details. In recent times,
the use of RMIS has become more sophisticated. It is now possible to record details of risk
exposures, risk controls and risk action plans using such software packages. For RMIS used in
connection with insurance, details of insurance policies, insurance claim procedures and
insurance claim history can all be recorded and made available to authorized individuals. Such
systems can also be used to collect risk exposure information and report accidents or other
events that may lead to insurance claims. In addition to RMIS systems that record
information, there are a number of software products that support risk management. These
include software packages that can perform various activities and analytical systems that can
perform risk analysis and dependency modeling reviews.
It is generally accepted that the implementation of RMIS software for enterprise risk
management (ERM) initiatives can be very helpful. However, a frequently encountered
drawback is that entering large amounts of risk data into a computer database can be very
time-consuming. Nevertheless, the benefits of having the data available for detailed analysis
can make the effort worthwhile.
Risk information needs to be shared throughout the organization to increase risk
awareness and ensure improved risk performance. It is almost always the case that individuals
within an organization will have the best understanding of risk, as well as detailed practical
knowledge of actions to take to mitigate risk events. Communication is also essential for
sharing information about incidents that have occurred, including lessons learned and actions
taken to ensure they are not repeated. An analysis of the advantages and disadvantages of
RMIS is presented in the box below. In general, RMIS becomes more valuable when the risks
are complex or the amount of data that needs to be recorded is large.
Risk Management Information System (RMIS):
Without more advanced RMIS technology, risk managers are limited to capturing
exposure data and company loss experience relevant to ERM initiatives, using techniques
245
such as scenario modeling and simulation. It is possible that the costs of developing a robust,
ERM-enabled RMIS will outweigh the benefits. The costs are direct and tangible; the benefits
are difficult to estimate or demonstrate. Risk managers are already struggling to explain the
value of losses prevented or financed. Even if the risk reduction is significant, it is a potential
future benefit, not a definite immediate cost reduction.
Whether risk assessment from RMIS is likely to lead to marginal benefits sufficient to
offset the costs of tracking and analyzing data depends on the risk profile of the company.
Large companies stand to gain the most from RMIS, but as the cost of the computing tools
needed to collect data and perform sophisticated modeling continues to decline, the benefits
grow for all organizations. Ultimately, RMIS can pay for itself by allowing organizations to
avoid or effectively finance one major loss that would otherwise slash a company's financial
results.
PRACTITIONER COMPETENCIES RISK
27.1 COMPETENCY FRAMEWORK:
Risk management is increasingly seen as a profession, rather than a set of activities.
For any profession, it is important that a set of competencies is established that defines the
activities that practitioners in the profession need to display. There are several styles and
formats for competency frameworks, but most are based on the stages involved in the practice
of the profession. Having identified the stages involved in the profession, the level of
competence required at various stages of seniority is then described.
It is generally accepted that there are technical or hard skills required by individuals
working in any profession, along with various people or soft skills needed to be a successful
practitioner in that profession. In short, risk practitioners need more than just technical
competencies to successfully assist organizations with the design and implementation of risk
management frameworks. Two areas of technical skills are required by risk practitioners.
First, and most obviously, the practitioner needs to have competence across a wide range of
risk management issues and activities. He or she will also need a range of business skills to
understand the external context and internal context in which the organization operates. An
understanding of the business and the development of appropriate business skills are essential
if the risk management practitioner is to successfully develop appropriate risk management
processes and support the risk management framework or internal context.
This textbook is not about developing business skills, so the focus is on
246
greater emphasis is placed on the technical risk management skills that will be required by
risk practitioners. These risk management technical skills will be closely aligned with the
stages of implementation of risk management initiatives, as listed in Appendix C. Table 27.1
provides an overview of the risk management technical skills that a successful risk
management practitioner will need.
27.2 SKILL RANGE:
The range of skills required by successful risk management practitioners includes
technical or hard skills and people, interpersonal skills or soft skills. Technical skills can be
divided into risk management technical skills and business technical skills. Risk management
technical skills can be established as a competency framework, as described in Table 27.1.
The range of business skills that will be required will vary according to the type of
organization. In general, they will include skills related to accounting, finance, legal affairs,
human resources, marketing, operations and information technology. The importance of
people skills has increased considerably as communication within and between organizations
has changed. People skills are often referred to as soft skills. Technical skills are usually
considered to be related to intellectual intelligence, while soft skills or people skills are
associated with emotional intelligence. To be successful, risk practitioners need a combination
of both types of intelligence and both sets of skills.
People benefits or 'soft' skills:
While labeling them 'soft' might make them sound less important than technical skills,
in reality people skills are essential for all businesses, and can actually mean the difference
between success and failure. Hiring staff with good people skills will mean they are more
effective when interacting with people. This is especially important if your business is largely
based on face-to-face contact with clients.
Just as technical skills can be learned and developed, so can people skills. In fact,
people skills continue to be developed throughout life, but there are a few ways you can
encourage this in your life your business. These include workshops, seminars and encouraging
staff to provide input, advice and counsel in business discussions.
In addition to technical and people skills, a successful risk manager will also
requires skills related to self-management and self-development. Typically, these will be
skills expected of all technical professionals and will often be supported by adherence to a
code of ethics or code of conduct. Self-development includes activities that enhance talent and
potential, as well as improve job satisfaction and future employability. Self-development also
247
includes the development of others, and this can include activities such as teachers, mentors,
training providers and/or professional trainers.
Table 27.2 describes the various people skills required in a business environment.
These skills can be classified as communication, relationship, analytical and management
(CRAM) skills. Technical skills can be acquired through a combination of training and
experience, but people skills are much more dependent on the personality of the individual.
Therefore, it is a greater challenge for risk practitioners to master the various people skills
required to succeed.
27.3 COMMUNICATION SKILLS:
Accurate communication of risk issues is essential. Internal communication within the
organization will be done through the risk architecture. This is a formalized risk
communication structure associated with risk control activities and information gathering for
external risk reporting purposes. For example, a road transport company may want to focus on
the efficient operation of the organization and ensure that risk management receives proper
attention.
Under these circumstances, the company may decide to introduce a number of
measurable loss control programs. The company's board has requested a report at each board
meeting on the number of road accidents, frequency of vehicle breakdowns, fuel consumption
levels and incidents reported during deliveries. These reports will allow the board to compare
the company's performance, both against competitors and against historical data for the
company itself. In this case, the board is monitoring performance, while the management of
improved risk performance remains an executive responsibility to be executed by line
management. In some organizations, risk communication may also be more informal.
Communication will take place during risk assessment workshops and risk training courses.
Communication arrangements are part of the risk culture. External risk communication needs
to take place with external stakeholders, including the media, the general public and pressure
groups.
For example, if a road haulage company wants to expand its vehicle storage depot,
there will be a need to communicate with stakeholders, as well as the local authority's
planning department. The company will need to prepare arguments that provide an evaluation
of any possible risks to the community that may increase when the depot is extended. The
public perception of what is proposed and the impact on the surroundings may not be entirely
accurate. The company therefore needs to prepare honest, open and detailed arguments that
reassure all interested parties that adequate risk control arrangements are in place.
248
The box below provides examples of risk communication related to the nuclear and
chemical industries in the United States. The lesson here is that public perceptions of risk may
not align with scientific evidence. The information presented by an organization needs to do
more than just present intellectual information. Communications must also address emotional
issues.
Risk communication development:
The formal development of risk communication as a subject began in the late 1970s
with efforts by the nuclear and chemical industries in the United States to counter widespread
public concerns about such technologies. It was believed that clear and understandable
information was all that was needed to make people see that the risks were lower than many
feared. For decades this approach has failed, and most risk communication experts say it is
inadequate. Perceptions of risk, and the resulting behavior, are not just a matter of facts but
also of our feelings, instincts and personal life circumstances. Communication that offers facts
but fails to account for the affective side of our risk perception is simply incomplete.
Risk communication is also commonly thought of as what to say in a crisis situation,
but this is inadequate. While it is true that communication in times of crisis is important in
managing public response, many examples have taught that much of the effectiveness of risk
communication during a crisis is based on what has gone before.
An important consideration in relation to communication skills is the ability to run
training courses. In particular, risk practitioners need to facilitate risk assessment workshops.
There are a number of basic skills required to run a successful workshop, but the starting point
is to establish the structure and format. In general, the key is to ensure that discussions are
well structured and all participants have the opportunity to contribute equally.
Techniques used during the workshop included the use of sticky notes to capture ideas
from delegates. These notes were then organized according to how they related to the specific
questions that had been posed. The consolidation of many ideas into a small number of
agreed-upon issues requires skill on the part of the facilitator, who needs to identify
commonalities of ideas and consolidate compatible ideas into a small number of issues or,
more specifically, identified risks.
If graphics are usually present in reports, then presenting risk information can be used
in this style. However, if all reports in the organization are narrative only, then it becomes a
challenge for the risk practitioner to present the risk report in an interesting way using only
words. Similarly, if the risk practitioner is invited to make a presentation to the board, then the
presentation style should be in line with other board presentations. Detailed preparation and
249
knowledge of relevant background information is essential. When making a presentation to
the board, it is important for the risk practitioner to decide what should be gained from the
presentation. If the risk practitioner is only providing a report for information, it is a different
style of presentation than a report to the board that requires a decision and/or authorization to
take a specific action. The phrase 'know your audience and their expectations' is especially
important when the audience is the board of the organization.
When communicating a message, it is useful to think about the '5Cs' of communication.
Messages should be clear, concise, coherent, credible and complete:
•
A clear message will ensure that the recipient understands the purpose for which you
are communicating with them;
•
Short messages are more likely to be received because you stay to the point and keep
it short;
•
a logically coherent message with all points connected and relevant to the main topic;
•
A credible message will convince your audience that you understand their concerns
and priorities;
•
Complete messages provide the audience with everything they need to take the
necessary action.
27.4 RELATIONSHIP SKILLS:
There are various relationship skills required, as shown in Table 27.2. Perhaps the
most important are influencing and negotiating skills. Relationship skills are important, as are
motivation and political skills. As with other people skills, relationship skills need to be
performed within the culture of the organization and in a way that is fully mindful of its
internal context. Relationship skills also include listening skills. It is important to listen to the
point of view of the individual you are negotiating with or trying to influence. In general,
influence is achieved by using positive energy and enthusiasm about the issues that need to
change.
Successful influence is best achieved by individuals who have the ability to gain
support, inspire others, create relationships and engage the imagination of others. Achieving
improvements in risk management standards often requires continuous negotiation. The
means to achieve successful negotiations are well established, and risk practitioners need to be
aware of and embrace negotiation techniques. Political skills are often difficult and the subject
sounds very scary. Nevertheless, to be a good influence, successful risk practitioners need to
understand the importance of political skills. All organizations have challenging individuals
250
who exhibit inappropriate behavior. Risk practitioners need to understand group dynamics and
be able to defuse conflicts and negotiate solutions in a flexible way. Political skills include
awareness of cultural influences and the requirements of different stakeholders.
In many ways, political skills are most important when risk practitioners are leading
meetings. Everyone present in the meeting has the right to voice their opinion in full, as long
as the message is clear, concise, coherent, and credible. The role of a chair, especially when
present in a non-executive role is to remain neutral and remain impartial while guiding the
meeting to the right consensus. The core of relationship skills is building relationships with
various stakeholders. The various stakeholders in an organization will include customers,
staff, financiers, suppliers, regulators and the public (CSFSRS). With so many stakeholders,
not all of whom will be interested in risk and risk management, it is clear that risk
practitioners need good communication and relationship skills.
Dealing with the opinions of multiple stakeholders will require risk practitioners to
have highly developed people skills. An example of the challenges faced by risk practitioners
in general, and health and safety specialists in particular, is offered by Jeremy Clarkson, when
he worked at the BBC, and who wrote in the Sunday Times on April 4, 2004:
Health and Safety is now so out of control that I find it almost impossible to do my job. At Top
Gear, we refer to the BBC's health and safety officers as Prohibition Officers from the PPD
or Program Prevention Department.
27.5 ANALYTICAL SKILLS:
Analytical skills are extensive and require strategic and logical thinking. Sometimes,
when problem solving is involved, creative lateral thinking is also a key requirement of risk
practitioners. Many risk practitioners are involved in risk quantification, either as part of the
Basel II capital requirement calculation or as part of the analysis to determine the appropriate
level of insurance required. However, analytical skills are not always mathematically based
and well-developed problem-solving skills will be of great benefit to the typical risk
practitioner. In addition to analytical skills, research skills are often a requirement of many
risk practitioners. The ability to find and analyze information quickly and efficiently will be
of great benefit to risk practitioners.
Risk practitioners are often required to evaluate a lot of information on a particular
topic, find common threads in that information and present the findings in a concise and
logical manner. This is almost always a requirement when risk practitioners are drafting their
251
written reports or preparing training courses or presentations. The benefits of becoming an
expert in analytical activities are greatest when risk practitioners seek to facilitate risk
assessment workshops. It is often the case in risk assessment workshops that delegates will
have differing views on the level of risk presented by a particular situation. A skilled
facilitator is able to listen to these conflicting views and identify the underlying assumptions
that led to the different conclusions. Having identified the assumptions and assumptions, a
skilled facilitator will then be able to challenge the different parties with the reasons for their
differing opinions. This will be the most successful way to reach a common view.
Analytical skills involve the ability to understand, challenge and articulate problems
and concepts and thereby make informed decisions. These skills include the ability to
demonstrate and apply logical thinking to gather and analyze information, as well as design
and test solutions to problems. The output of analytical skills is the ability to formulate
appropriate alternative solutions and challenge alternatives so as to develop the most logical
plan of action.
Problem solving and decision making are essential skills for business life. Problem
solving often involves decision making and decision making is critical to risk management.
There are activities and techniques to improve decision-making and decision quality.
Decision-making comes more naturally to certain personalities, so these people should focus
more on improving the quality of their decisions. People who are less natural at making
decisions are often capable of making quality judgments, but may need to be more decisive in
acting on decisions made.
Problem solving and decision making are closely linked and each requires creativity in
identifying and developing options. Brainstorming techniques are very useful and this will
include SWOT and PESTLE analysis structures. Good decision-making requires a mix of
skills, including creative development and identification of options, clarity of judgment,
decisiveness of decision and effectiveness of implementation.
27.6 MANAGEMENT SKILLS:
Although risk management departments are usually quite small, this is not always the
case. In any case, even if risk practitioners do not have direct management responsibilities,
there is a need to understand management skills. Such skills may be relevant in relation to
persuading other managers to take different actions. Awareness of these management skills
should extend to team management and delegation of authority. Many of the people skills
described in this section are also relevant as management skills. Perhaps the most important
252
skill of these people as managers is motivation. Motivational skills are important for risk
practitioners, especially where behavior change or the development of a risk-aware culture
required. Risk practitioners need to motivate individuals, managers and directors to behave
differently.
Also quite important are self-management skills. This will include
the ability to set appropriate priorities, meet necessary deadlines and maintain self-motivation.
Time management, organization and self-motivation skills remain important for risk
practitioners throughout their working lives.
It may be worth reflecting on the fact that there is a difference between management
and leadership. An individual may be able to manage a department by exercising tight control
over individual activities. This is not the same as a leader who has established a set of
priorities and empowered team members to manage their own activities towards the
fulfillment of those priorities. Ideally, the leader will ensure that priorities have been
developed in full consultation with the individuals responsible for delivering those priorities.
Leadership Versus Management:
The biggest difference between managers and leaders is the way they motivate the
people who work for them and this sets the tone for most other aspects of what they do.
Managers have subordinates and have positions of authority and their subordinates work for
them and mostly do what they are told. Managers are paid to get things done and pass on this
work focus to their subordinates. Managers seek control and this shows that they are relatively
risk-averse and they will try to avoid conflict if possible. Leaders have followers, not
subordinates. Many organizational leaders do have subordinates, but only because they are
also managers. When they want to lead, they relinquish formal authoritarian control. Leaders
find it natural to face problems that must be overcome. They are comfortable with risk and
will see routes that others avoid as potential opportunities, but may break the rules in order to
overcome them getting things done.
GOVERNANCE RISK
Learning Outcomes for Section Seven:
•
describe the main features of the corporate governance model and explain the links to
risk management in different types of organizations;
•
outlines the importance of evaluating board and board committee performance and
253
how this relates to corporate governance;
•
list the different types of stakeholders of a typical organization (CSFSRS) and explain
their influence on risk management;
•
explains the importance of stakeholder expectations and how these can be managed
through effective dialog and communication;
•
summarizes the main features of operational risk as practiced in financial institutions,
such as banks and insurance companies;
•
describe the main sources of operational risk in financial institutions and provide
examples of how these risks are managed;
•
produces a brief descriptionof the project life cycleand the importance of risk
management at each stage;
•
describes the key features of a project risk management system, such as the project
risk analysis and management (PRAM) approach;
•
explain the importance of supply chain and the contribution of supply chain risk
management to organizational success;
•
generate examples of risks associated with outsourcing and how these risks can be
successfully managed.
Case Study:
Severn Trent Water: Our approach to risk
We have set ourselves some very challenging targets and continue to strive to improve
our standards of service to customers and our overall performance. The group's risk
management and internal control systems are critical to achieving these targets and enable the
identification, assessment and mitigation of risks inherent in our business activities.
Accountability for the effectiveness of the group's enterprise risk management (ERM) policy
rests with the board, with oversight from the executive team, supported by operational risk
owners and a central ERM team responsible for implementing the ERM process.
Within Severn Trent Water, our approach reflects our status as a
regulated utilities that provide essential services and operate as part of critical national
infrastructure for the UK. We aim to have a robust control framework to enable us to
understand our risks and manage these risks effectively and efficiently. In our unregulated
business, we take a more commercial approach to our decisions around which risks are
acceptable. However, we recognize that we provide products and services to clients operating
in a regulated environment. As a result, for risks that may impact our client services, we take
254
a similar approach to risk as in our own regulated business. The ERM process covers all types
of risks including operational, financial, legal and regulatory. Our risk assessment includes
explicit consideration of the likely impact of the risk on the reputation of the group as a
whole. The resilience of our services is critical and we regularly conduct joint exercises with
other agencies such as local authorities, police and fire services to test this resilience.
Tim Hortons: Sustainability and responsibility:
Sustainability and responsibility at Tim Hortons is integrated through a framework
divided into three core pillars: people, community and planet. Within each pillar are a number
of key issues considered important to our stakeholders such as nutrition, food safety,
employees, children, animal welfare, community giving, environmental stewardship, climate
change and sustainable supply chain practices. We have developed a number of commitments
and goals in relation to each of these focus areas, and have reported our performance against
these goals in our annual sustainability and responsibility report.
Our sustainability and responsibility policy includes structures and processes
support for effective governance and accountability of sustainability and responsibility, and is
reviewed regularly. The board governs sustainability and responsibility through the board's
nominating and corporate governance committees. Oversight activities include: review of
policy development; sustainability and responsibility strategy, including risk mitigation; and
organizational sustainability and responsibility commitments, objectives and external
reporting. Management accountability for sustainability and responsibility resides within the
Tim Hortons executive group.
The assessment and management of sustainability-related risks and opportunities is
embedded as part of our governance framework, as is our sustainability and responsibility
strategy and supporting implementation plans. Key aspects of our approach include
assessment of the sustainability and responsibility impacts of key business decisions;
integration of sustainability and responsibility into corporate risk management programs, as
applicable; development of internal performance scorecards; monitoring our relationships
with our stakeholders; assessment of sustainability and responsibility trends; and
consideration of public policy, consumer, corporate, and general societal trends, issues, and
developments that may impact the company.
DCMS: Capacity to handle risks:
Within core departments, risk is actively managed and risk management is
incorporated into all departmental processes. The departmental risk framework identifies risk
255
management as a key role of the board, executive council and its sub-committees. Policies and
guidance are available to staff on the intranet, and masterclasses are provided risk
management has been provided. The company committee has overall responsibility for the
risk management framework.
The risk management framework consists of three management levels through which risks are
managed:
•
At the local level, risks are managed and risk registers are maintained by policy and
operational teams and by project and program teams across departments.
•
At the committee level, risks are managed by company committees. The committee
maintains its own risk register and manages red-rated operational risks within the
corporate area.
•
Risks escalated by the corporate committee, investment committee, governance board
and operational, delivery and strategic risks across departments are managed by the
executive board.
An internal audit review of the department's risk management systems found that they provide
reasonable assurance. It was concluded that the department understands and manages key
business risks for business-as-usual and program activities. However, the different approaches
to risk management methodologies suggest there is no universal adherence to an agreed risk
management framework or a single risk severity assessment method, and that it is necessary
to develop a more structured and consistent approach to monitoring and benchmarking risks
in this area.
CORPORATE GOVERNANCE MODEL
28.1 CORPORATE GOVERNANCE:
Corporate governance covers a very wide range of topics, and risk management is an
integral part of successful corporate governance in any organization. Most countries in the
world place corporate governance requirements on organizations. These requirements are
particularly strong in relation to companies quoted on stock exchanges, organizations
registered as charities and government departments, agencies and authorities. For example,
companies listed on the London Stock Exchange must be guided by the UK Corporate
Governance Code (2014) published by the Financial Reporting Council.
The purpose of corporate governance is to facilitate accountability and responsibility
for effective and efficient performance and ethical behavior. It should protect executives and
256
employees in doing the job they are hired to do. Finally, it should ensure stakeholder
confidence in the organization's ability to identify and achieve outcomes valued by
stakeholders. There are two main approaches to the enforcement of corporate governance
standards. Some countries treat corporate governance requirements as 'comply or explain'. In
other words, the organization must either comply with the requirement or explain why the
requirement is not appropriate, necessary, or feasible to comply with. Where appropriate, the
organization may explain that an alternative approach was taken to achieve the same result. In
these countries, requirements may be considered as one way to achieve good practice, but
alternative arrangements that are equally effective may also be acceptable.
Other countries require full compliance with the detailed requirements, although
limited alternatives to achieve compliance are sometimes included in these requirements. In
these countries, detailed compliance is expected and exceptions are not acceptable. Corporate
governance requirements should be seen as obligations placed on the board of the
organization. These requirements are placed on board members by legislation and by various
codes of practice. Often, these corporate governance requirements are presented as detailed
codes of practice. To begin the task of improving corporate governance standards,
organizations can develop a code of conduct for company directors, along with a
corresponding 'delegation of authority' document. Annual statements on potential 'conflicts of
interest' should be requested from directors and training should be provided to the board on
corporate governance.
Also, the organization should establish appropriate committees (as listed below) with
defined terms of reference and membership of each of these committees, which may be
established as sub-committees of the board. Reports on corporate governance standards,
concerns and activities should be received at each board meeting, and these papers will often
be presented by the company secretary. Such committees may include:
•
risk management committee;
•
audit committee;
•
disclosure committee;
•
nomination committee;
•
remuneration committee.
Corporate governance objectives:
The purpose of corporate governance is to facilitate accountability and responsibility
for efficient and effective performance, and ethical behavior. It should protect executives and
257
employees in doing the job they are hired to do. Finally, it should ensure stakeholder
confidence in the organization's ability to identify and achieve outcomes valued by
stakeholders.
28.2 CORPORATE GOVERNANCE PRINCIPLES OECD:
The basic definition of corporate governance is 'the system by which an organization is
directed and controlled'. Corporate governance is therefore concerned with systems,
procedures, controls, accountability and decision-making at the highest level and throughout
the organization. As corporate governance is concerned with the way senior management
fulfills its responsibilities and authority, there is a large component of risk management
contained within the overall corporate governance structure for any organization. Corporate
governance is concerned with the need for openness, integrity and accountability in decision-
making, and it is relevant to all organizations regardless of their size or whether in the public
or private sector.
The Organization for Economic Cooperation and Development (OECD) is an
international organization that helps governments address the economic, social and
governance challenges of the global economy. The OECD updated (in 2015) its set of
principles for corporate governance and these are listed in Table 28.1. These principles focus
on developing an effective corporate governance framework that takes into account the rights
of stakeholders.
The principles require fair treatment of all stakeholders and an influential role for
stakeholders in corporate governance. Finally, the principles require disclosure and
transparency. All of these principles are delivered by the board of the organization and the
principles, therefore, make detailed reference to the responsibilities of the board. There have
been a number of standards published recently on corporate governance and British Standards
recently published BS 13500:2013 'Code of practice for delivering effective governance of
organizations'. When publishing the standard, British Standards commented that: 'It is
increasingly clear that society's expectations of organizational behavior and performance, and
thus: "governance", are increasing. This increased expectation is partly in response to a steady
stream of major incidents and allegations of abuse of power.'
The approach in BS 13500 is based on evidence that good governance drives
organizational and societal success. The scope of the code therefore goes beyond the
avoidance or mitigation of problems. It defines different accountabilities for different
stakeholders and is intended to be used as a basic checklist to ensure that all elements of a
good governance system are in place. It is also emphasized that having a corporate
258
governance system in place does not guarantee effective governance, but encourages and
supports positive organizational values and behaviors.
28.3 LSE CORPORATE GOVERNANCE FRAMEWORK:
The London Stock Exchange (LSE) has produced guidance on corporate governance,
and the focus of that guidance is on board effectiveness. In the LSE's view, corporate
governance is about the effective management of the organization and the corresponding
responsibilities and roles of senior managers and board members within the organization.
Figure 28.1 provides a summary of the London Stock Exchange's governance framework.
Governance activities are centered on the organization's board and the LSE guidelines refer to
this board as the supervisory and managerial board. The corporate governance framework has
two main components: 1) the responsibilities, obligations and rewards of board members; and
2) fulfillment of stakeholders' expectations, rights, participation and dialog.
The importance of board members' responsibilities, obligations and rewards is emphasized
and includes arrangements for:
•
determine the membership of the council;
•
board member accountability;
•
delegation of authority from the board;
•
remuneration of board members.
The responsibilities of board members must be met in five important areas, namely the
fulfillment of stakeholder expectations, rights, participation and dialog. In summary, the five
areas are:
•
strategic thinking, planning and implementation;
•
corporate social responsibility;
•
effective risk management;
•
audit and risk assurance;
•
full and accurate disclosure.
The OECD principles and the LSE corporate governance framework provide the requirements
and overall framework within which corporate governance should be implemented. However,
the activities used to deliver each of the five areas of stakeholder expectations will vary. Risk
management activities should be viewed within the broader corporate governance framework.
Although risk management is presented As a separate component of corporate governance
259
within the LSE framework, risk issues also underpin strategy, corporate social responsibility,
audit and disclosure.
Non-executive directors play an important role in corporate governance.
In general, the audit committee will be a non-executive group and represent the third line of
defense, as described in Chapter 35. It is generally accepted that effective non-executive
directors will:
•
uphold the highest ethical standards of integrity and honesty;
•
support executives in their business leadership;
•
monitoring executive behavior;
•
question, debate, challenge and make decisions objectively;
•
listen to the views of others on and off the board;
•
earn the trust and respect of other board members;
•
promoting higher standards of corporate governance;
•
seek compliance with applicable governance code provisions.
28.4 CORPORATE GOVERNANCE FOR BANKS :
Corporate governance and risk management activities in financial organizations are
strictly regulated and governed. Most financial organizations, including banks, establish their
own internal corporate governance guidelines. Typically, these guidelines will cover director
qualifications, director responsibilities and the delegated responsibilities and powers of board
committees. The guidelines should also consider arrangements for annual performance
evaluation of the board and arrangements for senior management succession. The corporate
governance structure will typically be a set of principles governing the conduct of the board of
directors. These governing principles will include information for board members on dealing
with conflicts of interest, confidentiality and compliance with laws, rules and regulations.
A key part of ensuring adequate corporate governance for financial institutions is
adequate training and induction for board members. Typically, an orientation program for
new board members will include details:
•
legal and regulatory framework;
•
risk management;
•
capital management and group accounting;
•
human resources and compensation;
•
audit committee, internal audit and external audit;
260
•
communication, including branding.
The global financial crisis has resulted in banks and other financial institutions reviewing their
own corporate governance standards. The overview in the box below provides an overview of
a large national bank and provides a critique of the bank in relation to corporate governance
failures.
Operational risk:
The bank is the largest financial services institution listed on the national stock
exchange and is among the 30 most profitable financial services organizations in the world. In
January 2004, the bank disclosed to the public that it had identified substantial losses relating
to unauthorized trading in foreign currency options. The losses were classified as operational
risk. The concurrent issue of further substantial losses on home loans questioned the strength
of risk management practices and the lack of auditor independence, reinforcing the view that
corporate governance had not been given the priority it deserved for several years.
28.5 CORPORATE GOVERNANCE FOR GOVERNMENT INSTITUTIONS
For government agencies, robust corporate governance arrangements are usually
mandatory. Also, for many government agencies, the main reason to pay attention to risk
management is to ensure that adequate corporate governance arrangements are in place. In
other words, the primary motivation for ensuring a good standard of risk management in a
typical government agency is the desire to support the agency's corporate governance
arrangements. Figure 28.2 shows the components of corporate governance for a typical
government agency.
For commercial organizations, corporate governance and risk management are
designed to help the organization achieve its objectives, including commercial or market
objectives. The motivation for government departments to ensure good corporate governance
standards is narrower and often focused on accountability. In government agencies, the
driving principles include value for money and avoidance of inappropriate behavior.
Corporate governance is often seen by government agencies as a control framework that
supports innovation, integrity and accountability and encourages good management
throughout the organization.
Within the corporate governance framework, the responsibilities of individual staff
members are often defined. Reporting structures for risk issues are also outlined. Linking risk
management efforts with corporate governance can also allow certain risk areas to be
261
identified for special attention. Typically, these will include value for money, business
continuity, fraud prevention and IT security assurance. Underpinning corporate governance
activities within a government department, agency or authority will be the public life
principles, often referred to as the Nolan principles. These principles are presented in Table
28.2.
The box below provides an example of the importance of corporate governance
arrangements within a government agency. The important contributions of risk management
and corporate governance arrangements and management practices are highlighted in this
example.
Welsh Assembly Government: risk management policy:
Risk policy The Welsh Assembly Government (WAG) sets out a policy on the
identification and management of risks it faces in achieving its objectives. Its purpose is to
ensure that risks are taken into account at all stages in the development and delivery of
WAG's activities, including risk analysis and the development of actions to manage risks, and
to monitor, review and evaluate those activities.
The Accounting Officer and Strategic Delivery & Performance Board of the Welsh
Assembly Government have adopted the following risk management policy to create an
environment and structure for the implementation of the WAG plan, to:
•
ensure that the Welsh Assembly Government's objectives are not adversely affected by
significant risks that have not been anticipated;
•
ensure the achievement of outputs and outcomes and have reliable contingency
arrangements to deal with unforeseen events that may jeopardize service delivery;
•
promote a more innovative and less risk-averse culture where appropriate risk-taking
in pursuit of opportunities to benefit WAG is encouraged;
•
provides a solid foundation for integrating risk management into decision-making;
•
establishing excellent corporate governance components and management practices.
28.6 PERFORMANCE EVALUATION COUNCIL:
The board has overall responsibility for the organization in terms of setting strategy
and ensuring satisfactory governance. Management of the organization is the responsibility of
executive management, and top management, through the executive directors of the
organization, will often be members of the board. When executive and non-executive
directors are members of the same board, this is referred to as a unitary board. In many
organizations, the board consists only of non-executive directors, and is referred to as the
262
supervisory board. Where a supervisory board exists, the executive directors will meet as an
executive committee. This structure of separating non-executive and executive directors into
separate committees is sometimes referred to as a two-tier board structure.
In some countries, a two-tier board structure is more common. Also, a two-tier board
structure is usually placed in charity and public sector organizations. Regardless of whether
the structure is unitary or two-tier, the board will have a range of responsibilities. It is standard
practice for the board to identify those issues where it will retain the highest authority and
responsibility. These issues are usually referred to as issues reserved for the board. The main
area of board responsibility that is usually not delegated is the setting of the organization's risk
appetite. Having decided on the matters reserved for the board, it is then necessary to decide
how authority and responsibility will be delegated with respect to other matters. Large
organizations usually produce a statement of delegation of authority, which will be an
important document related to the governance structure within the organization.
Executive directors, managers and staff represent the three levels of management in an
organization, and together these are the first line of defense in ensuring satisfactory standards
of governance, including risk management and internal controls. The board should be aware
of the specialist risk management functions within the organization and should be made aware
of the activities of these functions and their role as the second line of defense. Non-executive
board members will be members of the audit committee and they should be aware of its
function as a third line of defense in ensuring adequate risk governance. Evaluation of board
performance is a very important part of the corporate governance arrangements for any
organization. Table 28.3 provides a list of issues that should be included in an evaluation of
board effectiveness. The areas to be evaluated are as follows:
•
membership and structure;
•
aims and objectives;
•
engagement and accountability;
•
monitoring and review;
•
performance and impact.
The checklists listed in Table 28.3 focus on corporate governance efforts and on board
performance levels. When deciding on issues related to strategy, tactics, operations and
compliance, the board needs to ensure that adequate procedures are in place to reach
decisions. This decision will result in an action and the implementation of the action needs to
be monitored. The course of action will produce some outputs, and these need to be evaluated
in relation to the impact achieved. When evaluating the effectiveness of a council, the impact
263
of its decisions is the ultimate test. The level of impact can then be evaluated against the
vision, mission and goals of the organization. This needs to be supported by an effective
organizational structure, as outlined in the text box on page 350.
Government structure:
A good organizational structure supports effective risk management. The structure
should fit the organization but will typically provide three levels of governance with respect
to risk:
•
direct responsibility for risk management and control (i.e., staff and management
working within or managing operational business units and boards);
•
coordination, facilitation and oversight of the effectiveness and integrity of the risk
management framework (e.g., risk committees and risk management functions);
•
provision of independent assurance and challenge across all business functions with
respect to the integrity and effectiveness of the risk management framework (i.e.,
internal and external audit).
Students also viewed